Thursday, June 26, 2008

Does LLVM Mean An Alternative to Objective-C is in the Works?

The LLVM project has popped up on the radar a bunch of times lately. There's a variety of speculation about why the sudden interest.

I'll throw my hat in and suggest that Apple is thinking seriously about a full-service alternative to Objective-C for programming against the native OS X (Cocoa) API.

Objective-C hasn't spread as a general use language on other platforms, and Apple is showing a higher level of interest in expanding its ISV/developer base.

While other language bindings have been promised or offered over the years, none have been developed or maintained to the point that they are a realistic equivalent/alternative to ObjC. For example, according to an Apple insider I spoke with, it turned out that, under the hood -- at the level of linking, marshaling, etc. -- the cost of the incompatibilities with Java just got to be too great to try and keep it as a first-class environment next to ObjC.

It would seem that LLVM could open up a lot of doors here.

If, as reported, the Xcode environment hooks in with LLVM/GCC, then there is a natural integration point introduced at the intermediate representation (IR) level.

It may not be trivial -- LLVM is designed to be lower-level than, say Microsoft's CLR. The CLR, together with the CTS (common type system) and various other infrastructure and requirements, created a level of guaranteed interoperability between any two .Net languages ... somewhat different from the purpose of LLVM, which appears to be more about the ability to rigorously transform and optimize code in a hardware independent manner.

In this sense it may be about helping with Apple's parallelization work as well as cross-compilation for GPUs or PowerPC. Still, at the end of the day, there are libraries to be called into and data to be passed. And having a big multi-language abstraction in the middle would seem to make it a lot easier to massage the call patterns of other languages so that they play nice with ObjC system libraries.

Oh, and check this out: it's fun and interactive: you can try it in your browser and see the IR right now!

Friday, June 20, 2008

Want to Read Your Parents' / Boss' / Coworkers' Files? Mozy Client Circumvents Windows File Access Permissions

Last fall I wrote about Mozy, a cloud-backup company (now owned by EMC), which had a severe bug: it didn't back up all the files it was scheduled to. What was most disturbing was not that they hadn't caught the bug ... it's that when I tried to work with them to resolve it, they blew me off. Apparently I wasn't the only one to have this problem either, as people from all over found my blog post and emailed me, saying they saw the same behavior and asking if I had a fix.

I still think that not backing up files is the biggest possible bug for a backup program.

But now there's competition: their latest client allows a non-privileged user on a Windows XP system (haven't tried it on Vista yet) to restore private files belonging to any other user ... including Administrators, and place the "restored" files into the non-privileged user's folders, with full access, and fully decrypted.

How does this work? Say Jim, the Admin on the box, installs Mozy in a default configuration. Mozy is backing up Jim's "My Documents" folder and subfolders, among various other things. Jim's son Lenny, who is a non-privileged XP user and who is not supposed to have access to Jim's private files logs on.

Lenny notices that "My Computer" contains a virtual drive corresponding to the Mozy backup set. In that virtual drive is ... a "C:" drive ... and a "Documents and Settings" folder ... and a "Jim" folder. Now in XP, "C:\Documents and Settings\Jim" is another name for Jim's "My Documents" folder. This particular instance though is not the actual "C:\Documents and Settings\Jim", which Lenny doesn't have any access rights to, but the backup image of the folder.

So Lenny browses through, finds something interesting, right clicks and chooses "Restore To," which lets him "restore" his dad's file to somewhere of his choosing. He browses to his Desktop, clicks ok, waits a few seconds, and now he has the file.

(Even if Jim has chosen to manage his own crypto key -- one of Mozy's coolest features -- the Mozy client keeps that key accessible so that it can perform automated backups. Unfortunately, it also uses the key for restore operations no matter who performs the restore ... so files restored in this way are decrypted.)

Ok, so there are no secrets on the family computer. Not the biggest surprise, since if junior really wants the data, there are tons of other ways to get it, from booting a Live CD and mounting the hard disk, to yanking the hard drive right out of the box.

But here's where it gets more interesting: In many (most? ... all that I've worked at anyway) corporate, Active Directory- / Domain Controller- managed XP Pro deployments, folks can log on to each others' workstations at will, provided they use their own credentials in the Domain. Their Domain profile updates to the local machine as necessary, and they can then work there. They may even be able to log in remotely via Remote Desktop.

So at work, I walk up to my co-worker's machine (or maybe RDP in) and log in as myself. I open the Mozy tray icon, and proceed to restore their files from the backup set to my own directory, or to an unprotected area like C:\Temp. From there I can open/read/copy these files however I like. Incidentally, if my boss' files weren't already scheduled to back up, I can add them to the backup set. Next time the backup runs, they'll show up in my view of the "Virtual/Restore Drive."

I haven't tested the Mozy "Pro" business client, but since the docs [PDF] look identical to the Home client (apart from a color accent) I suspect it behaves exactly the same way (see in particular sections 7.3 "Using the MozyPro Virtual Drive" and 7.4 "Right-Click Restores") Not to mention that if Mozy fixed this in the Pro edition I can't think of any reason they'd intentionally keep a broken code fork for the Home edition.

I think there are some other fun tricks one could play with this client too, but it all boils down to two things:

  1. The underlying process is a privileged process, but it takes orders from a client run by any user.(I'm no security guru, but this sounds like a Confused Deputy problem to me.)
  2. The full fidelity of the local file (including a way to associate ownership and permissions) is not being preserved through the backup round trip.

I'd have reported it to Mozy before writing about it here, but they made their lack of interest clear last time around.

Update: I forgot to mention, MozyPro offers "Network share and mapped drive support" ... combined with the bug described here, that's some serious potential risk to add to the mix.

Wednesday, June 18, 2008

Please, Tell Me Another Cool Story About Your AAPL Stock

A comment I read today claimed that Research in Motion (maker of the Blackberry mobiles) stock (RIMM) has outperformed Apple's over any conceivable period you might want to look at. (Yes, I checked it out, it's true, and I have some numbers for you later if you don't want to go try it yourself.)

Here's what I find really interesting: Apple doesn't just have product fanboys, it has stock fanboys too. I've personally met dozens of people who -- entirely unprompted -- insisted on telling me about their AAPL stock adventures, successes, questions about timing and the future ... I haven't met a single RIMM investor who has spontaneously felt the need to chat me up about the stock.

Now there's no mystery about RIMM: Anyone who understands fundamentals could analyze RIMM as easily as AAPL. Or if they want to really get into it, RIMM's products, plans, sales channels, and management are arguably more transparent, simpler, and easier to crack than AAPL's. (Most investors love leaks and hate surprises.) So it's not like these AAPL investors stuck with the company they could understand and analyze.

Instead, I'd venture the opposite: I bet they know little to nothing about either company under the hood, but they love the drama and the theater of an Apple product announcement, whether it's really good or bad for the stock. They think that press coverage somehow equals investing success.

As for the numbers, I checked Google Finance and observed that ... yes ... in all the time that these two companies have been public, RIMM has outperformed AAPL over all reasonable intervals. In fact, even if you had, say, sold your AAPL to buy RIMM at the worst conceivable moment, when RIMM peaked relative to AAPL, within a few years your RIMM holdings would already be worth much more than the AAPL shares.

I'm not bringing this up to recommend one stock over the other. They have actually trended together, and if this sector is your thing (I count them together today, because of the iPod/iPhone contribution to Apple's success), then you might want to invest in both of them ... and some of their other competitors too ... to diversify, at the expense of trying to make the most money on a single horse.

But what cracks me up is how people so often want to believe a story they know over a story they don't know; a simple story over a complex story; and a story (narrative construct in general) over the tricky realities that motivate and underlie all of our constructs.

And if you're one of those people so in love with a romanticized Apple story that you don't mind having half the returns (in the last 5 years), 40% of the returns (last 2 years), or even just 30% of the returns (1 year) of a RIMM investor ... I'm not saying sell Apple, but diversify, diversify, diversify!

Monday, June 16, 2008

If Developers Love Speed, Why Is a Slow Laptop More Popular than a Fast Desktop?

When I was in college, there was an anthropology meme about how childbirth became riskier when the human pelvis adjusted for walking upright. So the ability to walk and run -- or the brain developments that caused humans to deal with problems by walking and running instead of some other way -- must have offered some massive evolutionary advantage that outweighed increased risk to mother and offspring in childbirth.

I'm not sure where this belief stands now -- whether it's established dogma or the anthro equivalent of an urban legend -- but there seems to be a funky analogy among developers and their dev machines.

I'm amazed by how many devs want to be mobile so bad that they use a laptop as a principal (or only!) development machine. I'm more amazed when these same people then get into a silly debate about "the best tools for the job," whether that's an OS debate, or IDEs, or something else.

Because, like walking upright in the story, a laptop offers mobility at a very heavy price.

I work machines pretty hard -- running server software, virtual machines, development environments / debuggers, lots of browsers, random other tools, some of which even use CPU cycles and not just memory. I appreciate the productivity and uninterrupted "flow" that a really fast machine offers.

Laptop performance is awful compared to desktop machines, and with every passing month a laptop (due to its limited ability for upgrade) falls farther and farther behind its well-maintained desktop counterpart. And a plain ol' $100 motherboard and $250 processor in a desktop will do things that make most laptops implode into a singularity, whether it's the 1333 MHz FSB, the 3+ GHz quad-core CPU, or a graphics card whose cooling pipe alone can't fit inside a laptop.

Even the top end, like the fastest Alienware gear, has some fundamental limitations that sound like desktops from a few years back: 2.8 GHz CPU / 800 FSB / 667 Memory ... and a price tag (with the best options) near $5,000!

It's not an OS thing either: the hyper-popular MacBook Pro, while one of the fastest "conventional/mass-availability/non-gaming" laptops, is a complete lightweight compared to the base 8-core Mac Pro tower (that runs the same $2,800 as a the top-end MacBook Pro).

Don't even get me started on the garbage laptops that most companies give their employees, machines which are optimized for durability, enterprise management, and running Office. Sporting things like 4200 rpm hard drives.

And for the occasional but real necessity of mobility, a $250 cheeseball laptop does a fine job for giving presentations, working with Office, and even a quick hack here or there, so it's not as though there's a huge sunk cost just in being able to bring a slide deck to a client.

Yet ... the ability to move around instead of sitting in one place offers -- or at least appears to offer -- some kind of power that compensates for all of these issues.

Can anyone clue me in on exactly what it is?

Thursday, June 12, 2008

I Say "Ôpen" - You Say "Õpen": It's Not iPhone vs. Android, It's Software vs. Telcos

I couldn't find the first article I had read spreading the Android vs. iPhone competition meme. No matter, it has taken root and grown like ivy. iPhone doesn't compete with feature phones or smartphones, but with Android, yada yada. Where's Microsoft and RIM, yada yada. iPhone is closed, Android is open...

Hold that last part just a sec.

It is true that by the standards of the software world, iPhone is less "open" than Android -- Android will run on lots of hardware, it is open to programming at more layers of the stack, doesn't involve an App Store or a pseudo-proprietary language. iPhone is more constrained.

It's shaping up to be an epic battle if you accept that framing of the story... But:

By the standards of the wireless telco world, both iPhone and Android are "open" (as are Symbian and Windows Mobile) because they let you choose what you want to run, and by exposing services like GPS location and push messaging to ISVs, they allow a freeform relationship between the device owner and the software vendors offering real, fast-paced innovation. Such a relationship is a huge change from tradition, where the telco mediates the relationship to the detriment of everyone involved.

Never mind if the data access costs a bit more than some folks might like (Gizmodo shows that there isn't really any change here from existing smartphone plans). The carrier has to make money somehow, and building wireless infrastructure and selling access to it is what they're good at. Controlling the user experience is not what they're good at (one reason they rank slightly below used car salesmen and vampires in terms of customer satisfaction).

Looked at this way, iPhone and Android have a whole lot in common: they're trying to push the evolution of consumer use of mobile devices while trying to wrest control of the narrative from telcos who have stifled the industry for almost a decade.

The hype and success of iPhone and Android is a boon for consumers and for the entire industry, a chance for America to move from a cellular Minitel world to an Internet world.

Monday, June 09, 2008

In Blue Trunks, Skyfire and ISPs; In Red Trunks, Multi-Core CPUs, GPUs, Smartphones, iPhone and Laptops

Skyfire is a mobile browser that has been exhibited at DEMO and has just closed a $13 million B-series funding round (they had received $4.8 million total prior funding). The elevator pitch is that Skyfire brings any web content to the mobile phone, including Flash applications, YouTube videos, Ajax, etc.

I've been trying the Skyfire beta, and I have to say that it's a neat piece of engineering, even if it's just a stripped down VNC-style screen/audio scraping client for a server-side browser session.

But I'm stunned that it has received this level of venture backing.

My surprise isn't because the software is buggy, slow, and has a bad interface on my Samsung Blackjack. Since I'm running a beta in the 0.6 or 0.7 version range, I feel I should be charitable and I'll pretend that all the bugs will be fixed by 1.0, the interface will be great, and it'll run 10x as fast as it does today.

Instead, my surprise is because Skyfire is really about a great periodic function known as "thin client, no, fat client, no, thin client, no, fat client ..." and Skyfire is the epitome of the thin-client position.

Instead of running a browser (which ironically was once considered the thin client, but is now just the universal fat client, consuming hundreds of MB of memory on a desktop to run several Flash or Ajax apps) on a small device, they punted. They'd run the browser in a data center with memory, CPU, and bandwidth, and hand the phone a 2008 equivalent of a green-screen terminal.

This is a losing proposition. For a long time now, all signs have pointed to the fact that fat clients win. And not just because they happen to offer a better user experience (thin-client proponents insist that will change 'someday' although I doubt it).

The economics and technology lean toward the fat client: Although bandwidth has gotten cheaper on an absolute dollars-per-megabit basis,

  • Bandwidth has gotten more expensive relative to the speed of "local" hardware buses: USB 2.0, eSATA, PCI-X, 1333MHz memory, gigabit Ethernet etc.
  • Bandwidth has gotten more expensive relative to the cost of local computation: a midgrade Intel proc costs the equivalent of a few months of home DSL or cable ISP service, and this equivalent has been stable for a number of years ... and the computational power of that midgrade CPU has gone up severalfold, while the DSL/cable bandwidth has stagnated ... and now is threatened by both metered-pricing and traffic-shaping schemes. On the GPU side, the differential has changed by orders of magnitude to the advantage of the fat client.
  • A given "bandwidth experience" has gotten more expensive as users expect to be connected in multiple contexts: To have the same "experience" I have to buy the same bandwidth several times, once for when I'm home, again for when I'm on my cell phone, again when I need to use WiFi somewhere, and maybe a fourth time for a 3G laptop card.
  • Cheap powerful computation has innovators, while bandwidth has innovation obstructers.

Sure, raw dollars-per-CPU-cycle and per-kWh can be optimized in a data center somewhere.

But as long as the cost to connect me and that computation dwarfs the inefficiencies of just carrying the computer with me, Skyfire and its investors have bet on the wrong horse.

Sunday, June 08, 2008

Microsoft Should Trumpet, not Downplay, iPhone's Real Accomplishment (Hint: It's not about Sales Volume)

In this article, Philip Elmer-DeWitt deconstructs a Microsoft partner mass email to discuss how a heap of chest thumping is presumably hiding real insecurities about how the Windows Mobile ecosystem stacks up to that of the iPhone.

Coming before the new iPhone launch, I agree this is not a coincidence. And although I've penned defenses of Microsoft in this blog, this post isn't one them. Instead of chest thumping, Microsoft should be talking to its partners about what Apple has accomplished with the iPhone that Microsoft has not in the 6-odd years since the first Windows Mobile phone shipped... and how that accomplishment has created new opportunities and liberated new value for the entire wireless space including the WinMo world.

In a nutshell, one of the enduring problems with wireless is that no matter how good the phones got (first WAP, then Java apps -- with networking, then color and multimedia and .Net and push data and QWERTY keyboards etc.), U.S. customers just never seemed to get that this was a real computing device, that would powerfully complement their PC(s) and could be just as general in use.

No matter how much analysis showed that the phones people already had could save weeks out of their lives through increased convenience and productivity (with the right software), almost no one used productivity apps, or mobile websites, on their phone. Some conceptual chasm just stopped people in the U.S.

So Apple comes along with the iPhone. And feature-for-feature, the original iPhone OS (not the OSX core, but as it was exposed developers/users) couldn't hope to keep up with Windows Mobile 2003, let alone '07 (WinMo 6.0).

But Apple was hunting different game. By combining a beautiful interface, ridiculously fast processor (to the point that battery life suffered), and an all-in-one experience featuring massive "On Ramp" signage to apps and the web, Apple got people to understand the phone was a computer that normally, natively runs apps and accesses the network, something no one else had accomplished on a mass scale in America.

I've written before about stuff Apple does poorly. This iPhone-as-computer play isn't one of those things. It was a big gamble, but arguably Apple has pulled off another early-Macintosh-type accomplishment in terms of changing how the public understands what a device can/should do.

And, as with the Macintosh, there is no reason that this "enlightenment" should only put dollars on Apple's bottom line. It boosts Windows Mobile, Symbian, Blackberry, Palm ... by focusing free mindshare on the phone as computer.

Now the other players need to follow through. Microsoft and RIM have the lead in the U.S. -- the first thing they ought to do is stop everything and get a browser on their phones that doesn't totally stink (that's the sanitized version of how both those guys' browsers deal with the modern web).

I won't detail requirements; I think Safari on the iPhone is a clear enough target. And while the wide variety of OEM hardware that runs Windows Mobile won't all have the CPU muscle for a Safari, Microsoft should make a credible effort to replace notepad, er, I mean Pocket IE. Meanwhile, why not send out a partner mass email confessing that PIE alone is costing everyone in the WinMo value chain bigtime.

If I were Ballmer, I'd dig up half a dozen hackers from inside or outside who have worked on the Mozilla codebase. I'd get them porting whatever they could to WinMo, and I'd have an internal team building a new Pocket IE product as well. At the end of Q3 '08, whichever browser works better on the most Windows Mobile devices, becomes part of WinMo, the other guys get a mediocre line for their resume (unshipped product), a vacation, and a reassignment to the next Microsoft Bob.

Saturday, June 07, 2008

Maybe a Reason to Learn some Scheme, not a Reason to Avoid Anonymous Functions

A team member with one of my consulting projects sent an email yesterday, describing his counterintuitive run-in with the this keyword in an ActionScript 3 anonymous function. He found a fellow traveler looking at the same issue here... and concluded this might by 'yet another reason to avoid anonymous functions.'

I have a different view, which I thought might be worth reproducing here:

I'm not sure this is a reason to avoid anonymous functions. Looking at the issue and the blog post, the following points may be helpful for the newbies to ActionScript. AS3, and the Flex/Eclipse (FlexBuilder) environment especially, make ActionScript seem like a strange flavor of Java (or C#). But it's not.
ActionScript 3 is an implementation of EcmaScript 4. It has much more to do with JavaScript than with Java, although Adobe intentionally created an environment that would be familiar and comfy for Java devs.

EcmaScript (aka JavaScript) is a Lisp/Scheme family language not a C/C++/Java family language.

Unfortunately, for historical reasons, it shares some syntax constructs with the C-derivative languages, and ES4/AS3/JS2 adds more of those -- but many of them have different meanings, as the aforementioned blogger discovers the hard way.

If you're interested in how this came about, and how to think about it, I can't say enough to praise Douglas Crockford's lectures on "The JavaScript Programming Language", which you can watch from YUI theater. Brendan Eich takes issue with some of the "politics" stories in Crockford's account. But confirms that engineers were recruited to Netscape with the promise of implementing [some flavor of] Scheme in the browser.

If you expect to spend any amount of time in the future doing JS or AS, a couple hours watching Doug Crockford speak are unbelievably worth it. JavaScript (and AS) are extremely powerful languages and can work really well ... only they definitely don't work like they appear they should, if you see the syntax and come from a C/Java background...

Once we realize that we're basically running Scheme in the browser (Brendan says Self), lambda -- anonymous functions and their closures -- become first-class objects as fundamental to us as stack vars in a C language.

As a bonus, if you're new to this and have some time, MIT has published one of the classic textbooks, "Structure and Interpretation of Computer Programs" online for free under a Creative Commons License, along with instructors' manual, exercises, etc.

Actually, I'm gonna go out on a limb here and say if your company or team has a C/stack/register kind of background (Assembly/C/C++/C#/Java/Pascal/Delphi/VB.net/etc) and you're looking at getting involved in JavaScript/ActionScript/Ruby projects, make a team workshop out of doing as much of the Abelson/Sussman book as you can get away with. As a practical side effect, it'll also make your SQL code easier (core SQL is more like Scheme than C) and give you another way to look at problems.

Thursday, May 29, 2008

Higher Energy Prices == More Value in Software, Bandwidth

I got to see Arthur Rosenfeld speak at UC Berkeley's Physics Dept. graduation last week, when my younger brother finished up there as an undergrad. Dr. Rosenfeld's lab and LBNL worked in both research and policy, producing technical advancements in energy efficiency focusing on physical buildings.

His talk got me thinking that not only can information processing produce efficiencies ... but actually that higher energy costs may also be a boon to all manner of information processing and software applications, because it increases the general (relative) value both of processing and of bandwidth (and associated infrastructure).

The gains apply not only to applications directly focused on saving fuel (e.g. logistics systems), but also all of the productivity apps that allow more (or the same) industrial capability with less effort, time, and raw materials. This productivity argument is a standard ROI type argument about information systems. It just takes on a new urgency as forecasts for the energy component in these industrial processes show a bigger number.

Also worth re-examining are the applications which are meant not to make moving physical stuff more efficient -- but to obviate the need completely. The U.S. Mail's logistics capability may make Netflix much more efficient than driving an SUV to Blockbuster ... but BitTorrent makes Netflix look like the stone age. It's no surprise that the easiest thing to move as data is a data-like-object.

The other category is meat-like-objects. Telecommuting and satellite work sites are vastly more usable and useful now than they were even 6 years ago when companies (famously Sun) ditched office space after the dot-com crash.

While issues remain with 100%-offsite work, I believe the era of traveling to the office five days a week for 'info-worker' jobs is pretty much over. Already, I see many companies allowing or encouraging people to work somewhere else part of the week, coming in only 2 or 3 days. That movement can become broader based as the support software and bandwidth improves. In the verticals, the telemedicine model will become more prevalent.

We can also create improvements in industries where the physical world is the point, like grocery stores -- and no, I'm not thinking about stuff like WebVan even if Safeway.com does pretty well, and amazon.com can ship you a year's worth of pasta. I'm thinking that sharing and augmenting data from a store (and its upstream supply chain) can reduce the number of trips people take to the store ... you won't go when they don't have what you're looking for; you'll look at the produce or the microbrews remotely and decide whether to bother; you'll spend less time in the store, which means a smaller (both in business hours and space) site can service the same volume of sales.

But I'm getting too specific: my point is not to envision kooky Internet schemes for avoiding bruised apples. It's that all of the software we have (operating systems, applications), hardware (GPUs, quad-core procs), and bandwidth becomes measurably more valuable as they becomes a viable substitute good for energy. And where we always measured productivity by looking at time-replacement, that time becomes doubly valuable when we are also paying more to heat, cool, light, or motorize the environment where people need to spend that time.

Monday, May 26, 2008

My Brain on Web 3.0: a Killer App for the Semantic Web?

Here's a semantic app I'd really like and which could make the Internet -- and data stores in general -- more valuable. If anyone sees this and thinks it's a great startup idea, you're welcome to develop it.

Right now, a number of semantic analysis engines are being developed, and many are running well in production. Examples include ClearForest, which is related to Reuters Calais.

There are also a bunch of up-and-coming semantic-web apps, like Twine, that add semantic analysis to the extant web 2.0 experience. But while the RDF-enabled-del.icio.us-on-steroids-with-autotagging may be nice -- heck, I'm sure I'll be using one of those systems -- I want something that can carry out the kind of mental associations that I normally would have to do myself.

In order to make that a reality, I'll need several things:

  1. The Model: it works by association, and associations have direction, degree, and kind, among other things. So we need more than just a network. We need a model that implements a metric space or vector space, allowing distances to be computed between any two points with sensible behavior, and where measures (length, volume) can easily and intuitively work.
  2. Concepts (e.g., "politics"), and the places concepts are referenced (say, a political blog page), both live inside this space as subspaces, just like in my brain. Some of these spaces may consist of just one element.
  3. The formulae that support metric need to be fine tuned so that abstract tags ("politics", "justice" as opposed to "Davis, CA" or "bananas") don't suck a million other things to within epsilon of themselves. We can't have everything that linguistically has to do with politics cluster tightly in the space to a politics node, or else the system isn't terribly helpful.
  4. I want the system to start out thinking like me ... and then I can experiment later with "social thinking." What does this mean? My semantic tagging is different from everyone else's. Each group or culture I'm in sees the content differently from other groups and cultures; there is no universal invariant conceptual structure. One persons sees a news story and thinks "economics" while someone else thinks "environment" and another thinks "social justice." If we mush all these tags together we get nothing terribly useful. So: let's start out with my view of the world, we'll compare and integrate others' later.
  5. How to do #4? Start with every web page I visit (not just those I actively tag) -- read my history file or my network traffic (obviously, keep raw data local for now). Read my email and my calendar and my notes and phone (PIM) and my to-do list. And weight accordingly: associations in a web page I write (like this blog post) count more than stuff I browse through; notes I make in my phone or Outlook count for even more; the metadata in my calendar and the titles of my contacts mean a heck of a lot for the model. Walk my social graph and look at what my friends know and are interested in! These are all straightforward algorithmic steps. Leaving aside any self-tuning in the metrics engine, there is no AI or black box here.
  6. The data from #5 is part of the metric function ... that's how the system shapes itself to my view of the world, or at least my "attention waveform" as I transmit that through keystrokes and mouse clicks. Concretely, nodes "move" in the space based on whether I actually key them, whether they appear in meetings in my calendar, whether they are tightly clustered to my personal contacts etc. Even my contacts are arranged based on how long I've known them, what I talk to them about, how often, etc.
  7. The system will make mistakes. So all the more reason for (1) privacy around my core data and (2) a dashboard where I can "juice" certain things or move them around. (This is where interesting goal-oriented self-retuning can come inThere is plenty of other data that can be shared and deduced for network-effect-dependent revenue streams.
  8. A UI into the model. What I'd really like is something brilliant and minimalist (that I can't myself invent!) I know there are lots of desktop-based visualization methods that would be fascinating and could dazzle a crowd at a presentation, but I want something day-to-day useful ... and ideally something that fits on a mobile phone (or at least iPhone) screen. So that in a perfect world, if I'm out and about, I can poke this system with one piece of data and have it return the associations my brain makes -- and the ones it would make if I were jacked up on caffeine and had the whole internet in my frontal lobe somewhere. I'd like maps, charts, and pictures in there too.

I hope this outline makes some sort of sense. Like I said, it's really not as tricky or complex as it sounds. Fine tuning the metrics will take real work, as will optimizing the data structures so that the relevant queries are fast, and so that the system can work in "tinfoil-hat-private-mode" as well as "publish-whatever-you-deduce-from-my-friendfeed-and-private-chats-mode."

Incidentally, this app could also help solve the augmented reality dilemma of "how do you narrow down all the possible info about the input objects and coordinates, so that the user sees something interesting and/or actionable," so that's another angle.

Have some capital or time you want to throw in this direction? Feel free to email me -- adbreind@gmail.com ... or if you want to loot this idea and think you can build a killer app for the semantic web era? That's fine too -- send me a link when I can sign up for the beta.

Thursday, May 22, 2008

Great Article on the True Nature of LINQ in C#

In the early days of C# 3.0, Microsoft distributed a whitepaper which walked through the rationale behind the additions to language, how the language changes related to the syntax options, and what it could be used for.

Among the key applications ... perhaps a co-evolved objective ... for the new constructs was LINQ ... of the to-SQL, to-XML, and over-Objects varieties.

As Visual Studio 2008 and C# 3.0 has moved out into wide use, though, that background has faded away and instead one sees a ton of quick examples and how-tos about LINQ and database operations that give the impression it's all some kind of fancy SQL trick.

Which is why I really liked this article on 7 Tricks to Simplify Your Programs with LINQ.

The only thing I didn't love was the name, because it's not really LINQ that Igor is talking about, it's the awesome functional programming features under the hood ... which happen to enable LINQ.

Igor shows how the underlying extension method and lamba constructs let you do the cool Lisp (ok, Ruby) tricks with C#, and he does it without getting into explaining what all the machinery is or even what it's called. Those explanations are important to be sure, but having these quick (2-3 lines!), powerful examples communicates a lot at first glance to readers who may not want to read about all the CS issues right away.

Furthermore, Igor avoids examples featuring the slightly misleading SQLesque syntactic sugar that can cloud what's really happening... until his last example.

Which is very useful, because the busy developer-on-the-run seeing a LINQ example doesn't realize that the select/from/where stuff are not magic language keywords. They're just an alternate way of saying Foo.Where or Foo.Select. They're just extension methods that happen to be fairly fundamental to working with lists and sets.

Maybe Igor even gets some folks who thought C# had somehow sucked in SQL to realize that, instead, all the time they've been writing complex SQL queries, they've actually been doing that functional programming stuff they've been hearing so much about. And now they can "think the same way" in C#.

Tips: Cable Modem Signal Troubleshooting

I've had a few problems with fluctuating signal levels on my cable modem, which result in losing connectivity for a period of time. If you have a cable modem and the connection has ever been flaky for no apparent reason, you might be able to use a few tips I've picked up.

First, most cable modems have an internal management/monitoring system you can use to see what's going on, and it's conveniently exposed via HTTP so you can look at it with your browser.

This web page has a great collection of information on accessing the modem status and what numbers and error messages to look for. This may sound obvious, but download all of the info before you have an outage unless you have a redundant connection. (Also, don't be scared off by the old dates on the page ... most newer models have the same interfaces, and of course DOCSIS is a standard so it doesn't change year to year).

The modem typically listens on 192.168.100.1. So if you have a router (e.g. a WiFi access point) between your PC and modem, you may need to adjust the subnets or routing, or remove it, because this subnet may be downstream/local/wrong-side-o-the-box for you. If subnets and routing aren't your thing, the easiest alternative is to unhook the router and connect directly to the modem.

With cable modems, it's not just an issue of having a "strong enough" signal -- the signal has to be consistent within a certain band, because the modem determines its uplink transmit power level based on the downstream level it observes. In other words, if the downstream level comes in too strong, then the modem will reduce its upstream power in response, and you can lose connectivity because of that.

If you've had some issues, you see signal fluctuations, and your cable operator doesn't have any reports of problems (their system can remotely observe other people in your area), here are a couple of remediation steps to try:

First, isolate the cable modem on your wiring -- meaning unhook other devices, TVs, DVRs, etc., which might be on your line. Clearly not a long-term solution, but if this makes a difference then you'll have info that will help if and when you do need the cable company to make adjustments.

If that doesn't make a help, follow the cable line (assuming you can get to it) from the modem all the way back to where it comes into your house. Remove any unneeded splitters, barrel connectors, 20m tangles of  coax, etc. To the extent that you do need these parts, they should be ideally be 5GHz capable (marked that way right on the device). If you have older ones that say, e.g., 1000MHz, replace them with newer ones.

Splitters and the like are not normally weatherproofed, and apparently (I have no proper data to support this, but technicians have told me), they show deterioration after a few years of exposure to heat, cold, condensation, etc. in basements and crawlspaces -- enough to cause a high-frequency signal to get flaky. And they can end up producing effects that vary with temperature.

Last, on my line, a technician also chopped out the connectors where the cable company's own line transitions to the house wiring, put new connectors on both sides, and hooked it back together. If you want to make this swap, or replace any of your connectors (as opposed to parts that the connectors attach to, like splitters), you'll need a coax tool for cutting and stripping the wire and then crimping on a new connector.

These primitive coax tricks won't solve all problems (even in my own installation, these changes resolved maybe 85% of the trouble) but they may make a difference and, at the least, they'll remove a bunch of unknowns from your equation.

Monday, May 19, 2008

mod_ndb: Wicked REST for My[Giant]SQL Cluster

I caught a great presentation at CommunityOne a couple of weeks ago, and haven't had a chance to write about it until now.

In a nutshell, mod_ndb is an Apache module which allow a limited set of parametrizable MySQL queries to be automagically exposed as REST services via Apache. There are three things I left out of that sentence for clarity, that make this uber-cool:

  1. The operations actually run against MySQL Cluster, a high-performance, shared-nothing (code for you don't need to manage a SAN and shared filesystem) scale-out system.
  2. In exchange for not having full SQL capability, these services interact with MySQL Cluster using the cluster's native NDB API for maximum performance.
  3. The latest version of MySQL Cluster, 5.1, has significant technical advantages over the earlier but still impressive 4.1 and 5.0. These include the ability to store more data on disk instead of dedicated RAM, and this collection of improvements. (In that doc, where you see references to 'carrier grade edition' note also that, according to the CommunityOne talk, future versions of MySQL Cluster will be on a unified codebase from that carrier grade version.)

I've liked MySQL Cluster since it's debut, and I'm thrilled to see this evolution.

As far as "let's download this right now and set it up," it is true that in the four years or so since that debut, the niche for scale-out clustering has narrowed:

On one hand, machines and storage have continued to get cheaper and faster, with the result that a data set and transaction load that might have a cluster of 2-4 dual-proc servers, and associated hassle, can now be handled by a single server with a couple of fat quad-core Xeons. The single OS and single filesystem simplify things vastly, to the benefit of databases like SQL Server, which have not invested in a scale-out strategy.

On the other hand, applications with a need for super-massive data that can live with some latency and a lightly structured, don't-call-me-relational data model can pay as they go for that scale-out capability with Amazon SimpleDB, Microsoft SSDS, etc.

Still, there is a well-defined middle section for a product like MySQL Cluster (and its arch-nemesis, Oracle RAC):

  • big data sets and/or large-scale OLTP,
  • plus a highly-structured relational data model. (Microsoft has asserted that SSDS will move toward full relational capabilities in the longer-term roadmap, but inasmuch as the initial service is still in beta, I don't count that.)
  • legal or business requirements to keep the data in-house (not in the cloud)

Or you can flip it around the other way: if your app doesn't need a cluster like this (or something similar), what are you really doing, anyway?

Thursday, May 15, 2008

Vista Performance: It Really Is That Bad

I try to stay away from the rant post, it's too easy and doesn't contribute a lot. But I feel myself succumbing, so at least I'll try and mix in a little useful material with my rant.

I just spent some significant time trying get Vista to behave on my wife's laptop. By behave, I mean not make it impossible for her to surf the web with Firefox because the CPU was pegged most of the time and the HDD never spun down.

First, some facts:

  1. I'm as close to a Microsoft fanboy as you'll find in the Bay Area. They do great stuff. I'm an ecumenical kind of guy, so I also so like Ruby and Flex and Java and Linux (wait 'til my next MySQL post). I.e., I'm not married to Microsoft, but I think they have done some amazing engineering in the last 10 years and it's a pleasure to work with almost all of their late-model products.
  2. This machine, while not blazing by 2008 standards is only a few years old, does have a 3 GHz HT proc, multiple gigs of RAM, nVidia graphics, plenty of hard drive space, etc. In fact, it ranks in the 4.x range on Vista's own "performance estimate" in every category except graphics. Which shouldn't matter because Aero Glass is turned off, and my wife isn't a gamer.
  3. Just to cover all the bases, it's plugged in and not configured to ever step down the processor or anything like that to save power. And there's almost no software on it. It's basically Firefox and MS Office, Grisoft/AVG, whatever Windows Update considers critical, and not much else. My wife runs under a non-admin account because she neither wants nor needs to install or configure anything on it.
  4. An early-ish adopter, I was forced to abandon Vista after seeing it run cripplingly slowly on a 3.5 GHz, 5+ rated desktop. As a developer, watching this machine churn while it tries to decide which UAC prompt to throw next wasn't acceptable, since I had XP on the same box (dual-boot) and could measure that XP was easily 25% faster. But the wife liked Vista's look and feel, actually preferred it to XP, so cool, didn't think perf would be a big issue for her.

Ok, so the performance was all gone to heck. I checked all the obvious background tasks that could be going nuts, virus scans, disk indexing and all that. Found a few services and tasks that had caused problems before and disabled all of them. Can't imagine why they're running by default. What ever happened to configuring services to run based on their actually being needed by something the user wants to do?

The killer this particular time was the 'network location awareness service' and the DNS caching service. First, NLA. According to MSDN (full info here), this service is 'vital for computers or devices that might move between different networks.' First, I'm not sure I believe that; so far, the computer seems to work better without it. The little icon (and service) that would take 5 minutes to realize the machine was actually on the Internet (you know the icon) is now dead, and apps connect right away. Funny how that works.

Just for the sake of argument, let's pretend that it really is 'vital for computers moving between different networks.' Here's a clue: (1) it doesn't take much monitoring for the machine to realize it's always on the same network in my house, so (2) shut this stupid service down, (3) if another network is detected or the old one is unavailable, maybe then spin this beast up and (4) monitor your own resource usage -- if the service starts using 50%+ of the CPU all the time, for whatever reason, and the network isn't ever changing, why not shut it the #$% down at that point?

I could make the same argument for DNS cache. Although it boggles the mind how a service this simple could ever be using a real percentage of a modern CPU. I turned it off. I guess Comcast will hate me now for making an extra 25 lookups a day.

I'm not going to get into the argument that there shouldn't be lots of services on the machine -- after all, most of the myriad services have little performance impact and at least in Vista are supposedly less likely to compromise security. Although I would prefer a 'configure to run after deciding it's useful and not harmful' self-management approach.

I just wonder, if a pristine machine like this one, well configured etc., scoring generally 4 in the Vista perf scale, and whose only sin is being 2005 vintage, gets mucked up this badly from such mild use, there are truly some problems with Vista, both for home users and businesses, that are more serious than I would have believed.

Ok, so I promised I'd try and offer a little useful info. Once again, for the sake of SEO

Some possible fixes for Really Bad Perf in a basic Vista machine:

  • go into the task scheduler and get rid of tasks you don't want to run;
  • look at the Network Location Awareness and DNSCache services (I'm not gonna say kill them unless that's what your particular machine needs ... but look at them);
  • if you haven't quashed Aero already, turn it all off and see if that helps;
  • and if you're running Vista Ultimate, and you don't actually ever use Media Center, go and kill all the tasks and services related to MC because Vista isn't smart enough to notice that you don't need 'em, and I've caught them hogging a ton of resources.

Last, not to get into the 'uphill to school both ways thing,' but a 700+MB working set with no user apps running??? You just want to say, "Man, have some self respect and get on a treadmill once in a while..."

Sunday, May 11, 2008

Ghost of Christmas Yet to Come: Alternative Futures for Windows

Sun's OpenSolaris demos and pleas ("put in on your laptop -- really!") last week got me thinking about the desktop OS, or more precisely the boot OS ...

Some folks have hypothesized that 'Windows 7' will be ultra-modular and may introduce a new API scheme while supporting the old ones via virtualization.

I think this is the right idea, but can be taken much further, with benefit to the entire industry/ecosystem.

Consider:

  1. The desktop will remain critical, as long as NVidia and Intel keep loading cores and cache onto chips, while keeping the price low and the power consumption efficient. Unless/until mobile broadband gets faster, more reliable, higher penetration, and about a 90% price cut, the desktop (or laptop or palmtop) is where a lot of computing will happen.
  2. Windows will remain vital for a majority of desktop users: businesses keep Windows to keep their legacy line-of-business apps running. Those workstations also run Office. Users want to run Office at home. There are also gamers who haven't migrated to consoles.
  3. (and this is the fun part): Windows doesn't have to be that desktop, and that desktop doesn't have to be Windows. Breaking them apart properly can create more value Microsoft (in terms of equivalent or greater revenue, with lower costs), and opportunity for everyone else (Apple, Sun, Linux distros, device makers).

What I am basically proposing is that Windows be so extremely modularized that many (eventually most or even all) flavors of it run only in virtualization on top of ... well ... anything.

Having Windows be the Ring 0 (or -1) operating system is hard and expensive and in most cases no longer necessary. It also doesn't pay well. Making an operating system run well on every cheap piece of hardware, taking the blame for the blue screens caused by other folks' faulty drivers, and being the "buck stops here" guy for security and resource management is neither cheap nor easy.

So I say: ditch it!

Could this work? In most cases, yes.

Businesses don't need Windows per se. What they need is an operating system that is supportable and manageable and can run their legacy Windows apps without incurring a bunch of additional cost.

What would a minimal Win32 Lite OS look like? The XP Embedded system builder is all about figuring that out. The Wine, Mainsoft, and Mono folks also have pretty good data on which APIs are critical for which sorts of apps. I'm not suggesting running a port of Win32 (or .Net), just that those folks have real good familiarity with which APIs and services are critical for running a user's apps, and the dependency chains between them. I don't claim to have that info at my fingertips, but we know that an upper bound for client software is XP Pro. From there we can subtract a lot.

So businesses could be running Linux or OpenSolaris or Mac OS, and run a SKU of Win32Lite in VirtualBox. Microsoft wins, because they only deliver and debug against a small set of virtual hardware devices, and can charge around the same amount as they currently do for the license (on an annual amortized or subscription basis) and support. As long as they produce a great implementation and great APIs to develop against (they've got a big headstart for desktop apps), there's no reason they wouldn't keep selling licenses.

Some security issues are lessened, because the virtualization layer is senior to the VM. Similarly with deployment, monitoring, resource management, etc. And hardware has migrated (and continues to migrate) to the USB bus, which is supported via the VM.

What about consumers? The rise of web applications doesn't mean the desktop is irrelevant -- all the apps in Flash, Silverlight, and Java make that clear. But those are browser plug-ins, which don't rely on Windows being underneath them. Home users may well want the latest Microsoft Office 2007, so Wine isn't their solution ... they'll buy a different SKU of Win32Lite to run office and their handful of random non-Web apps... maybe some of the Adobe products.

For the few cases where performance is important (let's say a non-linear editing tool for hacking HD videos), a simple user-mode service on the underlying host can deal with big number crunching or disk-file-shuffling jobs in cooperation with the VM. Again, most legacy consumer gadgets don't need to care about the "real" OS, since they're on USB and they're proxied through to the VM. Most of them will play nice with other-OS class drivers (such as 'mass storage' or 'image acquisition') anyway, so users may not need Windows at all for them.

So who isn't covered by these basic configurations? Folks with real custom hardware (strange ISA or PCI cards and the like) and hardcore gamers.

I have a feeling the 'real custom hardware' will show up more in businesses, which can lean on Microsoft's 10-year-plus support lifecycle policy. Even in slow industries, that should provide enough time to at least plan a migration.

For gamers, well, there are at least 3 options for Microsoft, all of which can provide revenue:

  1. Drive innovation in 3D acceleration under virtualization ... Fusion already supports DX9 Shader 2, and with Microsoft's contribution I'm sure the perf could get vaguely close to unmediated DX.
  2. Encourage gamers to migrate to a console... not a loss for Microsoft if they can bulk up margins even a little on the XBox
  3. Offer a DirectX-on-the-Metal version of Windows, to be run from a bootloader next to a 'productivity OS' ... and I'm thinking DX-on-the-Metal is not that dissimilar from XBox anyway.

And one more thing:

Sooner or later, if the must-boot-on-the-metal requirement has been gone from Windows, hardware changes will make it so that Windows no longer can boot on commodity metal.

The architecture shift will inevitably happen before some businesses are ready to make a switch (don't believe this? go look at the airlines). For some businesses, there may be expensive retro boards (just like there were Z80 boards for running CP/M in 65xx and x86 machines), but eventually we'll need to run Windows in a VM on top of some hardware emulation.

I don't think it's in the least unreasonable to expect emulated x86 hardware to run as fast at that point as real hardware does today. We'll call it MAME Enterprise Edition.

Wednesday, May 07, 2008

Alternate Reality: Java and .Net Both Went Open Source 8 Years Ago

The later-phase, heading-to-market end of application model innovation is screaming along.

Sun and Microsoft have announced their intent to get into cloud models that improve scalability and manageability. We don't know for sure how pleasant the programming will be, but it seems reasonable to assume it's at least as good as ASP.net 3.5 or J5EE. Microsoft seems to be aiming center-of-the-road with stuff like ASP.net, the MVC flavor,  and "dynamic data" pieces, while Sun is putting a big chunk of its chips on the Java side, and another big piece on JRuby/whatever-is-next-that-they-can-get-to-run-in-Glassfish.

Amazon is offering persistent disks for EC2, acknowledging that the RDBMS-backed app is not immediately going to disappear in favor of a S3 or SimpleDB layer. 'Cause syncing RDB stores usefully on S3 is a hassle (see slides 10-14 here).

Or, you can also buy all the missing pieces of the Amazon stack from RightScale.

Then there's Passenger (mod_rails) for Apache, and a Glassfish gem, which both aim to improve Rails deployability and incrementally bump performance.

But all this got me thinking about an alternate universe, one of those hindsight 20/20 things, that's interesting to imagine:

For Sun and Microsoft, I believe the missed-opportunity-of-the-decade was not open sourcing the JVM and CLR respectively (and their core libraries and infrastructure), from around 2000.

In the late 90s, Java was a beautiful thing, and aside from a few anti-OO diehards, it was clear that if the perf issues and minor hassles could be overcome, virtualized apps in an elegant environment (Smalltalk, oh wait, did I say that out loud?) were the future.

By 2000, Java legitimized VMs for server apps. As for GUI apps, graphics, printing, language neutral JIT, all manner of easy native interop, module loading, and the other parts Sun didn't get to ... Microsoft had those problems licked even if CLR was still in beta.

If all this IP had gone open at that time, a few major projects -- maybe 2 or 3 -- would probably have come out of it, and these projects would be the de facto runtimes for everything we want to run today. These few projects would spawn native bindings for all manner of OSes according to the existing APIs, so it would be even easier to really write apps that run on all kinds of devices, or in a cloud facility, or in on local elastic virtual infrastructure.

With the languages separate from the VMs, but with well known interfaces, a lot of debates (JavaScript 2 for example) would be less necessary. Meanwhile, Apple could have contributed whatever changes were necessary to get keep Cocoa APIs in sync, instead of going halfway down the Java road and then getting stuck, which would vastly improve the reach of that platform (their mission being more about user experience than about Objective C).

Performance, security, deployability, management -- these problems wouldn't magically go away, but with a more modest universe of options, they become infinitely more tractable.

In hindsight it seems that keeping these technologies proprietary (Sun's moving along; you can see Microsoft's code now, but you can't change it and re-release your own variant) was about fear and ego and control, defensive maneuvering.

I find it hard to see how either of these players would have made a dime less money in the scenario here; actually they would probably have made more money and have even more mindshare than they do now.

Sunday, May 04, 2008

Martin Fowler's DSL Material

I'm not a big link blog guy, but Martin Fowler's note/outline/draft material for an upcoming book on Domain-Specific Languages is worth checking out at your earliest convenience. I've been impressed.

Lest you be tempted to pick sides for or against DSLs (really not the point of Mssr. Fowler's book), or to postpone thinking hard about them, consider: DSLs are already merging with with 'traditional' languages and APIs ... it is likely that this trend will continue, with the result that DSLs will be a fact of life in the 'standard model' approach for many types of applications.

So it's probably useful to get a grounding in what they can really do, how they can best do it... and how they can best not interfere when they shouldn't.

Sunday, April 27, 2008

Don't Feel Bad, It's Also Amateur Hour at Analog Devices

Analog Devices, whose D/A, A/D, and DSP circuitry power on-board sound in everything from ThinkPads to ASUS' main line of motherboards, makes a wicked bad driver suite.

Last summer, I was troubleshooting a situation where laptops were exhibiting lots of really short freezes at a close-to-the-metal level ... keystroke input being delayed, or mouse cursors getting jittery. Turned out to be DPC storms resulting from the Analog Devices SoundMAX driver and usermode controls.

Today I was struggling with the latest flavor of this driver set, which attempts to detect what you've plugged in to which port, and then auto-configure. Which it does wrong, forcing you to come up with tricks to get basic things like a headset and microphone working. Guys, we've had the "green" and "pink" sockets on sound cards for like 15 years now, give me some credit here.

But that's not what got me really annoyed. No, these guys have gotten themselves really confused about how multi-user logon and fast user switching works on XP. They've only had seven years to get that right. They pop up some of their controls and wizards in the wrong user session ... when I tried to close them and switch back to the account I needed to be on, their driver blue-screened my box.

As a developer, I install all kinds of stuff on my machines and I often torture them in unseemly ways. But, since 2001 when I started using Windows XP, this is the first time I've had a blue screen during a regular old user session, after a successful boot.

This is a WHQL certified driver too. For a long time there were problems where developers didn't get their drivers WHQL certified, which led to users clicking the infamous "continue anyway" button, and companies ignoring WHQL; I'd hate to suppose Microsoft solved that problem by letting junk like this pass the test.

Saturday, April 26, 2008

DVD Flick Installer Needs to Rewrite a System Library Why?

I feel bad ripping one in the crew that builds DVD Flick, a well regarded open source tool. From what I can tell, this is a fully-open, Sourceforge-hosted, quick-authoring tool similar to the excellent ConvertXToDVD.

During its installation, though, it attempts to overwrite the richtx32.ocx file in the windows/system32 directory. Richtx32.ocx is a Microsoft-authored GUI widget component (an AcitveX library) present in all or most Windows systems.

Trying to overwrite this is bad on so many levels. Who knows which version of this lib is being supplied by DVD Flick? The installer definitely doesn't compare versions and make an intelligent choice, or it would have chosen not to even try on my systems, where everything is up to date. So it's an old version, maybe one with bugs or security vulnerabilities, that could compromise my system because any process might load this code up.

Not to mention it appears to the user that the app needs to alter their system in order to continue. Since they trust this app (it's been written up in blogs like LifeHacker), they start thinking "oh, sometimes free apps I download off the Internet need to overwrite my system libraries, no big deal" ... all the UAC in the world won't be able to overcome that mentality (although theoretically Vista has other protections to remedy this specific problem).

I tried to think of any justification for this behavior, but I couldn't. True, there are aspects of the ActiveX/Registry/DLL Hell problem that can make something like this a little tricky, but there are workarounds as well.

Starting with the easiest fix: include a legit Microsoft merge module containing the latest DLL version, and first, in the installer script, check the installed lib version/signature to see if it's necessary to install a new one at all.

The other possibility, that DVD Flick isn't trying to update this library, but needs to install its own version on top of the existing one, with some extended functionality, would be even more ridiculous... I entertained this idea for a moment, but it appears not to be the case.

Wednesday, April 23, 2008

Augmented Reality is Here, You Just Can't See It

Augmented reality is here now, and is going to get bigger fast. In fact, it's going to be a killer app for the semantic web.

Where did I come up with that?

Well, as far as not seeing it ... that's because it doesn't look like the picture you have in your head. You're thinking of stuff floating in midair like in Minority Report or at least a heads-up display with goggles or a sceen that overlays data onto video.

Those may be nice implementations. But the core utility of augmented reality is getting information on stuff you're near (where near can be physical or by mental association) and having it delivered to you in an actionable "heads-up way" even if it's not on a HUD.

In the information sense, AR is already popular. Joe calls Fred on his cell phone: "I'm trying to find a hardware store down here near 20th, can you hop on Google maps and find it?" Fred looks it up, maybe hits Street Views, done. Later he calls Fred again from a party: "That girl is here -- the one I met at your office party, used to work with you... what is her name? She's looking great. What is her whole deal again?" That's augmented reality by cellphone and human reverse TTY, call it v 0.5.

Then there's v 0.6, which is Google Local for Mobile/iPhone, Windows Live Mobile, or the like. GLM offers "My Location"-biased search results, while WLM has solid speech recognition (you can just tell it where you are or what you want). These mobile search products are great, except that they are relatively active, not passive -- you need to tell them what you're interested in, they doesn't already know. And they only knows a little bit about places and a little more about businesses.

Despite the limitations, these two methods are real examples of AR in use today, even if people don't call it that.

I assert that AR is a killer semantic web app because it's the semantic tools that let the machine filter the Internet down to what's relevant in your (metaphorical) field of view, when you're out in the real world.

Googling for answers in many real-world situations is drinking from a firehose, and you need to go all the way into the cyber world (iPhone, laptop, etc.) and invest effort to get what you want. That's not AR, it's just context switching and portable cyberspace.

AR is a system that can matrix your interests, contacts, places, and needs against all the current information germane to where you are or what you're doing ... and then pick out just the high level parts you want, with a mechanism to drill down by concept. Doing that by brute-force search, or even collaborative methods (think geotags), won't get you far enough. You need a true semantic layer to front-load the work and make this real-time.

On the other side, once you have a workable if basic semantic layer, then AR becomes a very basic incredibly useful flavor of personal, semantic search.