Thursday, March 22, 2012

Hubble will live

I read with delight on the BBC news website this morning that a rescue mission to renew failing systems and install new instruments to the Hubble space telescope will be going ahead after it was canceled after the space shuttle Columbia disaster. This important for several reasons. Some of the most amazing discoveries have been made about our universe with the help of Hubble and given the rate of these discoveries its entirely possible that there are many more waiting to happen if Hubble is given the chance.
This is of course not to mention that some of the most beautiful images of our universe have come in through its mirror system - images that have left the world in awe. In an attempt to share with you the importance of this rescue mission I’ve uploaded a set of images from Hubble that I feel justifies all the effort being made and some more.
Long live Hubble!
The best images from Hubble

Twitter

I was intrigued by the facebook idea of a personal status and I was searching for a way to have my own status on my website that I could update from anywhere; a mobile phone, instant messenger and of course a computer. I came across Twitter during one of my revision breaks and realised that with its API and free remote access tools, including text messages, it was the perfect way for me to achieve what I wanted.
Within 5 minutes I was registered and within another 5 I had enabled updates via my mobile phone and instant messenger as well as writing a script that allowed me to update from the Linux terminal (hee hee). In my next revision break I spent a few minutes writing the code to integrate my Twitter status into my website and after a bit of tinkering with CURL and string splitting in php there it was in my side-bar under “My status”.
Whats so nice about all this is that my status is completely hidden on Twitter’s public site and yet my own site can tooth into their API and grab the status meaning I can update my site over my phone for free and only allow my site users to see it. I could also change my site to only allow logged in users to view it, I have complete control.
This is in sharp contrast to facebook’s way of doing a status update which, despite having an API, seems to always require a computer and a visit to their site to both view and update the status field. I want tools to enhance my own site and what it provides to my readers, not tools that use up more of my time because I have to update something in two locations. This means that, for now at least, my facebook status will remain disabled. If I figure out a way to use CURL to update my status inline with Twitter on facebook as well but without logging me out of facebook in my browser (this is what happens when I try it at the moment) then I will.
For now, enjoy my useful and most likely amusing status updates in my sidebar - no stalking please ;)

phpBB RC1 Released

Its a truly momentous day in the forum world! After many years (yes years) of waiting there finally exists a downloadable, supported copy of the latest incarnation of phpBB3. The full release announcement is here. This news is hot of the press so have fun watching the currently active users on the phpBB forums go soaring sky high!
I’d like to take this opportunity to say how happy I am that this release has come to fruition and to give HUGE thanks to the phpBB developers and indeed all team members for their hard work. I have been critical before about your progress with the new release (and am glad your release has come soon enough for me not to seriously consider acting on that post!), but I really think it has all been worth it and I look forward to the continued use of your software for many years to come. All the best phpBB, you once again reign supreme in the forum world and I for one am very proud to be using your software.
As for my mods, yes, I will be porting all of them that haven’t been catered for by default in the new version. As for when it will happen, some time over the summer most likely.
Sadly for those at RouterTech, I will not be moving the forums over to the new version. We have a heavily customised system running there and a conversion would most likely involve a lot of extra work for team members, not to mention a delay in our ability to release and support firmware which we know doesn’t sit well with users ;)

Two Tier Internet

There has been a lot of talk lately in the news about the potential for the implementation of a two tier internet, that is to say a global collection of networks in which some traffic is given priority over others, not necessarily for reasons of efficiency but for those of financial incentive - those that can afford to pay can prioritise their internet traffic or take advantage of less restrictive access to the content of others.
This is something I wanted to muse over a little before committing thoughts to my blog because it is something close to my heart. Having given it some thought though it is actually a less savoury prospect than I had ever imagined and I was never in favour of a two tier internet in the first place.
At present the internet is a place in which content is indiscriminately accessible to all; something I publish is available to a user in, say, Australia as readily as it is to someone who lives up my street. Likewise someone on a cheap ISP can also access my published content in exactly the same way as someone on a more expensive provider.
Two Tier Internet means that for the first time some publishers will be able to dictate which “class” of consumer will be able to access their content and what is worse even if the publisher intends to allow everyone equal access the ISP could be equally restrictive if it took their fancy. My internet might not be the same as your internet and this means that whole areas of the internet could be completely invisible to you without you even knowing it. Sure, you might be able to hit IP addresses but they would time out as if there was no machine responding if they weren’t on your tier.
I cannot stress enough how damaging this will be to the whole ethos of the internet. Tim Berners Lee (creator of the world wide web in case you didn’t know) said himself that the connections we use to share data should be freely accessible to all and that the whole way in which the internet works relies on us all being on one network in which we all have the potential to be equal players. If the very creator of the web intended us to have one internet and believes it would be damaging to split it up, why should legislators who have no technical knowledge have the right to say it shouldn’t be that way? Quite simply they are taking the piss.
I’m not going to jump on a high horse about the quality of the content I have to distribute to the world, especially since some of it is probably pretty crap in the eyes of some who might come across it, but I sure as hell don’t want to see someone else deciding who should see it or not based on who is lining their pockets. I put it online because I want everyone in the world with a connection to be able to read, listen to, watch or download it as they wish. If a day comes when I can no longer do that, the one place on earth where we are all still truly free, the internet, really will be dead and the world will be a much darker place.

Akismet Failing

It is without a doubt that one of the few anti-spam measures in place on my blog that has stopped me disabling comments is Akismet. The service catches literally thousands of spam comments on a daily basis. The problem is that while I used to get absolutely no spam through to my moderation queue such that all I had to decide was if I wanted a comment published, I’m now getting spam through as well and I’m having to mark various items as spam for submission to Akismet.
Critics will no doubt point out that this quantity of spam can’t be numerous and they’d be right, but as the solution didn’t previously let any through and Akismet is a continuously evolving anti-spam solution its worrying that its effectively getting worse over time as it means spam is evolving better than the defenses of Akismet.
Spam is without a doubt one of the biggest issues on the world wide web and while it hasn’t yet caused me to disable access to anything on my sites, if too much spam gets through to my blog moderation queue then I will be disabling comments. You might argue that disabling a feature is letting them win, but my take on it is that if I end up reading spam then I’m letting the spammers win because they have reached me as a reader. Likewise if there is a possibility that the comments might reach my blog then I’d be letting the spammers win by allowing the comments to reach a global audience.
Here’s hoping that Akismet doesn’t get any worse at blocking spam, or even gets better, as that way the comments can keep on flowing and I can be safe in the knowledge that I’m not in any way helping spammers reach their audience.

Facebook Fresh

It can’t have escaped the attentions of those that read my blog that I don’t like facebook being littered with applications. Not that I dislike the idea of an API or the ability for developers to interact with facebook but I simply preferred the API when external applications were kept as just that, external to facebook and only visible on an external URL, not on the pages and profiles of facebook its self. The “clean” look of facebook was what made it appealing to me.
Given that facebook refuse to make it possible for individuals to disable viewing the stupid applications some people decide to add to their profiles leaving frustrated users like myself in a hell resembling MySpace (note my comparison to a network I did not join due to the awful looking profiles), someone else has stepped into the breech and produced a solution.
Meet Facebook Fresh ™, a novel solution for all firefox users such that they never have to look at an application on facebook ever again. Screens will suddenly look as nice and neat as they did the day you joined the site. Refreshing? You bet.

phpBB3 release date announced

The phpBB group have have announced the final release date of phpBB3. This is an important milestone as there hasn’t been a new version released for 7 years and finally after much hard work from some and waiting around for many, its going to be here. This is a fantastic development and I feel sure that this advance will once again put phpBB far ahead of the game in the web based forum world.

New Router

Today I setup a new router in our house, the Netgear DG834G. After carefully ensuring all existing settings were mirrored on the new device it was just a question of unplugging the cables from the old router and plugging them into the new one, like for like. It worked straight away with no noticeable problems.
I’ve known for years that I really should have replaced my old Origo (more modern requirements were taking their toll on its memory and other capabilities) but today, when I got an extra 100 Kb/s download speed simply by changing my router, I wish I had done it sooner!
I did hit one snag though in that my ability to connect to remote VPN networks using PPTP suddenly stopped working. After a bit of experimentation I realised that for some reason having DMZ enabled to any IP caused authentication to fail. Disabling DMZ allowed the connections to happen flawlessly.
Having to implement this work around didn’t fuss me as I don’t actually use DMZ, in fact it was merely pointed at a non-existent IP on my subnet in order to shield unused ports. Turns out that the Netgear doesn’t need such a thing to ensure all risky ports but the ones forwarded are hidden. Times have changed since the Origo days but old habits die hard!

Webperf Issues

For the last few weeks or so, Webperf has been having back-end CGI issues. This has resulted in their usual colourful array of graphical statistics being missing in action. These are an invaluable resource for web hosts and similar to keep tabs on how they are doing compared to others in terms of their availability and bandwidth provisioning etc. Without it many people, myself included, have been getting frustrated.
If Webperf are not able to keep on top of the work required to run and maintain the site they should hand over to one of the many willing volunteers that have sprung up since the downtime. We need this site and this inaction is annoying and frustrating.

Google change favorites icon

Regular Google users will have noticed that the favorites icon has recently changed from Old Google Favorites Logo to New Google Favorites Logo. Given how infrequently images and layouts related to Google’s home page have changed over the years, does this small change mean fundamental changes might be in the air at Google?

Problem with lftp solved

I thought I’d share this little solution with people as its been bugging me for ages. My command line ftp client of choice, lftp, recently started not connecting. I couldn’t find a suitable solution until I noticed that the AUTH command was being used when I normally don’t make use of that for ordinary ftp sessions.
I added the following line to my lftp.conf file:

set ftp:ssl-allow false

This fixed the issue of failing to connect and everything is now working as it should. Hope this helps someone who is in a similar fix.

Facebook Username

Last night facebook launched a username option which allows visitors to the site to go straight to a profile by putting the username in the URL. I of course made sure I snagged my username as soon as the system went live, so you can now access my facebook profile (if I have granted you access to it of course), on the following URL

www.facebook.com/kieranoshea
Sadly I wasn’t able to snag “kieran” for a username as it had already been taken - Kieran Cloonan I’m looking at you - grrr! I could have had “oshea” but having that as a username seemed to bring back distant memories of being called by my surname at school so I decided against it. The username “oshea” has in fact now been taken so Ben O’Shea, I wish you the best of luck with it.
All in all I think this is a good move by facebook. While some might criticise it and say it’s just another step towards becoming MySpace, I see it as more of a step towards the modern web. PHP files and arguments in the URL are so last century. Pretty permalinks and restful behaviour are what it is all about these days. While I can’t see facebook truly implementing a restful URL structure they have certainly made an important forward step with usernames.

WordCamp

WordCamp UK is being held in Cardiff this year and on account of the fact I live relatively close by now and have always meant to go but never got around to, I’ve signed myself up. For those of you that don’t know, WordCamp is an informal gathering of bloggers and developers who use WordPress. There is an opportunity to attend talks, discuss projects and of course socialise with other technically minded individuals.
The scheduled talks look like they could prove very interesting and there is already a large group of people signed up, some of whom I have already exchanged words with over the internet on various occasions so it will be great to meet them in person. Matt Mullenweg is also attending and having the opportunity to thank him in person for creating WordPress will be really cool.

WordPress Geek

I found this amusing list of things that might make you a WordPress geek. I found myself falling into a number of the categories listed so I think it’s a strong possibility that I am in fact a WordPress geek. How do you fare against this list?

Comments on DRM

The original published date on this article, “The Day the Music Died“, is a little old but I think many of the points are still relevant to a lot of the online music services out there today. Certainly food for thought if you own an iPod or other similar device that allows you to pay for and download music that is restricted with DRM.

Spam Insight

I read a brief but interesting article on the Akismet blog today offering an insight into the current state of web based spam.
While Akismet isn’t a blocking service I personally feel that the large IP ranges identified by the article as solely in use by spammers could do with being blocked.

Home VPN

I’ve written an article over on RouterTech about how to setup your own home VPN server. It’s something I’ve mentioned to a few people lately that I use so I figured it was time to share exactly how it’s done. Questions and comments are of course always welcome over on the RouterTech forums.

Foursquare Auto-Checkin

Having been a recently new joiner to the foursquare phenomenon I’ve quickly decided that I like it and that it’s leaps and bounds ahead of Facebook places. That being said, it’s not without issue. The main one being that there are places I regularly frequent that I want to check into, but don’t wish to publish on twitter. “You can do that!” I hear you cry, well yes, you can, but you still have to get your phone out of your pocket.
To me, getting one’s phone out of one’s pocket should be to actually say something, such as “I’m at somewhere new” or “I’m at somewhere I normally visit but I’m here for longer this time, come and join me”. If I’m just heading to the office or going home, I want to log that onto the statistics but not shout about it. While there is of course an option on the mobile app to do this, I have to specifically choose that option. In reality, what I really want to do is only to touch my phone if I have something to say, otherwise let foursquare do the work for me.
Enter the API! I have long been a user of google latitude. This little known service allows me, via a private API key, to retrieve the latitude and longitude coordinates of my phone wherever it is. I used this feature to track my road trip progress and it worked very well. To this end, knowing that foursquare is primarily powered by coordinates and I always have access to mine, I decided to stick my coders hat on and program my way to lazy foursuare use.
Registering for a foursquare API key is easy and it arrives straight away. Getting an OAuth token using the key was also just as easy and within a minute or so I was able to call out instructions to foursquare from my server, pretending to be me. It didn’t take me long to close the loop so that to all intents and purposes my server is me as it knows where I am.
Although it’s a little rough around the edges, I now have an application running that has a pre-set list of locations that it is allowed to check me into and when my coordinates say that I am there, it calls out to foursquare and does so.
While this is far from ready for release, I do hope to do so in not too distant future, perhaps in time for WordCamp. In the meantime I’m going to sit back and enjoy ousting my colleagues as mayor of the office, just by pulling into the car park. After all, isn’t that what this whole foursquare thing is all about?

Push e-mail on an iPhone or iPad

When you search google for a similar phrase to the title of this post you usually get a fairly stock response; use exchange, mobile me or gmail and you can have push e-mail by simply activating it in the mail settings. The thing is, most people who search for the above know this already. What they really want to know is how they can push e-mail with a conventional e-mail account that they may have from a hosting provider and access through thunderbird or outlook.
With BlackBerry, push e-mail is really simple. Just provide the setup screen with your IMAP enabled e-mail address and password and BlackBerry will start pushing e-mail to your phone. With iPhone and iPad it can also be that simple without changing your mail provider or e-mail address but to get there we need a step in between. I call this the fake exchange server.
A little known sourceforge project called z-push holds all the answers. Essentially by installing this PHP code on a web server and setting up a config file or two we can fool an iPhone or iPad into thinking it is talking to a Microsoft exchange server and get genuine push e-mail from a standard IMAP e-mail account!
To get started you’ll need the following:
  • A web server
  • Copy of Z-Push code
  • The details of your IMAP e-mail server
Don’t look with concern at the first requirement. You can probably make use of a shared hosting account for this, or if you were prepared to go out and spend on mobile me then you will probably be able to spend less and get your own VPS, which, if you intend to push a lot of mail, might be a better bet in the long run anyway.
Configure your web server to support SSL and install PHP. I won’t go into detail on how to do this as there are plenty of online tutorials for this already that you can google. The SSL bit is important as this will ensure that e-mail traffic from your iPhone or iPad is encrypted which is essential if you have a habit of using open WiFi connections while on the move. If you’re doing things on the cheap and using a home server then make sure you have a static IP at home. You can get a free SSL certificate from the fine folks at StartSSL.
Once your server is up, follow the instructions for installing z-push from their website. In practice I found that the stable version was far from it and didn’t really work so opted for the 2.0 alpha version. Try your luck and see what you get. There is a forum on the z-push site from where you should be able to obtain help if you need it.
With z-push installed and configured as per your IMAP e-mail server settings, you’re ready to try your luck from your Apple device. Head on over to e-mail accounts and delete the current entry you have. Once you have done this, select to configure a new account and choose Microsoft Exchange. Enter your e-mail address, username and password. Leave the domain blank and SSL on. Often your username and e-mail address are one and the same although this can vary. It’s unlikely that just these details will connect as you’re pushing mail from your dummy server, so you’ll be prompted after a few seconds for a server URL. Enter the domain name on which you have installed z-push.
Assuming all of this is accepted by your Apple device, you now just need to go to the fetch new data settings, enable push and and change fetch to manually. Open up mail and if all is working you should see your e-mail in folders. If so your final test will be to return to the home screen, send an e-mail to yourself from your PC and watch the iPhone/iPad. You should see the e-mail arrive within seconds. If so, you’re pushing mail!
At the close of this article I’d like to mention that my ability to investigate this scenario and write up the solution is due in no small part to the generosity of Stinky Ink in them putting up an iPad2 as a prize in their WordCamp UK competition, many thanks once again!

Anti-Spam Effectiveness

What website are you looking at? Sounds a simple enough question right? Well for a human maybe but perhaps not for a CAPTCHA reading online bot. A problem that’s plagued bloggers and forum administrators for years is how to stay ahead of the comment/post spam that invariably results from putting one of these sites online.
The solution until about a year ago has been to go for a centralised solution like Akismet or make your CAPTCHA ever increasingly harder to read and thus harder to crack. Unfortunately the latter has simply increased the number of frustrated users resorting to e-mail to ask for access or giving up altogether. Akismet has stayed ahead of the curve and for one-off comments on blogs and other types of media has proved invaluable. For forums however there isn’t really a reliable connection between most forum systems and Akismet and administrators have been left wondering what to replace their ageing, difficult to read and fundamentally ineffective CAPTCHAs with.
Welcome the Q&A. While this concept has been around for a while, Q&A really comes into it’s own when you factor in randomisation. If a particular style of CAPTCHA is in use by many sites then it’s well worth a spammer trying to crack it as they reap large rewards. Custom solutions on the other hand have the advantage that unless you run a huge site like BBC News, they’re not going to be worth cracking as there are easier rewards to be reaped elsewhere. While you could use a custom CAPTCHA this requires some effort and you’ll probably end up re-using someone else’s code which defeats the uniqueness objective. This is when we resort to the simple question, unique to every website. Where am I? Who is my admin?
Having implemented such unique questions to all of my forums recently I can report a resounding success. No automated registrations leaving just the handful of spamming manual ones which are easy to weed out of an early morning. The big bonus here is legit users find it a doddle to register as they either know by heart or can easily look up the answer. I also now have the slightly tangential advantage that if I were to start getting automated registrations again then my sites may well have become as popular as BBC News which would certainly bring a smile to the face.

Stalling File Transfer Over VPN

The other day I had cause to allow someone to access their corporate VPN over my home internet connection. After I had configured the appropriate pass-through settings for the IP address that my DHCP server had allocated their laptop they were able to connect easily. One issue remained however; whenever they checked a file out of sharepoint that was over 250Kb or so, the file transfer to their machine would stall and consequently crash the browser.
Google threw up all sorts of possibilities but the more things we tried (and that failed) the more I couldn’t escape from the idea that it must be some network related issue. I got to thinking about the nature of VPN and how there is an initial connection and then a large stream of UDP packets over the tunnel for the data transfer. That’s when a light bulb switched on - I’d seen something like that before in my Draytek router settings.
Draytek have a nice selection of anti denial of service features which I have activated to protect my network. Some of these concern certain types of flood defense; where a count of packets is maintained and if it exceeds a certain threshold then the connection will be dropped for a period of time. This would result in the appearance of a stall for any file transfer caught up in the melé. Bingo!
The culprit setting is shown in the screen shot below, “Enable UDP flood defense”. Originally this was set to 150, I had to set it to 1000 in order to eliminate that VPN issue.
Draytek DoS UDP Settings Screenshot
It’s worth discussing why the number has to be so high for my fix and why it may not need to be so high for you. Most home connections over VPN end up being below 5Mbit or so with the corporate end point on the other hand being capable of 100Mbit. This results in the overall speed obviously being tied to your 5Mbit speed. In my case I use the FTTC technology and thus have speeds up to 80Mbit. This means I can transfer many more packets per second than most people on home connections so it is likely that you won’t have to go so high as 1000 to get the desired result in the Draytek settings.
I hope this helps someone out, feel free to get in touch with me if you have any questions.