<feed xmlns=http://www.w3.org/2005/Atom><generator uri=https://jekyllrb.com/ version>Jekyll</generator>
<link href=https://computer-curmudgeon.com rel=self type=application/atom+xml><link href=https://computer-curmudgeon.com/ rel=alternate type=text/html><updated>2022-09-10T21:00:11-07:00</updated>
<id>https://computer-curmudgeon.com/</id><title type=html>Stephen Savitzky</title><subtitle>Computer Curmudgeon for hire</subtitle>
<entry><title type=html>What Were You Thinking, Patreon?</title><link href=https://computer-curmudgeon.com/Blog/2022/09/10/what-were-you-thinking-patreon-/ rel=alternate type=text/html title="What Were You Thinking, Patreon?"><published>2022-09-10T00:00:00-07:00</published>
<updated>2022-09-10T00:00:00-07:00</updated>
<id>https://computer-curmudgeon.com/Blog/2022/09/10/what-were-you-thinking-patreon-/</id>
<content type=html xml:base=https://computer-curmudgeon.com/Blog/2022/09/10/what-were-you-thinking-patreon-/>&lt;p> So, a couple of days ago (September 8th, to be exact) Patreon &lt;a
 href="https://securityboulevard.com/2022/09/patreon-fires-security-team-richixbw/"
 >laid off their entire five-person security team&lt;/a>. WTF? The linked
 article goes on to say,

&lt;blockquote>
&lt;p> The firm, which is &lt;a
 href="https://blog.patreon.com/patreon-is-restricted-in-russia" >still
 doing business in Russia&lt;/a>, simply calls it “a strategic shift” (which
 seems to be corporate mumbo-jumbo for “cheaper outsourcing”). But infosec
 experts call it a “nightmare” caused by an “untrustworthy” company that’s
 “just put a massive target on its back.”
&lt;/blockquote>

&lt;p> You can see links to more articles below in the &lt;a href="#resources"
 >resources&lt;/a>.

&lt;p> The minimum reasonable response to this would be to change your password.
 Done that. It's not &lt;em>un&lt;/em>reasonable to delete your account. I'm
 still supporting a few sites, so I'll leave my account in place until I
 see what's going to happen. And laying in a supply of popcorn.

&lt;h3 id="resources">Resources&lt;/h3>
&lt;ul class="resource-list">
 &lt;li> @ &lt;a href="https://www.itpro.co.uk/security/cyber-security/369037/patreon-confirms-it-parted-ways-with-its-entire-cyber-security-team"
 >Patreon confirms it 'parted ways' with its 'entire' cyber security team | IT PRO&lt;/a>
 &lt;li> &lt;a href=https://techcrunch.com/2022/09/09/patreon-security-layoffs/
 >Patreon confirms security team layoffs | TechCrunch&lt;/a>
 &lt;li> &lt;a href="https://securityboulevard.com/2022/09/patreon-fires-security-team-richixbw/"
 >Patreon Fires its Security Team — and the Internet Freaks Out&lt;/a>
 &lt;li> &lt;a href="https://www.webpronews.com/patreon-just-let-its-entire-security-team-go/"
 >Patreon Just Let Its Entire Security Team Go [Updated]&lt;/a>
 &lt;li> &lt;a href="https://soatok.blog/2022/09/09/should-you-delete-your-patreon-account-after-they-laid-off-their-entire-security-team/"
 >Should You Delete Your Patreon Account After They Laid Off Their Entire Security
 Team? - Dhole Moments&lt;/a> -> excellent discussion of risks and alternatives
 -> changed password. Probably ought to delete account too, but I'm using it.
&lt;/ul></content>
<author><name></name></author><category term="curmudgeon, computers, security, "><summary type=html>So, a couple of days ago (September 8th, to be exact) Patreon &lt;a href="https://securityboulevard.com/2022/09/patreon-fires-security-team-richixbw/" >laid off their entire five-person security team. WTF? The linked article goes on to say,</summary></entry>
<entry><title type=html>Update Zoom on Mac ASAP</title><link href=https://computer-curmudgeon.com/Blog/2022/08/16/update-zoom-on-mac-asap/ rel=alternate type=text/html title="Update Zoom on Mac ASAP"><published>2022-08-16T00:00:00-07:00</published>
<updated>2022-08-16T00:00:00-07:00</updated>
<id>https://computer-curmudgeon.com/Blog/2022/08/16/update-zoom-on-mac-asap/</id>
<content type=html xml:base=https://computer-curmudgeon.com/Blog/2022/08/16/update-zoom-on-mac-asap/>&lt;p>&lt;p> According to &lt;a
 href="https://arstechnica.com/information-technology/2022/08/zoom-patches-mac-auto-updater-vulnerability-that-granted-root-access/=1"
 >this article posted yesterday on Ars Technica&lt;/a>, there is a major
 security hole in Zoom for the Mac. &lt;a
 href="https://explore.zoom.us/en/trust/security/security-bulletin/" >Zoom
 issued a security bulletin on Saturday&lt;/a>. The article suggests that you
 should &lt;a href="https://zoom.us/download#client_4meeting" >download the
 update directly from Zoom&lt;/a> or click on your menu bar options to &amp;ldquo;Check
 for updates&amp;rdquo; rather than waiting for the auto-update, although if you&amp;rsquo;ve
 already updated since Saturday you&amp;rsquo;re probably ok.&lt;/p>

&lt;p>&lt;p> The article goes into more detail; tl;dr is that Zoom&amp;rsquo;s installer is owned
 by and runs as root, and has a major bug that allows unsigned updates to
 be installed.&lt;/p>

&lt;p>&lt;h3 id="resources">Resources&lt;/h3>
&lt;ul class="resource-list">
 &lt;li> &lt;a href="https://zoom.us/download#client_4meeting" >Download Center - Zoom&lt;/a>
 &lt;li> &lt;a href="https://explore.zoom.us/en/trust/security/security-bulletin/"
 >Zoom security bulletin ZSB-22018 08/13/2022&lt;/a>
 &lt;li> &lt;a
 href="https://arstechnica.com/information-technology/2022/08/zoom-patches-mac-auto-updater-vulnerability-that-granted-root-access/"
 >Update Zoom for Mac now to avoid root-access vulnerability | Ars
 Technica&lt;/a>
&lt;/ul>&lt;/p></content>
<author><name></name></author><category term="curmudgeon, computers, security"><summary type=html>According to &lt;a href="https://arstechnica.com/information-technology/2022/08/zoom-patches-mac-auto-updater-vulnerability-that-granted-root-access/=1" >this article posted yesterday on Ars Technica, there is a major security hole in Zoom for the Mac. &lt;a href="https://explore.zoom.us/en/trust/security/security-bulletin/" >Zoom issued a security bulletin on Saturday. The article suggests that you should download the update directly from Zoom or click on your menu bar options to &amp;ldquo;Check for updates&amp;rdquo; rather than waiting for the auto-update, although if you&amp;rsquo;ve already updated since Saturday you&amp;rsquo;re probably ok.</summary></entry>
<entry><title type=html>Trojan Source</title><link href=https://computer-curmudgeon.com/Blog/2021/11/02/trojan-source/ rel=alternate type=text/html title="Trojan Source"><published>2021-11-02T00:00:00-07:00</published>
<updated>2021-11-02T00:00:00-07:00</updated>
<id>https://computer-curmudgeon.com/Blog/2021/11/02/trojan-source/</id>
<content type=html xml:base=https://computer-curmudgeon.com/Blog/2021/11/02/trojan-source/>&lt;p> &lt;a
 href="https://krebsonsecurity.com/2021/11/trojan-source-bug-threatens-the-security-of-all-code/"
 >This post in Krebs on Security&lt;/a> describes an unusual and potentially
 very dangerous attack technique that can be used to sneak evil code past
 code reviews and into the supply chain. Briefly, it allows evildoers to
 write code that looks very different to a human and a compiler. It should
 probably come as no surprise that it involves &lt;a
 href="https://home.unicode.org/" >Unicode&lt;/a>, the same coding standard
 that lets you make blog posts that include inline emoji, or mix text in
 English and Arabic.

&lt;p> In particular, it's the latter ability that the vulnerability targets,
 specifically Unicode's &lt;a
 href="https://www.w3.org/International/articles/inline-bidi-markup/uba-basics"
 >"Bidi" algorithm&lt;/a> for presenting a mix of left-to-right and
 right-to-left text. (Read the Bidi article for details and examples --
 I'm not going to try plopping random text in languages I don't know into
 the middle of a blog post.)

&lt;p> Now go read the "&lt;a href="https://www.trojansource.codes/" >Trojan Source
 Attacks&lt;/a>" website, and the associated &lt;a
 href="https://www.trojansource.codes/trojan-source.pdf" >paper [PDF]&lt;/a>
 and &lt;a href="https://github.com/nickboucher/trojan-source" >GitHub
 repo&lt;/a>. Observe, in particular, the &lt;a href=
 "https://github.blog/changelog/2021-10-31-warning-about-bidirectional-unicode-text/"
 >Warning about bidirectional Unicode text&lt;/a> that GitHub now attaches to
 files like &lt;a
 href="https://github.com/nickboucher/trojan-source/blob/main/C%2B%2B/commenting-out.cpp"
 >this one in C++&lt;/a>. Observe also that GitHub does &lt;em>not&lt;/em> flag
 files that, for example, mix &lt;a
 href="https://github.com/nickboucher/trojan-source/blob/main/C%2B%2B/homoglyph-function.cpp"
 >homoglyphs&lt;/a> like "H" (the usual ASCII version) and "Н" (the
 similar-looking Cyrillic letter that sounds like "N"; how similar it looks
 depends on what font your browser is using). If you're unlucky,
 you might have clicked on a URL containing one or more of these, that took
 you someplace unexpected and almost certainly malicious.

&lt;p> The Trojan Source attack works by making use of the control characters
 U+202B RIGHT-TO-LEFT EMBEDDING (RLE) and U+202A LEFT-TO-RIGHT EMBEDDING
 (LRE), which change the base direction explicitly.

&lt;p> And remember: ШYSINAШYG - What You See Is Not Always What You've Got!

&lt;h3 id="resources">Resources&lt;/h3>
&lt;ul class="resource-list">
 &lt;li> &lt;a href="https://www.trojansource.codes/" >Trojan Source Attacks&lt;/a>
 &lt;li> &lt;a
 href="https://www.trojansource.codes/trojan-source.pdf" >here [PDF]&lt;/a>
 &lt;pre>
 @article{boucher_trojansource_2021,
	title = {Trojan {Source}: {Invisible} {Vulnerabilities}},
	url = {https://trojansource.codes/trojan-source.pdf},
	journal = {Preprint.},
	author = {Nicholas Boucher and Ross Anderson},
	year = {2021}
 }
 &lt;/pre>
 &lt;/li>
 &lt;li> &lt;a href="https://krebsonsecurity.com/2021/11/trojan-source-bug-threatens-the-security-of-all-code/"
 >‘Trojan Source’ Bug Threatens the Security of All Code – Krebs on Security&lt;/a>
 &lt;/li>
 &lt;li> &lt;a href="https://github.com/nickboucher/trojan-source"
 >nickboucher/trojan-source: Trojan Source: Invisible Vulnerabilities&lt;/a>
 &lt;/li>
 &lt;li> &lt;a href=
 "https://github.blog/changelog/2021-10-31-warning-about-bidirectional-unicode-text/"
 >Warning about bidirectional Unicode text | GitHub Changelog&lt;/a>
 &lt;/li>
 &lt;li> &lt;a href="https://www.w3.org/International/articles/inline-bidi-markup/uba-basics"
 >Unicode Bidirectional Algorithm basics&lt;/a>
 &lt;/li>
 &lt;li> but... &lt;a href="https://research.swtch.com/trojan"
 >research!rsc: On “Trojan Source” Attacks&lt;/a>
 &lt;/li>
&lt;/ul></content>
<author><name></name></author><category term="curmudgeon, computers, "><summary type=html>&lt;a href="https://krebsonsecurity.com/2021/11/trojan-source-bug-threatens-the-security-of-all-code/" >This post in Krebs on Security describes an unusual and potentially very dangerous attack technique that can be used to sneak evil code past code reviews and into the supply chain. Briefly, it allows evildoers to write code that looks very different to a human and a compiler. It should probably come as no surprise that it involves &lt;a href="https://home.unicode.org/" >Unicode, the same coding standard that lets you make blog posts that include inline emoji, or mix text in English and Arabic.</summary></entry>
<entry><title type=html>What happened to facebook yesterday?</title><link href=https://computer-curmudgeon.com/Blog/2021/10/06/what-happened-to-facebook-yesterday-/ rel=alternate type=text/html title="What happened to facebook yesterday?"><published>2021-10-06T00:00:00-07:00</published>
<updated>2021-10-06T00:00:00-07:00</updated>
<id>https://computer-curmudgeon.com/Blog/2021/10/06/what-happened-to-facebook-yesterday-/</id>
<content type=html xml:base=https://computer-curmudgeon.com/Blog/2021/10/06/what-happened-to-facebook-yesterday-/>&lt;p> If you're sensible enough not to use Facebook, WhatsApp, or Instagram, or
 to have set up "log in with Facebook" on any site you use regularly, you
 might not have noticed that they all &lt;a
 href="https://blog.cloudflare.com/october-2021-facebook-outage/"
 >disappeared from the internet&lt;/a> for about six hours yesterday. Or if
 you noticed, you might not have cared. But you might have read some of
 the news about it, and wondered what the heck BGP and DNS are, and what
 they had to do with it all.

&lt;p> And if not, I'm going to tell you anyway.

&lt;p> You're more likely to have heard of DNS: that's the Internet's phone
 book. Your web browser, and every other program that connects to anything
 over the Internet, uses the &lt;a
 href="https://en.wikipedia.org/wiki/Domain_Name_System" >Domain Name
 System&lt;/a> to look up a "domain name" like, say,
 "&lt;code>www.facebook.com&lt;/code>", and find the numerical IP address that it
 refers to. &lt;a href="https://www.cloudflare.com/learning/dns/what-is-dns/"
 >DNS works&lt;/a> by splitting the name into parts, and looking them up in a
 series of "name servers". First it looks in a "&lt;a
 href="https://www.cloudflare.com/learning/dns/glossary/dns-root-server/"
 >root server&lt;/a>" to find the address of the &lt;a
 href="https://www.cloudflare.com/learning/dns/top-level-domain/"
 >Top-Level Domain (TLD)&lt;/a> server that holds the lookup table for the
 last part of the name, e.g., "&lt;code>com&lt;/code>". From the TLD server it
 gets the address of the "authoritative name server" that holds the lookup
 table for the next part of the name, e.g., &lt;code>facebook&lt;/code>, and
 looks there for any subdomains (e.g. "&lt;code>www&lt;/code>").

&lt;p> (When you buy a "domain name", what you're actually buying is a line in the
 TLD servers that points to the DNS server for your domain. You also have
 to get somebody to "host" that server; that's usually also the company
 that hosts your website, but it doesn't have to be.)

&lt;p> All this takes a while, so the network stack on your computer passes the
 whole process off to a "caching name server" which remembers every domain
 name it looks up, for a time which is called the name's "time to live"
 (TTL). Your ISP has a caching name server they would like you to use, but
 I'd recommend telling your router (if you have full control over it) to
 use Cloudflare's or Google's nameserver, at the IP address 1.1.1.1 or
 8.8.8.8 respectively. Your router will also keep track of the names of
 the computers attached to your local network.

&lt;p> Finally, we get to the &lt;a
 href="https://en.wikipedia.org/wiki/Border_Gateway_Protocol" >Border
 Gateway Protocol (BGP)&lt;/a>. If DNS is the phone book where you look up
 street addresses, BGP is the road map that tells your packets how to get
 there from your house, and in particular what route to take.

&lt;p> The Internet is a network of networks, and it's split up into "&lt;a
 href="https://www.cloudflare.com/learning/network-layer/what-is-an-autonomous-system/"
 >autonomous systems (AS)&lt;/a>, each of which is a large pool of routers
 belonging to a single organization. Each AS exchanges messages with its
 neighbors, using BGP to determine the "best" route between the itself and
 every other AS in the Internet. (The best route isn't always the
 shortest; the protocol can also take things like the cost of messages into
 account.) BGP isn't entirely automatic -- there's some manual
 configuration involved.

&lt;p> &lt;a href="https://blog.cloudflare.com/october-2021-facebook-outage/" >What
 happened yesterday&lt;/a> was that somebody at Facebook accidentally gave a
 command that resulted in all the routes leading to Facebook's data centers
 being withdrawn. In less than a minute Facebook's DNS servers noticed
 that their network was "unhealthy", and took themselves offline. At that
 point Facebook had basically shot themselves in the foot with a cannon.

&lt;p> Normally, engineers can fix server configuration problems like this by
 connecting to the servers over the internet. But Facebook's servers
 weren't connected to the internet anymore. To make matters worse, the
 computers that control access to Facebook's buildings -- offices as well
 as data centers -- weren't able to connect to the database that told them
 whose badges were valid.

&lt;p> Meanwhile, computers that wanted to look up Facebook or any of its other
 domains (like WhatsApp and Instagram), kept getting DNS failures. There
 isn't a good way for an app or a computer to determine whether a DNS
 lookup failure is temporary or permanent, so they keep re-trying,
 sometimes (as &lt;a
 href="https://blog.cloudflare.com/october-2021-facebook-outage/"
 >Cloudflare's blog post puts it&lt;/a>) "aggressively". Users don't usually
 take an error for an answer either, so they keep reloading pages,
 restarting their browsers, and so on. "Sometimes also aggressively."
 Traffic to Facebook's DNS servers increased to 30 times normal, and
 traffic to alternatives like Signal, Twitter, Telegram, and Tiktok
 nearly doubled.

&lt;p> Altogether a nice demonstration of Facebook's monopoly power, and great
 fun to read about if you weren't relying on it.

&lt;h3 id="resources">Resources&lt;/h3>
&lt;ul class="resource-list">
 &lt;li> &lt;a href="https://blog.cloudflare.com/october-2021-facebook-outage/"
 >Understanding How Facebook Disappeared from the Internet&lt;/a>
 &lt;/li>
 &lt;li> &lt;a href="https://engineering.fb.com/2021/10/04/networking-traffic/outage/"
 >Update about the October 4th outage - Facebook Engineering&lt;/a>
 &lt;/li>
 &lt;li> &lt;a href=
 "https://krebsonsecurity.com/2021/10/what-happened-to-facebook-instagram-whatsapp/"
 >What Happened to Facebook, Instagram, & WhatsApp? – Krebs on Security&lt;/a>
 &lt;/li>
 &lt;li> &lt;a href="https://engineering.fb.com/2021/10/05/networking-traffic/outage-details/"
 >More details about the October 4 outage - Facebook Engineering&lt;/a>
 &lt;/li>
 &lt;li> &lt;a href="https://blog.cdemi.io/beginners-guide-to-understanding-bgp/"
 >Beginner's Guide to Understanding BGP&lt;/a>
 &lt;/li>
 &lt;li> &lt;a href="https://www.cloudflare.com/learning/dns/what-is-dns/" >What is
 DNS? | How DNS works | Cloudflare&lt;/a> 
 &lt;/li>
&lt;/ul></content>
<author><name></name></author><category term="curmudgeon, computers, "><summary type=html>If you're sensible enough not to use Facebook, WhatsApp, or Instagram, or to have set up "log in with Facebook" on any site you use regularly, you might not have noticed that they all &lt;a href="https://blog.cloudflare.com/october-2021-facebook-outage/" >disappeared from the internet for about six hours yesterday. Or if you noticed, you might not have cared. But you might have read some of the news about it, and wondered what the heck BGP and DNS are, and what they had to do with it all.</summary></entry>
<entry><title type=html>Public Service Announcement: Recent leaks and other news</title><link href=https://computer-curmudgeon.com/Blog/2021/10/06/public-service-announcement-recent-leaks-and-other-news/ rel=alternate type=text/html title="Public Service Announcement: Recent leaks and other news"><published>2021-10-06T00:00:00-07:00</published>
<updated>2021-10-06T00:00:00-07:00</updated>
<id>https://computer-curmudgeon.com/Blog/2021/10/06/public-service-announcement-recent-leaks-and-other-news/</id>
<content type=html xml:base=https://computer-curmudgeon.com/Blog/2021/10/06/public-service-announcement-recent-leaks-and-other-news/>&lt;p> 1. &lt;a
 href="https://www.videogameschronicle.com/news/the-entirety-of-twitch-has-reportedly-been-leaked/"
 >The entirety of Twitch has reportedly been leaked&lt;/a>: source code, user
 payouts, hashed passwords. Change your password RIGHT NOW.

&lt;p> 2. &lt;a href="https://www.vice.com/en/article/z3xpm8/company-that-routes-billions-of-text-messages-quietly-says-it-was-hacked"
 >Company That Routes Billions of Text Messages Quietly Says It Was
 Hacked&lt;/a>;
 &lt;a href="https://blog.malwarebytes.com/malwarebytes-news/2021/10/criminals-were-inside-syniverse-for-5-years-before-anyone-noticed/"
 >Criminals were inside Syniverse for 5 years before anyone noticed - Malwarebytes&lt;/a>; &lt;a href="https://www.mobileworldlive.com/featured-content/top-three/syniverse-admits-to-repeated-data-breach"
 >Syniverse responds to data breach&lt;/a>. Good reason to switch to Signal,
 if you haven't already. Won't help with ordinary SMS text messages, though.
 Don't send secrets via SMS.

&lt;p> ... and in other news,

&lt;p> 3. &lt;a
 href="https://www.cbsnews.com/news/facebook-whistleblower-frances-haugen-misinformation-public-60-minutes-2021-10-03/"
 >Facebook whistleblower Frances Haugen details company's misleading
 efforts on 60 Min&lt;/a>. &lt;q>Facebook, over and over again, has shown it
 chooses profit over safety. It is subsidizing, it is paying for its
 profits with our safety.&lt;/q> But you knew that already, right?

&lt;p> 4. This morning I got an email from my mobile provider, AT&amp;amp;T, offering
 me a pair of free security apps collectively called &lt;a
 href=https://www.att.com/security/ >AT&T ActiveArmor&lt;/a> &lt;a
 href="https://www.att.com/security/security-apps/" >(details)&lt;/a>. I'd
 quote the email, but it was nothing but a pretty image. I went to the
 Google and Apple app stores and read the reviews. Apparently, it's just
 like all the other AT&amp;amp;T bloatware I've deleted over the years: flaky,
 a memory and bandwith hog, and not worth the price you pay for it. And
 when I can say that about something &lt;em>free&lt;/em>, well...

&lt;p> 5. ...and speaking of free, &lt;a href=
 "https://www.techrepublic.com/article/windows-11-drops-oct-5-mark-your-calendars/"
 >Windows 11 drops Oct. 5: Mark your calendars - TechRepublic&lt;/a>. That
 would be today. Also, &lt;a
 href=https://www.zdnet.com/article/windows-11-upgrade-five-questions-to-ask-first/
 >Windows 11 upgrade: Five questions to ask first | ZDNet&lt;/a>. Fortunately
 it won't run on &lt;em>any&lt;/em> of my machines, so I don't have to care.

&lt;p> P.S. In case you're trying to understand yesterday's Facebook
 et. al. outage, that's what I'll be writing about next.</content>
<author><name></name></author><category term="psa, curmudgeon"><summary type=html>1. &lt;a href="https://www.videogameschronicle.com/news/the-entirety-of-twitch-has-reportedly-been-leaked/" >The entirety of Twitch has reportedly been leaked: source code, user payouts, hashed passwords. Change your password RIGHT NOW.</summary></entry>
<entry><title type=html>Finding ELIZA</title><link href=https://computer-curmudgeon.com/Blog/2021/06/05/finding-eliza/ rel=alternate type=text/html title="Finding ELIZA"><published>2021-06-05T00:00:00-07:00</published>
<updated>2021-06-05T00:00:00-07:00</updated>
<id>https://computer-curmudgeon.com/Blog/2021/06/05/finding-eliza/</id>
<content type=html xml:base=https://computer-curmudgeon.com/Blog/2021/06/05/finding-eliza/>&lt;p>&lt;p> &lt;strong>Note:&lt;/strong> Despite being posted on a Saturday and a title that
 includes the name of a &lt;a
 href="https://en.wikipedia.org/wiki/Eliza_Doolittle" >a character&lt;/a> from
 &lt;a href="https://en.wikipedia.org/wiki/My_Fair_Lady" >a well-known
 musical&lt;/a>, this is &lt;em>not&lt;/em> a Songs for Saturday post. It doesn&amp;rsquo;t
 have anything to do with &lt;a
 href="https://en.wikipedia.org/wiki/Finding_Nemo" >fish&lt;/a>, either.&lt;/p>

&lt;p>&lt;p> Remarkably, &lt;em>Joseph Weizenbaum&amp;rsquo;s &lt;a
 href="https://drive.google.com/file/d/1DkdV2o-36mm3x2nURjhKiCaFcjZtMIoI/view"
 >original source code&lt;/a> for &lt;a
 href="https://en.wikipedia.org/wiki/ELIZA" >ELIZA&lt;/a> has been
 rediscovered,&lt;/em> after having been missing and believed lost for over
 half a century, and was &lt;a
 href="https://sites.google.com/view/elizagen-org/the-original-eliza" >made
 public&lt;/a> on May 23rd of this year. ELIZA is probably the oldest and
 almost certainly the best-known implementation of what is now known as a
 chatbot.&lt;/p>

&lt;p>&lt;p> If you decide to look at the code, start by reading &lt;a
 href="https://sites.google.com/view/elizagen-org/the-original-eliza" >the
 web page it&amp;rsquo;s embedded in&lt;/a> before you dive into the listing. The
 &amp;ldquo;Notes on reading the code&amp;rdquo; section, which comes &lt;em>after&lt;/em> the
 listing, will prevent a lot of confusion. &lt;a
 href="https://drive.google.com/file/d/1DkdV2o-36mm3x2nURjhKiCaFcjZtMIoI/view"
 >The listing itself&lt;/a> is a scan of a 132-column listing, and definitely
 benefits from being viewed full-screen on a large monitor.&lt;/p>

&lt;p>&lt;p> The first thing you see in the listing is the &lt;em>script&lt;/em> &amp;ndash; the set
 of rules that tells the ELIZA program how to respond to input. The
 program itself starts on page 6. You might be misled by the rules, which
 are in the form of parenthesized lists, into thinking that the program
 would be written in LISP. It&amp;rsquo;s not; it&amp;rsquo;s written in &lt;a
 href="https://en.wikipedia.org/wiki/MAD_programming_language" >MAD&lt;/a>, an
 Algol-like language, with Weisenbaum&amp;rsquo;s &lt;a
 href="https://en.wikipedia.org/wiki/SLIP_(programming_language)" >SLIP&lt;/a>
 (Symmetric List Processing) primitives embedded in it.&lt;/p>

&lt;p>&lt;p> SLIP uses circular, bidirectionally-linked lists. Each list has a header
 with pointers to the first and last list element; the header of an empty
 list points to itself. I&amp;rsquo;ve lost track of how many times I&amp;rsquo;ve implemented
 doubly-linked lists, in everything from assembly language to Java.&lt;/p>

&lt;p>&lt;p> ELIZA is the name of the &lt;em>program&lt;/em>, but &amp;ldquo;Eliza&amp;rdquo; usually refers to
 the combination of an Eliza-like program with the Doctor script. The most
 common script is a (rather poor) simulation of a &lt;a
 href="https://en.wikipedia.org/wiki/Person-centered_therapy" >Rogerian&lt;/a>
 psychotherapist called &amp;ldquo;Doctor&amp;rdquo;. According to the note at the bottom of
 the Original Eliza page, actual Rogerian therapists have pronounced it a
 perfect example of how &lt;em>not&lt;/em> to do Rogerian therapy. Nevertheless,
 many people are said to have been helped by ELIZA, and it&amp;rsquo;s possible to
 have a &lt;a
 href="https://computerhistory.org/blog/the-promise-of-the-doctor-program-early-ai-at-stanford/"
 >surprisingly intimate conversation&lt;/a> with her as long as you suspend
 your disbelief and respect her limits.&lt;/p>

&lt;p>&lt;p> If you have Emacs installed on your computer, you can access a &lt;a
 href="http://git.savannah.gnu.org/cgit/emacs.git/tree/lisp/play/doctor.el"
 >version of Doctor&lt;/a> with &lt;code>M-X doctor&lt;/code>. Otherwise, browse to
 &lt;a href="http://psych.fullerton.edu/mbirnbaum/psych101/Eliza.htm" >Eliza,
 Computer Therapist&lt;/a> if you don&amp;rsquo;t mind having a potentially intimate
 conversation with something hosted on a public website. (Or simply
 download the page &amp;ndash; it&amp;rsquo;s written in Javascript.)&lt;/p>

&lt;p>&lt;h3 id="resources">Resources&lt;/h3>
&lt;ul class="resource-list">
 &lt;li> &lt;a href="https://sites.google.com/view/elizagen-org/about"
 >ELIZAGEN &amp;ndash; The Genealogy of ELIZA&lt;/a> &amp;ldquo;This site is dedicated to
 tracing the legacy ofJoseph Weizenbaum&amp;rsquo;s ELIZA (aka. Doctor) program.&amp;rdquo;
 &lt;li> &lt;a href="https://sites.google.com/view/elizagen-org/the-original-eliza"
 >ELIZAGEN - The Original ELIZA&lt;/a> - the source code.
 &lt;li> &lt;a href="https://github.com/anthay/ELIZA" >anthay/ELIZA: A Simulation
 in C++ of Joseph Weizenbaum’s 1966 ELIZA&lt;/a> by Anthony Hay. The
 README includes both a copy of the transcript published in Wizenbaum&amp;rsquo;s
 CACM article in 1966, and a detailed description of the script syntax
 and how it works.
 &lt;li> &lt;a
 href="https://babel.hathitrust.org/cgi/pt?id=mdp.39015021689271&view=1up&seq=7"
 >MAD (Michigan Algorithm Decoder) manual&lt;/a> by Elliott Organick
 (1961).
 &lt;li> &lt;a href="https://www.gnu.org/software/gslip/manual/" >GNU gSlip&lt;/a> [&lt;a
 href="https://www.gnu.org/software/gslip/manual/UserManual.pdf" >PDF
 Manual(738K)&lt;/a>] for C++.
 &lt;li> &lt;a
 href="http://git.savannah.gnu.org/cgit/emacs.git/tree/lisp/play/doctor.el"
 >doctor.el\play\lisp - emacs.git - Emacs source repository&lt;/a> - the
 Doctor program as implemented in Emacs LISP.
 &lt;li> &lt;a href="http://psych.fullerton.edu/mbirnbaum/psych101/Eliza.htm" >Eliza,
 Computer Therapist&lt;/a> in Javascript
&lt;/ul>&lt;/p></content>
<author><name></name></author><category term="curmudgeon, computers, history, ai, list-processing"><summary type=html>Note: Despite being posted on a Saturday and a title that includes the name of a &lt;a href="https://en.wikipedia.org/wiki/Eliza_Doolittle" >a character from a well-known musical, this is not a Songs for Saturday post. It doesn&amp;rsquo;t have anything to do with &lt;a href="https://en.wikipedia.org/wiki/Finding_Nemo" >fish, either.</summary></entry>
<entry><title type=html>RIP Fry’s Electronics – the end of an era</title><link href=https://computer-curmudgeon.com/Blog/2021/02/24/rip-fry-s-electronics-the-end-of-an-era/ rel=alternate type=text/html title="RIP Fry's Electronics -- the end of an era"><published>2021-02-24T00:00:00-08:00</published>
<updated>2021-02-24T00:00:00-08:00</updated>
<id>https://computer-curmudgeon.com/Blog/2021/02/24/rip-fry-s-electronics-the-end-of-an-era/</id>
<content type=html xml:base=https://computer-curmudgeon.com/Blog/2021/02/24/rip-fry-s-electronics-the-end-of-an-era/>&lt;p> Today I was shocked to read that &lt;a
 href="https://en.wikipedia.org/wiki/Fry's_Electronics" >Fry's
 Electronics&lt;/a> &lt;a href=
 "https://apnews.com/article/frys-electronics-closing-9cf141bb1996899d5bd931109eb34f34"
 >has gone out of business&lt;/a>, as of midnight last night (February 24th).
 Their &lt;a href="https://www.frys.com/" >web page&lt;/a> has the announcement:

&lt;blockquote>
&lt;p> After nearly 36 years in business as the one-stop-shop and online resource
 for high-tech professionals across nine states and 31 stores, Fry’s
 Electronics, Inc. (“Fry’s” or “Company”), has made the difficult decision
 to shut down its operations and close its business permanently as a result
 of changes in the retail industry and the challenges posed by the Covid-19
 pandemic. The Company will implement the shut down through an orderly wind
 down process that it believes will be in the best interests of the
 Company, its creditors, and other stakeholders. 
&lt;/blockquote>

&lt;p> It's a sad, sad day. Their first ad, a full page in the &lt;a
 href="https://www.mercurynews.com/" >San Jose Mercury-News&lt;/a>, was like
 nothing seen before (or since), listing computer chips and potato chips on
 the same page. (Its relationship to &lt;a
 href="https://en.wikipedia.org/wiki/Fry%27s_Food_and_Drug" >Fry's Food and
 Drug&lt;/a>, which had recently been sold by the founders' father, was
 obvious.) As time went by the groceries largely disappeared, but soft
 drinks and munchies remained, and some of the larger stores included a
 cafe&amp;eacute;.

&lt;p> I (snail) mailed a copy of that first ad to my father, and that first
 Sunnyvale store was one of the tourist attractions we visited on his next
 visit to the West Coast. I have no idea how much money I spent there over
 the years.

&lt;p> After I moved to Washington in 2012 my visits to Fry's became much less
 frequent, and more of my electronics started coming from Amazon. It's
 been years since I saw the inside of a Fry's store.

&lt;p> I'll miss it.</content>
<author><name></name></author><category term="curmudgeon, computers, rip, memoir, 2021"><summary type=html>Today I was shocked to read that &lt;a href="https://en.wikipedia.org/wiki/Fry's_Electronics" >Fry's Electronics &lt;a href= "https://apnews.com/article/frys-electronics-closing-9cf141bb1996899d5bd931109eb34f34" >has gone out of business, as of midnight last night (February 24th). Their web page has the announcement:</summary></entry>
<entry><title type=html>Dependency Confusion</title><link href=https://computer-curmudgeon.com/Blog/2021/02/16/dependency-confusion/ rel=alternate type=text/html title="Dependency Confusion"><published>2021-02-16T00:00:00-08:00</published>
<updated>2021-02-16T00:00:00-08:00</updated>
<id>https://computer-curmudgeon.com/Blog/2021/02/16/dependency-confusion/</id>
<content type=html xml:base=https://computer-curmudgeon.com/Blog/2021/02/16/dependency-confusion/>&lt;p> I've always been a little uncomfortable about build systems and languages
 that start the build by going out to a package repository and pulling down
 the most recent (minor or patch) version of every one of the package's
 dependencies. Followed by all of &lt;em>their&lt;/em> dependencies. The
 best-known of these are probably Python's &lt;code>pip&lt;/code> package
 manager, Javascript's &lt;code>npm&lt;/code> (node package manager), and Ruby's
 &lt;code>gems&lt;/code>. They're quite impressive to watch, as they fetch
 package after package from their repository and include it in the program
 or web page being built. What could possibly go wrong?

&lt;p> Plenty, as it turns out.

&lt;p> The best-known technique for taking advantage of a package manager is &lt;a
 href="https://incolumitas.com/2016/06/08/typosquatting-package-managers/"
 >typosquatting&lt;/a> -- picking a name for a malware package that's a
 plausible misspelling of a real one, and waiting for someone to make a
 typo. (It's an adaptation of the same technique from DNS - picking a
 domain name close to that of some popular site in hopes of siphoning off
 some of the legitimate site's traffic. These days it's common for
 companies to typosquat their own domains before somebody else does --
 &lt;code>facbook.com&lt;/code> redirects to FB, for example.)

&lt;p> A few days ago, Alex Birsan published "&lt;a
 href="https://medium.com/@alex.birsan/dependency-confusion-4a5d60fec610"
 >Dependency Confusion: How I Hacked Into Apple, Microsoft and Dozens of
 Other Companies&lt;/a>", describing a new attack that relies on the way
 package managers like &lt;code>npm&lt;/code> resolve dependencies, by looking
 for and fetching the most recent compatible version (i.e. with the same
 major version) of every package, and the fact that they can be made to
 look in more than one repository.

&lt;p> Fetching the most recent minor version of a package is usually perfectly
 safe; packages have owners, and only the owner can upload a new version to
 the repository. (There have been a few cases where somebody has gotten
 tired of maintaining a popular package, and transferred ownership to
 someone who turned out to be, shall we say, less than reliable.)

&lt;p> The problem comes if, like most large companies and many small ones, you
 have a private repository that some of your packages come from. The
 package manager looks in both places, public and private, for the most
 recent version. If an attacker somehow gets the name and version number
 of a private package that doesn't exist in the public repository, they can
 upload a bogus package with the same name and a later version.

&lt;p> It turns out that the names and versions of private packages can be
 leaked in a wide variety of ways. The simplest turns out to be looking in
 your target's web apps -- apparently it's not uncommon to find a copy of a
 `package.json` left in the app's JavaScript by the build process. Birsan
 goes into detail on this and other sources of information.

&lt;p> Microsoft has published &lt;a
 href="https://azure.microsoft.com/en-us/resources/3-ways-to-mitigate-risk-using-private-package-feeds/"
 >3 Ways to Mitigate Risk When Using Private Package Feeds&lt;/a>, so that's a
 good place to look if you have this problem and want to fix it. (Hint:
 you &lt;em>really&lt;/em> want to fix it.) Tl;dr: by far the simplest fix is to
 have one private repo that includes both your private packages,
 &lt;em>and&lt;/em> all of the public packages your software depends on. Point
 your package manager at &lt;em>that&lt;/em>. Updating the repo to get the most
 recent public versions is left as an exercise for the reader; if I was
 doing it I'd just make a set of dummy package that depend on them.

&lt;p> Happy hacking!

&lt;h3 id="resources">Resources&lt;/h3>
&lt;ul class="resource-list">
 &lt;li> &lt;a href="https://medium.com/@alex.birsan/dependency-confusion-4a5d60fec610"
 >Dependency Confusion: How I Hacked Into Apple, Microsoft and Dozens of Other
 Companies | by Alex Birsan | Feb, 2021 | Medium&lt;/a>
 &lt;li> &lt;a href="https://www.bleepingcomputer.com/news/security/researcher-hacks-over-35-tech-firms-in-novel-supply-chain-attack/"
 >Researcher hacks over 35 tech firms in novel supply chain attack&lt;/a> 
 &lt;li> &lt;a href="https://azure.microsoft.com/en-us/resources/3-ways-to-mitigate-risk-using-private-package-feeds/"
 >3 Ways to Mitigate Risk When Using Private Package Feeds&lt;/a>
 &lt;li> &lt;a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-24105"
 >CVE-2021-24105 - Security Update Guide - Microsoft - Package Managers Configurations
 Remote Code Execution Vulnerability&lt;/a> 
 &lt;li> &lt;a
 href="https://incolumitas.com/2016/06/08/typosquatting-package-managers/"
 >incolumitas.com – Typosquatting programming language package
 managers&lt;/a>
 &lt;li> &lt;a href="https://semver.org/" >Semantic Versioning 2.0.0&lt;/a> 
&lt;/ul></content>
<author><name></name></author><category term="curmudgeon, computers, attacks, supply-chain, packages"><summary type=html>I've always been a little uncomfortable about build systems and languages that start the build by going out to a package repository and pulling down the most recent (minor or patch) version of every one of the package's dependencies. Followed by all of their dependencies. The best-known of these are probably Python's pip package manager, Javascript's npm (node package manager), and Ruby's gems. They're quite impressive to watch, as they fetch package after package from their repository and include it in the program or web page being built. What could possibly go wrong?</summary></entry>
<entry><title type=html>Curmudgeon Thinks Out Loud</title><link href=https://computer-curmudgeon.com/Blog/2020/09/05/curmudgeon-thinks-out-loud/ rel=alternate type=text/html title="Curmudgeon Thinks Out Loud"><published>2020-09-05T00:00:00-07:00</published>
<updated>2020-09-05T00:00:00-07:00</updated>
<id>https://computer-curmudgeon.com/Blog/2020/09/05/curmudgeon-thinks-out-loud/</id>
<content type=html xml:base=https://computer-curmudgeon.com/Blog/2020/09/05/curmudgeon-thinks-out-loud/>&lt;p> ...about disk partitioning. &lt;em>Content warning: rather specialized
 geekness. If that's not something you're into, you might want to &lt;a
 href="#skip">skip&lt;/a> this.&lt;/em>&lt;br>



&lt;p> If you've been reading my posts for a while, especially if you've been
 reading them on &lt;a href="https://mdlbear.dreamwidth.org/" >Dreamwidth&lt;/a>,
 you may have noticed a tendency to over-think things. And if you read &lt;a
 href="https://mdlbear.dreamwidth.org/1734398.html" >this Curmudgeon
 post&lt;/a>, you can probably guess what I'm over-thinking about. Or at
 least one of the things -- my previous post, about keyboards, was the
 other.

&lt;p> Last Sunday the SSD in Sable, my main laptop, became corrupted, and after
 waffling for a while about what to replace it with I ordered a new one --
 a bigger one, of course. The old one was/is 500GB; the new one is twice
 that. That raises two obvious questions: how to partition the new drive,
 and what to do with the old one. I'm planning to tackle that second
 question after it has actually &lt;em>become&lt;/em> the old drive.

&lt;p> Most of my current overthinking is about partitioning the new drive.
 There doesn't seem to be much point in putting Windows on it (see below;
 the old drive has/had a Windows partition that I haven't used since I got
 it), so the real questions are: how many different Linux distros do I want
 to install, and how should I organize the disk to support that?

&lt;p> Installing and playing with Linux distros is enormous fun, and a
 tremendous time-sink. The most sensible thing would be to just install
 Ubuntu, which I'm already using, on my main machine, and play around on a
 machine I don't use daily, perhaps finally settling on some other distro
 that I prefer, and switching to it.

&lt;p> Anyone who expects me to be sensible about this doesn't know me very
 well.

&lt;p> The distros I'm most interested in investigating are Mint with the MATE
 desktop, which is based on Gnome-2, and Ubuntu Studio, which has the
 low-latency kernel and defaults to a multimedia production environment.
 My current desktop is Gnome Flashback on Ubuntu, which isn't as close to
 Gnome-2 as I'd really like, and I'm still using Ubuntu 18.04, which has
 gotten a little long in the tooth by now.

&lt;p> So the minimum set of distros to install are Mint and Ubuntu Studio.
 Ubuntu Studio is just Ubuntu with a different set of defaults; mainly the
 low-latency kernel, so I don't have to bother with installing regular
 Ubuntu. Linux Mint comes in two flavors -- LMDE (Linux Mint Debian
 Edition), and Mint 20, which is based on Ubuntu 20.04. Modulo hardware
 support I think I'd lean toward LMDE; there are also some indications that
 Mint 20 identifies itself as Ubuntu to the EFI bootloader, which could be
 a problem. I'll make four distro-root partitions, because I might need to
 drop back to Ubuntu 18.04 if something goes really wonky (like support for
 XMonad), and in any case I want to have some room to experiment.

&lt;p> I see that the root partition of my current install on Raven is using 14G
 out of a 20G partition, so I'm thinking somewhere between 25 and 32 would
 be a good size; I'll go with the high end because I can. That means 128
 GB for roots. Eventually I expect to settle on Mint for most things plus
 Studio for audio, but you never know...

&lt;p> At first I wasn't sure that a GPT partition table (that's an unnecessary
 redundancy, of course) would be a good idea; I've had a lot of trouble
 with that in the past. But the idea of
 having an actual boot manager (with a better UI than Grub) is attractive,
 as is the idea of &lt;em>not&lt;/em> having the stupid distinction between
 primary and logical partitions. And "&lt;a
 href="https://medium.com/@manujarvinen/setting-up-a-multi-boot-of-5-linux-distributions-ca1fcf8d502"
 >Setting up a multi-boot of 5 Linux distributions | by Manu Järvinen&lt;/a>"
 looks pretty straightforward. It's definitely worth a try. I can always
 nuke it and start over if I get into serious trouble, though I don't think
 I will.

&lt;p> The remaining question is what to do with the left-over 800+ GB of space,
 and that's one I actually have a good answer to. I need to have a home
 directory on each distro, because they'll all have mostly-incompatible
 config files. So the big partition is where all of the state that I
 &lt;em>can&lt;/em> share will live. It will have a symlink or bind mount on
 each of the separate homes, and many of the config files and others will
 live in it. That goes for Documents, Downloads, etc. as well.

&lt;p> The traditional name for that partition is &lt;code>vv&lt;/code>, and I have no
 reason to change it. The name comes from bygone days when I split up a
 brand-new, &lt;em>enormous&lt;/em> 120(?) GB drive into partitions called
 &lt;code>uu&lt;/code>, &lt;code>vv&lt;/code>, &lt;code>ww&lt;/code>, &lt;code>xx&lt;/code>,
 &lt;code>yy&lt;/code> and &lt;code>zz&lt;/code>. They were originally mirrors for
 partitions called &lt;code>uu&lt;/code>, &lt;code>v&lt;/code>, &lt;code>w&lt;/code>,
 &lt;code>x&lt;/code>, &lt;code>y&lt;/code> and &lt;code>z&lt;/code>; when the first drive
 crashed, as they do, ...

&lt;p> I used to put &lt;code>/usr&lt;/code> on &lt;code>u&lt;/code>, and &lt;code>/var&lt;/code>
 on &lt;code>v&lt;/code>, using the rest for the roots of various distros. So
 &lt;code>v&lt;/code> was always the biggest one, at least on the server. Most
 of the lettered partitions became unnecessary once I stopped playing
 around with multiple distros quite as much, and &lt;code>vv&lt;/code>, mounted
 via NFS from the file server, remained as the place where websites,
 writing, and other projects ended up. My current server, Nova, has both
 &lt;code>vv&lt;/code> and &lt;code>home&lt;/code> in separate partitions and
 &lt;code>~/vv&lt;/code> is a symlink. Everywhere else, including my web host,
 it's a real directory tree under my home directory.

&lt;blockquote> (aside) Have I written about how I organize things under
 &lt;code>~/vv/*&lt;/code>? (Grep, grep, grep.) No, apparently not. (/me adds a
 to-do item.) But I &lt;em>have&lt;/em> written about the origin of this
 partitioning scheme, in &lt;a
 href="https://steve.savitzky.net/Doc/Linux/multiple-distros.html" >Playing
 with Multiple Distros&lt;/a> 2003/6/9. First of a series called &lt;a
 href="https://steve.savitzky.net/Doc/Linux/how-i-work.html" >How I
 Work&lt;/a>, which I seem to have abandoned back in 2006. Oops!
&lt;/blockquote>

&lt;p> Each distro will have its own set of home directories; that keeps any
 distribution-specific configuration files from getting clobbered. Any
 config files that &lt;em>aren't&lt;/em> distro-specific will be symlinks into
 &lt;code>vv&lt;/code>; mostly &lt;code>vv/prj/&lt;a
 href="https://gitlab.com/ssavitzky/Honu" >Honu&lt;/a>&lt;/code>, which is my
 generic configuration and setup repository, or
 &lt;code>vv/prj/Mathilda&lt;/code>, which is its machine-specific counterpart.
 Downloads, Documents, etc. will also be symlinks into &lt;code>vv&lt;/code>, so
 that they're all accessible from every distro. Home directories get
 backed up into &lt;code>vv/backups&lt;/code> on the fileserver; because almost
 everything is symlinked, they tend to be quite small.

&lt;p> I think, in a nod to tradition, I'm going to label the various root
 partitions &lt;code>ww&lt;/code>, &lt;code>xx&lt;/code>, &lt;code>yy&lt;/code> and
 &lt;code>zz&lt;/code>. And I'll probably make a small partition for boot or
 swap if anything needs it, otherwise it may end up with a lightweight
 distro on it... So should I call that &lt;code>uu&lt;/code>?...



&lt;p> &lt;a name="skip">&amp;nbsp;&lt;/a> &lt;!-- skip target; here so as not to get cut off -->
 &lt;!-- by exporters that delete the colophon -->
 Dreamwidth makes an excellent rubber duck -- thanks for listening.</content>
<author><name></name></author><category term="curmudgeon, computers, planning, partitioning"><summary type=html>...about disk partitioning. Content warning: rather specialized geekness. If that's not something you're into, you might want to &lt;a href="#skip">skip this.</summary></entry>
<entry><title type=html>The Curmudgeon Contemplates Keyboards</title><link href=https://computer-curmudgeon.com/Blog/2020/09/02/the-curmudgeon-contemplates-keyboards/ rel=alternate type=text/html title="The Curmudgeon Contemplates Keyboards"><published>2020-09-02T00:00:00-07:00</published>
<updated>2020-09-02T00:00:00-07:00</updated>
<id>https://computer-curmudgeon.com/Blog/2020/09/02/the-curmudgeon-contemplates-keyboards/</id>
<content type=html xml:base=https://computer-curmudgeon.com/Blog/2020/09/02/the-curmudgeon-contemplates-keyboards/>&lt;p> For the last week or two my external keyboard has been flaking out --
 dropping keystrokes, and occasionally barfing out a string of repeats.
 The cats, of course, know nothing about this. Or will admit to nothing,
 in any case. So yesterday, after determining that a blast of canned
 difluoroethane wasn't going to fix it, I finally started to think
 seriously about replacing it.

&lt;p> The keyboard has only a limited set of plausible replacements, because
 there are only two types of external keyboard that I can stand: the &lt;a
 href="https://en.wikipedia.org/wiki/Model_M_keyboard" >Model M&lt;/a> and the
 &lt;a
 href="https://www.lenovo.com/us/en/accessories-and-monitors/keyboards-and-mice/keyboards/KBD-BO-TrackPoint-KBD-US-English/p/4Y40X49493"
 >ThinkPad TrackPoint Keyboard&lt;/a>. The Model M and the oldest of the
 Thinkpad keyboards (the marvelous SK-8845 Ultranav) can be dismissed out
 of hand because they lack a logo key, which I've gotten used to using as
 &lt;a href="https://mdlbear.dreamwidth.org/1573035.html" >Xmonad's Mod
 key&lt;/a>. Most Model Ms lack a trackpoint, although I have one that has it
 -- and two PS-2 connectors on the cable. Besices, I'm not positive that I
 can &lt;em>find&lt;/em> my Model M at this point, and it takes up a lot of desk
 space that I don't have anymore.

&lt;p> The second generation of Thinkpad keyboards -- the SK-8855 -- have a logo
 key, and an attached USB cable that stows into a recess on the back, but
 have the page-up and page-down keys on the right-hand edge, in what has
 become, for me, the wrong place. That makes them just enough different
 from the keyboards on the newer Thinkpads that it's annoying. I have one
 that I'd consider using anyway, but it's broken; my second one is out on
 loan.

&lt;p> (You might well ask why, since both of the laptops I'm using -- Sable and
 Raven -- are Thinkpads with the right keyboard, I would be looking at
 external keyboards. I blame the cats. If I have an external keyboard and
 an external monitor on my desk, I can close the lid and let Desti sit on
 it. Come to think of it, that may be why I need a replacement keyboard in
 the first place.)

&lt;p> There are three Thinkpad keyboards with the new layout -- the &lt;a href=
 "https://smile.amazon.com/Lenovo-ThinkPad-Compact-Keyboard-TrackPoint/dp/B00F3U4TQS"
 >KU-1255&lt;/a>, which is what I'm looking to replace, the &lt;a
 href="https://support.lenovo.com/us/en/solutions/pd026744" >Bluetooth
 version,&lt;/a> and the shiny new &lt;a
 href="https://www.lenovo.com/us/en/accessories-and-monitors/keyboards-and-mice/keyboards/KBD-BO-TrackPoint-KBD-US-English/p/4Y40X49493"
 >ThinkPad TrackPoint Keyboard II&lt;/a>. The Bluetooth version has gotten
 poor reviews -- apparently it tends to be laggy -- and in any case one of
 the laptops it needs to go with doesn't have Bluetooth. (I know --
 dongles. I'm also running out of USB ports.) The Keyboard II has
 &lt;em>both&lt;/em> Bluetooth and a wireless USB dongle. (It would, of course,
 be ideal if it were compatible with Logitech's, but of course it wouldn't
 be.)

&lt;p> I was just about to order one when I saw this line on Lenovo's website:

&lt;blockquote>
 Ships in more than 5 weeks.
&lt;/blockquote>

&lt;p> So it looks as though I get to spend $60 on a KU-1255 to use while I'm
 waiting. Or instead. Or maybe an SK-8855, because they have an attached USB cable
 instead of requiring a (fragile) micro-USB, except that those appear to be
 made of unobtainium today. And I can get the KU-1255 from Amazon and have it
 delivered tomorrow.

&lt;p> Just for the record, here's what I like (and some reviewers detest, of
 course) about the newer Thinkpad keyboards:
&lt;ul>
 &lt;li> Page-up and page-down keys. (Many -- perhaps most -- newer compact
 keyboards require using the function key on the up and down arrows,
 which makes it hard to hit one-handed. Because cat.)
 &lt;li> The cursor keys are all in one place on the lower right: the arrows in
 an inverted-T arrangement, with the page-up and page-down on either
 side of the up-arrow in what practically &lt;em>every other keyboard&lt;/em>
 leaves as empty space. Huh?
 &lt;li> Trackpoint -- the little red pointing stick between the G, H, and B
 keys. I don't always use it, but it's there when I need it. And you
 can scroll with it.
 &lt;li> Along with the trackpoint, there are &lt;em>three&lt;/em> buttons directly
 under the space bar. The middle one is what you hold down to scroll
 with the trackpoint; on Linux it's also "paste selection" in most
 places, and "download" in browsers.
 &lt;li> The classic Thinkpad key-feel. A lot like a Model M clicky-key only
 &lt;em>silent&lt;/em>. Less travel than the mechanical keys on the Model M,
 but I've come to prefer that.
&lt;/ul>

&lt;p> I'm still waffling over the II. It's hard to justify, now that I have a
 1255 on order. But not impossible. Meanwhile I'll just sit here
 listening to &lt;a href="https://www.youtube.com/watch?v=jinGW7ZDGPM" >The
 Typewriter (a concerto for orchestra and solo typewriter) by Leroy
 Anderson)&lt;/a>. (There's a version that includes a repeat performance
 using an IBM Selectric, but I can't seem to find it now. It would have
 been perfect for this post.)</content>
<author><name></name></author><category term=curmudgeon><category term=computers><category term=keyboards><summary type=html>For the last week or two my external keyboard has been flaking out -- dropping keystrokes, and occasionally barfing out a string of repeats. The cats, of course, know nothing about this. Or will admit to nothing, in any case. So yesterday, after determining that a blast of canned difluoroethane wasn't going to fix it, I finally started to think seriously about replacing it.</summary></entry></feed>