Shared posts

09 Jan 18:56

Vancouver Views, Entitled Homeowners and the Trees that Got in the Way

by Sandy James Planner

prune-walnut

prune-walnut

There is now a three part trilogy in Vancouver where a valued public resource~public trees~have been hacked or poisoned on public lands. Two of the previous public tree mutilations were performed to improve private views. You may have read the latest in the Vancouver Sun where after the December windstorm Park Board staff discovered  at Spanish Banks near Tolmie Street a group of conifer trees had been delimbed and their tops sawed off.

And it wasn’t someone looking for a quick fix to grabbing a Christmas tree, as the  tops and limbs were found in the park. How could someone have done this without anyone seeing? And why has this happened? Howard Norman of the Parks Board minced no words saying “In my experience, this is strictly view-related. That’s the only rational reason I can think of.

The trees were partially sawed through and were then broken in windstorms. The trees will continue to develop, but their  canopies will be significantly altered, suggesting  the involvement of a  nearby view property owner that may not know the wrath of Vancouverites when public trees are sullied. The Park Board is working with the Vancouver Police to ascertain who the culprit is, but finger-pointing is already focused upon the exclusive hilly view properties across from the beach.

There have been two other outrageous tree desecrations on public land. In 1997  29 maple trees and five cherry trees on ocean view property owned by Metro Vancouver were sawed down near the University Endowment Land  view home of Jacqueline Cohen. It turned out that despite denying it, Ms. Cohen had indeed hired someone to cut the trees down, and forgot to pay that person, who told his story. A settlement of $50,000 was reached with Metro Vancouver as well as an apology given.

There was also the case of interior designer June Matheson who lived at 2015 Beach Avenue on English Bay. Five large public trees on city land in front of her second floor beach facing condo had been drilled into and poison sourced from the United States injected. Called the “Tree Assassin” at the time, Ms. Matheson avoided jail time but did have to pay $50,000 to have trees replanted at this location and also in Stanley Park. Ms. Matheson’s lawyer said she  had to sell her view condo after being charged  because  “people were throwing rocks, eggs and even bags they used to clean up after their dogs at her apartment balcony. My 70-something client is now the object, truly, of feces and abuse.”

As the judge in the Matheson case observed “The resulting attention and harassment forced her to sell the two things she loved most, her apartment and her business. Ms. Matheson has demonstrated genuine contrition for her involvement.”

That is why the altering of the public trees at Spanish Banks is so alarming. It is not only the replacement of trees which may have some difficulty growing in those sandy soils, but also the misunderstanding of how close Vancouverites hold the value of the public realm and of trees in parks. Whoever cut those trees misjudged the importance of public trees to Vancouverites. As Ms. Matheson told the judge in her tree poisoning court case “”I had to sell my home that I love because of endless harassment. I now have a home with no view. My health has been affected and I’ve had death threats made against me.”

cnewsfototree-vandal

cnewsfototree-vandalImage: Bigwnews.com
09 Jan 18:56

Border wall progress chart

by Nathan Yau

Denise Lu for The New York Times provides a quick overview of the proposed border wall and its progress. Scroll for zeros.

Tags: New York Times, wall

09 Jan 18:56

Firefox 65 Beta 10 Testday, January 11th

by Bogdan Maris

Hello Mozillians,

We are happy to let you know that Friday, January 11th, we are organizing Firefox 65 Beta 10 Testday. We’ll be focusing our testing on:  Firefox Monitor, Content Blocking and Find Toolbar. 

Check out the detailed instructions via this etherpad.

No previous testing experience is required, so feel free to join us on #qa IRC channel where our moderators will offer you guidance and answer your questions.

Join us and help us make Firefox better!

See you on Friday!

09 Jan 18:56

En guise de vœux 2019

by Tristan

Portrait de Tristan Nitot avec son vélo de nuit

Nous sommes le 7 janvier et je n’ai toujours pas souhaité la bonne année à mes lecteurs… Il est temps que je m’y mette ! Plutôt que vous lister les bonnes résolutions pour 2019, je voudrais vous parler de celles déjà mises en place en 2018…

Comme vous le savez peut-être, après plusieurs années à parler du climat avec une régularité très variable, j’ai décidé de passer à l’action. On peut remercier au passage Nicolas Hulot qui, par sa démission, a su me motiver, combiné au dernier rapport du GIEC.

En 2018 :

  • J’ai changé mes habitudes alimentaires :
    • j’ai limité au maximum ma consommation de boeuf ;
    • Je mange végétarien presque tous les midis : j’ai trouvé un traiteur italien qui fait des salades (base pate ou salade suivant la saison) avec des ingrédients au choix.
  • Je limite au maximum l’utilisation de plastique jetable :
    • J’utilise une gourde à la place des verres en plastique et des bouteilles en plastique ;
    • je ne prendre plus de boissons à emporter le midi ;
    • Je limite au maximum les déjeuners à emporter et je mange sur place, ça limite l’utilisation de récipients et couverts jetables ;
  • J’ai pris des décisions en ce qui concerne mes transports :
    • J’ai décidé de ne plus prendre l’avion pour partir en vacances en 2019[1] ;
    • Je prends le train autant que possible pour le boulot (Nice et Toulouse : aussi jolies que vous soyez, vous m’êtes pénibles à privilégier l’avion !)
    • Je n’utilise quasiment jamais de véhicules thermiques (moto, voiture) pour aller au boulot, sauf cas de force majeur ;
    • Je suis devenu un fier vélotafeur[2].
    • Je pratique toujours l’éco-conduite, ça limite grandement ma consommation d’essence ;
    • Coté moto, j’ai ressenti un fort désintérêt pour la moto, jusqu’alors passion dévorante. J’ai revendu ma Harley au printemps. Je traine toujours les stigmates de ma collectionnite et j’ai donc toujours quelques vieilles bécanes au garage, mais la plus grosse est un modeste 650cc qui a 14 ans, et c’est aussi bien comme ça.
  • J’ai décidé de me documenter (ça se voit dans mes billets En Vrac) pour mieux comprendre le changement climatique, les moyens d’action, etc. et pouvoir en parler autour de moi :
    • J’ai changé les comptes Twitter que je suis : plus de vélotafeurs, moins d’emmerdeurs et moins de gens qui abordent les sujets qui me lassent[3] ;
    • J’écoute plus de podcasts sur l’environnement ;
    • J’achète et je lis plus de livres sur le changement climatique.
    • J’ai arrêté d’acheter des magazines de moto. À la place ce sont des magazines de vélo !

Pour 2019, je vais continuer dans cette direction. Et vous ? Vous avez des choses que vous comptez mettre en place ou que vous me suggérez ?

Notes

[1] Pour le boulot, ça va être beaucoup plus compliqué :-/

[2] Personne allant au travail à vélo.

[3] Si je ne vous suis plus, ne le prenez pas personnellement, vous faites sûrement partie de la 2eme catégorie ;-)

09 Jan 18:56

Printing a Fountain Pen

by peter@rukavina.net (Peter Rukavina)

As an experiment I decided to see if I could print a fountain pen on my 3D printer

I found this Open 3D Fountain pen model on Thingiverse, and I’ve been printing it this week (each of the three sections take a couple of hours or more to print).

One of the things I realized when I went to print is that when I switched from using a MacBook Air to using a Mac Mini as my computer I lost the use of an SD card reader. I could have powered up the MacBook Air, but I opted instead to use the opportunity to experiment with OctoPrint, the self-styled “snappy web interface for your 3D printer.”

OctoPrint makes the process of using my Monoprice Select Mini 3D printer so much easier: rather than having to schlep an SD card around from computer to printer, I just connect the printer to the Raspberry Pi I set up (via OctoPi) with OctoPrint and then can control and monitor the entire print process from there.

OctoPrint has some very nice features.

The Temperature tab shows me the temperature of the print head and of the heated bed (and let’s me adjust, if needed):

Photo of the OctoPrint Temperature tab.

The GCode Viewer tab shows me the print head in real time:

Screen shot of the GCode Viewer tab in OctoPrint.

And the Control tab shows me a live view of the print job via a webcam that I’ve connected to the Raspberry Pi:

Screen shot of the Control tab in OctoPrint.

OctoPrint can create a timelapse of the print job, using parameters I set; here’s what it created when I set it to take a timelapse shot every 10 seconds and printed the pen’s barrel:

And here’s a timelapse of the printing of the cap, taken from a different angle:

I’ve printed the three parts of the pen and, despite that I have a low-end printer, to my surprise, aided by a little bit of beeswax, the threaded parts screwed together without issue.

Photo of the three parts of the 3D printed pen.

Here’s the barrel screwed to the top:

Photo of assembled 3D printed pen.

It doesn’t look like a million bucks, but with some sanding and perhaps some painting, it might amount to something more than a striated hulk.

I’ve ordered a JoWo #6 nib to complete the pen, and once it arrives I’ll assemble everything and see how it feels as a pen.

09 Jan 18:56

Paradigm Shift In Transportation

by Ken Ohrn

That good old new transportation paradigm is getting an elevation in profile.

Charles Gauthier, DVBIA

TransLink, Modo, Evo and Mobi have formed a partnership around providing easier management of a multi-modal life.

It remains to be seen exactly how transit and mobility sharing services by various operators can be bundled, but Desmond told Daily Hive in a recent interview he envisions the launch of a new app that enables customers to plan, pay, and get information about a trip in a coherent, single platform. This could potentially be as extensive as transit, bike share, car share, and even taxi and rideshare services under the umbrella of one app.

With thanks to Kenneth Chan at the Daily Hive.

Price Tags has written extensively about this type of business model, calling it “Mobility as a Service“.

I’ve been predicting the arrival of the TSP – a single provider of transportation services, rather like a Shaw or Telus offering a suite of communications options, from cellphone to cable TV. In the case of a Transportation Service Provider, a single monthly bill will give you information and access to all forms of transit, train, car- and bikeshare, rentals, pre-paid tolls, road pricing charges, parking and maybe even maintenance for your increasingly less-needed private car and bike.

A few entrepreneurs have already made forays into this space in Vancouver.  The big difference to these is that the TransLink partnership will incorporate payment for services.

09 Jan 18:55

2019-01-07 Daybook

Perfectionism Is Increasing, and That’s Not Good News | Thomas Curran and Andrew P. Hill have found...
09 Jan 18:54

Pushed up a day thanks to a leak, GitHub has ma...

Pushed up a day thanks to a leak, GitHub has made unlimited private repositories available for developers on the free plan. Most people on the Pro plan probably have it because of wanting to have a few more private repositories. Now, there’s no need to pay for that.

What happens if you keep paying for the Pro? You can look at the pricing page for all the details, but as far as I’m concerned, the big reason to pay for Pro is having unlimited collaborators on a private project. If you don’t use this, then you can probably stop paying.

Unless, of course, you find yourself liking the new Pro features which arrive in the future. Whatever they might happen to be.

09 Jan 18:54

Win a Set of reTyres – Skins for Bike Tires!

by Average Joe Cyclist

Introducing reTyre – Skins for Bike Tires! Enter to win a set.What do you do if you’re halfway home on your bike, and it starts snowing? You could carry on cycling, hoping you’re not going to slide out and hurt yourself. Or, you could stop and grab the studded tire skins you keep in your pannier, quickly zip them over your bike tires, and then continue on your way safely. That’s the genius of reTyre! It’s a new product that launched on KickStarter last year, and is now doing well. reTyres is a modular tire system that lets you quickly adapt your bike tires to meet changing conditions, such as off-road cycling, or snow. Check out videos that show how they work.

The post Win a Set of reTyres – Skins for Bike Tires! appeared first on Average Joe Cyclist.

09 Jan 18:54

The web will, eventually, make everyone a crime...

The web will, eventually, make everyone a crime victim.

09 Jan 18:54

Twitter Favorites: [bmann] Further experiments with Flickr exports, cloud syncing and more. Up on the blog now https://t.co/N0newjJcPH -- incl… https://t.co/R5ruBnYKsi

Boris Mann @bmann
Further experiments with Flickr exports, cloud syncing and more. Up on the blog now blog.bmannconsulting.com/more-flickr-fi… -- incl… twitter.com/i/web/status/1…
09 Jan 18:54

Yoga C930 vs iPad Pro :: Wer gewinnt?

by Volker Weber

c251050922b128be758d424041e76179

Yoga C930, Apple Watch Series 4 und iPad Pro 12.9 sind meine Gewinner 2018. Die Kombination ist ungewöhnlich. Was mache ich eigentlich mit Yoga und was mit iPad?

An alle, die jetzt daran denken, ob sie nicht vielleicht doch lieber ein Yoga als ein MacBook ... Nein, lieber nicht. Windows nervt, immer wieder mal. Ich hatte bereits einen Bluescreen, wahrscheinlich, weil irgendein Treiber noch ein Problem hat, oder irgendeine Systemkomponenten korrupt ist, oder weiß der Geier. Nur wenn Windows bereits gesetzt ist, dann kann ich zu diesem Yoga raten.

Die Maschine, die ich habe, ist sehr gut ausgestattet. 8th gen Core i7, 16 GB RAM, 512 GB SSD, 4K Display. Mehr als ich brauche. Da kann man abkürzen. Das Display ist zwar der Hammer, aber es hat auch Nachteile. Einen höheren Stromverbrauch etwa. Und manche Software (hallo Lync) mag keine hochauflösenden Displays. Praktischer ist da sicherlich das FHD Display.

iPad Pro ist durch iOS vollkommen unauffällig. Es funktioniert einfach. Ich denke niemals über Betriebssystem und irgendwelche Wartung nach, sondern mache einfach mein Ding. Alles, was ich in den letzten zwei Monaten geschrieben habe, kam vom iPad Pro. Und das passiert in iA Writer. Bildverarbeitung mit Affinity Photo, PDF-Überarbeitung mit Readdle PDF Expert, Email mit Outlook, das alles ohne irgendwelche Probleme.

Das kann nicht jeder. Wer "richtig" Office machen will/muss, der kommt mit den schlappen iOS-Versionen nicht weit. Wo Excel drauf steht, ist nicht immer Excel drin. Selbst Word und PowerPoint sind nur ein müder Abklatsch. Da muss Windows ran, oder halt macOS. Wenn ich diese Programme nicht benötige, heißt das nicht, dass das bei Euch auch so ist.

Wenn ich schon alles mit iPad Pro mache, was bleibt dann noch für Yoga? Die ganz wenigen Workflows, die auf dem iPad nicht gehen, etwa meine Calibre Library. Und interessanterweise genau das, für was viele Leute ein iPad nehmen, etwa im Internet zu browsen oder Filme anzuschauen. Das Yoga hat das beste Display in vowe's magic flying circus. Ich liege gerne auf dem Sofa, setze mir das Yoga auf den Brustkorb und schaue Filme auf Netflix. Mit den vier Atmos-Lautsprechern habe ich das totale Kinogefühl. Könnte das iPad Pro auch. Gute Lautsprecher hat es, aber ein Display im falschen Format, und ich müsste es festhalten.

Yoga für Medienkonsum, iPad Pro zum Arbeiten. Für mich ist das keine verkehrte Welt.

09 Jan 18:54

Asoziale Netzwerke

by Volker Weber

Wir wissen mittlerweile, dass Rauchen tödlich sein kann, Zucker Löcher in die Zähne und einen dicken Bauch macht und dass asoziale Netzwerke zerstören. Im Kleinen wie im Großen. Nichts davon ist geboten.

09 Jan 18:53

Huawei Crapware 9.0

by Volker Weber

ad215d48a34baec21c31458b76c13aa9

Gestern hat auch das Huawei Mate 10 Pro sein Update auf Android Pie bekommen. Mit dem zwei Monate alten Security Patch vom 1. November. Dafür mit dem ganzen Haufen Mist, den Huawei da auf Android Pie türmt. Man sieht es gleich an den geschmackvollen Icons. Hardware können sie. Aber Software?

Man sieht auf einen Blick, warum mir das Nokia 7 Plus viel lieber ist.

09 Jan 18:53

Instapaper Liked: What we gain from keeping books – and why it doesn’t need to be ‘joy’

"Literature does not exist only to provoke feelings of happiness or to placate us with its pleasure; art should also challenge and perturb us." Amen sister.…
09 Jan 18:53

Twitter Favorites: [whosthisaida] Driving thru Yonge & Dundas. Their video #billboards are reminding me that the new @KimsConvenience is tomorrow! (+… https://t.co/ojIVka72fk

Aida King @whosthisaida
Driving thru Yonge & Dundas. Their video #billboards are reminding me that the new @KimsConvenience is tomorrow! (+… twitter.com/i/web/status/1…
09 Jan 18:51

The Lament Of Carlos Ghosn: The Man Who Loved Nissan Has His Day In Court

by subcultureist

 

The former Chairman of Nissan, Carlos Ghosn, made his first public appearance since his arrest in November of 2018, today in Japanese court. He discussed his innocence of any crime,  his love for the company that betrayed him, and disputed the charges he is facing in court. The statement was read in English. We will post the Japanese later. 

January 8, 2019

Statement of Carlos Ghosn

Your Honor,

I am grateful to finally have the opportunity to speak publicly. I look forward to beginning the process of defending myself against the accusations that have been made against me.

First, let me say that I have a genuine love and appreciation for Nissan. I believe strongly that in all of my efforts on behalf of the company, I have acted honorably, legally, and with the knowledge and approval of the appropriate executives inside the company—with the sole purpose of supporting and strengthening Nissan, and helping to restore its place as one of Japan’s finest and most respected companies.

Now I would like to address the allegations.

1.​The FX Forward contracts

When I first joined Nissan and moved to Japan almost 20 years ago, I wanted to be paid in U.S. dollars, but was told that that was not possible and was given an employment contract that required me to be paid in Japanese yen. I have long been concerned about the volatility of the yen relative to the U.S. dollar. I am a U.S. dollar-based individual—my children live in the U.S. and I have strong ties to Lebanon, whose currency has a fixed exchange rate against the U.S. dollar. I wanted predictability in my income in order to help me take care of my family.

To deal with this issue, I entered into foreign exchange contracts throughout my tenure at Nissan, beginning in 2002. Two such contracts are at issue in this proceeding. One was signed in 2006, when the Nissan stock price was around 1500 yen and the yen/dollar rate was around 118. The other was signed in 2007, when the Nissan stock price was around 1400 yen and the yen/dollar exchange rate was around 114.

The 2008–2009 financial crisis caused Nissan’s shares to plummet to 400 yen in October 2008 and to 250 yen in February 2009 (down more than 80% from its peak) and the yen/dollar exchange rate dropped below 80. It was a perfect storm that no one predicted. The entire banking system was frozen, and the bank asked for an immediate increase in my collateral on the contracts, which I could not satisfy on my own.

I was faced with two stark choices:

1. Resign from Nissan, so that I could receive my retirement allowance, which I could then use to provide the necessary collateral. But my moral commitment to Nissan would not allow me to step down during that crucial time; a captain doesn’t jump ship in the middle of a storm.

2. Ask Nissan to temporarily take on the collateral, so long as it came to no cost to the company, while I gathered collateral from my other sources.

I chose option 2. The FX contracts were then transferred back to me without Nissan incurring any loss.

2.​Khaled Juffali

Khaled Juffali has been a long-time supporter and partner of Nissan. During a very difficult period, Khaled Juffali Company helped Nissan solicit financing and helped Nissan solve a complicated problem involving a local distributor—indeed, Juffali helped Nissan restructure struggling distributors throughout the Gulf region, enablingNissan to better compete with rivals like Toyota, which was outperforming Nissan. Juffali also assisted Nissan in negotiating the development of a manufacturing plant in Saudi Arabia, organizing high-level meetings with Saudi officials.

Khaled Juffali Company was appropriately compensated—an amount disclosed to and approved by the appropriate officers at Nissan—in exchange for these critical services that substantially benefited Nissan.

3.​The FIEL Allegations

Four major companies sought to recruit me while I was CEO of Nissan, including Ford (by Bill Ford) and General Motors (by Steve Rattner, the then-Car Czar under President Barack Obama). Even though their proposals were very attractive, I could not in good conscience abandon Nissan while we were in the midst of ourturnaround. Nissan is an iconic Japanese company that I care about deeply. Although I chose not to pursue the other opportunities, I did keep a record of the market compensation for my role, which those companies offeredme if I had taken these jobs. This was an internal benchmark that I kept for my own future reference—it had no legal effect; it was never shared with the directors; and it never represented any kind of binding commitment. Infact, the various proposals for non-compete and advisory services post-retirement made by some members of the board did not reflect or reference my internal calculations, underscoring their hypothetical, non-binding nature.

Contrary to the accusations made by the prosecutors, I never received any compensation from Nissan that was not disclosed, nor did I ever enter into any binding contract with Nissan to be paid a fixed amount that was not disclosed. Moreover, I understood that any draft proposals for post-retirement compensation were reviewed by internal and external lawyers, showing I had no intent to violate the law. For me, the test is the “death test”: if I died today, could my heirs require Nissan to pay anything other than my retirement allowance? The answer is an unequivocal “No.”

4.​Contribution to Nissan

I have dedicated two decades of my life to reviving Nissan and building the Alliance. I worked toward these goals day and night, on the earth and in the air, standing shoulder to shoulder with hardworking Nissan employees around the globe, to create value. The fruits of our labors have been extraordinary. We transformed Nissan, moving it from a position of a debt of 2 trillion yen in 1999 to cash of 1.8 trillion yen at the end of 2006, from 2.5 million cars sold in 1999 at a significant loss to 5.8 million cars sold profitably in 2016. Nissan’s asset base tripled during the period. We saw the revival of icons like the Fairlady Z and Nissan G-TR; Nissan’s industrial entry into Wuhon, China, St. Petersburg, Russia, Chennai, India, and Resende, Brazil; the pioneering of a mass market for electric cars with the Leaf; the jumpstarting of autonomous cars; the introduction of Mitsubishi Motors to the Alliance; and the Alliance becoming the number one auto group in the world in 2017, producing more than 10 million cars annually. We created,directly and indirectly, countless jobs in Japan and reestablished Nissan as a pillar of the Japanese economy.

These accomplishments—secured alongside the peerless team of Nissan employees worldwide—are the greatest joy of my life, next to my family.

5.​Conclusion

Your Honor, I am an innocent of the accusations made against me. I have always acted with integrity and have never been accused of any wrongdoing in my several-decade professional career. I have been wrongly accused and unfairly detained based on meritless and unsubstantiated accusations.

Thank you, your Honor, for listening to me.

09 Jan 18:50

An End To Predictions, A Call For Revolution

I reposted the fourth section of that essay as a piece all by itself: Moving from...
09 Jan 18:50

Lasst uns mal über Sicherheit reden

by Volker Weber

3956cf98dfa3a207f2e8859c28358049

Ein 20-jähriger Schüler war es also. Nicht der russische Geheimdienst. Und wie geht das? Vermutlich erschreckend einfach.

Wenn man mit Computern sprechen kann, dann wird man immer wieder mal um Hilfe gebeten. Und ich hänge immer wieder an der selben Stelle: "Wie heißt das Passwort?" Die einzige Stelle, an der technisches Wissen nicht weiterhilft. Diese Zugangskontrolle aus dem Mittelalter — ja, dem richtigen — taugt nichts und hat noch nie getaugt.

Die Menschen sind mit Passwörtern überfordert. Sie geben einfach irgendwas ein. Gerne auch immer wieder das selbe. Dumme Menschen? Nein, untaugliche Technik, die den Menschen leichtfertig zum Schuldigen macht.

Es gibt 'zig Listen mit Millionen von Zugangsdaten. Jede Wette, dass die auch funktionieren, wenn man die mal mit Facebook probiert. Und da die Menschen ihrem Smartphone, und das ist in vielen Fällen eben auch Facebook Messenger, einfach alles anvertrauen, sind sie weg, die Daten. Also nicht weg weg, sondern nur kopiert weg. Das muss man nicht dem Seehofer erklären, damit er es schlecht weitererzählt.

Zwei Dinge können wir jetzt tun:

  1. Die Aufmerksamkeit nutzen, um jetzt ein bisschen mehr Sicherheit zu predigen.
  2. Bessere Sicherungssystem als Passwörter durchsetzen.

Alles was wichtig ist, Google Account, Microsoft Account, Dropbox, Twitter etc. hat bei mir eine Zweifaktor-Authentisierung. Bei Dir auch?

09 Jan 18:50

Zweifaktor-Authentisierung :: Wie geht das?

by Volker Weber

728e7bc76b9312dc7d594690e0a5cebf

Anmeldung mit Username und Passwort ist schwierig, weil viele Menschen nicht wissen, welches Passwort wo zu welchem Username gehört. Sie schreiben vielleicht noch das Passwort auf, manchmal auch den Username, aber selten die Ressource, für die das gilt. Deshalb bringe ich den Leuten bei, immer drei Sachen aufzuschreiben. Wo, wer, wie. Wo? icloud. Wer? vowe@vowe.net Wie? Lampeglockepferd82schrubber

Wenn man das nicht macht, dann ist unklar, welches Passwort jetzt für das Postfach und welches für die iCloud gilt. Besser ist es nicht dasselbe.

Mit Zweifaktur-Authentisierung wird das noch mal schwieriger. Das Prinzip heißt "weiß was, hat was". Das "weiß was" haben wir schon geklärt. Aber jetzt brauchen wir einen zweiten Faktor, das "hat was". Ihr habt vielleicht schon diese Einmalpasswort-Generatoren gesehen. SecureID steht da meistens drauf. Alle 30 Sekunden spuckt das Display eine neue Zahlenkombination aus. Wer das Ding nicht hat, kann mit dem "weiß was" nichts anfangen.

Dieses "hat was" kann in verschiedener Weise gelöst werden. Etwa durch "kann eine SMS empfangen". Oder "geht unter dieser Nummer ans Telefon". Alle Accounts, die Zweifaktor anbieten, haben auch einen ganzen Kanon dieser Lösungen. Man kann sich häufig vorab auch eine Liste mit zehn Einmal-Passwörtern ausdrucken und die der Oma geben, die man dann anruft und sich die Zahlen vorlesen lässt.

Ich finde ein Verfahren praktisch: Authenticator App. Diese App macht das Gleiche wie die SecureID, für mehrere Konten gleichzeitig. Microsoft hat eine, Google auch, die meisten Passwort-Speicher auch. Die sind alle interoperabel, weil ein RFC-Standard verwendet wird und lediglich ein Seed Key ausgetauscht wird, aus dem sich unter Kenntnis der genauen Uhrzeit ein Einmal-Passwort berechnen lässt. Und was macht man, wenn das Handy weg ist? Ich kann beliebig viele Authenticator Apps konfigurieren, auf mehreren Geräten. Die zeigen alle stets die selben Einmalpasswörter an. Man muss halt vorher überlegen, was einem so alles passieren könnte.

Es gibt nur eins, was man keinesfalls machen sollte: Auf den zweiten Faktor verzichten. Und ganz dumm ist es, wenn man für einen Passwort Reset nur Zugang zu einem Mailkonto braucht, das nicht mit einem zweiten Faktor gesichert ist. In dem Fall reicht ein einziges Passwort, um ALLE Konten abzugreifen.

09 Jan 18:50

Mozilla Announces Deal to Bring Firefox Reality to HTC VIVE Devices

by Sean White

Last year, Mozilla set out to build a best-in-class browser that was made specifically for immersive browsing. The result was Firefox Reality, a browser designed from the ground up to work on virtual reality headsets. To kick off 2019, we are happy to announce that we are partnering with HTC VIVE to power immersive web experiences across Vive’s portfolio of devices.

What does this mean? It means that Vive users will enjoy all of the benefits of Firefox Reality (such as its speed, power, and privacy features) every time they open the Vive internet browser. We are also excited to bring our feed of immersive web experiences to every Vive user. There are so many amazing creators out there, and we are continually impressed by what they are building.

“This year, Vive has set out to bring everyday computing tasks into VR for the first time,” said Michael Almeraris, Vice President, HTC Vive. “Through our exciting and innovative collaboration with Mozilla, we’re closing the gap in XR computing, empowering Vive users to get more content in their headset, while enabling developers to quickly create content for consumers.”

Virtual reality is one example of how web browsing is evolving beyond our desktop and mobile screens. Here at Mozilla, we are working hard to ensure these new platforms can deliver browsing experiences that provide users with the level of privacy, ease-of-use, and control that they have come to expect from Firefox.

In the few months since we released Firefox Reality, we have already released several new features and improvements based on the feedback we’ve received from our users and content creators. In 2019, you will see us continue to prove our commitment to this product and our users with every update we provide.

Stay tuned to our mixed reality blog and twitter account for more details. In the meantime, you can check out all of the announcements from HTC Vive here.

If you have an all-in-one VR device running Vive Wave, you can search for “Firefox Reality” in the Viveport store to try it out right now.

The post Mozilla Announces Deal to Bring Firefox Reality to HTC VIVE Devices appeared first on The Mozilla Blog.

09 Jan 18:50

The “Grievance Studies” Hoax and the IRB Process

Steven D. Krause, Jan 08, 2019
Icon

I admit, I don't have a lot of patience with the Research Ethics Board (REB) (our version of the Institutional Review Board (IRB) discussed in the article). It's slow and it often feels like it's reviewing the research, not the ethics of what we're doing. But it is impossible not to be sympathetic with the purpose of the Board, which is to ensure that scientific research doesn't create harm. And that's what's wrong with the reserach conducted by James A. Lindsay, Peter Boghossian, and Helen Pluckrose and what hasn't really been made clear until now. It wasn't simply that they didn't consult their ethics board. It's that, under the guise of 'research', the study appears to have been designed to embarrass or humiliate its subjects. In so doing it discredits all research. And a review board would not have approved it. Image: Resnik, NIH. More: Inside Higher Ed, Daily Nous.

Web: [Direct Link] [This Post]
09 Jan 18:50

Authenticated OpenRefine Server on Digital Ocean, Redux

by Tony Hirst

Following on from yesterday’s recipe showing how to Running OpenRefine On Digital Ocean Under Simple Auth, here’s an even easier way that doesn’t require ssh and doesn’t require console access: just copy and paste some set-up info into a form on the Digital Ocean droplet creation page.

Every little everything helps… this link will set new users up with $100 of free credit on Digital Ocean; somewhere down the line I may get a small amount of affiliate link powered Digital Ocean credit to help keep my own server costs covered…

The Digital Ocean droplet creator has an option to add a User data start-up script when the droplet is created (docs).

This means we can provide a script that will download and install everything we need, including a file to define a service that will run OpenRefine.

Copy and paste the script in the gist that can be found here into the user data area before you create the droplet. The code will be executed once the droplet is up and running and should install the nginx proxy and the OpenRefine application. A default user (test) and password (letmein) are defined in script.

If you are trusting of the gist, you can install it more succinctly from the gist repository. You can also define your own user and password. To take this installation route, use the code that follows below in the userdata area:

Here’s the code…:

#!/bin/bash

#We can over-ride the default credentials
USER_NAME=testuser
USER_PWD=testpwd

#Get the latest version of installer script and run it

source <( curl -s https://gist.githubusercontent.com/psychemedia/f256960c112347dd410c2beec8ce05e3/raw/ )

(There should be no spaces between the less than and open bracket characters in the source command.)

For an explicit link to a particlar version of the script, go to the gist, and copy the link for the raw version of the latest file or the version you want.

Note that this route requires you to place considerable trust in the publisher of the remote installation script. Do you really trust a file with such a dodgy filename?

It will probably take two or three minutes to download and install everything, so don’t be too worried if you don’t see anything at the provided IP address immediately. Just keep refreshing the page…

The first sign of life you should see is the nginx default page…

Wait a few moments and reload the page… Next up is a holding page as the OpenRefine application is installed and the service started…

This page should automatically refresh itself every 5 seconds or so. When the service is up and running, you should get a page like this:

Click the link and you should be prompted with the the user/password authenticator challenge. Provide the username/password and you should be taken to your OpenRefine server.

09 Jan 18:50

Say Hi to Simon!

simon starts to work at DatawrapperSimon’s always smiling when he’s working. Or at least when he’s at Cyclehack Berlin. Photo by Matthias Grytzka, published under CC BY 2.0 (adapted).

We’re thrilled to introduce you all to yet another new addition to the Datawrapper team: Simon Jockers. He will work for three days a week as a software engineer. As such, he will help to build the next version of the Datawrapper chart editor and will also work on the chart types that users can create with Datawrapper.

I asked Simon some questions so that we can all get to know him:

Hi Simon! Can you introduce yourself?

Hi! I am a web developer and (occasional) data journalist with an academic background in media technology and computer science. Outside of my day-to-day work, I help organize community events around open technology and journalism topics, such as the Hacks/Hackers Berlin meetup.

What did you do before working at Datawrapper?

I have worked as a web developer for more than twelve years and have focused on civic tech and data journalism projects for the past five. My last real job was at the German non-profit newsroom CORRECTIV, where I developed newsroom tools, contributed to data reporting, and helped to build a small technology and data team within the newsroom.

I am also a co-founder and the project lead of Datenguide, an open data initiative that aims to make German official statistics more accessible for journalists. With Datenguide, I recently went through the Mozilla Open Leaders program, which is an excellent training and mentorship program for people who work in open technology projects.

Simon’s Datenguide project

I have also been involved with community-supported agriculture (CSA) for many years and have recently helped to relaunch ernte-teilen.org, a web app that brings together farmers and consumers in CSA initiatives.

How did you get interested in Data Vis / Data Journalism?

I first got interested in data visualization during my Bachelor studies, when one of Edward Tufte’s books was part of the reading list for a visual design class I was taking. Shortly afterward I started working in web design and development.

"Some of my first jobs were building interactive infographics and charts – this was around 2007 and people used Flash for this kind of work."

Some of my first jobs were building interactive infographics and charts – this was around 2007 and people used Flash for this kind of work. A couple of years after that I got involved with the German open data and civic tech scene and finally moved into data journalism when I joined CORRECTIV in 2014.

Why did you want to join Datawrapper?

Datawrapper makes an important contribution to the data journalism community by helping journalists around the world to publish their data reporting. It enables them to create maps and charts without having to worry about the design and technology underneath. For me, joining Datawrapper is a logical next step in my journey to make better data journalism tools. It is also the opportunity to work with some of the brightest people in data visualization today.


We’re super happy to welcome Simon on board. If you want to find out more about him, visit his personal website simonjockers.de, find him on Twitter (@sjockers), Github (@sjockers) or the Mastodon instance vis.social (again, @sjockers).

09 Jan 18:49

Apple Music Wrapped: A Shortcut to Visualize Your Most Listened Songs, Artists, and Genres of the Year

by Federico Viticci

When Spotify was my music streaming service of choice, one of the features I really liked was its personalized Wrapped report generated at the end of the year. I've always been a fan of geeky annual reports and stats about the usage of any given web service – be it Spotify, Pocket, or Toggl. I appreciate a detailed look at 12 months of collected data to gain some insight into my habits and patterns.

I've always been annoyed by the lack of a similar feature in Apple Music; I'm surprised that Apple still hasn't added a native "Year in Review" option – a baffling omission given how the company is already collecting all of the necessary data points in the cloud. Official "Apple Music Wrapped" functionality would bolster the service's catalog of personalized features, providing users with a "reward" at the end of the year in the form of reports and playlists to help them rediscover what they listened to over the past year.

But Apple doesn't seem interested in adding this feature to Apple Music, so I decided to build my own using Shortcuts. The result is the most complex shortcut I've ever created comprising over 540 actions. It's not perfect due to the limitations of iOS and Shortcuts, but it's the closest I was able to come to replicating Spotify's excellent Wrapped feature.

Apple Music Wrapped

As always, let's take a look at the final result before examining some of the underlying details and limitations of the shortcut.

Apple Music Wrapped generates a personalized music report that, by default, collects your 100 most-played songs added to your library in any given year since Apple Music was launched in 2015, sorting them from largest to smallest play count. The shortcut takes less than 30 seconds1 to run and the final report is opened in Safari as a custom webpage.

Using data natively exposed from Apple Music to Shortcuts on-device, Apple Music Wrapped creates personalized reports featuring the following items:

  • Most listened song of the year
  • Top 10 songs2
  • Most listened artist of the year
  • Top 5 artists
  • Favorite genres
  • A "top nine" image based on the artwork for your most listened-to songs
  • Stats for play counts, listening time, and total duration of top songs
  • Full list of your top 100 songs

Thanks to Shortcuts' ability to create offline webpages with custom HTML, CSS, and JavaScript, I was able to style the resulting webpage using elements from Apple Music's website; there's even an embedded Apple Music widget that lets you preview your top song of the year in the browser.3

Furthermore, Apple Music Wrapped can:

  • Analyze an arbitrary number of songs (50, 200, 500, etc.)
  • Generate reports for any year from 2015 onward
  • Create a PDF version of the report
  • Create a new playlist in Apple Music with your top 25 songs of the year

There is essentially no configuration needed to run Apple Music Wrapped on an iPhone or iPad. Upon installing the shortcut, you'll be presented with two Import Questions to change the number of songs to analyze and the year for which you want to generate a report. By default, the shortcut evaluates your 100 most-played songs added to your library in 2018. If you use Apple Music but never add songs to your library, this shortcut won't generate a report. Also, for the best experience, I recommend running this shortcut toward the end of the year (for reasons I'll detail later).

If you want to change the song and year values, you'll find two variables near the top of the shortcut that you can modify.

You can modify the main two variables upon installing the shortcut...

You can modify the main two variables upon installing the shortcut...

...or later inside the shortcut itself.

...or later inside the shortcut itself.

You don't need to change anything else. For the shortcut to work, however, you'll have to grant Shortcuts access to your Apple Music library and notifications, which will be used to communicate progress while the shortcut is running.

Local notifications are used to display progress while the shortcut is running.

Local notifications are used to display progress while the shortcut is running.

You'll be asked two questions while your Apple Music Wrapped report is being built. First, you'll be able to choose whether or not you want to create a playlist containing your Top 25 songs of the year; if you accept, the shortcut will create a new playlist in the Music app. To skip the playlist, tap 'Nope' and continue.

The Top 25 playlist created by Apple Music Wrapped.

The Top 25 playlist created by Apple Music Wrapped.

Second, toward the end of the shortcut you'll be given the option to save a PDF version of the report either in the Files app or Dropbox. Again, tapping 'Nope' will continue the shortcut without consequences. Because Shortcuts is creating a webpage and sending it to Safari with an extremely long URL scheme (more on this below), you're going to have to wait a few seconds after Shortcuts launches Safari for the full report to be displayed.

I don't want to get into all the technical details and challenges I faced when building Apple Music Wrapped, but it is, by far, the most advanced and complex shortcut I've ever shared here on MacStories. I had to come up with JavaScript-based hacks for sorting numbers and string de-duplication (without actually showing Safari inside the shortcut!), and I figured out a way to load artist profile pictures from the Apple Music CDN (which is not natively supported by Shortcuts). The shortcut tries to "fail gracefully" as much as possible, and there are dozens of instances where I had to rely on regular expressions or embedded CSS to prepare the final report.

I've been working on this shortcut every day for the past couple of months, and I tried to comment every sequence of actions for clarity and future-proofing. While I'm sure I forgot about some weird edge cases (and if you run into issues, please let me know), I'm happy about the fact that this shortcut runs fast, has no external dependencies, and doesn't save any additional configuration/cache files in the user's iCloud Drive account.

With this in mind, allow me to clarify a few important points about issues and limitations that are unfortunately outside of my control.

Limitations and Other Details Worth Knowing

Apple Music Wrapped pushes the limits of what is possible to achieve with the 'Find Music Where...' and 'Open URLs' actions of the Shortcuts app. In the past few weeks, I (and other testers) have run into limitations and inconsistencies worth pointing out both for MacStories readers and Shortcuts engineers at Apple.

First and foremost, you'll find that running the shortcut for the same number of songs and the same year multiple times may result in slightly different counts for top artists and songs. This is due to the fact that the 'Find Music Where' action doesn't always return the same set of items when filtering your music library. This problem also applies to play counts: it appears that Shortcuts' Music actions only count a song as played if it's been played in full without skipping, but in my experience, these counts may also be different across devices or inconsistent across different runs of the shortcut. I brought all of these issues to the attention of the Shortcuts team at Apple, and I hope they'll be able to ship more flexible and reliable Apple Music filtering actions in the future.

Everything revolves around this initial filtering action.

Everything revolves around this initial filtering action.

The other big limitation of Apple Music Wrapped is that it relies on a memory-intensive workaround to open a custom webpage in Safari – that is, it loads a webpage using a data: URL that contains a long base64-encoded representation of the HTML page. This text string includes image assets and JavaScript code as well. For this reason, two things may happen:

  • You may receive a "Couldn't communicate with a helper application" error message at the end of the shortcut. My understanding is that this is a memory-related issue. Usually, you can "fix" it by force-quitting Safari, the Shortcuts app, or both, and trying to run the shortcut again.
  • After running the shortcut a few times and generating multiple reports, you may notice slowdowns when typing search queries in the Safari address bar. My guess is that this is happening because Safari keeps the long URLs used to assemble custom webpages in its history. Once you're done with the Apple Music Wrapped reports you want to see, I highly recommend clearing your Safari history and website data on all your devices. Everything would be so much easier if only Safari for iOS could open plain .html files like it can on macOS.

In my tests over the past few weeks, these were the issues that often came up when running the shortcut, which I'm afraid I can't fix myself for now. There are also other smaller annoyances beyond my control worth noting:

  • Apple Music Wrapped filters songs based on the year they were added to your music library. If you just search and stream songs without saving them to your library, the shortcut won't find them. Because the shortcut looks for songs that were added between January 1 and December 31 of a specific year, it's primarily designed to give you an overview of new songs that you listened to in the past 12 months.
  • Play counts are not specific by year. To my knowledge, there is no way in Shortcuts to say "give me the number of times this song was played in this time period" (if I missed this, please let me know). This shouldn't be a problem for the 2018 report and future reports if you run them toward the end of each year, but may result in inflated play counts for songs in older reports (2015-2017).
  • If the shortcut finds a song in your library that isn't available on the iTunes Store because you uploaded it from your computer, it will not be linked in the Top 10 Songs list (as there's no iTunes link for it to begin with). In theory, this shortcut should work for locally-uploaded tracks if you never add anything from the Apple Music service, but I haven't been able to test it under such conditions.
  • The "duration is longer than 30 seconds" song filter just doesn't work. I wanted to exclude interludes and other short non-song tracks that are often present in albums, but the 'Find Music Where' action returns them anyway. Oh well.
  • The Top 25 playlist can't be automatically shared by Shortcuts with a link. If you want to share it with others, you'll have to do so manually.

Apple Music Wrapped is the shortcut I'm most proud of, but it's also one I hope Apple sherlocks as soon as possible. There's only so much data I can parse with Shortcuts' (buggy) Apple Music actions; ideally, Apple should copy Spotify's approach and build their own report with more precise stats for songs and genres, details about devices you listened on, days of the week when you're the most active, and so forth. I look forward to the day when, at the end of the year, Apple Music will send me a personalized report with a detailed, in-depth look at my listening habits for the past year.

Until that happens, Apple Music Wrapped should be a pretty good workaround to quickly visualize songs, artists, and genres that defined your past 12 months in Apple Music. I had fun analyzing my music habits with this shortcut, and I hope MacStories readers can find it useful too. You can download it below.

Apple Music Wrapped

Create a detailed report for the music you've listened to in the past year. The shortcut can optionally create a Top 25 playlist for your most played songs and generate a PDF report. The shortcut is primarily designed for Apple Music subscribers.

Get the shortcut here.


  1. When activated from the main Library view of Shortcuts. ↩︎
  2. By default, the shortcut searches for songs in your Top 10 using the United States iTunes Search API. If you want results for a different country, change the 'Search iTunes Store' actions accordingly. ↩︎
  3. You can actually log into your Apple Music account from the report webpage and listen to the song in full from the widget. ↩︎

Support MacStories Directly

Club MacStories offers exclusive access to extra MacStories content, delivered every week; it's also a way to support us directly.

Club MacStories will help you discover the best apps for your devices and get the most out of your iPhone, iPad, and Mac. Plus, it's made in Italy.

Join Now
09 Jan 18:49

Courier: Dropbox migration to gRPC

by Ruslan Nigmatullin and Alexey Ivanov

Dropbox runs hundreds of services, written in different languages, which exchange millions of requests per second. At the core of our Service Oriented Architecture is Courier, our gRPC-based Remote Procedure Call (RPC) framework. While developing Courier, we learned a lot about extending gRPC, optimizing performance for scale, and providing a bridge from our legacy RPC system.

Note: this post shows code generation examples in Python and Go. We also support Rust and Java.

The road to gRPC

Courier is not Dropbox’s first RPC framework. Even before we started to break our Python monolith into services in earnest, we needed a solid foundation for inter-service communication. Especially since the choice of the RPC framework has profound reliability implications.

Previously, Dropbox experimented with multiple RPC frameworks. At first, we started with a custom protocol for manual serialization and de-serialization. Some services like our Scribe-based log pipeline used Apache Thrift. But our main RPC framework (legacy RPC) was an HTTP/1.1-based protocol with protobuf-encoded messages.

For our new framework, there were several choices. We could evolve the legacy RPC framework to incorporate Swagger (now OpenAPI). Or we could create a new standard. We also considered building on top of both Thrift and gRPC.

We settled on gRPC primarily because it allowed us to bring forward our existing protobufs. For our use cases, multiplexing HTTP/2 transport and bi-directional streaming were also attractive.

Note that if fbthrift had existed at the time, we may have taken a closer look at Thrift based solutions.

What Courier brings to gRPC

Courier is not a different RPC protocol—it’s just how Dropbox integrated gRPC with our existing infrastructure. For example, it needs to work with our specific versions of authentication, authorization, and service discovery. It also needs to integrate with our stats, event logging, and tracing tools. The result of all that work is what we call Courier.

While we support using Bandaid as a gRPC proxy for a few specific use cases, the majority of our services communicate with each other with no proxy, to minimize the effect of the RPC on serving latency.

We want to minimize the amount of boilerplate we write. Since Courier is our common framework for service development, it incorporates features which all services need. Most of these features are enabled by default, and can be controlled by command-line arguments. Some of them can also be toggled dynamically via a feature flag.

Security: service identity and TLS mutual authentication

Courier implements our standard service identity mechanism. All our servers and clients have their own TLS certificates, which are issued by our internal Certificate Authority. Each one has an identity, encoded in the certificate. This identity is then used for mutual authentication, where the server verifies the client, and the client verifies the server.

On the TLS side, where we control both ends of the communication, we enforce quite restrictive defaults. Encryption with PFS is mandatory for all internal RPCs. The TLS version is pinned to 1.2+. We also restrict symmetric/asymmetric algorithms to a secure subset, with ECDHE-ECDSA-AES128-GCM-SHA256 being preferred.

After identity is confirmed and the request is decrypted, the server verifies that the client has proper permissions. Access Control Lists (ACLs) and rate limits can be set on both services and individual methods. They can also be updated via our distributed config filesystem (AFS). This allows service owners to shed load in a matter of seconds, without needing to restart processes. Subscribing to notifications and handling configuration updates is taken care of by the Courier framework.

Service “Identity” is the global identifier for ACLs, rate limits, stats, and more. As a side bonus, it’s also cryptographically secure.

Here is an example of Courier ACL/ratelimit configuration definition from our Optical Character Recognition (OCR) service:

limits:
  dropbox_engine_ocr:
    # All RPC methods.
    default:
      max_concurrency: 32
      queue_timeout_ms: 1000

      rate_acls:
        # OCR clients are unlimited.
        ocr: -1
        # Nobody else gets to talk to us.
        authenticated: 0
        unauthenticated: 0

We are considering adopting the SPIFFE Verifiable Identity Document (SVID), which is part of Secure Production Identity Framework for Everyone (SPIFFE). This would make our RPC framework compatible with various open source projects.

Observability: stats and tracing

Using just an identity, you can easily locate standard logs, stats, traces, and other useful information about a Courier service.

Our code generation adds per-service and per-method stats for both clients and servers. Server stats are broken down by the client identity. Out of the box, we have granular attribution of load, errors, and latency for any Courier service.

Courier stats include client-side availability and latency, as well as server-side request rates and queue sizes. We also have various break-downs like per-method latency histograms or per-client TLS handshakes.

One of the benefits of having our own code generation is that we can initialize these data structures statically, including histograms and tracing spans. This minimizes the performance impact.

Our legacy RPC only propagated request_id across API boundaries. This allowed joining logs from different services. In Courier, we’ve introduced an API based on a subset of the OpenTracing specification. We wrote our own client libraries, while the server-side is built on top of Cassandra and Jaeger. The details of how we made this tracing system performant warrant a dedicated blog post.

Tracing also gives us the ability to generate a runtime service dependency graph. This helps engineers to understand all the transitive dependencies of a service. It can also potentially be used as a post-deploy check for avoiding unintentional dependencies.

Reliability: deadlines and circuit-breaking

Courier provides a centralized location for language specific implementations of functionality common to all clients, such as timeouts. Over time, we have added many capabilities at this layer, often as action items from postmortems.

Deadlines
Every gRPC request includes a deadline, indicating how long the client will wait for a reply. Since Courier stubs automatically propagate known metadata, the deadline travels with the request even across API boundaries. Within a process, deadlines are converted into a native representation. For example, in Go they are represented by a context.Context result from the WithDeadline method.

In practice, we have fixed whole classes of reliability problems by forcing engineers to define deadlines in their service definitions.

This context can travel even outside of the RPC layer! For example, our legacy MySQL ORM serializes the RPC context along with the deadline into a comment in the SQL query. Our SQLProxy can parse these comments and KILL queries when the deadline is exceeded. As a side benefit, we have per-request attribution when debugging database queries.

Circuit-breaking
Another common problem that our legacy RPC clients have to solve is implementing custom exponential backoff and jitter on retries. This is often necessary to prevent cascading overloads from one service to another.

In Courier, we wanted to solve circuit-breaking in a more generic way. We started by introducing a LIFO queue between the listener and the workpool.

In the case of a service overload, this LIFO queue acts as an automatic circuit breaker. The queue is not only bounded by size, but critically, it’s also bounded by time. A request can only spend so long in the queue.

LIFO has the downside of request reordering. If you want to preserve ordering, you can use CoDel. It also has circuit breaking properties, but won’t mess with the order of requests.

Introspection: debug endpoints

Even though debug endpoints are not part of Courier itself, they are widely adopted across Dropbox. They are too useful to not mention! Here are a couple of examples of useful introspections.

For security reasons, you may want to expose these on a separate port (possibly only on a loopback interface) or even a Unix socket (so access can be additionally controlled with Unix file permissions.) You should also strongly consider using mutual TLS authentication there by asking developers to present their certs to access debug endpoints (esp. non-readonly ones.)

Runtime
Having the ability to get an insight into the runtime state is a very useful debug feature, e.g. heap and CPU profiles could be exposed as HTTP or gRPC endpoints.

We are planning on using this during the canary verification procedure to automate CPU/memory diffs between old and new code versions.

These debug endpoints can allow modification of runtime state, e.g. a golang-based service can allow dynamically setting the GCPercent.

Library
For a library author being able to automatically export some library-specific data as an RPC-endpoint may be quite useful. Good examples here is that malloc library can dump its internal stats. Another example is a read/write debug endpoint to change the logging level of a service on the fly.

RPC
It is given that troubleshooting encrypted and binary-encoded protocols will be a bit complicated, therefore putting in as much instrumentation as performance allows in the RPC layer itself is the right thing to do. One example of such an introspection API is a recent channelz proposal for the gRPC.

Application
Being able to view application-level parameters can also be useful. A good example is a generalized application info endpoint with build/source hash, command line, etc. This can be used by the orchestration system to verify the consistency of a service deployment.

Performance optimizations

We discovered a handful of Dropbox specific performance bottlenecks when rolling out gRPC at scale.

TLS handshake overhead

With a service that handles lots of connections, the cumulative CPU overhead of TLS handshakes can become non-negligible. This is especially true during mass service restarts.

We switched from RSA 2048 keypairs to ECDSA P-256 to get better performance for signing operations. Here are BoringSSL performance examples (note that RSA is still faster for signature verification):

RSA:

𝛌 ~/c0d3/boringssl bazel run -- //:bssl speed -filter 'RSA 2048'
Did ... RSA 2048 signing operations in ..............  (1527.9 ops/sec)
Did ... RSA 2048 verify (same key) operations in .... (37066.4 ops/sec)
Did ... RSA 2048 verify (fresh key) operations in ... (25887.6 ops/sec)

ECDSA:

𝛌 ~/c0d3/boringssl bazel run -- //:bssl speed -filter 'ECDSA P-256'
Did ... ECDSA P-256 signing operations in ... (40410.9 ops/sec)
Did ... ECDSA P-256 verify operations in .... (17037.5 ops/sec)

Since RSA 2048 verification is ~3x faster than ECDSA P-256 one, from a performance perspective, you may consider using RSA for your root/leaf certs. From a security perspective though it’s a bit more complicated since you’ll be chaining different security primitives and therefore resulting security properties will be the minimum of all of them.
For the same performance reasons you should also think twice before using RSA 4096 (and higher) certs for your root/leaf certs.

We also found that TLS library choice (and compilation flags) matter a lot for both performance and security. For example, here is a comparison of MacOS X Mojave’s LibreSSL build vs homebrewed OpenSSL on the same hardware:

LibreSSL 2.6.4:

𝛌 ~ openssl speed rsa2048
LibreSSL 2.6.4
...
                  sign    verify    sign/s verify/s
rsa 2048 bits 0.032491s 0.001505s     30.8    664.3

OpenSSL 1.1.1a:

𝛌 ~ openssl speed rsa2048
OpenSSL 1.1.1a  20 Nov 2018
...
                  sign    verify    sign/s verify/s
rsa 2048 bits 0.000992s 0.000029s   1208.0  34454.8

But the fastest way to do a TLS handshake is to not do it at all! We’ve modified gRPC-core and gRPC-python to support session resumption, which made service rollout way less CPU intensive.

Encryption is not expensive

It is a common misconception that encryption is expensive. Symmetric encryption is actually blazingly fast on modern hardware. A desktop-grade processor is able to encrypt and authenticate data at 40Gbps rate on a single core:

𝛌 ~/c0d3/boringssl bazel run -- //:bssl speed -filter 'AES'
Did ... AES-128-GCM (8192 bytes) seal operations in ... 4534.4 MB/s

Nevertheless, we did end up having to tune gRPC for our 50Gb/s storage boxes. We learned that when the encryption speed is comparable to the memory copy speed, reducing the number of memcpy operations was critical. In addition, we also made some of the changes to gRPC itself.

Authenticated and encrypted protocols have caught many tricky hardware issues. For example, processor, DMA, and network data corruptions. Even if you are not using gRPC, using TLS for internal communication is always a good idea.

High Bandwidth-Delay product links

Dropbox has multiple data centers connected through a backbone network. Sometimes nodes from different regions need to communicate with each other over RPC, e.g. for the purposes of replication. When using TCP the kernel is responsible for limiting the amount of data inflight for a given connection (within the limits of /proc/sys/net/ipv4/tcp_{r,w}mem), though since gRPC is HTTP/2-based it also has its own flow control on top of TCP. The upper bound for the BDP is hardcoded in grpc-go to 16Mb, which can become a bottleneck for a single high BDP connection.

Golang’s net.Server vs grpc.Server

In our Go code we initially supported both HTTP/1.1 and gRPC using the same net.Server. This was logical from the code maintenance perspective but had suboptimal performance. Splitting HTTP/1.1 and gRPC paths to be processed by separate servers and switching gRPC to grpc.Server greatly improved throughput and memory usage of our Courier services.

golang/protobuf vs gogo/protobuf

Marshaling and unmarshaling can be expensive when you switch to gRPC. For our Go code, we’ve switched to gogo/protobuf which noticeably decreased CPU usage on our busiest Courier servers.

As always, there are some caveats around using gogo/protobuf, but if you stick to a sane subset of functionality you should be fine.

Implementation details

Starting from here, we are going to dig way deeper into the guts of Courier, looking at protobuf schemas and stub examples from different languages. For all the examples below we are going to use our Test service (the service we use in Courier’s integration tests).

Service description

Let’s look at the snippet from the Test service definition:

service Test {
    option (rpc_core.service_default_deadline_ms) = 1000;

    rpc UnaryUnary(TestRequest) returns (TestResponse) {
        option (rpc_core.method_default_deadline_ms) = 5000;
    }

    rpc UnaryStream(TestRequest) returns (stream TestResponse) {
        option (rpc_core.method_no_deadline) = true;
    }
    ...
}

As was mentioned in the reliability section above, deadlines are mandatory for all Courier methods. They can be set for the whole service with the following protobuf option:

option (rpc_core.service_default_deadline_ms) = 1000;

Each method can also set its own deadline, overriding the service-wide one (if present).

option (rpc_core.method_default_deadline_ms) = 5000;

In rare cases where deadline doesn’t really make sense (such as a method to watch some resource), the developer is allowed to explicitly disable it:

option (rpc_core.method_no_deadline) = true;

The real service definition is also expected to have extensive API documentation, sometimes even along with usage examples.

Stub generation

Courier generates its own stubs instead of relying on interceptors (except for the Java case, where the interceptor API is powerful enough) mainly because it gives us more flexibility. Let’s compare our stubs to the default ones using Golang as an example.

This is what default gRPC server stubs look like:

func _Test_UnaryUnary_Handler(srv interface{}, ctx context.Context, dec func(interface{}) error, interceptor grpc.UnaryServerInterceptor) (interface{}, error) {
        in := new(TestRequest)
        if err := dec(in); err != nil {
                return nil, err
        }
        if interceptor == nil {
                return srv.(TestServer).UnaryUnary(ctx, in)
        }
        info := &grpc.UnaryServerInfo{
                Server:     srv,
                FullMethod: "/test.Test/UnaryUnary",
        }
        handler := func(ctx context.Context, req interface{}) (interface{}, error) {
                return srv.(TestServer).UnaryUnary(ctx, req.(*TestRequest))
        }
        return interceptor(ctx, in, info, handler)
}

Here, all the processing happens inline: decoding the protobuf, running interceptors, and calling the UnaryUnary handler itself.

Now let’s look at Courier stubs:

func _Test_UnaryUnary_dbxHandler(
        srv interface{},
        ctx context.Context,
        dec func(interface{}) error,
        interceptor grpc.UnaryServerInterceptor) (
        interface{},
        error) {

        defer processor.PanicHandler()

        impl := srv.(*dbxTestServerImpl)
        metadata := impl.testUnaryUnaryMetadata

        ctx = metadata.SetupContext(ctx)
        clientId = client_info.ClientId(ctx)
        stats := metadata.StatsMap.GetOrCreatePerClientStats(clientId)
        stats.TotalCount.Inc()

        req := &processor.UnaryUnaryRequest{
                Srv:            srv,
                Ctx:            ctx,
                Dec:            dec,
                Interceptor:    interceptor,
                RpcStats:       stats,
                Metadata:       metadata,
                FullMethodPath: "/test.Test/UnaryUnary",
                Req:            &test.TestRequest{},
                Handler:        impl._UnaryUnary_internalHandler,
                ClientId:       clientId,
                EnqueueTime:    time.Now(),
        }

        metadata.WorkPool.Process(req).Wait()
        return req.Resp, req.Err
}

That’s a lot of code, so let’s go over it line by line.

First, we defer the panic handler that is responsible for automatic error collection. This allows us to send all uncaught exceptions to centralized storage for later aggregation and reporting:

defer processor.PanicHandler()

One more reason for setting up a custom panic handler is to ensure that we abort application on panic. Default golang/net HTTP handler behavior is to ignore it and continue serving new requests (with potentially corrupted and inconsistent state).

Then we propagate context by overriding its values from the metadata of the incoming request:

ctx = metadata.SetupContext(ctx)
clientId = client_info.ClientId(ctx)

We also create (and cache for efficiency purposes) the per-client stats on the server side for more granular attribution:

stats := metadata.StatsMap.GetOrCreatePerClientStats(clientId)

This dynamically creates a per-client (i.e. per-TLS identity) stats in runtime. We also have per-method stats for each service and, since the stub generator has access to all the methods during the code generation time, we can statically pre-create these to avoid runtime overhead.

Then we create the request structure, pass it to the work pool, and wait for the completion:

req := &processor.UnaryUnaryRequest{
        Srv:            srv,
        Ctx:            ctx,
        Dec:            dec,
        Interceptor:    interceptor,
        RpcStats:       stats,
        Metadata:       metadata,
        ...
}
metadata.WorkPool.Process(req).Wait()

Note that almost no work has been done by this point: no protobuf decoding, no interceptor execution, etc. ACL enforcement, prioritization, and rate-limiting happens inside the workpool before any of that is done.

Note that the golang gRPC library supports the Tap interface, which allows very early request interception. This provides infrastructure for building efficient rate-limiters with minimal overhead.

App-specific error codes

Our stub generator also allows developers to define app-specific error codes through custom options:

enum ErrorCode {
  option (rpc_core.rpc_error) = true;

  UNKNOWN = 0;
  NOT_FOUND = 1 [(rpc_core.grpc_code)="NOT_FOUND"];
  ALREADY_EXISTS = 2 [(rpc_core.grpc_code)="ALREADY_EXISTS"];
  ...
  STALE_READ = 7 [(rpc_core.grpc_code)="UNAVAILABLE"];
  SHUTTING_DOWN = 8 [(rpc_core.grpc_code)="CANCELLED"];
}

Within the same service, both gRPC and app errors are propagated, while between API boundaries all errors are replaced with UNKNOWN. This avoids the problem of accidental error proxying between different services, potentially changing their semantic meaning.

Python-specific changes

Our Python stubs add an explicit context parameter to all Courier handlers, e.g.:

from dropbox.context import Context
from dropbox.proto.test.service_pb2 import (
        TestRequest,
        TestResponse,
)
from typing_extensions import Protocol

class TestCourierClient(Protocol):
    def UnaryUnary(
            self,
            ctx,      # type: Context
            request,  # type: TestRequest
            ):
        # type: (...) -> TestResponse
        ...

At first, it looked a bit strange, but after some time developers got used to the explicit ctx just as they got used to self.

Note that our stubs are also fully mypy-typed which pays off in full during large-scale refactoring. It also integrates nicely with some IDEs like PyCharm.

Continuing the static typing trend, we also add mypy annotations to protos themselves:

class TestMessage(Message):
    field: int

    def __init__(self,
        field : Optional[int] = ...,
        ) -> None: ...
    @staticmethod
    def FromString(s: bytes) -> TestMessage: ...

These annotations prevent many common bugs, such as assigning None to a string field in Python.

This code is opensourced at dropbox/mypy-protobuf.

Migration process

Writing a new RPC stack is by no means an easy task, but in terms of operational complexity it still can’t be compared to the process of infra-wide migration to it. To assure the success of this project, we’ve tried to make it easier for the developers to migrate from legacy RPC to Courier. Since the migration by itself is a very error-prone process, we’ve decided to go with a multi-step process.

Step 0: Freeze the legacy RPC

Before we did anything, we froze the legacy RPC feature set so it’s no longer a moving target. This also gave people an incentive to move to Courier, since all new features like tracing and streaming were only available to services using Courier.

Step 1: A common interface for the legacy RPC and Courier

We started by defining a common interface for both legacy RPC and Courier. Our code generation was responsible for producing both versions of the stubs that satisfy this interface:

type TestServer interface {
   UnaryUnary(
      ctx context.Context,
      req *test.TestRequest) (
      *test.TestResponse,
      error)
   ...
}

Step 2: Migration to the new interface

Then we started switching each service to the new interface but continued using legacy RPC. This was often a huge diff touching all the methods in the service and its clients. Since this is the most error-prone step, we wanted to de-risk it as much as possible by changing one variable at a time.

Low profile services with a small number of methods and spare error budget can do the migration in a single step and ignore this warning.

Step 3: Switch clients to use Courier RPC

As part of the Courier migration, we also started running both legacy and Courier servers in the same binary on different ports. Now changing the RPC implementation is a one-line diff to the client:

class MyClient(object):
  def __init__(self):
-   self.client = LegacyRPCClient('myservice')
+   self.client = CourierRPCClient('myservice')

Note that using that model we can migrate one client at a time, starting with ones that have lower SLAs like batch processing and other async jobs.

Step 4: Clean up

After all service clients have migrated it is time to prove that legacy RPC is not used anymore (this can be done statically by code inspection and at runtime looking at legacy server stats.) After this step is done developers can proceed to clean up and remove old code.

Lessons learned

At the end of the day, what Courier brings to the table is a unified RPC framework that speeds up service development, simplifies operations, and improves Dropbox reliability.

Here are the main lessons we’ve learned during the Courier development and deployment:

  1. Observability is a feature. Having all the metrics and breakdowns out-of-the-box is invaluable during troubleshooting.
  2. Standardization and uniformity are important. They lower cognitive load, and simplify operations and code maintenance.
  3. Try to minimize the amount of boilerplate code developers need to write. Codegen is your friend here.
  4. Make migration as easy as possible. Migration will likely take way more time than the development itself. Also, migration is only finished after cleanup is performed.
  5. RPC framework can be a place to add infrastructure-wide reliability improvements, e.g. mandatory deadlines, overload protection, etc. Common reliability issues can be identified by aggregating incident reports on a quarterly basis.

Future Work

Courier, as well as gRPC itself, is a moving target so let’s wrap up with the Runtime team and Reliability teams’ roadmaps.

In relatively near future we wanted to add a proper resolver API to Python’s gRPC code, switch to C++ bindings in Python/Rust, and add full circuit breaking and fault injection support. Later next year we are planning on looking into ALTS and moving TLS handshake to a separate process (possibly even outside of the services’ container.)

We are hiring!

Do you like runtime-related stuff? Dropbox has a globally distributed edge network, terabits of traffic, millions of requests per second, and comfy small teams in both Mountain View and San Francisco.

Traffic/Runtime/Reliability teams are hiring both SWEs and SREs to work on TCP/IP packet processors and load balancers, HTTP/gRPC proxies, and our internal service mesh runtime: Courier/gRPC, Service Discovery, and AFS. Not your thing? We’re also hiring for a wide variety of engineering positions in San Francisco, New York, Seattle, Tel Aviv, and other offices around the world.

Acknowledgments

Contributors: Ashwin Amit, Can Berk Guder, Dave Zbarsky, Giang Nguyen, Mehrdad Afshari, Patrick Lee, Ross Delinger, Ruslan Nigmatullin, Russ Allbery, Santosh Ananthakrishnan.

We are also very grateful to the gRPC team for their support.

09 Jan 18:49

Kohler’s fully immersive flagship intelligent toilet experience

by Josh Bernoff

CES, the consumer electronics show, is the apotheosis of overblown technology demos and promises. Exuberant press releases abound. Kohler’s bathroom products are now fully digital, connected, and interactive — so it must compete on hype with the likes of Facebook and Samsung. Let’s just say that after reading the company’s latest press release, I’m flush … Continued

The post Kohler’s fully immersive flagship intelligent toilet experience appeared first on without bullshit.

09 Jan 18:48

CES AirPlay, HomeKit, and Accessory Roundup, Part 1

by John Voorhees

Apple may not be exhibiting at CES, but its presence is felt nonetheless. More than ever, Apple’s technologies like HomeKit and AirPlay are showing up in third-party hardware. What’s different this year is the first appearance of Apple video content on third-party devices in what is undoubtedly the first step in the company’s emerging video strategy, which breaks from the traditionally tight integration between Apple hardware and software.

As in past years, the MacStories team is sifting through the hundreds of press releases to find the announcements that are most relevant to our readers. CES has only just begun, and we’ve already seen a long list of product announcements that affect iOS and Mac users. Below are the highlights of those early announcements. We’ll follow up with another roundup later this week collecting additional products showcased at CES.

It’s worth noting that CES announcements rarely indicate the countries in which new products will be available, so it’s worth keeping an eye out for additional details if you see something that interests you.

AirPlay and HomeKit-Enabled TVs

As we reported last weekend, Samsung announced that its 2019 TVs will include AirPlay 2 support and an iTunes Movies and TV Shows app. The same functionality will be added to some of Samsung's 2018 TVs through a firmware update. The news from Samsung was followed by an update to Apple’s AirPlay webpage indicating that more TV manufacturers would add AirPlay 2 support and previewing future AirPlay features.

On Monday, three more TV manufacturers, Vizio, LG, and Sony, announced upcoming AirPlay 2 and HomeKit support, which will allow compatible TVs to stream video from iOS devices and Macs and be controlled from Apple's Home app and with Siri. AirPlay 2 support will also enable compatible TVs to act as speakers for audio content.

The four TV manufacturers collectively control 75% of the US smart TV market. Although most existing TVs won't be updated to work with AirPlay, the market share of the participants means that the majority of new TVs sold in the US will be capable of playing video and audio streaming from iOS devices and Macs.

The main difference between Samsung's announcement over the weekend and those of Vizio, LG, and Sony is that the iTunes app is a Samsung exclusive for now and only Samsung and Vizio plan to update older-model TVs with AirPlay support. Also, The Verge reports that Samsung has made no promises regarding support for HomeKit functionality.

HomeKit Accessories

Just like last year, CES is teeming with new HomeKit accessories. The announcements feel a little different this year though. Part of that is the control from the Home app that HomeKit-enabled TVs will enjoy for the first time. However, there have also been notable announcements by companies like Arlo and Netatmo that passed over HomeKit integration initially but are now adopting the feature. Add to that a long list of new HomeKit products from other companies including doorbells, which disappeared from Apple’s HomeKit accessory webpage last summer, and more than ever, HomeKit feels like a robust, healthy platform that most device manufacturers want to support.

Netatmo began to embrace HomeKit when it added security devices to its lineup. This week, the company introduced the Smart Video Doorbell that will allow users to monitor who is at their door and communicate with them remotely when the product is released later this year. Unlike Amazon’s Ring, which is subscription-based and only supports Alexa, Netatmo’s device records video to a microSD card, Dropbox, or FTP server without the added cost of a subscription.

Arlo says its Arlo Ultra and Arlo Pro 2 cameras will soon add HomeKit support too. That’s a nice start, but it’s not Arlo’s entire device lineup. The announcement is nonetheless notable since neither Canary’s security cameras nor Ring’s new Door View Cam and other products support HomeKit.

In another sign of growing acceptance of HomeKit among accessory makers, Belkin, which added HomeKit support to its line of Wemo plugs using a bridge last year, is adding native HomeKit support to light switches. Expected in spring or summer, the switches will retail for $39.99 for single pole and $49.99 for 3-way switches.

A wide range of other HomeKit-enabled devices have been announced at CES too:

  • Ikea will launch smart blinds in February starting for $110, which is considerably cheaper than some existing options.
  • Smart lock options will expand in 2019 with new products from Kwikset and Mighton according to Engadget.
  • Honeywell’s new T9 and T10 Pro smart thermostats that include room-by-room temperature sensing and motion detection, similar to Ecobee thermostats, support Google Assistant and Alexa at launch and will add HomeKit support later this year.
  • First Alert announced a new version of its Safe and Sound smoke and carbon monoxide detector that also includes mesh WiFi extender and speaker system functionality in a single unit. The Safe and Sound will work with Siri via HomeKit, plus Alexa and Google Assistant at launch, and will add AirPlay 2 later this year.
  • TP-Link’s Kasa Smart Plug Mini will add HomeKit support in early 2019.
  • Another company that will add ‘better-late-than-never’ support for HomeKit is Brilliant. The company’s Home Control switch debuted last year with support for Alexa, Google Assistant, Ring, Nest, and many other devices but no HomeKit support. The company says HomeKit support will be added in spring 2019.
  • Eve introduced a HomeKit-enabled LED light strip that will retail for $79.95 and a power strip that monitors energy consumption for $49.95.
  • Kohler is showing off its new Sensate faucet that can be turned on and off using HomeKit’s Siri integration and dispense precise amounts of water.

iPhone, iPad, and Mac Accessories

USB-C cables and charging solutions are getting a boost at CES. Long-time Apple accessory makers Belkin and Griffin both announced that they will be shipping the first third-party USB-C to Lightning cables. Belkin's cables will come in 4, 6, and 10 foot lengths and cost between $24.99 and $34.99, while MacRumors says Griffin’s cables are coming in Q2 2019 in 4 and 6 foot models for $19.99 and $29.99, along with a 5-foot aluminum braided model for $34.99.

Belkin, Griffin, and Anker are also showing off new USB-C chargers at CES. Belkin announced 27W USB-C wall and car chargers, plus a 20,000mAh battery pack with a 30W USB-C port and 12W USB-A port. Griffin will ship 18W USB-C wall and car chargers along with a wall charger that includes an 18W USB-C port and 12W USB-A port. Griffin also debuted a lineup of new Qi charging stands and a Qi charging battery pack. Finally, The Verge reports that Anker says its new gallium nitride fast charger, which was announced last October, will be available later this month for $29.99. The relatively small 30W charger is designed to charge smaller USB-C devices faster than other available chargers.

It wouldn’t be CES without new cases. OtterBox has teamed up with PopSockets. Instead of attaching a PopSocket directly to your phone, the OtterBox case lets you connect it to the case. It’s a chunky solution, but worth a look if you don’t like the idea of attaching a PopSocket directly to your iPhone or another third-party case.

For iPad users, Zagg introduced a trio of cases. The Slim Book Go is a detachable keyboard case with backlit keys and multiple viewing angles that comes in several colors. The Messenger Folio has a simpler design with no backlit keys, no detachable keyboard, and just two viewing angles. Finally, the Rugged Book Go, which also has a detachable keyboard, is a chunky case designed to protect the 11-inch iPad Pro from drops.

In Q1 2019, Mophie is introducing new Juice Pack cases for the iPhone XS, XS Max, and XR. Mophie says the 2,000mAh XS case extends the iPhone’s battery life by up to 25 hours, while the 2,200mAh XS Max and XR models extend battery life up to 31 hours. The XS case is also compatible with the iPhone X.

I’ve used Shure’s Lightning-enabled microphone for recording with iPhones in the past. It’s not a pro-level microphone, but it’s significantly better than the one built into the iPhone. Now Shure is leveraging its microphone as part of a video recording kit called the MV88+ Video Kit that includes the mic, a tripod, and phone clamp. For anyone starting with videography, vlogging, or field recording, Shure’s kit looks like a handy all-in-one solution.

Finally, there are a handful of eGPU solutions available for the Mac already, but OWC’s announcement at CES is interesting because, unlike Blackmagic’s offerings that aren’t upgradable, it’s just an enclosure that accepts a variety of GPU cards. Known as the Mercury Helios FX 650 eGPU, OWC’s $389 enclosure connects via Thunderbolt 3, includes HDMI, DisplayPort, and DVI connections, and supplies 100W of power to the connected MacBook.


I enjoy CES on two levels. First, I love the big announcements like the ones that AirPlay 2 and HomeKit are coming to all the major smart TV manufacturers because it's the sort of move by Apple that has the potential to lead to interesting changes in the video streaming landscape.

Second, there is also always more pedestrian news at CES that I enjoy unearthing because of its potential for improving the day-to-day use of technology. Qi charging battery packs, USB-C to Lightning cables, and cheaper HomeKit blinds may not be as exciting as the TVs announced, but they are the kinds of products that can have a more immediate impact, which is also why they're the sort of items that we'll continue to highlight on MacStories as new announcements are made.


Support MacStories Directly

Club MacStories offers exclusive access to extra MacStories content, delivered every week; it's also a way to support us directly.

Club MacStories will help you discover the best apps for your devices and get the most out of your iPhone, iPad, and Mac. Plus, it's made in Italy.

Join Now
09 Jan 18:48

“The president,” he said, “would like a Diet Coke.”

by Andrea

The Atlantic: Why Mike Pence Couldn’t End the Shutdown. “The vice president has led negotiations to reopen the government. But even after the White House’s state-of-emergency threat, he doesn’t appear to have the authority to do much about it.”

“White House allies on the Hill and former administration officials acknowledged privately that the vice president may be more hamstrung than ever, unable to capitalize on many of the strengths he was originally chosen for. But crucially, those sources said, Pence has never expressed any displeasure with his circumstances, and would never suggest, even privately they say, that Trump’s whims have made shuttle diplomacy difficult. “There’s a reason Pence has avoided the fate of so many others,” another former senior White House official told me. “He acquiesces entirely to the will of Trump 100 percent of the time.””

Link via MetaFilter.

09 Jan 18:18

November 2018 iPhone sales down 20% compared to 2017: Counterpoint

by Sameer Chhabra
iPhone XR

A new study from Hong Kong-based research firm Counterpoint shows that November 2018’s iPhone sales were down 20 percent compared to 2017.

The study confirmed that the more affordable iPhone XR was the best-selling smartphone released by Apple in 2018, compared to the iPhone X in November 2017.

Interesting to note is that Apple sold 50 percent more iPhone X smartphones in November 2017, compared to the iPhone XR in November 2018.

Still, overall iPhone sales numbers went down in 2018 in the Asia Pacific region, as well as in Europe and the U.S.

“The decline in the US and Europe is due to the lengthening replacement cycle and decreased operator discounts this year during the launch of new iPhones,” wrote Counterpoint research analyst Shobhit Srivastava, in a January 6th, 2019 report.

“While the decline in emerging markets like the Asia Pacific (excluding China and India) is due to the higher price when compared to offerings from Chinese players.”

Counterpoint’s study showed that the iPhone XR outsold the iPhone XS and XS Max, with the 64GB iPhone XR being the best-selling device in November 2018.

“We estimate iPhone XR to further eat into the share of higher-priced iPhone XS and XS Max during December 2018,” wrote Srivastava.

Apple released the iPhone XS and XS Max in most markets in September 2018.

The iPhone XR was released in most markets in October 2018.

The iPhone X was released in November 2017.

It’s worth noting that Counterpoint’s latest study falls in line with an earnings guidance revision released by Apple CEO Tim Cook on January 2nd, 2019.

Apple used its guidance revision to inform investors that lower than anticipated iPhone sales contributed to the company decision to revise its expected earnings for Q1 2019.

Apple will release its Q1 2019 earnings on January 29th, 2019.

Source: Counterpoint

The post November 2018 iPhone sales down 20% compared to 2017: Counterpoint appeared first on MobileSyrup.