Tuesday, January 29, 2019

Responsible Corporations: My Privacy Does Matter

Yesterday was a big day in the Apple world, and not in a good way.

Around 4 PM on January 28th, MacRumors, my go-to source for Apple news, began reporting on a serious flaw discovered in the Group FaceTime feature of the latest iOS update. The bug was straightforward and alarming: if you initiated a FaceTime call with someone and then added yourself back into the call as a third participant, an audio bridge would open on the other end, whether or not the person you called ever accepted. In plain terms, you could listen in on someone without their knowledge or consent.

By 11 PM, local television news was running the story. That same night, Apple disabled Group FaceTime on their servers entirely, shutting down the vulnerability before it could spread further.

I went to bed feeling reasonably reassured. Apple has spent years positioning itself as a company that genuinely champions user privacy. It is woven into their marketing, their product announcements, and their public messaging. I had just upgraded a Mac, and one of the first things Mojave presented me with was a notice about privacy and Apple's commitment to protecting it. Their entire privacy page exists as a public declaration of values. I believed them. I still want to.

Then I woke up the next morning.

MacRumors had posted a thread showing that a teenager had discovered this exact bug and reported it to Apple on January 21st, a full seven days before it became public. The timestamps on those posts cannot be faked. Apple had been made aware of a significant privacy vulnerability affecting millions of users, and nothing changed until mainstream media picked up the story.

That is the part that concerns me most.

I am not suggesting Apple acted maliciously. What I am suggesting is that somewhere in the chain between a teenager's bug report and a company-wide response, something failed. Either the report did not reach the right people, or it did and the urgency was not recognized, or, in the worst case scenario, someone knew and was quietly working toward a backend fix before the story got out. Any of those outcomes points to a process problem that a company of Apple's size and stated values should not have.

Technology companies, especially those that have built their brand on privacy and trust, have a responsibility that goes beyond good marketing. When a flaw is reported, the response cannot depend on whether a journalist picks up the story first. Users deserve to know when their security is at risk. Transparency, even when it is uncomfortable, is what actually builds trust over time.

Apple has done remarkable things. I remain a believer in a lot of what they stand for. But this was a stumble, and it deserves to be called one clearly.

Put people above the bottom line. Always.

Monday, November 19, 2018

Windows 10 Fall 2018 Update: A LTSC Usability Problem Microsoft Missed

Let me be clear upfront: the Windows 10 Fall 2018 update, version 1809, did not delete my user files and did not touch my activation keys. Those horror stories made the rounds and understandably scared a lot of IT administrators. That is not what this post is about.

This is about a quieter, more frustrating problem. A usability issue that suggests Microsoft's engineers lost track of which version of Windows they were actually building for.

At work, we run the Long Term Servicing Channel build of Windows 10, now called LTSC, previously called LTSB. The Long Term Servicing Channel exists specifically for environments that need maximum stability and minimal disruption. It is the right choice for a lot of businesses, and we made that choice deliberately. The tradeoff has always been clear: you give up Microsoft Edge and the Microsoft Store in exchange for a leaner, more predictable operating system.

Losing Edge was never a hardship. Losing the Store created some friction. A few users wanted access to the Windows Subsystem for Linux, which inexplicably requires the Microsoft Store to download and install. Others ran into printer driver issues, specifically with HP hardware, that also required the Store to resolve. Those are legitimate complaints worth a separate conversation with Microsoft.

But the 1809 update introduced something new and genuinely irritating. The updated interface now includes a Themes section, which has never appeared in an LTSC build before. Scattered throughout the updated UI are hooks and prompts pointing directly to the Microsoft Store, a component that is not installed and was never meant to be part of this build.

Click on certain interface elements and you are told you need a Store package to proceed. Try to use the updated Snipping Tool, which now prompts you to upgrade to Snip and Sketch, and you are directed to download an app that only exists in the Store. The Store that is not there. The Store that was intentionally left out.

This is what makes it frustrating. These are not edge cases or obscure settings. These are visible, everyday parts of the interface. In the previous 2016 LTSB build, none of these prompts existed. Someone made a decision during the 1809 development cycle to update the interface without accounting for the fact that LTSC users would be staring at buttons and options that lead nowhere, for the next three years.

The ask here is simple. Microsoft, when you build for LTSC, please take the time to remove or hide the elements that depend on components your LTSC users deliberately do not have. Do not leave people staring at a prompt they can never fulfill. That is not a small thing when you are managing a fleet of business machines and your users are asking why something that looks like it should work simply does not.

Do better with the details, Microsoft. Your enterprise customers are counting on it.

Friday, October 12, 2018

Proper Documentation REQUIRED!

I have been in IT since 1989. Twenty-nine years in the field, twenty-five of them as paid professional engagements. My first computer was a Macintosh SE with dual floppy drives, no hard drive, and 1MB of RAM. I say that not to date myself, but to establish that I have seen a lot of what works and a lot of what does not.

Recently, I took over full responsibility for the IT organization at Virtual Instruments. My background has always been rooted in infrastructure: servers, routers, switches, endpoints. Taking on the application side of the business was a new challenge, and what I found when I got there was instructive in the worst possible way.

From Order to Chaos, and Back Again

I joined Virtual Instruments in 2009. On paper, I am employee number 76, and I am one of a small handful of people who have been with the company from its earliest days to now. During that time, the applications division was always a separate world from infrastructure.

For a while, it was run well. A Director of Applications named Anne was exceptional at her job. She had the skills, the discipline, and the professionalism to run a tight operation. You always knew where things stood. When she left in 2015, that position was not backfilled, and the vacuum it created had consequences that lasted years.

From late 2015 through early 2018, the applications team existed largely in firefighting mode. Too many tasks, not enough oversight, and no consistent framework to work within. A lot changed during that period. Almost none of it was documented.

When I took over in 2018, my first priority was to bring stability and industry best practices to a department that had been operating in the dark. That meant a significant amount of reverse engineering.

We use an ERP system that has no native integration with our CRM or warehouse platform. To bridge that gap, we rely on middleware, specifically Dell Boomi, to move orders between systems. What I found when I started digging into the existing Boomi workflows ranged from straightforward and logical to genuinely difficult to interpret. Some processes had multiple forked paths that seemed to meander without clear purpose. Staring at someone else's undocumented code and asking yourself what they were trying to accomplish is a frustrating and time-consuming way to run an IT operation.

It does not have to be this way.

Documentation Is Not Bureaucracy. It Is Respect for the Next Person.

I have lived by one principle throughout my career: there is no acceptable reason for an IT professional to skip proper documentation. None. Not timeline pressure, not team size, not the assumption that you will always be there to explain it yourself.

The framework I keep coming back to is ITIL. If you are not familiar with it, here is the short version. ITIL 3.0 is an industry standard framework that structures IT service management into five stages:

  • Service Strategy
  • Service Design
  • Service Transition
  • Service Operations
  • Continual Service Improvement

Service Strategy aligns IT activities with the core needs of the business. Service Design creates and adapts services to support those needs. Service Transition moves systems through change management, testing, and knowledge transfer. Service Operation manages day-to-day events and incidents. Continual Service Improvement identifies opportunities to do things better over time.

Working within a framework like ITIL or COBIT makes undocumented work structurally difficult. The discipline is built in. When my predecessor operated without any framework, critical context was lost the moment a project closed. No notes. No decision rationale. No institutional knowledge. Just systems running on logic nobody could fully explain anymore.

Good documentation paired with sound architectural decisions creates systems that are manageable. The absence of both creates systems that are fragile and expensive to maintain.

The Tools That Made a Difference

Choosing the right framework is only part of the answer. You also need tools that support the work without getting in the way. Here is what we put in place:

Atlassian Confluence became our documentation hub. Of all the wiki-style platforms I have evaluated, Confluence is the most intuitive and flexible. The tool has to disappear into the work. If people are fighting the interface, they are not documenting.

A proper helpdesk and ticketing system is non-negotiable. Every IT team, regardless of size, needs a way to track incidents and requests. Metrics depend on it. Accountability depends on it.

GitHub gave our application team a place to store and version their code. Infrastructure teams may not use it daily, but for any team writing or managing scripts and integrations, it is indispensable.

Monday.com helped bring visibility to complex, multi-phase projects with a lot of moving parts and stakeholders who needed to stay informed without being in every meeting.

Slack improved day-to-day communication and collaboration across the team in ways that email simply cannot match.

Where We Are Now

Today, the applications team is visible, accessible, and effective. We are doing more with a lean, skilled group, supplementing with contractors when we have genuine technical gaps to fill. We are methodically working through systems that were previously black boxes, exposing what is inside, documenting what we find, and building a foundation that the next person can actually work from.

The lesson is simple. No IT team is too small to operate with discipline and documentation. A team of two people benefits from a framework. A team of five people needs one. The investment in doing it right the first time pays back every single time someone has to touch that system after you.

Document your work. Every time. No exceptions.

Wednesday, September 12, 2018

Apple Announcement Day - Fall 2018

I am not going to run through predictions or spec leaks. There are plenty of sites better positioned for that. What I do want to talk about is something that deserves more direct attention: the death of the sub-$1,000 smartphone.

The iPhone has been around for just over ten years. In that time, the price has climbed steadily while the subsidized carrier model that once softened that climb has quietly disappeared. Today you essentially have two realistic options: buy the phone outright, or spread the same full retail cost across 12 or 24 monthly installments. Either way, you are paying the same amount. The installment plan just makes it easier not to notice.

I bought an iPhone X outright last year. $1,200 for the 256GB model, before tax, plus whatever time I spent waiting in line. Apple's cost to manufacture that phone was approximately $400. That is a $600 margin on a single device.

Here is how the numbers have looked across every base iPhone model over the years:

ModelDateBuild CostRetail Price
iPhoneJun 2007$220$499
iPhone 3GJul 2008$174$199
iPhone 3GSJun 2009$179$199
iPhone 4Jun 2010$187$199
iPhone 4SOct 2011$188$199
iPhone 5Sep 2012$194$199
iPhone 5CSep 2013$173$99
iPhone 5SSep 2013$198$199
iPhone 6Sep 2014$211$199
iPhone 6SSep 2015$211$649
iPhone 6S+Sep 2015$236$749
iPhone SEMar 2016$160$399
iPhone 7Sep 2016$224$649
iPhone 7+Sep 2016$277$769
iPhone 8Sep 2017$247$699
iPhone 8+Sep 2017$295$799
iPhone XSep 2017$370$999
iPhone XSSep 2018$999
iPhone XS MaxSep 2018$370$1,099
iPhone XRSep 2018$749

The pattern is clear. Carrier subsidies began disappearing around the iPhone 6 era, a transition that started in 2013 and was essentially complete by the time the iPhone 7 launched. Retail prices jumped immediately and have not looked back.

The XS, XS Max, and XR were all announced today. The era of the sub-$1,000 iPhone is over.

There are alternatives worth considering. OnePlus continues to produce excellent Android hardware at prices that make Apple's lineup look difficult to justify on value alone. But if you are deeply embedded in the Apple ecosystem and have no interest in leaving it, you are going to keep paying. The ecosystem lock-in is real, and Apple knows it.

The Apple Watch tells a similar story. I bought a Series 3 with cellular last September for $429. Today Apple announced the Series 4, and the base model without cellular starts at $429. Add cellular and you are at $529. That is a $100 increase for the same feature I was already paying for.

To refresh both my phone and my watch in 2018 would cost me somewhere around $1,800.

Here is where I landed. The Series 4 watch is worth the upgrade. The EKG capability alone justifies it for me. The phone is a different calculation. The XS is an "S" year, which historically means refinement rather than reinvention. I am going to wait for the reviews, specifically around camera performance and the practical value of the upgrades, before I decide whether the cost is worth it this cycle.

Apple makes extraordinary products. But at some point the value conversation has to happen honestly, and that point is now.

Tuesday, July 7, 2015

Find My Mac: Good Idea, Incomplete Execution

In IT, stolen hardware is a fact of life. Laptops walk out the door. It happens in offices, coffee shops, airports, and cars. So when Apple extended its Find My iPhone feature to the Mac platform through iCloud, it should have been a meaningful step forward. The problem is that on the Mac side, it falls well short of what it could and should be.

Here is why this matters. The Activation Lock feature Apple introduced for iPhones has produced measurable results. A New York City Police Department report from October 2014 showed that iPhone thefts dropped 19% and grand larcenies involving Apple devices dropped 29% after Activation Lock launched. CNET reported shortly after that stolen iPhone volumes dropped 25% in New York, 40% in San Francisco, and 50% in London in the twelve months following the feature's introduction. Those are not small numbers. The feature works.

So why does the Mac version not work the same way?

Find My Mac exists, but it has a fundamental weakness: wiping the machine defeats it entirely. A thief who knows what they are doing can erase the drive, reinstall the operating system, and the device has no memory of who it belonged to. The serial number to iCloud account association disappears. The machine becomes anonymous.

That does not have to be the case, and fixing it does not require a dramatic rethinking of how Macs work.

Every Mac periodically checks for software updates. That is already built in. Why could that check-in process not also include a reference back to iCloud to verify whether the device's serial number is associated with an account? If it is, and the machine has been wiped and a new iCloud account is being added, the system could simply respond: this Mac is already registered to another account. Just like an iPhone. Just like an iPad.

The responsibility chain would mirror what already exists in the iOS world. If you are selling a Mac, you remove the activation lock before handing it over. If you are buying one, you verify the lock is clear before completing the purchase. Simple, familiar, and already proven to reduce theft.

The serial number is permanent. The iCloud association does not have to disappear just because someone reformatted the drive. Keeping that link intact across a wipe is technically achievable, and the real-world impact on theft rates would likely mirror what we have already seen on iOS.

Apple has built the foundation. The logic for how this should work is straightforward. The data showing it would make a difference is already there.

Apple, if you are hiring, I am available.

Tuesday, February 18, 2014

Old Poems I Dredged Up from the Internet

 I stumbled across these recently while wandering through the older corners of the web. They are mine, written back in 2001 when I apparently had a lot of feelings about computers and a lot of time to put them into verse. I am sharing them here partly for the sake of preservation, and partly because they still make me smile.

Tuesday, December 3, 2013

macOS 10.9.1 Mavericks Beta and World of Warcraft

 I have been running the Mavericks 10.9.1 beta for about a week, and overall it addresses a solid number of the usability issues that shipped with 10.9. So far so good, with one very specific and very annoying exception.

The system is kernel panicking and rebooting spontaneously, and I cannot pin it to anything except World of Warcraft. Ripping CDs, streaming music, general use — all fine. The moment I sit down to play, it is only a matter of time before the OS halts and restarts with no useful detail about what caused it. Every single time, it is during gameplay. Nothing else triggers it.

I am choosing to believe the operating system has developed opinions about how I spend my free time.

To verify the issue is actually tied to the 10.9.1 beta and not something deeper, I am rolling back to 10.9.0. If the problem disappears, that confirms it. If it does not, I may have to drag my dual Xeon tower in from the garage to keep the WoW habit alive and the Mac out of trouble.

More to follow once I have results.

Today, the world feels a little quieter, a little dimmer.

We knew this day would come, but we held onto the hope that there would be more time. John Michael "Ozzy" Osbourne—our beloved Pri...