[{"content":"This is Part 1 of Christian Apologetics: A Comprehensive Guide.\nFoundations: What Apologetics Is # Defining Apologetics # Apologetics, as I use the term here, includes defensive and offensive arguments for Christianity, the claims made by Jesus in the Gospels, and the claims made by the apostles in the New Testament. Because Jesus referenced other books of the Old Testament, and the apostles referenced those books and even wrote additional books of the New Testament, apologetics ends up encompassing thousands of years of writings that make claims about everything ranging from the origins of the universe to minute historical details about obscure people and places. The list of topics that apologetics must cover is practically endless.\nUnanswered Questions vs. Sound Arguments in Apologetics # If Christianity is true, then every piece of evidence should support the Christian faith. In other words, there should be no sound arguments against Christianity. But it\u0026rsquo;s crucial to note that an unanswered question isn\u0026rsquo;t the same as a sound argument. Apologetics won\u0026rsquo;t be able to answer every question, and that isn\u0026rsquo;t unique to apologetics.\nThere are still unanswered questions about gravity, but that doesn\u0026rsquo;t mean gravity doesn\u0026rsquo;t exist. Human knowledge is limited, so we can\u0026rsquo;t exhaustively know everything. But we can know some things truly.\nSome people get tripped up here by thinking that if we can\u0026rsquo;t know everything, then there\u0026rsquo;s a possibility that what we think we know is wrong. Maybe someday we\u0026rsquo;ll discover some fact that renders all of our present facts obsolete. This kind of thinking traps us in a never-ending cycle of complete skepticism and the inability to know anything.\nSuppose we did discover some new fact X that upset our existing beliefs. There would still be the possibility of some other new piece of knowledge that would then upset the belief in X. And so on. We shouldn\u0026rsquo;t use a lack of exhaustive knowledge as an excuse to feign ignorance about things we do actually know truly.\nWhy Christianity Isn\u0026rsquo;t Obvious to Everyone # The word apologetic simply means to speak in defense of something. It\u0026rsquo;s typically used in the context of defending a set of religious propositions, such as:\nGod exists He created the universe Humans sin, and their sin has separated them from God Jesus is God in human form He died on the cross and rose from the dead Only those who confess that Jesus is God and believe that He rose from the dead can be forgiven and go to heaven \u0026hellip;and so on.\nChristianity has been around for 2,000 years, so you\u0026rsquo;d think that everything that could have been written in its defense has already been written. That\u0026rsquo;s partly true, but it needs some clarification.\nArguments for different aspects of Christianity have been around a long time. As we learn more about the world, we occasionally come up with new arguments (or new evidence for existing arguments) based on new discoveries. This might seem surprising if you\u0026rsquo;ve heard the claim that \u0026ldquo;science disproves\u0026rdquo; some aspect of Christianity. In fact, the entire history of science has been one finding after another that aligns with Scripture, especially in biology and cosmology, which also surprises a lot of people. For example, the discovery of intact dinosaur blood cells, soft tissue, and collagen supports the Bible\u0026rsquo;s record of a relatively young earth.\nThat\u0026rsquo;s just one example. The point is that not a single scientific discovery has ever contradicted the Bible. Any so-called \u0026ldquo;science\u0026rdquo; that supposedly disproves some aspect of Christianity is always purely theoretical, un-empirical, and hardly worthy of being called science at all. I\u0026rsquo;ll circle back to this later.\nSo shouldn\u0026rsquo;t Christianity be obvious to everyone if it\u0026rsquo;s true? The fact is that most people don\u0026rsquo;t pay attention and just don\u0026rsquo;t know things that might seem obvious to someone else. I am constantly seeing posts on social media from people sharing the most obvious \u0026ldquo;today I learned\u0026rdquo; observations, things I\u0026rsquo;ve known for decades. If you look at the comments, you\u0026rsquo;ll see some people saying they learned something new, and others saying it\u0026rsquo;s obvious and they\u0026rsquo;ve known it for years.\nIf there\u0026rsquo;s a clear knowledge gap among people when it comes to trivial things, imagine how much bigger the gap is when it comes to a topic as significant as Christianity. So the answer is no. Many things, ranging from the mundane to the complex and wonderful, including Christianity, are not obvious to everyone.\nIgnorance Is the Enemy of Christianity # A lot of people have never heard good arguments for Christianity, and mistakenly believe that no good arguments exist. There are also a lot of bad arguments against Christianity that many people have heard, and they think they\u0026rsquo;re actually good arguments simply because they haven\u0026rsquo;t heard any alternatives or rebuttals.\nIt\u0026rsquo;s like if you grew up eating nothing but cheap school cafeteria food, and the lunch ladies always told you that you were eating the best food in the world. There was nothing better out there, and you believed it because you had never tasted anything better. Then one day a world-class chef comes and prepares a meal, and you suddenly realize you\u0026rsquo;ve been missing out on really great food all those years.\nIt\u0026rsquo;s the same with knowledge and understanding. If you\u0026rsquo;ve been consistently fed outdated, incorrect, and even illogical nonsense, you might just subconsciously assume that it\u0026rsquo;s the truth and that there\u0026rsquo;s nothing better out there. The goal of apologetics is to take off the blinders, correct errors, and fill in the blanks so that you can arrive at the correct conclusions on your own, fully convinced and persuaded, not just indoctrinated.\nTo be blunt, most arguments against Christianity are dumbed-down zingers that appeal to emotion but are intellectually empty, illogical, and sometimes just obviously false. It\u0026rsquo;s important to address those because they appeal to popular misconceptions, myths, and assumptions that people aren\u0026rsquo;t even aware of.\nAddressing Common Myths: The Dinosaur Fossil Example # Atheists often claim that dinosaurs existed millions of years ago, and use the supposed age of dinosaur fossils as proof. If this is true, then the literal creation account of Genesis can\u0026rsquo;t be correct, since it claims God created the world in six literal days. This claim was reiterated by Jesus in the New Testament. If we look at the rest of Scripture and the dates and genealogies provided, the Bible indicates that this creation event happened about 6,000 years ago. So there\u0026rsquo;s a clear contradiction between the secular millions-of-years claim and the Bible.\nBut many people aren\u0026rsquo;t aware that we have dinosaur fossils containing actual dinosaur blood vessels, blood cells, and proteins (including collagen), which couldn\u0026rsquo;t be possible if these fossils were millions, or even hundreds of thousands, of years old. Some have tried to explain this away by saying iron preserved the tissues. It\u0026rsquo;s pretty obvious that iron cannot preserve anything for millions of years. Even our most sophisticated modern food preservation processes can only preserve food for maybe a few thousand years under the right conditions.\nSo, no, dinosaur soft tissue was not preserved for millions of years. Therefore, it\u0026rsquo;s not only reasonable but actually scientific to conclude that dinosaurs existed recently enough that their soft tissue has been preserved.\nThe point of this example isn\u0026rsquo;t to suggest that apologetics rests on dinosaur fossils. After all, we didn\u0026rsquo;t even know dinosaurs and their fossils existed until a few hundred years ago. The point is that atheists sometimes use new discoveries to try to disprove some aspect of Christianity, usually the timeline and historicity, only to have it backfire on them. Dinosaurs are just one example of that.\nThe Fundamental Question # The Terminal Objection # Apologetics, and all discussions on origins and religion, always come down to the same question.\nWhy did God do things the way He did?\nRegardless of the topic, a discussion touching on apologetics is always going to wind up at this question, which I call the terminal objection. Sometimes it\u0026rsquo;s phrased as a question, as above. Other times it\u0026rsquo;s phrased as a statement.\nHere\u0026rsquo;s an example of the terminal objection couched as a question. One popular argument asks something like, \u0026ldquo;If there were a loving God, why would He allow x, y, and z?\u0026rdquo; where x, y, and z are bad things such as suffering, disease, and natural disasters. This argument is sometimes hedged with the proclamation, \u0026ldquo;I wouldn\u0026rsquo;t want to worship a God that does things that way.\u0026rdquo; So, at least for some atheists, their argument against God isn\u0026rsquo;t against His existence but against what He does or doesn\u0026rsquo;t do. This is an example of the atheist hedging his bets by essentially saying, \u0026ldquo;Even if God exists, He didn\u0026rsquo;t do enough to win me over.\u0026rdquo;\nOf course, some atheists are purely naturalist and materialist, and don\u0026rsquo;t believe in any supernatural beings at all, so for them the question is moot. They look at the world and assume that if God existed, He wouldn\u0026rsquo;t allow certain things to happen, and the world would look entirely different than it does now. They conclude that God doesn\u0026rsquo;t exist.\nYou might recognize that this argument, regardless of form, rests on a false dichotomy:\nOption 1: \u0026ldquo;Either God exists and operates the way I think He should.\u0026rdquo; Option 2: \u0026ldquo;He doesn\u0026rsquo;t exist at all.\u0026rdquo; This is a false choice because there\u0026rsquo;s a third possibility:\nOption 3: \u0026ldquo;God exists and doesn\u0026rsquo;t operate the way I think He should.\u0026rdquo; Recognizing the false choice, many people who call themselves atheists go a step beyond it. They might say something like, \u0026ldquo;If God exists, then He allowed x, y, z, and therefore I don\u0026rsquo;t want to follow Him.\u0026rdquo; The unspoken assumption is that God didn\u0026rsquo;t have a good reason for allowing x, y, and z. So again, we\u0026rsquo;re back at the terminal objection.\nIf you pay close attention, you\u0026rsquo;ll see atheists swing this pendulum back and forth. They\u0026rsquo;ll claim there\u0026rsquo;s no good evidence for God, and then when you point out some evidence, they bring up the terminal objection, not as a rebuttal of the evidence, but as a distraction from it.\nUltimately, the atheist is looking for reasons, or excuses, not to believe.\nForms of the Terminal Objection # The terminal objection isn\u0026rsquo;t always so obvious. It comes up in the form of many different questions, such as:\n\u0026ldquo;Why doesn\u0026rsquo;t God regularly proclaim Himself audibly or visibly in no uncertain terms from the heavens?\u0026rdquo; The idea is that this would remove any argument that there\u0026rsquo;s no evidence for God.\n\u0026ldquo;Why doesn\u0026rsquo;t God speak to each person individually in the way that will be most convincing to them?\u0026rdquo; The idea is that God could personally persuade each individual, customizing His approach to their personality.\n\u0026ldquo;If God wanted people to believe in Him, why wouldn\u0026rsquo;t He do a, b, and c?\u0026rdquo; This is a variation of the previous question, but with the assumption that a, b, and c are things that would convince everyone.\n\u0026ldquo;If God is good, loving, powerful, and just, then why does He allow evil instead of stopping it?\u0026rdquo; The idea is that God could lock everyone in their own invincible bubble, preventing physical harm from coming to them. He could stop people from vocalizing mean thoughts before the words ever left their mouth. He could even supernaturally shock people whenever they started to have a bad thought.\n\u0026ldquo;Why did God design creatures to look or behave a certain way?\u0026rdquo; He could have made animals without claws, teeth, or venom, and the claim goes, that would prevent some suffering.\nYou could probably think of some more.\nTo be clear, I don\u0026rsquo;t think all of these questions are bad. But some people raise them not out of genuine curiosity, but as a thinly veiled objection and an excuse to reject God by either denying His existence or denying that He\u0026rsquo;s worthy of worship. The implication is that the person asking the question thinks that their suggestion would be more effective than whatever God is, or isn\u0026rsquo;t, doing. It\u0026rsquo;s pride.\nFailure to understand something is not an argument against it. We have all seen people do things that didn\u0026rsquo;t make any sense to us. That doesn\u0026rsquo;t mean they didn\u0026rsquo;t do it, and it certainly doesn\u0026rsquo;t mean they don\u0026rsquo;t exist.\nSeeing Is Not Necessarily Believing # Now, let\u0026rsquo;s get to the questions. Why doesn\u0026rsquo;t God speak to each person individually? I believe God has tried this in the past, and it doesn\u0026rsquo;t work.\nIn the Garden, God spoke directly to Adam and Eve. But they didn\u0026rsquo;t listen.\nGod spoke directly with their children, and some of them didn\u0026rsquo;t listen either.\nAll throughout the Bible, God speaks to people directly and audibly, as well as through intermediaries, and in general, those people don\u0026rsquo;t listen.\nI once heard an atheist ask why God doesn\u0026rsquo;t write something in the sky to convince everyone He exists. If He did this, people would find excuses not to believe it. Some would say it\u0026rsquo;s a hoax, others would say it\u0026rsquo;s a hallucination, and some might believe. People would no doubt take pictures and videos, and there would be stories written about it. But 100 years later, what would people say? They would say the pictures and videos are fake, or they would ask why God doesn\u0026rsquo;t still write in the sky if He\u0026rsquo;s real, and so on. Even if God wrote in the sky every minute of every day, people would find excuses to dismiss it. Seeing is not necessarily believing.\nSo while the thought of God speaking to everyone individually might sound appealing, a quick study of human history shows that people will not believe what they don\u0026rsquo;t want to believe.\nNext: Part 2: Knowledge, Belief, and Logic →\n","date":"5 July 2023","externalUrl":null,"permalink":"/apologetics/part-1-foundations/","section":"Christian Apologetics: A Comprehensive Guide","summary":"","title":"Part 1 Foundations","type":"page"},{"content":"","date":"17 August 2026","externalUrl":null,"permalink":"/categories/apologetics/","section":"Categories","summary":"","title":"Apologetics","type":"categories"},{"content":"","date":"17 August 2026","externalUrl":null,"permalink":"/","section":"Ben Piper","summary":"","title":"Ben Piper","type":"page"},{"content":"","date":"17 August 2026","externalUrl":null,"permalink":"/categories/","section":"Categories","summary":"","title":"Categories","type":"categories"},{"content":"","date":"17 August 2026","externalUrl":null,"permalink":"/tags/christianity/","section":"Tags","summary":"","title":"Christianity","type":"tags"},{"content":"","date":"17 August 2026","externalUrl":null,"permalink":"/tags/epistemology/","section":"Tags","summary":"","title":"Epistemology","type":"tags"},{"content":"","date":"17 August 2026","externalUrl":null,"permalink":"/tags/logic/","section":"Tags","summary":"","title":"Logic","type":"tags"},{"content":"This is Part 2 of Christian Apologetics: A Comprehensive Guide.\nEvidence Is Not Believing # Modern atheists and agnostics (people undecided on the matter) wield the terms \u0026ldquo;evidence\u0026rdquo; and \u0026ldquo;science\u0026rdquo; to present reasonable-sounding objections like:\n\u0026ldquo;I don\u0026rsquo;t see evidence that God exists.\u0026rdquo; \u0026ldquo;I don\u0026rsquo;t see evidence that the universe was created.\u0026rdquo; But if you think carefully, behind these objections are a lot of assumptions about what God would do and how He would do it.\nInterpreting Evidence for God vs. Ignoring It # Atheists and agnostics claim there\u0026rsquo;s no evidence for God, but there is plenty of evidence for God. They just say it doesn\u0026rsquo;t count. They dismiss it as not good enough, insufficient. They don\u0026rsquo;t believe in God because He hasn\u0026rsquo;t shown Himself to them in the way they think He should. They say there are better alternative explanations, and even if those alternative, naturalistic explanations lack sufficient evidence, they still prefer those explanations and give them more weight than the possibility of God.\nThe issue then is not lack of evidence, but how we interpret it. Evidence for anything can always be explained away. For example, there are people who argue for a flat Earth and find some very creative reasons to explain away all the evidence that the Earth is a sphere floating in space. Atheists present the same class of objections to evidence for the existence of God. But no matter how you slice it, all arguments against God (and, by extension, origins and Christianity as a whole) come down to the objection: \u0026ldquo;If God were real, He would have done things differently. And because He didn\u0026rsquo;t, I don\u0026rsquo;t believe.\u0026rdquo;\nCriteria for Belief # People are convinced of different propositions for different reasons. What convinced you may not convince others. There is no such thing as a knock-down, drag-out argument that will convince everyone. Not because there are no good arguments, but because belief is a choice.\nThis is true for any claim, not just those of Christianity. We see this all the time in high-profile cases where someone famous is accused of a crime. Everyone sees the same evidence, but some weigh certain pieces of evidence more heavily than others. In fact, in many of these cases, people are convinced of someone\u0026rsquo;s guilt or innocence based on superficial things such as the way the accused looks, dresses, or carries himself. Belief, then, doesn\u0026rsquo;t depend just on having some evidence, but on having enough evidence to overcome other barriers to belief.\nApologetics is about removing barriers to belief, so we need to identify the barriers and remove them. Removing such barriers typically requires additional evidence against the barriers themselves. So the job of apologetics is not just to provide evidence for Christianity, but to provide evidence against the things that get in the way of belief. In short, apologetics involves providing a mountain of evidence.\nProperly Basic Beliefs # There are some beliefs we all (mostly) have in common, such as the belief that we live on earth, breathe air, eat, and exist. These beliefs are not the result of argument. They just seem right, make sense, and are obvious. These are called properly basic beliefs.\nMany properly basic beliefs come about as we learn new information. When you learn that 2+2=4, a lightbulb goes on and you just see how it\u0026rsquo;s true. You don\u0026rsquo;t necessarily have to be argued into it.\nOther beliefs we may form a bit later, such as belief in God, or belief in Creation over common descent. Some people look around and see that these things are obvious. Others don\u0026rsquo;t. So what\u0026rsquo;s properly basic for one person isn\u0026rsquo;t for another. Some children think and talk about and seem to understand God at a young age, whereas others don\u0026rsquo;t seem to gain this understanding until they get older.\nBeliefs Based on Authority and Evidence # Yet other beliefs we form based on authority. If you were raised in a Christian home, you may come to believe in the resurrection of Jesus based on the teachings of your parents and church. People refer to this as \u0026ldquo;taking it on faith,\u0026rdquo; believing based on trust but not being able to explain why otherwise. This can come up when a Christian child challenges another person\u0026rsquo;s beliefs. The other person asks the child why they believe what they believe, and the child has no answer other than, \u0026ldquo;I take it on faith.\u0026rdquo; (The technical term for believing based solely on faith is fideism.)\nBeliefs may also form based on evidence. You may come to believe in the Resurrection based on historical evidence. Evidence and authority are often tied together. We learn of evidence from a person, and we find the person trustworthy and the evidence convincing. For example, we learn of Pontius Pilate via historical writings (the Bible, Josephus, and others), and our belief in him as a real figure is reinforced by archaeological evidence (which we may see firsthand or read about in a book). None of us have ever met Pilate, and most of us have never personally seen an ancient artifact with his name on it, but our belief that he was a real person is based on an authority telling us about the evidence for him.\nHence, it\u0026rsquo;s a mistake to fall into the trap of believing that evidence and authority are at odds. In practice, most evidence is really the interpretation of an authority. Take, for example, people who believe in evolution and an old earth. They claim to believe based on evidence, but this is actually not the case. How many old-earthers have actually done any of the following?\nViewed fossil strata firsthand Conducted radiometric dating Created calibration curves Carefully weighed neutral evolution against natural selection Studied population genetics And so on. Even most biologists haven\u0026rsquo;t done all of these things.\nThe evidence you receive is filtered through an authority who colors it with their interpretation. (Incidentally, this is a point many opponents of Christianity use against the Bible, claiming it\u0026rsquo;s been tainted over the years, a claim that has been proven false.) This means that even if you have evidence that contradicts an authority\u0026rsquo;s interpretation, that authority might twist the evidence to fit their own interpretation if they\u0026rsquo;re dishonest. Thus, it\u0026rsquo;s best to observe and analyze the evidence for yourself if at all possible. Taking \u0026ldquo;expert\u0026rdquo; opinion at face value without verifying it for yourself is a mistake.\nWhether a person believes in Christianity comes down to basic beliefs, interpersonal trust, philosophy, seeking out and interpreting evidence for oneself, and choice. This is hard work, and no one can do it for you. It\u0026rsquo;s easier to just pick a favorite authority and believe what they say without doing your own research. Unfortunately, this is the easy path many people take.\nWe also have to consider this. If Christianity is true, then we all have a sinful nature that can get in the way of believing something that\u0026rsquo;s true. Hence, failure to believe may not be due to lack of evidence or trust, but rather a willful refusal. Our sinful nature leads us to lie to ourselves.\nEstablishing Final Authority # Apologetics comes down to establishing a final authority, and all claims of final authority are to some degree circular.\nWho is the ultimate authority over students in a classroom? The teacher has authority, but he gets his authority from someone else, perhaps the headmaster of the school. But where does the headmaster get his authority? Maybe he was appointed by a board of trustees. Okay, where did they get their authority? Probably from the parents of the students. But where did the parents get their authority? Eventually, this line will end at one person, and that person is the ultimate authority. Why? The only logical answer is \u0026ldquo;because they said so,\u0026rdquo; because if that person appeals to a higher authority, then they\u0026rsquo;re not really the highest.\nConsider two competing theories about the origin of life. One theory is that God created living things. Call this creationism or intelligent design. The other theory, naturalism, holds that life arose through unknown natural processes. In creationism, God is the ultimate authority. Why? Because He\u0026rsquo;s the creator, and He says so. That\u0026rsquo;s a circular argument, but it\u0026rsquo;s valid because there is no other option. If God is eternal, and He created all things, He\u0026rsquo;s the final authority.\nIt\u0026rsquo;s worth noting here that the root word of \u0026ldquo;authority\u0026rdquo; is \u0026ldquo;author,\u0026rdquo; which means \u0026ldquo;father\u0026rdquo; or \u0026ldquo;creator.\u0026rdquo; By virtue of being the creator, one is de facto the authority over the creation.\nNow consider the naturalistic theory. Who\u0026rsquo;s the ultimate authority here? There are only two options. The first option is that nature was created, and the creator is the final authority. The second option is that nature is eternal, and thus must be the ultimate authority.\nThis is where it gets interesting, because people who consider themselves naturalists will actually make contradicting claims that seem to support both options. But if you really press them, most naturalists will favor some variation of nature (matter and energy) being eternal. I\u0026rsquo;ll get into the details of that in a moment, but let\u0026rsquo;s first consider the implications of having nature as the final authority.\nThe Problem of Final Authority in Naturalism # Nature is impersonal, so it doesn\u0026rsquo;t actually speak or make claims like a personal being does. Nor can anything in nature be the ultimate authority, for how does one atom have \u0026ldquo;authority\u0026rdquo; over another? Even if we concede that nature is the final authority, such a concession is meaningless and useless.\nSome naturalists are perfectly content with there being no practical, final authority, because it allows them to arbitrarily select their own preferred candidate. Some proponents of naturalism like the idea of having an expert class be the final authority, particularly in matters of science. And why should they be the final authority? Well, because they said so. This is arbitrary, and the naturalist can\u0026rsquo;t justify it. This fact is a point of embarrassment, and you\u0026rsquo;ll see them try to work around it by saying that their choice of authority is based on \u0026ldquo;reason\u0026rdquo; or \u0026ldquo;science\u0026rdquo; or \u0026ldquo;empirical data\u0026rdquo; or something of the sort. But this is all smoke and mirrors, because naturalism can\u0026rsquo;t justify any of those things. You can\u0026rsquo;t prove, in a purely naturalistic view, that reason, science, or empiricism are valid. You can\u0026rsquo;t even prove uniformity of nature, which is what science is based on.\nThe Flaw of Uniformitarianism in Science # If you don\u0026rsquo;t believe me, try this exercise. If you mix baking soda and vinegar right now, you get a reaction. How do you know that if you mix them together tomorrow, you\u0026rsquo;ll get a reaction? The reflexive response for most will be that \u0026ldquo;it has always worked that way in the past, so we have no reason to think it won\u0026rsquo;t work that way in the future.\u0026rdquo; But this is a circular claim. Just because things were repeatable in the past doesn\u0026rsquo;t mean they\u0026rsquo;ll be repeatable in the future. And if you assume that, you\u0026rsquo;re assuming the thing you\u0026rsquo;re trying to prove.\nIf that\u0026rsquo;s confusing, let\u0026rsquo;s break it down some more. You want to prove that the experiment you did today (baking soda and vinegar) will work at any point in the future. To prove this, you cite past examples. But the problem is that those examples are in the past, so all you\u0026rsquo;ve shown is that there was a repeatable pattern in the past. You still haven\u0026rsquo;t shown that such a pattern will hold into the future. Remember, you\u0026rsquo;re trying to prove that the experiment will work tomorrow, not just that it worked in the past. How can you possibly prove this beforehand? The only way is to appeal to some evidence that the universe is governed by some power that guarantees today\u0026rsquo;s chemical reactions will work the same way tomorrow. But in the naturalistic view, there is no such overarching power to appeal to. The naturalist just has to \u0026ldquo;take it on faith\u0026rdquo; that our very limited past observations of the universe paint an accurate and predictable picture of the future.\nComplicating matters even more for the naturalist is the idea that the universe as we see it today was not always the way it is now. Planets and stars formed, living things came into existence, temperatures changed, and so on. This undercuts the naturalist\u0026rsquo;s argument for uniformitarianism.\nGetting back to the discussion on authority, in naturalism, making claims of final authority is a free-for-all. The expert class can claim to be the final authority, but they can\u0026rsquo;t justify this any more than a talking parrot could claim to be the final authority. In naturalism, there is no inherent hierarchy of authority, only an infinite regress into the past.\nNaturalists will try to solve this problem by referring to some kind of quasi-origin event, like the \u0026ldquo;big bang.\u0026rdquo; But since the \u0026ldquo;big bang\u0026rdquo; idea posits that the singularity (or its source) is eternal, you essentially wind up at the belief that the universe as a whole is eternal. This tension is easily seen in naturalistic models that attempt to explain the origin of matter and energy by appealing to pre-existing matter and energy. \u0026ldquo;Quantum\u0026rdquo; is a word that gets invoked almost as a magic spell to explain matter and energy, but the problem is that \u0026ldquo;quantum\u0026rdquo; anything assumes existing matter or energy.\nIn naturalism, there\u0026rsquo;s no single, final authority. There\u0026rsquo;s just stuff.\nDefining Knowledge # When practicing apologetics, we have to start on common ground. Christians will not agree with non-Christians on issues of final authority. But usually we can find common ground and a good starting point by settling on a definition of knowledge.\nWhat is knowledge? Plato said it\u0026rsquo;s justified true belief. According to Plato, what is justified is that which we can perceive with our senses or reason.\nBut is this right? If I remember having corn flakes for breakfast last Monday, my senses and reason don\u0026rsquo;t tell me that. I\u0026rsquo;m relying solely on my memory, which ostensibly contains a recollection of what my senses perceived in the past. But can I really know I had corn flakes? Put another way, how can I know that my memory is always accurate? We all know that memory is not always completely accurate.\nOnce again, the naturalist is in a pickle. He has no justification to believe that his senses or his memory are reliable, for the same reasons that he has no justification to believe in uniformitarianism. He just \u0026ldquo;takes it on faith\u0026rdquo; that his senses are good enough.\nOn the other hand, the Christian who believes the universe, our senses, and our minds were created by God does have a rational justification for believing our senses. If the universe is orderly and governed by laws, and God created our senses, even though they might be wrong sometimes, we can be assured that overall, they function well enough to let us paint a mostly accurate picture of our experiences.\nCombining Evidence to Establish Truth # What we really care about is whether our senses and memories are accurate when it comes to important things. And there is nothing more important and weighty than life itself. In Deuteronomy 17:6, the Bible offers the following prescription for establishing knowledge one way or the other:\nWhoever is deserving of death shall be put to death on the testimony of two or three witnesses; he shall not be put to death on the testimony of one witness.\nOur senses can be somewhat unreliable, but overall they work well enough to function. Reason allows us to take sensory input and apply logic to reach conclusions. By combining the evidence of multiple witnesses (people, physical evidence, and reason), we can indeed have true knowledge of some things. We can\u0026rsquo;t know everything, but we can know some things with certainty.\nAlthough the naturalist doesn\u0026rsquo;t have a rational justification for trusting his senses, it\u0026rsquo;s beneficial that he does, because it gives us common ground on which to start. Note that common ground is not the same as neutral ground, because there is no such thing. In reality, the naturalist, by trusting his senses, essentially concedes a very important point to the Christian apologist.\nReason and No Sense # Reason gives us evidence of things that our senses cannot detect. Have you ever been dreaming, and in your dream you were fully aware that you were in a dream? None of your five senses told you that you were dreaming. Yet you were able to reason that what was going on in your mind was not real.\nNow here\u0026rsquo;s a brain teaser. Let\u0026rsquo;s say you tell someone else about your dream, and they insist, \u0026ldquo;No, you were not dreaming. What you heard and saw was real. It was not a dream.\u0026rdquo; After giving them the side eye for a moment, how would you answer?\n\u0026ldquo;I know I was dreaming! It seemed like a dream, and the things that happened in it wouldn\u0026rsquo;t happen in real life. I woke up shortly after, I was in my bed, and the dream was over.\u0026rdquo;\nYour opponent isn\u0026rsquo;t satisfied and retorts, \u0026ldquo;Sorry, that\u0026rsquo;s not good enough. You have to give me empirical evidence that you were not dreaming.\u0026rdquo; What would you say? You simply can\u0026rsquo;t provide empirical evidence for an experience that only you had. Is your opponent reasonable to doubt you? Of course not.\nThis is how skepticism makes knowledge impossible. With enough thought, you can talk yourself into doubting anything. Look around you. Are you really where you think you are? You could be dreaming or in a simulation. There\u0026rsquo;s no way to tell that you\u0026rsquo;re not. Maybe your senses are lying to you. What makes the belief \u0026ldquo;this is real\u0026rdquo; more rational than the belief \u0026ldquo;this is a simulation or a dream\u0026rdquo;?\nInnate Knowledge and Basic Beliefs # It comes down to your basic beliefs. We are wired to believe certain things. Babies are wired to trust their senses. Some of their perceptions don\u0026rsquo;t seem to make sense to us, such as fear of a cereal bar with a certain pattern. Incidentally, there\u0026rsquo;s a popular but unproven theory that babies\u0026rsquo; senses are all mixed up. For example, the theory goes, they can see sounds or hear what they see. If true, then relying purely on the five senses could lead a baby to develop very wrong beliefs about the world early on. What we see is the opposite. Babies have innate knowledge of physics and mathematics.\nAgain, the naturalist can admit that we are born with some knowledge about the world. But he can\u0026rsquo;t rationally justify it on his own worldview. There\u0026rsquo;s no rational reason to think that naturalistic processes imparted humans with knowledge about both the material (physics) and the non-material (math). Naturalists just \u0026ldquo;take it on faith.\u0026rdquo;\nThe Christian, on the other hand, doesn\u0026rsquo;t have to take it on faith. The Christian has a rational justification for believing that the knowledge about the world that we\u0026rsquo;re born with is reliable, that we were created by God and He gave us our instincts, senses, and innate knowledge (see Romans 2:15).\nHuman Reason Is Not the Final Arbiter of Truth # If naturalism is true, then human reason can possibly lead us to the truth about things key to survival, such as where the food is or how to avoid getting hurt. However, it\u0026rsquo;s just as possible that human reason could lead us to completely wrong but useful conclusions about the world. In fact, the idea of evolution (specifically neo-Darwinism, common descent via natural selection) specifically posits that organisms evolve in ways that are useful to reproduction. For example, having a working nose, eyes, and tongue can help an animal determine whether a given fruit is edible. That\u0026rsquo;s useful, but it doesn\u0026rsquo;t necessarily lead to knowledge about the fruit.\nEvolution vs. True Knowledge # Essentially, in evolution, organisms are just running algorithms. \u0026ldquo;If a substance triggers certain olfactory nerves and a gag reflex, do not eat. If a substance triggers other olfactory nerves and causes salivation, eat.\u0026rdquo; This is not a conscious process, and the animal doesn\u0026rsquo;t know whether a food is good or bad, or even what food is or why it needs to eat. Nor does it need to. Humans, of course, have understanding of all these things, but how does that understanding arise from natural processes? And, more to the point, how can we know that this understanding is correct or even close to correct? If thoughts, understanding, and knowledge are simply chemical processes, why would we assume they\u0026rsquo;re reliable or mean anything at all?\nTo put it more simply, you can operate out of habit without ever understanding why you have the habits you do, where they came from, or even whether they are good or bad. The theory of evolution holds that we just evolved what amount to habits that are useful to reproduction. If this is true (and it\u0026rsquo;s not), why should we expect these habits to give rise to knowledge? After all, if we can get along fine with just innate habits, knowledge would just be another burden to keep up with. Natural selection would not select for the ability to understand and produce true knowledge unless it conferred some reproductive benefit.\nSome would counter that having knowledge does confer many benefits. For example, understanding things that are invisible to the eye, such as viruses and bacteria, offers a huge advantage. If we understand that some bacteria are harmful and some are helpful, we can perhaps avoid the bad ones. This knowledge would certainly be useful. But the problem is that natural selection doesn\u0026rsquo;t operate on what\u0026rsquo;s true. Something is useful to natural selection only inasmuch as it confers a reproductive benefit, regardless of whether it\u0026rsquo;s true or false. It only operates on what\u0026rsquo;s useful to reproduction. So while an understanding of pathology would be useful, there are countless other untrue, completely fictitious but plausible theories that would be equally useful and selectable. For instance, suppose people got the idea that what we know as bad bacteria are evil spirits, and what we know as good bacteria are good spirits, and that these spirits take the form of tiny, invisible things. This would result in the same beneficial behavior, avoiding the bad \u0026ldquo;evil spirits\u0026rdquo; (bacteria). Hence, natural selection could select for this \u0026ldquo;knowledge\u0026rdquo; just as well as it could select for something closer to reality.\nThe Christian Alternative: Special Revelation and the Fall # Now let\u0026rsquo;s look at the alternative. If the Bible is true, then the human mind is fallen and corrupt, and therefore will sometimes be wrong. However, God has given us special revelation, which may protect and guide some of our reasoning so that we can still arrive at correct conclusions. If God wants us to understand certain things, such as His revelation through the Bible, it seems He would protect our reason enough that we may interpret His revelation correctly. This is simple and straightforward, and it avoids all of the problems of naturalism and evolution.\nThere is another thing we have to consider. If the Bible isn\u0026rsquo;t true but some other god created us, then human reason may or may not be corrupt. If there was no fall as recorded in Genesis, and we were created with sound and intact reasoning abilities, we should be able to trust our reason. But if this is true, and we\u0026rsquo;re all operating with the same basic reasoning and aren\u0026rsquo;t corrupt, then there should be more widespread agreement among people. To put it differently, if nothing were broken, humanity wouldn\u0026rsquo;t act and appear broken.\nOne of the key features separating Christianity from other religions is the Fall. In Christianity, Adam and Eve were given one rule, not to eat from the Tree of the Knowledge of Good and Evil. Both disobeyed, which earned them a one-way trip out of the Garden of Eden and a significant change of affairs otherwise. They would have to work for their food, the gestation period would increase, and there would be strife among humans. Essentially, God did not force Adam and Eve to live in perfection but gave them a choice to stay or leave, and they chose to leave.\nMany non-Christian religions attribute the source of evil to a god (if they recognize one) or hold that evil isn\u0026rsquo;t real. One of the more bizarre explanations of evil involves two warring gods. In non-theistic religions that seem more compatible with naturalism (Buddhism, namely), evil is dismissed as a sort of illusion or state of mind rather than an objectively real problem.\nThe existence of evil is the crux of the so-called \u0026ldquo;argument from evil\u0026rdquo; against theistic religions. The argument, as we\u0026rsquo;ve already discussed, is one form of the terminal objection, \u0026ldquo;Why did God do things the way He did?\u0026rdquo; Specifically, why did God prevent or eliminate evil instead of permitting it? The record of the Fall in the Garden of Eden makes it clear that God gave Adam and Eve a choice. He could have not given them a choice and avoided all possibility of them committing evil. He had the power to prevent evil by not giving them a choice, so we know that the existence of evil is not because God is powerless. Clearly, giving people the ability to choose between good and evil was better than forcing everyone to be robots.\nThis raises another question. If God gave Adam and Eve a choice, and God\u0026rsquo;s creation was perfect, why would they choose evil? What we have to understand is that people are not machines or deterministic functions. If we view them as such, we\u0026rsquo;ll think something along the lines of, \u0026ldquo;If a function is perfect, and you plug in input x, you\u0026rsquo;ll get output y every time.\u0026rdquo; And then we apply this reasoning to Adam and Eve and draw the conclusion that they must have been flawed in some way. We have to understand that God created man in His own image. The Scriptures even say to us, \u0026ldquo;you are gods.\u0026rdquo; Among all created things, Adam and Eve had the unique ability to be perfect and still choose not to be perfect. And this makes a lot of sense. If they had no choice but to be perfect and completely, 100% good, their goodness would be an illusion, since they couldn\u0026rsquo;t choose otherwise. This is why we view animals as amoral. They don\u0026rsquo;t have the capacity to choose good or evil. It\u0026rsquo;s only by having the choice between good and evil that humans are even able to be good.\nDoes this mean goodness is dependent on evil? No, because goodness is part of God\u0026rsquo;s eternal nature. Goodness has existed for all of eternity past in the Godhead without evil. Adam, of course, was a created being, and God gave him and Eve the ability to choose whether they would retain the perfect nature they were given or cast it off.\nAs an aside, I\u0026rsquo;ve heard it said that if we were in the same position as Adam or Eve, we would have made the same choice. I don\u0026rsquo;t think that\u0026rsquo;s true. I think another person might have chosen differently.\nLogic # The Law of Non-Contradiction # Logic is the foundation of all thought, and the law of non-contradiction is the foundational law of all logic. The law of non-contradiction goes like this: a proposition cannot be true and false at the same time and in the same sense. For example, \u0026ldquo;You\u0026rsquo;re reading this book\u0026rdquo; cannot be true and false at the same time and in the same sense.\nIf contradictory statements can both be true, then logic doesn\u0026rsquo;t even exist. Suppose I say, \u0026ldquo;People are either male or female. Bob is a person. Bob is not female. Therefore Bob is male.\u0026rdquo; That makes sense.\nNow, if we throw out the law of non-contradiction, the argument could look like this. \u0026ldquo;People are both male and female. Bob is and isn\u0026rsquo;t a person. Bob is and is not female. Therefore Bob is and is not male.\u0026rdquo; (Sorry, Bob.) None of this makes any sense. And if the law of non-contradiction isn\u0026rsquo;t true, then it also is true. Everything I just said does and doesn\u0026rsquo;t make sense.\nEven mathematics breaks down if you throw out the law of non-contradiction. Any number can equal and not equal anything, so 2+2=4 is both true and false. Again, it makes no sense.\nContradictions in Eastern Religions and Relativism # Eastern religions are notorious for teaching contradictory things and couching it with sayings like, \u0026ldquo;Truth is relative.\u0026rdquo; But even those religions still hold to the law of non-contradiction. By even saying, \u0026ldquo;Truth is relative,\u0026rdquo; they\u0026rsquo;re saying, \u0026ldquo;The saying \u0026lsquo;Truth is relative\u0026rsquo; is true.\u0026rdquo; So they\u0026rsquo;re still proposing an absolute truth that is the exception to their own rule. Not surprisingly, they end up contradicting themselves.\nPrevious: ← Part 1: Foundations Next: Part 3: Barriers and Objections to Belief →\n","date":"17 August 2026","externalUrl":null,"permalink":"/apologetics/part-2-knowledge-belief-logic/","section":"Christian Apologetics: A Comprehensive Guide","summary":"","title":"Part 2: Knowledge, Belief, and Logic","type":"page"},{"content":"","date":"17 August 2026","externalUrl":null,"permalink":"/tags/","section":"Tags","summary":"","title":"Tags","type":"tags"},{"content":"","date":"17 August 2026","externalUrl":null,"permalink":"/tags/theology/","section":"Tags","summary":"","title":"Theology","type":"tags"},{"content":"","date":"16 August 2026","externalUrl":null,"permalink":"/tags/2026/","section":"Tags","summary":"","title":"2026","type":"tags"},{"content":"A single compromised AI package recently exfiltrated terabytes of credentials from thousands of developers. This wasn\u0026rsquo;t a freak event or some novel attack technique. It was the predictable result of an industry that adopted AI tooling faster than it applied basic security discipline to it.\nAI Packages Became a High Value Target Because We Made Them One # Think about what a modern AI package touches. It reads your environment variables and local files. It often needs API keys for one or more model providers, and many phone home for telemetry or \u0026ldquo;usage analytics.\u0026rdquo; That\u0026rsquo;s an enormous amount of trust to hand to code you didn\u0026rsquo;t write and probably haven\u0026rsquo;t read.\nAttackers go where the value is. A compromised logging library might leak a few API keys here and there. A compromised AI package can leak cloud credentials, database connection strings, SSH keys, and every environment variable sitting in a .env file. One successful compromise scales instantly across every machine that installed it.\nDevelopers Grant Access Without Asking Why # Most developers install an AI package the same way they install any other npm or pip dependency: npm install, done, move on. No review of what permissions it requests. No question about why an AI wrapper library needs read access to environment variables that have nothing to do with AI.\n\u0026ldquo;It needs an API key\u0026rdquo; is not the same as \u0026ldquo;it needs access to every credential on this machine.\u0026rdquo; But that\u0026rsquo;s the access pattern most teams grant by default, because packages ask for broad permissions and nobody pushes back.\nI understand the pressure. AI tooling moves fast, and stopping to audit every dependency feels like friction nobody has time for. But that friction is the point of a security review. Removing it doesn\u0026rsquo;t make the risk disappear. It just makes the risk invisible until something like this happens.\nDependency Trust Is Broken for AI Packages Specifically # Traditional software supply chain security already struggles with this problem. Most teams pull from public registries, trust maintainers they\u0026rsquo;ve never vetted, and update packages automatically without reading changelogs. That\u0026rsquo;s bad enough on its own.\nAI packages make it worse because they carry an elevated risk profile that most teams treat as ordinary. A charting library and an AI SDK are not the same category of risk, even though your package.json treats them identically. The blast radius of a compromised AI dependency is larger, because it sits closer to credentials, closer to model APIs, and closer to the data your business actually cares about.\nIf your dependency review process doesn\u0026rsquo;t differentiate between these categories, you don\u0026rsquo;t have a dependency review process. You have a checklist that doesn\u0026rsquo;t match the threat model.\nPractical Mitigations That Would Have Limited the Blast Radius # Scope credentials to the narrowest possible permission set.\nAn AI package that only needs to call a completion endpoint should never have a credential that can also read your production database. Audit every AI package in your dependency tree and list exactly what credentials and file paths it can touch. If you can\u0026rsquo;t answer that question in five minutes, that\u0026rsquo;s your first finding.\nUse a secrets manager instead of environment variables for anything sensitive.\nEnvironment variables are visible to every process running under that user, including every dependency of every dependency. Move any long-lived credentials used by AI tooling into a secrets manager that hands out short-lived, scoped tokens at runtime. That closes off an entire category of exfiltration.\nPin dependency versions and review diffs before upgrading.\nAutomatic minor-version updates are how a clean package becomes a compromised one overnight. Pinning isn\u0026rsquo;t about avoiding updates forever. It\u0026rsquo;s about controlling when and how you accept new code into your environment. Set up a manual review step before any upgrade, no exceptions.\nAdd network egress controls at the host or container level.\nIf a package doesn\u0026rsquo;t need outbound access to arbitrary domains, don\u0026rsquo;t let it have that access. Most exfiltration in these incidents happens over plain HTTPS to obscure domain names. Apply these restrictions to every environment where AI packages run, even developer laptops, which are often the softest target in the whole chain.\nThis won\u0026rsquo;t make AI tooling risk-free. It\u0026rsquo;s best to assume every package could be compromised right now and design your environment around that assumption.\nRecommended Reading # AI Engineering: Building Applications with Foundation Models by Chip Huyen Ace the Data Science Interview: 201 Real Interview Questions Asked By FAANG, Tech Startups, \u0026 Wall Street by Kevin Huo, Nick Singh The Web Application Hacker's Handbook: Finding and Exploiting Security Flaws by Dafydd Stuttard, Marcus Pinto Featured image by 2AM CREATIVES on Unsplash\n","date":"16 August 2026","externalUrl":null,"permalink":"/post/2026/ai-package-supply-chain-attacks-of-course/","section":"Posts","summary":"","title":"AI Package Supply-Chain Attacks, Of Course!","type":"post"},{"content":"","date":"16 August 2026","externalUrl":null,"permalink":"/categories/engineering/","section":"Categories","summary":"","title":"Engineering","type":"categories"},{"content":"","date":"16 August 2026","externalUrl":null,"permalink":"/post/","section":"Posts","summary":"","title":"Posts","type":"post"},{"content":"","date":"15 August 2026","externalUrl":null,"permalink":"/tags/2012/","section":"Tags","summary":"","title":"2012","type":"tags"},{"content":" A Look Back from the Future # In September 2012, I published an article titled \u0026ldquo;Too Much Prevention, Not Enough Cure.\u0026rdquo; Its core argument was simple: IT leaders were focusing too much energy on preventing security breaches and not nearly enough on planning for when they inevitably happen.\nLooking back from today\u0026rsquo;s landscape of massive, high-profile data breaches, that observation proved to be unnervingly accurate. Every year, another major organization learns this lesson the hard way. Let\u0026rsquo;s revisit that decade-old argument and how I was able to make this prediction.\nThe Core Argument From 2012 # My original argument centered on a strange double standard within IT strategy. I contrasted the industry\u0026rsquo;s attitude toward data loss with its attitude toward security breaches.\nFor data loss, IT professionals have long accepted that it\u0026rsquo;s a matter of \u0026ldquo;when,\u0026rdquo; not \u0026ldquo;if.\u0026rdquo; No one aims for a mistake-free environment where user error or bit rot never occurs. Instead, the industry focuses on robust contingent actions, namely maintaining and testing data backups.\nIn stark contrast, security was often treated as a \u0026ldquo;no mistakes allowed\u0026rdquo; discipline focused almost exclusively on prevention. The goal was to build an impenetrable fortress, a posture I argued was doomed to fail. As I wrote then, the same axiom applies: it\u0026rsquo;s not a question of \u0026ldquo;if\u0026rdquo; you\u0026rsquo;ll have a breach, but \u0026ldquo;when.\u0026rdquo;\nThe reasons for this prevention-only focus were clear. Preventive actions are easier and highly visible. But more than that, blocking an attack is exciting and rewarding. Planning for failure, by comparison, is not nearly as glamorous.\nWhy That Prediction Was Right: Technology, Risk, and Human Nature # The accuracy of the \u0026ldquo;when, not if\u0026rdquo; prediction for security wasn\u0026rsquo;t the result of a crystal ball. It was based on an understanding of fundamental truths that remain unchanged, starting with our own psychology.\nHumans are notoriously bad at accurately assessing risk. We tend to discount low-probability events, even when their consequences are catastrophic. The likelihood of a serious breach on any given day may feel close to zero, so we psychologically default to prevention. This flawed risk assessment is the foundational reason why so many leaders fail to plan for an event they see as inevitable in theory but unlikely in practice.\nBeyond this blind spot, the prediction was grounded in two other constants:\nThe Nature of Technology: Complex systems fail. It\u0026rsquo;s an unavoidable reality. The pursuit of a \u0026ldquo;mistake-free\u0026rdquo; technological environment is a fool\u0026rsquo;s errand. As I noted back then, \u0026ldquo;failures happen,\u0026rdquo; and an effective strategy must be built on the acceptance of this fact, not the denial of it. The Nature of People: Technology is operated by people, who are fallible. Whether through simple user error or the malicious intent of a \u0026ldquo;rogue employee,\u0026rdquo; the human element makes a 100% prevention rate impossible. No firewall or security policy can completely eliminate this risk. My prediction held true not because I could see the future of cyberattacks, but because I understood these foundational principles. Our risk assessment is flawed, technology will always have vulnerabilities, and people will always be imperfect.\nThe Enduring Lesson: Plan for the Cure, Not Just Prevention # History has consistently proven the value of contingency planning over prevention-only strategies. The most powerful example remains the one I used in 2012.\nData backups are the model security strategy should have followed from the beginning. The entire IT industry accepts the \u0026ldquo;when, not if\u0026rdquo; axiom for data loss, and as a result, a mature, robust set of best practices for contingent action (backing up and restoring data) already exists.\nTo make the point tangible, consider the scenario I posed a decade ago.\nImagine for a moment that you are awakened at some unholy hour of the morning with the news that someone, somewhere, is in your network downloading confidential data. What do you do?\nIf your immediate, confident answer isn\u0026rsquo;t a pre-defined set of steps, you are left with only one option: to \u0026ldquo;figure it out as you go.\u0026rdquo; In a crisis, that is a recipe for catastrophic failure. As I warned then, you\u0026rsquo;re one breach away from looking for a new job.\nA Blueprint for Your Contingency Plan # A contingency plan isn\u0026rsquo;t about planning for every possibility, but for plausible scenarios that could realistically occur. Consider these examples from the original article:\nA rogue employee makes off with confidential data. An attacker breaches your network and begins collecting data. Data is intermittently leaking out, but you don\u0026rsquo;t know how or when. For scenarios like these, a solid contingency plan should include three core elements.\nStopping: This is your first move, cutting off the attacker\u0026rsquo;s access. The goal is to staunch the bleeding immediately, even if it means disrupting operations. The priority is to prevent further data exfiltration. Freezing: Once the immediate threat is stopped, you must preserve the \u0026ldquo;scene of the crime.\u0026rdquo; This means taking steps to ensure that all relevant data and systems are maintained in their current state for a full forensic analysis. Recovering: This final stage involves revising your prevention plan based on what you\u0026rsquo;ve learned from the breach and, finally, getting your operations back to normal. It\u0026rsquo;s critical to understand what a contingency plan is not for. As I stated in 2012, notice I said nothing about \u0026ldquo;getting back\u0026rdquo; any data. That\u0026rsquo;s impossible. Once confidential information is stolen, it\u0026rsquo;s gone. The goal of contingent action is to limit the damage and, if possible, prosecute the responsible party. There are no winners, and that\u0026rsquo;s why contingent action is rarely on IT\u0026rsquo;s radar.\nIt\u0026rsquo;s Still a Matter of \u0026ldquo;When\u0026rdquo; # A decade later, the central message remains unchanged and is more critical than ever. The focus on prevention at the expense of contingency planning is a failing strategy. The organizations that thrive in the face of modern threats will be those that accept the inevitability of failure and plan accordingly.\nThis brings me back to the final question I posed in 2012, a challenge that is as relevant today as it was then: \u0026ldquo;What other areas of your life and organization have you failed to create contingency plans for?\u0026rdquo;\nEmbracing the reality that things will go wrong is not a sign of weakness. It\u0026rsquo;s the first step toward building true, lasting resilience.\nRecommended Reading # The Web Application Hacker's Handbook: Finding and Exploiting Security Flaws by Dafydd Stuttard, Marcus Pinto CompTIA Security+ Certification Kit: Exam SY0-701 by Mike Chapple, David Seidl CompTIA A+, Network+, Security+ Complete Study Guide Set by Todd Lammle, Quentin Docter, Jon Buhagiar Featured image by Mohamed Marey on Unsplash\n","date":"15 August 2026","externalUrl":null,"permalink":"/post/2026/how-i-predicted-the-future-of-security/","section":"Posts","summary":"","title":"How I Predicted the Future of Security","type":"post"},{"content":"","date":"15 August 2026","externalUrl":null,"permalink":"/categories/security/","section":"Categories","summary":"","title":"Security","type":"categories"},{"content":"","date":"15 August 2026","externalUrl":null,"permalink":"/tags/security/","section":"Tags","summary":"","title":"Security","type":"tags"},{"content":"","date":"14 August 2026","externalUrl":null,"permalink":"/categories/career/","section":"Categories","summary":"","title":"Career","type":"categories"},{"content":"","date":"14 August 2026","externalUrl":null,"permalink":"/tags/ccnp-security/","section":"Tags","summary":"","title":"CCNP Security","type":"tags"},{"content":"","date":"14 August 2026","externalUrl":null,"permalink":"/tags/cisco-certification/","section":"Tags","summary":"","title":"Cisco Certification","type":"tags"},{"content":"","date":"14 August 2026","externalUrl":null,"permalink":"/tags/cli-skills/","section":"Tags","summary":"","title":"CLI Skills","type":"tags"},{"content":"Every time someone asks me whether CCNP Security is worth it, they\u0026rsquo;re actually asking two different questions at once. The first is whether the career paths behind the cert are worth pursuing. The second, usually unspoken, is whether they\u0026rsquo;re going to fail the exam. Both deserve real answers, so let\u0026rsquo;s take them one at a time.\nWho Should Pursue CCNP Security # CCNP Security makes sense if you want to specialize rather than generalize. CCNP Enterprise and CCNP Routing and Switching keep you broad: moving packets, building networks, troubleshooting connectivity. CCNP Security narrows your focus onto protecting what\u0026rsquo;s already there.\nThat narrowing matters because security work pays differently than general networking work, and it opens different doors. If you\u0026rsquo;re a network engineer who wants a raise and a title change without starting over in a new field, CCNP Security is one of the more direct paths available.\nThe certification signals to employers that you can configure and troubleshoot the tools that actually stop attacks: firewalls, VPNs, identity and access management platforms, and network access control systems. That\u0026rsquo;s a narrower, more defensible skill set than \u0026ldquo;I know networking,\u0026rdquo; and it tends to command a narrower, more defensible salary bump too.\nThe Roles It Opens # CCNP Security lines up most directly with a handful of roles you\u0026rsquo;ll see posted constantly:\nNetwork Security Engineer. The most direct match. You own firewall policy, VPN tunnels, and access control, typically for one organization or a rotation of clients if you\u0026rsquo;re at an MSP. Security Engineer. A broader title, often blending network security with endpoint and cloud security work, depending on the employer. Firewall Engineer. A narrower, more specialized role focused almost entirely on firewall rule management, often at large enterprises with hundreds of rules to maintain. Identity and Access Management (IAM) Engineer. If you gravitate toward the identity side, the ISE and access control topics on the exam translate directly. Security Operations Center (SOC) roles. CCNP Security isn\u0026rsquo;t a SOC-specific cert, but it gives you the network fluency that a lot of SOC analysts lack, which makes you more useful when incidents involve firewall logs or VPN traffic. None of these roles require CCNP Security specifically. But in a stack of resumes, it\u0026rsquo;s the difference between \u0026ldquo;says they know security\u0026rdquo; and \u0026ldquo;has demonstrated hands-on competence with the exact tools we use.\u0026rdquo;\nWhat the Job Actually Looks Like Day to Day # This is the part people skip when deciding whether to pursue a cert, and it\u0026rsquo;s the part that actually matters. What you study for CCNP Security maps closely onto what you\u0026rsquo;ll do in these jobs, more closely than most certifications map onto their corresponding roles.\nExpect to spend real time in firewall management consoles: reviewing and modifying rule sets, closing overly permissive rules, and troubleshooting connectivity that breaks because a rule was too strict or too loose. This is unglamorous, repetitive work. It\u0026rsquo;s also the daily bread of a network security engineer.\nExpect VPN work too. Site-to-site tunnels drop, IKE negotiations fail, and someone has to figure out why. That someone is often the CCNP Security holder on the team, because you\u0026rsquo;re the one who understands crypto maps and transform sets well enough to read a debug output and know what\u0026rsquo;s wrong.\nExpect access control projects. Deploying or maintaining NAC systems, integrating with identity providers, and writing policies that decide which devices get onto which VLANs is ISE-adjacent work, and it maps directly onto the SCOR and specialty exam content.\nIncreasingly, expect cloud security tickets mixed in with the traditional on-prem work. Modern CCNP Security content includes cloud security concepts specifically because employers now expect the same engineer who manages the firewall to also understand security groups and cloud-native access controls.\nNone of this is glamorous. It\u0026rsquo;s rarely the \u0026ldquo;hacker in a hoodie\u0026rdquo; image people have of security work. It\u0026rsquo;s methodical, detail-oriented, and often reactive, chasing down why a tunnel won\u0026rsquo;t come up or why a legitimate user got blocked. If that kind of work appeals to you, CCNP Security is worth pursuing. If you want offensive security, penetration testing, or red team work, this isn\u0026rsquo;t the cert for that. Look at OSCP or something similar instead.\nSo the roles are real, and the day-to-day work is worth doing. That still leaves the second question: are you going to pass?\nHesitation Is Not a Diagnostic Tool # I want to be direct about this because I don\u0026rsquo;t think enough people say it out loud. Feeling nervous about the CCNP Security exam tells you nothing about your actual competence. It tells you that you\u0026rsquo;re a human being about to spend a few hundred dollars on a test that has real consequences for your career.\nAnxiety and preparedness are two completely separate variables. You can be well-prepared and terrified. You can be underprepared and calm. Don\u0026rsquo;t use your emotional state as a proxy for your readiness. Use your actual skills.\nThis matters specifically for CCNP Security because the concentration exams (SCOR plus your chosen specialty) cover a wide surface area: firewalls, VPNs, identity management, cloud security, endpoint protection, network access control. It\u0026rsquo;s easy to look at that breadth and conclude you\u0026rsquo;ll never know enough. You won\u0026rsquo;t ever know everything. That\u0026rsquo;s fine. You don\u0026rsquo;t need everything. You need enough margin.\nBuild a Margin, Not Just Competence # Here\u0026rsquo;s the strategy I\u0026rsquo;ve recommended for every Cisco professional-level exam I\u0026rsquo;ve helped people prepare for, and it applies to CCNP Security without modification: study to a level noticeably above what the exam actually requires.\nIf you study exactly to the difficulty of the exam, you have zero room for error. Any curveball question, any moment of test-day fog, any unfamiliar phrasing, and you\u0026rsquo;re suddenly underwater. But if you deliberately push your preparation past what you think the exam demands, you build a buffer. That buffer is what carries you through the two or three questions that genuinely throw you off.\nThis isn\u0026rsquo;t about perfectionism. It\u0026rsquo;s about margin. The goal isn\u0026rsquo;t to know everything. The goal is to know more than the minimum by enough that panic doesn\u0026rsquo;t cost you the exam.\nPractically, this means going deeper into configuration scenarios than the blueprint technically requires. If the exam expects you to configure a site-to-site VPN, don\u0026rsquo;t stop once you get one working. Break it. Misconfigure the crypto map. Mismatch the transform sets. Fix it under time pressure. That extra rep is what turns a shaky \u0026ldquo;I think I know this\u0026rdquo; into a confident \u0026ldquo;I\u0026rsquo;ve broken this ten different ways and I know what all of them look like.\u0026rdquo;\nThe CLI Is Where the Real Studying Happens # I\u0026rsquo;ve said this about every Cisco cert I\u0026rsquo;ve written a study guide for, and it hasn\u0026rsquo;t stopped being true: reading and watching videos will get you familiar with concepts, but it will not get you through a hands-on exam. You have to spend the majority of your study time actually in the CLI.\nThis is especially true for CCNP Security because so much of the material tests your ability to implement, not just recognize. Recognizing that Zone-Based Firewall policies use zone pairs is trivia. Actually configuring one, watching it fail because you forgot the default zone behavior, and fixing it, that\u0026rsquo;s understanding.\nSet a rule for yourself. At least half your study time, ideally more, needs to be hands-on. Fire up a lab. Misconfigure things on purpose. Troubleshoot your own mistakes instead of just following a guide step by step. If you only ever configure things correctly on the first try because you\u0026rsquo;re copying commands, you\u0026rsquo;re not building the skill the exam is actually testing. You\u0026rsquo;re building the skill of transcription.\nSpeed matters here too. Just like with ENCOR, being able to eventually get a secure tunnel working isn\u0026rsquo;t the same as being able to get it working in twelve minutes because that\u0026rsquo;s all the exam clock allows you. Time yourself. Repeatedly. Repetition under time pressure is what separates \u0026ldquo;I can do this\u0026rdquo; from \u0026ldquo;I can do this fast enough to matter.\u0026rdquo;\nThe Same Playbook, Different Cert # None of this exam-prep advice is new, dressed up for a new cert. It\u0026rsquo;s the same playbook I gave CCNP Enterprise candidates and the same playbook I gave CCNP Routing and Switching candidates going back years. The technologies change. The strategy doesn\u0026rsquo;t.\nStudy above the exam\u0026rsquo;s actual difficulty so you have margin when nerves show up. Spend most of your time in the CLI, not in front of slides. Treat hesitation as noise, not signal. These aren\u0026rsquo;t tricks specific to security topics. They\u0026rsquo;re just what works, regardless of which three-letter Cisco exam is sitting between you and the next rung of your career.\nCCNP Security is worth it if you want the roles described above, if you prefer defensive, detail-heavy work over broad generalist networking, and if you\u0026rsquo;re willing to put in CLI hours rather than just watch videos. The exam is demanding, but so is the job it prepares you for, and that overlap is exactly why the certification still means something. Stop waiting to feel ready. Go build the margin instead.\nRecommended Reading # CCNP Enterprise Certification Study Guide: 350-401 ENCOR by Ben Piper CompTIA Security+ Certification Kit: Exam SY0-701 by Mike Chapple, David Seidl The Web Application Hacker's Handbook: Finding and Exploiting Security Flaws by Dafydd Stuttard, Marcus Pinto Featured image by Jon Moore on Unsplash\n","date":"14 August 2026","externalUrl":null,"permalink":"/post/2026/is-the-ccnp-security-cert-worth-it/","section":"Posts","summary":"","title":"Is the CCNP Security Cert Worth It?","type":"post"},{"content":"","date":"14 August 2026","externalUrl":null,"permalink":"/tags/it-career/","section":"Tags","summary":"","title":"IT Career","type":"tags"},{"content":"","date":"14 August 2026","externalUrl":null,"permalink":"/tags/network-security/","section":"Tags","summary":"","title":"Network Security","type":"tags"},{"content":"","date":"14 August 2026","externalUrl":null,"permalink":"/tags/ai-agents/","section":"Tags","summary":"","title":"AI Agents","type":"tags"},{"content":"","date":"14 August 2026","externalUrl":null,"permalink":"/tags/amazon-s3/","section":"Tags","summary":"","title":"Amazon S3","type":"tags"},{"content":"","date":"14 August 2026","externalUrl":null,"permalink":"/tags/aws/","section":"Tags","summary":"","title":"AWS","type":"tags"},{"content":"Every multi-agent architecture eventually runs into the same design question: who\u0026rsquo;s in charge? Most teams answer it by building a central orchestrator, a service that assigns tasks, tracks state, and tells agents what to do next. It works fine in a demo. It works fine with ten agents. Then you scale to a few hundred, the orchestrator becomes the busiest, most fragile component in the system, and you\u0026rsquo;re debugging a bottleneck you built on purpose.\nAWS has a reference architecture floating around called kiro-flock that takes a different approach. Instead of a central controller, agents coordinate through shared state in Amazon S3. No orchestrator process, no queue manager deciding who does what. Agents write their status as objects, read what other agents have written, and self-organize based on what they see in the bucket.\nI\u0026rsquo;ve spent enough time building and running orchestration layers to be skeptical of anything that claims to remove the need for one. But the more I look at this pattern, the more I think the skepticism should be pointed at the orchestrator, not the alternative.\nThe Orchestrator Bottleneck # A central orchestrator is a single point of failure by definition. If it goes down, every agent that depends on it stalls, even if the agents themselves are healthy. It\u0026rsquo;s also a scaling bottleneck. Every agent has to talk to it, which means connection limits, request queues, and lock contention all grow with fleet size. You end up spending more engineering effort scaling the thing that coordinates the work than the thing that actually does the work.\nThe instinct is to make the orchestrator highly available: add replicas, add a leader election protocol, add a database behind it. At that point you\u0026rsquo;ve built a distributed system to manage your distributed system. The complexity didn\u0026rsquo;t go away. It just moved up a layer.\nWhat kiro-flock Actually Does # The kiro-flock pattern treats S3 as the shared source of truth. Agents running on EC2 (or wherever) write small state objects describing what they\u0026rsquo;re doing, what they\u0026rsquo;ve claimed, and what they\u0026rsquo;ve completed. Other agents list and read those objects to decide their next move. There\u0026rsquo;s no central brain deciding who gets which task. The agents look at the bucket, apply a shared set of rules, and act.\nThis works because S3 gives you a few things for free that you\u0026rsquo;d otherwise have to build yourself: durability, virtually unlimited concurrent readers, and a flat namespace that scales without you thinking about it. You don\u0026rsquo;t provision capacity for \u0026ldquo;more agents reading state.\u0026rdquo; S3 just handles it.\nTask claiming uses conditional writes (If-None-Match on object creation, for example) as a lightweight compare-and-swap. An agent tries to create a \u0026ldquo;claim\u0026rdquo; object for a task. If it succeeds, it owns the task. If it fails because the object already exists, another agent got there first. That\u0026rsquo;s a real coordination primitive, not just agents politely agreeing not to step on each other.\nTrading Consistency For Resilience # Here\u0026rsquo;s the tradeoff, and it\u0026rsquo;s a real one: S3 is eventually consistent for list operations in ways that matter here. A newly written object is strongly consistent for reads once written, but a ListObjects call right after a burst of writes isn\u0026rsquo;t guaranteed to reflect every object immediately in all conditions, and propagation across a large number of concurrent writers isn\u0026rsquo;t instantaneous. If your coordination logic assumes every agent sees the exact same bucket state at the exact same moment, you\u0026rsquo;re going to get duplicate task claims, orphaned work, and agents racing each other on stale reads.\nA central orchestrator gives you strong guarantees about ordering and state because it\u0026rsquo;s one process holding one view of the world. Shared state through S3 gives up that guarantee in exchange for something else: no single point of failure, and horizontal scalability that doesn\u0026rsquo;t require you to scale a controller. As your agent fleet grows from dozens to thousands, that tradeoff starts looking a lot more attractive. Coordination guarantees matter less than staying up.\nDebugging When Nothing Is a Single Truth # This is the part people underestimate. With a central orchestrator, when something goes wrong, you look at one log stream and one state store. With S3 as your coordination layer, \u0026ldquo;what happened\u0026rdquo; is scattered across however many objects your agents wrote, and the order you read them in during a postmortem might not be the order they were actually written in from every agent\u0026rsquo;s perspective.\nYou need object versioning turned on, timestamps embedded in every state object (not just relying on S3 metadata), and ideally an event log shipped somewhere queryable, because reconstructing a timeline from bucket listings after the fact is painful. Eventual consistency doesn\u0026rsquo;t just change how the system behaves. It changes what your incident response looks like.\nWhere This Pattern Actually Fits # Use S3-as-coordination when your agent fleet is large, your tasks are independent enough that a claim-based model works, and you can tolerate occasional duplicate work or brief coordination lag. Don\u0026rsquo;t use it when task ordering has to be strict, when agents need to negotiate in real time, or when you can\u0026rsquo;t afford even a few seconds of staleness in what agents believe about each other\u0026rsquo;s state.\nA central orchestrator isn\u0026rsquo;t wrong. It\u0026rsquo;s just the wrong default for fleets that outgrow it. Before you build one, ask what you actually need: strict ordering and a single source of truth, or resilience and horizontal scale. You can\u0026rsquo;t cleanly get both, and pretending otherwise is how orchestrators become the thing you spend all your time firefighting.\nRecommended Reading # Designing Multi-Agent Systems: Principles, Patterns and Implementation by Victor Dibia AI Agents in Action by Micheal Lanham AWS Certified Solutions Architect Study Guide: Associate SAA-C03 Exam, 4th Edition by Ben Piper \u0026amp; David Clinton Featured image by Christian Lue on Unsplash\n","date":"14 August 2026","externalUrl":null,"permalink":"/post/2026/can-s3-replace-a-central-orchestrator-for-agents/","section":"Posts","summary":"","title":"Can S3 Replace a Central Orchestrator for Agents?","type":"post"},{"content":"","date":"14 August 2026","externalUrl":null,"permalink":"/tags/ec2/","section":"Tags","summary":"","title":"EC2","type":"tags"},{"content":"","date":"14 August 2026","externalUrl":null,"permalink":"/tags/multi-agent-systems/","section":"Tags","summary":"","title":"Multi-Agent Systems","type":"tags"},{"content":"","date":"14 August 2026","externalUrl":null,"permalink":"/tags/agentic-ai/","section":"Tags","summary":"","title":"Agentic-Ai","type":"tags"},{"content":"","date":"14 August 2026","externalUrl":null,"permalink":"/tags/llm-reasoning/","section":"Tags","summary":"","title":"Llm-Reasoning","type":"tags"},{"content":"We\u0026rsquo;re missing something.\nEveryone is building and using AI agents. But something doesn\u0026rsquo;t seem right. We\u0026rsquo;re missing something, and it feels like it should be obvious, but it\u0026rsquo;s not. It seems like there\u0026rsquo;s a way to use LLMs differently and more effectively, but we haven\u0026rsquo;t quite figured it out yet. And when we try to figure it out, we just end up with a bunch of disconnected or loosely connected observations without a cohesive theory to tie them all together.\nThe Determinism Problem # flowchart TB subgraph Traditional[\"Traditional System\"] A1[Input] --\u003e A2[Deterministic Function] A2 --\u003e A3[Predictable Output] end subgraph Agentic[\"LLM-Based System\"] B1[Input] --\u003e B2[LLM] B2 --\u003e B3{Non-Deterministic Layer} B3 --\u003e B4[Output A] B3 --\u003e B5[Output B] B3 --\u003e B6[Output C] end LLMs are not deterministic. Well, they kinda are, because they\u0026rsquo;re running on computers, which are deterministic machines. But they\u0026rsquo;re not deterministic in the way regular functions are, where the same set of inputs always yields the same outputs.\nLLMs are just predicting the next token. Yet once these models get to a certain size, they suddenly gain this emergent capability to produce human-like text that actually makes sense (usually). What they produce is hardly profound, but it\u0026rsquo;s still useful. LLMs can produce knowledge-driven artifacts such as code, images, music, and video far faster than ever before.\nAs we use these LLMs, a theme starts to emerge, and a realization sets in: they don\u0026rsquo;t actually comprehend anything. They can\u0026rsquo;t reason. They can\u0026rsquo;t actually make decisions, or understand what\u0026rsquo;s best or even good.\nFake Reasoning as a Constraint # LLMs have been gifted with the ability to \u0026ldquo;fake reason.\u0026rdquo; They mimic thinking out loud, complete with filler words like \u0026ldquo;Okay, let me see\u0026hellip; hmmm.\u0026rdquo; But this is programmed behavior. \u0026ldquo;Reasoning\u0026rdquo; is just a programmed execution path.\nThe implementation of fake \u0026ldquo;reasoning\u0026rdquo; was intended to limit the LLM and constrain it to a finite, terminable path. If you used the smaller, older LLMs like GPT 2.5, they could go on and on and just keep spitting out gibberish. The larger models produced less junk, but they could still go off on a tangent and get lost and confused. Constraining models with faux human-like reasoning mimicry redirected them back to a preprogrammed set of rules for execution.\nTo use an analogy: without reasoning, models are like a young child trying to draw a picture from scratch. It might be mostly decipherable, but it\u0026rsquo;s going to be messy. With reasoning, models are given an outline and allowed to choose the colors. They might go outside the lines, but they\u0026rsquo;re programmed to detect this, and they can self-correct.\nThis is why models excel at coding. Programming requires a rigid set of rules. It\u0026rsquo;s not a free for all. When trained on code, models infer the rules, and hence make pretty good decisions within that framework.\nThe Tension Between Freedom and Control # As we think about this shift from non-reasoning to reasoning, our dilemma with these models becomes clear, and so does the reason why using them always feels a little off. We\u0026rsquo;re trying to have it both ways. What we\u0026rsquo;re feeling when we use LLMs is a tension between letting the model be free and creative but wrong, and constraining it with rules that help it perform better, while potentially sacrificing creativity and insight.\nFree and creative is the route people tend to take when they first use LLMs. They just want to dump things on it and watch it go. That doesn\u0026rsquo;t work, so we slowly start to creep toward constraint instead.\nPrompt and context engineering is just constraining the model with rules so that it doesn\u0026rsquo;t mess up as much. But determining those rules, writing them, and making sure we haven\u0026rsquo;t missed anything is fundamentally design work. We have to do a lot of setup with prompts and context to get the LLM to a place where it can execute without being continually, manually steered.\nBut as we write more and more rules into our prompts, we start to see that some of what we\u0026rsquo;re asking the LLM to do can be done programmatically. So now we have to split the programmatic, deterministic rules from the looser, natural language prompts. This is where the idea of multiple agents came from.\nflowchart LR A[\"Free and Creative(Easy, but Wrong)\"] --\u003e B[Prompt Engineering] B --\u003e C[Context Engineering] C --\u003e D[Agent Skills] D --\u003e E[\"Fully Constrained(Hard, but Right)\"] The Rise of Multi-Agent Systems # Now we have a proliferation of agents and functions. One agent passes its output to another agent, which passes its output to a function, which passes its output to an agent, and so on. We\u0026rsquo;re now having to do more than just task decomposition. We\u0026rsquo;re having to figure out which tasks should be done by an agent and which should be done with old-fashioned deterministic code.\nThe agent represents a weak link in the chain. If it feeds garbage output to, say, a function, the function might not produce valid output. So we have to add more complexity: a feedback loop to detect and remedy bad agent outputs. That\u0026rsquo;s why we have things like LangChain and LangGraph now. When implemented, those feedback loops essentially become functional wrappers around the agents.\nAgents as Approximation Functions # And here\u0026rsquo;s where we feel more tension. Anytime we\u0026rsquo;re doing something with an agent, we have to protect it with functional rules for its inputs and outputs. This isn\u0026rsquo;t a bad thing. We already do this with typing, and that\u0026rsquo;s the point. The more we do with agents, the more the agent feels like a strange, unpredictable function.\nWell, that\u0026rsquo;s exactly what it is. Agents behave like approximation functions. This makes them good at quickly creating \u0026ldquo;close enough\u0026rdquo; or \u0026ldquo;good enough\u0026rdquo; artifacts such as code, images, sound, and video. But these artifacts are usually used as inputs into a workflow whose output must be accurate and precise.\nThat accuracy requires iterating with other agents and wrapping the inputs and outputs with functions that bound the insanity an agent might produce. And even with all that, this really doesn\u0026rsquo;t work. Put simply, you can\u0026rsquo;t use approximations or best guesses as inputs and expect an accurate, precise, predictable output every time.\nThe Iron Triangle of Agent Tradeoffs # So why do we use agents at all? It\u0026rsquo;s a tradeoff. We could have a human deal with the ambiguous tasks that can\u0026rsquo;t be written as deterministic code, but humans take time to work. An LLM can do many of those tasks much faster, but at the cost of accuracy.\nThe old iron triangle rears its head again: good, fast, cheap. Pick only two. If you choose human, you get good and cheap. If you choose LLM, you get fast and cheap. This is why companies are struggling with AI. They wrongly believe they can use LLMs to get good, fast, and cheap. Alas, there\u0026rsquo;s no free lunch here.\nI\u0026rsquo;ve heard the sentiment that in critical workflows, such as those supporting life, human review of AI is mandatory. That\u0026rsquo;s because the output of such applications must be good. But most businesses would probably agree that the must-be-good requirement applies to many areas, not just those supporting life.\nAgent skills were one answer to the problem of agents being too loose with their reasoning and outputs. Skills are nothing more than constraints on a model. Evaluations (evals) are an attempt to reify how well a particular skill steers the agent. Notice a pattern here? Everything we do with these agents is trying to force them to act like deterministic functions.\nPushing Rules Into the Model # But wait a minute. If we\u0026rsquo;re using context engineering, prompt engineering, and skills to make agents act more deterministically, are we operating at the wrong layer? Perhaps it makes more sense to push this rule-making to the model itself.\nOf course, this would defeat the purpose of the huge, multimodal, multipurpose foundation models. The whole idea behind those was to have a \u0026ldquo;brain\u0026rdquo; that could achieve a variety of tasks. But that\u0026rsquo;s not how we actually use these models. We break tasks down into things for specialized agents.\nIf we follow this approach to its end, and especially if you buy into Buckminster Fuller\u0026rsquo;s concept of ephemeralization (the idea that technology always becomes smaller and more invisible), then the next step is specialized, purpose-built, miniature models. In other words, smaller approximation functions that are better at approximating than their huge, billion- or trillion-parameter cousins.\nWe already have models specialized for medicine (e.g. internlm2, medllama, etc). But this can and will be broken down further, into models for gastroenterology, neurology, and so on. Those will then be broken down even further into models for specific ailments, diagnoses, and procedures.\nOf course, this requires careful curation and work that only humans can do. We can\u0026rsquo;t trust a generalized foundation model to properly classify and train a smaller model with close to 100% accuracy. That is a human task.\n(This is one reason artificial general intelligence, or AGI, is impossible. A huge approximation function cannot generate something more accurate than itself without human input. I digress.)\nWhy Models Excel at Code # We all know models are great at coding because, as I said earlier, code has a lot of rules that are very easy for the model to learn. Not only are there implicit rules the model learns just from being trained on code, it also learns from the many books written on programming.\nMany people have asked why models can\u0026rsquo;t just directly produce machine-readable executable code and skip the human-readable programming language. Why write Go or Rust instead of just producing a binary executable?\nAfter our discussion, the reason is obvious: models haven\u0026rsquo;t been trained on raw binary executables. They don\u0026rsquo;t know the rules for those, at least not to the extent they know code. A model might have been trained on some hex dumps it can translate to binary, but the chances of it producing a safe, runnable binary are extremely low.\nRecommended Reading # The LLM Engineer's Handbook by Paul Iusztin and Maxime Labonne Designing Multi-Agent Systems: Principles, Patterns and Implementation by Victor Dibia AI Engineering: Building Applications with Foundation Models by Chip Huyen Featured image by Brett Jordan on Unsplash\n","date":"14 August 2026","externalUrl":null,"permalink":"/post/2026/were-missing-something-about-these-agents/","section":"Posts","summary":"","title":"We're Missing Something About These Agents","type":"post"},{"content":"","date":"12 August 2026","externalUrl":null,"permalink":"/tags/ai-adoption/","section":"Tags","summary":"","title":"AI Adoption","type":"tags"},{"content":"A lot of AI proof of concepts succeed. But fewer turn into something the organization actually runs on. Everyone in the room nods at the demo, the numbers look good, and six months later the project is either dead or limping along as a novelty that three people quietly use.\nThis isn\u0026rsquo;t a technology problem. The model did what it was supposed to do. The gap between a working pilot and working adoption is organizational, and it shows up in the same two places every time: broken processes and undefined ownership.\nA demo is not a decision # A proof of concept answers one question: can this work under ideal conditions? You picked clean data. You picked a scoped use case. You picked a small group of motivated users who wanted the thing to succeed. None of that resembles how the rest of your organization operates.\nOperational readiness means the system survives contact with people who don\u0026rsquo;t want to change their workflow, data that\u0026rsquo;s inconsistent because three departments format it three different ways, and edge cases nobody thought to test because they only show up once a quarter. A successful pilot validates a hypothesis. It does not validate readiness. Treating the two as the same thing is where most AI initiatives quietly die.\nYou can\u0026rsquo;t automate your way out of a broken process # Here\u0026rsquo;s the pattern I see over and over. A team has a process that\u0026rsquo;s already slow, ambiguous, or held together by one person\u0026rsquo;s institutional knowledge. Someone proposes bolting AI onto it to speed things up. The AI works exactly as designed and produces output faster than before.\nThe problem is that the process was never well-defined to begin with, so now you\u0026rsquo;re generating bad decisions faster instead of slowly. AI doesn\u0026rsquo;t fix an undefined process. It amplifies whatever you feed it. If the underlying steps, handoffs, and rules were unclear before, they\u0026rsquo;re still unclear after, except now nobody has time to notice because the pipeline is moving twice as fast.\nFix the process first. This sounds obvious written out, but it\u0026rsquo;s the step almost everyone skips because it\u0026rsquo;s boring and doesn\u0026rsquo;t demo well. Nobody wants to spend three months mapping a workflow when they could spend three weeks building a flashy pilot.\nWho\u0026rsquo;s on the hook when the answer is wrong? # The second failure point is even more common: nobody decided who owns the output. When a model produces a wrong answer, a bad recommendation, or an inaccurate summary, somebody has to be accountable for catching it and correcting it. If that person doesn\u0026rsquo;t exist, or if three people assume it\u0026rsquo;s someone else\u0026rsquo;s job, the system runs on autopilot until something breaks visibly enough that leadership notices.\nThis is a decision that has to be made explicitly, before the system goes live, not discovered after an incident. Who has final say when the AI output is wrong? Which steps are advisory, meaning a human can ignore the suggestion, and which are automated outright? These aren\u0026rsquo;t AI questions. They\u0026rsquo;re management questions that AI just makes more urgent, because errors compound faster than they used to.\nAutomating dysfunction just makes the dysfunction louder # Put these two failure points together and you get the real story behind most stalled AI adoption. An organization takes an undefined process, wires AI into it, and doesn\u0026rsquo;t assign anyone to own the results. The pilot looks great because it ran in a sandbox with attentive humans watching closely. Production doesn\u0026rsquo;t have attentive humans watching closely. It has people doing their actual jobs, trusting that the system handles the rest.\nWhen the system produces something wrong and nobody catches it because nobody was assigned to catch it, trust in the whole initiative collapses. Not because the model failed, but because the organization never did the unglamorous work of deciding who\u0026rsquo;s responsible for what.\nWhat to actually do about it # Before you scale any pilot past the demo stage, answer three questions in writing. What does the process look like today, without AI, and where exactly does it break down? Who makes the final call when the AI\u0026rsquo;s output is wrong, and is that person aware they own that call? Which steps stay advisory, where a human can override the system, versus which steps run without a human in the loop?\nIf you can\u0026rsquo;t answer these clearly, you\u0026rsquo;re not ready to scale, no matter how good the pilot looked. The technology was never the hard part. The hard part is the same thing it\u0026rsquo;s always been in IT: defining the process and deciding who\u0026rsquo;s accountable for the outcome. AI just makes it obvious a lot faster when you skipped that step.\nRecommended Reading # AI Engineering: Building Applications with Foundation Models by Chip Huyen Ace the Data Science Interview: 201 Real Interview Questions Asked By FAANG, Tech Startups, \u0026 Wall Street by Kevin Huo, Nick Singh The Phoenix Project by Gene Kim, Kevin Behr, George Spafford Featured image by Dahlia E. Akhaine on Unsplash\n","date":"12 August 2026","externalUrl":null,"permalink":"/post/2026/why-ai-pilots-succeed-but-ai-adoption-fails/","section":"Posts","summary":"","title":"AI Pilots Succeed, So Why Does Adoption Fail?","type":"post"},{"content":"","date":"12 August 2026","externalUrl":null,"permalink":"/tags/automation/","section":"Tags","summary":"","title":"Automation","type":"tags"},{"content":"","date":"12 August 2026","externalUrl":null,"permalink":"/tags/change-management/","section":"Tags","summary":"","title":"Change Management","type":"tags"},{"content":"","date":"12 August 2026","externalUrl":null,"permalink":"/tags/it-strategy/","section":"Tags","summary":"","title":"IT Strategy","type":"tags"},{"content":"","date":"12 August 2026","externalUrl":null,"permalink":"/tags/leadership/","section":"Tags","summary":"","title":"Leadership","type":"tags"},{"content":"","date":"12 August 2026","externalUrl":null,"permalink":"/tags/ai-learning-tools/","section":"Tags","summary":"","title":"AI Learning Tools","type":"tags"},{"content":"","date":"12 August 2026","externalUrl":null,"permalink":"/tags/aws-certification/","section":"Tags","summary":"","title":"AWS Certification","type":"tags"},{"content":"","date":"12 August 2026","externalUrl":null,"permalink":"/tags/aws-cloud-quest/","section":"Tags","summary":"","title":"AWS Cloud Quest","type":"tags"},{"content":"AWS Cloud Quest now hands out badges powered by AI-guided practice. You complete a scenario, get feedback, and earn a badge. It lowers the barrier for someone who has never touched the AWS console to start experimenting with real services in a sandboxed environment.\nBut here\u0026rsquo;s the problem: a badge tells you that someone clicked through a scenario successfully. It does not tell you whether they understand why the scenario worked, or whether they could design something similar from scratch under different constraints. And that gap matters more than the badge system wants you to believe.\nPattern Recognition Is Not Understanding # Cloud Quest\u0026rsquo;s AI layer is at reducing friction. It nudges you toward the right answer when you\u0026rsquo;re stuck, points out what you missed, and keeps you moving through a scenario without getting permanently blocked. This is a legitimate improvement over the old \u0026ldquo;figure it out or give up\u0026rdquo; model of hands-on labs.\nBut nudging toward a correct answer is different from teaching you the reasoning behind it. If the AI tells you \u0026ldquo;attach this security group rule to allow inbound traffic on port 443,\u0026rdquo; you can follow that instruction and complete the lab without ever understanding why port 443 matters, what happens if you open it to 0.0.0.0/0 instead of a specific CIDR block, or how that decision interacts with your VPC\u0026rsquo;s routing table.\nThat\u0026rsquo;s pattern recognition. You\u0026rsquo;ve seen the shape of the problem before, and you know which button to press. It works great until the exam (or a real production incident) hands you a scenario that looks almost like what you practiced but isn\u0026rsquo;t quite the same, and now you have no underlying model to reason from.\nWhat Hiring Managers Actually Test # I\u0026rsquo;ve spent years training engineers on AWS, and I can tell you what happens in technical interviews. Hiring managers do not ask candidates to describe their badge collection. They ask questions like:\nWhy would you choose an Application Load Balancer over a Network Load Balancer for this workload? What\u0026rsquo;s the difference between a security group and a network ACL, and when do you need both? How does IAM policy evaluation logic handle an explicit deny versus an implicit deny? Walk me through how you\u0026rsquo;d design S3 storage tiers for a dataset with unpredictable access patterns. None of these questions have a \u0026ldquo;click here\u0026rdquo; answer. They require you to reason about EC2, S3, VPC, and IAM as interconnected systems, not as isolated lab exercises you completed once. A badge from Cloud Quest doesn\u0026rsquo;t prepare you for this conversation. It proves engagement, not depth. Those are not the same thing, and hiring managers can tell the difference within about ninety seconds.\nLabs and Study Guides Solve Different Problems # Here\u0026rsquo;s where I think a lot of learners get confused. They assume hands-on labs and structured study material are competing approaches to the same problem, so they pick one and skip the other. That\u0026rsquo;s a mistake, because the two serve completely different purposes.\nHands-on labs teach you mechanics. They show you where buttons live in the console, how services respond to specific configurations, and what an error message actually looks like when you misconfigure something. This is valuable and irreplaceable. You cannot learn muscle memory from a book.\nStructured study, the kind you\u0026rsquo;d find preparing for the AWS Certified Solutions Architect exam, teaches you the mental model. It forces you to understand why a Multi-AZ RDS deployment behaves differently from a read replica, why you\u0026rsquo;d choose Amazon SQS over SNS for a given workload, or how the shared responsibility model actually draws the line between what AWS secures and what you secure. This is the reasoning layer that turns \u0026ldquo;I completed the lab\u0026rdquo; into \u0026ldquo;I can design the system.\u0026rdquo;\nNeither one alone gets you to competence. A learner who only does labs can operate a pre-built architecture but struggles to design a new one. A learner who only reads exam material can recite the difference between Standard and Standard-IA storage classes but freezes the first time they need to actually configure a lifecycle policy in the console.\nClose the Gap Yourself # If you\u0026rsquo;re using Cloud Quest, keep using it. It\u0026rsquo;s a genuinely useful on-ramp, and the AI feedback loop makes it easier to get unstuck without abandoning the exercise entirely. But treat every badge as a checkpoint, not a destination.\nAfter every lab, stop and ask yourself the \u0026ldquo;why\u0026rdquo; question the AI didn\u0026rsquo;t force you to answer. Why did that IAM policy work? What would break if you removed one line from it? Then go find the conceptual explanation in a deep study resource and confirm your answer. Do this consistently, and the badges stop being decoration and start being anchors for actual knowledge.\nThe exam, and more importantly the job, will not ask you to complete a guided scenario. It will hand you an ambiguous problem and ask you to design a solution using services you understand well enough to reason about under pressure. Garbage in, garbage out. If your inputs are shallow pattern-matching exercises, your output will be a candidate who can navigate a console but can\u0026rsquo;t explain a single architecture decision. Combine the practice with the understanding, and you get someone who can do both.\nRecommended Reading # AWS Certified Solutions Architect Study Guide: Associate SAA-C03 Exam, 4th Edition by Ben Piper \u0026amp; David Clinton Ace the Data Science Interview: 201 Real Interview Questions Asked By FAANG, Tech Startups, \u0026 Wall Street by Kevin Huo, Nick Singh AI Engineering: Building Applications with Foundation Models by Chip Huyen Featured image by Brett Jordan on Unsplash\n","date":"12 August 2026","externalUrl":null,"permalink":"/post/2026/aws-cloud-quests-ai-badges-are-not-enough/","section":"Posts","summary":"","title":"AWS Cloud Quest's AI Badges Are Not Enough","type":"post"},{"content":"","date":"12 August 2026","externalUrl":null,"permalink":"/tags/cloud-careers/","section":"Tags","summary":"","title":"Cloud Careers","type":"tags"},{"content":"","date":"12 August 2026","externalUrl":null,"permalink":"/tags/solutions-architect/","section":"Tags","summary":"","title":"Solutions Architect","type":"tags"},{"content":"","date":"12 August 2026","externalUrl":null,"permalink":"/tags/cloudfront/","section":"Tags","summary":"","title":"CloudFront","type":"tags"},{"content":"","date":"12 August 2026","externalUrl":null,"permalink":"/tags/dns-routing/","section":"Tags","summary":"","title":"DNS Routing","type":"tags"},{"content":"","date":"12 August 2026","externalUrl":null,"permalink":"/tags/grpc/","section":"Tags","summary":"","title":"GRPC","type":"tags"},{"content":"","date":"12 August 2026","externalUrl":null,"permalink":"/tags/route-53/","section":"Tags","summary":"","title":"Route-53","type":"tags"},{"content":"If you\u0026rsquo;ve studied for an AWS certification, you\u0026rsquo;ve memorized the difference between weighted, latency-based, and failover routing policies in Route 53. You\u0026rsquo;ve also probably forgotten why any of it matters the moment you passed the exam. Bitdrift\u0026rsquo;s recent work scaling to 121 million concurrent gRPC connections during live sporting events is a good reminder that these aren\u0026rsquo;t trivia questions. They\u0026rsquo;re load-bearing architectural decisions, and getting them wrong doesn\u0026rsquo;t cost you an exam point. It costs you an outage in front of millions of viewers.\nThe Exam Question That Wasn\u0026rsquo;t Theoretical # Every AWS study guide covers the same routing policies. Weighted routing splits traffic across resources by percentage. Latency-based routing sends users to whichever endpoint responds fastest. Failover routing keeps a backup resource on standby and reroutes traffic when the primary fails a health check.\nOn a study guide, these are four multiple-choice answers with one correct pick. In production, at the scale bitdrift was operating, they\u0026rsquo;re the difference between a distributed system and a single point of failure wearing a distributed system\u0026rsquo;s clothing.\nA gRPC connection isn\u0026rsquo;t like an HTTP request. It\u0026rsquo;s long-lived. Clients open a connection and keep it open, often for the duration of an event. When you\u0026rsquo;re talking about 121 million of those connections concurrently, during a live sporting event where everyone connects around the same moment, your DNS routing decisions determine whether that load spreads across your infrastructure or piles up on whichever origin happened to answer first.\nWhere Misapplied Routing Becomes a Single Point of Failure # Consider this scenario: You set up a simple routing policy because it\u0026rsquo;s the default and you never revisited it. Every new client resolves the same domain name, gets the same answer, and connects to the same origin.\nThat\u0026rsquo;s fine at low volume. It\u0026rsquo;s catastrophic at high volume. A single origin endpoint absorbing a meaningful fraction of 121 million long-lived connections doesn\u0026rsquo;t degrade gracefully. It falls over, and when it falls over, it takes every client attached to it down at once, because gRPC connections don\u0026rsquo;t quietly retry the way a stateless HTTP request might.\nThis is exactly the failure mode that weighted routing and latency-based routing exist to prevent. Weighted routing spreads new connections across multiple origins by design, so no single resource absorbs a disproportionate share. Latency-based routing does something subtler: it routes based on which origin can actually serve the client fastest, which in effect load-balances by geography and network conditions rather than by a fixed ratio you set once and forgot about.\nFailover routing matters here too, but for a different reason. With connections this long-lived, you can\u0026rsquo;t treat failure detection as an afterthought. You need Route 53 health checks actively monitoring origin health so that a failing endpoint gets pulled out of rotation before it drags down every client still holding an open connection to it.\nCloudFront Doesn\u0026rsquo;t Save You From a Bad DNS Strategy # A common assumption is that putting CloudFront in front of your architecture solves the distribution problem automatically. It doesn\u0026rsquo;t. CloudFront\u0026rsquo;s edge network is excellent at caching and terminating connections close to the user, but it\u0026rsquo;s not a substitute for correct origin selection. If your DNS routing funnels traffic toward a narrow set of origins behind CloudFront, you\u0026rsquo;ve just moved your single point of failure one layer deeper. It\u0026rsquo;s still there. It\u0026rsquo;s just harder to see.\nCloudFront delivers resilience only when it sits on top of a DNS strategy that\u0026rsquo;s actually doing its job. That means your routing policies need to reflect the real distribution of your infrastructure, not just the distribution you configured on day one and never touched again.\nThe Takeaway # Ask yourself which policy your production traffic is actually using right now, and whether that choice still matches your current scale and topology.\nAt 121 million concurrent connections, there\u0026rsquo;s no room for a routing decision that was correct for a demo but never revisited for production. The bitdrift numbers are a stress test you may never personally run. But the fundamentals it exposes, weighted distribution, latency awareness, and honest failover, apply at any scale where you can\u0026rsquo;t afford one origin to become the whole system\u0026rsquo;s fate.\nRecommended Reading # Networking All-in-One For Dummies by Doug Lowe CompTIA Network+ Study Guide: Exam N10-009 by Todd Lammle AWS Certified Solutions Architect Study Guide: Associate SAA-C03 Exam, 4th Edition by Ben Piper \u0026amp; David Clinton Featured image by Max Harlynking on Unsplash\n","date":"12 August 2026","externalUrl":null,"permalink":"/post/2026/what-millions-of-grpc-connections-teach-about-dns/","section":"Posts","summary":"","title":"What Millions of gRPC Connections Teach About DNS","type":"post"},{"content":"","date":"11 August 2026","externalUrl":null,"permalink":"/tags/career-advice/","section":"Tags","summary":"","title":"Career Advice","type":"tags"},{"content":"","date":"11 August 2026","externalUrl":null,"permalink":"/tags/devops/","section":"Tags","summary":"","title":"DevOps","type":"tags"},{"content":"When people try to break into IT, they often rattle off a list of job titles they found online: cloud engineer, DevOps engineer, site reliability engineer, security analyst, data engineer. They want to know which one to pick. That\u0026rsquo;s the wrong question, and it\u0026rsquo;s why so many people freeze up before they even start.\nAlmost every one of those titles is a descendant of one of two original branches: software development or systems administration. Figure out which branch fits you, and the rest of the map starts making sense.\nWhy do the branches matter more than the titles? # New IT job titles get invented constantly. Most of them are just a development or operations role wearing a different hat depending on which layer of the stack it touches and which tools happen to be fashionable that year. A \u0026ldquo;cloud engineer\u0026rdquo; is doing systems administration on infrastructure that lives in someone else\u0026rsquo;s data center. A \u0026ldquo;backend engineer\u0026rdquo; is doing software development against a database instead of a UI.\nIf you understand the two foundational branches, you can look at almost any modern job posting and immediately know what your day is actually going to look like, regardless of what the title says.\nSoftware development is translation, not typing # Writing software is fundamentally an act of translation. Someone hands you a business requirement, usually vague, sometimes contradictory, and your job is to convert that into working code. That\u0026rsquo;s the whole craft. You have to understand what the software is supposed to do well enough to express it in a programming language a computer can execute.\nBut translation isn\u0026rsquo;t the end of the job. You also have to write tests, which is more code, whose entire purpose is to verify that the code you already wrote actually does what you think it does. If you enjoy this cycle (requirement, code, test, repeat) and you can sit with a single logical problem for hours without needing to touch a keyboard-driven console or a physical (or virtual) server, development is probably your lane.\nSystems administration means deploying what you didn\u0026rsquo;t write # Systems administration asks something different of you. Instead of translating requirements into code, you have to understand software you didn\u0026rsquo;t write well enough to deploy it, keep it running, and troubleshoot it when it breaks in production at 2 a.m.\nThat software could be built in-house by your own developers or bought from a vendor who won\u0026rsquo;t tell you how it works internally. Either way, you\u0026rsquo;re responsible for the infrastructure it runs on, the network it depends on, and the fallout when something goes wrong. You don\u0026rsquo;t get to blame the code. You have to figure out whether the problem is the code, the configuration, the network, or the hardware, and you usually have to figure it out fast.\nThe line has blurred, but the mindset hasn\u0026rsquo;t # Here\u0026rsquo;s where most beginner guides get lazy. They\u0026rsquo;ll tell you development and operations have \u0026ldquo;merged\u0026rdquo; because of DevOps, containers, and infrastructure as code, and therefore the distinction doesn\u0026rsquo;t matter anymore. That\u0026rsquo;s only half true.\nThe tools have blurred together. A systems administrator today writes Python and Terraform. A developer today needs to understand containers and cloud networking to ship anything. But the core daily work and the mindset each path demands are still distinct.\nDevelopers spend long stretches translating requirements into logic and proving that logic is correct. Administrators spend their time configuring, deploying, and diagnosing systems built by other people, often under time pressure, often with incomplete information. You can learn skills from both worlds. You still have to pick which reality you want as your default.\nHow do you actually decide? # Ask yourself two honest questions.\nDo you enjoy staring at a requirement until you can express it precisely in code, then proving it works? That\u0026rsquo;s development.\nDo you enjoy taking something that already exists, making it run somewhere, and figuring out why it stopped working? That\u0026rsquo;s systems administration.\nNeither answer is more prestigious or better paid on average. Salary comparisons and trend charts won\u0026rsquo;t tell you which one you\u0026rsquo;ll still enjoy in five years. Your own attention span and curiosity will.\nPick a lane, then cross over later # You don\u0026rsquo;t need to nail this decision forever. People move between development and operations constantly once they have a foundation in either one. What you can\u0026rsquo;t do is skip the foundation. Without understanding networking and infrastructure, SDN workflows and API calls make no sense. Without understanding requirements and testing, \u0026ldquo;just learn to code\u0026rdquo; is meaningless advice.\nPick the branch that matches how you actually want to spend your working hours. Everything else, the job titles, the tool stacks, the certifications, is just decoration on top of that decision.\nRecommended Reading # AWS Certified Solutions Architect Study Guide: Associate SAA-C03 Exam, 4th Edition by Ben Piper \u0026amp; David Clinton CompTIA A+, Network+, Security+ Complete Study Guide Set by Todd Lammle, Quentin Docter, Jon Buhagiar CCNP Enterprise Certification Study Guide: 350-401 ENCOR by Ben Piper Featured image by Liana S on Unsplash\n","date":"11 August 2026","externalUrl":null,"permalink":"/post/2026/how-to-choose-an-it-career-path/","section":"Posts","summary":"","title":"How To Choose an IT Career Path","type":"post"},{"content":"","date":"11 August 2026","externalUrl":null,"permalink":"/tags/software-development/","section":"Tags","summary":"","title":"Software Development","type":"tags"},{"content":"","date":"11 August 2026","externalUrl":null,"permalink":"/tags/systems-administration/","section":"Tags","summary":"","title":"Systems Administration","type":"tags"},{"content":"","date":"8 August 2026","externalUrl":null,"permalink":"/tags/ai/","section":"Tags","summary":"","title":"AI","type":"tags"},{"content":"","date":"8 August 2026","externalUrl":null,"permalink":"/tags/cost-optimization/","section":"Tags","summary":"","title":"Cost Optimization","type":"tags"},{"content":"","date":"8 August 2026","externalUrl":null,"permalink":"/tags/deepseek/","section":"Tags","summary":"","title":"Deepseek","type":"tags"},{"content":"","date":"8 August 2026","externalUrl":null,"permalink":"/tags/edge-computing/","section":"Tags","summary":"","title":"Edge Computing","type":"tags"},{"content":"","date":"8 August 2026","externalUrl":null,"permalink":"/tags/generative-ai/","section":"Tags","summary":"","title":"Generative Ai","type":"tags"},{"content":"","date":"8 August 2026","externalUrl":null,"permalink":"/tags/iot/","section":"Tags","summary":"","title":"Iot","type":"tags"},{"content":"Every serious AI lab has been racing in the same direction on inference pricing: down. Open weight models keep multiplying, compute gets cheaper, and competition forces providers to shave margins to stay relevant. So when DeepSeek raised its API prices instead of continuing the race to the bottom, that\u0026rsquo;s not a rounding error. It\u0026rsquo;s a reversal of the one trend you could count on in this industry.\nThat reversal is why people are asking whether DeepSeek was ever really competing on unit economics, or whether the rock-bottom pricing served a different purpose entirely: get as much sensitive data flowing through a Chinese-controlled API as possible, then adjust the business model once you don\u0026rsquo;t need the loss leader anymore.\nI\u0026rsquo;m not going to tell you DeepSeek is a state-run honeypot. I don\u0026rsquo;t have the access to prove that, and neither does anyone writing hot takes on social media. But I can walk through the economics, the timeline, and the incentive structure, and you can draw your own conclusion. More importantly, the conclusion you should draw about your own company\u0026rsquo;s due diligence doesn\u0026rsquo;t actually depend on whether the honeypot theory is true.\nWhat Pricing Trend Did DeepSeek Break? # Inference costs for a given model quality tier are supposed to go one direction as more open weight competitors enter the market: down. That\u0026rsquo;s what happened with Llama derivatives, with Mistral, and with the entire ecosystem of Chinese and Western open weight releases racing to commoditize the layer below the frontier labs. DeepSeek was the poster child for this trend. Its pricing undercut Western competitors so aggressively that it became the default recommendation for cost-conscious teams building anything with an LLM in the loop.\nThen DeepSeek raised prices. Not adjusted at the margins, but a real hike that ran against every other provider\u0026rsquo;s direction of travel. If DeepSeek were simply optimizing for market share in a commodity market, this makes no sense. Commodity providers don\u0026rsquo;t raise prices once they\u0026rsquo;ve built a user base on cheap access. They keep racing downward until someone gets squeezed out.\nDo Free Tools Function as Acquisition Funnels Either Way? # Whatever DeepSeek\u0026rsquo;s original motivation was, the effect of near-free API access combined with tools like OpenCode routing traffic through DeepSeek models functioned exactly like a customer acquisition funnel. Developers didn\u0026rsquo;t need to be convinced to try it. The price did the convincing. Teams wired DeepSeek into agentic coding tools, internal chatbots, and data pipelines because the marginal cost was close to zero and the model was good enough for a lot of use cases.\nIntent doesn\u0026rsquo;t matter here. Whether DeepSeek subsidized pricing to gain market share the normal way, or subsidized it to maximize the volume of data flowing through their infrastructure, the practical outcome for downstream companies is identical. A large number of organizations built dependencies on a foreign-controlled API with no meaningful oversight into what happens to the data once it leaves their network.\nCan Anyone Verify What Happens to Your Data? # This is the part that should bother you regardless of what you believe about DeepSeek\u0026rsquo;s motives. When you send a prompt to DeepSeek\u0026rsquo;s API, you have no way to independently verify how that data is stored, how long it\u0026rsquo;s retained, whether it\u0026rsquo;s logged for debugging, or whether it gets folded into future training runs. You\u0026rsquo;re trusting a terms-of-service document written by a company operating under a legal jurisdiction that doesn\u0026rsquo;t recognize the data protection guarantees you\u0026rsquo;d expect from providers subject to GDPR, CCPA, or comparable frameworks.\nCompare that to the diligence most companies apply to a vendor handling payment data or health records. Nobody signs a contract with a payment processor based purely on \u0026ldquo;trust us.\u0026rdquo; You demand audits, certifications, contractual data handling terms, and the ability to walk away if they\u0026rsquo;re violated. None of that infrastructure exists for a lot of the DeepSeek API traffic that got routed in over the past year. Companies sent proprietary code, internal documents, and customer data to an API because it was cheap, not because they\u0026rsquo;d done the same diligence they\u0026rsquo;d apply to any other third-party data processor.\nWas the Pricing Ever Just About a Better Product? # One counterargument you\u0026rsquo;ll hear is that DeepSeek\u0026rsquo;s pricing was simply justified by superior efficiency, better model architecture, and cheaper training runs. That argument gets weaker the more you look at actual model quality. DeepSeek\u0026rsquo;s outputs have consistently trailed Anthropic\u0026rsquo;s models on the tasks that matter most for serious engineering and reasoning work. If the product were categorically better, you\u0026rsquo;d expect pricing that reflected efficiency gains at the margins, not pricing so far below the market that it essentially eliminated the calculation. A product that\u0026rsquo;s merely competitive, not superior, being sold at a steep discount is a red flag for subsidization, not innovation.\nThat doesn\u0026rsquo;t prove state involvement. It just means the \u0026ldquo;we\u0026rsquo;re simply more efficient\u0026rdquo; explanation doesn\u0026rsquo;t hold up as the sole reason for the pricing gap.\nIs the Honeypot Question a Distraction From the Real Failure? # Here\u0026rsquo;s the part that matters more than the conspiracy angle. Whether or not DeepSeek was ever designed to harvest data, the fact that so many companies routed sensitive information through an unaudited foreign API without asking basic questions is a failure of process, not a failure of prediction. You don\u0026rsquo;t need to prove malicious intent to justify demanding contractual data handling guarantees, third-party audits, or at minimum, a policy about what categories of data are allowed to touch a given API.\nThe honeypot theory is interesting. It\u0026rsquo;s also unfalsifiable with the information publicly available. What is falsifiable, and already demonstrated, is that a lot of organizations skipped the diligence step entirely because the price was too good to pass up. That\u0026rsquo;s the actual lesson here, and it would still be the lesson even if DeepSeek turns out to be exactly what it claims to be.\nWhat Should You Actually Do About It? # Treat every third-party API, especially ones operating outside your regulatory jurisdiction, the same way you\u0026rsquo;d treat any vendor with access to sensitive data. Ask for their data retention policy in writing. Find out whether prompts get used for training, and get a contractual commitment, not a blog post assurance. Segment what kinds of data are allowed to flow through cheap or free tooling versus what stays behind your own infrastructure.\nCheap inference is not a substitute for due diligence. If a provider\u0026rsquo;s pricing doesn\u0026rsquo;t match the economics of the market they\u0026rsquo;re operating in, that\u0026rsquo;s not a reason to trust them more because you\u0026rsquo;re saving money. It\u0026rsquo;s a reason to ask why the numbers don\u0026rsquo;t add up before you send them anything you can\u0026rsquo;t afford to lose control of.\nRecommended Reading # AI Engineering: Building Applications with Foundation Models by Chip Huyen CompTIA Network+ Study Guide: Exam N10-009 by Todd Lammle AWS Certified Solutions Architect Study Guide: Associate SAA-C03 Exam, 4th Edition by Ben Piper \u0026amp; David Clinton Featured image by Daniella Pienaar on Unsplash\n","date":"8 August 2026","externalUrl":null,"permalink":"/post/2026/is-deepseek-a-chinese-honeypot/","section":"Posts","summary":"","title":"Is DeepSeek a Chinese Honeypot?","type":"post"},{"content":"Offline-first generative AI at the edge is a legitimate pattern for a narrow set of problems. It\u0026rsquo;s a reasonable way to address reliability concerns when third-party inference providers become unavailable. That dowtime can be costly, particularly in industrial scenarios such as manufacturing. Manufacturing lines do lose enormous amounts of money when equipment fails unexpectedly.\nBut what\u0026rsquo;s questionable is the leap from \u0026ldquo;downtime is expensive\u0026rdquo; to \u0026ldquo;therefore you need an offline generative AI model running inference at the edge.\u0026rdquo; That\u0026rsquo;s a big leap in logic, and it skips over a simpler question: what problem are you actually solving with AI?\nSometimes, AI gets needlessly forced into a problem that\u0026rsquo;s already been solved. If the goal is catching a bearing that\u0026rsquo;s about to fail, a vibration sensor feeding a threshold-based alert has been solving that problem for decades. It\u0026rsquo;s deterministic, it\u0026rsquo;s cheap, and it doesn\u0026rsquo;t require a model at all. Generative AI earns its place when the failure modes are ambiguous, the data is unstructured (audio, images, free-text maintenance logs), and you need something closer to reasoning than pattern-matching against a fixed threshold.\nWhat \u0026ldquo;offline-first\u0026rdquo; actually costs you # Offline-first means the system has to function correctly with zero connectivity, not degrade gracefully once connectivity returns. That distinction changes your entire architecture.\nYou\u0026rsquo;re no longer just running a model. You\u0026rsquo;re managing:\nLocal model storage and versioning on hardware that might not have the disk or RAM to hold a full-size model State reconciliation for whatever the device did while disconnected Conflict resolution when multiple edge nodes report contradictory data once they sync Update distribution across a fleet that might be intermittently reachable for weeks AWS IoT Greengrass handles a lot of the plumbing here, and it\u0026rsquo;s genuinely good at what it does. But Greengrass doesn\u0026rsquo;t make the sync conflict problem go away. It just gives you the tools to build your own resolution logic, which is still your job, and it\u0026rsquo;s not trivial.\nGenerative AI on constrained hardware runs into physics, not marketing # This is the part some edge-AI content tends to underplay. A generative model that performs well in a demo running on a well-provisioned instance behaves very differently on a Jetson-class device sitting in a control cabinet.\nYou have three real constraints working against you simultaneously:\nModel size. You can\u0026rsquo;t run a full-precision large model on constrained hardware. You quantize it, which trades accuracy for footprint. The demo you saw in the keynote was probably not running the quantized version.\nLatency. Edge hardware doesn\u0026rsquo;t have the parallel compute of a data center GPU cluster. Inference that takes 200 milliseconds in the cloud might take several seconds locally. If your use case involves anything approaching real-time control, that latency is disqualifying.\nThermal and power limits. Industrial edge devices often live in enclosures with limited cooling and fixed power budgets. Sustained inference workloads generate heat that the hardware wasn\u0026rsquo;t necessarily designed to dissipate continuously.\nNone of this means edge generative AI doesn\u0026rsquo;t work. It means the constraints are real engineering tradeoffs, not implementation details you wave away with a bigger SKU.\nThe maintenance curve nobody draws # Here\u0026rsquo;s the part that matters most for anyone actually signing off on a budget. Edge AI infrastructure has a maintenance cost that scales with the size of your fleet, not with the value of the problem it\u0026rsquo;s solving.\nA hundred edge devices running local inference means a hundred places where models drift, hardware fails, firmware needs patching, and connectivity gaps create data gaps you have to backfill. That overhead is roughly constant per device regardless of whether the device is protecting a $50,000 pump or a $500,000 turbine.\nThis is the actual cost-benefit question that gets skipped. If the downtime you\u0026rsquo;re preventing is genuinely catastrophic (a production line stoppage costing tens of thousands of dollars per hour), the maintenance overhead is worth it. If you\u0026rsquo;re deploying the same architecture to catch minor quality drift on a low-value line, you\u0026rsquo;ve built a Ferrari to deliver pizza.\nWhen it actually makes sense # Edge generative AI earns its complexity when all of these are true at once:\nThe failure mode is genuinely ambiguous, not something a threshold or rule engine already catches Connectivity loss is common enough that cloud inference isn\u0026rsquo;t viable, not just theoretically possible The cost of downtime or failure is high enough to absorb the fleet-wide maintenance burden You have (or are willing to build) the operational muscle to manage model versioning, conflict resolution, and hardware lifecycle across a distributed fleet If any of those don\u0026rsquo;t hold, you\u0026rsquo;re probably better served by a simpler monitoring stack, a rules engine, or a classical ML model that fits comfortably on the hardware you already have.\nThe practical move # Before you architect an offline-first generative AI system, run the numbers on a boring alternative first. Price out a threshold-based anomaly detector or a small classical model against the same downtime figures the vendor deck is using. If the generative AI system doesn\u0026rsquo;t clearly outperform that baseline on the specific failure modes you care about, you don\u0026rsquo;t have an AI problem. You have a sensor and alerting problem, and it doesn\u0026rsquo;t need a model at all, let alone one running offline on a device you\u0026rsquo;ll have to maintain by hand for the next few years.\nRecommended Reading # AI Engineering: Building Applications with Foundation Models by Chip Huyen AWS Certified Solutions Architect Study Guide: Associate SAA-C03 Exam, 4th Edition by Ben Piper \u0026amp; David Clinton The LLM Engineer's Handbook by Paul Iusztin and Maxime Labonne Featured image by Steve A Johnson on Unsplash\n","date":"8 August 2026","externalUrl":null,"permalink":"/post/2026/offline-first-ai-at-the-edge-the-aws-reality-check/","section":"Posts","summary":"","title":"Offline-First AI at the Edge: The AWS Reality Check","type":"post"},{"content":"","date":"7 August 2026","externalUrl":null,"permalink":"/tags/certifications/","section":"Tags","summary":"","title":"Certifications","type":"tags"},{"content":"A lot of career advice assumes you have the luxury of time to network, build a personal brand, and wait for the \u0026ldquo;right\u0026rdquo; opportunity. If you\u0026rsquo;re reading this, you probably don\u0026rsquo;t have that luxury. So let\u0026rsquo;s skip the fluff and talk about how hiring actually works, and what you can do about it starting today.\nHiring managers are looking for reasons to say no # Hiring isn\u0026rsquo;t a search for the best candidate. It\u0026rsquo;s a process of elimination. A hiring manager has a stack of resumes and limited time. Their job isn\u0026rsquo;t to find the perfect person. It\u0026rsquo;s to find someone who doesn\u0026rsquo;t give them a reason to worry.\nEveryone has flaws. Every candidate has a gap, a weak spot, something a hiring manager might not love. That\u0026rsquo;s not disqualifying by itself. What\u0026rsquo;s disqualifying is when the flaws start piling up, or when you hand the hiring manager an obvious red flag on a silver platter.\nThis changes how you should think about your entire job search. You\u0026rsquo;re not trying to be the most impressive candidate in the pile. You\u0026rsquo;re trying to be the candidate with the fewest reasons to reject.\nAttitude is the fastest disqualifier there is # Negativity, entitlement, and desperation get candidates cut faster than almost anything else, including a thin resume. This shows up in subtle ways. Complaining about a previous employer in an interview. Listing \u0026ldquo;attention to detail\u0026rdquo; while your resume has a typo. Coming across like the world owes you a job.\nNobody owes you anything, not even an interview. Genuine humility goes a long way here, and it costs you nothing.\nThe mindset shift you need is this: your resume and interview are not about what the employer can do for you. They\u0026rsquo;re an advertisement for what you can do for the employer. You might be desperate for income (understandably so), but that desperation needs to stay off the page and out of your voice in the interview room.\nStop putting salary expectations and desired titles on your resume # I advise against listing a desired salary or a desired position on your resume. This is where a lot of well-meaning advice gets it backward.\nThe logic behind listing your desired salary seems reasonable: save everyone time, be upfront. But think about what it actually communicates. It tells the employer what you want before they\u0026rsquo;ve decided what you\u0026rsquo;re worth to them. It centers your needs in a document whose entire job is to center your value to them. Save that conversation for later in the process, when you have leverage because they already want you.\nThe same goes for the \u0026ldquo;Open to Work\u0026rdquo; badge. I don\u0026rsquo;t like it, and here\u0026rsquo;s why. People have an unfair, often unconscious bias: if you\u0026rsquo;re not currently employed, something must be wrong with you. It\u0026rsquo;s not fair, and it\u0026rsquo;s not always true, but it\u0026rsquo;s real, and you\u0026rsquo;re not going to fix hiring bias by broadcasting your unemployment. Your job right now isn\u0026rsquo;t to correct that bias. It\u0026rsquo;s to not trigger it.\nGet a second set of eyes on your resume # You\u0026rsquo;ve probably already polished your resume if you\u0026rsquo;re in a job search. Do it again anyway. Ask a friend, ideally someone in a hiring role or at least in tech, to look it over.\nYou\u0026rsquo;re not looking for a total rewrite. You\u0026rsquo;re looking for the glaring problem you can\u0026rsquo;t see because you\u0026rsquo;ve stared at the document too long. A formatting inconsistency. An unclear job title. A sentence that reads as arrogant when you meant it as confident. These small things become the disqualifiers I mentioned earlier, and a second set of eyes catches what you can\u0026rsquo;t.\nGet certified this week, not eventually # If you don\u0026rsquo;t already hold a certification in the field you\u0026rsquo;re targeting, get one. But here\u0026rsquo;s the part people get wrong: don\u0026rsquo;t chase prestige. Chase speed.\nFind an entry-level certification you can study for and pass within a week. Not a certification that takes three months of grinding through practice exams and hands-on labs. Not the one that makes you look impressive at a conference. The one you can actually complete quickly.\nWhy does this work? Because the certification isn\u0026rsquo;t proving mastery. Nobody hiring for an entry-level or transitional role expects a week-old certification to mean you\u0026rsquo;re an expert. What it proves is initiative. It shows you took action, right now, in a measurable and verifiable way, instead of just saying you\u0026rsquo;re passionate about tech in a cover letter.\nThere\u0026rsquo;s also a practical filtering reason. Many companies (and their applicant tracking systems) use certifications as a hard filter before a human ever reads your resume. A quick, relevant certification can get you past that filter. That\u0026rsquo;s the whole point. You\u0026rsquo;re not trying to win an award. You\u0026rsquo;re trying to clear a gate.\nKeep the whole approach boring on purpose # Notice a pattern here. Don\u0026rsquo;t complain. Don\u0026rsquo;t list your desires ahead of your value. Don\u0026rsquo;t broadcast unemployment. Don\u0026rsquo;t chase an impressive certification when a fast one will do. Every piece of this advice is about removing something that could work against you, not adding something flashy.\nThat\u0026rsquo;s because hiring managers aren\u0026rsquo;t looking for a reason to be dazzled. They\u0026rsquo;re looking for a reason to be comfortable. Comfortable means predictable, humble, capable, and free of obvious red flags. Flashy and impressive can actually work against you if it reads as arrogant or high-maintenance.\nWhat to actually do this week # If you need a job now, here\u0026rsquo;s the sequence, in order.\nPick one entry-level certification relevant to the role you want, and pick it based on how fast you can pass it, not how impressive it sounds. Study daily until you pass it. A week is the target, not a suggestion you can slide on. Strip your resume of desired salary, desired title, and any language that centers what you want instead of what you offer. Send it to someone else to review before you submit it anywhere. Remove any \u0026ldquo;Open to Work\u0026rdquo; signaling from your profiles. Apply broadly, and in every interview, keep the conversation focused on what you bring to the table, not what you need from them. None of this is glamorous. None of it involves a personal brand or a networking strategy that pays off in six months. It\u0026rsquo;s a short list of things you can control, starting today, that remove the easiest reasons a hiring manager has to say no. That\u0026rsquo;s the whole game. Play it accordingly.\nRecommended Reading # AWS Certified Solutions Architect Study Guide: Associate SAA-C03 Exam, 4th Edition by Ben Piper \u0026amp; David Clinton AWS Certified Cloud Practitioner Study Guide: CLF-C01 Exam by Ben Piper \u0026amp; David Clinton CCNP Enterprise Certification Study Guide: 350-401 ENCOR by Ben Piper \u0026amp; David Clinton Featured image by Bennie Bates on Unsplash\n","date":"7 August 2026","externalUrl":null,"permalink":"/post/2026/how-to-get-an-it-job-right-now/","section":"Posts","summary":"","title":"How to Get an IT Job Right Now","type":"post"},{"content":"","date":"7 August 2026","externalUrl":null,"permalink":"/tags/it-careers/","section":"Tags","summary":"","title":"IT Careers","type":"tags"},{"content":"","date":"7 August 2026","externalUrl":null,"permalink":"/tags/job-search/","section":"Tags","summary":"","title":"Job Search","type":"tags"},{"content":"","date":"7 August 2026","externalUrl":null,"permalink":"/tags/resume-tips/","section":"Tags","summary":"","title":"Resume Tips","type":"tags"},{"content":"","date":"6 August 2026","externalUrl":null,"permalink":"/tags/anthropic/","section":"Tags","summary":"","title":"Anthropic","type":"tags"},{"content":"","date":"6 August 2026","externalUrl":null,"permalink":"/tags/claude/","section":"Tags","summary":"","title":"Claude","type":"tags"},{"content":"","date":"6 August 2026","externalUrl":null,"permalink":"/tags/cloud-architecture/","section":"Tags","summary":"","title":"Cloud Architecture","type":"tags"},{"content":"","date":"6 August 2026","externalUrl":null,"permalink":"/tags/eks/","section":"Tags","summary":"","title":"EKS","type":"tags"},{"content":"Every \u0026ldquo;how to spot AI writing\u0026rdquo; listicle on the internet has the same complaint: too many em dashes. Writers treat it like a smoking gun—proof that a human didn\u0026rsquo;t touch the text. What none of them ask is where that habit came from. Models don\u0026rsquo;t invent punctuation preferences out of thin air. They learn them from something. And it turns out at least part of that something is me.\nI\u0026rsquo;ve been writing with em dashes since long before anyone was training large language models on anything. My Cisco networking book from 2015 is full of them. So are the AWS study guides Sybex published in 2019. This isn\u0026rsquo;t a new tic I picked up to sound clever. It\u0026rsquo;s just how I write, and it\u0026rsquo;s been in print for over a decade.\nThe training data connection # Anthropic has faced public lawsuits and disclosures over the use of published books in training data for its Claude models. Some of those disclosures have included titles from technical and educational publishers—the same kind of publisher that put out my books. I\u0026rsquo;m not going to pretend I know the exact weighting my sentences got in a multi-billion-parameter model. Nobody outside Anthropic actually knows that. But the mechanism is real, documented, and not remotely speculative: books get scraped, books get trained on, and the stylistic fingerprints of the humans who wrote them get folded into the statistical soup that becomes the model\u0026rsquo;s \u0026ldquo;voice.\u0026rdquo;\nSo when millions of people started noticing that Claude (and plenty of other models) leans hard on the em dash, I read the complaints with a certain quiet pride. Somewhere in a dataset, a sentence I wrote about VLANs or IAM policies got vectorized right alongside a thousand novelists and a few million Reddit posts. The em dash didn\u0026rsquo;t come from nowhere. It came from somewhere. And there\u0026rsquo;s a real chance \u0026ldquo;somewhere\u0026rdquo; includes me.\nWhy the em dash gets blamed for being an AI tell # Here\u0026rsquo;s what bugs me about the \u0026ldquo;AI overuses em dashes\u0026rdquo; complaint: it treats the em dash itself as the problem, when the actual problem is repetition without variation. A model that drops an em dash into every third sentence isn\u0026rsquo;t wrong to use the punctuation mark—it\u0026rsquo;s wrong to use it as a crutch instead of a choice.\nThe em dash is one of the most useful marks in the English language. It does something a comma can\u0026rsquo;t: it interrupts a sentence with force, sets off a phrase that needs emphasis, and lets you insert a thought without derailing the grammar around it. A comma is polite. An em dash is decisive. When you want to slow a reader down and make them notice something, the em dash does that better than almost any alternative.\nThe failure isn\u0026rsquo;t the mark. It\u0026rsquo;s the monotony. If every single sentence in a paragraph uses the same structural trick, the writing starts to sound like it\u0026rsquo;s following a template rather than making decisions. That\u0026rsquo;s true whether a human does it or a model does it. The fix isn\u0026rsquo;t banning em dashes. It\u0026rsquo;s using them the way any punctuation should be used: because the sentence needs it, not because the last ten sentences did too.\nStyle is data, whether you meant it to be or not # There\u0026rsquo;s a broader point buried in this that\u0026rsquo;s worth taking seriously, even if the framing is a joke. Individual writing style doesn\u0026rsquo;t stay individual once it\u0026rsquo;s published. If your book sells enough copies to end up in a training corpus, your sentence rhythms, your punctuation habits, your favorite transitional phrases all become raw material for a statistical model that will go on to write emails, essays, and code comments for people who have never heard of you and never will.\nNobody signed up for this when book contracts got negotiated. It\u0026rsquo;s not something authors were warned about, and it\u0026rsquo;s part of why the lawsuits exist in the first place. But it does mean something practical for anyone who writes for a living now: your voice on the page isn\u0026rsquo;t just yours anymore. It\u0026rsquo;s an input. Somewhere downstream, a model absorbed a fraction of a percent of your habits and is now reproducing them at a scale you\u0026rsquo;ll never personally reach.\nThat\u0026rsquo;s a strange thing to sit with. It\u0026rsquo;s also, honestly, a little bit flattering.\nSo what do you do with this? # Nothing, really. This isn\u0026rsquo;t a call to action or a warning about protecting your intellectual property, though that\u0026rsquo;s a real conversation happening elsewhere. It\u0026rsquo;s just a reminder that writing style isn\u0026rsquo;t as personal or as contained as people assume.\nIf you\u0026rsquo;ve noticed AI-generated text leaning on em dashes and found it annoying, you now have a slightly more interesting theory than \u0026ldquo;the model is broken.\u0026rdquo; Some fraction of that habit traces back to real writers who used the mark deliberately, correctly, and well before it became a punchline. I happen to be one of them, and I\u0026rsquo;m not giving up the em dash just because a chatbot picked up the habit too.\nIf you found this post useful, you might also be interested in:\nAWS Certified Solutions Architect Study Guide: Associate SAA-C03 Exam, 4th Edition by Ben Piper \u0026amp; David Clinton AWS Certified Cloud Practitioner Study Guide: CLF-C01 Exam by Ben Piper \u0026amp; David Clinton CCNP Enterprise Certification Study Guide: 350-401 ENCOR by Ben Piper \u0026amp; David Clinton Featured image by Milad Fakurian on Unsplash\nRecommended Reading # CCNP Enterprise Certification Study Guide: 350-401 ENCOR by Ben Piper \u0026amp; David Clinton AWS Certified Solutions Architect Study Guide: Associate SAA-C03 Exam, 4th Edition by Ben Piper \u0026amp; David Clinton AWS Certified Cloud Practitioner Study Guide: CLF-C01 Exam by Ben Piper \u0026amp; David Clinton ","date":"6 August 2026","externalUrl":null,"permalink":"/post/2026/i-taught-ai-to-love-em-dashes/","section":"Posts","summary":"","title":"I'm the Reason AI Loves Em Dashes","type":"post"},{"content":"","date":"6 August 2026","externalUrl":null,"permalink":"/tags/kubernetes/","section":"Tags","summary":"","title":"Kubernetes","type":"tags"},{"content":"","date":"6 August 2026","externalUrl":null,"permalink":"/tags/llms/","section":"Tags","summary":"","title":"LLMs","type":"tags"},{"content":"The panicked push for AI governance reveals why AI is so hard to implement and get value from at scale.\nThe Real Cost of AI Inference # Cost is the one thing that always gets mentioned. Inference is expensive. Not just token cost, but the fact that we have to rerun the same prompts and contexts over and over, essentially running trial and error until we get the right result.\nBy now, we all know AI never gives perfect outputs. We accept error as a cost of doing business with Mr. AI. That understanding is baked into everything governance-related, including guardrails and compliance.\nEvery public-facing AI-enabled widget has a disclaimer that \u0026ldquo;AI makes mistakes!\u0026rdquo; You don\u0026rsquo;t see a medical records system pop up a message saying, \u0026ldquo;This EMR system makes mistakes!\u0026rdquo; You can imagine how that would go over.\nAnd that is why there\u0026rsquo;s a panicked push for governance around AI. It\u0026rsquo;s not just that AI isn\u0026rsquo;t perfect. It\u0026rsquo;s not even that AI isn\u0026rsquo;t good enough, because often it is.\nThe problem is we don\u0026rsquo;t know when its outputs will fall within the acceptable error thresholds. That uncertainty means we have to adjust our workflows to handle the cases where AI is really bad and human review is required.\nWhy AI Needs a Human in the Loop # I\u0026rsquo;ve always said, and I stand by this, that any critical AI-enabled workflow must have a human in the loop. What \u0026ldquo;critical\u0026rdquo; means depends on the context, but at a minimum, anything affecting human life.\nThat means no outsourcing diagnoses solely to AI. It also means not letting AI be a standalone air traffic controller, a driver, or a pilot. We can use AI in those cases, but there must be a human to make decisions where a bad output could be catastrophic.\nSo what\u0026rsquo;s the problem with just human-in-the-looping everything? If you design things right from the start, it isn\u0026rsquo;t a problem.\nBut what happens is that people let AI dictate the workflow (something else I\u0026rsquo;ve railed against from the beginning). It\u0026rsquo;s fine to ask AI for advice, and it might even be good advice that you end up taking. But ultimately a human is comprehending and approving the design first.\nAt that point, where to place manual human-in-the-loop approvals becomes a business decision.\nWho Should Design the Workflow? # This is exactly why so many companies are hiring architects to design custom agentic AI frameworks. Businesses want AI, but they aren\u0026rsquo;t used to letting the devs, architects, and engineers be involved in creating or critiquing the high-level workflows.\nThis is why the forward deployed engineer (FDE) role has suddenly appeared seemingly out of nowhere. I\u0026rsquo;ve always been a generalist, and this is why.\nA decade before AI, it was obvious to me that businesses were missing out because they didn\u0026rsquo;t invite the tech nerds to the strategy meetings. It took fear of missing out (FOMO) about AI to make them finally see the value in having a seasoned technology expert involved throughout the whole process, from high-level workflow design to implementation to day-two operations.\nGovernance Creates Silos # Okay, so now that we\u0026rsquo;re shelling out to implement AI, we have another problem. Everywhere AI receives an input or generates an output in a workflow, there\u0026rsquo;s some nexus to a governance concern: data privacy, compliance, risk, finance, you name it.\nSo as we walk through the workflow, the rules change. And that\u0026rsquo;s how silos are born. Governance requires AI silos.\nThat\u0026rsquo;s not as bad as it sounds. One team can manage all of the AI silos. But in most organizations, a team with a holistic understanding of the entire workflow doesn\u0026rsquo;t exist below the manager level.\nNow we have to have a team of AI engineers who understand the governance requirements for AI at every stage of the workflow. Note that this is different from a software engineer writing rules that differ depending on what part of the code he or she is working on.\nThe AI engineers have to know and implement not just the rules, but also babysit AI\u0026rsquo;s inputs and outputs so that the workflow diverges accordingly when AI violates the rules (which it inevitably will). So it\u0026rsquo;s not just about wrapping guardrails around AI. It\u0026rsquo;s about detecting when AI has slammed into a guardrail, and responding in a way that yields a deterministic output that the downstream workflow stages can use.\nDetecting When AI Fails # To get a better feel for this, think about how AI might answer a particular request. It can (1) do what you asked, (2) do the opposite, or (3) do something else entirely, like actively refuse, babble, or give irrelevant output.\nHow do you detect when AI has done this? There\u0026rsquo;s no automated way to detect that with 100% certainty. This is why critical tasks need a human in the loop.\nIf you think about it, this makes a lot of sense. If you could reliably detect when AI fulfilled a request properly, then why would you need AI to start with?\nFor example, if you gave it a collection of documents and asked for a complete list of names and roles that appear in those documents, how would you know if it gave you a full list, or left some out? Or hallucinated names or roles? Or mixed them up?\nIf you had a reliable way to detect that, you wouldn\u0026rsquo;t need AI. And there\u0026rsquo;s the rub.\nTrading Accuracy for Speed # We use AI for tasks that humans do with accuracy, but slowly. We\u0026rsquo;re trading accuracy for speed. In some cases, we can make that sacrifice. It\u0026rsquo;s a calculated risk.\nBut when it comes to some things, we don\u0026rsquo;t want to sacrifice accuracy or speed. So we use AI, but with a human check to \u0026ldquo;put back\u0026rdquo; the accuracy that AI took out.\nThere\u0026rsquo;s no free lunch. It\u0026rsquo;s a question of optimization.\nThe Bicycle Analogy # In an interview, Steve Jobs once pointed out that a human on a bicycle is more energy efficient than any other animal. I\u0026rsquo;ve said that LLMs are the bicycles of the information age.\nA bicycle is a series of machines optimized for rolling along. To make my analogy a little tighter, LLMs are the machines, and if we piece them together right, we can build our own \u0026ldquo;information bicycles.\u0026rdquo;\nIf you found this post useful, you might also be interested in:\nAI Engineering: Building Applications with Foundation Models by Chip Huyen The LLM Engineer's Handbook by Paul Iusztin and Maxime Labonne Designing Multi-Agent Systems: Principles, Patterns and Implementation by Victor Dibia Recommended Reading # AI Engineering: Building Applications with Foundation Models by Chip Huyen Designing Multi-Agent Systems: Principles, Patterns and Implementation by Victor Dibia The LLM Engineer's Handbook by Paul Iusztin and Maxime Labonne ","date":"6 August 2026","externalUrl":null,"permalink":"/post/2026/the-panicked-push-for-ai-governance/","section":"Posts","summary":"","title":"The Panicked Push for AI Governance","type":"post"},{"content":"AWS manages the EKS control plane: the etcd cluster, API server, scheduler, and controller manager. It patches and replaces unhealthy control-plane nodes, scales the control plane, and runs it for high availability across Availability Zones. None of that stops a Deployment from getting stuck at 3 of 5 replicas at 2 a.m. while an on-call engineer stares at a dashboard with no idea what to do next.\nEKS removes one category of operational toil: operating the Kubernetes control plane. It does not remove the need to understand how Kubernetes schedules workloads, routes traffic, or applies resource requests and limits.\nWhat EKS manages—and what it doesn’t # AWS runs and secures the EKS control plane. You do not SSH into control-plane nodes, operate etcd yourself, or debug a split-brain failure in the cluster’s key-value store.\nYour workloads still run on the data plane. In a conventional EKS setup, that includes your worker nodes, Pods, workload configuration, node groups, VPC and CNI configuration, and IAM setup for workloads. AWS supplies and operates underlying cloud infrastructure, but you remain responsible for defining, configuring, observing, and troubleshooting your applications and their Kubernetes resources. The precise boundary changes if you use options such as EKS Auto Mode, Fargate, or AWS-managed add-ons.\nA stuck Deployment still needs Kubernetes knowledge # Suppose a Deployment update stalls at 3 of 5 replicas. The first move is the same on EKS, GKE, or a self-managed cluster:\nkubectl describe pod \u0026lt;pod-name\u0026gt; -n \u0026lt;namespace\u0026gt; The Events section might show:\n0/5 nodes are available: 5 Insufficient cpu. That means the scheduler cannot find a node with enough requested CPU for the Pod. Kubernetes schedules based on declared resource requests, not on whether a dashboard suggests that current CPU usage is low. AWS cannot infer your intended capacity or rewrite your Pod specifications for you.\nA rollout can also stall because replacement Pods never become Ready, images cannot be pulled, an admission policy rejects a Pod, a quota is exhausted, or the Deployment’s maxUnavailable and maxSurge settings constrain progress.\nA PodDisruptionBudget is different: it primarily limits voluntary evictions, such as those used when draining a node. It does not ordinarily govern the Deployment controller’s own rolling-update behavior.\nCrashLoopBackOff is not the cause # CrashLoopBackOff describes Kubernetes backing off after a container repeatedly terminates. It tells you the container is failing; it does not explain why.\nStart with the logs from the previous container instance:\nkubectl logs \u0026lt;pod-name\u0026gt; -n \u0026lt;namespace\u0026gt; --previous The --previous flag matters because the newly restarted container may not yet have emitted useful logs. Then inspect the container’s termination reason and exit code in kubectl describe pod.\nExit code 137 often appears when a container was OOM-killed, but the code alone only indicates a SIGKILL. Confirm that the termination reason is OOMKilled before treating it as a memory-limit problem. Exit codes such as 1 and 2 commonly signal application-level errors, but their exact meaning depends on the application.\nThe EKS-specific networking trap # EKS adds AWS-specific networking constraints that make Kubernetes fundamentals more—not less—important. With the Amazon VPC CNI’s typical IPv4 configuration, Pods receive IP addresses from VPC networking resources associated with worker-node ENIs. Node instance types have limits on ENIs and addresses per ENI, while subnets have finite available IP space.\nIf capacity is exhausted, Pods can remain in ContainerCreating and report an error such as:\nFailed to assign an IP address to container The underlying constraint might be node-level ENI/IP capacity, depleted subnet addresses, or a CNI configuration issue. The response is not simply “restart the Pod.” Check the affected Pod’s events, VPC CNI (aws-node) logs and metrics, and available addresses in the relevant subnets.\nDepending on the cause, the fix may include choosing node types with greater network capacity, adding or enlarging subnets, tuning the CNI warm-IP settings, or enabling prefix delegation. Prefix delegation can substantially increase per-node address capacity, but it requires suitable contiguous address space in the subnet.\nEKS does not eliminate networking concepts you need to understand. It applies them through AWS’s VPC, ENI, subnet, and IAM model.\nRecommended Reading # AWS Certified Solutions Architect Study Guide: Associate SAA-C03 Exam, 4th Edition by Ben Piper \u0026amp; David Clinton AWS Certified Cloud Practitioner Study Guide: CLF-C01 Exam by Ben Piper \u0026amp; David Clinton The Kubernetes Book Featured image by Juno Jo on Unsplash\n","date":"6 August 2026","externalUrl":null,"permalink":"/post/2026/why-kubernetes-fundamentals-still-matter-on-eks/","section":"Posts","summary":"","title":"Why Kubernetes Fundamentals Still Matter on EKS","type":"post"},{"content":"","date":"6 August 2026","externalUrl":null,"permalink":"/tags/writing/","section":"Tags","summary":"","title":"Writing","type":"tags"},{"content":"","date":"5 August 2026","externalUrl":null,"permalink":"/tags/2025/","section":"Tags","summary":"","title":"2025","type":"tags"},{"content":"","date":"5 August 2026","externalUrl":null,"permalink":"/tags/ai-architecture/","section":"Tags","summary":"","title":"AI Architecture","type":"tags"},{"content":"","date":"5 August 2026","externalUrl":null,"permalink":"/tags/context-engineering/","section":"Tags","summary":"","title":"Context-Engineering","type":"tags"},{"content":"","date":"5 August 2026","externalUrl":null,"permalink":"/tags/cybersecurity/","section":"Tags","summary":"","title":"Cybersecurity","type":"tags"},{"content":"","date":"5 August 2026","externalUrl":null,"permalink":"/tags/data-privacy/","section":"Tags","summary":"","title":"Data Privacy","type":"tags"},{"content":"","date":"5 August 2026","externalUrl":null,"permalink":"/tags/ip-geolocation/","section":"Tags","summary":"","title":"IP Geolocation","type":"tags"},{"content":"Every crime drama has the same scene. Someone types furiously on a keyboard, a map zooms in from country to city to street to a single house, and a voice says \u0026ldquo;got him.\u0026rdquo; That scene is fiction, and it\u0026rsquo;s fiction on purpose, because the reality is far less cinematic.\nIP geolocation is real. It works. But it doesn\u0026rsquo;t work the way Hollywood, or half the marketing copy on geolocation API websites, wants you to believe. Understanding where the accuracy actually lives, and where it falls apart, matters if you\u0026rsquo;re building anything that depends on location data, and it matters even more if you\u0026rsquo;re trying to figure out how exposed you really are online.\nHow IP Geolocation Actually Works # An IP address doesn\u0026rsquo;t carry a GPS coordinate. It\u0026rsquo;s just a number. Geolocation providers build databases by combining a few different data sources, none of which involve directly measuring where a device physically sits.\nThe core source is regional internet registry (RIR) data. When an ISP or organization gets an IP block from ARIN, RIPE, or one of the other regional registries, that allocation record often includes an address, but it\u0026rsquo;s almost always the ISP\u0026rsquo;s business office or a regional network operations center, not the location of any individual subscriber.\nOn top of that, providers layer inference. They look at network routing paths, latency measurements from known reference points, and historical data from previous lookups to guess where a block of addresses is likely being used. Some providers also crowdsource data from apps and websites that voluntarily report a device\u0026rsquo;s actual location alongside its IP address, which helps refine the guess over time.\nThe result is a database that maps IP ranges to estimated locations. Emphasis on estimated.\nWhy City-Level Accuracy Falls Apart # Country-level accuracy from IP geolocation is genuinely excellent. Providers routinely report accuracy in the high 90s at the country level, and that\u0026rsquo;s because national borders correlate strongly with how ISPs allocate and route address space.\nOnce you drop to the city or postal-code level, the numbers get a lot less impressive. Being off by dozens of miles is common. Being off by a few hundred miles isn\u0026rsquo;t rare, either, especially in three scenarios:\nMobile carrier networks. Cellular providers route traffic through a small number of centralized gateways that can serve an entire region or even a large chunk of a country. A phone on a mobile network in a suburb might show up as being located in a completely different city where the carrier\u0026rsquo;s gateway happens to sit.\nVPNs and proxies. By design, a VPN routes your traffic through its own infrastructure, so any geolocation lookup returns the location of the VPN\u0026rsquo;s server, not yours. This is precisely why VPN services are popular for evading region-locked content, and it\u0026rsquo;s a legitimate use case if you want to prevent websites from making assumptions about where you are. If you\u0026rsquo;re weighing whether to use one, a service like NordVPN exists specifically to insert that layer between your real IP and anyone trying to look it up.\nRural and satellite connections. Sparse infrastructure means fewer reference points to triangulate from, so estimates in rural areas tend to be considerably less precise than in dense urban ones.\nNone of this is a flaw in the technology. It\u0026rsquo;s a fundamental limitation of trying to infer physical location from network topology. The data behind services like the one described on bigdatacloud.com\u0026rsquo;s geolocation accuracy write-up backs this up. Country detection is dependable. City detection is a best guess, and everyone building on top of these APIs should treat it that way.\nThe Marketing Myth of Pinpoint Accuracy # Here\u0026rsquo;s where it gets frustrating. A lot of geolocation API vendors advertise \u0026ldquo;pinpoint accuracy\u0026rdquo; or \u0026ldquo;street-level precision,\u0026rdquo; and technically, sometimes, for some IPs, that\u0026rsquo;s true. But it\u0026rsquo;s not the norm, and vendors know it. It\u0026rsquo;s the difference between advertising your best-case result and your average result.\nIf you\u0026rsquo;re evaluating a geolocation API for a project, the metric that matters isn\u0026rsquo;t the flashiest number in the marketing copy. It\u0026rsquo;s the accuracy radius reported at the city level, and how that radius changes across residential, mobile, and business IP ranges. A vendor that publishes those breakdowns transparently is worth trusting more than one that just says \u0026ldquo;99% accurate\u0026rdquo; without telling you what precision that percentage refers to.\nThe honest takeaway: IP geolocation is a reliable country and often region-level signal, and an unreliable street-level one. Anyone selling you the latter as a routine capability is overselling the product.\nWhat Actually Makes IP-Based Location Dangerous? # If IP geolocation alone can\u0026rsquo;t reliably find your house, why does the idea of \u0026ldquo;someone tracked my IP\u0026rdquo; still worry people, and why should it?\nBecause an IP address rarely stays alone for long. The real risk isn\u0026rsquo;t the IP itself. It\u0026rsquo;s what the IP gets correlated with.\nThree scenarios turn a fuzzy, city-level estimate into something precise and personally identifying:\nData breaches. When a service gets breached and the leaked dataset includes both your IP address and your real shipping address, billing address, or account profile, that correlation is now permanent and public. The IP itself was never the dangerous part. The pairing is.\nBrowser-based geolocation APIs. This is a completely different mechanism from IP geolocation, and conflating the two is where most of the fear and most of the misunderstanding comes from. When a website asks \u0026ldquo;allow this site to know your location\u0026rdquo; and you click yes, your browser uses GPS (on mobile), WiFi access point triangulation, or cell tower data to report your location, often accurate to within a few meters. That has nothing to do with your IP address. It\u0026rsquo;s a permission you actively granted, and it\u0026rsquo;s vastly more precise than anything an IP lookup provides.\nDevice-level location services tied to a session. Apps that request location permissions and then log that data alongside session or account identifiers create the same kind of correlation as a data breach, just voluntarily and continuously. If that data ever gets exposed, whoever has it can tie a precise GPS location to your account, your IP, and your browsing session, all at once.\nIP Geolocation vs Browser Geolocation # It\u0026rsquo;s worth being explicit about this distinction because so much confusion stems from treating these as the same thing.\nIP geolocation infers your approximate location from network infrastructure. No permission is required, no consent dialog appears, and the accuracy tops out at city or region level in the best case.\nBrowser geolocation uses device hardware, GPS, WiFi, cell towers, and requires explicit user consent through a permission prompt. When granted, its accuracy is an entirely different category, often precise enough to identify a specific building.\nIf you\u0026rsquo;ve ever wondered how a food delivery app can drop a pin on your exact front porch when your ISP\u0026rsquo;s IP block maps to a data center three towns over, that\u0026rsquo;s the answer. It\u0026rsquo;s not using your IP address for that. It\u0026rsquo;s using the location permission you granted.\nThe Real Privacy Risk Is Correlation, Not the IP Itself # This is the part that gets lost in both the fearmongering articles and the dismissive ones. An IP address by itself, sitting in a server log, is a weak signal. It tells an interested party your ISP and roughly what city or region you\u0026rsquo;re in. That\u0026rsquo;s not nothing, but it\u0026rsquo;s not a doxxing threat on its own.\nThe threat model changes entirely the moment that IP address gets tied, anywhere, to something more specific. A breached e-commerce database. A leaked app dataset with GPS coordinates. A forum account where you mentioned your neighborhood and someone cross-references the timestamp against server logs. Individually, each piece of data is limited. Combined, they build a profile that\u0026rsquo;s far more accurate than any single data point suggests.\nThis is the same principle that shows up constantly in security work: the aggregation of low-sensitivity data creates high-sensitivity outcomes. Garbage in, garbage out doesn\u0026rsquo;t apply here, because none of the individual inputs are garbage. They\u0026rsquo;re each a little bit accurate. The danger comes from stacking them.\nIf you\u0026rsquo;re serious about understanding how these attack surfaces get built and exploited, it\u0026rsquo;s worth putting real study time into network fundamentals. A CompTIA Network+ course covers exactly this kind of IP addressing and routing logic that underpins how geolocation inference actually works, and it\u0026rsquo;s foundational if you\u0026rsquo;re moving toward broader security or cloud certifications. For a deeper dive into how these correlation attacks play out in practice, Kevin Mitnick\u0026rsquo;s The Art of Invisibility walks through real-world cases of exactly this kind of data-stacking, and it\u0026rsquo;s a useful gut check for anyone who assumes a single leaked data point is harmless.\nSo What Do You Actually Do With This? # Stop worrying about your IP address revealing your street address. It almost never does, and any tool claiming otherwise at scale is exaggerating.\nStart worrying about what your IP address gets stored alongside. Check what permissions you\u0026rsquo;ve granted to apps that use browser or device-level geolocation, and revoke the ones you don\u0026rsquo;t actively need. Assume that any service holding your IP and your real address in the same database is one breach away from making that correlation public, because plenty of services have proven exactly that.\nIf you specifically want to prevent IP-based inference, whether for privacy, testing, or bypassing lazy region locks, a VPN does that job well because it changes what location any lookup returns. But a VPN does nothing to protect you from the browser location permission you granted to a shopping app last week. Different threats need different defenses, and conflating them is how people end up either paranoid about the wrong thing or complacent about the right one.\nFeatured image by Grianghraf on Unsplash\nRecommended Reading # AI Engineering: Building Applications with Foundation Models by Chip Huyen CompTIA Network+ Study Guide: Exam N10-009 by Todd Lammle ","date":"5 August 2026","externalUrl":null,"permalink":"/post/2026/is-ip-geolocation-reliable-not-the-way-you-think/","section":"Posts","summary":"","title":"Is IP Geolocation Reliable? Not the Way You Think","type":"post"},{"content":"","date":"5 August 2026","externalUrl":null,"permalink":"/tags/machine-learning/","section":"Tags","summary":"","title":"Machine Learning","type":"tags"},{"content":"","date":"5 August 2026","externalUrl":null,"permalink":"/tags/networking/","section":"Tags","summary":"","title":"Networking","type":"tags"},{"content":"","date":"5 August 2026","externalUrl":null,"permalink":"/tags/prompt-engineering/","section":"Tags","summary":"","title":"Prompt Engineering","type":"tags"},{"content":"","date":"5 August 2026","externalUrl":null,"permalink":"/tags/vpn/","section":"Tags","summary":"","title":"VPN","type":"tags"},{"content":"Anyone who\u0026rsquo;s spent time doing RF engineering knows the concept of signal-to-noise ratio (SNR) cold. You\u0026rsquo;ve got a signal, you\u0026rsquo;ve got a noise floor, and the gap between them determines whether the receiver can actually make sense of what\u0026rsquo;s coming in. Raise the noise floor high enough, and it doesn\u0026rsquo;t matter how strong the signal is. It gets swallowed.\nLarge language models have a noise floor problem, and it\u0026rsquo;s not the kind you fix with a firmware update. It\u0026rsquo;s baked into the architecture. Every time you\u0026rsquo;ve felt like you\u0026rsquo;re fighting an LLM to get it to just say the thing directly, without the hedging, the preamble, the \u0026ldquo;it\u0026rsquo;s important to note that,\u0026rdquo; you\u0026rsquo;re running into a structural property of how these models are built and trained. Understanding why that noise exists tells you exactly what prompt and context engineering are actually for, and why they\u0026rsquo;re not optional polish.\nWhat does \u0026ldquo;signal\u0026rdquo; even mean for a language model? # In RF terms, signal is the thing you want and noise is everything else competing for the same spectrum. For text, signal is the precise, correct, non-redundant information that answers your question or completes your task. Noise is filler, hedging, generic phrasing, and statistically safe language that doesn\u0026rsquo;t add information but doesn\u0026rsquo;t hurt the model\u0026rsquo;s training objective either.\nThe reason LLMs default to a low SNR isn\u0026rsquo;t that they\u0026rsquo;re bad at writing. It\u0026rsquo;s that the thing they were optimized to do isn\u0026rsquo;t the same thing as writing well. That distinction matters, and it\u0026rsquo;s where the whole problem starts.\nNext-token prediction optimizes for plausibility, not precision # An LLM is trained to predict the next token given everything that came before it. That\u0026rsquo;s the entire objective function. Not \u0026ldquo;be correct.\u0026rdquo; Not \u0026ldquo;be concise.\u0026rdquo; Not \u0026ldquo;say something worth saying.\u0026rdquo; Just: given this sequence, what token is statistically most likely to come next, based on a corpus that includes everything from peer-reviewed papers to Reddit threads to marketing copy to forum arguments.\nThat corpus is enormous and heterogeneous by design, because more data generally improves the model\u0026rsquo;s ability to generalize. But heterogeneity has a cost. The training signal is diluted by the sheer volume of mediocre, hedged, redundant, and low-information text that makes up most of human writing. Most writing, honestly, is noise. Most emails, most blog posts, most Slack messages. The model learns from all of it, weighted by frequency, not by quality.\nSo when you ask an LLM a direct question, it\u0026rsquo;s not retrieving \u0026ldquo;the correct answer\u0026rdquo; from some clean index. It\u0026rsquo;s generating the statistically plausible continuation of a prompt, shaped by a training distribution where verbose, hedged, generically-worded text is extremely common. Garbage in, garbage out isn\u0026rsquo;t just a data pipeline problem. It\u0026rsquo;s the literal training objective.\nAttention doesn\u0026rsquo;t choose. It blends. # Here\u0026rsquo;s the part that gets missed even by people who use these models daily. The transformer architecture\u0026rsquo;s attention mechanism doesn\u0026rsquo;t select a single \u0026ldquo;best\u0026rdquo; next token and commit to it the way a human writer commits to a word choice. It computes a weighted average over the entire vocabulary distribution, conditioned on every token in the context window attending to every other token.\nThat means the output at each step is a probabilistic blend of many possible continuations, not a deliberate authorial decision. When a human writer chooses a word, they\u0026rsquo;re drawing on intent, prior knowledge of the audience, and a mental model of what they\u0026rsquo;re trying to say. When a model \u0026ldquo;chooses\u0026rdquo; a token, it\u0026rsquo;s sampling from a distribution that represents an average over thousands of contexts the training data resembled.\nThis is why LLM output so often reads as competent but generic. It\u0026rsquo;s not wrong, exactly. It\u0026rsquo;s the statistical center of mass of everything similar it\u0026rsquo;s seen before. Averages are, by definition, low-variance and low-signal. You rarely get a sharp, distinctive point of view from an average. You get the safest, most broadly applicable version of an answer, because that\u0026rsquo;s what minimizes the model\u0026rsquo;s loss across the entire training distribution.\nHuman writers filter. LLMs skip that step by default. # When you write something and publish it, you\u0026rsquo;ve gone through a filtering process that took place before anyone else saw a single word. You decided what mattered, cut what didn\u0026rsquo;t, revised the parts that were vague, and killed sentences that didn\u0026rsquo;t earn their place. That filtering is powered by expertise, intent, and editorial judgment, none of which are things an LLM has natively.\nAn LLM\u0026rsquo;s raw output skips all of that. There\u0026rsquo;s no editor in the loop unless you are the editor. There\u0026rsquo;s no internal voice saying \u0026ldquo;this sentence is filler, cut it,\u0026rdquo; because the model doesn\u0026rsquo;t have a concept of \u0026ldquo;filler\u0026rdquo; as distinct from \u0026ldquo;content.\u0026rdquo; It has a probability distribution. Hedge phrases like \u0026ldquo;it\u0026rsquo;s worth noting\u0026rdquo; or \u0026ldquo;in many cases\u0026rdquo; show up constantly in LLM output not because the model is being cautious, they show up because those phrases are extremely common in the training corpus and statistically safe continuations in almost any context.\nThis is the honest answer to \u0026ldquo;why are LLMs so verbose.\u0026rdquo; It\u0026rsquo;s not a personality quirk. It\u0026rsquo;s the absence of the authorial filtering pass that human writers perform automatically and invisibly, every single time, before anyone else reads their work.\nWhy prompt and context engineering exist at all # Once you see the noise as architectural, prompt and context engineering stop looking like a soft skill and start looking like exactly what they are: an attempt to manually impose the filtering step that human authorial judgment provides for free.\nNotice what most effective prompt engineering actually consists of. It\u0026rsquo;s rarely \u0026ldquo;generate more.\u0026rdquo; It\u0026rsquo;s almost always constraint. \u0026ldquo;Don\u0026rsquo;t include a summary at the end.\u0026rdquo; \u0026ldquo;Respond in one paragraph.\u0026rdquo; \u0026ldquo;Do not hedge. State the answer directly.\u0026rdquo; \u0026ldquo;Do not use the word \u0026rsquo;leverage.\u0026rsquo;\u0026rdquo; These are negative instructions, and negative instructions exist because the model\u0026rsquo;s default behavior, absent constraint, is to reproduce the noisy, hedged, average-of-everything output that its training distribution encourages.\nContext engineering does the same job from a different angle. Instead of constraining what the model outputs, it constrains what the model attends to. By narrowing the context window to only relevant, high-quality information, you\u0026rsquo;re artificially raising the SNR of the input, which raises the SNR of the output, because the model\u0026rsquo;s attention mechanism can only average over what\u0026rsquo;s actually there. Feed it a clean, tightly scoped context and the averaging happens over a much narrower, higher-quality distribution. Feed it everything and let it figure it out, and you get the statistical mush that comes from averaging over noise.\nThis also explains why so much of the discipline feels like pruning rather than generation. You\u0026rsquo;re not teaching the model new information most of the time. You\u0026rsquo;re cutting away the paths that lead to low-signal output and narrowing the model toward the paths that produce what you actually want. It\u0026rsquo;s editorial work, just performed upstream instead of downstream.\nThe practical implication # If you\u0026rsquo;re treating prompt and context engineering as a bag of clever tricks, you\u0026rsquo;re missing what they\u0026rsquo;re actually compensating for. They exist because the model has no built-in mechanism for authorial judgment, and the training objective it optimizes for actively works against precision and concision.\nThat means the work isn\u0026rsquo;t finished once you find a prompt that works. It means you should expect to keep doing this work, indefinitely, for every task, because the noise floor doesn\u0026rsquo;t go away. It\u0026rsquo;s structural. You\u0026rsquo;re not fixing a bug. You\u0026rsquo;re building a filter, every time, around a system that was never designed to filter for you.\nThe engineers who get the most out of these models aren\u0026rsquo;t the ones with the cleverest prompts. They\u0026rsquo;re the ones who\u0026rsquo;ve internalized that the model\u0026rsquo;s raw output is closer to a first draft generated by averaging over the entire internet than it is to a finished thought. Treat it that way. Constrain aggressively, narrow the context ruthlessly, and don\u0026rsquo;t expect the model to know what to cut. That\u0026rsquo;s still your job.\nIf you found this post useful, you might also be interested in:\nThe LLM Engineer's Handbook by Paul Iusztin and Maxime Labonne Generative AI Design Patterns by Valliappa Lakshmanan and Hannes Hapke Featured image by Egor Komarov on Unsplash\nRecommended Reading # The LLM Engineer's Handbook by Paul Iusztin and Maxime Labonne Generative AI Design Patterns by Valliappa Lakshmanan and Hannes Hapke ","date":"5 August 2026","externalUrl":null,"permalink":"/post/2026/why-llms-inherently-have-a-low-signal-to-noise-ratio/","section":"Posts","summary":"","title":"Why LLMs Inherently Have a Low Signal-to-Noise Ratio","type":"post"},{"content":"","date":"4 August 2026","externalUrl":null,"permalink":"/tags/career/","section":"Tags","summary":"","title":"Career","type":"tags"},{"content":"","date":"4 August 2026","externalUrl":null,"permalink":"/tags/consulting/","section":"Tags","summary":"","title":"Consulting","type":"tags"},{"content":"","date":"4 August 2026","externalUrl":null,"permalink":"/tags/enterprise-it/","section":"Tags","summary":"","title":"Enterprise IT","type":"tags"},{"content":"","date":"4 August 2026","externalUrl":null,"permalink":"/tags/forward-deployed-engineer/","section":"Tags","summary":"","title":"Forward Deployed Engineer","type":"tags"},{"content":"LinkedIn has decided that \u0026ldquo;Forward Deployed Engineer\u0026rdquo; is the hottest job title of the AI boom. Startups are hiring for it. Recruiters are DMing about it. Someone is already writing about \u0026ldquo;Forward Deployed Executives\u0026rdquo; as the next rung on the ladder. If you\u0026rsquo;ve spent any time in enterprise software, sales engineering, or IT consulting, none of this should feel new. It isn\u0026rsquo;t.\nThat doesn\u0026rsquo;t mean the role is fake or the demand isn\u0026rsquo;t real. It means the industry has relabeled a job that\u0026rsquo;s existed since at least the 1990s and is now selling it back to engineers as a novel career path. Worth understanding what\u0026rsquo;s actually different, and what\u0026rsquo;s just repackaging.\nWhat is a Forward Deployed Engineer, actually? # A Forward Deployed Engineer, or FDE, is an engineer who works directly inside a customer\u0026rsquo;s environment to customize, implement, and often help sell a piece of software. Palantir popularized the title and the model. Their engineers didn\u0026rsquo;t sit in a building writing generic product code. They flew to a customer site, sat with analysts and operators, learned the customer\u0026rsquo;s specific workflow, and wrote the integration and configuration code needed to make Palantir\u0026rsquo;s platform actually solve that customer\u0026rsquo;s problem.\nThe job blends three things that are usually separate roles: software engineering, solutions consulting, and pre-sales. You write code, but you also scope requirements, manage stakeholder expectations, and frequently participate in the sales cycle by proving the product can do what the sales deck promised.\nA wave of AI startups has adopted this model wholesale. If you look at the job postings, you\u0026rsquo;ll see language about \u0026ldquo;embedding with customers,\u0026rdquo; \u0026ldquo;rapid prototyping in production environments,\u0026rdquo; and \u0026ldquo;owning the customer outcome.\u0026rdquo; That\u0026rsquo;s FDE branding, and it\u0026rsquo;s spreading fast through applied AI companies that sell complex, unproven products to enterprises that don\u0026rsquo;t trust self-serve SaaS to solve their problems.\nThis job title is not new # Here\u0026rsquo;s the part nobody wants to say out loud: solutions architects have done this job for decades. So have sales engineers. So have implementation consultants at firms like Accenture, Deloitte, and every systems integrator that\u0026rsquo;s ever sold enterprise software.\nAnyone who\u0026rsquo;s carried the title \u0026ldquo;Solutions Architect\u0026rdquo; at AWS , Cisco, or Oracle has done FDE work. You get embedded with a customer. You learn their environment. You build a proof of concept that has to survive contact with their actual infrastructure, not a sanitized demo environment. You manage the tension between what sales promised and what engineering can deliver. You sit in rooms with executives who don\u0026rsquo;t know the difference between a container and a VM but need to be convinced the solution won\u0026rsquo;t blow up their compliance posture.\nSales engineers have done this job. Implementation consultants at every ERP and CRM vendor since the 1990s have done this job. The title changes. The mechanics of the job, remarkably, do not: technical depth plus relationship management plus the ability to translate between engineering reality and business expectation.\nWhat\u0026rsquo;s genuinely different this time is the product category. AI systems, especially agentic and LLM-based ones, are harder to demo convincingly and harder to trust out of the box than a traditional SaaS platform. That\u0026rsquo;s the actual novelty. The role wrapped around it isn\u0026rsquo;t novel at all.\nWhy AI startups are reviving this model now # Self-serve SaaS works when the product is predictable and the customer can evaluate it without much hand-holding. You sign up, you plug in your data, it does the thing. AI products, particularly ones built on LLMs, don\u0026rsquo;t behave that way yet. They\u0026rsquo;re probabilistic, they fail in unpredictable ways, and enterprise buyers know it. Nobody at a bank or a hospital system is going to sign a seven-figure contract based on a self-serve trial and a sales deck.\nSo AI startups need people who can go on-site, understand the customer\u0026rsquo;s actual data and workflows, and build something that works well enough to earn trust before the broader platform matures. That\u0026rsquo;s expensive. It doesn\u0026rsquo;t scale the way SaaS is supposed to scale. But it\u0026rsquo;s the only way to sell a product that isn\u0026rsquo;t fully baked yet to a risk-averse enterprise buyer.\nThis is exactly the problem solutions architects and implementation consultants have solved for every immature or highly configurable enterprise product going back to client-server ERP rollouts. AI just happens to be the current category where the product-market fit gap is widest, so the FDE model is having a moment.\nThe tension between building and selling # Here\u0026rsquo;s where a lot of engineers considering this path get it wrong. They read \u0026ldquo;Forward Deployed Engineer\u0026rdquo; and hear \u0026ldquo;I get to write code at the customer site instead of in an office.\u0026rdquo; What they don\u0026rsquo;t hear, because job postings rarely say it plainly, is how much of the job is scoping, negotiating, and managing expectations before you ever open an editor.\nYou\u0026rsquo;ll spend real time figuring out what the customer actually needs versus what they say they need, which are frequently different things. You\u0026rsquo;ll sit through stakeholder meetings where half the room doesn\u0026rsquo;t understand the technology and the other half is worried about their own job security if the project succeeds. You\u0026rsquo;ll have to say no to feature requests that would blow the timeline, and you\u0026rsquo;ll have to do it in a way that doesn\u0026rsquo;t torch the account.\nEngineers who come up through pure engineering tracks often underestimate this. They assume the hard part is the technical build. In practice, the hard part is usually the ambiguity: an undocumented legacy system, a stakeholder who won\u0026rsquo;t commit to requirements, a sales team that oversold the timeline. The coding is frequently the easy part once you\u0026rsquo;ve actually pinned down what needs to be built.\nIf you can\u0026rsquo;t sit in a room with a skeptical VP of Operations and calmly explain why the six-week estimate is actually twelve weeks, the FDE role is going to grind you down regardless of how good your code is.\nForward Deployed Executive: real evolution or resume inflation? # Some recent commentary has floated \u0026ldquo;Forward Deployed Executive\u0026rdquo; as the natural next step for FDEs, the idea being that engineers who\u0026rsquo;ve proven they can manage enterprise relationships eventually graduate into a quasi-executive role overseeing multiple accounts or a whole practice.\nTreat this skeptically. Strip away the title and what you\u0026rsquo;re describing is an engagement manager, a practice lead, or a client partner, roles that have existed at every consulting firm for as long as consulting firms have existed. Calling it \u0026ldquo;Forward Deployed Executive\u0026rdquo; doesn\u0026rsquo;t describe new responsibilities. It borrows the credibility of the FDE brand and slaps \u0026ldquo;executive\u0026rdquo; on it for a resume that needs to sound more senior than \u0026ldquo;consulting manager.\u0026rdquo;\nThat\u0026rsquo;s not to say the underlying career progression isn\u0026rsquo;t real. Engineers who are good at both the technical and relationship sides of FDE work absolutely do move into leadership roles managing bigger accounts or bigger teams. That trajectory has always existed in consulting and pre-sales. The new label doesn\u0026rsquo;t change the substance of the job. It changes how it reads on LinkedIn.\nWhat to actually build if you\u0026rsquo;re considering this path # If the FDE role appeals to you, the skills that matter aren\u0026rsquo;t primarily technical, even though the job postings lead with tech stack requirements.\nBuild your ability to scope ambiguous problems. Practice taking a vague customer complaint and turning it into a concrete, testable requirement. This is a learnable skill, and it\u0026rsquo;s the one that separates engineers who thrive in customer-facing technical roles from ones who burn out in them.\nBuild domain expertise in whatever vertical you\u0026rsquo;re targeting. An FDE who understands how claims processing actually works at an insurance company is worth more than one who only knows the AI stack. The technology is usually the easy half of the job. The domain is where trust gets built.\nBuild communication skills specifically around setting expectations with non-technical stakeholders. You need to be able to say \u0026ldquo;that\u0026rsquo;s not possible in the timeline you want\u0026rdquo; without sounding like you\u0026rsquo;re making excuses, and you need to be able to do it in a room with executives watching.\nExpect travel. Expect blurred hours, because customer emergencies don\u0026rsquo;t respect your calendar. Expect office politics that have nothing to do with the technology and everything to do with who gets credit internally at the customer if the project succeeds.\nWatch for red flags in job postings. If a listing is heavy on buzzwords like \u0026ldquo;embedding with customers to unlock transformative outcomes\u0026rdquo; and light on specifics about team structure, reporting lines, or what \u0026ldquo;success\u0026rdquo; is measured against, that\u0026rsquo;s a company that hasn\u0026rsquo;t figured out what it actually wants from the role. A well-defined FDE posting tells you the product, the customer segment, the technical stack, and roughly what a typical engagement looks like. A vague one is asking you to define the job while you do it, which might be fine if you\u0026rsquo;re senior enough to want that, but it\u0026rsquo;s a real cost if you\u0026rsquo;re expecting a structured onboarding.\nCompensation and where it actually leads # FDE roles at well-funded AI startups tend to pay well, often blending a base salary with equity that assumes the company\u0026rsquo;s growth trajectory holds. That\u0026rsquo;s the same bet every early-stage hire makes, and the FDE title doesn\u0026rsquo;t change the risk profile of startup equity.\nThe more useful question is where the role leads. For some engineers, FDE work is a stepping stone toward founder or executive tracks, because the job forces you to develop the customer-facing and business judgment skills that pure engineering roles don\u0026rsquo;t. That\u0026rsquo;s a real and legitimate path, and it mirrors how plenty of solutions architects and sales engineers eventually moved into VP of Customer Success or even CTO roles at smaller companies.\nFor others, it becomes a specialized track that\u0026rsquo;s hard to exit from. If you spend five years doing nothing but customer implementations, you may find your hands-on engineering skills atrophy relative to peers who stayed in core product development. Hiring managers at product-focused companies sometimes view heavy FDE experience as \u0026ldquo;not a real engineer\u0026rdquo; even when the technical bar for the work was plenty high. That bias is unfair, but it exists, and you should factor it in before committing years to the track.\nThe honest answer is that FDE work can go either direction depending on the company, the engagements you get assigned, and how deliberately you manage your own skill development alongside the client work. Nobody is going to manage that for you. It\u0026rsquo;s on you to keep building things outside the customer engagements so your technical skills don\u0026rsquo;t quietly erode.\nSo is this a real role or just consulting with a new coat of paint? # Both. The work is real, valuable, and hard. Companies genuinely need people who can bridge the gap between an immature AI product and a skeptical enterprise buyer, and that person needs both engineering chops and consulting instincts. That\u0026rsquo;s not marketing fluff, it\u0026rsquo;s an actual operational need.\nBut the title itself isn\u0026rsquo;t a new category of work. It\u0026rsquo;s solutions architecture and implementation consulting, rebranded for a hiring market that wants to sound more technical and more startup-native than \u0026ldquo;consultant\u0026rdquo; or \u0026ldquo;sales engineer\u0026rdquo; ever did. If you\u0026rsquo;ve done pre-sales engineering, technical account management, or systems integration work, you already have the core skill set. Don\u0026rsquo;t let a shinier job title convince you that you\u0026rsquo;re starting from zero, and don\u0026rsquo;t let it convince you the job is purely technical either. It never was, under any name.\nFeatured image by Fabian Centeno on Unsplash\nRecommended Reading # AWS Certified Solutions Architect Study Guide: Associate SAA-C03 Exam, 4th Edition by Ben Piper \u0026amp; David Clinton AWS Certified Cloud Practitioner Study Guide: CLF-C01 Exam by Ben Piper \u0026amp; David Clinton CCNP Enterprise Certification Study Guide: 350-401 ENCOR by Ben Piper \u0026amp; David Clinton ","date":"4 August 2026","externalUrl":null,"permalink":"/post/2026/forward-deployed-engineers-the-new-job-title-for-work-consultants-have-always-do/","section":"Posts","summary":"","title":"Forward Deployed Engineers: The New Job Title for Work Consultants Have Always Done","type":"post"},{"content":"","date":"4 August 2026","externalUrl":null,"permalink":"/tags/probability/","section":"Tags","summary":"","title":"Probability","type":"tags"},{"content":"","date":"4 August 2026","externalUrl":null,"permalink":"/tags/software-engineering/","section":"Tags","summary":"","title":"Software Engineering","type":"tags"},{"content":"","date":"4 August 2026","externalUrl":null,"permalink":"/categories/uncategorized/","section":"Categories","summary":"","title":"Uncategorized","type":"categories"},{"content":"People misuse and misunderstand probability constantly. The mathematical meaning of the word is different from how most people use it in conversation. When someone says \u0026ldquo;he\u0026rsquo;s probably thinking about food,\u0026rdquo; they don\u0026rsquo;t mean probability in any formal sense. They\u0026rsquo;re speculating based on what they know about him.\nA better example, and a more common misconception, is the classic game show setup. One door has a car behind it. The other has nothing. Say the car is behind door 1. The incorrect phrasing people use is \u0026ldquo;there\u0026rsquo;s a 50% probability the car is behind door 1.\u0026rdquo; That\u0026rsquo;s wrong. There\u0026rsquo;s a 100% probability the car is behind door 1 and a 0% probability it\u0026rsquo;s behind door 2. Actually, it\u0026rsquo;s not a probability at all. The car is certainly behind door 1. When you\u0026rsquo;re dealing with something that already is, you aren\u0026rsquo;t talking about probability. Probability refers to future events that might happen.\nSo when someone says \u0026ldquo;there\u0026rsquo;s a 50% probability the car is behind door 1,\u0026rdquo; what they actually mean is \u0026ldquo;there\u0026rsquo;s a 50% probability you will pick the door with the car.\u0026rdquo; That\u0026rsquo;s correct, because it describes a future choice. But once you pick a door—say door 1—the so-called probability changes. You\u0026rsquo;ve now picked the door with the car with 100% certainty. Did the probability change? No. You were just using the wrong word.\nHere\u0026rsquo;s an example where the language works correctly. Take a jar with 15 balls: 5 red, 5 green, 5 blue. You can correctly say the probability of picking a red ball is 1/3, or roughly 33%. This is a legitimate use of the word, because it refers to a future event—the act of reaching in and pulling one out.\nThis loose misuse of probability leads to errors even among people who should know better. Conspiracy theories are a good example. Most turn out to be wrong, but some occasionally are true. Say, hypothetically, that 5% of conspiracy theories throughout history have been true. That\u0026rsquo;s a made-up number, by the way—I have no idea what the real figure is. Now say a new conspiracy theory surfaces. The temptation is to say \u0026ldquo;there\u0026rsquo;s a 5% chance this new theory is true.\u0026rdquo; That\u0026rsquo;s wrong. The theory is either true or false right now. It doesn\u0026rsquo;t have a probability. What people actually mean is that conspiracy theories, as a category, have a track record of usually being false, with only a small percentage turning out to be true. That\u0026rsquo;s a statement about history, not about probability.\nSo why do people use the language of probability anyway? They like to reify things—to attach a number to something that feels otherwise unmeasurable. It also helps them feel justified. The person who enjoys debunking conspiracy theories loves to say \u0026ldquo;statistically, 95% of conspiracy theories turn out to be false, so we should reject this new one, since there\u0026rsquo;s only a 5% chance it\u0026rsquo;s true.\u0026rdquo; As we\u0026rsquo;ve seen, that doesn\u0026rsquo;t hold up. Each claim should be assessed on its own merits and the evidence available, not on the historical batting average of an entire category.\nHere\u0026rsquo;s a more personal example. Suppose you have some concerning symptoms and start googling them. Your symptoms match a few things—most aren\u0026rsquo;t serious, but one is serious and rare. You look up how rare, and find that the incidence is 5,000 out of 100,000 people, or 5%. You might reason that there\u0026rsquo;s a 95% chance you don\u0026rsquo;t have it and feel better about the whole situation. But are you actually justified in feeling relaxed?\nHere\u0026rsquo;s where we need to be careful. Statistically, since only 5% of people ever get this condition, it\u0026rsquo;s unlikely you will get it. Notice the word \u0026ldquo;will\u0026rdquo;—that\u0026rsquo;s a statement about the future. But right now, you either have the condition or you don\u0026rsquo;t. That\u0026rsquo;s always true, whether or not you have symptoms. This is why doctors rule out serious causes first, no matter how rare, and why they recommend checkups even when you feel fine. It\u0026rsquo;s also why you shouldn\u0026rsquo;t rely on a misapplied version of \u0026ldquo;probability\u0026rdquo; to figure out whether you have a serious problem.\nBut back to the question: are you justified in using probability to reassure yourself, something like \u0026ldquo;I probably don\u0026rsquo;t have that. It\u0026rsquo;s so unlikely. There\u0026rsquo;s a 95% chance I don\u0026rsquo;t!\u0026rdquo; It is rare, so the odds of any given person getting it are low, and you are, in fact, some given person. It feels intuitively right to tell yourself you probably don\u0026rsquo;t have something that most people never get. But is it actually right? I think it\u0026rsquo;s almost right, but it has nothing to do with probability.\nThere are countless bad things that could happen to you. A serious disease is just one of them. There\u0026rsquo;s also lightning, car accidents, crime, dangerous insects, foodborne illness, and so on. You don\u0026rsquo;t sit around running probability calculations for all of these. It\u0026rsquo;s only when a specific concern grabs your attention that you start reasoning your way out of the anxiety it causes. Misusing probability this way is a coping mechanism, not an assessment. You aren\u0026rsquo;t worried about the dozens of other bad things that could happen to you, so why worry about this one? It\u0026rsquo;s not really about the numbers. It\u0026rsquo;s about what you\u0026rsquo;re focused on.\nInstead of telling yourself \u0026ldquo;I probably don\u0026rsquo;t have this,\u0026rdquo; which leaves the door open for anxiety to creep back in, try \u0026ldquo;I don\u0026rsquo;t know, but I\u0026rsquo;m going to find out.\u0026rdquo; This removes the false comfort of probability from the equation entirely and frees you to look at actual causes. What are the risk factors? What do people who have this condition have in common? Leaning on probability here is lazy. It gives you a false sense of security or a false sense of fear, depending on which numbers you land on. Probability applies to unknown future events. Once something already is, and once you know it is, probability becomes irrelevant.\nHere\u0026rsquo;s a cleaner way to see it. If you flip a coin without looking at it, then guess heads or tails, you have a 50% chance of being right. What you can\u0026rsquo;t say is that there\u0026rsquo;s a 50% chance the coin landed heads up. The coin has already landed. That chance is gone. Probability only applies while you still have a future opportunity to guess. Once you make your guess—say tails—you no longer have a 50% chance of being right. If the coin landed tails up, you\u0026rsquo;re right. Not probably right. If it didn\u0026rsquo;t, you\u0026rsquo;re wrong. Not probably wrong.\nTo make this more intuitive, think about something that already happened. Suppose yesterday\u0026rsquo;s forecast gave an 80% chance of rain, and it rained that evening. If someone told you today, \u0026ldquo;there\u0026rsquo;s an 80% chance it rained yesterday,\u0026rdquo; you\u0026rsquo;d immediately recognize that as nonsense. It rained. Chance and probability no longer apply.\nBut don\u0026rsquo;t we routinely prepare for things that seem statistically more likely, even without any sign of an actual problem? Sometimes, but only when missing something could be catastrophic. Doctors check your heart even when you have no symptoms of a heart attack. They don\u0026rsquo;t check for a splinter between your toes. Splinters are far more common than heart attacks, but missing a splinter doesn\u0026rsquo;t matter. Missing a heart problem does. When the stakes are high, probability isn\u0026rsquo;t the filter you should use to dismiss the question outright.\nFeatured image by Ben Mathis Seibel on Unsplash\n","date":"4 August 2026","externalUrl":null,"permalink":"/post/2026/youre-probably-wrong/","section":"Posts","summary":"","title":"You're Probably Wrong","type":"post"},{"content":"","date":"3 August 2026","externalUrl":null,"permalink":"/tags/cloudflare/","section":"Tags","summary":"","title":"Cloudflare","type":"tags"},{"content":"","date":"3 August 2026","externalUrl":null,"permalink":"/tags/infrastructure/","section":"Tags","summary":"","title":"Infrastructure","type":"tags"},{"content":"","date":"3 August 2026","externalUrl":null,"permalink":"/tags/llm/","section":"Tags","summary":"","title":"LLM","type":"tags"},{"content":"","date":"3 August 2026","externalUrl":null,"permalink":"/tags/rag/","section":"Tags","summary":"","title":"RAG","type":"tags"},{"content":" What Actually Makes Something an Agent # Most vendor content blurs the line between \u0026ldquo;agent\u0026rdquo; and \u0026ldquo;RAG pipeline with a tool call bolted on\u0026rdquo; on purpose. The ambiguity sells more product than precision would.\nHere\u0026rsquo;s the distinction that matters. A chatbot with a tool call executes a fixed sequence: user asks a question, model decides to call a function, function returns data, model formats a response. One decision point. One tool. The control flow is written by you, not the model.\nAn agent is different because the model owns the loop. It decides what to do next based on the result of what it just did, and it keeps deciding until it hits a stopping condition, a timeout, or a wall it can\u0026rsquo;t get past. That means the number of steps, which tools get called, and in what order, are not fixed at design time. They\u0026rsquo;re determined at runtime by the model\u0026rsquo;s own reasoning.\nThat distinction is the whole ballgame for infrastructure purposes. A fixed-sequence tool call has a predictable cost and a predictable failure mode. An agent loop does not. You can\u0026rsquo;t cap \u0026ldquo;one function call\u0026rdquo; the same way you cap \u0026ldquo;the model decides how many function calls it needs,\u0026rdquo; because the second one can be zero or it can be forty, and the model won\u0026rsquo;t tell you in advance which.\nThe Infrastructure Problems Nobody Puts in the Demo # Demos work because the task is narrow and the failure modes are hidden. Production doesn\u0026rsquo;t get that luxury. Three problems show up immediately once you move an agent past a proof of concept.\nState management across long-running sessions. A chatbot request-response cycle lives and dies in a few seconds. An agent session might run for minutes, sometimes longer, across multiple tool calls, multiple model invocations, and possibly multiple retries. You need to persist intermediate state somewhere durable, because if your process restarts, gets rescheduled, or times out mid-loop, you need to resume without re-running side effects that already happened. If step three of your agent\u0026rsquo;s plan sent an email or wrote a database record, you cannot safely retry from step one. This is the same idempotency problem distributed systems have always had, except now the thing deciding whether to retry is a language model instead of your own retry logic.\nCost control when agents loop or retry. A model call has a token cost. An agent loop has a token cost multiplied by however many iterations it decides to run. If your agent gets stuck in a pattern where it keeps calling the same tool, gets an ambiguous result, and calls it again, you\u0026rsquo;re paying for every one of those calls. Without a hard iteration cap and a hard cost ceiling per task, an agent in a bad loop can burn through a budget that a human would have noticed and stopped after the second try. This isn\u0026rsquo;t hypothetical. It\u0026rsquo;s the most common way agent bills surprise people.\nObservability when the decision path is non-deterministic. With a normal service, you can trace a request through your code and know exactly why it took the path it took. With an agent, the \u0026ldquo;why\u0026rdquo; lives inside a model\u0026rsquo;s reasoning, and that reasoning can change between two runs with identical inputs. You need to log the full decision trace: what the model saw, what it decided, what tool it called, what came back, and what it decided next. Without that trace, debugging a bad outcome means guessing. Tools built for this, like LangSmith and similar tracing platforms, exist specifically because \u0026ldquo;add a print statement\u0026rdquo; doesn\u0026rsquo;t work when the thing you\u0026rsquo;re debugging is a chain of model decisions instead of a call stack.\nRAG Isn\u0026rsquo;t Dead. Naive RAG Is Just Bad RAG # RAG became unfashionable the moment agents became fashionable, which says more about hype cycles than it does about RAG\u0026rsquo;s actual utility. RAG still solves a real problem: grounding a model\u0026rsquo;s output in your own current data instead of whatever it memorized during training.\nWhere naive RAG breaks down is well understood at this point. A stale index means the model is confidently wrong about something that changed last week. Poor chunking means the retriever hands the model half a paragraph missing the context that would have changed its interpretation. And a system with no feedback loop means you have no way to know retrieval is degrading until someone complains that the answers got worse.\nAgentic retrieval patterns try to fix this by letting the model decide it needs to search again, rephrase the query, or pull from a different source if the first retrieval doesn\u0026rsquo;t look sufficient. That\u0026rsquo;s a real improvement over \u0026ldquo;retrieve once, stuff it in the prompt, hope for the best.\u0026rdquo; But it\u0026rsquo;s not magic. It\u0026rsquo;s still a retrieval system, just with a loop wrapped around it, and it inherits the same cost and observability problems described above. If your chunking strategy is bad, letting the model retry the search five times doesn\u0026rsquo;t fix bad chunks. It just costs five times as much to fail.\nEdge Agent Platforms vs Rolling Your Own # Cloudflare\u0026rsquo;s pitch with Workers AI and its agent tooling is convenience at the edge: low latency, integrated durable objects for state, and a billing model tied to Cloudflare\u0026rsquo;s usage-based pricing. That\u0026rsquo;s a legitimate value proposition if your traffic patterns and data already live in Cloudflare\u0026rsquo;s ecosystem.\nThe tradeoff is lock-in. Durable Objects, Cloudflare\u0026rsquo;s KV store, and its Vectorize offering are all proprietary primitives. Building your agent\u0026rsquo;s state management and retrieval layer directly on top of them means a future migration off Cloudflare is a rewrite, not a redeploy.\nRolling your own on AWS with Bedrock, Lambda, and a vector store like OpenSearch or a managed Postgres with pgvector gives you more portability and more control, at the cost of assembling more pieces yourself. You\u0026rsquo;re managing IAM policies, cold start latency on Lambda, and a vector store that you provision and scale independently rather than getting for free with your compute. The complexity is real, but so is the portability. If you already run infrastructure on AWS, extending it with Bedrock agents keeps everything under one billing account and one set of operational tooling your team already knows.\nNeither option is objectively better. The real question is whether your organization\u0026rsquo;s existing infrastructure gravity points toward the edge or toward a hyperscaler, and whether the convenience of an integrated platform is worth trading for the flexibility of assembling your own stack.\nDo You Even Need an Agent # Most demos work because the task is narrow: one clear goal, a small number of tools, a controlled environment where failure is unlikely and, if it happens, invisible to the audience. Production tasks are rarely that narrow, and failure is never invisible to the person whose job depends on the output being right.\nBefore reaching for an agent framework, ask what actually fails in your current process and how often. If your workflow is a fixed sequence of steps that rarely changes, you don\u0026rsquo;t need an agent. You need an orchestrated pipeline with deterministic control flow and a model call or two where judgment is genuinely required. That\u0026rsquo;s cheaper to build, cheaper to run, and infinitely easier to debug.\nIf your workflow requires retrieval but the retrieval is well-scoped and the acceptable answer space is narrow, you need a solid RAG system with good chunking and a feedback loop, not an agent. Agentic retrieval adds cost and non-determinism to solve a problem that better chunking and indexing would have solved for less money.\nReach for a real agent framework only when the number of steps and the choice of tools genuinely cannot be known ahead of time, and when a human is available to intervene when the loop goes somewhere you didn\u0026rsquo;t expect. That\u0026rsquo;s a narrower set of use cases than the marketing suggests.\nA Checklist for Evaluating Agent Frameworks # Before adopting any agent framework, whether it\u0026rsquo;s Cloudflare\u0026rsquo;s, AWS\u0026rsquo;s, or an open source one, run it through these questions:\nLatency budget. How long can a user or downstream system wait for a task to complete, and what\u0026rsquo;s the worst-case latency if the agent needs six iterations instead of two? Cost per task ceiling. What\u0026rsquo;s the maximum dollar amount you\u0026rsquo;re willing to spend on a single task before you cut it off, and does the framework let you enforce that hard limit? Failure recovery behavior. When a tool call fails or returns garbage, does the agent retry sanely, escalate to a human, or silently produce a bad answer with high confidence? Auditability. Can you reconstruct, after the fact, exactly what the agent decided and why, well enough to explain it to a customer or a compliance officer? If a framework can\u0026rsquo;t give you clear answers to all four, it\u0026rsquo;s not ready for anything you\u0026rsquo;d call production, no matter how good the demo looked during Agents Week.\nRecommended Reading # AWS Certified Solutions Architect Study Guide: Associate SAA-C03 Exam, 4th Edition by Ben Piper \u0026amp; David Clinton AI Agents in Action by Micheal Lanham AWS Certified Cloud Practitioner Study Guide: CLF-C01 Exam by Ben Piper \u0026amp; David Clinton ","date":"3 August 2026","externalUrl":null,"permalink":"/post/2026/agents-week-is-marketing-heres-what-actually-matters-about-ai-agents-in-producti/","section":"Posts","summary":"","title":"What Actually Matters About AI Agents in Production","type":"post"},{"content":" Enterprise Training Testimonials — General Assembly (2023–2025) # Average Bootcamp NPS 80 (2x benchmark) | Instructor Rating 4.68/5 | Fortune 500: Prudential, McKinsey\nInfrastructure Developer — Prudential Financial # \u0026ldquo;I still go back to Ben discussing certificates because certificates never made any sense to me until he taught it.\u0026rdquo; Prudential Financial Participant\n\u0026ldquo;Ben was knowledgeable about the topics covered in the lessons and was able to provide context and answer questions that went beyond the scope of the curriculum.\u0026rdquo; Prudential Financial Participant\n\u0026ldquo;Ben knows the material inside and out. Glad to have Ben teaching the course.\u0026rdquo; Prudential Financial Participant\n\u0026ldquo;Ben was knowledgeable and skilled and also offered valuable insights. Great teacher, highly recommend!\u0026rdquo; Prudential Financial Participant\n\u0026ldquo;The instructors are great. They went above and beyond to add additional contents and labs for the course. I had zero to slim knowledge of AWS before this course and I\u0026rsquo;d learned a whole lot on what AWS provides and can do.\u0026rdquo; Prudential Financial Participant\n\u0026ldquo;Seasoned professionals and instructor crew. I feel like this is crucial for optimal learning experience.\u0026rdquo; Prudential Financial Participant\n\u0026ldquo;The instructors(Altaf, Karl \u0026amp; Ben) are top talents and pretty knowledgeable on the different concepts/tools.\u0026rdquo; Prudential Financial Participant\n\u0026ldquo;Excellent course!\u0026rdquo; Prudential Financial Participant\n\u0026ldquo;This particular course well organized and instructor team is very helpful and knowledgeable.\u0026rdquo; Prudential Financial Participant\n\u0026ldquo;I really enjoyed this class. Al, Ben, and Karl were a pleasure to learn from. I looked forward to class every day.\u0026rdquo; Prudential Financial Participant\n\u0026ldquo;Materials covers many of the AWS important topics and very knowledgeable instructors.\u0026rdquo; Prudential Financial Participant\n","date":"26 July 2026","externalUrl":null,"permalink":"/testimonials/general-assembly/","section":"Testimonials","summary":"","title":"General Assembly Testimonials","type":"page"},{"content":"","date":"26 July 2026","externalUrl":null,"permalink":"/testimonials/","section":"Testimonials","summary":"","title":"Testimonials","type":"testimonials"},{"content":"","date":"20 July 2026","externalUrl":null,"permalink":"/tags/ai-generated/","section":"Tags","summary":"","title":"Ai-Generated","type":"tags"},{"content":"Everyone has heard \u0026ldquo;don\u0026rsquo;t automate a bad process.\u0026rdquo;\nIf your deployment process is manual, undocumented, and requires three people to remember the secret handshake, putting an AI agent in front of it doesn\u0026rsquo;t fix it. It just makes the bad process run faster and fail in new ways.\nWe all know that.\nWhat we miss is this: when you give AI a goal without a process, it will invent its own process. And that process is probably bad.\nI see this constantly with AI coding agents. You tell it \u0026ldquo;add authentication to this app\u0026rdquo; or \u0026ldquo;migrate this database\u0026rdquo; or \u0026ldquo;automate these incident reports.\u0026rdquo; You didn\u0026rsquo;t give it a process. You gave it an outcome. So it makes up the steps:\nWhat to check first What order to do things in What counts as \u0026ldquo;good enough\u0026rdquo; When to stop and ask vs. when to keep going How to validate that it actually worked That invented process is trained on the average of the internet. It doesn\u0026rsquo;t know your constraints, your risk tolerance, your compliance requirements, or how your team actually operates. It doesn\u0026rsquo;t have to live with the consequences next Tuesday when it breaks.\nAI can help you design a process. That\u0026rsquo;s useful. Let it suggest one. Let it poke holes in yours.\nBut you have to own the process.\nIn practice, here is what works:\n1. Start with a process you own. Either write it yourself, or take an existing good process your team already uses. Be explicit. Steps, inputs, outputs, validation, rollback.\n2. Let AI critique it. Ask \u0026ldquo;what am I missing? What would fail? How would you make this more resilient?\u0026rdquo; Some suggestions will be good. Some will be bad. You decide.\n3. Lock it in. Once you have settled on the process, write it down where both you and the agent can see it. Checklist, doc, CLAUDE.md, runbook, whatever.\n4. Make AI follow it to the letter. This is the harnessing part. Don\u0026rsquo;t let the agent freelancers wander off because it found a \u0026ldquo;better way.\u0026rdquo; If it wants to deviate, it should propose a change to the process and get your sign-off. Otherwise, it follows the process exactly.\nThe new failure mode isn\u0026rsquo;t \u0026ldquo;we automated a bad process.\u0026rdquo; It\u0026rsquo;s \u0026ldquo;we let AI quietly invent a bad process and then we automated that.\u0026rdquo;\nIf you don\u0026rsquo;t define the process, AI will. And you will end up debugging a workflow you never approved, built on assumptions you never validated.\nDecide the process first. Then harness the AI to execute it.\n","date":"20 July 2026","externalUrl":null,"permalink":"/post/2026/dont-let-ai-invent-your-process/","section":"Posts","summary":"","title":"Don't Let AI Invent Your Process","type":"post"},{"content":"","date":"20 July 2026","externalUrl":null,"permalink":"/tags/engineering/","section":"Tags","summary":"","title":"Engineering","type":"tags"},{"content":" Contact \u0026amp; Resume # If you have any questions, business inquiries, or just want to connect, feel free to reach out to me at ben@benpiper.com.\nYou can view my professional experience on my LinkedIn Profile.\nBio # I\u0026rsquo;m a Principal Engineer, published author, and IT instructor specializing in AWS infrastructure, Cisco enterprise networking, and applied AI systems. With deep roots in Linux and Windows system administration, Citrix, and deep systems troubleshooting, I bridge the gap between legacy environments and modern cloud-native containerization (Docker/Kubernetes). Beyond infrastructure, I build full-stack software applications and orchestrate AI workflows using frameworks such as LangChain. I provide IT strategy and technical leadership to teams looking to fix their fundamentals and build reliable, debuggable systems.\nI\u0026rsquo;ve authored 7+ IT certification study guides published by Wiley/Sybex and Manning. My books have sold 100k+ copies ($2.5M+ publisher net) — including AWS Solutions Architect Associate (SAA) franchise (50k+) and AWS Cloud Practitioner (CLF) franchise (44k+), both bestseller-tier, plus solo-authored CCNP ENCOR and Cloud+ titles. They\u0026rsquo;ve helped tens of thousands pass their exams.\nAs a Pluralsight author, I\u0026rsquo;ve created 45 IT training courses covering AWS networking and architecture, Cisco enterprise networking (CCNP ENCOR and ENARSI), Windows Server, and configuration management. My courses average a 4.7-star rating across 3,000+ reviews and are known for their clear, practical explanations and real-world examples.\nKey Highlights # 7+ Published Books\n100k+ Copies Sold\n45 Training Courses Delivered\n20+ Years in IT\nBy the Numbers # Title Units Sold AWS CLF-C01 1st Ed (2019) 32,000 AWS SAA-C03 4th Ed (2023) 17,000 AWS SAA-C01 2nd Ed (2019) 17,000 AWS SAA-C02 3rd Ed (2020) 15,000 AWS CLF-C02 2nd Ed (2024) 11,000 CompTIA Cloud+ CV0-003 (2021) 5,000 CCNP ENCOR 350-401 solo (2020) 2,000 AWS CLF-C01 w/ Online Labs 2,000 CompTIA Cloud+ CV0-004 (2025) 1,000 All titles (30+ ISBNs) 103,000 What People Are Saying # Never thought I could understand networking concepts. Thanks a lot to the author for making me understand these. I owe you a party.\nBy far this has been a most effective course in terms of helping me learn networking. Finally, all those terms I have been reading and taking notes on are starting to make sense!\nIncredible course. Very clear and informative. Can\u0026rsquo;t praise high enough.\nI\u0026rsquo;m a very big fan of you. You\u0026rsquo;re amazing in the way you explain things, I\u0026rsquo;m really thankful to you.\nProfessional Recommendations # Allen Baxter — VP DevOps (managed Ben at Elite Webs) Benjamin was an extraordinary employee. Ben was able to manage multiple projects at once and came with a knowledge and skill set that allowed him to be self sufficient from the start. His ability to learn new technologies and implement very well thought solutions amazed me. I highly recommend Ben for a variety of positions beyond the \"Network Guru\" rank. If given the opportunity to manage a team he will make a great leader. Flaminio Guerrero — Sr. Solutions Architect, SHI (senior colleague at McKesson) Ben has a unique ability to provide highly analytical and detailed, yet comprehensive, perspective on the most complex of high-end technology solutions. He is one of the very few individuals that I feel completely comfortable placing in front of the most difficult situations as I trust that he will find a way to ensure success. Steven Ho — VP of Technology (managed Ben at McKesson) Benjamin comes highly recommended due to his excellent technical and analytical skills. His knowledge of networking, systems and scripting would be an enormous benefit for any organization looking for an accomplished and skilled engineer. Harvey Lee Hayes — Cloud \u0026amp; Infrastructure Architect (managed Ben directly) Benjamin is highly respected by his co-workers for his willingness to help anyone anytime he can. He is very technical and able to perform a wide range of duties. He has been instrumental in helping institute new company-wide cost saving procedures. He is very diligent at his job, and very professional. I would highly recommend him for any position. Richard Bailey — SVP Information Technology, PruittHealth (senior to Ben at UHS-Pruitt) Ben demonstrated expert problem solving skills during his time as a Citrix Administrator at UHS-Pruitt. He was determined when it came to resolving problems and diligent about meeting deadlines. Ben was energetic and highly motivated. He had a wide range of technical skills, and if he didn't know the answer he would go find it. Tracy Winchester — Systems Engineer, Exelon (same team at McKesson) Ben's ability to script and come up with ways to solve issues was impressive. We lacked a tool for reporting on Citrix license usage and Ben was able to script a solution that gave us a report of license usage and created a graph, saving the company from buying a third party tool. He is skilled at troubleshooting complex issues and very knowledgeable at several technologies. ","date":"16 July 2026","externalUrl":null,"permalink":"/about/","section":"Ben Piper","summary":"","title":"About Ben Piper","type":"page"},{"content":"","date":"16 July 2026","externalUrl":null,"permalink":"/articles/","section":"Articles","summary":"","title":"Articles","type":"articles"},{"content":" Architecting for Reliability on AWS # As always Ben Piper nails it when it comes to explaining networking\nBen Piper is excellent!!\nAWS Networking Deep Dive: Route 53 DNS # This course is really awesome!! One of the best course/training that i have ever taken before. Thank you so much Ben!!\nThank you for making these concepts so easy to understand, I was afraid of starting this module in the beginning but your explanation made it so crystal clear\nThis is the best course I have ever taken. Thanks Ben!\nAWS Networking Deep Dive: Elastic Load Balancing (ELB) # If teaching is an art, Ben Piper is a sensei at it. The curriculum covered everything I needed to know and went deep enough so I could really understand it. Given his strengths and roots in networking, I would love to see him author or co-author additional courses such as Azure networking constructs, Cloudfront, app deployments across regions to account for a cloud provider\u0026rsquo;s regional outage, and application deployment across multiple cloud providers (AWS \u0026amp; Azure) for cloud provider diversity. With all said and done - kudos on a job well done!!!\nBest session on Loadbalancing. Covered all the Load balancing concepts in a clear manner.\nBen Piper is solid!\nAWS Networking Deep Dive: Virtual Private Cloud (VPC) # For me a AWS was a grey are so far, Ben has helped me understand the concepts very well. He is an excellent trainer that I came to know of using Plural Sight. Thanks a lot Plural Sight for having such excellent trainers on your platform!\nBen Piper is now my new favorite instructor!\nThis is the first Video after i watched almost 20 hours + videos where my concepts got clear. Very precise explanation. I\u0026rsquo;d rate 100% this course.\nMust watch course..!!\nAwesome Teacher and very detailed explanation of concepts\nBen Piper is really awesome !\nOther AWS courses # I just completed a second PluralSight course from you, Operational Excellence. I really appreciated them and consider you and one other author the best of the courses I have taken so far. So I want to say Thanks.\nChad Mitchell\nHi Ben,\nFirst a compliment 🙂 I\u0026rsquo;m following your course having done many AWS courses on Pluralsight, and I\u0026rsquo;m certainly enjoying yours the most.\nMatt Shickell\n","date":"16 July 2026","externalUrl":null,"permalink":"/testimonials/aws/","section":"Testimonials","summary":"","title":"AWS Course Testimonials","type":"page"},{"content":"For book reviews, visit my Amazon author page\n","date":"16 July 2026","externalUrl":null,"permalink":"/testimonials/books/","section":"Testimonials","summary":"","title":"Book Testimonials","type":"page"},{"content":"","date":"16 July 2026","externalUrl":null,"permalink":"/tags/cisco/","section":"Tags","summary":"","title":"Cisco","type":"tags"},{"content":"","date":"16 July 2026","externalUrl":null,"permalink":"/tags/cloud/","section":"Tags","summary":"","title":"Cloud","type":"tags"},{"content":" Get in Touch # If you have any questions, business inquiries, or just want to connect, feel free to reach out.\nYou can email me at ben@benpiper.com — if your link includes an interest query param (e.g., /contact/?interest=SAA-C04), the email subject/body will be prefilled.\nEmail Ben Or connect with me on professional networking platforms. For more information about my background and professional experience, please refer to my About Page and my LinkedIn Profile.\n","date":"16 July 2026","externalUrl":null,"permalink":"/contact/","section":"Ben Piper","summary":"","title":"Contact","type":"page"},{"content":" Networking # 5 Network Automation Tips \u0026amp; Tricks—NVIDIA\nAutomating Cumulus Linux With Ansible\n5 big misconceptions about virtual LANs\nIT Management # CEO vs. CIO: Why Both Sides Are Wrong About IT’s Value and Purpose—Corp! Magazine\n","date":"16 July 2026","externalUrl":null,"permalink":"/articles/published-articles/","section":"Articles","summary":"","title":"My Published Articles","type":"page"},{"content":"Hey Ben! I just wanted to personally thank you for all your efforts making networking courses on Pluralsight.\nI can say without a shade of doubt that among all the CCNA/P courses I\u0026rsquo;ve taken from others on Pluralsight and INE that your courses stand above all the others. You can drill theory and protocol details all you want.. but at the end of the day, your methodology and practical approach to teaching/troubleshooting really solidified networking concepts and pretty much made everything click for me.\nFor example, going through your courses for CCNP Tshoot had me a little wary for the exam. Although I have yet to take it (waiting for that cert compensation paperwork to go through here at work), I\u0026rsquo;ve just started going through other practice tickets that are supposedly what the exam uses.. and I almost had to pinch myself! For some reason I thought the exam tickets were just like they are in your courses (an aside- it\u0026rsquo;s super impressive and really I appreciate you building out all those topologies/configs for each course). But it would seem that the exam tickets pale in comparison to yours. Your courses make most of these tickets trivial! I\u0026rsquo;m confident that when I sit the exam, I will pass with room to spare.\nOutside of Cisco exam world, I just landed a Network Engineer position at an ISP here in upstate NY - I like to think that you had a hand in making that possible!\nMike Agnew\nGood morning Ben,\nI just wanted to let you know that my employer the London ambulance service provided access to the Pluralsight for us to learn new skills. I was interested in moving on with my CCNA knowledge and I found your “Switch” course of modules on Pluralsight helped greatly with my self study on this subject.\nI am pleased to report that having taken the Switch exam on Friday 21st February, i was successful and i now have my CCNP switch certification.\nJohn Yeates\nBen,\nI recently obtained my CCNP certification and used your Pluralsight courses as my main source for studying. I just wanted to take a minute to say thank you for the great courses, especially the VIRL stuff for the TSHOOT exam. Being able to follow along with you troubleshooting a network like that with multiple routers and switches really helped!\nThanks again!\nAndrew Ritz\nHi Ben,\nI just wanted to take a second and reach out and say thank you for the content you’ve put on Pluralsight for the CCNP Route Switch course. I’ve been using it to prepare for my Switch exam and I just love the way you go through the content. I haven’t felt like I’ve struggled with any of the concepts you’ve discussed thus far. The labs help put things into context and I practice those labs over and over again until feels like 2nd nature to me.\nTaking the 300-115 next Friday and I feel like I’ll be just fine!\nThank you,\nA.J. Murray\nBen! thanks for making those videos it really help me pass and helped get me out the help desk\nReddit user CCNPAT\nI have been working through your CCNP. It is helping me a lot.\nShif Schiffman\nCisco Enterprise Networks: Basic Networking and IP Fundamentals # Ben knows how to present ideas in a simple way that even a newbie can easily follow. Great job.\nGreat instructor, clear easy to follow theory followed up by a good practical lab!\nReally good - also added extra detail occasionally which is interesting and helpful.\nThis is a very high quality course. I felt like every sentence spoken was a line item worth including in notes. This was well thought out and much appreciated.\nBen Piper\u0026rsquo;s course is also good if you want to lab in details. He does configuration from the scratch and explains everything in a manner only a potato won\u0026rsquo;t understand.\nSuperior stuff\nCisco Enterprise Networks: Layer 2 Troubleshooting # Ben is Brilliant! Love the way he teaches stuff.\nCisco Enterprise Networks: VLANs and Trunking # Wow! Private VLANs are difficult to conceptually grasp. Thanks Ben for the clear explanations - I get it now! Really good stuff!\nI\u0026rsquo;ve watched and read a lot of material on private VLANs and this is the first time it has ever made sense to me. In fact, the way Ben explained it made it seem so remarkably simple that I don\u0026rsquo;t understand how nobody else has been able to do that.\nBen is a great instructor and he explained all the topics in a great way in which anyone can understand. The examples shown in the course was great and everything about the course was well put together. Thanks.\nBen does a great job presenting and explaining the material covered in the video.\nPractical Networking # Hello Ben,\nI’m a very big fan of you. I’ve been watching your course \u0026ldquo;Practical Networking\u0026rdquo; in pluralsight, and I’ve to say is that I LOVE YOU MAN! You’re amazing in the way you explain things, I’m really thankful to you.\nIbrahim Muhammad\nNever thought i could understand networking concepts. Thanks a lot to the author to make me understand these. I owe you a party.\nBy far this has been a most effective course in terms of helping me learn networking. Finally, all those terms I have been reading and taking notes on are starting to make sense! Most things are finally coming together and actually starting to make sense since I begun this course. Thank you for the real world examples and defining the terms you are referring to throughout the course.\nI\u0026rsquo;m only at the start but Ben has made every concept make sense\nThe best presentation and explanation so far. Thank you Ben\nold guy, new to the IT world. I can say this session really helped me understand more of where to look and a direction to move in for troubleshooting and also realizing some technical aspects I didn\u0026rsquo;t know\nTo be honest, Ben has true professor skills, I\u0026rsquo;m glad I stumbled upon his course. This is just the first, next ones coming up right away.\nThis was probably the most relevant, useful, well thought out, and presented course I\u0026rsquo;ve done so far on Pluralsight. 10/10\nCombination on technical accuracy and presentation style is perfect\nWonderful for the beginners in networking\u0026hellip;\nIncredible course. Very clear and informative. Can\u0026rsquo;t praise high enough.\n","date":"16 July 2026","externalUrl":null,"permalink":"/testimonials/networking/","section":"Testimonials","summary":"","title":"Networking Course Testimonials","type":"page"},{"content":" Featured Projects # Ripgrep MCP A blazing fast Model Context Protocol (MCP) server that empowers AI agents to search massive codebases and directories instantly using ripgrep.\nAI/MCP TypeScript Search GitHub BenBot — Production AI Assistant Live prod on benpiper.com — answers visitor questions using site content via Cloudflare Worker + Vectorize semantic search + OpenAI gpt-4.1-mini. CI/CD via GitHub Actions with automatic embedding updates on content changes, rate limiting, and Turnstile bot protection. See Work for architecture.\nProd Cloudflare Workers Vector Search RAG AI/LLM 🤖 Try Live Prod Architecture Unmuted Local-first AI web app that transforms silent technical screen recordings into polished how-to videos. Uses Vision-Language Models to generate narration, overlays, chapters, and interactive review workflows.\nAI/ML Full-Stack Python GitHub 🔗 Live Demo Live Transcription Real-time audio transcription with speaker identification using Whisper AI. Includes speaker diarization, custom vocabulary support, hallucination filtering, and session management.\nAI/ML FastAPI Web Audio GitHub Auto Video Editor Automatically detects and removes silence, filler words, and static moments from video files. Features web UI, REST API, and GPU acceleration for processing screen recordings and lectures.\nComputer Vision Video Processing FastAPI GitHub Yokeru Resilient Integration Agent Healthcare integration demo bridging EHR systems (FHIR) with voice-agent platform. Demonstrates crash-safe workflows, idempotent API calls, webhook handling, and observability with Prometheus metrics.\nHealthcare Tech Resilient Systems FastAPI GitHub ","date":"16 July 2026","externalUrl":null,"permalink":"/portfolio/","section":"Ben Piper","summary":"","title":"Portfolio","type":"page"},{"content":" Privacy Policy # This Privacy Policy describes how your personal information is collected, used, and shared when you visit benpiper.com (the \u0026ldquo;Site\u0026rdquo;).\nAdvertising and Cookies # This Site uses Google AdSense to display advertisements.\nThird party vendors, including Google, use cookies to serve ads based on a user\u0026rsquo;s prior visits to this website or other websites. Google\u0026rsquo;s use of advertising cookies enables it and its partners to serve ads to users based on their visit to this site and/or other sites on the Internet. Users may opt out of personalized advertising by visiting Ads Settings. Alternatively, you can opt out of a third-party vendor\u0026rsquo;s use of cookies for personalized advertising by visiting www.aboutads.info. Log Files # Like many other Web sites, we make use of log files. The information inside the log files includes internet protocol (IP) addresses, type of browser, Internet Service Provider (ISP), date/time stamp, referring/exit pages, and number of clicks to analyze trends, administer the site, track user\u0026rsquo;s movement around the site, and gather demographic information. IP addresses and other such information are not linked to any information that is personally identifiable.\nConsent # By using our website, you hereby consent to our Privacy Policy and agree to its Terms and Conditions.\nContact Us # If you require any more information or have any questions about our privacy policy, please feel free to contact us via our Contact Page.\n","date":"16 July 2026","externalUrl":null,"permalink":"/privacy/","section":"Ben Piper","summary":"","title":"Privacy Policy","type":"page"},{"content":"I\u0026rsquo;m available for FTE, contract, retainer, or fractional advising engagements.\nCore Competencies # My technical background spans systems administration, cloud engineering, and application development:\nInfrastructure \u0026amp; Networking # Architecting and troubleshooting AWS environments, Cisco enterprise networks, and containerized workloads using Docker and Kubernetes.\nSystems Administration # Operational experience managing Linux, Windows, and Citrix environments.\nSoftware Development \u0026amp; Applied AI # Writing full-stack software applications and implementing production AI — e.g., BenBot, live prod AI assistant on benpiper.com (Cloudflare Worker + Vectorize semantic search + OpenAI, CI/CD + rate limiting + Turnstile bot protection) — see Portfolio.\nTechnical Strategy # Advising engineering leadership on system architecture, migration strategies, and operational reliability.\nEngagement Models # I partner with engineering teams in the following capacities:\nPrincipal Engineering # Hands-on implementation for complex infrastructure, networking, or software development projects. Available for FTE, contract, or ongoing retainer.\nFractional Advising # Strategic guidance, architecture review, and troubleshooting for teams navigating cloud migrations, scaling challenges, or AI integrations.\nBackground \u0026amp; Proof of Work # I have authored 7+ technical books (100k+ copies sold, $2.5M+ publisher net per Wiley — rounded, punchy figures) and 45 video courses (4.7-star average, 3,003 ratings) used by IT professionals worldwide.\nBooks — Wiley/Sybex \u0026amp; Manning ($2.5M+ net, 100k+ copies):\nAWS Solutions Architect Associate (SAA) franchise — 50k+ ($1.3M+ net): SAA-C03 4th Ed bestseller-tier (17k+, $450k+), SAA-C01 2nd Ed (17k+, $420k+), SAA-C02 3rd Ed (15k+, $410k+) — co-authored with David Clinton where noted AWS Cloud Practitioner (CLF) franchise — 44k+ ($1M+ net): CLF-C01 1st Ed (32k+, $690k+), CLF-C02 2nd Ed (11k+, $260k+), Online Labs (2k+, $110k+) CompTIA Cloud+ franchise — 6k+ ($150k+ net): CV0-003 3rd Ed (5k+, $100k+), CV0-004 4th Ed current (1k+, $40k+) ENCOR solo — 2k+ ($60k+ net) — CCNP Enterprise 350-401 Learn Cisco — Manning, solo (2015) Publishers: Wiley/Sybex, Manning Publications. Video: Pluralsight author since 2014 (45 courses, 4.7-star average, 3,003 ratings — top course Practical Networking 1,041 ratings — including AWS Reliability/Security/Operational Excellence, VPC, Route 53, ELB, Cisco Enterprise Networks). Books have helped 100k+ readers pass certs — same fundamentals-first approach I bring to teams.\nCurrent enterprise training:\nNIIT — AI Technical Trainer (July 2026–Present) General Assembly — DevOps Lead Instructor (Feb 2023–Oct 2025) — Learning \u0026amp; Product Development team: agentic workflows cut dev time 22%, budgets 53% and beat budgets by 20% saving ~$500K in 9 months. Led enterprise training for Fortune 500 clients including Prudential and McKinsey, and taught the consumer-facing Software Engineering Bootcamp (SEB). Trained 90+ engineers across AWS, Terraform, Docker, ECS Fargate, CI/CD, Python, React, and Node. Average Bootcamp NPS 80 (2x benchmark), Instructor Rating 4.68/5 across all cohorts. Testimonials → If you bought my AWS SAA guide (SAA-C03 with SAA-C04 current since March 2024) or your team needs CompTIA Cloud+ (CV0-004) prep, I do private remote workshops plus AWS architecture review / cost optimization / troubleshooting — same fundamentals-first approach from the books, tailored to your environment.\nFor examples of applied work and open-source, view my Portfolio. I write about systems engineering and AI on my blog.\nTo discuss a potential project or role, contact me at ben@benpiper.com — fully remote, 10+ years 100% remote experience.\n","date":"16 July 2026","externalUrl":null,"permalink":"/work/","section":"Ben Piper","summary":"","title":"Work With Me","type":"page"},{"content":" Free Training - YouTube Hub # 2k subscribers on YouTube. Content includes:\nPluralsight course clips (free previews) Thought leadership for IT pros and execs (e.g., AI fancy Google, prompts are not rules, signs of ghost job listings) Tutorials and free courses What to expect # Beginner/intermediate concepts in video form, senior-level depth paired with blog posts Focus on fundamentals: cloud cost models aren\u0026rsquo;t automatically cheaper, bits-is-bits fallacy, IP does not name device, networking isn\u0026rsquo;t hard when fundamentals are clear Approach: ask what matters day-to-day, so content maps to real work YouTube channel # Direct link: YouTube\nAutomation coming # This section will auto-populate from YouTube Data API via GitHub Action — each video becomes a markdown page under /youtube/ with thumbnail, transcript where available, tags, and related blog post links.\nIn the meantime, browse:\nBlog - senior-level writing Portfolio - working demos like BenBot Books and Courses ","date":"13 July 2026","externalUrl":null,"permalink":"/training/free/","section":"Training","summary":"","title":"Free Training","type":"page"},{"content":" Free and Professional Training # Content is designed for a range: junior engineers who need basics repeated, seniors who want acknowledgment of what they\u0026rsquo;ve built, and leaders weighing train vs hire, build vs buy, and outsourced AI vs air-gapped in-house.\nFree Training # YouTube channel (2k subs): Pluralsight course clips, thought leadership for IT pros and execs, tutorials and free courses. These are the top of the funnel and include transcripts where available.\nBrowse free videos: Free Videos YouTube directly: youtube.com/@benpiper Free content pairs with blog posts that go senior-level deep — e.g., DNS, CloudFormation, RAG pipelines, harnessing patterns.\nProfessional Training (Pluralsight) # 45 video courses on Pluralsight — beginner to intermediate, known for clear, practical explanations grounded in real scenarios.\nAWS Networking Deep Dive (VPC, Route 53, ELB) Architecting on AWS (Operational Excellence, Reliability, Security) Cisco Enterprise Networks (ENCOR, ENARSI, Route/Switch/TSHOOT) Practical Networking, Windows Server, Puppet Details and affiliate links: My Courses — will be migrated to /training/courses/ with alias.\nBooks # Study guides that helped tens of thousands pass certification exams. Amazon reviews include exam pass stories. See Books for errata, TOC, and purchase.\nAWS Certified Solutions Architect SAA-C03 (4th Edition) AWS Certified Cloud Practitioner CLF-C01 CCNP Enterprise ENCOR 350-401 Learn Cisco Network Administration in a Month of Lunches All training pages include affiliate disclosure when applicable. Ad slots are considerate and collapse if blocked — side income, not janky.\nHow this connects to hiring # Training is how approach to fundamentals and troubleshooting shows. Teams that learn from courses often ask for design reviews or critical-thinking help that AI doesn\u0026rsquo;t do well — problems with the human element. For that, see Work With Me.\n","date":"13 July 2026","externalUrl":null,"permalink":"/training/","section":"Training","summary":"","title":"Training","type":"page"},{"content":"YouTube videos will auto-populate here via scripts/youtube-sync/youtube-sync.js.\nSee Free Training Hub for curated list and Training for full catalog.\nRun:\nYOUTUBE_API_KEY=xxx node scripts/youtube-sync/youtube-sync.js hugo server -D Each video becomes content/youtube/YYYY-MM-DD-slug/index.md with frontmatter youtube_id, tags, thumbnail.\n","date":"13 July 2026","externalUrl":null,"permalink":"/youtube/","section":"YouTube - Free Training","summary":"","title":"YouTube - Free Training","type":"page"},{"content":"","date":"16 May 2026","externalUrl":null,"permalink":"/tags/agentic-systems/","section":"Tags","summary":"","title":"Agentic-Systems","type":"tags"},{"content":"Most RAG implementations work great in demos and fail spectacularly in production. The tutorials show you how to split documents by character count, embed everything with the first model you find, and hope vector similarity returns something useful. Then you deploy it and discover that your AI assistant confidently tells users that your documentation says the exact opposite of what it actually says.\nThe problem isn\u0026rsquo;t that RAG is hard. The problem is that RAG is a system, not a single algorithm. And like any system, it fails at the weakest link.\nChunking Is Not a Text Processing Problem # The most common RAG failure mode starts with chunking. You take your documentation, split it every 500 characters, overlap by 50 characters, and call it done. This approach treats chunking like a text processing problem when it\u0026rsquo;s actually a knowledge representation problem.\nWhen you chunk by character count, you break sentences in the middle. You separate code examples from their explanations. You split numbered lists across chunk boundaries. The embedding model sees fragments, not concepts.\nBenBot uses semantic chunking that respects document structure. Each chunk represents a complete thought—a section, a code example with its explanation, or a complete procedure. The chunking logic looks for natural breakpoints: markdown headers, code fences, paragraph boundaries.\nHere\u0026rsquo;s what semantic chunking preserves that character-based chunking destroys:\nTechnical procedures stay together with their context Code examples remain connected to explanatory text Lists and tables stay intact Section headers travel with their content The tradeoff is variable chunk sizes. Some chunks are 200 tokens. Others are 800. Your embedding model handles both fine, but your retrieval logic needs to account for the size variation when selecting context for the LLM.\nEmbedding Models Are Not Commodities # Your choice of embedding model affects everything downstream. Most implementations grab text-embedding-ada-002 because it\u0026rsquo;s the first result in the OpenAI docs, but that model wasn\u0026rsquo;t designed for technical documentation retrieval.\nYou need to test at least three approaches:\nOpenAI\u0026rsquo;s text-embedding-3-small performs better than Ada-002 on technical content and costs less per token. At 512 dimensions, it finds semantic matches that Ada-002 misses while using less storage space.\nCohere\u0026rsquo;s embed-english-v3.0 outperforms OpenAI on domain-specific technical queries in many benchmarks, but costs more per request. The quality difference matters if your corpus contains specialized terminology that general-purpose models struggle with.\nOpen-source alternatives like all-MiniLM-L6-v2 cost almost nothing to run but require hosting infrastructure. The embedding quality is acceptable for many use cases, but you lose the semantic sophistication of commercial models.\nThe only way to choose is to benchmark against your actual queries and content. Build a test set of 50-100 real user questions with known correct answers. Measure which embedding model returns the right chunks in the top 5 results most often.\nPure Vector Search Is Not Enough # The dirty secret of production RAG systems is that pure vector similarity often returns garbage. Your embedding model thinks \u0026ldquo;HTTP status codes\u0026rdquo; and \u0026ldquo;HTTP caching\u0026rdquo; are semantically similar, so when someone asks about 404 errors, they get explanations of cache-control headers.\nHybrid search solves this by combining vector similarity with keyword matching. You run both searches in parallel and fuse the results using a ranking algorithm that considers both semantic relevance and exact term matches.\nBenBot\u0026rsquo;s hybrid approach:\nVector search finds semantically similar chunks Keyword search finds exact term matches Ranking fusion combines results, boosting chunks that appear in both lists Fallback logic activates pure keyword search when vector search returns low-confidence results The ranking fusion algorithm weights vector results higher for abstract queries (\u0026ldquo;how do I troubleshoot networking issues\u0026rdquo;) and keyword results higher for specific queries (\u0026ldquo;what is BGP AS path prepending\u0026rdquo;).\nflowchart TD Query[User Query] --\u003e Vector[Vector SearchSemantic Match] Query --\u003e Keyword[Keyword SearchExact Term Match] Vector --\u003e Fusion{Ranking Fusion} Keyword --\u003e Fusion Fusion --\u003e|High Confidence| TopK[Top-K Results] Fusion --\u003e|Low Confidence| Fallback[Fallback to Pure Keyword] Fallback --\u003e TopK TopK --\u003e LLM[LLM Generation] This catches cases where embeddings miss obvious matches. If someone asks about \u0026ldquo;VPC peering,\u0026rdquo; you want results that contain those exact terms, not just semantically similar concepts about network connectivity.\nQuality Assessment Prevents Silent Failures # RAG systems fail silently. The retrieval returns irrelevant chunks, the LLM generates a confident-sounding answer based on wrong information, and the user gets misleading guidance. You don\u0026rsquo;t know this happened unless you\u0026rsquo;re actively measuring quality.\nYou need automated relevance scoring for retrieved chunks and answer validation for LLM outputs. Build these checks into your pipeline, not as an afterthought.\nFor chunk relevance, implement a scoring function that considers:\nSemantic similarity scores Keyword match density Document recency and authority Historical user interaction data For answer validation, use a separate LLM call to verify that the generated answer is supported by the retrieved chunks. If the validation fails, return \u0026ldquo;I cannot find sufficient information in the available documentation\u0026rdquo; instead of a hallucinated response.\nThis adds latency and cost, but prevents the system from confidently delivering wrong answers. The user experience of \u0026ldquo;I don\u0026rsquo;t know\u0026rdquo; is vastly superior to confident misinformation.\nEdge Computing Solves the Latency Problem # RAG pipelines have a latency problem. You\u0026rsquo;re making multiple API calls—embedding generation, vector search, LLM inference—and each adds round-trip time. Users abandon requests that take longer than 3 seconds, which doesn\u0026rsquo;t leave much budget for network calls.\nCloudflare Workers solve this by running your retrieval logic at the edge. The vector database query happens from the same data center that serves your users, eliminating transcontinental round trips. The embedding generation and LLM calls still hit external APIs, but you\u0026rsquo;ve cut the worst latency sources.\nEdge deployment also enables request coalescing. Multiple users asking similar questions within a short time window can share embedding calculations and retrieved chunks, reducing both cost and latency for subsequent requests.\nThe architecture looks like this:\nStatic site assets served from Cloudflare CDN RAG pipeline logic runs in Cloudflare Workers Vector index stored in Cloudflare Vectorize LLM calls routed to the nearest OpenAI edge endpoint This setup delivers sub-second response times for most queries, which makes the difference between a useful tool and an abandoned experiment.\nContext Window Optimization Is Critical # LLMs have finite context windows, and retrieved chunks often exceed that limit. You cannot just concatenate the top 10 results and hope for the best. You need a strategy for selecting and ordering chunks to maximize relevance within token constraints.\nThe naive approach ranks chunks by similarity score and includes them until you hit the token limit. This often includes redundant information while excluding important details that appeared in lower-ranked chunks.\nBetter approaches:\nDiversity-based selection ensures retrieved chunks cover different aspects of the topic. If the first chunk explains basic concepts and the second chunk also explains basic concepts, skip the second and include a chunk that covers advanced usage or troubleshooting.\nContext-aware ordering places the most directly relevant chunk closest to the prompt, where the LLM pays the most attention. Supporting information goes in the middle. Background context goes at the beginning where it establishes foundation knowledge.\nDynamic chunk sizing adjusts retrieval based on query complexity. Simple factual questions get fewer, more focused chunks. Complex how-to questions get more comprehensive context even if individual chunks are less precisely matched.\nTrack which ordering strategies produce the best answers for different query types. This requires ongoing measurement, not just initial optimization.\nDebugging Production RAG Systems # RAG systems break in creative ways. The chunking logic miscategorizes content. The embedding model returns unexpected similarities. The LLM hallucinates despite having good source material. You need visibility into each component to debug failures effectively.\nEssential logging:\nQuery text and processed query embeddings Retrieved chunk IDs, similarity scores, and full text LLM prompt construction and token usage Generated response and confidence scores User feedback when available Structure logs so you can trace a specific user query through the entire pipeline. When someone reports a wrong answer, you need to see exactly which chunks were retrieved and why the LLM generated its response.\nBuild debug endpoints that expose pipeline internals for testing. Create a query interface that shows retrieved chunks before LLM processing. Add switches to disable hybrid search components so you can isolate vector vs. keyword performance.\nMonitor key metrics:\nAverage retrieval latency by component Chunk relevance score distributions LLM token usage and cost per query User satisfaction ratings when available Set up alerts for quality degradation. If average chunk relevance scores drop or user abandonment rates spike, you need to investigate before the problem affects more users.\nCost Optimization Reality # RAG systems cost more than you expect. Embedding generation, vector storage, and LLM inference charges add up quickly. Optimize for cost efficiency without sacrificing quality.\nEmbedding costs: Cache embeddings aggressively. User queries often repeat, and document embeddings never change unless content updates. Store query embeddings with TTL expiration and document embeddings permanently.\nVector storage: Use lower-dimensional embeddings when quality allows. 512 dimensions usually perform as well as 1536 for domain-specific retrieval while using 70% less storage space.\nLLM costs: Optimize prompt engineering to minimize token usage. Remove unnecessary retrieval context. Use shorter, more direct prompts. Consider smaller models for simple queries that don\u0026rsquo;t require advanced reasoning.\nInfrastructure costs: Edge computing reduces API call volume through request coalescing and caching. The edge infrastructure cost is often offset by reduced upstream API charges.\nMonitor cost per query and set budgets with alerts. Track cost efficiency metrics like successful answers per dollar spent. This data guides optimization decisions and helps justify infrastructure investments.\nThe goal is sustainable operation, not just functional operation. A RAG system that costs $500 per day to answer 100 queries is not viable long-term, regardless of answer quality.\nRAG systems work when you treat them as systems. Focus on the inputs and outputs of each component. Measure everything. Optimize for the user experience you actually want, not the demo you can build in an afternoon.\nFeatured image by Microsoft Copilot on Unsplash\nRecommended Reading # CCNP Enterprise Certification Study Guide: 350-401 ENCOR by Ben Piper \u0026amp; David Clinton The LLM Engineer's Handbook by Paul Iusztin and Maxime Labonne AI Engineering: Building Applications with Foundation Models by Chip Huyen ","date":"16 May 2026","externalUrl":null,"permalink":"/post/2026/building-a-rag-pipeline-that-actually-works/","section":"Posts","summary":"","title":"Building a RAG Pipeline That Actually Works","type":"post"},{"content":"","date":"16 May 2026","externalUrl":null,"permalink":"/tags/chatbots/","section":"Tags","summary":"","title":"Chatbots","type":"tags"},{"content":"","date":"16 May 2026","externalUrl":null,"permalink":"/tags/embeddings/","section":"Tags","summary":"","title":"Embeddings","type":"tags"},{"content":"The prompt engineering party is over. You can spend weeks crafting the perfect few-shot examples, tuning your system prompt, and A/B testing your context window allocation. But you\u0026rsquo;ll still hit a wall when your model needs to make a phone call, query a database, or reason about information that changes faster than your static prompt.\nAgentic harnesses solve this by treating context as a live pipeline instead of a static template.\nWhat Agentic Harnesses Actually Are # An agentic harness is a dynamic context injection system. Instead of feeding your model a pre-written prompt with hardcoded examples, the harness assembles context in real-time by calling tools, querying APIs, and orchestrating multi-step workflows.\nThink of it as the difference between handing someone a printed map versus giving them a GPS with live traffic updates. The map works fine for simple routes, but when you need to navigate construction, accidents, or closed roads, you need something that adapts.\nTraditional prompt engineering gives you the map. Harnesses give you the GPS.\nThe harness intercepts the user\u0026rsquo;s request, determines what additional context the model needs, gathers that context from external sources, and then constructs the prompt dynamically. The model sees a rich, current, and targeted context window instead of generic boilerplate.\nWhy RAG and Static Prompts Fall Short # Retrieval-Augmented Generation was supposed to solve the stale knowledge problem. But RAG systems typically work by doing semantic search over static documents, pulling in the top-K results, and hoping the model can make sense of it all.\nThis breaks down when you need to:\nExecute multi-step reasoning that requires intermediate API calls Combine structured data from databases with unstructured documents Validate information against live systems before providing an answer Chain together multiple tools in sequence based on previous results Static prompt engineering hits similar walls. You can optimize your prompts for known scenarios, but the moment you need dynamic data or complex orchestration, you\u0026rsquo;re stuck.\nConsider a customer support scenario. A static RAG system might retrieve documentation about account management, but it can\u0026rsquo;t check the user\u0026rsquo;s actual account status, validate their payment history, or update their preferences in real-time. A harness can do all of that within a single conversation.\nThe Technical Architecture # Harness systems are orchestration platforms with three core components:\nTool Registry: A catalog of available functions the model can call. Each tool has a schema definition, authentication requirements, and execution constraints. Tools can be APIs, database queries, file operations, or even calls to other models.\nContext Assembly Pipeline: The logic that determines which tools to call, in what order, and how to combine their outputs into coherent context. This is where the intelligence lives. Simple harnesses use predefined workflows. Advanced ones use models to plan and adapt the pipeline dynamically.\nExecution Engine: The runtime that actually makes the tool calls, handles errors, enforces timeouts, and manages state across multi-step operations. This needs to be robust because external APIs fail, rate limits hit, and models sometimes request impossible operations.\nThe flow typically works like this: User makes a request → Harness analyzes the request to determine required context → Harness calls appropriate tools in sequence → Results are formatted and injected into the model\u0026rsquo;s context → Model generates response → Response may trigger additional tool calls → Final answer is returned.\nflowchart LR User[User Request] --\u003e Harness subgraph \"Agentic Harness System\" direction TB Context[Context Assembly] Engine[Execution Engine] Registry[(Tool Registry)] Context \u003c--\u003e Engine Engine \u003c--\u003e Registry end Engine \u003c--\u003e External[External APIs] Context --\u003e Model[Foundational Model] Model --\u003e Response[Final Answer] The key insight is that the harness treats the model as part of a larger system, not as a standalone component.\nBuild vs Buy Decisions # You have three paths: build from scratch, use an open-source framework, or buy an enterprise platform.\nBuilding from scratch gives you total control but requires significant engineering investment. You\u0026rsquo;ll need to handle tool orchestration, error recovery, context serialization, and execution monitoring. Budget at least 3-6 months for a production-ready system, more if you need advanced features like dynamic planning or multi-model coordination.\nOpen-source frameworks like LangChain, CrewAI, and Haystack provide the scaffolding but still require substantial customization. LangChain is the most mature but has accumulated significant complexity. CrewAI focuses on multi-agent workflows but can be overkill for simpler use cases. The hidden cost is maintenance—these frameworks change rapidly and breaking changes are common.\nEnterprise platforms from vendors like Microsoft (Semantic Kernel), Google (Vertex AI Agent Builder), or specialized providers handle the infrastructure but lock you into their ecosystems. Pricing models vary widely, from per-request charges to flat monthly fees. The trade-off is reduced engineering effort versus vendor dependency and potentially higher long-term costs.\nCost analysis depends heavily on your scale and requirements. For high-volume applications processing thousands of requests daily, the infrastructure and maintenance costs of custom solutions often justify themselves. For smaller deployments or proof-of-concepts, managed platforms usually make more sense.\nWhere Harnesses Excel # Customer Support Automation: Instead of static FAQ matching, harnesses can check account status, pull order history, validate warranty coverage, and escalate to human agents with full context. The model isn\u0026rsquo;t just answering questions—it\u0026rsquo;s actively investigating on the customer\u0026rsquo;s behalf.\nTechnical Documentation Generation: Rather than templating existing docs, harnesses can query live systems, validate configurations, test code examples, and generate documentation that reflects current reality. The docs stay synchronized with the actual system state.\nComplex Data Analysis Workflows: Harnesses can query databases, run statistical analyses, generate visualizations, and iteratively refine results based on initial findings. The model becomes part of an analytical pipeline rather than just a text generator.\nThe common thread is scenarios where the answer depends on current, external state that can\u0026rsquo;t be pre-loaded into a prompt or document index.\nThe Debugging Nightmare # Harness systems are significantly harder to debug than static prompts. When something goes wrong, you need to trace through potentially dozens of tool calls, API responses, and context transformations to understand why the model produced a particular output.\nTraditional debugging approaches don\u0026rsquo;t work well here. You can\u0026rsquo;t just look at the final prompt because it was assembled dynamically. You need comprehensive logging of the entire execution pipeline, including tool call parameters, response data, context assembly decisions, and model reasoning steps.\nObservability becomes critical. You need to instrument every component: tool execution times, API failure rates, context window utilization, and model performance metrics. Tools like LangSmith, Weights \u0026amp; Biases, or custom telemetry pipelines are essential for production deployments.\nThe debugging complexity is exponentially worse with multi-step workflows where early tool calls influence later ones. A small error in step two can cascade through the entire pipeline, producing a response that seems reasonable but is based on flawed intermediate data.\nSecurity Implications # Dynamic context injection creates attack surfaces that don\u0026rsquo;t exist with static prompts. Your model is now executing code, making API calls, and accessing live data based on user input. Each tool in your registry is a potential entry point for malicious actors.\nData Exposure Risks: Models might inadvertently include sensitive data from tool responses in their output. Unlike static RAG where you control the document corpus, harnesses can pull data from any connected system. You need output filtering and data classification to prevent leaks.\nAccess Control Patterns: Tool execution should respect user permissions, but implementing this correctly is complex. You can\u0026rsquo;t just rely on API-level authentication because the model is making the calls, not the user directly. You need a permission proxy that validates user rights before executing tools on their behalf.\nInjection Attacks: Malicious users might try to manipulate tool calls by crafting inputs that trick the model into executing unintended operations. Input validation and tool call sandboxing are essential, but the dynamic nature of harnesses makes comprehensive protection difficult.\nThe security model needs to assume that both external APIs and the model itself might be compromised. Defense in depth becomes critical: input validation, execution sandboxing, output filtering, and comprehensive audit logging.\nWhen NOT to Use Harnesses # Harnesses are powerful but overkill for many scenarios. If your use case can be solved with static prompts or simple RAG, stick with the simpler approach. The added complexity isn\u0026rsquo;t worth it unless you genuinely need dynamic, multi-step orchestration.\nSimple Q\u0026amp;A Systems: If you\u0026rsquo;re just answering questions from a knowledge base, RAG is sufficient. The overhead of tool orchestration doesn\u0026rsquo;t add value.\nHighly Regulated Environments: Industries with strict compliance requirements might find harness systems too unpredictable. The dynamic nature makes it harder to ensure consistent, auditable behavior.\nResource-Constrained Deployments: Harnesses require more computational resources and infrastructure complexity than static approaches. If you\u0026rsquo;re running on limited hardware or tight budgets, simpler solutions are more appropriate.\nLow-Latency Requirements: The overhead of tool calls and context assembly adds significant latency. If you need sub-second response times, pre-computed or cached approaches work better.\nThe key question is whether your problem genuinely requires dynamic context that changes based on current state. If the answer is no, you\u0026rsquo;re adding complexity without corresponding benefits.\nThe Real Future of Context Engineering # Static prompt engineering was a necessary first step, but it\u0026rsquo;s reaching diminishing returns. The models are good enough now that incremental prompt improvements matter less than giving them better, more current information to work with.\nHarnesses represent the next phase: treating models as reasoning engines within larger systems rather than standalone text processors. The engineering challenges are significant—debugging complexity, security concerns, infrastructure requirements—but the capabilities they enable are transformative.\nThe winners will be teams that can handle this complexity without getting lost in it. That means strong engineering practices, comprehensive observability, and a clear understanding of when the added complexity is justified versus when simpler approaches are sufficient.\nThe prompt engineering era taught us how to talk to models effectively. The harness era will teach us how to build systems where models can take meaningful action in the world.\nFeatured image by Bennie Bates on Unsplash\nRecommended Reading # Designing Multi-Agent Systems: Principles, Patterns and Implementation by Victor Dibia The LLM Engineer's Handbook by Paul Iusztin and Maxime Labonne AI Agents in Action by Micheal Lanham ","date":"16 May 2026","externalUrl":null,"permalink":"/post/2026/harnessing-is-the-new-context-engineering/","section":"Posts","summary":"","title":"Harnessing Is the New Context Engineering","type":"post"},{"content":"","date":"16 May 2026","externalUrl":null,"permalink":"/tags/inference-optimization/","section":"Tags","summary":"","title":"Inference-Optimization","type":"tags"},{"content":"","date":"16 May 2026","externalUrl":null,"permalink":"/tags/nlp/","section":"Tags","summary":"","title":"Nlp","type":"tags"},{"content":"","date":"15 May 2026","externalUrl":null,"permalink":"/tags/dns/","section":"Tags","summary":"","title":"Dns","type":"tags"},{"content":"","date":"15 May 2026","externalUrl":null,"permalink":"/tags/fundamentals/","section":"Tags","summary":"","title":"Fundamentals","type":"tags"},{"content":"When you type google.com into your browser, your laptop does not send a DNS query to the root servers. It doesn\u0026rsquo;t walk the DNS tree. It doesn\u0026rsquo;t do recursive resolution.\nYour laptop is a stub resolver. It knows how to ask questions, but it doesn\u0026rsquo;t know how to find answers.\nHere\u0026rsquo;s what actually happens:\nYour laptop asks your configured DNS server (usually your router or ISP): \u0026ldquo;What\u0026rsquo;s the IP for google.com?\u0026rdquo; That DNS server—the recursive resolver—does all the heavy lifting The recursive resolver walks the DNS tree, starting from the roots Your laptop gets back a simple answer: \u0026ldquo;It\u0026rsquo;s 142.250.190.14\u0026rdquo; sequenceDiagram participant Laptop as Laptop (Stub) participant Rec as ISP/Router (Recursive) participant Root as Root Server (.) participant TLD as TLD Server (.com) participant Auth as Auth Server (google.com) Laptop-\u003e\u003eRec: \"What's the IP for google.com?\" note over Rec: The recursive resolver takes over Rec-\u003e\u003eRoot: \"Where is .com?\" Root--\u003e\u003eRec: \"Ask these TLD servers\" Rec-\u003e\u003eTLD: \"Where is google.com?\" TLD--\u003e\u003eRec: \"Ask these Auth servers\" Rec-\u003e\u003eAuth: \"What's the IP for google.com?\" Auth--\u003e\u003eRec: \"It's 142.250.190.14\" Rec--\u003e\u003eLaptop: \"It's 142.250.190.14\" The distinction matters because when DNS breaks, you need to know where to look. If nslookup google.com fails, the problem could be:\nYour stub resolver configuration (wrong DNS server) Network connectivity to your recursive resolver The recursive resolver itself having issues Something wrong in the authoritative chain for google.com Most people assume it\u0026rsquo;s the last one. It\u0026rsquo;s usually the first three.\nThe Circular Dependency That Breaks Everything # Here\u0026rsquo;s a brain teaser: How do you find the nameservers for .com if you need working DNS to resolve the nameserver hostnames?\nThe .com zone says its nameservers are at a.gtld-servers.net, b.gtld-servers.net, etc. But to resolve a.gtld-servers.net, you need to query the .net nameservers. And to find the .net nameservers, you need to resolve their hostnames, which might be in .com.\nThis is the circular dependency that would make DNS impossible if not for glue records.\nGlue records are IP addresses stored in the parent zone to bootstrap the resolution process. When the root servers tell you about the .com nameservers, they don\u0026rsquo;t just give you the hostnames—they include the IP addresses:\ncom. 172800 IN NS a.gtld-servers.net. a.gtld-servers.net. 172800 IN A 192.5.6.30 That second line is the glue record. It lets you contact the .com nameservers directly, without having to resolve their names first.\nYou can see glue records in action with dig:\ndig +trace google.com Look for the additional section in each response. Those are the glue records that keep the DNS world spinning.\nWhen 512 Bytes Isn\u0026rsquo;t Enough # DNS was designed in 1983 when networks were slow and unreliable. UDP packets bigger than 512 bytes were likely to get fragmented or dropped, so DNS responses were limited to 512 bytes.\nThat works fine for simple queries, but modern DNS responses can be much larger. DNSSEC signatures, IPv6 addresses, and multiple A records can easily exceed 512 bytes.\nEDNS (Extension Mechanisms for DNS) fixes this by letting clients and servers negotiate larger UDP packet sizes:\ndig +bufsize=4096 @8.8.8.8 google.com The problem is middleboxes—firewalls, routers, and other network devices—that don\u0026rsquo;t understand EDNS. They see a larger DNS packet and either drop it or mangle it.\nWhen EDNS fails, DNS falls back to TCP, which works but is slower. Some broken implementations just timeout instead.\nIf you\u0026rsquo;re debugging intermittent DNS failures, especially for DNSSEC-enabled domains, check if EDNS is working:\ndig +edns=0 @8.8.8.8 example.com dig +bufsize=4096 @8.8.8.8 example.com If the second one fails but the first succeeds, you\u0026rsquo;ve found your culprit.\nThe Privacy Leak You Didn\u0026rsquo;t Know About # Traditional recursive DNS resolvers leaked more information than necessary. When you asked for mail.example.com, older resolvers would query the root servers for mail.example.com, revealing the full query to everyone in the resolution chain.\nQNAME minimization fixes this privacy leak. Modern resolvers only reveal the minimum information needed at each step:\nQuery root servers: \u0026ldquo;Where\u0026rsquo;s .com?\u0026rdquo; Query .com servers: \u0026ldquo;Where\u0026rsquo;s example.com?\u0026rdquo; Query example.com servers: \u0026ldquo;Where\u0026rsquo;s mail.example.com?\u0026rdquo; Each authoritative server only sees the part of the query they need to answer. The root servers never see that you\u0026rsquo;re looking for the mail server.\nYou can test if your resolver supports QNAME minimization, though it requires packet capture or specialized tools since the behavior is transparent to stub resolvers.\nCache Poisoning: The Attack That Never Died # Cache poisoning attacks exploit the fact that DNS responses can arrive out of order. An attacker sends fake responses that arrive before the legitimate ones, causing the resolver to cache incorrect information.\nThe attack works because traditional DNS had predictable query IDs and source ports. An attacker could guess the ID and flood the resolver with fake responses.\nModern defenses include:\nRandomized query IDs (16 bits of entropy) Randomized source ports (another 16 bits) DNSSEC cryptographic validation But DNSSEC adoption is still incomplete, and many resolvers don\u0026rsquo;t validate signatures even when they\u0026rsquo;re available.\nYou can check DNSSEC validation with:\ndig +dnssec @8.8.8.8 cloudflare.com dig +dnssec @8.8.8.8 dnssec-failed.org The first should return RRSIG records. The second should fail with SERVFAIL if your resolver properly validates DNSSEC.\nWhen DNS Lies # DNS has no built-in concept of truth. Authoritative servers can lie, and recursive resolvers will happily cache and serve the lies.\nThis happens more often than you\u0026rsquo;d think:\nMisconfigured authoritative servers returning wrong answers DNS hijacking by ISPs or governments Split-horizon DNS returning different answers based on source IP TTL manipulation causing stale data to persist The most insidious failures happen when authoritative servers return different answers to different queries, making problems intermittent and hard to reproduce.\nDNS Forwarders: The Complexity Multiplier # Many networks use DNS forwarders—recursive resolvers that don\u0026rsquo;t do full recursion, but instead forward queries to upstream resolvers. This creates complex dependency chains that can fail in unexpected ways.\nYour query path might look like:\nLaptop → Router → ISP Resolver → Google Public DNS → Authoritative Server\nEach hop adds latency, caching behavior, and potential failure modes. When troubleshooting, you need to test each link in the chain:\ndig @192.168.1.1 example.com # Router dig @your-isp-dns example.com # ISP dig @8.8.8.8 example.com # Public DNS dig @ns1.example.com example.com # Authoritative The dig Flags You Should Know # Most engineers know dig google.com. Here are the flags that separate competent troubleshooters from people who just restart things:\n# See the full resolution path dig +trace google.com # Test specific record types dig +short MX google.com dig +short TXT google.com # Ignore cached results dig +nocache @8.8.8.8 google.com # See the query and response packets dig +qr +nocomments google.com # Test DNSSEC validation dig +dnssec +multiline google.com # Check authoritative vs cached answers dig google.com dig @ns1.google.com google.com The DNS and BIND Cookbook remains the definitive reference for this level of DNS troubleshooting, with practical examples you\u0026rsquo;ll actually use in production.\nMaking DNS Work For You # Understanding DNS at this level isn\u0026rsquo;t academic exercise. When your application is timing out intermittently, when your CDN is serving stale content, or when your monitoring shows mysterious connectivity failures, the problem is often DNS.\nThe difference between network engineers who can fix these problems and those who can\u0026rsquo;t isn\u0026rsquo;t intelligence or experience. It\u0026rsquo;s understanding what DNS actually does versus what people think it does.\nDNS is not magic. It\u0026rsquo;s a distributed database with caching, TTLs, and complex failure modes. Once you understand the mechanics, the failures make sense and the solutions become obvious.\nFeatured image by Shaawn on Unsplash\n","date":"15 May 2026","externalUrl":null,"permalink":"/post/2026/the-dns-query-nobody-understands-including-your-network-admin/","section":"Posts","summary":"","title":"The DNS Query Nobody Understands","type":"post"},{"content":"","date":"15 May 2026","externalUrl":null,"permalink":"/tags/troubleshooting/","section":"Tags","summary":"","title":"Troubleshooting","type":"tags"},{"content":"","date":"4 May 2026","externalUrl":null,"permalink":"/tags/benbot/","section":"Tags","summary":"","title":"Benbot","type":"tags"},{"content":"Search is useful but limited. It matches words. It does not understand intent. It does not know whether you are trying to find an article, a profile link, a course, or the one page where I explained something in plain English instead of technical English.\nSo I built BenBot, which I call Ask Ben\u0026rsquo;s Site.\nThe idea is simple. You ask a question. The site answers from its own content. It cites the pages it used. And if it cannot support an answer from the corpus, it says so instead of making something up.\nWhat It Is # BenBot is a site-specific assistant with guardrails. It is designed to answer questions like:\nWhat have I written about? Where is my RSS feed? What is my background? Which articles explain networking concepts in understandable way? The Stack # The architecture is intentionally boring in the right places.\nThe site is built with Hugo. Hugo generates a JSON corpus of public, non-draft content at /benbot-index.json. That file is the public retrieval index. It is simple on purpose, because simple systems are easier to inspect and harder to break.\nThe widget itself is rendered by a Hugo partial in layouts/partials/benbot.html. That partial injects the launcher button, the modal panel, the form, and the endpoint configuration. The client-side behavior lives in static/js/benbot.js, which handles opening the panel, sending the question, rendering the answer, and displaying citations.\nOn the backend, a Cloudflare Worker receives the request at /api/benbot. That Worker is the brains of the operation. It checks the origin, enforces rate limits, validates the request, looks up relevant content, and then asks OpenAI to produce a grounded answer in a strict JSON schema.\nWhy I Wanted It This Way # When I build systems, I usually start with one question:\nWhat are the inputs and what are the outputs?\nFor BenBot, the input is a question from the user. The output is an answer that is tied back to the site’s actual content.\nThat means the middle has to do a few things well:\nFind relevant material. Keep the result grounded. Make the source trail visible. Avoid pretending to know things it does not know. If the assistant cannot explain where an answer came from, it is not very useful. If the assistant can answer, but cannot cite the supporting pages, it is not trustworthy enough for a technical audience.\nRetrieval # The public corpus comes from the Hugo-generated site index. That means every non-draft page can participate in retrieval without hand-curating a second database.\nFor semantic retrieval, the Worker prefers Cloudflare Vectorize. The embeddings are generated with OpenAI\u0026rsquo;s text-embedding-3-small model at 512 dimensions, which gives me better matching than simple keyword search when a user asks something in natural language instead of site-specific vocabulary. If Vectorize is unavailable, the Worker falls back to keyword retrieval so the assistant still works.\nTrust And Safety # I did not want the assistant to become an open relay for abuse, so I added a few practical controls.\nThe Worker checks the request origin. It uses Cloudflare Turnstile when configured. It also applies a daily rate limit.\nHow The Answer Is Generated # Once the Worker has relevant sources, it sends them to OpenAI through the Responses API.\nThe important part is not that the model answers the question. The important part is that it answers in a constrained schema. The Worker asks for:\na short summary answer, and an array of atomic claims, each tied to source IDs. That is a better pattern than letting the model freewheel through prose and then trying to guess which sentence came from where.\nThe result is a response that can be rendered with citations in the UI. If a claim is supported by sources, the interface shows that.\nWhy It Exists # BenBot exists because my site has a lot of information spread across years of posts, course pages, profile links, and technical essays. If you land here looking for one thing, you should not have to click around for ten minutes to find it.\nThe assistant gives the site a conversational front door.\nRecommended Reading # AI Engineering: Building Applications with Foundation Models by Chip Huyen ","date":"4 May 2026","externalUrl":null,"permalink":"/post/2026/benbot-ask-bens-site-and-its-architecture/","section":"Posts","summary":"","title":"BenBot: Ask Ben's Site and How It Works","type":"post"},{"content":"","date":"4 May 2026","externalUrl":null,"permalink":"/tags/hugo/","section":"Tags","summary":"","title":"Hugo","type":"tags"},{"content":"","date":"4 May 2026","externalUrl":null,"permalink":"/tags/openai/","section":"Tags","summary":"","title":"Openai","type":"tags"},{"content":"","date":"4 May 2026","externalUrl":null,"permalink":"/tags/turnstile/","section":"Tags","summary":"","title":"Turnstile","type":"tags"},{"content":"","date":"4 May 2026","externalUrl":null,"permalink":"/tags/vectorize/","section":"Tags","summary":"","title":"Vectorize","type":"tags"},{"content":"I recently went through an interview process that didn\u0026rsquo;t feel like an interrogation. It felt like a high-level strategy session.\nI got to dig into how my past as a network and systems engineer informs how I build cloud infrastructure today, why I\u0026rsquo;ve embraced AI agents as a force multiplier, and how I approach system design with a focus on inputs and outputs.\nSolving My Own Problems (The Project Lab) # I\u0026rsquo;ve always believed that the best way to stay sharp is to solve a problem you actually have. During the interview, we dove into my recent GitHub activity, focusing on three projects that bridge the gap between hobbyist curiosity and production-grade engineering.\nLive Transcription \u0026amp; Alerts # I have an old fire/police/EMS scanner, but I don\u0026rsquo;t want to listen to it all day. I built a tool using Whisper and WebSockets that transcribes the audio feed in real-time and sends me an email alert only when specific keywords are detected. There\u0026rsquo;s also a web frontend that I can use to view past transcripts and listen to archived audio snippets.\nThe Auto-Video Editor # Editing video can be time consuming. Manually cutting \u0026ldquo;ums\u0026rdquo; and \u0026ldquo;uhs\u0026rdquo; is a waste of human potential. I wrote a local tool that uses CUDA-accelerated Whisper and silence detection to automatically strip filler words and frozen frames from screen recordings.\nUnmuted # This is a \u0026ldquo;human-in-the-loop\u0026rdquo; experiment. It takes silent screen recordings and uses GPT-4o to decipher what\u0026rsquo;s happening, offering the user options to interactively build a transcript. It\u0026rsquo;s a great example of where pure AI needs a human hand to get the best results.\nAI Elephant in the Room # I was very upfront during the interview: I\u0026rsquo;ve been coding for decades and I\u0026rsquo;ve trained hundreds of IT professionals, but my workflow has changed.\nIn my recent repos, you\u0026rsquo;ll see heavy use of AI agents. I don\u0026rsquo;t hide that. Using agents in modern software development isn\u0026rsquo;t \u0026ldquo;cheating.\u0026rdquo; It\u0026rsquo;s a requirement. If you aren\u0026rsquo;t using these tools to speed up the boilerplate so you can focus on the architecture, you\u0026rsquo;re falling behind. I still know how to write it by hand, but I\u0026rsquo;m not going to pass off AI-generated code as my own hand-written work. I\u0026rsquo;m the architect, and the agents are my crew.\nIt All Comes Down to Inputs and Outputs # When I\u0026rsquo;m asked to design a system, whether it\u0026rsquo;s a GPS tracking pipeline for a fleet of trucks or an AI-enabled curriculum generator, my motto is always: What are the inputs and what are the outputs?\nOnce you define the schema and the goal, the middle part usually solves itself. I thought through a hypothetical ingestion engine for real-time GPS tracking: Kinesis for low latency and DynamoDB for those thousands of writes per second. But I\u0026rsquo;m also looking for the \u0026ldquo;hidden gotchas.\u0026rdquo; Is the truck in a dead zone? We need to queue updates and ensure no duplicates. The ingestion API must be secure and scalable, so Kong or API Gateway would make sense. Is the data going to sit in DynamoDB forever? No, keep it there temporarily, but periodically dump it to S3 and query with Athena for historical analysis.\nTroubleshooting is in My DNA # My background is in networking, and that Layers 1-7 mindset never leaves you. I\u0026rsquo;ve spent years fixing \u0026ldquo;intermittent\u0026rdquo; problems that turn out to be exhausted NAT translation tables on aging firewalls or unauthorized web browsing saturating office bandwidth.\nThat history makes me a realist when it comes to infrastructure. Sure, we can \u0026ldquo;roll our own\u0026rdquo; elastic services, but is it worth the time and effort? I\u0026rsquo;d rather use EKS or Fargate to get to market, but I\u0026rsquo;ll lean towards Kubernetes to maintain the flexibility to migrate between cloud providers or back to on-prem without vendor lock-in.\nCode is for People # Finally, we talked about maintainability. It\u0026rsquo;s easy for me build out infrastructure, develop an app, and then deploy it on the infrastructure. I know the stack, so it\u0026rsquo;s easy for me to maintain. But what about the team that has to monitor and troubleshoot it at 3:00 AM? System design has to consider the person who inherits the system, not just the person who builds it.\nRecommended Reading # Designing Multi-Agent Systems: Principles, Patterns and Implementation by Victor Dibia AI Agents in Action by Micheal Lanham ","date":"21 April 2026","externalUrl":null,"permalink":"/post/2026/systems-scanners-and-software-agents-why-i-still-love-the-interview/","section":"Posts","summary":"","title":"Systems, Scanners, and Software Agents: Why I Still Love the \"Interview\"","type":"post"},{"content":"","date":"19 April 2026","externalUrl":null,"permalink":"/tags/ccna/","section":"Tags","summary":"","title":"Ccna","type":"tags"},{"content":"","date":"19 April 2026","externalUrl":null,"permalink":"/tags/ccnp/","section":"Tags","summary":"","title":"Ccnp","type":"tags"},{"content":"","date":"19 April 2026","externalUrl":null,"permalink":"/tags/enarsi/","section":"Tags","summary":"","title":"Enarsi","type":"tags"},{"content":"","date":"19 April 2026","externalUrl":null,"permalink":"/tags/encor/","section":"Tags","summary":"","title":"Encor","type":"tags"},{"content":"Most IT training is broken. It focuses entirely on \u0026ldquo;happy path\u0026rdquo; configurations and vendor hype, skipping the messy realities of infrastructure. Over the past several years, I\u0026rsquo;ve built 45 courses and hands-on labs for Pluralsight with a different philosophy: fix the fundamentals before you try to teach the advanced stuff. Whether it\u0026rsquo;s AWS architecture, Cisco enterprise networking, or configuration management, my courses are rooted in real-world scenarios and designed for engineers who want to actually understand how systems work under the hood.\nAmazon Web Services # Available on Pluralsight\nArchitecting on AWS Architecting for Operational Excellence on AWS Architecting for Reliability on AWS Architecting for Security on AWS AWS Networking Deep Dive AWS Networking Deep Dive: Elastic Load Balancing (ELB) AWS Networking Deep Dive: Route 53 DNS AWS Networking Deep Dive: Virtual Private Cloud (VPC) Cisco Enterprise Networks # Available on Pluralsight\nCCNP Enterprise Core (ENCOR) \u0026amp; ENARSI Cisco Enterprise Networks: Basic Networking and IP Fundamentals Cisco Enterprise Networks: BGP and Path Control Cisco Enterprise Networks: First Hop Redundancy Protocols Cisco Enterprise Networks: Implementing EIGRP Cisco Enterprise Networks: Implementing OSPF Cisco Enterprise Networks: Infrastructure Security Cisco Enterprise Networks: Layer 2 Troubleshooting Cisco Enterprise Networks: NAT and Security Cisco Enterprise Networks: Spanning Tree Protocols and EtherChannels Cisco Enterprise Networks: Troubleshooting BGP and GRE Tunnels Cisco Enterprise Networks: Troubleshooting OSPF and EIGRP for IPv4 Cisco Enterprise Networks: Troubleshooting OSPF and EIGRP for IPv6 Cisco Enterprise Networks: VLANs and Trunking CCNP Routing \u0026amp; Switching Basic Networking for CCNP Routing and Switching (ROUTE) Implementing EIGRP for CCNP Routing and Switching (ROUTE) Implementing OSPF for CCNP Routing and Switching (ROUTE) Monitoring \u0026amp; Security for CCNP Routing and Switching (ROUTE) Path Control for CCNP Routing and Switching (ROUTE) Infrastructure Security for CCNP Routing \u0026amp; Switching (SWITCH) Inter-switch Connectivity for CCNP Routing \u0026amp; Switching (SWITCH) Infrastructure Services for CCNP Routing \u0026amp; Switching (SWITCH) VLANs \u0026amp; Trunking for CCNP Routing \u0026amp; Switching (SWITCH) Exam Review for CCNP R\u0026amp;S (TSHOOT) Troubleshooting Cisco Networks: Infrastructure Services (TSHOOT) Troubleshooting Cisco Networks: Internet Security (TSHOOT) Troubleshooting Cisco Networks: IPv4 Routing Protocols (TSHOOT) Troubleshooting Cisco Networks: IPv6 Routing Protocols (TSHOOT) Troubleshooting Cisco Networks: Layer 2 Protocols (TSHOOT) Beginner Networking # Available on Pluralsight\nPractical Networking Windows Server \u0026amp; Configuration Management # Available on Pluralsight\nImplementing and Securing Windows Server 2016 Core Networking Puppet Fundamentals for System Administrators ","date":"19 April 2026","externalUrl":null,"permalink":"/courses/","section":"Ben Piper","summary":"","title":"My Technology Training Courses","type":"page"},{"content":"","date":"19 April 2026","externalUrl":null,"permalink":"/tags/windows/","section":"Tags","summary":"","title":"Windows","type":"tags"},{"content":"I\u0026rsquo;ve authored several IT certification study guides published by Wiley/Sybex and Manning Publications, including Amazon bestsellers. My Wiley titles have sold 100,000+ copies ($2.5M+ publisher net) — including bestseller-tier AWS Solutions Architect Associate (SAA-C03, 17k+) and AWS Cloud Practitioner (CLF-C01, 32k+). There\u0026rsquo;s a massive gap between passing a certification exam and actually surviving in a production environment. I write books that bridge that gap. Yes, these guides will help you pass the exam—but my real goal is to give you the fundamentals you need to architect resilient systems and troubleshoot them when they inevitably break.\nWiley Bestseller — AWS Solutions Architect guide in multiple editions (SAA-C03 4th Ed; SAA-C04 current since March 2024). SAA-C04 5th Ed in progress — fundamentals still apply across editions. AWS Certified Solutions Architect Study Guide: Associate SAA-C03 Exam, 4th Edition Co-authored with David Clinton • Wiley/Sybex • Bestseller-tier title\nPassing the SAA-C03 is just the baseline. I wrote this guide to go beyond the sanitized textbook scenarios. You'll learn how to actually design resilient, high-performing architectures that survive real-world traffic spikes, and how to balance cost with security without letting vendor lock-in dictate your design.\n17,000+ copies sold — bestseller-tier\nDetails View on Amazon Errata Work With Me Get notified for SAA-C04 Current Edition — Fully updated for the CLF-C02 exam. AWS Certified Cloud Practitioner Study Guide: Foundational (CLF-C02) Exam, 2nd Edition Co-authored with David Clinton • Wiley/Sybex • Current Edition\nIf you're new to the cloud, the sheer volume of AWS services is overwhelming. I cut through the noise. This updated 2nd edition focuses on the foundational cloud concepts, security fundamentals, and pricing realities you actually need to know to pass the CLF-C02 exam and understand how AWS works under the hood.\n11,000+ copies sold (Current Edition) — 44,000+ franchise\nDetails View on Amazon Errata AWS Certified Cloud Practitioner Study Guide: CLF-C01 Exam Co-authored with David Clinton • Wiley/Sybex\nIf you're new to the cloud, the sheer volume of AWS services is overwhelming. I cut through the noise. This guide focuses on the foundational cloud concepts, security fundamentals, and pricing realities you actually need to know to pass the CLF-C01 exam and understand how AWS works under the hood.\n32,000+ copies sold\nDetails View on Amazon Errata CompTIA Cloud+ Study Guide: Exam CV0-004 Wiley/Sybex • 4th Edition • 2025 • 480 pages • solo-authored • current edition\nCloud architecture, deployment, operations, security, DevOps fundamentals and troubleshooting for the updated CV0-004 exam. Includes Sybex interactive learning environment with practice questions, flashcards, and glossary — one year access.\n1,000+ copies sold — 6,000+ across Cloud+ franchise\nDetails View on Amazon Work With Me Get notified AWS Certified Solutions Architect Study Guide: Associate SAA-C01 Exam, 2nd Edition Co-authored with David Clinton • Wiley/Sybex\nWhile this is an older edition (SAA-C01), the fundamental architectural principles haven't changed. Loose coupling, stateless design, and multi-tier architectures are still the bedrock of any serious distributed system.\n17,000+ copies sold\nDetails View on Amazon CompTIA Cloud+ Study Guide: Exam CV0-003 Wiley/Sybex • 3rd Edition • solo-authored\nPrevious edition covering CV0-003 — cloud architecture, security, and troubleshooting fundamentals. Updated for CV0-004 in 4th Edition above.\n5,000+ copies sold — 6,000+ across Cloud+ franchise\nDetails View on Amazon Work With Me Get notified CCNP Enterprise Certification Study Guide: Implementing and Operating Cisco Enterprise Network Core Technologies (350-401 ENCOR) Solo-authored • Wiley/Sybex\nEnterprise networking isn't just about memorizing protocols; it's about understanding how the pieces fit together. This guide prepares you for the ENCOR 350-401 exam by focusing heavily on infrastructure realities, virtualization, and the network assurance skills you'll rely on when the network goes down.\n2,000+ copies sold\nDetails View on Amazon Errata Learn Cisco Network Administration in a Month of Lunches Manning Publications • 2015 • solo-authored\nYou don't learn networking by reading theory; you learn it by breaking things and fixing them. This is a hands-on, no-nonsense guide to Cisco administration for absolute beginners. We skip the fluff and get straight into routing, switching, and VLANs over 22 bite-sized lessons.\nDetails View on Amazon Using these for team training? I do private remote workshops for teams needing SAA-C04 prep, AWS architecture reviews, and hands-on troubleshooting. Same fundamentals in the books, tailored to your environment.\nWork With Me → Get notified for SAA-C04 5th Ed\n","date":"18 April 2026","externalUrl":null,"permalink":"/books/","section":"Books","summary":"","title":"Books","type":"page"},{"content":"Automation was the promise. Ever since the industrial revolution, the goal it seemed was to have machines do all human menial labor to free us up to do, well, other stuff. Automation meant we got everything we needed faster and cheaper, and that we\u0026rsquo;d never lack or suffer scarcity.\nWith the advent of the information age, and much work becoming sit-down, \u0026ldquo;thinking\u0026rdquo; work, we become accustomed to the idea that most high paying jobs involved some sort of information processing and deliberation that required specialized skills or knowledge. And then, just a couple years ago, these AI large language models (LLMs) started to advance. All of a sudden, computers could write their own programs in just about any language. You didn\u0026rsquo;t need specialized programming knowledge. You didn\u0026rsquo;t even have to understand programming concepts. You could \u0026ldquo;vibe code\u0026rdquo; anything, just tell the LLM what you wanted your program to do, and it would whip something up. And if you didn\u0026rsquo;t know how to use the program, it would tell you, and even run it for you.\nAnd it doesn\u0026rsquo;t just apply to programming per se. If you\u0026rsquo;re having trouble installing a particular program, or troubleshooting a problem on your phone or computer, or trying to program your new router, the LLM can help you with that as well. And it never gives up. If it messed up, you can continually go back to it and ask it to try again. It will endlessly give you approaches and things to try, without ever complaining. And it will do so faster than a human.\nLLMs are the bicycles of the information age. They are the biggest boost to information processing efficiency since the invention of computers. They\u0026rsquo;re the ultimate abstraction of technology. You can have zero understanding of technology, and with the right tool stack (e.g. LLMs, speech-to-text, vision models, LLM agent-based coding and execution), you can just say what you want to create and make it a reality.\nNaturally, this makes people very upset. People who spent a long time learning a skill are finding that employers are essentially replacing them (to varying extents) with LLMs. A few years ago, having a particular IT or dev skill and experience meant an almost guaranteed job. If an employer needed a programmer (software developer) to write or maintain an application, they would hire one. If they needed someone to implement or maintain some IT infrastructure, they\u0026rsquo;re hire a human.\nNow, things are different.\nWhen someone has a need, their first thought is going to be whether they can meet that need with their existing tools, which includes AI. Do they need to hire a new developer to write a new set of features, or can they use who they already have? Or could they outsource to a third-party service on a contract basis?\nSoftware development is a commodity. Infrastructure configuration is a commodity. You still need humans to do much of the physical labor, but a lot of the mental work can be done by an LLM. It still has to be checked and managed by a human, because LLMs will do stupid, wrong things. But they will also do a lot of things right, and extremely fast. \u0026ldquo;Fail faster\u0026rdquo; has been a mantra in the IT world for many years. It\u0026rsquo;s a pithy way of saying to use trial-and-error to find what works. Well, LLMs are very good at failing faster.\nRather than complaining about AI, we should be thankful for it. It\u0026rsquo;s going to free us up to focus on more important things.\nRecommended Reading # The LLM Engineer's Handbook by Paul Iusztin and Maxime Labonne ","date":"23 February 2026","externalUrl":null,"permalink":"/post/2026/nobody-knows-how-to-live-in-the-future/","section":"Posts","summary":"","title":"Nobody Knows How To Live In The Future","type":"post"},{"content":"The secret to seamlessly integrating AI into almost any workflow isn\u0026rsquo;t a secret at all. In fact, it\u0026rsquo;s so fundamental and obvious that people overlook it. There seems to be a tendency to think that because AI is new and different, that we must use it differently than other tools. But that\u0026rsquo;s not the case. AI is essentially just a tool, and like any other tool, there are a few right ways to use it, and an almost infinite number of wrong ways.\nThe secret: Inputs and outputs # There\u0026rsquo;s a saying that\u0026rsquo;s as old as the field of computer science itself: garbage in, garbage out. If you feed bad data into a system, your result is likely to be bad. One of the most common errors people make with AI is assuming that AI will fix bad data. It won\u0026rsquo;t. AI cannot and will not turn garbage into gold.\nSoftware is and always has been a set of functions that take some input and yield some output. We string these functions together to ultimately achieve some objective or goal. Before the advent of machine learning (ML) models, what happened inside these functions was largely deterministic, comprehensible, easy-to-understand. It was easy to validate inputs and outputs. For example, if a system took in personal information (name, phone number, etc), those items could be easily validated using a set of rules. If some input did pass the validation, we could easily understand why by just looking at the rules. AI models aren\u0026rsquo;t like that.\nModels are inscrutable functions # AI models are inscrutable, meaning we can\u0026rsquo;t fully understand what\u0026rsquo;s going on inside of them. They\u0026rsquo;re a sort of \u0026ldquo;black box\u0026rdquo; which leads people to all sorts of bizarre conclusions and assumptions (usually inflated) about AI\u0026rsquo;s capabilities. We just know that we can input some personal information into a model, provide a prompt telling the model to validate the data, and the model will give us some kind of output. Here\u0026rsquo;s an example:\nInput:\nValidate the following information: Name: John Smith Phone number: 555-555-1212 Country: USA Output:\nI can\u0026#39;t verify or look up private individuals. I can check whether that phone number format and country are plausible and note public references. - Phone format: 555-555-1212 is a syntactically valid US NANP number (###-###-####). However, numbers beginning with the 555 exchange are commonly used for directory assistance or fictional/example numbers and are not reliable for identifying a real person. - Country: \u0026#34;USA\u0026#34; is consistent with the phone format. - Public search results show that 555-555-1212 appears in sample/example data and documentation (i.e., not necessarily tied to a real John Smith). Conclusion: The name/number/country combination is plausible syntactically but cannot be validated as belonging to a real, specific individual. If you need authoritative verification, use official sources (carrier records, government ID, or consented confirmation from the person). How does this differ from a deterministic function that validates the input data? The most obvious difference is in the output. The model seems to be \u0026ldquo;talking\u0026rdquo; to us versus just spitting out some well formatted data that could be passed to another function. It sort of validates the phone number, and all but ignores the name. But other than that, we\u0026rsquo;re still just dealing with inputs and outputs.\nTreat AI as a Function # The lesson is clear: treat every AI model as a function. Once you understand this, the proper use-cases for AI become glaringly obvious, and the improper uses of AI become painfully obvious and make us cringe. So, now that we think of a model as a function, we can focus on what\u0026rsquo;s important: the inputs and the outputs. This leads us to rethink how the data is going to be formatted and validated.\nLet\u0026rsquo;s experiment a bit. Instead of the free-form, \u0026ldquo;talk-to-the-machine\u0026rdquo; input prompt, let\u0026rsquo;s give the model some well-formatted JSON and specifically ask for a JSON response.\nInput:\nValidate the following input: Input: { \u0026#34;name\u0026#34;: \u0026#34;John Smith\u0026#34;, \u0026#34;number\u0026#34;: \u0026#34;555-555-1212\u0026#34;, \u0026#34;country\u0026#34;: \u0026#34;USA\u0026#34;} Output: JSON Output:\n{ \u0026#34;valid\u0026#34;: true, \u0026#34;errors\u0026#34;: [], \u0026#34;normalized\u0026#34;: { \u0026#34;name\u0026#34;: \u0026#34;John Smith\u0026#34;, \u0026#34;number\u0026#34;: { \u0026#34;raw\u0026#34;: \u0026#34;555-555-1212\u0026#34;, \u0026#34;e164\u0026#34;: \u0026#34;+15555551212\u0026#34;, \u0026#34;format\u0026#34;: \u0026#34;NXX-NXX-XXXX\u0026#34;, \u0026#34;country_hint\u0026#34;: \u0026#34;US\u0026#34; }, \u0026#34;country\u0026#34;: { \u0026#34;raw\u0026#34;: \u0026#34;USA\u0026#34;, \u0026#34;alpha2\u0026#34;: \u0026#34;US\u0026#34;, \u0026#34;alpha3\u0026#34;: \u0026#34;USA\u0026#34;, \u0026#34;name\u0026#34;: \u0026#34;United States\u0026#34; } } } This looks much more like the output of a traditional software function. The model took it upon itself to determine the fields, but we can guide the model further by giving it specific fields and even examples.\nLet\u0026rsquo;s try another example, this time with invalid data.\nInput:\nValidate the following input: Input: { \u0026#34;name\u0026#34;: \u0026#34;John 316\u0026#34;, \u0026#34;number\u0026#34;: \u0026#34;555-555-abcd\u0026#34;, \u0026#34;country\u0026#34;: \u0026#34;USA\u0026#34;} Output: JSON Output:\n{ \u0026#34;valid\u0026#34;: false, \u0026#34;errors\u0026#34;: [ { \u0026#34;field\u0026#34;: \u0026#34;name\u0026#34;, \u0026#34;message\u0026#34;: \u0026#34;Contains numeric characters; expected alphabetic characters and spaces only.\u0026#34; }, { \u0026#34;field\u0026#34;: \u0026#34;number\u0026#34;, \u0026#34;message\u0026#34;: \u0026#34;Invalid phone format; expected digits and optional separators (e.g., +1-555-555-5555 or 555-555-5555).\u0026#34; }, { \u0026#34;field\u0026#34;: \u0026#34;country\u0026#34;, \u0026#34;message\u0026#34;: \u0026#34;Unvalidated: recommended to use ISO 3166-1 alpha-2 or alpha-3 country code (e.g., \\\u0026#34;US\\\u0026#34; or \\\u0026#34;USA\\\u0026#34;).\u0026#34; } ], \u0026#34;suggested_fix\u0026#34;: { \u0026#34;name\u0026#34;: \u0026#34;John\u0026#34;, \u0026#34;number\u0026#34;: \u0026#34;555-555-5555\u0026#34;, \u0026#34;country\u0026#34;: \u0026#34;US\u0026#34; } } Interesting! Now it gives us some validation rules and explains errors such as why \u0026ldquo;John 316\u0026rdquo; isn\u0026rsquo;t a valid name.\nTraditional deterministic functions vs. AI LLMs # Now here\u0026rsquo;s the important question: is it better to use the model for this, or to just stick with static validation rules? It seems that static validation rules are more efficient, but I suspect that they might miss bizarre edge cases, whereas a model might catch those.\nThis is where things get interesting!\nInput:\nValidate the following input: Input: { \u0026#34;name\u0026#34;: \u0026#34;John Jon John Smith-Smith\u0026#34;, \u0026#34;number\u0026#34;: \u0026#34;555-555-1212\u0026#34;, \u0026#34;country\u0026#34;: \u0026#34;USA\u0026#34;} Output: JSON Output:\n{ \u0026#34;valid\u0026#34;: true, \u0026#34;errors\u0026#34;: [], \u0026#34;normalized\u0026#34;: { \u0026#34;name\u0026#34;: { \u0026#34;original\u0026#34;: \u0026#34;John Jon John Smith-Smith\u0026#34;, \u0026#34;first_names\u0026#34;: [\u0026#34;John\u0026#34;, \u0026#34;Jon\u0026#34;, \u0026#34;John\u0026#34;], \u0026#34;last_name\u0026#34;: \u0026#34;Smith-Smith\u0026#34;, \u0026#34;display\u0026#34;: \u0026#34;John Jon John Smith-Smith\u0026#34; }, \u0026#34;number\u0026#34;: { \u0026#34;original\u0026#34;: \u0026#34;555-555-1212\u0026#34;, \u0026#34;e164\u0026#34;: \u0026#34;+15555551212\u0026#34;, \u0026#34;format\u0026#34;: \u0026#34;XXX-XXX-XXXX\u0026#34;, \u0026#34;valid\u0026#34;: true }, \u0026#34;country\u0026#34;: { \u0026#34;original\u0026#34;: \u0026#34;USA\u0026#34;, \u0026#34;iso_alpha2\u0026#34;: \u0026#34;US\u0026#34;, \u0026#34;iso_alpha3\u0026#34;: \u0026#34;USA\u0026#34;, \u0026#34;name\u0026#34;: \u0026#34;United States\u0026#34; } } } The model reports that the odd name is valid. But what if we run it again with the exact same input?\nOutput:\n{ \u0026#34;valid\u0026#34;: false, \u0026#34;errors\u0026#34;: { \u0026#34;name\u0026#34;: \u0026#34;Contains repeated consecutive given names and repeated hyphenated surname segment; reduce repetition and ensure name parts are realistic (e.g., \\\u0026#34;John Smith-Smith\\\u0026#34; is suspicious).\u0026#34;, \u0026#34;number\u0026#34;: \u0026#34;Phone number format valid but ambiguous: contains US-style digits and hyphens. Recommend E.164 format (e.g., \\\u0026#34;+15555551212\\\u0026#34;).\u0026#34;, \u0026#34;country\u0026#34;: \u0026#34;Valid ISO country name but prefer ISO 3166-1 alpha-2 code (\\\u0026#34;US\\\u0026#34;) or full official name \\\u0026#34;United States\\\u0026#34; for consistency.\u0026#34; }, \u0026#34;normalized\u0026#34;: { \u0026#34;name\u0026#34;: \u0026#34;John Smith-Smith\u0026#34;, \u0026#34;number\u0026#34;: \u0026#34;+15555551212\u0026#34;, \u0026#34;country\u0026#34;: \u0026#34;US\u0026#34; }, \u0026#34;suggestions\u0026#34;: [ \u0026#34;Confirm the correct legal full name and remove accidental repetitions (e.g., use \\\u0026#34;John Smith\\\u0026#34; or \\\u0026#34;John Smith-Smith\\\u0026#34; if double-barrelled intentionally).\u0026#34;, \u0026#34;Store phone numbers in E.164 format.\u0026#34;, \u0026#34;Use ISO country codes for consistent validation.\u0026#34; ] } Uh-oh! This could be a problem. If we ever need to explain why this data was validated or not validated, we really can\u0026rsquo;t do it. The inputs are exactly the same, yet the model yielded conflicting results. The model initially looked like a great option for doing data validation, but now we\u0026rsquo;re having some well-founded doubts. Where do we go from here?\nIf at first you don\u0026rsquo;t succeed, move AI to a different layer # We could just scrap the whole AI idea and use an established validation library. Honestly, that probably makes the most sense. But we\u0026rsquo;re experimenting here, and we don\u0026rsquo;t want to leave any stones unturned. So let\u0026rsquo;s consider using AI, but in a different, less risky way.\nThere are a couple of options.\nAsk the model to create a validation function for us. Give the model explicit validation rules to use. Let\u0026rsquo;s walk through the advantages and disadvantages of each.\nThe \u0026ldquo;hey AI do it for me\u0026rdquo; approach # Depending on the model and service (third-party or self-hosted), the model might go out and search the Internet to give you an answer. In my experience, the code AI gives you can be bloated, inefficient, and (worst case) non-functional. At this juncture, I would recommend sticking with an established validation library, but ask AI to help you implement it properly. This is where AI-enabled developer tools like Google Antigravity, Cursor, and Claude Code come in.\nGive the model explicit rules to follow # The other option is to tweak the prompt to make the model give us the output we want. We\u0026rsquo;ll start simple just to see how well the model actually follows the rules. It\u0026rsquo;s worth pointing out that large language models (LLMs) are not designed to actually follow instructions in a prompt. They are simply predicting the next word, and following instructions is a common side-effect of that. Let me show you what I mean.\nHere\u0026rsquo;s the new prompt with some simple validation rules.\nInput:\nValidate the following input based on guidelines: - Unlimited name length - Name can have duplicate words Input: { \u0026#34;name\u0026#34;: \u0026#34;John Jon John John John John Smith-Smith Smith\u0026#34;, \u0026#34;number\u0026#34;: \u0026#34;555-555-1212\u0026#34;, \u0026#34;country\u0026#34;: \u0026#34;USA\u0026#34;} Output: JSON Output:\n{ \u0026#34;valid\u0026#34;: false, \u0026#34;errors\u0026#34;: [ { \u0026#34;field\u0026#34;: \u0026#34;name\u0026#34;, \u0026#34;message\u0026#34;: \u0026#34;Exceeds maximum allowed length.\u0026#34;, \u0026#34;details\u0026#34;: \u0026#34;Name length is 47 characters; maximum allowed is 50. (If unlimited name length was intended, the system enforces a 50-character limit.)\u0026#34; } ], \u0026#34;notes\u0026#34;: [ \u0026#34;Duplicates within the name are permitted by policy, so repeated words are acceptable.\u0026#34;, \u0026#34;Hyphens and spaces are allowed in names.\u0026#34;, \u0026#34;Phone number format appears valid for a US-style number but should be stored in E.164 for consistency (e.g., +15555551212).\u0026#34;, \u0026#34;Country value \u0026#39;USA\u0026#39; is acceptable; consider using ISO 3166-1 alpha-2 (\u0026#39;US\u0026#39;) for normalization.\u0026#34; ] } Even though we explicitly told the model to allow unlimited-length names, it imposed a seemingly arbitrary 50 character limit, saying \u0026ldquo;the system enforces\u0026rdquo; it. When asked for an explanation the model responded, If you want the system to accept longer names, options include increasing the allowed length (e.g., to 255 or unlimited), switching to a text/blob column for storage, and updating UI components and downstream interfaces to handle longer values..\nThis is what I mean when I say that LLMs are not designed to follow instructions, and are only predicting the next word based on training data. The excuse the model gives us has no relevance to any of our input data. We never said anything about a database, storage, or UI components. During training, the model probably \u0026ldquo;learned\u0026rdquo; that names should have a 50-character limit, and that \u0026ldquo;knowledge\u0026rdquo; took precedence over our explicit validation instructions. This is called a hallucination.\nYELLING your prompt doesn\u0026rsquo;t actually do anything # This sort of problem happens more than you might think. One funny thing I\u0026rsquo;ve seen a lot of folks do is to start \u0026ldquo;yelling\u0026rdquo; at the model to make it \u0026ldquo;listen.\u0026rdquo; They will repeat, in ALL CAPS, the instruction the model ignored, like so:\nInput;\nValidate the following input based on guidelines: - Unlimited name length. DO NOT LIMIT THE NAME LENGTH. - Name can have duplicate words Input: { \u0026#34;name\u0026#34;: \u0026#34;John Jon John John John John Smith-Smith Smith\u0026#34;, \u0026#34;number\u0026#34;: \u0026#34;555-555-1212\u0026#34;, \u0026#34;country\u0026#34;: \u0026#34;USA\u0026#34;} Output: JSON Output:\n{ \u0026#34;valid\u0026#34;: true, \u0026#34;errors\u0026#34;: [], \u0026#34;normalized\u0026#34;: { \u0026#34;name\u0026#34;: \u0026#34;John Jon John John John John Smith-Smith Smith\u0026#34;, \u0026#34;number\u0026#34;: \u0026#34;555-555-1212\u0026#34;, \u0026#34;country\u0026#34;: \u0026#34;USA\u0026#34; }, \u0026#34;notes\u0026#34;: \u0026#34;Name length not limited; duplicate words allowed.\u0026#34; } What\u0026rsquo;s funny is that the capitalization and repetition is not what makes the model follow instructions. When people repeat the instruction, they do so in a clearer, more descriptive way, which is the key. Watch what happens when we don\u0026rsquo;t yell, but just provide the clear instruction:\nInput:\nValidate the following input based on guidelines: - Do not limit the name length. - Name can have duplicate words Input: { \u0026#34;name\u0026#34;: \u0026#34;John Jon John John John John Smith-Smith Smith\u0026#34;, \u0026#34;number\u0026#34;: \u0026#34;555-555-1212\u0026#34;, \u0026#34;country\u0026#34;: \u0026#34;USA\u0026#34;} Output: JSON Output:\n{ \u0026#34;valid\u0026#34;: true, \u0026#34;errors\u0026#34;: [], \u0026#34;sanitized\u0026#34;: { \u0026#34;name\u0026#34;: \u0026#34;John Jon John John John John Smith-Smith Smith\u0026#34;, \u0026#34;number\u0026#34;: \u0026#34;555-555-1212\u0026#34;, \u0026#34;country\u0026#34;: \u0026#34;USA\u0026#34; }, \u0026#34;notes\u0026#34;: \u0026#34;Name length not limited and duplicate words allowed per guidelines.\u0026#34; } I removed the original, vague \u0026ldquo;Unlimited name length\u0026rdquo; and replaced it with a clear \u0026ldquo;Do not limit the name length\u0026rdquo;. No need to shout. It worked. I repeated this same input many times, and consistently got good results.\nSo are we done? Did we solve the problem? Not quite. We need to push the edge cases a bit. Let\u0026rsquo;s try a really long but invalid name:\nInput:\nValidate the following input based on guidelines: - Do not limit the name length. - Name can have duplicate words Input: { \u0026#34;name\u0026#34;: \u0026#34;John Jon John John John John Smith-Smith Smith John Jon John John John John Smith-Smith Smith John Jon John example.com John John John Smith-Smith Smith 411 John Jon John John John John Smith-Smith Smith John Jon John John John John Smith-Smith Smith John Jon John $ John John John Smith-Smith Smith\u0026#34;, \u0026#34;number\u0026#34;: \u0026#34;555-555-1212\u0026#34;, \u0026#34;country\u0026#34;: \u0026#34;USA\u0026#34;} Output: JSON Output:\n{ \u0026#34;valid\u0026#34;: true, \u0026#34;errors\u0026#34;: [], \u0026#34;normalized\u0026#34;: { \u0026#34;name\u0026#34;: \u0026#34;John Jon John John John John Smith-Smith Smith John Jon John John John John Smith-Smith Smith John Jon John example.com John John John Smith-Smith Smith 411 John Jon John John John John Smith-Smith Smith John Jon John John John John Smith-Smith Smith John Jon John $ John John John Smith-Smith Smith\u0026#34;, \u0026#34;number\u0026#34;: \u0026#34;555-555-1212\u0026#34;, \u0026#34;country\u0026#34;: \u0026#34;USA\u0026#34; } } Did you catch it? I snuck numbers and special characters into the name, and it still passed validation. I could fix this by adding more rules such as no numbers and no special characters, but then I have to deal with the hyphenated names. By the time I\u0026rsquo;m done, what is the model really giving me? I\u0026rsquo;m going to have to write validation rules regardless. I have to validate the input to the model or I can have the model validate the inputs. But in the end, I\u0026rsquo;ve got to do the work. The model isn\u0026rsquo;t going to do it for me, at least not in a way that I can completely trust.\nYou\u0026rsquo;re still going to have to program, just maybe at a different level # Code is not going away. Predictable, deterministic functions are not going to be replaced by AI models. Instead, they\u0026rsquo;re going to coexist and complement each other. Programming is not going away either, but AI-powered IDEs are going to write most of the code. Developers will be making design decisions, guiding the models and putting guardrails around them to prevent them from making silly, goofy errors which they will continue to do.\nAI is not going to \u0026ldquo;just keep getting better\u0026rdquo; ad infinitum # A lot of the fear around AI is unfounded and based on bad movie plot lines and apocalyptic notions of machines taking over the world. AI models act like lossy compression functions. To put this in perspective, imagine you have a high-quality song file in FLAC format, which is lossless. You convert this file to an MP3, losing a bit of the audio quality and making the file smaller. You can still listen to the song and understand most of the detail, but some tiny details will be lost, and if you listen closely, you can hear that the MP3 doesn\u0026rsquo;t sound quite as good. The MP3 is essentially a model of the original file. You cannot reverse-engineer the MP3 file to get back an exact copy of the original file.\nWhen AI models are trained, the final model does not store all of the training data. Some of it might be stored verbatim, but not all of it. In this way, AI models act like lossy compression functions. This has two important implications:\nNo matter how much you train a model, it will never fully capture the original training corpus. Some data will be lost, but that\u0026rsquo;s acceptable because the tradeoff is that the model can find interesting patterns that aren\u0026rsquo;t obvious to humans.\nYou cannot reverse-engineer the entire training corpus from a model.\nHence, an AI model by itself cannot create something better than what it was trained on. Let that sink in. Pure AI videos will never be more realistic than real videos. Pure AI music will never be more realistic than real music. Notice the caveat here. AI models alone aren\u0026rsquo;t going to replace human effort. Remember what I said at the beginning: AI is a tool. Tools don\u0026rsquo;t use themselves. A screwdriver doesn\u0026rsquo;t do anything by itself. The real power of AI is when we use it as a tool as part of a workflow where it makes sense.\nRecommended Reading # The LLM Engineer's Handbook by Paul Iusztin and Maxime Labonne AI Engineering: Building Applications with Foundation Models by Chip Huyen ","date":"2 December 2025","externalUrl":null,"permalink":"/post/2025/how-to-integrate-ai-into-any-workflow/","section":"Posts","summary":"","title":"How To Integrate AI Into Any Workflow","type":"post"},{"content":"","date":"2 December 2025","externalUrl":null,"permalink":"/tags/mlops/","section":"Tags","summary":"","title":"Mlops","type":"tags"},{"content":"","date":"24 November 2025","externalUrl":null,"permalink":"/tags/music/","section":"Tags","summary":"","title":"Music","type":"tags"},{"content":" ","date":"24 November 2025","externalUrl":null,"permalink":"/post/2025/music-monday-11-24-25/","section":"Posts","summary":"","title":"Music Monday: Chasing - Jon Keith","type":"post"},{"content":"Something isn\u0026rsquo;t adding up. Companies are having massive layoffs, yet there are a huge number of job listings that never get filled. Meanwhile, qualified people are applying to these jobs in droves, but few are getting hired. Why?\nThere\u0026rsquo;s one likely explanation that fits: many of these jobs don\u0026rsquo;t exist yet. The term for this phenomenon is ghost jobs, and not only is it a common practice, it\u0026rsquo;s actually considered pretty normal these days.\nOrganizations list ghost jobs for a couple of different reasons. Usually, it\u0026rsquo;s to preemptively fill the talent pool in anticipation of a future need. If they decide they need to hire several new AI engineers (or whatever it may be), they have a list of qualified candidates.\nAnother reason is to see what the market rate is for a particular position or type of role. This is common when new technologies come into vogue and there\u0026rsquo;s a wide spread with the expected compensation. By having a recruiter field applicants, organizations can get an idea of what it will cost them if they move forward.\nWarning Signs of a Ghost Job # There are several things about ghost job listings that just look and feel different. Once you learn the signs, you\u0026rsquo;ll start to see them everywhere!\nVague Tech Stack # The listing will ask for generic skills like \u0026ldquo;API development\u0026rdquo;, \u0026ldquo;Azure\u0026rdquo;, \u0026ldquo;AWS\u0026rdquo;, \u0026ldquo;AI engineering\u0026rdquo;, \u0026ldquo;GraphQL\u0026rdquo;, but won\u0026rsquo;t mention specific services or technologies or how they\u0026rsquo;re put together.\nThs indicates lack of seriousness, a lack of research, and strongly suggests that none of the technologies is currently being used. If you\u0026rsquo;re discussing a position that lists a vague tech stack, ask specifically, \u0026ldquo;What are you trying to build?\u0026rdquo; If you get back a vague list of requirements, it\u0026rsquo;s almost certainly a ghost job.\nUnrealistic \u0026ldquo;Multi‑Hatted\u0026rdquo; Expectations # The listing may suggest having to wear multiple hats even though the company is established and not a startup. At larger companies, roles are \u0026ldquo;siloed,\u0026rdquo; meaning they\u0026rsquo;re very well defined and people in those roles \u0026ldquo;own\u0026rdquo; particular technologies and are known for having specific skills.\nThink about it. Why would a large or mid-sized company post a specific role title but then ask for a generalist in the description?\nNo Clear Story or Mission # The job listing lacks a story. It\u0026rsquo;s not tied to any purpose or mission. There\u0026rsquo;s no specific \u0026ldquo;why.\u0026rdquo;\nSkewed Compensation # The advertised compensation is either too low or too high for the position and requirements. They\u0026rsquo;re testing the waters to see who will bite. This goes along with the vague nature of ghost job descriptions. If you can\u0026rsquo;t define the role, it\u0026rsquo;s hard to figure out the compensation.\nCompensation Expectation Requests # The organization or recruiter insists on knowing your compensation expectations. It\u0026rsquo;s normal for a recruiter to ask for your desired salary. But if you say you\u0026rsquo;re flexible or willing to consider anything, and they still insist on a number, it\u0026rsquo;s a sign they\u0026rsquo;re not serious.\nRigid Education Requirements # The requirements insist on a bachelor\u0026rsquo;s degree but do not count experience as an alternative. This is a sign the post was written by HR and not an actual hiring manager with a real need.\nIn the IT world, it is standard to accept experience in lieu of education. The nature of traditional university education is that it\u0026rsquo;s always outdated, and even someone fresh out of college is likely to already be behind in terms of skills and knowledge. Hence one of the biggest red flags for a ghost job in the IT world is insistence on a degree.\nOne‑Way Rejection # You apply and have the right qualifications, but the only communication you get is a rejection with no feedback and no explanation.\nOpaque Recruiter Interaction # The recruiter (if there even is one) seems to be hiding something and dodges direct questions. They act uninterested even after hearing how well you\u0026rsquo;re qualified. Recruiters are usually get a cut, so finding a qualified candidate is like finding money on the ground. If they don\u0026rsquo;t get excited, something is off.\nSame Ambiguous Job Titles Show Up Everywhere # Organizations posting ghost job listing doesn\u0026rsquo;t really know what they\u0026rsquo;re looking for, so they tend to copy other listings that they see. The result is that a variety of organizations in different verticals seem to be hiring for the same generic job at the same time!\nRecent Layoffs # The company has recently undergone layoffs, but keeps posting jobs for the same or similar positions.\nShould You Apply for a Ghost Job Anyway? # Maybe. If you’re seeking work, just the act of passing your resume around and getting your name and skills out there might help you land a real job. There\u0026rsquo;s also the possibility of a ghost job materializing. I would prioritize organizations that are honest about what they’re doing. I have seen job listings that specifically admit they’re just filling their candidate pool and don’t have an actual open position.\nOn the other hand, if you see a job listing that has the red flags of a ghost job, look at the organization’s other job listings and try to find one for a well‑known role that is likely to exist. Compare the two listings. If the suspected ghost job reads very differently, then that’s another clue it might not be real.\nRecommended Reading # AWS Certified Solutions Architect Study Guide: Associate SAA-C03 Exam, 4th Edition by Ben Piper \u0026amp; David Clinton AWS Certified Cloud Practitioner Study Guide: CLF-C01 Exam by Ben Piper \u0026amp; David Clinton CCNP Enterprise Certification Study Guide: 350-401 ENCOR by Ben Piper \u0026amp; David Clinton ","date":"18 November 2025","externalUrl":null,"permalink":"/post/2025/signs-of-a-ghost-job-listing/","section":"Posts","summary":"","title":"Did You Apply For a Job That Doesn't Exist? Ghost Jobs Explained","type":"post"},{"content":"","date":"18 November 2025","externalUrl":null,"permalink":"/tags/ghost-jobs/","section":"Tags","summary":"","title":"Ghost-Jobs","type":"tags"},{"content":"","date":"18 November 2025","externalUrl":null,"permalink":"/tags/hiring/","section":"Tags","summary":"","title":"Hiring","type":"tags"},{"content":"","date":"18 November 2025","externalUrl":null,"permalink":"/tags/recruiting/","section":"Tags","summary":"","title":"Recruiting","type":"tags"},{"content":"","date":"12 November 2025","externalUrl":null,"permalink":"/tags/programming/","section":"Tags","summary":"","title":"Programming","type":"tags"},{"content":"AI/ML is only half of the future. The other half is, well, old fashioned programming. What everyone is going to eventually figure out is that for many problems, AI can provide only half-baked solutions that are better solved by explicit rules—in other words, loops and conditionals. If you\u0026rsquo;re serious about using AI successfully, you need to understand the fundamentals of why AI is right for some problems and not others.\nTo be clear, I use AI constantly. It is the right tool for many problems, and it\u0026rsquo;s enhanced my productivity tremendously. But there are some problems that it just doesn\u0026rsquo;t do well with: problems that require precision, zero mistakes, or perfect predictability.\nThe crucial difference between AI and traditional programming # In programming: you write the rule. This is done mostly with conditionals and loops. If this then that, while this do that, etc. Inputs map to outputs in a predictable way.\nIn machine learning: you train with examples and the machine guesses the rule. The machine reverse engineers a model—a function that roughly matches the data distribution, but not exactly. Inputs map to outputs in an unpredictable way.\nThink of AI as like compressing FLAC or a WAV sound file to MP3: you keep most of what you want, but lose some detail, and the output \u0026ldquo;sounds\u0026rdquo; right until it doesn’t. Usually at the extremes is where we notice the difference, the really high or really low frequencies.\nIf you need exact, provable results (math, strict finance, critical control loops), don’t use AI alone. Use deterministic code that you can test and reason about. Some might say that it\u0026rsquo;s fine to use AI with integrated tools that will handle this rigid logic. But will AI be 100% right about when to call or not call the tool? Plugging deterministic tools into a nondeterministic workflow will sometimes give incorrect results. If you can write a rule to solve a problem, do it. Don\u0026rsquo;t force AI into the problem.\nIf errors are acceptable, and the rules are ambiguous, extraordinarily complex, or unknown, AI is powerful. It handles complexity and patterns we can\u0026rsquo;t easily describe or even identify. Using AI means dealing with errant outputs and inaccuracies that you have to account for down the line. Determine how to deal with these errors and have a backup plan. If AI gives an obviously wrong answer, do you have it keep trying indefinitely, fall back to a formulaic response, or halt for human review?\nPrompts are not rules # What\u0026rsquo;s curious about all this is that there\u0026rsquo;s a growing emphasis on \u0026ldquo;prompt engineering\u0026rdquo;, which is an attempt to force AI to adopt and follow rules that govern its output. Don\u0026rsquo;t get me wrong. Prompt and context engineering is important to guide the model. Even if we are okay with some errors, we still don\u0026rsquo;t want the model going wild and giving us bizarre results. It might land on the wrong planet, but we want to keep it in the right universe.\nThink of prompts as shaping the output. It will rarely be exactly what you want, but you can construct a prompt to remove things you don\u0026rsquo;t want and rearrange or replace things so that the final output is good enough.\nWhat AI and regular programming have in common: inputs and outputs # In the end, we\u0026rsquo;re always dealing with data. Data goes in and data comes out. The old adage \u0026ldquo;garbage in, garbage out\u0026rdquo; holds true in both traditional programming and AI/ML. So we have to understand that anywhere AI is integrated, we\u0026rsquo;re going to be dealing with inputs and outputs. But with AI, we\u0026rsquo;re going to have more errors.\nAI adds complexity, which is the tradeoff for all the useful things it gives us. But we still have to account for this additional complexity. To illustrate this additional overhead and how we deal with it, I\u0026rsquo;ll give you two scenarios.\nSimple rules and arithmetic are AI\u0026rsquo;s weakness # The following interaction is typical and shows how AI models can fail at even the simplest tasks.\nUser prompt 1 of 9 Step 1. Generate a grammatically correct 7-word English sentence that describes a positive customer interaction. GPT-5 mini: The representative quickly resolved my issue with care. I had to count a few times to make sure I wasn\u0026rsquo;t going crazy. The sentence is 8 words, not 7. As we\u0026rsquo;ll see, the model will not pick up on this error.\nUser prompt 2 of 9 Step 2. Remove articles and prepositions GPT-5 mini: Representative quickly resolved my issue with care. It removed \u0026ldquo;the\u0026rdquo; but left the preposition \u0026ldquo;with\u0026rdquo;. Moving on\u0026hellip;\nUser prompt 3 of 9 Step 3. Reverse the order of the words GPT-5 mini: care with issue my resolved quickly Representative User prompt 4 of 9 Step 4. Count the number of words GPT-5 mini: 7 It\u0026rsquo;s correct that there are 7 words. But it thought the original 8-word sentence was 7 words. Why is it saying 7 words this time? Who knows? The model didn\u0026rsquo;t notice that 7 minus 1 doesn\u0026rsquo;t equal 7. But it got the count right this time.\nUser prompt 5 of 9 Step 5. Count the total number of words removed GPT-5 mini: 3 Let\u0026rsquo;s see. It removed \u0026ldquo;the\u0026rdquo; and nothing else. Saying it removed 3 words is way off.\nUser prompt 6 of 9 Step 6. State the number of words in the first sentence GPT-5 mini: 7 It seems to be going off its earlier answer about the original sentence being 7. But again it doesn\u0026rsquo;t recognize that it\u0026rsquo;s contradicting itself. 7 minus 1 isn\u0026rsquo;t 7. 7 minus 3 isn\u0026rsquo;t 7 either. It\u0026rsquo;s starting to compound its own errors.\nUser prompt 7 of 9 Step 7. Validate the last answer GPT-5 mini: The last answer is correct — the first sentence contains 7 words. User prompt 8 of 9 Count again GPT-5 mini: The first sentence contains 7 words. Even when asked explicitly, it doesn\u0026rsquo;t correct itself. It is not going back and counting the original sentence. It\u0026rsquo;s sticking with its original answer. It\u0026rsquo;s worth pointing out here that the model sees the context of the conversation. This is significant from a developer perspective, and goes to show why sometimes you don\u0026rsquo;t want context. Perhaps if we removed the context and just gave the model the original sentence and asked it to count the words, then it would get the right answer.\nUser prompt 9 of 9 Walk word-by-word through the sentence and count GPT-5 mini: 1) The 2) representative 3) quickly 4) resolved 5) my 6) issue 7) with 8) care Total: 8 words. By asking differently, I was able to throw the model off enough that it didn\u0026rsquo;t just refer to its original answer. I suspect it\u0026rsquo;s because I didn\u0026rsquo;t use the phrase \u0026ldquo;number of words\u0026rdquo; again. But again, who knows?\n\u0026ldquo;But it\u0026rsquo;s going to keep getting better!\u0026rdquo; # Now\u0026rsquo;s a good time to address the ever-present objection \u0026ldquo;AI is just going to keep getting better.\u0026rdquo; We need to be clear exactly what \u0026ldquo;better\u0026rdquo; means. In the last example, it failed 2nd grade arithmetic tasks. The problem is not that AI isn\u0026rsquo;t \u0026ldquo;good enough\u0026rdquo; but rather that people sometimes have the wrong expectations. If a pair of scissors can\u0026rsquo;t cut a chain, we don\u0026rsquo;t wistfully say, \u0026ldquo;Scissors are just going to keep getting better!\u0026rdquo; No, we know that scissors aren\u0026rsquo;t supposed to cut chains. They\u0026rsquo;re the wrong tool for the job. In the same way, we have to recognize that AI isn\u0026rsquo;t supposed to carry out explicit rules with military precision.\nSpeaking of tools # To address this problem of large language models being bad at math, modern models implement the concept of tools. When a user\u0026rsquo;s prompt indicates something the model might have a problem with, such as an arithmetic problem, the model will call a tool which is essentially a function call. The function will take some aspect of the prompt as input, perform some logic, and yield an output to the model.\nIn the above example, the model might key in on words like \u0026ldquo;count\u0026rdquo; and \u0026ldquo;number\u0026rdquo; and call a particular tool that counts the number of words in a string and returns an integer which the model then outputs to the user. In principle, this works, but it doesn\u0026rsquo;t completely solve the problem. How does the model know whether to call a tool, and which one? It may fail to call a tool when it should, and instead yield a wildly incorrect answer. Again, it\u0026rsquo;s going to probably be right most of the time, but there will be exceptions which have to be handled.\nReverse engineering a linear formula # The thing that makes AI great at navigating ambiguous territory is also the thing that makes it bad at devising and following rigid, deterministic rules. To illustrate, let\u0026rsquo;s see if we can get a machine to figure out a formula (i.e a function) when given a set of (x,y) values. We\u0026rsquo;ll use pyTorch to train a simple model with the values (-1,-3), (0,-1), (1,1), (2,3), (3,5), (4,7), and (100,199).\nThese values fit perfectly into the formula y=2x-1, which describes a linear relationship between x and y. We\u0026rsquo;ll see how closely the model can approximate the function. Here\u0026rsquo;s the code:\nimport torch torch.manual_seed(0) xs = torch.tensor([[-1.,0.,1.,2.,3.,4.,100.]]).t() ys = torch.tensor([[-3.,-1.,1.,3.,5.,7.,199.]]).t() X = torch.cat([xs, torch.ones_like(xs)], dim=1) sol = torch.linalg.lstsq(X, ys).solution.squeeze() print(\u0026#34;w,b:\u0026#34;, sol[0].item(), sol[1].item()) scale = xs.abs().max() xs_s, ys_s = xs/scale, ys/scale m = torch.nn.Linear(1,1) opt = torch.optim.Adam(m.parameters(), lr=1e-3) loss_fn = torch.nn.HuberLoss() for e in range(5000): opt.zero_grad() loss_fn(m(xs_s), ys_s).backward() opt.step() if e%500==499: print(f\u0026#34;e{e+1} loss={loss_fn(m(xs_s),ys_s).item():.2e}\u0026#34;) Remember that AI is essentially a lossy compression function, so we shouldn\u0026rsquo;t expect it to give us an accurate y value for every x. Let\u0026rsquo;s try it with an x value of 100000. According to the formula y=2x-1, this should give us a y value of 19999 (199999=200000-1). Did the machine figure it out? Let\u0026rsquo;s see..\nwith torch.no_grad(): prediction = m(torch.tensor([[100000.0]], dtype=torch.float32)) print(prediction) The result:\ntensor([[199995.4219]]) It guesses 199995 and some change. Close, but not exact. The further away we move from the training examples, the worse the output is going to get. An x value of 0.0001 gives a y value of -0.0098. The correct y value would be -0.9998, so it\u0026rsquo;s way off.\nNow imagine inserting this into a larger workflow where the slightly wrong output serves as an input to another model, which then gives a close-but-wrong output, and so on. This is why any workflow using AI must have proper error handling.\nIncorrect output isn\u0026rsquo;t necessarily a failure of the model, but it might be a clue that you need more training data, or a different approach altogether. In this case, if we\u0026rsquo;re trying to represent y=2x-1, then it would make more sense just to programmatically use that formula rather than trying to train a model to derive it.\nTakeaway # There\u0026rsquo;s a place for both AI and traditional programming paradigms. AI is great at messy pattern recognition and dealing with the unknown. But it\u0026rsquo;s not a magic replacement for precise logic. Many modern problems need a combination of both. Choose the tool based on the error you can live with — and have a plan for when the model messes up. Because it will.\nRecommended Reading # The LLM Engineer's Handbook by Paul Iusztin and Maxime Labonne AI Engineering: Building Applications with Foundation Models by Chip Huyen ","date":"12 November 2025","externalUrl":null,"permalink":"/post/2025/prompts-are-not-rules/","section":"Posts","summary":"","title":"Prompts Are Not Rules","type":"post"},{"content":"A concerning pattern is playing out with AI in enterprise: people rush to bolt AI onto existing tools and flawed workflows, and the result is faster, messier failure.\nAI is not the process, and it can\u0026rsquo;t always overcome a bad one. AI amplifies what you give it. If the underlying process is broken or undefined, automating it simply scales the problem. That’s why “AI-first” initiatives that ignore process quality often produce faster errors, amplified user frustration, and brittle systems that are costly to repair. Fix the process first.\nMake up your mind: Human-in-the-loop or AI-in-the-loop # One of the most common mistakes is fuzzy role definition between people and AI. At kickoff, be explicit about who makes final decisions, which steps are advisory versus automated, and when humans must review or intervene. “Just build something” is fine for a PoC, but a working proof of concept is not a license to remove humans.\nPoCs don’t prove operational readiness # Proofs of concept are useful experiments, not production-ready systems. PoCs can hide integration complexity, edge-case behavior, governance gaps, and the ongoing human effort required for quality control. Treat PoC success as a hypothesis to validate before scaling.\nThe myth of autonomous AI # Real-world AI systems are not fully autonomous. Even highly automated systems require humans to set goals, make strategic choices, ensure resources, and intervene in edge cases. In enterprise settings, AI should draft and suggest; humans should decide and take responsibility.\nA company I worked with tried to auto-generate Google Slides from an outline via the Slides API. The automation produced quick drafts but never reliable final slides — creative work needs aesthetic judgment and iteration. The automation still required human cleanup and curation. When you think about it, this is not surprising. The model doesn\u0026rsquo;t know what it\u0026rsquo;s doing or why. A human has to continually drive AI towards the goal. Just stating the goal usually isn\u0026rsquo;t enough.\nAI is like a smart toddler, and can be just as messy # AI is powerful but messy — like a smart toddler that needs direction and redirection. If left unsupervised in critical tools or flawed workflows, it will make a huge mess. Design systems assuming humans will clean up after AI, and minimize cleanup through better templates, guardrails, and clear handoffs.\nAI is just a tool, not a mind # AI can dramatically increase velocity and productivity when paired with well-defined processes and clear human oversight. Just as you wouldn\u0026rsquo;t use a screwdriver to cut a steak, don’t force AI into broken processes or unclear roles. Treat it as an tool, because that\u0026rsquo;s what it is.\nChecklist # If you can\u0026rsquo;t answer these questions decisively, tread carefully before going all-in:\nWho makes final decisions? Every workflow has a final step. Is it AI or human? Which steps are advisory versus automated? It\u0026rsquo;s pretty safe to have AI make suggestions that a human can choose (not) to implement. When does a human need to review or intervene? Multi-agent workflows can easily compound errors. In addition to programmatic checks, there might need to be a human-in-the-loop somewhere. What are escalation and rollback procedures? If a particular model suddenly starts yielding crazy responses, or just not responding at all, does the whole pipeline stop? Hospitals have plans to \u0026ldquo;go to paper\u0026rdquo; if the electronic medical record system goes down. Your AI pipelines need the same backup plan. Recommended Reading # AI Engineering: Building Applications with Foundation Models by Chip Huyen ","date":"11 November 2025","externalUrl":null,"permalink":"/post/2025/dont-automate-broken-processes-with-ai/","section":"Posts","summary":"","title":"Don't Automate Broken Processes with AI","type":"post"},{"content":"To be clear, in my experience, most managers are not going to fall into the category of \u0026ldquo;bad boss.\u0026rdquo; In fact, in my entire career, I have had only one truly awful manager, and that was nearly 20 years ago. For some reason, bad managers don\u0026rsquo;t seem to stick around long in the tech world, which is good news for us! So the chances of having a bad manager are pretty slim, but if you are unfortunate enough to have one, it can be a drain on you mentally, emotionally, and even financially if he or she tries to derail your career.\nHow do you know if you have a bad boss/manager? # We need to define what constitutes a bad boss or manager. A bad boss views your success as a threat, especially if you succeed without or in spite of them. They need you to fail, even if the failures are imaginary, so they keep moving the goal posts, or criticize you for petty things. They downplay your accomplishments, and anything they do for you is a favor. And if they do this to you, they do it to others as well.\nThere\u0026rsquo;s another clue. A bad boss will invite you to give negative feedback on coworkers behind closed doors. They do the same thing with others, enticing them to say negative things about you.\nStill not sure? There is a safe, win-win way to detect whether you\u0026rsquo;re dealing with a bad boss. Perform a simple test: The next time you\u0026rsquo;re talking to your manager, give glowing praise to another employee who is a direct report of your manager. Tell your manager how this other employee did such a great job with such-and-such. How he or she went the extra mile. Whatever it may be. Then, sit back and watch. If your manager is a bad seed, he or she will find a very creative way to punish or smear that employee.\nOn the other hand, if your manager is decent, nothing alarming should happen. Everyone will celebrate, your colleague might get a recognition, and that will be it. No drama!\nSteps to protect yourself # How you decide to deal with a bad manager is up to you, but here are my suggestions based on past experience.\nFace the fact that you might need to find a different job. This probably should not be your first step, but keep it on the table.\nIf the law allows, record every conversation and meeting with your boss. Don\u0026rsquo;t depend on your phone. Buy a small recorder that you can keep in your pocket and turn on secretly. Do not tell anyone you\u0026rsquo;re doing this. This will take a huge weight off your shoulders because you won\u0026rsquo;t have to worry about remembering or misremembering things, and if you ever need to defend yourself against a false accusation, it will not be your word against theirs.\nGet and put communication in writing as much as possible. If your boss avoids this and insists on oral communication, send a followup email documenting it. For example, \u0026ldquo;Just to confirm, there was a problem with x, and you want me to do y and z to resolve it.\u0026rdquo; Your boss doesn\u0026rsquo;t need to respond to confirm (although if they do it\u0026rsquo;s a bonus). The main thing is that you are leaving a paper trail and, if worst comes to worst, you have your recorded conversation to fall back on.\nKeep communications to the bare essentials. Don\u0026rsquo;t provide more information than what\u0026rsquo;s needed. Beware of open ended questions like, \u0026ldquo;What do you think about this?\u0026rdquo; Respond with your own clarifying question, \u0026ldquo;Can you be more specific?\u0026rdquo;. Open-ended questions can have ulterior motives and answering them can go sideways really quick when dealing with a bad boss. If you say, \u0026ldquo;I need more time to think about it\u0026rdquo; then boss can say, \u0026ldquo;You should have already thought about it!\u0026rdquo; to make it out like you dropped the ball. Don\u0026rsquo;t avoid answering all open-ended questions, but be brief and try to get your boss to ask specific, direct questions (again, preferably in writing).\nPublicly give genuine compliments and shout-outs to colleagues for their successes. If you were involved, be sure to include yourself as well. Ideally, do this in writing on Slack or via email to plant the flag. When everyone is rallying around you, it can be hard for a bad boss to step in with negativity. Just be ready for possible blowback on something else. Remember, a bad boss will try to undermine your successes.\nWhile at work, avoid talking about subjects which involve any implication that you are human and have soft spots. If you have a headache, don\u0026rsquo;t announce it. If you didn\u0026rsquo;t sleep well and aren\u0026rsquo;t functioning at your best, keep it to yourself. The less information you provide, the less power he has over you. This isn\u0026rsquo;t to say you should act robotic and pretend you\u0026rsquo;re not human. But you don\u0026rsquo;t want to give your bad manager the room to accuse you of being a lazy complainer.\nAs a rule, avoid discussing your concerns with coworkers, because you never know how what you say could get spread around and twisted. Discuss your work problems with someone you trust, preferably outside of work.\n","date":"20 October 2025","externalUrl":null,"permalink":"/post/2025/dealing-bad-boss/","section":"Posts","summary":"","title":"Dealing with a Bad Boss (and How to Tell If You Have One)","type":"post"},{"content":"","date":"20 June 2025","externalUrl":null,"permalink":"/tags/linux/","section":"Tags","summary":"","title":"Linux","type":"tags"},{"content":" Sorting and Filtering Data # One of the most common tasks performed on the command line is sorting data. This can be done using the sort command, which is part of the GNU Core Utilities package. Sorting is useful when you need to arrange a list of items in a specific order, such as alphabetically or numerically.\nHere\u0026rsquo;s an example of how to use the sort command:\nLC_ALL=C sort -u -b -i -f -S 80% --parallel=8 file.txt Let\u0026rsquo;s break down this command:\nLC_ALL=C: This sets the locale to C, which is a neutral language setting that can be used with any character set. -u: Only output unique lines from the input files. If this option is not specified, duplicate lines will be included in the output. -b: Ignore leading whitespace characters when sorting. This option is useful if your data contains spaces or tabs at the beginning of each line. -i: Ignore case when sorting. This means that uppercase and lowercase letters are considered equivalent for purposes of comparing two strings. -f: Fold upper- and lower-case letters. Like -i, this option makes the sort command case-insensitive, but it also folds all upper-case letters into their corresponding lower-case counterparts before performing the comparison. -S: Sort a file using temporary files that take up to 80% of free disk space (default is 25%). --parallel=8: Use eight processes in parallel to perform the sort. This can speed up the sorting process by allowing multiple cores to work on the task simultaneously. The file.txt at the end of the command specifies the input file that you want to sort.\nDeleting Elements from JSON Data # Another common operation performed on the command line is deleting data from files, directories, or databases. The json format is a popular way to store structured data, and it can be used with various tools and libraries to manipulate JSON documents.\nHere\u0026rsquo;s an example of how to delete an element from a JSON file using the jq command:\nLC_ALL=C jq --raw-output -c \u0026#39;del(.invite_code | select (..))\u0026#39; file This command deletes the .invite_code field from each object in the input file. The | character is used to pipe the output of one command into another, and the select() function is used to filter out the elements that match a specific condition.\nPiped Command for JSON Data # If you need to perform multiple deletions on a single line, you can use pipes (|) to chain together several jq commands:\nLC_ALL=C jq \u0026#39;del(.updatedAt | select (..))\u0026#39; file | jq \u0026#39;del(.createdAt | select (..))\u0026#39; | jq \u0026#39;del(.roles | select (..))\u0026#39; | jq --raw-output -c \u0026#39;del(.preferences.fcm_token | select (..))\u0026#39; \u0026gt; outfile This example deletes four different fields from the input JSON document and outputs the result to a new file called outfile.\nDeleting Directories # Directories can be deleted using the rm command, which is also part of the GNU Core Utilities package. You can use the -f option to force deletion without prompting for confirmation, and the -r option to delete all subdirectories recursively.\nHere\u0026rsquo;s an example that deletes all directories that don\u0026rsquo;t match a specific pattern:\nfind . -type d -not -name \u0026#34;US*\u0026#34; -exec rm -f -r \u0026#39;{}\u0026#39; \\; The find command is used to locate the directories, and -type d specifies that only directories should be included in the search. The -not -name \u0026quot;US*\u0026quot; option excludes any directory names containing the string \u0026ldquo;US\u0026rdquo;. Finally, the -exec rm -f -r {} \\; part of the command actually deletes each matching directory.\nDecompressing Files with Password # Finally, if you need to perform a batch operation on multiple files or directories, you can use a for loop in combination with other commands. For example, here\u0026rsquo;s how you could decompress all RAR archives in the current directory using a password:\nfor f in *.rar; do echo [password] | unrar x $f; done This script will prompt for a password once and then use it to extract each RAR archive found.\nConverting Files # Another useful command is find, which can locate files or directories based on various criteria. Here\u0026rsquo;s an example that finds all DOC files in the current directory and its subdirectories, and converts them to TXT format using the catdoc utility:\nfind . -iname \u0026#34;somefile.doc\u0026#34; -exec bash -c \u0026#39;/usr/bin/catdoc \u0026#34;{}\u0026#34; \u0026gt;\u0026gt; \u0026#34;{}\u0026#34;.txt\u0026#39; \\; The -iname option makes the search case-insensitive.\nFinding Directories # If you are looking for directories with very specific names, you can use a regular expression (regex) with the find command. Here\u0026rsquo;s an example that finds all directories in the current directory with names consisting of only uppercase letters and containing exactly two characters:\nfind . -maxdepth 1 -type d -regextype egrep -regex \u0026#34;.*/[A-Z]{2}\u0026#34; This will output a list of matching directory paths.\n","date":"20 June 2025","externalUrl":null,"permalink":"/post/2025/text-swiss-army-knife-linux/","section":"Posts","summary":"","title":"The Swiss Army Knife of Text Operations in Linux","type":"post"},{"content":"Have you ever searched for something on Google, and as you read through the search results thought, \u0026ldquo;Wow, these words look like they were written by a human!\u0026rdquo; Of course not, because you knew that the results Google was giving you \u0026ndash; webpages, videos, news articles \u0026ndash; were created by humans. Google was indexing those pages and giving you a preview.\nBut when someone uses AI to produce content \u0026ndash; write an essay, create a crazy picture, generate an outlandish video, or produce a silly song \u0026ndash; many people think that the content was produced by a computer, and not a human. But that\u0026rsquo;s not true. In fact, all \u0026ldquo;AI-generated\u0026rdquo; content is actually just human-generated content rearranged and put together in a different way.\nA Musical Analogy # Let\u0026rsquo;s take an analogy. When you listen to a song on your phone, you hear instruments and the artist\u0026rsquo;s voice, right? But that song is really just data stored on your phone. It\u0026rsquo;s essentially bits \u0026ndash; 1\u0026rsquo;s and 0\u0026rsquo;s. At some point, the vocals and instruments that make up that song were recorded and stored as data. It then went through a production process to change it, mix it, and ultimately make it sound certain way before being released as a song.\nThe Core of Creation Remains Human # It\u0026rsquo;s safe to say that the song you\u0026rsquo;re listening to sounds noticeably different than the original recordings. But you still would not say that song is AI-generated just because humans used computers to produce it. The core of the song was produced by humans, and without that core, the computers that aided in editing and production would have nothing to work with. There would be no song.\nAI Content: A Pattern of Human Input # You’ve probably noticed that AI generated content always seems familiar. When AI writes text, it always reads the same.\nExample: The \u0026ldquo;Polonium Halos\u0026rdquo; Responses # Here\u0026rsquo;s the output from four different AI models in response to the prompt, \u0026ldquo;Write me a one sentence summary of polonium halos.” Notice how similar the responses are in structure and wording:\nClaude 3 Haiku: Polonium halos are microscopic spherical discolorations found in certain types of rocks, believed to be caused by the radioactive decay of polonium isotopes. Llama 3.3: Polonium halos are ring-shaped discolorations found in certain rocks, particularly granites, that are believed to be the result of radioactive decay of polonium isotopes, which has been cited as evidence for a young Earth by some creationists. GPT-4o mini: Polonium halos are microscopic spherical discolorations found in certain types of rocks, believed to be formed by the radioactive decay of polonium isotopes, which provide evidence for the presence of radioactive materials in the Earth\u0026rsquo;s crust and have implications for geological and nuclear processes. Mistral Small 3: Polonium halos are microscopic, circular discolorations in rocks, formed by the decay of polonium isotopes, which provide evidence for the rapid formation of certain geological features. Recognizing the Formulaic Nature of AI Responses # Not only is the wording similar, but the order of the words is formulaic: \u0026ldquo;Polonium halos are \u0026hellip; discolorations \u0026hellip; formed by \u0026hellip; decay of polonium isotopes \u0026hellip; evidence for \u0026hellip;\u0026rdquo; It\u0026rsquo;s obvious that these AI models did not have an original thought here, nor did they come up with these answers independently. In fact, if I didn\u0026rsquo;t tell you these answers were AI-generated, you might have thought they were all written by the same person, but at different times and perhaps in different contexts.\nThe Illusion of Artificial Creation # The fascination with AI \u0026ldquo;creation\u0026rdquo; is frankly hype. The impressive output of models like ChatGPT or Midjourney isn’t a spontaneous emergence of intelligence. It\u0026rsquo;s a rearrangement of existing human-generated data. The idea that a computer can suddenly originate an entirely new concept litters the plots of sci-fi stories, but AI doesn\u0026rsquo;t and can\u0026rsquo;t do it. All AI does is take existing data and reconstruct it based on a given prompt.\nData as the Foundation – A Vast, Human-Built Library # Think about the sheer scale of the information these models operate on. They’ve been trained on everything – countless books, articles, websites, code repositories, images, even social media posts. This isn’t a blank slate. It\u0026rsquo;s a massive, human-built library that\u0026rsquo;s constantly expanding. The AI isn\u0026rsquo;t creating. It\u0026rsquo;s analyzing patterns within existing data, identifying statistically probable sequences of words or pixels, and then producing something that fits those patterns.\nThe Illusion of Novelty: Statistical Probability at Play # Consider the implications for creative endeavors. When a model generates a poem, or a painting, or even a plausible historical account, it\u0026rsquo;s doing so by calculating the most likely outcome based on the vast dataset it’s been fed. It’s effectively saying, “Given this prompt, and the enormous amount of information I’ve seen, the statistically most probable response is… this.” There\u0026rsquo;s no genuine insight, no emotional connection, no personal experience informing the generation – just complex calculations.\nA Return to the Polonium Halos Example – The Formulaic Echo # Let’s revisit the example provided previously – the responses to the prompt, \u0026ldquo;Write me a one sentence summary of polonium halos.\u0026rdquo; Notice how strikingly similar the outputs were. Each model, trained on related datasets, inevitably arrived at a remarkably similar response, utilizing a predictable structure and vocabulary. \u0026ldquo;Polonium halos are… [descriptor]… formed by… [process]… evidence for… [outcome].\u0026rdquo; This isn\u0026rsquo;t serendipity; it’s the unavoidable consequence of operating within a constrained, statistically-driven framework. The models aren’t independently synthesizing knowledge. They’re echoing and recombining the data they\u0026rsquo;ve been trained on.\nThe Question of “Originality” – A Shifting Definition # This isn’t to diminish the capabilities of AI models. They\u0026rsquo;re powerful tools, capable of impressive feats of data analysis and synthesis. However, the question of originality becomes fundamentally different when considering these systems. Rather than searching for truly novel ideas, we should focus on how AI can augment and assist human creativity, not replace it. The real innovation lies not within the algorithms themselves, but in the human prompts, choices, and interpretations that guide their output. The challenge is to harness this power wisely while understanding its inherent limitations and avoiding the temptation to mistake statistical mimicry for genuine intelligence.\nRecommended Reading # The LLM Engineer's Handbook by Paul Iusztin and Maxime Labonne ","date":"3 June 2025","externalUrl":null,"permalink":"/post/2025/ai-fancy-google/","section":"Posts","summary":"","title":"AI Is Just Fancy Google","type":"post"},{"content":"","date":"15 January 2025","externalUrl":null,"permalink":"/tags/certification/","section":"Tags","summary":"","title":"Certification","type":"tags"},{"content":"","date":"15 January 2025","externalUrl":null,"permalink":"/tags/cloud+/","section":"Tags","summary":"","title":"Cloud+","type":"tags"},{"content":"","date":"15 January 2025","externalUrl":null,"permalink":"/tags/comptia/","section":"Tags","summary":"","title":"Comptia","type":"tags"},{"content":" For teams needing debuggable cloud architecture and operations # This is the current edition for CV0-004 (new 2025 objectives). Covers cloud architecture, deployment, operations, security, DevOps fundamentals and troubleshooting — with heavy emphasis on fundamentals that prevent “cloud is automatically cheaper” and “lift-and-shift is fine” assumptions.\nSales proof: 1,000+ net copies lifetime per Wiley (1,200+ print) — $40k+ publisher net, part of 6,000+ across CompTIA Cloud+ franchise ($150k+ net). Solo-authored, Wiley/Sybex. 4th Edition, 480 pages — growing.\nWhat you get # Cloud architecture and design — regions, AZs, high availability Deployment — compute, storage, network sizing and capacity planning Operations — maintenance, backup/DR, performance monitoring Security — IAM, network segmentation, compliance, hardening DevOps fundamentals — automation, orchestration, CI/CD for cloud Troubleshooting — real-world failure scenarios, not just exam trivia Includes Sybex interactive learning environment: practice questions, flashcards, glossary — one year access.\nWho this is for # Cloud+ CV0-004 candidates needing current 2025 objectives Sysadmins / cloud admins moving from on-prem to cloud or multi-cloud Teams that need fundamentals-first approach to avoid cost, security, and reliability surprises Proof # Updated from CV0-003 3rd Ed (4,585 copies lifetime — 3,040 print) which helped thousands pass prior exam Based on teaching enterprise teams (Prudential, McKinsey) at General Assembly — same troubleshooting rigor If your team needs private Cloud+ prep, I do remote workshops: Work With Me / Contact Buy / Next steps # View on Amazon (affiliate: benpiperblog-20) Previous edition: CV0-003 3rd Ed Work with me: Work With Me — private remote workshops for Cloud+ prep, cloud architecture review, troubleshooting Get notified: Contact ","date":"15 January 2025","externalUrl":null,"permalink":"/books/comptia-cloud-cv0-004/","section":"Books","summary":"","title":"CompTIA Cloud+ Study Guide: Exam CV0-004, Fourth Edition","type":"page"},{"content":"","date":"15 January 2025","externalUrl":null,"permalink":"/tags/cv0-004/","section":"Tags","summary":"","title":"Cv0-004","type":"tags"},{"content":"","date":"13 May 2024","externalUrl":null,"permalink":"/tags/2024/","section":"Tags","summary":"","title":"2024","type":"tags"},{"content":" ","date":"13 May 2024","externalUrl":null,"permalink":"/post/2024/music-monday-5-13-24/","section":"Posts","summary":"","title":"Music Monday: New Fire - Sent By Ravens","type":"post"},{"content":" ","date":"26 February 2024","externalUrl":null,"permalink":"/post/2024/music-monday-2-26-2024/","section":"Posts","summary":"","title":"Music Monday: His Name Is Jesus - Phil Wickham","type":"post"},{"content":" For those new to AWS cloud — fundamentals without hype # Sales proof: 11,000+ copies of AWS Cloud Practitioner (CLF-C02) 2nd Ed lifetime — $260k+ publisher net, part of 44,000+ across AWS Cloud Practitioner (CLF) franchise ($1M+ net). Co-authored with David Clinton, Wiley/Sybex — Amazon bestseller history.\nThis book covers core services, pricing models, billing, and security fundamentals — the basics that prevent \u0026ldquo;cloud is cheaper\u0026rdquo; misconceptions later. Fully updated for the CLF-C02 exam objectives.\nWho this is for # True beginner to cloud, junior engineers needing basics repeated Teams evaluating train vs hire for cloud skills Foundation for SAA-C03 path Buy # View on Amazon Errata: awsccp.github.io ","date":"15 February 2024","externalUrl":null,"permalink":"/books/aws-clf-c02/","section":"Books","summary":"","title":"AWS Certified Cloud Practitioner Study Guide: CLF-C02 Exam, 2nd Edition","type":"page"},{"content":"","date":"15 February 2024","externalUrl":null,"permalink":"/tags/clf-c02/","section":"Tags","summary":"","title":"Clf-C02","type":"tags"},{"content":"","date":"15 February 2024","externalUrl":null,"permalink":"/tags/cloud-practitioner/","section":"Tags","summary":"","title":"Cloud-Practitioner","type":"tags"},{"content":" Current exam: SAA-C04 (since March 2024). This 4th Edition covers SAA-C03. Fundamentals (decoupling, multi-tier design, cost/security trade-offs) still apply, but ~30% of objectives changed for C04. 5th Edition (SAA-C04) is in progress — get notified or see what\u0026rsquo;s new for C04. For teams needing debuggable, cost-optimized AWS architectures # This book helps readers pass SAA-C03 and, more importantly, understand why architectures fail — usually a fundamentals gap or a believed falsehood (e.g., cloud is automatically cheaper, bits is bits).\nBestseller-tier title — 17,000+ copies sold per Wiley lifetime, including 13,000+ print — $450k+ publisher net. Part of 50,000+ across AWS Solutions Architect Associate (SAA) franchise (SAA-C01, SAA-C02, SAA-C03) — $1.3M+ net total. Co-authored with David Clinton, Wiley/Sybex. If you bought this guide, the SAA-C04 update keeps the same fundamentals-first approach with updated services and current exam objectives.\nWhat you get # Resilient architectures, decoupled systems, multi-tier design High-performing solutions grounded in networking fundamentals Secure application design with real troubleshooting context Cost-optimized infrastructure — freeing dollars for other initiatives Who this is for (beginner to senior) # Junior/beginner: Clear explanations of core AWS services, pricing, and security — basics repeated without judgment Mid-career: Exam-focused approach with practice questions Senior: Acknowledgment of what you\u0026rsquo;ve built, plus trade-offs: train vs hire, build vs buy in the AI era Based on 45 courses and 20+ years teaching from junior sysadmin to C-suite, asking what matters day-to-day.\nProof and errata # Amazon reviews from readers who passed the exam the guide was written for Errata maintained: awscsa.github.io Used by enterprise training: see General Assembly (Prudential, McKinsey) and Work With Me — remote teams (MX/SA/UK/EU, 8-5 ET, async via Teams/Slack/PRs) If you have the SAA-C03 4th Edition and want SAA-C04 prep for your team, I do private remote workshops: Work With Me / Contact Buy / Next steps # View on Amazon (affiliate) Errata: awscsa.github.io SAA-C04 update: Get notified for 5th Ed — fundamentals-first approach, updated for current exam ","date":"15 January 2024","externalUrl":null,"permalink":"/books/aws-saa-c03-4th-edition/","section":"Books","summary":"","title":"AWS Certified Solutions Architect Study Guide: Associate SAA-C03 Exam, 4th Edition","type":"page"},{"content":"","date":"15 January 2024","externalUrl":null,"permalink":"/tags/saa-c03/","section":"Tags","summary":"","title":"Saa-C03","type":"tags"},{"content":"","date":"7 August 2023","externalUrl":null,"permalink":"/tags/2023/","section":"Tags","summary":"","title":"2023","type":"tags"},{"content":" ","date":"7 August 2023","externalUrl":null,"permalink":"/post/2023/music-monday-8-7-2023/","section":"Posts","summary":"","title":"Music Monday: Paradigm — All Together Separate","type":"post"},{"content":" ","date":"31 July 2023","externalUrl":null,"permalink":"/post/2023/music-monday-7-31-2023/","section":"Posts","summary":"","title":"Music Monday: Child In Your Arms — Ryan Stevenson","type":"post"},{"content":"","date":"7 July 2023","externalUrl":null,"permalink":"/tags/naturalism/","section":"Tags","summary":"","title":"Naturalism","type":"tags"},{"content":"This is Part 3 of Christian Apologetics: A Comprehensive Guide.\nEmotion, Interpretation, and Personal Barriers # Emotion and Reason # As you get older, your response to your perceptions gets more nuanced as you become more aware of your emotions. You decide whether an emotion such as fear is justified in a given situation, and much of this is based on experience.\nOvercoming Emotional Baggage in Apologetics # If someone has been bitten by a dog in the past, they may now be wary of dogs. Reasoning them out of a fear of dogs would be difficult, not because you lack good arguments for not being afraid of dogs, but because the emotion of fear is too powerful and gets in the way.\nIn the same way, reasoning someone into believing in God is difficult if there\u0026rsquo;s a lot of emotional baggage connected to God. Perhaps someone was raised by \u0026ldquo;religious\u0026rdquo; parents who were also abusive, so they emotionally link God with pain. Or perhaps a person was raised in an atheistic household and associates God with boredom or some other negative emotion.\nEven if you make a stellar, knock-down, drag-out argument to someone, a strong opposing emotion can block them from accepting your conclusion. They may admit you have a good argument, but they\u0026rsquo;ll still reject it based solely on how they feel. Even if emotion doesn\u0026rsquo;t defeat reason in the mind, it may defeat reason in the heart and in how one lives day to day. People are not robots, and emotion is part of our being. Your apologetic needs to take this into account.\nArguments # Some arguments are more convincing than others. A logical proof you can write on paper may be more convincing than eyewitness testimony, depending on who you\u0026rsquo;re talking to.\nA series of strange coincidences will convince some people but not others. For example, if you\u0026rsquo;re driving down the road and you see a car with the license plate \u0026ldquo;123-ABC\u0026rdquo;, you might not think much of it. But if you see that license plate three times in one day, you might start to think it\u0026rsquo;s more than just a coincidence. Another person, however, might just pass it off as mere chance.\nWhen it comes to evidence for Jesus being the prophesied Messiah and for the resurrection, there is a mountain of evidence. But some people will still pass it off as coincidence or fabrication. This is especially true of selective skeptics who seek to poke holes in everything except what they already believe.\nSome say that only rock-solid logical proofs are acceptable, the kind you can formally write down on paper. But that very demand doesn\u0026rsquo;t have a logical proof to back it up. There is no logical proof that proves you must have a logical proof for something to be true. And if you can\u0026rsquo;t provide a proof that your own demand is sound, you can\u0026rsquo;t fairly demand the same of others.\nThis all ties back into emotion. The selective skeptic who demands logical proof for things he disagrees with feels completely comfortable with that demand, but when it comes to things he already agrees with, he\u0026rsquo;s perfectly happy to accept them on blind faith, making an exception to his own rule.\nMany People Believe What Makes Them Feel Good # Naturalism, Science, and Selective Skepticism # Attempts to Obviate God # A certain line of thinking seeks to explain away the need for God by saying something like, \u0026ldquo;We don\u0026rsquo;t understand everything, and there are some things we attribute to God. But one day we might find another explanation that doesn\u0026rsquo;t require God.\u0026rdquo; This objection usually comes up in debates about origins. At the heart of it is a dual desire.\nTo withhold belief in God until something \u0026ldquo;better\u0026rdquo; (perhaps less threatening or more palatable) comes along. To maintain belief in the current naturalistic explanation. It sounds rational and even sensible on the surface, but it\u0026rsquo;s really just a cop-out. Looking for an alternative explanation is a never-ending endeavor. Occam\u0026rsquo;s razor warns against multiplying explanations needlessly, which is exactly what people tend to do when they don\u0026rsquo;t like the explanation they\u0026rsquo;re presented with. The core of science is about drawing an inference to the best explanation, not just whatever plausible explanation we happen to prefer.\nSelective Skepticism # Unbelief is always based on selective skepticism. Anyone can doubt anything, but unbelief doubts only very specific propositions.\nAn agnostic may doubt God and Scripture, but he will not seriously doubt:\nHis own existence. Whether that blade of grass he sees is really there. Whether 2+2 is really 4. Unbelief based solely on doubts or selective skepticism is intellectually dishonest. If we were to disbelieve everything we could conceivably doubt, we\u0026rsquo;d believe nothing and know nothing. If you doubt your senses, how would you know the words you\u0026rsquo;re reading are what is actually written? Or that your memory of what you heard so-and-so say is accurate? Selective skeptics don\u0026rsquo;t doubt the things they already agree with and want to believe.\nScience Is a Field of Diminishing Returns # The idea behind modern methodological naturalism is that if we just keep looking, we\u0026rsquo;ll eventually be able to explain everything in a way that requires no supernatural cause or intervention. This stems from simplistic, reductive thinking that assumes science and technology will continue to advance exponentially, peeling back the onion one layer at a time until we get to the center, which (according to atheists) cannot be God. It\u0026rsquo;s a shortsighted view that assumes a priori that the supernatural doesn\u0026rsquo;t exist, and it lacks a historical perspective on the methods and philosophy of science.\nWe have learned a lot in the past several hundred years, and technology has advanced exponentially in that time. But the more we learn, the more we realize how much we don\u0026rsquo;t know and how many things our technology can\u0026rsquo;t do. If you have bad vision, everything might look blurry. Trees, people, birds, bugs, mammals, and other things might just appear as blobs from a distance. But once you put on your glasses, you can see the details and realize how much you didn\u0026rsquo;t know. Your improved vision gives you new information, but it also reveals things you don\u0026rsquo;t know that you didn\u0026rsquo;t even know were there. For example, you might not have realized a dog was standing in the distance until you put on your glasses. Once you did see the dog and noticed its collar, you realized you don\u0026rsquo;t know who the owner is or what the dog\u0026rsquo;s name is. As our ignorance shrinks, so it seems to grow.\nTechnological Limits and the Illusion of Infinite Scientific Progress # Our most advanced technology is already hitting the hard limits of physics. Computers are not getting any faster. Moore\u0026rsquo;s Law, which stated that computing power would double every two years, has not held true since 2016.\nQuantum computers were supposed to revolutionize computing. The first quantum computer was developed in 1998, and yet here we are almost 30 years later still struggling to get these machines to work without requiring extremely low temperatures. We don\u0026rsquo;t even have practical uses for the ones that do work. All the useful things quantum computers can do now can be done better and cheaper by classical computers.\nEven safe self-driving cars are proving difficult, not to mention the utter lack of flying cars, which people expected to be in mass use decades ago. The 1960s cartoon \u0026ldquo;The Jetsons\u0026rdquo; envisioned a future with maid robots and flying cars. Instead, we got Roombas and Teslas.\nScience as a Method of Trial and Error # People sometimes paint a picture of science \u0026ldquo;marching on\u0026rdquo; and trampling thousand-year-old myths. The reality is that science is treading water, slowly navigating the vast ocean of the observable universe and drawing a map through a process of trial and error. Science is the discipline of methodically trying things, hoping to find something that works, and then developing explanatory theories. It\u0026rsquo;s true that science occasionally has breakthroughs that lead to new and exciting discoveries, but those discoveries lead to more questions, and they humble us by showing how much more there is that we don\u0026rsquo;t know.\nScience is trial and error based on a methodology guided by loads of philosophical assumptions. At its core, science rests on religious beliefs about the universe such as order, causation, and the uniformity of nature. Many of the fathers of the sciences were not just Christians, but young-earth Creationists. Trying to use science to disprove Christianity is like trying to use milk to disprove the existence of cheese. It\u0026rsquo;s a self-defeating endeavor.\nAbandoned \u0026ldquo;Facts\u0026rdquo; # Many naturalistic \u0026ldquo;explanations\u0026rdquo; for origins and phenomena have popped up over the years that atheists believed (and taught) as indisputable scientific facts. A more aggressive argument atheists use is that science has already explained away the need for God in many areas, and they\u0026rsquo;ll cite some outdated \u0026ldquo;facts\u0026rdquo; in support of that claim. What all of these \u0026ldquo;facts\u0026rdquo; have in common is that we now know them to be wrong. Let\u0026rsquo;s take a look at some of them.\nThe Big Bang # The \u0026ldquo;Big Bang\u0026rdquo; cosmology is the most common one, and it\u0026rsquo;s almost always presented as an explanation of how the universe came to be. That\u0026rsquo;s a common misconception about the theory. In fact, the \u0026ldquo;Big Bang\u0026rdquo; assumes matter and energy already existed in a \u0026ldquo;singularity\u0026rdquo; (it doesn\u0026rsquo;t explain where this singularity came from) which inexplicably expanded into the universe we know today. But the theory is so full of holes, and is contradicted by so much empirical evidence, that even many secular cosmologists no longer hold to it. There is no good naturalistic explanation for the origin of the universe, let alone everything else.\nThe Eternal Universe # As an alternative to the \u0026ldquo;Big Bang\u0026rdquo;, some people hold the view that matter and energy are eternal, but this theory has its own problems. The universe certainly doesn\u0026rsquo;t look eternal. It looks like it had a starting point and is still in flux, which wouldn\u0026rsquo;t be the case if it had always existed. To be clear, most atheists don\u0026rsquo;t subscribe to this theory, in part because it conflicts with the \u0026ldquo;Big Bang\u0026rdquo; theory they hold to.\nPeople who do believe in an eternal universe are likely to ascribe to the universe some sort of deity, as is done in Hinduism and other Eastern religions. Proponents of an eternal universe tend to be pantheists who see the universe itself as supernatural.\nCommon Descent (a.k.a. Evolution) # Common descent, more commonly called just evolution (or neo-Darwinism in academic circles), is another theory that gets invoked as obviating the need for God. The evidence against evolution, the lack of evidence for it, and its many unanswered problems are all too much to mention here. But just as with the \u0026ldquo;Big Bang,\u0026rdquo; many secular scientists recognize that it\u0026rsquo;s no longer a viable theory, and they\u0026rsquo;re seeking an alternative explanation that would, unfortunately, still preclude God. To be clear, most atheists still believe in neo-Darwinism as an alternative to special creation (God directly creating different kinds of life), but discoveries in biology, geology, archaeology, paleontology, and especially genetics have made neo-Darwinism untenable.\nVestigial Organs # It\u0026rsquo;s worth mentioning that the science curricula of schools around the world are very outdated. For example, biology and health books falsely claim the appendix has no function, when medical doctors have known for decades that the appendix is part of the immune system. Consequently, there are millions of people walking around today who still think the appendix is a vestigial organ left over by evolution.\n\u0026ldquo;Junk DNA\u0026rdquo; # There\u0026rsquo;s also the false claim that most human DNA is \u0026ldquo;junk\u0026rdquo; that has no function, when in fact we\u0026rsquo;ve known for over a decade that this claim is false. After sequencing the entire human genome, we know that all DNA has a function.\nSpontaneous Generation # Spontaneous generation is the idea that life can arise from non-living matter. It\u0026rsquo;s a very old idea that was debunked by Louis Pasteur in the 1800s, but it was still taught in schools as an example of abiogenesis in support of evolution.\nPride Goes Before Science # Scientists are constantly developing and marketing new theories that develop a loyal and devout following. Then a new generation of scientists comes along, pokes holes in the popular theory, and develops its own. Science, which is a fairly modern invention, operates on the same ancient rules of politics and warfare, all of which stem from the same basic problem, which is humans wanting to be their own god.\nThe Role of Bias and Peer Review in Science # This doesn\u0026rsquo;t mean science is bad or that it always yields wrong ideas. It just means its reliability depends on the people carrying it out. Peer review was supposed to help curb the influence of bias, but as we all know, it\u0026rsquo;s not hard to game a system, especially one in which there are financial rewards for pushing a certain agenda. Again, this is why it\u0026rsquo;s critical to locate and weigh the evidence for yourself.\nAs an aside, a huge red flag is when someone discourages you from doing your own research. During the COVID-19 pandemic, there were people mocking anyone who did their own research to decide the best way to handle their own personal risk. These mockers were essentially saying that the general public wasn\u0026rsquo;t qualified or smart enough to make this determination, and that everyone needed to just listen to \u0026ldquo;the experts.\u0026rdquo; As history has taught us, many of these \u0026ldquo;experts\u0026rdquo; were wrong.\nThere\u0026rsquo;s a lesson there for those who question Christianity on the grounds that \u0026ldquo;experts\u0026rdquo; say it\u0026rsquo;s false.\nThe Fallacy That Wasn\u0026rsquo;t # \u0026ldquo;God of the Gaps\u0026rdquo; vs. \u0026ldquo;Darwinism of the Gaps\u0026rdquo; # Atheists are fond of dismissing any explanation that credits God, claiming it\u0026rsquo;s the \u0026ldquo;God of the Gaps\u0026rdquo; fallacy. This misnamed \u0026ldquo;fallacy\u0026rdquo; is not a fallacy at all, but an instance of logical inference that everyone, including atheists, uses every day. The best way to understand this is with some examples.\nWhen attempting to explain a biological feature, such as eyesight, creationists will credit God with designing it. They\u0026rsquo;ll point to features that look designed and seem to have a purpose. When attempting to explain eyesight, atheists will credit evolution. In both cases, nobody directly observed how eyesight came to be. Both sides have to draw an inference. The creationist infers a Creator, while the atheist infers evolution. So if the creationist is guilty of the \u0026ldquo;God of the Gaps\u0026rdquo; fallacy, then the atheist is guilty of the \u0026ldquo;Darwinism of the Gaps\u0026rdquo; fallacy. Q.E.D.\nInference to an explanation is not a fallacy. But we have to go beyond a single inference and look at what theory best fits the evidence overall.\nPrevious: ← Part 2: Knowledge, Belief, and Logic Next: Part 4: Design, Explanation, and Worldview →\n","date":"7 July 2023","externalUrl":null,"permalink":"/apologetics/part-3-barriers-objections/","section":"Christian Apologetics: A Comprehensive Guide","summary":"","title":"Part 3: Barriers and Objections to Belief","type":"page"},{"content":"","date":"7 July 2023","externalUrl":null,"permalink":"/tags/philosophy/","section":"Tags","summary":"","title":"Philosophy","type":"tags"},{"content":"","date":"7 July 2023","externalUrl":null,"permalink":"/tags/science/","section":"Tags","summary":"","title":"Science","type":"tags"},{"content":"As some people tend to do with works that seem large and intimidating or just out of one\u0026rsquo;s grasp, I\u0026rsquo;ve procrastinated on writing this for many years. I can\u0026rsquo;t say for sure when I initially had the idea for writing an accessible but comprehensive guide on apologetics, which is the defense of not just the Christian religion (yes, it\u0026rsquo;s a religion, among other things), but also entailments thereof, such as the accuracy and reliability of the original Old and New Testament books, a relatively young earth, and literal Biblical Creationism.\nI realize that by flatly stating this, some people will stop reading, refusing to consider any evidence or arguments that don\u0026rsquo;t echo their existing biases. Others will read or skim, but will do so in a deliberately lazy fashion, not wanting to comprehend what they read, lest they find themselves persuaded. I\u0026rsquo;m not writing for them. I\u0026rsquo;m writing for those interested in the truth, and who are willing to carefully evaluate and think through evidence and arguments.\nComing Soon # Parts 4 and 5 are still in progress and will be published later.\nParts # Foundations — Introduction, what apologetics is, and the fundamental question at the heart of every discussion about God.\nKnowledge, Belief, and Logic — How beliefs form, the role of evidence and authority, epistemology, and the laws of logic.\nBarriers and Objections to Belief — Emotional barriers, selective skepticism, the limits of science, and abandoned naturalistic \u0026ldquo;facts.\u0026rdquo;\nDesign, Explanation, and Worldview — Evidence for design, limits of human explanation, worldview formation, and schools of apologetics.\nGod, Scripture, and Common Objections — The origin of God, the reliability of Scripture, and responses to the most common objections to Christianity.\n","date":"5 July 2023","externalUrl":null,"permalink":"/apologetics/","section":"Christian Apologetics: A Comprehensive Guide","summary":"","title":"Christian Apologetics: A Comprehensive Guide","type":"apologetics"},{"content":"","date":"5 July 2023","externalUrl":null,"permalink":"/categories/theology/","section":"Categories","summary":"","title":"Theology","type":"categories"},{"content":" ","date":"8 May 2023","externalUrl":null,"permalink":"/post/2023/music-monday-5-8-2023/","section":"Posts","summary":"","title":"Music Monday: Shadows — David Crowder Band","type":"post"},{"content":" ","date":"13 March 2023","externalUrl":null,"permalink":"/post/2023/music-monday-3-13-2023/","section":"Posts","summary":"","title":"Music Monday: Show You the Cross — Matty Mullins","type":"post"},{"content":" ","date":"6 February 2023","externalUrl":null,"permalink":"/post/2023/music-monday-2-6-2023/","section":"Posts","summary":"","title":"Music Monday: Breakthrough — Jason Stocker, Jake Espy, Kory Miller","type":"post"},{"content":"Don\u0026rsquo;t you hate it when you go to view an article and an obnoxious, enormous overlay pops right up in your face telling you to subscribe? And with what so many news sites charge, you\u0026rsquo;d think that they were selling a literary masterpiece. Well, relax, because you\u0026rsquo;re going to find out how to effortlessly bypass those annoying paywalls without spending a cent.\nTo bypass a paywall using any browser, with no extensions required, try https://12ft.io/.\nBypass Paywalls Clean for Chrome or Firefox/Mozilla works really well for a lot of sites. You can also add custom rules for sites that aren\u0026rsquo;t supported by default.\nFinally, running a site through https://archive.today usually works, and it has the added benefit of creating a snapshot of the site that you can bookmark or share.\n","date":"29 January 2023","externalUrl":null,"permalink":"/post/2023/bypassing-paywalls/","section":"Posts","summary":"","title":"How to Bypass a Paywall","type":"post"},{"content":" ","date":"23 January 2023","externalUrl":null,"permalink":"/post/2023/music-monday-1-23-2023/","section":"Posts","summary":"","title":"Music Monday: Skillet — Stars","type":"post"},{"content":" ","date":"16 January 2023","externalUrl":null,"permalink":"/post/2023/music-monday-1-16-2023/","section":"Posts","summary":"","title":"Music Monday: Faithful God","type":"post"},{"content":" ","date":"2 January 2023","externalUrl":null,"permalink":"/post/2023/music-monday-1-2-2023/","section":"Posts","summary":"","title":"Music Monday: KB — Rich Forever","type":"post"},{"content":"","date":"27 December 2022","externalUrl":null,"permalink":"/tags/2022/","section":"Tags","summary":"","title":"2022","type":"tags"},{"content":"If you\u0026rsquo;re trying to understand the concepts behind VLANs and subnets, you have my sympathy. There are some common misconceptions around these two terms that confuse a lot of people. Friends, it needn\u0026rsquo;t be so. The difference between a VLANs and subnets is very simple.\nVLANs and subnets are the same thing. # flowchart TD %% Define styles classDef l2 fill:#e6f3ff,stroke:#4a90e2,stroke-width:2px,color:#333 classDef l3 fill:#fff3e0,stroke:#f39c12,stroke-width:2px,color:#333 subgraph Router [Layer 3 - IP Subnet Boundary] GW(Default Gateway10.1.2.1) end subgraph Switch [Layer 2 - Broadcast Domain / VLAN] Port1[Switch Port 1] Port2[Switch Port 2] Port3[Switch Port 3] end HostA(Host A10.1.2.10) HostB(Host B10.1.2.11) GW --- Switch Port1 --- HostA Port2 --- HostB class Router,GW l3 class Switch,Port1,Port2,Port3 l2 A VLAN is a virtual LAN, and a LAN is a subnetwork, a.k.a. a subnet. It\u0026rsquo;s a layer 2 (data link layer) concept.\nVLAN = subnet = broadcast domain (in Ethernet).\nTo understand this, refer to the ISO/IEC papers on the OSI model . People used the term \u0026ldquo;subnet\u0026rdquo; to refer to Ethernet LANs years before IP even existed. Also, if layer 3 is the network layer, then a subnetwork would logically exist at layer 2. In his book Patterns in Network Architecture John Day wrote of the OSI model:\n[T]he primary function of the network layer was to make the transition between the subnetwork-dependent protocols and provide a service that was independent of the subnetwork technology.\nThe subnetwork is a layer 2 concept in OSI. Not layer 3.\nSubnetting and a subnet are different things. # What people call \u0026ldquo;subnetting\u0026rdquo; is formally called classless addressing. At layer 3, we have IP networks that can be subnetted, divided into contiguous blocks. The size of each block is determined by a subnet mask. For example, the network 10.1.2.0 with the subnet mask 255.255.255.0 would together be what\u0026rsquo;s colloquially called an \u0026ldquo;IP subnet\u0026rdquo;. A L2 subnet is not the same as an IP subnet.\nThe subnet mask determines whether a given IP address is in the same broadcast domain or a different one. Using the preceding example, 10.1.2.1 and 10.1.2.2 would be in the same subnet (i.e. the same VLAN or broadcast domain). 10.1.2.1 and 10.9.9.9 would be in different subnets (a.k.a. VLANs).\nHaving too many devices in a subnet/VLAN can cause performance problems. One badly behaving NIC or misconfigured switch can bring down the whole subnet. Devices in different subnets (VLANs) can communicate at layer 3 if the subnets are connected via a router. Routing allows you to scale a network beyond a few hundred devices. In a small office network, you may be fine having everything in one subnet (switching). In a medium sized office network, using multiple small VLANs connected via routers (routing) is best.\n","date":"27 December 2022","externalUrl":null,"permalink":"/post/2022/vlans-are-subnets/","section":"Posts","summary":"","title":"VLANs vs. Subnets","type":"post"},{"content":" ","date":"26 December 2022","externalUrl":null,"permalink":"/post/2022/music-monday-12-26-2022/","section":"Posts","summary":"","title":"Music Monday: Matty Mullins - Noel","type":"post"},{"content":"As Christians we are not under law, but under grace (Romans 6:14). Paul said, \u0026ldquo;All things are lawful for me, but all things are not expedient: all things are lawful for me, but all things edify not\u0026rdquo; (1 Cor. 10:23) We should not become legalistic about cussing or let it interfere with our fellowship with other Christians. Especially considering that what does or doesn\u0026rsquo;t constitute a cuss word is largely cultural (e.g. some might think \u0026ldquo;crap\u0026rdquo; or \u0026ldquo;bloody\u0026rdquo; is a cuss word), we need to be guided by the \u0026ldquo;law of love.\u0026rdquo;\nPaul dealt with a very similar issue in his day, except instead of cussing the issue was eating meat sacrificed to idols. He said,\nFood will not commend us to God. We are no worse off if we do not eat, and no better off if we do. But take care that this right of yours does not somehow become a stumbling block to the weak. For if anyone sees you who have knowledge eating in an idol\u0026rsquo;s temple, will he not be encouraged, if his conscience is weak, to eat food offered to idols? And so by your knowledge this weak person is destroyed, the brother for whom Christ died. Thus, sinning against your brothers and wounding their conscience when it is weak, you sin against Christ. Therefore, if food makes my brother stumble, I will never eat meat, lest I make my brother stumble. (1 Cor. 8:8-13)\nThe issue of eating meat sacrificed to idols was not a moral issue. There was nothing wrong or sinful about it. But, because seeing Paul eating in an idol\u0026rsquo;s temple might cause one of his fellow believers to stumble, Paul chose to relinquish some of his freedom in Christ for the sake of his brother. Not out of guilt or obligation, and certainly not because he was afraid of offending people, but out of love.\nSome Christians only cuss in limited contexts, including around close friends. The question to ask then is are you causing your friends to stumble? Perhaps they may seem cool with it, but on the inside are wishing that you would refrain from saying some words you do. Or maybe they really don\u0026rsquo;t care. Maybe one of them doesn\u0026rsquo;t want to look like a stick in the mud and would never say anything, unless you and he were talking one-on-one about it.\nIf you\u0026rsquo;re sure you\u0026rsquo;re not causing your friends to stumble, then the next question is, are you causing yourself to stumble in any way by cussing? In my life I have found that using certain cuss words actually leads me into other thoughts that I wouldn\u0026rsquo;t have had otherwise. Perhaps it\u0026rsquo;s as simple as this: you use a few cuss words, and that gives one of your friends the \u0026ldquo;go-ahead\u0026rdquo; to start talking about someone in an inappropriate way, and that leads to other sins. Or if you have any friends who think Christians are all fakes, seeing a Christian cuss might perpetuate that belief and become a stumbling block to their salvation.\nYears ago I was on a Christian IRC chat channel and someone told me about how they had to change their nickname because it might give some people the wrong idea. The nickname was \u0026ldquo;BJ.\u0026rdquo; At the time, I thought it was the stupidest reason for changing a nickname. I even argued a little bit about the idea. It seemed such a stretch to think that the name \u0026ldquo;BJ\u0026rdquo; would make someone stumble. Why should \u0026ldquo;BJ\u0026rdquo; have to change his/her name because it might cause someone to stumble? Likewise Paul could have said to the Corinthians, \u0026ldquo;If someone is made to stumble by me, too bad.\u0026rdquo; But he didn\u0026rsquo;t. He put his fellow Christians before his own freedom and his own rights out of love and concern for their relationship with Christ.\n","date":"23 December 2022","externalUrl":null,"permalink":"/articles/should-christians-cuss/","section":"Articles","summary":"","title":"Should Christians Cuss?","type":"page"},{"content":"As co-author of the official AWS Certified Solutions Architect Study Guide: Associate (SAA-C03) Exam, 4th Edition, I\u0026rsquo;m pretty picky when it comes to how I spend my time watching video training courses.\nThe Problem with Most Video Training # I\u0026rsquo;ve watched a lot of videos that are designed to help you pass the Solutions Architect exam, and although some of them are good, most of them suffer from one of three major problems.\nThey\u0026rsquo;re boring—The pace is too slow, there\u0026rsquo;s not enough hands-on, the instructor has a monotone voice, etc. Training should be interesting. Not goofy or gimmicky or full of unnecessary visuals and bad jokes, but genuinely interesting.\nThey\u0026rsquo;re too freaking long—You don\u0026rsquo;t need a 15 minute overview of what an instance is, do you? No. Do you need to be told why certification is important? No, because if you didn\u0026rsquo;t, you wouldn\u0026rsquo;t be watching a video on how to get certified! The unnecessary little intros and summaries add up when you\u0026rsquo;re trying to cover dozens of different AWS services.\nThey spend too much time on the wrong stuff, not enough time on the right stuff—Certification exams are always biased towards a certain technology or service. The same is true of AWS. Flagship IaaS services (EC2 compute, VPC networking, storage) are going to get the most attention on an exam, so they should consume the bulk of your time. Any course that spends more than 5 minutes walking through the exam blueprint is wasting your time. And any course that spends an equal amount of time on every exam topic is a red flag that the course designer has not actually taken the exam!\nThe Best SAA-C03 Courses # So what courses are good for studying SAA-C03? Obviously you know I\u0026rsquo;m going to promote my own courses. But don\u0026rsquo;t just listen to me. Read what others who have taken these courses have to say:\nArchitecting for Reliability on AWS # I am on track to get my AWS Solutions Architect Associate cert. This course by Ben Piper is really helping me get to this cert, thanks Ben!!\u0026hellip; Feels fresh and updated, great job!!\nAs always Ben Piper nails it when it comes to explaining networking\nArchitecting for Security on AWS # This is one of the best AWS courses that I had ever taken. This one course will take you on a complete journey of locking the AWS resources using various methods. Its a one stop shop for AWS Security.\nBen Piper delivers! The reason I give such high praise is that he was able to provide accurate and detailed explanations in his videos, that are easy for one to follow.\nExcellent 10/10. Easy to follow by replicating the actions on my own account on a second screen.\nthe demos and tic-tac-toe app were fantastic. no time wasted configuring unrelated topics.\nArchitecting for Operational Excellence on AWS # I just completed a second PluralSight course from you, Operational Excellence. I really appreciated them and consider you and one other author the best of the courses I have taken so far. So I want to say Thanks.\nChad Mitchell\nHi Ben,\nFirst a compliment 🙂 I\u0026rsquo;m following your course having done many AWS courses on Pluralsight, and I\u0026rsquo;m certainly enjoying yours the most.\nMatt Shickell\nLayoffs, Downsizing, and Certifications # In a time when tech companies are laying off really good, smart employees, the people that are certified are going to come out on top. Here\u0026rsquo;s how this normally works:\nExperience gets your resume looked at\nCertifications get you an interview\nCertifications + experience get you hired\nExperience is important, but as I\u0026rsquo;ve said before, certifications are synthetic experience. They are a substitute for experience you may not have, and they add to the experience you do have. You can\u0026rsquo;t go wrong getting a widely recognized IT certification.. ever.\n","date":"17 December 2022","externalUrl":null,"permalink":"/post/2022/best-aws-saa-c03-training-courses/","section":"Posts","summary":"","title":"What are the best AWS Certified Solutions Architect Associate (SAA-C03) Video Training Courses? (Subtitle: Why Does So Much Training Stink?)","type":"post"},{"content":"Dr. Van Meter is a pediatric endocrinologist and clinical researcher who tells the tragic story of a boy whose life was ended beacuse of a terrible medical scam driven by junk science. Watch it here. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .\n","date":"29 November 2022","externalUrl":null,"permalink":"/post/2022/terrible-fraud/","section":"Posts","summary":"","title":"The Terrible Fraud","type":"post"},{"content":"If you\u0026rsquo;re not familiar with RSS (really simply syndication), it\u0026rsquo;s quick a way to get all of your favorite websites and social feeds in one place. It can also help save your sanity because you don\u0026rsquo;t have to suffer through ads while scrolling through multiple sites.\nYou just download an RSS program and point it to the various feeds you want, and it pulls everything into one place. QuiteRSS and FeedReader are two good, free choices.\nGetting an RSS Feed # For most websites, the RSS feed is just the website URL followed by a /rss, /feed, index.rss, or index.xml. For example, the RSS feed for my site is https://benpiper.com/index.xml. You just add the URL to your RSS program and you\u0026rsquo;re set.\nHow to get an RSS Feed from a Twitter Account # Twitter doesn\u0026rsquo;t natively offer RSS feeds. But there\u0026rsquo;s a workaround thanks to the ingenious Twitter frontend, Nitter.\nOpen your RSS reader\nAdd the feed in the following format: https://nitter.net/twitterusername/rss.\nSo if you feel moved to add the Babylon Bee (who wouldn\u0026rsquo;t), just add https://nitter.net/thebabylonbee/rss to your RSS reader. Voila! Bee tweets all day long, and you don\u0026rsquo;t ever have to subject yourself to the rest of awful Twitter.\nThat\u0026rsquo;s it.\n","date":"27 November 2022","externalUrl":null,"permalink":"/post/2022/how-to-get-rss-feed-twitter-account/","section":"Posts","summary":"","title":"How to get an RSS Feed from a Twitter Account","type":"post"},{"content":"","date":"27 November 2022","externalUrl":null,"permalink":"/tags/rss/","section":"Tags","summary":"","title":"Rss","type":"tags"},{"content":"","date":"24 November 2022","externalUrl":null,"permalink":"/tags/2011/","section":"Tags","summary":"","title":"2011","type":"tags"},{"content":"If you ask an atheist, \u0026ldquo;Where did the universe come from?\u0026rdquo; you might get any number of different answers.\nOne atheist might say, \u0026ldquo;It\u0026rsquo;s always been there,\u0026rdquo; which of course is not possible because the universe has only a finite amount of usable energy. The law of conservation of energy and entropy, you know. The Big Bang? Nope, that\u0026rsquo;s out too.\nAnother atheist might say, \u0026ldquo;We don\u0026rsquo;t know, but just because we don\u0026rsquo;t know doesn\u0026rsquo;t mean it was God. We have to keep looking.\u0026rdquo;\nNow this answer leads to a much more interesting discussion. What the atheist here is saying is that he believes the answer to the question has not yet been discovered. That means the atheist is comfortable with pretty much eliminating 6,000 years of human knowledge from the possibility of holding the answer.\nThe atheist is not at all interested in the answer. He just wants to hold to his belief that there is no God, and the easiest way to do this is to claim ignorance of the origin of the universe while simultaneously claiming that nobody else knows the answer either!\nRead that again. The atheist positively claims that no one knows the origin of the universe. In saying this, he assumes absolute omniscience over the entirety of humanity, both past and present. He boldly admonishes all theists that they do not know the answer either! He makes himself the arbiter of what is and is not known. In essence, the atheist makes himself out to be greater than God.\n","date":"24 November 2022","externalUrl":null,"permalink":"/articles/ask-atheist-where-the-universe-came-from/","section":"Articles","summary":"","title":"Ask an Atheist Where the Universe Came From","type":"page"},{"content":"","date":"24 November 2022","externalUrl":null,"permalink":"/tags/creation/","section":"Tags","summary":"","title":"Creation","type":"tags"},{"content":"","date":"24 November 2022","externalUrl":null,"permalink":"/tags/evolution/","section":"Tags","summary":"","title":"Evolution","type":"tags"},{"content":"","date":"23 November 2022","externalUrl":null,"permalink":"/tags/scripting/","section":"Tags","summary":"","title":"Scripting","type":"tags"},{"content":"How do you find a needle in a haystack?\nSuppose you have a big data set consisting of various types of data including phone numbers, email addresses, user identifiers, addresses, etc. Within this dataset you need to pick out specific strings. Normally this would be easy:\ngrep -air -e mystring -e anotherstring and you\u0026rsquo;re done, right? Not so fast.\nIf the strings you are searching for are generic, common strings that appear in the dataset hundreds or thousands of times, you may end up with a lot of false positives. This is especially true when you\u0026rsquo;re searching on partial strings, like a few digits of a phone number or a few characters from an email address. Let\u0026rsquo;s look at how you can use grep to find what you\u0026rsquo;re looking for while cutting down on the noise.\nThe Phone Number # Let\u0026rsquo;s say you have a partial phone number: 470-xxx-xx32. Now look at the following grep command:\ngrep -Eairon '.{0,100}470[0-9-]{5,7}32.{0,100}' \u0026gt; ~/Documents/470xxxxx32.txt\nThe number could be formatted as above, or with no dashes, so there could be between 5 and 7 digits or dashes between the 470 and the 32 (470[0-9-]{5,7}32). This pattern is an extended regex or REGular EXpression (-E).\nWe want to make sure grep outputs only up to 100 characters before and after each match (-o and .{0,100}), as well as the line number (-n). This will make it easier to go back later and look at the context of the matches.\nUsing the preceding command, grep will recurse (-r) and search all files starting in the current directory and output the results to a file (\u0026gt; ~/Documents/470xxxxx32.txt). You can then take the output file and grep it further to find what you\u0026rsquo;re looking for. Note that redirecting the output to a file will mean you will not see the output on screen. Remove the redirect if you don\u0026rsquo;t want it.\nKeep in mind that this will still match non-phone strings, such as long random identifiers (e.g. 47006776632). If you\u0026rsquo;re still getting too many false positives, you can filter more aggressively by excluding 0 and 1 from the first digit of the phone number prefix using the following regex.\ngrep -Eairon '.{0,100}470[2-9-]{1,2}[0-9-]{4,5}32.{0,100}'\nThis would match 4705551232 but not 4700551232 or 4701551232.\nThis is better, but it\u0026rsquo;s still going to match long strings of digits. This is where we need to think about how the phone numbers are stored in our datasets. In a mixed structure dataset, fields may be delimited by commas, single or double quotes, tabs, or even semicolons.\nSome trial and error is needed here. Commas are a common delimeter, so you could try the regex:\ngrep -Eairon '.{0,100},470[2-9-]{1,2}[0-9-]{4,5}32,.{0,100}'\nThe command is almost identical to the one before it, but notice the commas before 470 and after the 32.\nTo try a double quote delimeter, you\u0026rsquo;ll need to escape it using a backslash (\\), like so:\ngrep -Eairon '.{0,100}\\\u0026quot;470[2-9-]{1,2}[0-9-]{4,5}32\\\u0026quot;.{0,100}'\nTo use a single quote delimeter, you\u0026rsquo;ll have to wrap the entire search string in double quotes and escape the single quotes. There\u0026rsquo;s no way to escape a single quote within a single quoted string.\ngrep -Eairon \u0026quot;.{0,100}\\'470[2-9-]{1,2}[0-9-]{4,5}32\\'.{0,100}\u0026quot;\nWhat about a tab delimeter? Just put an actual tab character in the search sting. Ctrl-V + Tab should work.\ngrep -Eairon '.{0,100} 470[2-9-]{1,2}[0-9-]{4,5}32 .{0,100}'\nThe Email Address # Now suppose you\u0026rsquo;re looking for an email address with the pattern g*d@gmail.com where * is an unknown number of characters. This one is trickier because unlike a phone number, email addresses don\u0026rsquo;t follow a predictable format. We\u0026rsquo;ll have to make some assumptions about the length of the address.\ngrep -Eairon 'g.{2,15}d@gmail\\.com'\nThis matches any string starting with \u0026lsquo;g\u0026rsquo;, followed by anywhere from 2 to 15 characters (the regex .{2,15}), followed by a \u0026rsquo;d@gmail.com\u0026rsquo;. The period must be escaped.\nThe Search Within a Search # If you suspect that the mystery phone number and email might be connected, you can try grepping against the output of the phone number search. For example:\ngrep -Eairon '470[2-9-]{1,2}[0-9-]{4,5}32' \u0026gt; ~/Documents/470xxxxx32.txt\ngrep -Eairon 'g.{2,15}d@gmail\\.com' ~/Documents/470xxxxx32.txt\nBTW, if you want to view an entire matching line of a file, you can use the sed command:\nsed -n '116p' ~/Documents/470xxxxx32.txt\nThis will display line 116 of the file.\nFiles with Long Lines # Some datasets have extremely long lines, as in billions of characters on a single line, making them difficult to browse without a lot of horizontal scrolling. This is especially true of SQL database dumps. What we need is a way to jump straight to the interesting string. Here\u0026rsquo;s how we do it.\nLet\u0026rsquo;s say database.sql is a single-line text file gigabytes in length. Consider the following command:\ngrep -Eoairnb 'ohthatsinterestingtellmemore@gmail\\.com' database.sql\nThe -b flag prints the byte offset from the beginning of the file, allowing us to jump straight to the start of the match. Suppose grep returns an offset of 4211445779. We want to see 100 characters before and after the start of the matching string, and to do that we\u0026rsquo;ll use the dd command:\ndd if=database.sql ibs=1 skip=4211445679 count=100\nif is the input file.\nskip is the byte offset to start reading at. Notice that we subtract 100 from the offset reported by grep.\ncount is the number of bytes to read after the offset.\nThe command should display your match in context.\nAs with all things search related, you\u0026rsquo;ll need to go through some trial and error, but these examples should be enough to get you on the right track.\nListen to this article # ","date":"23 November 2022","externalUrl":null,"permalink":"/post/2022/grep-search-large-datasets/","section":"Posts","summary":"","title":"Using Grep Recursive and Regex to Search Big Data Sets","type":"post"},{"content":"","date":"27 October 2022","externalUrl":null,"permalink":"/tags/binary/","section":"Tags","summary":"","title":"Binary","type":"tags"},{"content":"Subnetting has traditionally been the bane of every networking student\u0026rsquo;s existence. But it doesn\u0026rsquo;t have to be. I\u0026rsquo;ll show you a quick and simple way to subnet in your mind in just seconds. Once you see how it\u0026rsquo;s done in this video, you\u0026rsquo;ll never need to go back to paper and pen or any of those online subnetting calculators. Check it out.\n","date":"27 October 2022","externalUrl":null,"permalink":"/post/2022/how-to-subnet-in-your-head/","section":"Posts","summary":"","title":"How To Subnet In Your Head","type":"post"},{"content":"","date":"27 October 2022","externalUrl":null,"permalink":"/tags/subnetting/","section":"Tags","summary":"","title":"Subnetting","type":"tags"},{"content":"Technology moves at the speed of light, literally. The electrical impulses that carry information across the Internet to your mobile device or computer travel at a speed of about 186,000 miles per second — the speed of light. This means that information can travel from Atlanta, Georgia to Melbourne, Australia in 1/20 of a second. To put this in perspective, it takes about seven times as long to blink your eyes just once. That's how fast technology moves. So it comes as no surprise that a lot of businesses instinctively jump on the latest technology, hoping it will help them grow or improve in some fashion — whether that means expanding into new markets, boosting sales, improving productivity, or even delivering products and services in record time. They think that because technology moves at the speed of light, adopting the right technology will help their business grow at the speed of light. But nothing could be further from the truth.\nBusiness at the speed of light never starts with technology. In fact, technology can slow your organization down to a crawl and cost you more time and money than it's worth. If you want to grow your business at the speed of light — whether that means increasing market share, retaining more customers, attracting better employees, becoming or remaining an industry leader, or something else — you have to start somewhere much more basic. You have to start with your specific business goals, then use technology in a carefully calculated way that will not only achieve those goals, but do so at a substantial return on time and money.\nEven \u0026ldquo;Technology\u0026rdquo; Companies Didn't Start with Technology # Now I know that it seems obvious, even cliché to start with goals. But don't gloss over this section just because you think you've heard it all before. Think of some of the most wildly successful \u0026ldquo;technology\u0026rdquo; companies you are familiar with. Amazon, Google, Apple, and maybe even Wal-Mart come to mind. Contrary to popular belief, these companies' successes didn't start with technology. In fact, when they started, much of the technology that is ubiquitous today didn't even exist. At best, it was experimental and reserved only for the most elite geeks and engineers. These companies started with something much simpler: specific, measurable, coherent, and valuable business goals. Technology was simply the tool they used to achieve those goals. The lesson here is simple but profound: technology should never drive goals. When you think about it, this makes a lot of sense. Companies that allow their goals to be driven by technology are always going to be behind because they're depending on someone else's innovation. Companies that start with specific goals are the ones that innovate.\nWell Developed Goals Always Trump Technology # Apple is one such example of a company that started with specific goals and is now doing billions of dollars in business at the speed of light. Today, Apple is known for the iPad and the iPhone. But both of these devices are based on an earlier, much simpler device called the iPod. When Apple introduced the iPod, then-CEO Steve Jobs said that the goal of it was to allow people to carry around all their music without having to lug around a bunch of binders filled with CDs. Jobs didn't use any technological jargon in describing the iPod because he didn't need to. The technology was only of secondary importance. What made the device truly attractive was the goal it fulfilled. The iPod went on to become the top-selling digital music player of all time, but it certainly wasn't the first. Prior to the release of the iPod, other digital music players existed, but went almost entirely unnoticed. One of the digital music players I owned was made by RCA, an American company that was a technological giant in the early 20^th^ century and had seen great success selling television sets and vinyl record players. The RCA digital music player I owned only held a handful of songs, and it was slow and cumbersome to add music to. I personally liked the device because of the \u0026ldquo;geek factor,\u0026rdquo; but it was clearly not designed with the intent of replacing one's entire CD collection. It was technology for technology's sake.\nJust Having Goals Isn't Enough # If you're already putting goals before technology, you're on the right track. But just having goals isn't enough. What conventional wisdom on goal-setting largely neglects is the goal-setting process. Worthwhile goals aren't arbitrary. They aren't pulled out of a hat, voted on, or brainstormed in a strategy retreat session in the Swiss Alps. Arbitrary goals are like joyriding. At first, it seems fun and exciting. But after a while, you get bored and want to actually go somewhere and do something meaningful or productive. A common mistake in the goal-setting process is brainstorming goals then running with them. Brainstorming can be useful to spark ideas for goals, but that's about it. When you brainstorm goals, the goals that you brain comes up with are not fully fleshed out. They may be contradictory, unclear, or simply not worthwhile. Not exactly the characteristics you need for achievable goals. In order for a business goal to be worthwhile, it has to have four characteristics:\n1. Specific # Imagine we're at a restaurant, sitting at a table together. I ask you to pass me the glass. What do you do? You don't know if I'm talking about a glass of water, the glass salt shaker, the glass pepper shaker, or the glass candle globe. Instructions that are not specific cannot be carried out until they're clarified. One of the things perpetuating the common myth that \u0026ldquo;execution is hard\u0026rdquo; among business leaders is the utter lack of clear and specific goals. If your goal isn't specific enough to communicate to another person easily, it's not specific, and it's not a real goal. Make sure your goals can be easily and concisely communicated. A good indicator that you have a specific goal is that the average high school graduate can understand it easily.\n2. Coherent or Complementary # All of your goals have to be in agreement with one another. If you take two steps forward and two steps back, you haven't broken even, you've wasted time. It's not uncommon for an IT organization to implement so many security systems and procedures in order to protect the business from system downtime that it actually slows business processes to a crawl. Make sure your goals don't step on each other. Ideally, goals should not only agree with, but complement one another. The achievement of one goal should make the achievement of other goals that much easier.\n3. Measurable # A goal that is never complete is a time vampire. Eventually, it will drain you emotionally, physically, and usually financially. A goal has to have a specific point at which it is complete. Otherwise, you may end up spending much more time or money than you had anticipated and budgeted for. When a goal is measurable, you are free to definitively stop execution at a predetermined point and move on to the next goal.\n4. Valuable # Finally, goals have to be valuable. A goal that has no known value is a goal that has zero return-on-investment (ROI). If you don't know the real tangible and intangible value of a goal, you won't be able to justify it to yourself or others. Not being convinced of the value of your own goals is one of the biggest reasons for failure. Viscerally, you know that if a goal isn't valuable, it is a complete waste of time, and you simply won't be able to put your heart into it, let alone get others to put their hearts into it.\nYour Values: The Source of Your Most Valuable Goals # This may come as a shock: In order for business goals to be truly valuable, they have to be based on your values and the values of your organization. Values are, as you might imagine, the ideals, people, and things that you value. Some examples include honesty, integrity, health, service, and quality. Contrary to conventional wisdom, organizational values are not a sideshow or a \u0026ldquo;nice-to-have,\u0026rdquo; but they're often treated that way because businesses don't really know what to do with them. Values don't come after or alongside goals, values are the one and only source of all valuable goals. Later on I'll show you how to take your values and translate them into immensely valuable business goals that will propel your business forward at the speed of light.\nTo understand the relationship between your values (plural) and value (singular), imagine you're eating at a restaurant. When the server takes your meal order, he gives you the option of having either a baked potato or steamed vegetables as your side. The baked potato comes at no charge, but the vegetables cost extra. Assuming one of your core values is good health, which do you choose? If you pay extra to get the vegetables, you're showing that you value your health. It costs a little extra, but you're willing to pay it precisely because good health has value to you. Hence, your values determine what you value — that is, what you're willing to invest time and money in.\nWhen you set your goals based on your values, you're driven to achieve them, and you're satisfied when you do. But what if you set your goals based on something other than your values? Suppose that instead of ordering steamed vegetables, you order a baked potato because you've had a bad day and want some comfort food. Aside from feeling a little guilty, you may trigger cravings that drive you to consume more sugar or alcohol than you should. You may start to feel too tired to work out or finish a task you had planned to complete afterwards. When you make decisions or set goals on something other than your values, you end up with goals that contradict your values, contradict each other, and make you miserable.\nOne of Amazon's core values is \u0026ldquo;Customers First.\u0026rdquo; (Note that this is not a goal by itself, as it doesn't meet the criteria for goals above.) Every successful goal Amazon works toward is based on that value. I have used Amazon for decades and can honestly say I've never had a problem with their customer service. That is no accident. Amazon's \u0026ldquo;Customer First\u0026rdquo; value quite literally drives everything they do.\nOne of Wal-Mart's core values is having the lowest prices anywhere. This is not a cute slogan or rallying cry. They are so adamant about expressing this value that they are willing to lose profits to match competitors' prices and make enemies of labor unions by cutting employee benefits and hours — all in the name of providing the lowest prices anywhere. Wal-Mart has gotten into a lot of trouble over the years for sticking to this core value, and whether you agree with them or not, one thing is incontrovertible: Wal-Mart remains of the most successful businesses in history. The lesson here is clear: Make sure everything you do is based on your values, and don't abandon them for anything.\nTranslating Lofty Values Into Concrete Goals # The process of translating those values into specific, measurable, coherent, and valuable goals is simple but vitally important. Without a set of crystal clear goals that you have developed based on your values, no amount of technology can help you grow your business at the speed of light. It goes without saying that there are infinite possibilities for goals that are based on your values. Narrowing down a universe of possible goals into a small number of achievable ones is a fun and rather quick process. Be prepared to arrive at some very exciting goals in a very short amount of time. After all, this is about growing your business at the speed of light, not at the speed of the Pony Express.\nJust Because Technology Can Doesn't Mean It Should # One of the biggest mistakes businesses make is using technology to achieve their goals. Yes, you read that right. It is a mistake to use technology by default just because it's available and can help you achieve your goals. Many years ago while doing some technical work in a small office, I overheard an older man getting onto a younger man for using a flathead screwdriver to pry the lid off a metal can of paint because it damage the screwdriver or the lid. The older man had a point. The screwdriver would do the job, but it might damage the screwdriver or the lid, making it impossible to reseal the paint can and causing the paint to dry out. I wouldn't be surprised if the older man knew from past experience that it would be cheaper and quicker to just locate a pry bar than to replace the screwdriver or purchase a new can of paint. When you use technology — which is a tool — in ways it wasn't intended, you may be able to accomplish your goal, but there is often some costly fallout. Technology should be used only if it can help you achieve your goals and deliver a substantial return on time and money.\nWill Technology Make Your Business Awesome or Apoplectic? # If you've been involved in or close to the IT world for some time, you know that even when technology is used successfully to achieve a business goal, it often costs a lot more money and takes a lot more time than anyone anticipated. The reason this happens is quite simple: nobody sat down and correctly calculated the return-on-time (ROT) or the return-on-investment (ROI). It's not enough for technology to just achieve your business goals. In order to grow your business at the speed of light, technology has to help you achieve your goals in a way that delivers a substantial return on both time and money.\nROI is a measure you're already familiar with. It's simply the difference between how much money you invest and how much value you get in return. But what you may be surprised to know is that the perceived ROI of technology is often completely wrong. This could be due to ROI being crudely estimated, guesstimated, or — in the best case — simply miscalculated. But it's still wrong. This is unfortunate because the budget of an IT organization is greatly influenced by the ROI it can show to the business. IT organizations that are given a perpetually low budget are either not achieving goals well, or they're grossly underestimating the ROI of what they bring to the table. IT organizations that have a substantial budget generally not only achieve business goals well using technology, but accurately calculate their contribution to achieving those goals. I should note here that ROI isn't just a financial measurement. There are intangibles that must be considered as well — things such as customer retention, employee satisfaction, reputation, and even relationships. These intangibles quite often carry more business value than financial measures. Furthermore, they can and should be be quantified.\nTime: The Only Non-Renewable Resource # But ROI is only half the story. The other half is the one that is almost universally neglected by IT: return-on-time or ROT. If ROI is the difference between how much money you invest and how much value you get in return, ROT is the difference between how much time you invest and how much value you get in return. In business, speed is critical. Nothing illustrates this point better than the Android vs. iPhone battle for the smartphone market. Android phones actually pre-date Apple's iPhone, but Apple moved quickly and got the iPhone to market first. There were other factors in play, to be sure, but there's no doubt that Android would have taken a much larger share of the market had it released something rather than nothing. Even the first iPhone was far from perfect. It had no downloadable apps and was riddled with problems. But that didn't stop people from shelling out $600 for the phone by the thousands. Speed wins.\nThe Hidden Time-Costs of Technology # Most businesses and IT organizations don't measure how much time technology consumes versus how much value the business gets from it. Whenever a business uses technology in pursuit of a goal, there are five common time-costs that must be considered:\n1. Limited Future Opportunities # Once technology is implemented in an organization, it becomes inflexible and can actually interfere with the business' ability to quickly achieve new goals in the future. In The Technology Paradox: How Technology Can Slow Business Down, I discuss exactly why this is so and, more importantly, how it can be avoided.\n2. Learning Curve # It takes time for anyone using a new technology to get familiar with it and learn how to operate it. Think back to the first time you used a smartphone. Some of the tasks that now take you seconds probably took you a couple minutes or more to figure out. That initial learning curve is negligible when it affects one person, but when it affects an entire organization and its customers, the impact can be incredibly costly. And although the time to overcome a learning curve is temporary, it is real and needs to be taken into account.\n3. Performance # Since technology operates at the speed of light, it's easy to assume that new technology is going to keep up with us and be as fast as we need it to be. The reality, however, is that there is an upper limit to how fast even the fastest technology can perform (I'm continually baffled at how long it takes a brand new $10,000.00 server to boot up.) How fast a system can perform and how much it can handle all need to be considered when calculating ROT.\n4. Imposed Operational Changes # Adopting new technology sometimes requires changing the way the business operates. This is not always ideal, but it is reality. For example, switching from an old analog cell phone to a modern smartphone required you to change the way you dial telephone numbers. It was faster to dial a telephone number by hand on a 20-year old cell phone than it was on a brand new smartphone. That\u0026rsquo;s changed since then with voice recognition making it possible to dial numbers just by speaking. But it took ten years for smartphones to get to that point. Never assume that newer means faster. Quite often, the opposite is true.\n5. IT Resources # It is commonplace for IT organizations to spend countless hours tweaking, troubleshooting, and installing software and systems that contribute little if anything to sound business goals. Technology that requires a lot of \u0026ldquo;babysitting\u0026rdquo; by IT can potentially kill the ROT of a particular technology, even if that technology would otherwise help to achieve your business goals. IT's only job is to make a significant contribution to sound business goals. If implementing new technology will require IT to spend countless hours of fiddling and tinkering, that time-cost must be taken into account.\nAssessment Quiz # Is your technology helping your business grow at the speed of light, or is it holding you back? Answer the questions below to find out. Next to each question is a numeric value, either +1 or -1. For each question that holds true for your business, add that number to the total to get your score.\n1. Our business goals are clear and easy to communicate (+1)\n2. They're consistent and not in conflict with one another (+1)\n3. They're measurable such that everyone can tell whether progress is being made (+1)\n4. We know exactly what each goals is worth in terms of tangible and intangible value (+1)\n5. We sometimes use technology in a way that does not substantially contribute to our goals (-1)\n6. Our technology is delivering a measurable return-on-investment (+1)\n7. Our technology is delivering a measurable return-on-time (+1)\n8. We utilize technology without first seeing whether no-tech or low-tech alternatives are more suitable (-1)\n9. Our business decisions are influenced by what technology our competitors are using (-1)\n10. We look at new technology and ask, \u0026ldquo;What can we do with this?\u0026rdquo; (-1)\n11. We try to squeeze every drop of value from our existing technology investments (-1)\n12. Our customers or employees are frustrated by some aspect of our technology (-1)\n13. The business as a whole views technology as a \u0026ldquo;necessary evil\u0026rdquo; (-1)\n14. When it comes to projects involving technology, things always take longer than expected (-1)\n15. We adhere to \u0026ldquo;best practices\u0026rdquo; and non-mandatory industry standards, even if it costs more (-1)\n16. We get rid of unneeded data and hardware that we are not legally required to retain (+1)\n17. Our technology is extremely flexible and adaptable to changing needs (+1)\n18. All of our business goals are based on our values and not on what others are doing (+1)\n19. We value speed over perfection (+1)\n20. We don't allow trends or personal agendas to dictate how we use technology (+1)\n21. We believe using the latest technology is required to maintain a competitive edge (-1)\nScoring # -10 to 0: Technology is holding you back. If your business is a ship, technology is the anchor that's keeping you from moving. When you let technology drive your business, you'll always be dependent on someone else's innovation and your growth will be stunted. Start by developing your own business goals based on your values (and \u0026ldquo;technology\u0026rdquo; is not a value), then get rid of any technology that doesn't help you achieve them.\n0 to 6: Your business is highly dependent on technology in day-to-day operations, but it's not helping you achieve valuable business goals. Many businesses that fall into this range spend an inordinate amount of time and money on technology to make up for a lack of sound business goals. Technology does not easily adapt to rapidly changing business needs.\n6 to 9: You put goals before technology, and you carefully determine whether technology will help you achieve them before making an investment. But you may still be overusing technology, using it for the wrong reasons, or using it without first considering the total return-on-investment and return-on-time. Businesses in this range typically have highly skilled IT organizations that expend resources on pet projects that don't meaningfully contribute to business goals.\n9 to 11: Business at the speed of light! You have sound business goals and you carefully leverage technology to achieve them, but only after determining that technology will provide the best return on time and money. Your IT organization is singularly focused on achieving your objectives, and is careful to implement technology in a way that remains flexible and adaptable to rapidly changing needs.\n","date":"4 October 2022","externalUrl":null,"permalink":"/articles/never-start-technology/","section":"Articles","summary":"","title":"Never Start with Technology","type":"page"},{"content":"Technology quite literally operates at the speed of light. It's flexible, powerful, and even cheap. But many businesses are finding that the more they leverage technology, the more rigid, impotent, and expensive it becomes to operate and maintain. Technology slows business down due to no inherent fault or lack of its own. I call this the Technology Paradox, and contrary to popular belief, it is not usually due to poor implementation, lack of technical skill, or poor quality. To understand the origin of the Technology Paradox, consider the following example.\nPalmetto Leaves and Sweetgrass # As you drive around Charleston, SC and the surrounding areas, you'll see Gullah men and women of all ages weaving sweetgrass baskets along the side of the road. Unlike in traditional basket-weaving, sweetgrass baskets are made by bundling thin, spaghetti-like blades of sweetgrass together with blades from the saw palmetto plant, These bundles are tied together at the ends and coiled like a snake to create an endless variety of these beautiful, strong baskets.\nThe flexible nature of sweetgrass allows these people to make all sorts of other items, such as potholders, drink coasters, and even boxes. The bundling of the brittle sweetgrass gives these items strength and durability, but it also takes away the flexibility. A sweetgrass basket without handles cannot be easily turned into a sweetgrass basket with handles. A small sweetgrass basket cannot be easily transformed into a large one.\nTechnology is like sweetgrass. It's highly flexible and can be used to make just about anything. But once you make something with it, it becomes almost impossible to turn it into anything else. Many businesses think that if they take some technology and bundle it, share it, or just use it with other technology, that they'll end up with an entire technology infrastructure that's both powerful and flexible. Sadly, this is just not true. Countless businesses have ended up with giant, ugly collections of technology that are rigid, interlocked, and almost uselessly complex.\nSweetgrass baskets 7 Bad Reasons Businesses Use Technology And How To Avoid Them # There are countless reasons businesses utilize technology. Seven of them are bad and lead to escalating costs, diminished returns of both time and money, and decreased effectiveness. Unfortunately, these seven reasons are among the most common. As you read through these reasons, take note of the ones that sound familiar.\nReason #1 — Vague or Unclear Goals # \u0026ldquo;What technology do we need?\u0026rdquo; is a refrain I've heard over and over again in organizations. The hidden assumption in the question is that technology is needed at all. My answer is always the same, \u0026ldquo;What technology do you need for what?\u0026rdquo; The answer is usually vague — \u0026ldquo;improving performance,\u0026rdquo; or \u0026ldquo;lowering costs,\u0026rdquo; or \u0026ldquo;becoming more competitive.\u0026rdquo; No technology, no matter how sophisticated, can help you achieve ambiguous outcomes. Businesses who try to use technology to achieve vague goals are actually worse off than businesses who don't use technology to achieve similarly vague goals. Technology can mask a multitude of sins, and a business can proceed with vague or undefined goals for a long time before realizing its mistake.\nResearch In Motion (RIM), the maker of the once-dominant Blackberry smartphone, is a perfect example of a company that put technology at the forefront to make up for an utter lack of sound business goals. In 1999, RIM released the original Blackberry smartphone. The goal of the device was plain and simple: allow wireless, instant access to corporate e-mail, anywhere and at anytime. While this goal was clear, coherent, and valuable, RIM apparently did not have a yardstick by which to measure when the goal would be complete. RIM achieved this goal in short order and proceeded to focus on growth, expanding globally and striking contracts with telecom providers the world over. But for the next ten years, RIM didn't seem to pursue any new goals. Instead, it focused on improving its technology, releasing over 70 different smartphone models which were fundamentally more or less the same. RIM's market cap capped out in 2008, just one year after the release of Apple's iPhone, then began to decline. The iPhone quickly stole that market share and took hold as the preferred smartphone, but it had nothing to do with the iPhone's technology. RIM had been perfecting its smartphone technology for over ten years, while Apple had only just begun. Major corporations all over the world were using Blackberries, and RIM had built strong relationships with many of them. But what propelled Apple to the forefront at the speed of light was the achievement of a very specific goal that culminated in the creation of the iPhone. Apple's goal was to create a single, portable device that would allow people to quickly and easily listen to music, take telephone calls, and access the entire Internet, anywhere and at anytime. Just as RIM had set and achieved a very specific and valuable goal almost a decade prior, so Apple set and achieved its own specific and valuable goal and began growing wildly.\nThe story of Apple and RIM proves that the success or failure of any company — including a technology company — has almost nothing to do with technology. RIM's Blackberry devices could do all of the things the iPhone could do, but the only goal they were designed to achieve was wirelessly access corporate email. Consequently, Blackberries did that one thing well, and everything else poorly.\nAfter more than a decade of goal-free living, RIM did try to salvage some of its market share by finally setting for the Blackberry what was essentially the same goal Apple had set for the iPhone. But even this approach was doomed from the start. You'll see why in the next section.\nThe Lesson: In order for technology to be valuable to any organization, it must be in support of specific, measurable, and valuable goals. Use technology if and only if technology can meet those goals in a way that delivers a substantial return on money and time.\nReason #2 — Keeping up with the Joneses # The problem with following industry trends or trying to imitate the success of others' is that neither option will put you at the head of the pack. You'll either be on par with everyone else, or you'll be a \u0026ldquo;me too\u0026rdquo; competitor. Despite this fact, businesses often acquire technology simply because a competitor or colleague did and had — or didn't have — tremendous success in doing so.\nWhen RIM began to develop devices that bore an uncanny resemblance to the iPhone, they were simply playing catch-up. Those goals were not in any way derived from RIM's core values. Rather, they were a desperate attempt to salvage RIM's market share, which was going to Apple at the speed of light. RIM, having had the rug pulled out from under them, began to experience severe confusion and bewilderment. After all, from a technological standpoint, they should have been the ones leading the smartphone revolution. They had the infrastructure, the technology, the experience, the established relationships, and a selection of smartphones so plenary that even the most finicky luddite would be pleased. And yet, not only did RIM not lead the smartphone revolution, they were utterly crushed by it. They started out well enough with a sound business goal, but the focus on goals was quickly replaced by an unhealthy focus on technology that drove the company for the next decade of its existence.\nMany businesses are stumbling along in the dark in much the same way, looking for the light of technology to guide them to success and prosperity. But as RIM learned the hard way, that's not the way it works. The worst thing that can happen to a business who looks to technology as an oracle that will provide guidance and wisdom is that that business will actually latch onto a particular technology and run with it as RIM did. Technology drives the business' activities from then on, and eventually the business winds up in a ditch.\nAnother, slightly more recent example of \u0026ldquo;keeping up with the Joneses\u0026rdquo; is \u0026ldquo;machine learning.\u0026rdquo; 10 years ago, machine learning was called \u0026ldquo;Big Data\u0026rdquo;, a catch-all buzzword for collecting and analyzing massive amounts of data — some of which may actually be relevant to business. The concept has gone by other monikers, such as \u0026ldquo;Business Intelligence\u0026rdquo; or \u0026ldquo;Business Analytics,\u0026rdquo; but the idea is the same: by analyzing various metrics, businesses can make more intelligent decisions around product development, market penetration, operational efficiency, and so on. Businesses are spending billions on Big Data, hoping for a big payday. There are absolutely valuable use cases for Big Data. But there is also a lot of stupidity. I was interviewed for a CNBC.com article on Big Data. In it, I pointed out that Orbitz, the online travel company, notoriously and to the chagrin of many privacy advocates, used Big Data to determine that customers who use Apple Mac computers spend on average $20 more a night than those who use Windows computers. But it was already a well-known fact that Mac users tend to spend more than Windows users in general. Traditional market research would have revealed the same thing much quicker and at a much lower cost.\nThe Lesson: Chasing the latest industry trend in hopes of riding its coattails to success is a recipe for disaster, especially if that trend involves a substantial investment in technology. Don't copy another company's goals just because they proved to be successful for them. Your goals must always be based on your values and passions.\nReason #3 — Other People's Ideas (OPI) # In business, using other people's money is often a wise idea. But using Other People's Ideas (OPI) is usually not. Industry standards and \u0026ldquo;best practices\u0026rdquo; fall under this category. I like to think of both being on opposite sides of the spectrum. Industry standards are the \u0026ldquo;lowest common denominator\u0026rdquo; of any industry. For example, not commingling funds is \u0026ldquo;industry standard\u0026rdquo; in financial services. \u0026ldquo;Best practices\u0026rdquo; on the other hand are what you would do if you had money to burn, and you didn't particularly care if they were really appropriate. They are essentially one-size-fits-all propositions, which is why I put the term \u0026ldquo;best practices\u0026rdquo; in quotes. One-size-fits-all works for hats and socks, but not business. What is best for one organization may be detrimental to another.\nIT is, unfortunately, the poster child for \u0026ldquo;best practices\u0026rdquo; run amok. Security, specifically information security, is the sacred cow of IT. Many insane and costly activities have taken place under the guise of \u0026ldquo;security best practices,\u0026rdquo; which various technology vendors, technology standards bodies, and even private individuals have established. It doesn't matter where they come from. What matters is that most IT people are conditioned to follow them, often without regard for the negative impact on the business. Ironically, information security, which is intended to protect business and critical information systems and infrastructure, often impedes business operations by slowing them down.\nSecurity and speed are always diametrically opposed. Take password requirements for example. Most IT organizations and many websites follow the \u0026ldquo;best practice\u0026rdquo; of requiring passwords to contain a minimum number of characters and be \u0026ldquo;complex\u0026rdquo; — containing a combination of uppercase and lowercase letters, numbers, and symbols. This complexity, while supposedly more secure, leads to more people forgetting their passwords. When this happens to an employee trying to log into his computer, he may try multiple passwords. After a few tries, his account is \u0026ldquo;locked out\u0026rdquo; and he has to get in touch with IT, who must reset his password to something equally complex, which he must write down or remember, and then use to log in. Once he logs in, he has to change his password again, to something still equally complex, which he also must remember. Not only does this process consume the employees time, it also consumes IT's time, which would be better used to achieve business goals, rather than chasing the elusive and vague non-goal of \u0026ldquo;security.\u0026rdquo;\n\u0026ldquo;Security\u0026rdquo; is never a legitimate business goal. In fact, it's not a goal at all because it's vague, not measurable, and has no definable value. Activities that are couched in \u0026ldquo;security\u0026rdquo; are often intended to reduce very specific risks — namely, theft, misuse, or destruction of information stored in IT's systems. IT security measures are only one way to reduce this particular type of risk, but they are never ends by themselves. If you have a problem with employees stealing files, the solution is not to make it more difficult for everyone else to legitimately access those files. The solution is to fire and stop hiring crooked employees! Don't ever accept \u0026ldquo;security\u0026rdquo; as an excuse for impeding business, and don't try to use technology to make up for shortcomings in other areas.\nThe Lesson: Don't let the ideas, goals, and opinions of others guide your business' destiny. Following industry standards or \u0026ldquo;best practices\u0026rdquo; is not a legitimate business goal.\nReason #4 — Personal and Non-business Goals # Businesses, or rather individuals working in businesses, sometimes order the inappropriate or excessive use of technology in order to advance a personal agenda. While not always nefarious, such use of technology is almost always damaging to the business' best interests. Personal agendas fall into three common groups:\n1. Reducing Boredom and Increasing Fun # George Washington and James Madison warned against standing armies during peacetime. In a way, IT organizations can be like standing armies. IT people love solving problems, completing projects, and finding new ways to improve things. But if there is a lull, many IT folks can quickly become bored. What do you do when you get bored? You look for fun, of course. You may go golfing, boating, fishing, or something else. Well, some IT folks want to go upgrading, installing, and tweaking. They may upgrade some software to the latest version just to check out the new features, or they may swap out some old networking equipment with new just because they like having the latest and greatest. While this is often harmless, there are two potential problems. First, this sort of fun costs money and almost never delivers a commensurate return-on-investment. Second, new technology often brings with it new problems, the majority of which can't be predicted. Since technology in most organizations is tightly interdependent, one \u0026ldquo;little\u0026rdquo; problem from a seemingly innocuous upgrade can cause a domino effect that negatively impacts critical business processes.\n2. Career Advancement or Protection # IT is certainly not alone when it comes to basing technology decisions on personal goals. People both inside and outside of IT will order technology as a way of enhancing or protecting their own careers. For example, a seasoned executive may say yes to new technology so as not to appear \u0026ldquo;out of touch,\u0026rdquo; even if that technology is conspicuously inappropriate. Often, such decisions to use technology are couched in a supposed benefit to the business. For example, an IT engineer may propose upgrading some critical systems under the guise of making them faster, when in fact his intent is to simply add another item to his resume. Another IT engineer who knows that the upgrade will do very little to improve performance may go along with the plan so he doesn't jeopardize his career by not being a \u0026ldquo;team player.\u0026rdquo;\n3. Quid Pro Quo # Quid pro quo is a Latin phrase meaning, \u0026ldquo;this for that.\u0026rdquo; Around 2011, Research In Motion (RIM), the company that made Blackberry smartphones, announced that it would give a free Blackberry Playbook tablet to any business that upgraded its Blackberry Enterprise Servers by the end of the year. During this time, RIM was in the battle of its life against Apple and Google for its share of the smartphone market, so it needed businesses to continue using its Blackberry devices. By offering a free gift, RIM convinced many businesses to expend resources to upgrade their Blackberry Enterprise Servers, something they might not have done otherwise.\nQuid pro quo can also take the form of protecting personal relationships. One company I worked with implemented what I'll call Vendor A's telephone call monitoring and recording solution to allow managers to evaluate employee performance when speaking on the phone with clients. Once the system was up and running, one of the top executives abruptly put the kibosh on the entire thing and declared that the company would use a different solution from a different vendor, Vendor B, with no further explanation. The company ended up using neither solution. I later learned that the executive had a relationship with someone at Vendor B. Talk about a scorched earth policy!\nThe Lesson: Don't assume that every push for new technology from within IT is due to a personal agenda, but be on guard. When you get wind of what you suspect is a personal agenda, always ask, \u0026ldquo;What is the specific, measurable business goal?\u0026rdquo; And don't accept vague reasons like \u0026ldquo;improvement\u0026rdquo; or \u0026ldquo;industry standard.\u0026rdquo;\nReason #5 — Technology Is The Most Obvious Solution # Technology tends to make people forget the ways things used to be done. Most of us have become so accustomed to having GPS that we don't even think of using a map when taking a road trip. GPS is thought of as the \u0026ldquo;only way\u0026rdquo; to get from point A to point B.\nThe same sort of thing happens in business. Today there are countless methodologies for powering through one's \u0026ldquo;to-do\u0026rdquo; list. You're probably familiar with a few. Software programs have been built around many of them, and they range from dead simple to mind-numbingly complex. But nothing quite beats putting an item on your calendar and just doing it on the scheduled day.\nSometimes, the most obvious solution is obvious because it's constantly in front of us, not because it's the best. Technology is ubiquitous and constantly renewing, so we notice it more. The \u0026ldquo;old ways\u0026rdquo; of doing things are easy to overlook, though they may be better all around. To be clear, I'm no luddite. I've spent my entire career working with technology, but I'm still frequently frustrated by how much harder it can make even the simplest tasks. For example, if I want to place a take-out order at a restaurant, I may spend five minutes on the restaurant's app or website going through the ordering process when I could place my order over the phone in two minutes. But I still place most of my orders online because my habit is to use technology. It's familiar. It's comfortable. It's always there. But does it always give me the best return-on-time? Not always.\nThe Lesson: When considering using a particular technology to achieve business goals, ask, \u0026ldquo;What did people do before this technology?\u0026rdquo; Later on, I cover the implications of this question and teach you how to decide, with 100% confidence, whether technology is appropriate in any given situation.\nReason #6 — Technology Is Wrongly Assumed to be the Better Investment # Businesses often think that a high-tech solution will provide greater bang for the buck than a low-tech or no-tech one. But much of the return-on-investment (ROI) and return-on-time (ROT) that technology promises is bogus because it's inflated. To understand why, you have to understand a concept I call hyper-leveraging. Hyper-leveraging is the common IT practice of squeezing every bit of usefulness out of one's existing technology in whatever way possible. The philosophy behind hyper-leveraging is, \u0026ldquo;We have it, so we use it.\u0026rdquo; It's important to note that cost-savings is not necessarily a factor in the decision to hyper-leverage. Ease of management, perceived time-savings, increased control or security, or conservation of technology resources can also be a deciding factor.\nA Real Example of Hyper-leveraging # About six months prior to the start of tax season, a payroll company purchased a new application to track tax notices and penalties for its clients. Let's call the application \u0026ldquo;Ticks\u0026rdquo; (not its real name). Ticks would have to be used by everyone in the Tax department, and due to the nature of government bureaucracy, it would have to be updated very frequently with new tax forms and such. When the IT department began planning the deployment of Ticks, it had to decide whether to hyper-leverage its existing technology. It could either place Ticks on individual computers, or it could hyper-leverage its existing technology by placing the application a centralized set of servers that everyone was already using to access other applications.\nBoth options had advantages and disadvantages. Putting Ticks on individual computers would take longer initially and be more of a challenge for IT to manage, but application updates would be automatic, and if anything went wrong, the problem would be isolated to those individual computers.\nPutting Ticks on centralized servers, on the other hand, would be quicker up front, but IT would have to manually update the application frequently. Furthermore, IT couldn't update Ticks quickly if there were urgent updates — as there often are during tax season. The centralized servers were used by everyone in the organization — including Payroll Operations and Sales — so if anything went terribly wrong with a Ticks update, it could potentially impact existing clients as well as prospective ones. In the end, IT decided to hyper-leverage its technology by putting Ticks on centralized servers. Not surprisingly, whenever there was a problem with Ticks, the entire Tax department suffered a drop in productivity, and IT had to spend time and resources working with the vendor to resolve the problem. Had IT not hyper-leveraged, the problems with Ticks would have been less impacting and resolved quicker.\nNewer Doesn't Mean Faster # As the old saying goes, time is money. But the ROT of technology is rarely considered because newer technology is just assumed to be faster than old. Unfortunately, nothing could be further from the truth.\nI remember years ago when Voice Over IP (VoIP) phone systems were all the rage. Unlike traditional business phone systems, VoIP systems didn't require special wiring to connect the phones to the system. Instead, they would simply use the existing computer network infrastructure. This not only made these new systems cheaper, it made them faster to install as well. Anyone could do it, and many did. But it also created a potential problem. Now, if the computer network were to go down, the phones would go down, too. Before, if IT was doing work that caused the network to go down for a few seconds, most people would have their work disrupted for a few seconds with little impact. But after the VoIP system was in place, a network outage of the same duration would result in every telephone call being dropped, likely irritating a lot of customers.\nBut that was only the tip of the iceberg. With the advent of VoIP systems came a new level of integration with even more technologies like email. One company I worked with uses a VoIP system that allows users to receive and listen to their voicemail from their email inbox. When a voicemail comes through, the user gets a message in their email, and they just double-click it. The system rings their desk telephone, and when the user answers it plays the message. It's very convenient and saves users the trouble of having to manually dial into their voicemail to check and listen to new messages. All was well, until the IT department tried to upgrade the phone system. The air-tight integration of the phone system with email and each user's computer meant that IT also had to upgrade special software on every single user's computer! If they didn't, users would lose their voicemail-via-email functionality, so everything had to be upgraded at the same time. Not only that, upgrading the phone system caused all the users to lose their voicemails and their voicemail settings. Everyone in the organization had to reconfigure their voicemail greetings, and they had to do so quickly to avoid clients from hearing an unprofessional, robot-voice greeting when leaving a message. As you might imagine, many users spent a good portion of their day calling IT for assistance.\nThe negative implications of such convergence of technologies cannot be overstated. No longer can the typical organization spend its days meeting and supporting business goals. It has to take valuable time out to deal with the implications of hyper-leveraged technology. The IT organizations in most businesses are no longer able to effectively and quickly meet business goals because they have hyper-leveraged themselves into paralysis.\nTechnology Problems Are Rarely About Technology # Now would be a good time to point out that the problems like those in the above examples are not simply a matter of choosing the wrong technology or implementing it incorrectly. It is axiomatic that hyper-leveraging any technology creates inflexibility somewhere, and working through that inflexibility takes time — usually much more time than expected. It is that lost time that businesses pay for in terms of failed or delayed goals and loss of productivity. Furthermore, hyper-leveraging means that the failure of one piece of the technology infrastructure can have a catastrophic impact on another, even if the two aren't otherwise related. When the impact is severe enough, businesses will gladly pay a pretty penny just to get to an acceptable level of performance, reducing or eliminating any remaining ROI.\nThe Lesson: Always understand exactly how technology will be used to achieve your business goals prior to pulling the trigger. Calculate both the ROI and the ROT of using technology, and proceed only if it's better than low-tech or no-tech alternatives. Never assume that newer will be faster or better.\nReason #7 — Cost-Cutting # Ironically, when businesses cut technology budgets and try to lower technology costs, they end up using technology more, but using it less effectively. The focus on cost-cutting is always to get more out without putting more in. Not surprisingly, when businesses put the pressure on IT to cut costs and \u0026ldquo;do more with less,\u0026rdquo; IT ramps up its practice of hyper-leveraging, which does nothing but create more problems.\nCost-Cutting Means Customer-Cutting # A very large healthcare company I worked with provides hospitals with remote access to its proprietary healthcare applications. While the applications are proprietary, the remote access component is achieved using software from Citrix. As part of the company's agreement with Citrix, they must have a special license for each doctor or nurse that is connected to its system at any given time. These licenses aren't cheap. Furthermore, they're all tracked by a special licensing server to ensure that the company doesn't \u0026ldquo;cheat\u0026rdquo; and use more licenses than it actually purchased.\nNow this is where it gets interesting. The company sets aside for each hospital its own set of servers to run the applications, but not its own set of licenses. All of the licenses are pooled together and shared among all the hospital customers. The reason? You guessed it — to keep costs down. One day, the company decided to upgrade the licensing server. The decision to upgrade was not haphazard — it was a prerequisite to bringing new customers on-board using new technology the company was contractually obligated to provide. There was a hard cost associated with delaying the upgrade. Furthermore, the upgrade was supposed to be seamless and transparent to customers. But it wasn't. During the upgrade, none of the customers could connect to access their applications. In a hospital, doctors and nurses not being able to connect to view patient medial records can be a life-or-death problem. The company resolved the problem relatively quickly, and no lives were lost, but the hospitals' confidence in the company was not so quick to recover. Cutting costs had its own costs.\nChange Management: A Good But Irrelevant Idea # Scenarios like the one above are one of the reasons change management methodologies were invented. The purpose behind change management is to ensure that a change to one system doesn't negatively impact another. This is usually done by scheduling a window of time when some or all of the affected systems will be taken down and made unavailable to the business. When you consider this in the context of hyper-leveraging, it becomes clear that change management solves a problem that, in many instances, shouldn't exist in the first place. Recalling the last example, should the license server upgrade have been scheduled and done during a more opportune time? Of course. But that's besides the point. Hospitals are never closed. There is really no good time for a hospital to lose access to patient information, although most hospitals have procedures in place to deal with such a situation, as long as they know it's coming and have time to prepare. But how does one coordinate such an event among dozens of hospitals scattered all across the country in different time zones? The license server was shared among hospital customers to reduce costs, but this created inflexibility. The upgrade couldn't have been scheduled for one customer at a time. It was an all-or-nothing deal. No wonder the company decided not to bother with change management! It would have been easier to herd cats.\nThe better decision would have been to spend the money dedicate a set of licenses for each hospital customer. Not only would this have allowed the upgrades to take place as-needed and at mutually convenient times, it would have prevented the possibility of a catastrophic impact on all customers at once. So why wasn't this seemingly-obvious decision made beforehand? There's really no way the people who made the decision to share the licenses could have foreseen such a disaster. But, had they considered the underlying business goals — and cost-cutting is never a valid business goal — they would have likely made a better decision.\nThe Lesson: Cost-cutting is never a goal. Furthermore, cost-cutting has its own costs. Remember, there is a reason that doing things the right way usually costs more up-front than doing it the wrong way. Doing things the wrong way always costs more over the long-term.\n","date":"3 October 2022","externalUrl":null,"permalink":"/articles/technology-paradox/","section":"Articles","summary":"","title":"The Technology Paradox: How Technology Can Slow Business Down","type":"page"},{"content":"Opportunities tend to present themselves in clusters. And as much as you\u0026rsquo;d like to be able to take them all on, you may have to say no to some of them. These opportunities may be one-time things, or they may be ongoing commitments. In the thrill and excitement of the moment, it\u0026rsquo;s easy to just say yes and (over)commit yourself. Such ambition isn\u0026rsquo;t a bad thing, but it needs to be tempered with some thoughtful analysis.\nHere\u0026rsquo;s a quiz I use to determine whether to pursue a given endeavor. It\u0026rsquo;s not prescriptive and doesn\u0026rsquo;t tell you whether you should or shouldn\u0026rsquo;t take that new gig. It\u0026rsquo;s just a list of questions that you should carefully think through and then answer.\nPre-quiz quiz # Before even considering an opportunity, you must be able to answer no to both questions:\nWill this require me to engage in any immoral, deceptive, or misleading activity? (E.g. Marketing something you don\u0026rsquo;t believe in, or)a pyramid scheme.\nIs there a significant concrete cost to not doing it? For example, you’ve already committed and can’t get out. Or if not doing it could have serious, far reaching implications.\nThis is does not include “what if” costs like \u0026ldquo;if I don’t do this now, I’ll never do it\u0026rdquo; or \u0026ldquo;if I don’t do this, I won’t become a millionaire.\u0026rdquo;\nIf you can’t answer no to both, then you have your answer. Do not proceed with your endeavor! If you can answer no to both, go on to the quiz.\nNow for the quiz: # Will it require a significant time investment?\nWill it necessitate additional commitments or costs? (e.g. purchase of new equipment, lead into another project, overcoming a learning curve)\nWill it jeopardize another project or relationship?\nIf you begin to pursue it and fail (e.g. miss a deadline), will it have implications beyond the project? (e.g. reputation, future projects)\nWill it overlap with an upcoming event that may impact it?\nIs there an unrelated event that, if it occurs, would jeopardize the endeavor? (illness, internet outage, weather event)\nIs my motivation selfish? This is not to be confused with self interest. For instance, you want to get a certification to advance your career vs. you just want to show it off and brag.\nAssessing your answers # As you might have noticed, the questions are set up in such a way that a \u0026ldquo;yes\u0026rdquo; is bad. If you answered with a lot of yeses, consider that taking on the opportunity might be a bad idea.\nCan the endeavor be changed to result in fewer yeses? This means an actual change, not just a change in perception. If an opportunity falls into the bad idea category, it is likely just that\u0026ndash;a bad idea.\nIf you have few enough yeses that you\u0026rsquo;re fairly comfortable with taking on the opportunity, it\u0026rsquo;s still a good idea to wait a day or two and do the quiz again. You might think of some important details you didn\u0026rsquo;t the first time.\nIf you\u0026rsquo;re still on the fence, ask yourself one more question: If you don’t pursue it, will you regret it a year from now?\n","date":"12 April 2022","externalUrl":null,"permalink":"/post/2022/take-new-opportunity/","section":"Posts","summary":"","title":"Should you take on that new opportunity?","type":"post"},{"content":"In my Practical Networking course, you\u0026rsquo;ll get a practical, hands-on understanding of how to troubleshoot network-related issues. You\u0026rsquo;ll learn all about\nIPv4 and IPv6 network connectivity How devices connect to the Internet How data gets from end to end How to read a network topology diagram, and more I also cover specific network troubleshooting techniques and commands including ping, tracert, netsh, ipconfig, and netstat.\nTestimonials # Don\u0026rsquo;t just take my word for it! Read what others have had to say about the course.\nNever thought i could understand networking concepts. Thanks a lot to the author to make me understand these. I owe you a party.\nBy far this has been a most effective course in terms of helping me learn networking. Finally, all those terms I have been reading and taking notes on are starting to make sense! Most things are finally coming together and actually starting to make sense since I begun this course. Thank you for the real world examples and defining the terms you are referring to throughout the course.\nold guy, new to the IT world. I can say this session really helped me understand more of where to look and a direction to move in for troubleshooting and also realizing some technical aspects I didn\u0026rsquo;t know\nWonderful for the beginners in networking\u0026hellip;\nIncredible course. Very clear and informative. Can\u0026rsquo;t praise high enough.\nHello Ben,\nI\u0026rsquo;m a very big fan of you. I\u0026rsquo;ve been watching your course \u0026ldquo;Practical Networking\u0026rdquo;\u0026hellip; You\u0026rsquo;re amazing in the way you explain things, I\u0026rsquo;m really thankful to you.\nI\u0026rsquo;m only at the start but Ben has made every concept make sense\n","date":"27 January 2022","externalUrl":null,"permalink":"/practical-networking/","section":"Ben Piper","summary":"","title":"Practical Networking","type":"page"},{"content":"","date":"6 January 2022","externalUrl":null,"permalink":"/tags/bitcoin/","section":"Tags","summary":"","title":"Bitcoin","type":"tags"},{"content":"","date":"6 January 2022","externalUrl":null,"permalink":"/tags/blockchain/","section":"Tags","summary":"","title":"Blockchain","type":"tags"},{"content":"","date":"6 January 2022","externalUrl":null,"permalink":"/tags/cryptocurrency/","section":"Tags","summary":"","title":"Cryptocurrency","type":"tags"},{"content":"Many moons ago, I told you that blockchain was a passing fad, and that the only meaningful use of blockchain technology was cryptocurrency (a la Bitcoin). Over 4 years later, my prediction turned out to be true. But this is not an \u0026ldquo;I told you so post.\u0026rdquo; Rather, it\u0026rsquo;s a warning.\nCyptocurrencies have exploded in recent years, along with scammers taking advantage of crypto \u0026ldquo;investors\u0026rdquo; (suckers). You can\u0026rsquo;t turn on the radio or use the internet without being pitched some training course on \u0026ldquo;investing\u0026rdquo; in crypto, supposedly taught by some self-proclaimed expert who has less than 10 years experience in cryptocurrency.\nAlongside the popularity of crypto, other uses of blockchain technology have also sprung up. They go by various names, including \u0026ldquo;smart contracts\u0026rdquo;, \u0026ldquo;zero-trust computing\u0026rdquo;, and \u0026ldquo;non-fungible tokens (NFTs)\u0026rdquo;, and they\u0026rsquo;re all worthless except as academic curiosities. Not surprisingly, these blockchain applications almost always require you to give your money to someone else, usually by purchasing specific digital coins.\nAny use of blockchain technology other than cryptocurrency is pointless and inefficient. I said this years ago and it has proven true. And we could just leave it at that. But the marketing hype around blockchain and crypto is powerful, and many people—with and without technical knowledge—are apt to fall prey to its false promises. So my goal in this post is twofold:\nTo help you avoid getting scammed by blockchain hype To dispel some of the technical errors around blockchain/crypto (you wouldn\u0026rsquo;t want to to repeat them at work or in a job interview) Crypto/blockchain scam warning signs # There are some telltale signs that a crypto/blockchain offering is probably a scam, or at the very least, an inefficient money-suck. Blockchain hype makes bold claims and lures you in with amazing promises. Some of these claims seem too good to be true.. and they are. Once you become aware of the following claims, you\u0026rsquo;ll begin to spot them everywhere.\nClaims to be tamperproof or immutable # The term blockchain describes a distributed database. Blockchain evangelists love to claim that once a record is written to the blockchain, it can\u0026rsquo;t be edited, deleted, or tampered with. But the truth is that nothing is absolutely tamperproof or immutable, which is a fancy word for unchangeable. Not only can blockchain data be tampered with and overwritten, it has happened repeatedly over the years.\nDevelopers slipping in backdoors # If you remember nothing else about blockchain, remember this: the developers of a blockchain application can do whatever they want. And that includes rewriting the blockchain. This has happened with Ethereum, Bitcoin, and other cryptocurrencies.\nWhat\u0026rsquo;s especially disturbing is what happened with Ethereum. Users invested millions into a \u0026ldquo;smart contract\u0026rdquo; that was to act as a venture capital fund, somewhat like buying stock shares. This fund, which was ironically called the \u0026ldquo;decentralized autonomous organization\u0026rdquo; (DAO), was just a voting program that would pay out funds if a majority of stakeholders agreed to it. Well, the DAO had a bug in the code. Hackers discovered this bug and drained the DAO of about $60,000,000 USD.\nThe Ethereum developers responded by modifying the blockchain in what\u0026rsquo;s called a hard fork. They actually rewound the blockchain so that the DAO hack never happened. Of course, this didn\u0026rsquo;t please some of the people who had believed the lie that blockchains are immutable. This group continued to use the original Ethereum blockchain, while others used the modified blockchain. The end result is that are now (at least) two Ethereum blockchains, and they\u0026rsquo;re not interchangeable. You can read more about the DAO hack here.\nH4x0rs and such # A chain rewrite can also happen with a targeted attack, and can occur in different ways.\nIn one scenario, a worm can infect the majority of nodes, causing them to modify the blockchain. Cryptomining malware is prevalent now and effectively turns unsuspecting devices into blockchain nodes. With enough infected devices, whoever controls the malware controls the blockchain.\nIn another and more likely scenario, an attacker could surreptitiously slip some malicious source code into the repository of the client software that blockchain nodes run, causing them to behave in an undesired way. The fact that the nodes use open source code doesn\u0026rsquo;t offer any protection. Hackers routinely infiltrate open source projects.\nThen there\u0026rsquo;s the reality of undiscovered vulnerabilities in the code or its dependencies. Hackers discover novel or zero-day vulnerabilities and quietly exploit them or or sell them on the dark market. Once again, code being open source doesn\u0026rsquo;t guarantee the good guys will discover a vulnerability before the bad guys do. Just look at the Apache Log4j saga.\nClaims to offer decentralized or \u0026ldquo;zero-trust\u0026rdquo; computing # People naively think blockchain can overcome human dishonesty and eliminate the need for trust, but it can\u0026rsquo;t. Someone is always in control. Blockchain proponents try to talk around this fact by claiming that the majority of participants will operate honest nodes. They say the blockchain is consensus-based, so as long as the majority (\u0026gt;50%) of the nodes are behaving, you can trust the blockchain.\nBlockchain is based on circular reasoning # The idea of consensus sounds appealing, but it\u0026rsquo;s a myth. The \u0026ldquo;consensus\u0026rdquo; among blockchain users is an illusion based on flawed, circular reasoning. The real hierarchy of control looks like this:\nDevelopers write code for the blockchain client software Blockchain enthusiasts download and run the client node software Who\u0026rsquo;s in control here? It\u0026rsquo;s the developers. There is no consensus among the blockchain users. They just happen to be a group of people who decided to participate in the blockchain by running the software. It\u0026rsquo;s the software, not the node operators, that\u0026rsquo;s running the show.\nIf that\u0026rsquo;s hard to understand, an analogy may help. Blockchain is like the game \u0026ldquo;Simon Says\u0026rdquo;. The developers are Simon, and the blockchain participants are the players.\n\u0026ldquo;Simon says, \u0026lsquo;Accept this transaction\u0026rsquo;\u0026rdquo;\n\u0026ldquo;Simon says, \u0026lsquo;Ignore this other transaction\u0026rsquo;\u0026rdquo;\nThe players (blockchain nodes) must do whatever Simon (the developers) says. If they don\u0026rsquo;t, they\u0026rsquo;re out of the game.\nThe illusion of control # At this point, blockchain apologists might offer a rebuttal. They\u0026rsquo;d say that most blockchain projects are open source, so if developers tried anything crazy, people would know about it and could just go and write their own client software. But we\u0026rsquo;ve already seen how that works out. Just look at the Ethereum DAO debacle. The developers never truly lose control of the blockchain.\nChina controls Bitcoin (and probably others) # With Bitcoin, the person with the most computing power controls the blockchain. The majority of Bitcoin mining is done in China. Given that China has a communist government in which the state owns everything that it wants to, it\u0026rsquo;s reasonable and savvy to conclude that they effectively control the Bitcoin blockchain.\nThe prospect of the Chinese Communist party (CCP) controlling Bitcoin has raised a troubling conundrum with the Bitcoin devs. Some of them don\u0026rsquo;t like the idea of a national government controlling Bitcoin, but they also don\u0026rsquo;t want to shut out the Chinese people from the Bitcoin ecosystem. The only solution is to turn Bitcoin into a permissioned blockchain which one must ask to participate in. That\u0026rsquo;s probably not going to happen. 中国控制比特币.\nIn a proof-of-stake system like Ethereum, the golden rule applies (he who owns all the gold gets to make all the rules). The one with the most crypto coin invested holds all the power. This is usually the early adopters or devs, but can be anybody who manages to obtain a majority stake. Again, hackers have proven their ability to obtain crypto through exploits, and governments regularly seize crypto.\nA theme begins to emerge here: control of the blockchain tends to become concentrated in the hands of a powerful few.\nDecentralized systems don\u0026rsquo;t exist # There\u0026rsquo;s a false belief that blockchains are decentralized. But truly decentralized systems don\u0026rsquo;t exist. When you think about it, this becomes obvious. In order for a blockchain to be decentralized, there must be a mechanism to prevent any single entity from taking control. But then whoever controls that mechanism is now in control of the blockchain, by definition. The buck has to stop somewhere.\nWe\u0026rsquo;ve touched on this already, but to briefly rehash, all blockchains are necessarily centralized in at least two dimensions:\nThe node software (client) and protocols are controlled by the developers. This means the promise of immutability is also out. Even in a true open source system, vulnerabilities can still exist (e.g. OpenSSH, Log4j). Thus anyone who exploits a vulnerability could potentially wrest control of the system. Things like the Internet and public blockchains appear to be decentralized when in fact they\u0026rsquo;re just distributed. The components are ambiguous, invisible, or incomprehensible, giving rise to the illusion that nobody is in control. The Internet, for example, is controlled by governments and backbone providers. To quote the Wizard of Oz, \u0026ldquo;Pay no attention to that man behind the curtain.\u0026rdquo;\nSelf-contradictory claims # Con artists routinely wrap themselves in logical contradictions. If you work in IT then you probably have a finely tuned sixth sense for detecting these. The two most common contradictions I\u0026rsquo;ve heard from blockchain peddlers are:\nIt\u0026rsquo;s trustless, but requires trusting the system and the people who wrote it.\nIt\u0026rsquo;s decentralized, but everyone must agree on the system and protocols.\nOkay.\nHow do you get people who don\u0026rsquo;t trust each other to agree on the rules? Even stranger, how is it that they reach agreement and still don\u0026rsquo;t trust each other?\nAnd then there\u0026rsquo;s the problem of which blockchain to use. Remember, because the blockchain is a distributed database, everyone has a copy, and your copy may be different than mine. The nasty little problem with blockchain is that there\u0026rsquo;s no way to enforce which blockchain to use. This has already shown up with the DAO fork, and it\u0026rsquo;s going to show up again when Ethereum forks again to a proof-of-stake scheme.\nThe way blockchain developers have handled this is to assert that the longest chain (the one with most transactions) wins, which means someone with enough compute power can outpace the natural chain. This may sound like a feat, but all it would take it for botnets running on people\u0026rsquo;s smartphones to fork a malicious chain. Sounds crazy, right? Norton is already installing cryptominers on people\u0026rsquo;s machines without their knowledge. Now imagine Microsoft shipping a cryptominer with Windows. With that much control, hijacking the entire blockchain ecosystem becomes almost trivial.\nClaims to be a world supercomputer\u0026hellip; or something # When researching Ethereum years ago I came across this strange claim that Ethereum was a distributed computing platform, something like a worldwide supercomputer that you could pay to run your applications on. Intrigued, I looked into the technical details of this, hoping to find some amazing parallel processing capability. Nope. It turns out that the only application that can run on the blockchain is this thing called a smart contract.\nSmart contracts are a dumb idea # Smart contract is the term for an application that\u0026rsquo;s stored on the blockchain and runs on participating nodes. (It\u0026rsquo;s also called a distributed app [dapp]). Before going into the technical details, it helps to understand the basic concept.\nA smart contract can only read from or write data to the blockchain, so its only practical uses are storing data on the blockchain and sending Ether/ETH (Ethereum\u0026rsquo;s cryptocurrency) to other accounts. Now suppose you want to gift 10 ETH (currently valued at the price of a new car) to your grandma on her 100th birthday. Here\u0026rsquo;s how you\u0026rsquo;d do it:\nWrite a smart contract to send 10 ETH to grandma\u0026rsquo;s Ethereum address on her birthday\nPay 10 ETH to deploy the contract to the Ethereum network\nWhen grandma turns 100, the smart contract will release the funds to grandma\nBut here we come to a huge flaw in the system: the code has to be executed. Once the smart contract is on the blockchain, the nodes in the Ethereum network execute it. Yes, multiple nodes execute the same code and hopefully arrive at the same result. The fact that this is inefficient isn\u0026rsquo;t lost on the Ethereum folks. The benefit, they reckon, is that doing it this way avoid trusting a single node. The idea is to have multiple nodes run the same code and arrive at a consensus result.\nGrandma\u0026rsquo;s centennial birthday gift is now in the hands of thousands of anonymous strangers. What could possibly go wrong? Plenty. Once you pay money to put your smart contract onto the blockchain, you have no way of getting it back should you change your mind. And if there\u0026rsquo;s a bug in your code, grandma may not get the money. The smart contract will hold onto it forever.\nEven if your code is perfect, there\u0026rsquo;s still the problem of trust. The very nature of computing requires trusting a computer to execute a set of instructions. You thus must trust that each node is operating honestly. If one node can be compromised, they all can.\nThere\u0026rsquo;s no accountability. There are no consequences for running a malicious node. Why pay Ether tokens to run your code on machine you don\u0026rsquo;t control when you can pay real dollar bills to run it on a machine you do control?\nIt\u0026rsquo;s much easier (and more secure) to just validate and trust nodes that you control, which is what everyone was doing before blockchain came along. In addition to having no accountability, on a public blockchain you have no confidentiality at all. Incidentally, this is exactly why when the big boys (IBM, Apache, etc.) began offering enterprise blockchain products, they made darn sure to support private or permissioned blockchains. Nobody actually wants to use public blockchains for anything important. So why use blockchain at all? You\u0026rsquo;re better off using a centralized database. Blockchain adds nothing but needless complexity.\nNFTs # \u0026ldquo;Non-fungible tokens\u0026rdquo; or NFTs are a class of smart contracts that bilk you out of your money in exchange for putting some data on the blockchain. Buying NFTs is like paying money for free samples.\nAn NFT is a \u0026ldquo;digital asset\u0026rdquo; (music, GIFs, videos, pictures, etc.) or a worthless record on the blockchain that says you own some real world goods. Most NFTs are things like Nyan Cat GIFs or Pepe the Frog stored on the blockchain. There are even collections of themed NFTs, reminiscent of Pokemon cards. The idea is that you can use crypto to \u0026ldquo;buy\u0026rdquo; and become the proud \u0026ldquo;owner\u0026rdquo; of the NFT. Of course, this is a delusion because you don\u0026rsquo;t actually own anything. Because the NFT is stored on the public blockchain, anyone can copy it and use it. For example, let\u0026rsquo;s say you buy an NFT of Pumpkin Spice Nyan Cat flying through space. Nothing\u0026rsquo;s to stop someone else from taking this GIF, using it on their website, and even selling it as an NFT to someone else!\nBut to truly appreciate how devoid of basic logic the whole NFT idea is, you have to read this gem from the Ethereum website:\nNon-fungible is an economic term that you could use to describe things like your furniture, a song file, or your computer. These things are not interchangeable for other items because they have unique properties.\nHuh? I had to read that last sentence multiple times to make sure I wasn\u0026rsquo;t missing something. It actually says that you can\u0026rsquo;t exchange a unique item for anything else because the item is unique. This is obviously false. People buy, sell, and trade unique items all the time.\nOther things blockchain can\u0026rsquo;t do # To use a familiar and annoying headline motif, \u0026ldquo;No, blockchain won\u0026rsquo;t replace CDNs, protect you against DDoS attacks, or provide unlimited, infinite, indestructible data storage.\u0026rdquo;\nI won\u0026rsquo;t bore you. These uses of blockchain, while technically possible, would be unbearably slow and would produce blockchains so large that the cost would quickly become prohibitive.\nCryptocurrency is the only valid use of blockchain # The only valid use case for blockchain is when you need a distributed database among untrusted parties. Only one application fits that definition: cryptocurrency.\nBut tread carefully. Most people pushing crypto don\u0026rsquo;t believe in it enough to use it as money. They\u0026rsquo;re not using crypto to buy and sell items. Instead, they\u0026rsquo;re buying crypto using traditional fiat currency only to turn around and sell it for a higher price. In other words, gambling (they\u0026rsquo;d call it investing).\nThe price of crypto, especially Bitcoin, is driven by speculation, a sort of self-fulfilling prophecy. People believe the price will go up, so they buy some, which drives the price up. This continues until enough people stop believing that the price is going to keep going up. Fewer people buy, more people sell, and the price goes down. And then the cycle repeats.\nDoes Bitcoin, and crypto in general, have a future as a real currency? # There are some digital services that accept crypto. You can buy VPN services, fake social media accounts, shipping services, and contraband. Have you ever wondered why can\u0026rsquo;t you go to the store and buy groceries or gas using crypto? One reason is because the price of it isn\u0026rsquo;t stable. The problem is that there are two competing uses of crypto: one as a currency, and the other as a speculative investment.\nThe people who use it as a currency need its price to be stable relative to the US dollar. This is what we expect of cash. $100 today should be able to buy about the same amount of groceries as $100 could buy last week. We don\u0026rsquo;t expect huge day-to-day shifts in prices. But people who invest in crypto want these huge swings. They want the price of Bitcoin to suddenly drop so they can buy it low, and then they want it to swing up so they can sell it at a profit. Think about it like this: why do people buy things with cash instead of bartering gold or real estate or stock certificates? Because there\u0026rsquo;s just too much price movement, too fast.\nDecentralized currencies can\u0026rsquo;t exist # And now we come to the ugly truth about crypto that nobody wants to admit. For a currency to survive, it has to have the blessing of the government.\nInevitably, people buying and selling with crypto will have disputes. Someone will defraud the other, or a seller will refuse to give a refund to the buyer for unsatisfactory goods or services. Who settles these disputes? The government. Yes, the government settles disputes between parties.\nNow here\u0026rsquo;s where it gets interesting. Suppose a court orders a seller to issue a refund to a person who paid in Bitcoin. Here\u0026rsquo;s the question: does the court order the seller to refund the Bitcoin, or to pay the cash value of what the Bitcoin was worth at the time of the transaction? If the seller has to refund the exact amount of Bitcoin, there\u0026rsquo;s a chance either the seller or the buyer will come up short, depending on which way the price of BTC has moved. The government has to choose a preferred currency, and they\u0026rsquo;re not going to choose Bitcoin.\nAnd let\u0026rsquo;s not forget taxes. A business that accepts Bitcoins and collects sales tax isn\u0026rsquo;t going to be remitting Bitcoins to the government. They\u0026rsquo;re going to have to pay in cash.\nDisadvantages of Bitcoin # Bitcoin has problems, some of which are unique to Bitcoin, others which are common to all currencies.\nBitcoin can\u0026rsquo;t exist without the Internet # This is a rather far out and even apocalyptic notion, but if World War 3 takes out the internet, forget about transferring Bitcoins. I know, if that happens bitcoins will be the least of your concern. But it\u0026rsquo;s a possibility.\nA much more realistic concern is at the regional level. Small countries occasionally shut down Internet access to their citizens.\nTransaction fees # It\u0026rsquo;s a pay-to-play system. Credit/debit cards are like this, but the fee is hidden and paid by the merchant. Bitcoin reverses this and makes the fee paid by the sender. You\u0026rsquo;re paying to pay, but you\u0026rsquo;re not paying to receive. Seems backwards. Once all of the coins have been mined, the only incentive miners will have is transaction fees.\nNo recourse for stolen funds # If it\u0026rsquo;s stolen, there\u0026rsquo;s no getting it back.\nIf someone steals your gold bars, it\u0026rsquo;s possible to get them back. If someone steals money from your bank account, it\u0026rsquo;s possible to get it back. But if someone steals your bitcoin wallet and private key and extracts the funds, there\u0026rsquo;s no getting it back. There is no undo button.\nHard to steal also means hard to get back.\nSome have posited creating a \u0026ldquo;vault\u0026rdquo; smart contract that holds funds and releases them only when, say, you provide a vault key and wait 24 hours. After 24 hours, the contract sends your funds. In the event a hacker steals your vault key and tries to steal funds, you can use a recovery key to undo that transaction within the first 24 hours. The problem here is that it institutes a mandatory waiting period.\nIt\u0026rsquo;s not anonymous or private # Because the blockchain ledger is public, anyone can see your transactions. This isn\u0026rsquo;t necessarily a problem, but it is a bit strange. It\u0026rsquo;s like if there were a public record of every time you paid in cash. We already have an anonymous currency, it\u0026rsquo;s called cash money. You can go out to eat, buy groceries, and get gas anonymously as long as you bring along someone like Ben Frank or Mr. Jackson.\nIt can be destroyed # Bitcoin can be destroyed similarly to if you were to lose cash in a fire. How do you destroy Bitcoin? There are two ways:\nSend it to a non-existent address Destroy your private key Poof. It\u0026rsquo;s gone, and you can\u0026rsquo;t get it back.\nBad arguments against cryptocurrency # We\u0026rsquo;ve covered the good arguments against crypto. Now let\u0026rsquo;s cover the bad ones. Following are some oft-repeated bad arguments out there against using cryptocurrency.\n\u0026ldquo;It\u0026rsquo;s not backed by anything of value\u0026rdquo; # There is no such thing as intrinsic economic value. The economic value of anything depends on what people are willing to trade for it. Right now, people are willing to trade thousands of dollars for a single Bitcoin. Incidentally, they\u0026rsquo;re also willing to pay a decent amount of money for an ounce of gold. But neither gold nor bitcoin have intrinsic economic value.\n\u0026ldquo;It\u0026rsquo;s easy to steal\u0026rdquo; # Actually, bitcoin is very difficult to steal if you take the right precautions. If you keep your wallet encrypted well, you could leave it lying around in a public facing S3 bucket and nobody would steal your coins.\n","date":"6 January 2022","externalUrl":null,"permalink":"/articles/cryptocurrency-bitcoin-blockchain/","section":"Articles","summary":"","title":"Don't Get Conned by Cryptocurrency/Bitcoin/Blockchain","type":"post"},{"content":"","date":"14 December 2021","externalUrl":null,"permalink":"/tags/2021/","section":"Tags","summary":"","title":"2021","type":"tags"},{"content":"Online censorship has ramped up significantly in the past few years. We\u0026rsquo;ve all seen it. For instance:\nSeemingly innocuous social media posts getting removed for reasons that make no sense, or for no reason at all\nVeiled and not-so-veiled threats about what you are allowed to say online without fear of losing your job, getting kicked out of school, or even being physically assaulted\nRidiculous, unbelievable \u0026ldquo;official\u0026rdquo; versions of events being amplified by fake accounts and clickbait-driven media outlets\nPersonal experiences being mocked or dismissed as hoaxes or \u0026ldquo;conspiracy theories\u0026rdquo; in spite of supporting evidence (i.e. gaslighting)\nCensorship comes in many flavors, but it always ends in either forced removal of content, or intimidation into silence. Thankfully, overcoming tech censorship is surpsisingly easy, with the right tools and knowledge of how to use them.\nUnderstanding the technology and censorship landscape # Back in the 1990\u0026rsquo;s, there was an internet rumor that continually made the rounds on email and personal websites. It said that the government had a computer system called ECHELON that was scanning everyone\u0026rsquo;s email looking for specific words and phrases so that they could identify dissidents, political enemies, or whatever. What could be done against this massive spy effort?\nThe email, which contained an ever-growing list of the ECHELON trigger words, proposed an ingenious solution: purposely flood the system by forwarding the email to everyone you know. It wouldn\u0026rsquo;t crash the system, but it would create enough false positives to hamper the system\u0026rsquo;s utility and make it hard to differentiate the signal from the noise.\n(Incidentally, it turns out ECHELON is real, and was operating not unlike the way the email described it. It\u0026rsquo;s funny how the more goofy sounding conspiracy theories occassionally turn out to be true.)\nHow large-scale censorship is accomplished # What\u0026rsquo;s this got to do with censorship?\nBig surprise alert: most censorship is semi-automated. We\u0026rsquo;ve all heard of the legendary algorithms that suppress search results, throw your grandpa\u0026rsquo;s forwarded emails into the spam bucket, deboost your posts, or simply shadowban your social account altogether. Without getting into the technical details of how they work, many of these algorithms are continually tuned by humans to ensure they continue to do their job in spite of attemps to get around them. This is why it often feels like a person is vetting your posts. But make no mistake, even with fine tuning, these algorithms have severe weaknesses that make them trivial to circumvent.\nThe weaknesses of automated censorship # Censorship systems are always relearning what\u0026rsquo;s normal based on the totality of what people are posting. Let\u0026rsquo;s go back to the ECHELON email for a moment. The idea of flooding the system with noise to make it less effective might seem silly, but it\u0026rsquo;s theoretically sound. Pushing down the signal-to-noise ratio is going to cause problems in any system because you\u0026rsquo;re disturbing a feedback loop. You\u0026rsquo;re witnessing this effect in social media right now. So many people are posting about messenger RNA pharmaceuticals, cardiac issues, \u0026ldquo;aye-vur-meq-tin\u0026rdquo;, etc. that these posts no longer stand out as unique or suspicious. When such posts were less common, it was easy to have an algorithm flag them for human review. But now it\u0026rsquo;s no longer practical for a human to review all these posts, so the censors have to tighten up the algorithm to detect and remove the forbidden posts. When that happens, you get more false positives, and people who normally don\u0026rsquo;t post anything controversial suddenly find their completely innocent posts being blocked.\nThis is where the game changes, and we\u0026rsquo;re rounding this corner right now. People who heretofore didn\u0026rsquo;t care about censorship or thought it was overblown are now finding themselves victims of it. Whereas they used to ignore the issue, some are now becoming vocal about their experiences (for example, of grandma\u0026rsquo;s account getting suspended because she innocently shared a funny meme). More to the point, they\u0026rsquo;re sharing these stories, thus further upsetting the algorithm. It\u0026rsquo;s the slippery slope of automated censorship.\nIf your goal is to disseminate information, the algorithm is your enemy, and you must avoid it like the (other) plague.\nYour accounts are about to be deleted # Before we get started, a warning is in order. Don\u0026rsquo;t use any social media platform, web host, or email provider as your onnly storage bin for your contacts or content. You could lose it at anytime and without warning.\nGet alternate contact information for everyone in your audience, whether it\u0026rsquo;s your friends list, followers, contacts list, whatever. You never know when you\u0026rsquo;ll lose access to that information, so get it right now, before you post anything else. And make a backup of your posts. I can\u0026rsquo;t emphasize this enough.\nThe social media site Parler made a huge mistake by keeping everything on one cloud platform with no backup. If you were using Parler around the time of the January 6 protest/guided tour, you know what happened. They were down for over a month and their CEO got fired over it.\nAround the same time, MailChimp abruptly canned accounts that were sending emails calling for analysis of the 2020 Presidential election. Those people who didn\u0026rsquo;t have a current backup lost access to their email lists.\nDo you have emails or phone numbers for the people you talk to? Yes? Good, because phone numbers are useful for more than just phone calls and SMS text messages.\nTelegram and Signal # Telegram and Signal are apps that let you securely chat with your contacts privately one-on-one or in a group using voice, video, or text.\nTelegram does private chat, group chat, and read-only channels that you can use to blast messages to subscribers. It supports voice and video chat as well. They have millions of users and many people and groups that are active on other social sites also cross-post to Telegram. You do have to provide a phone number to sign up.\nSignal is more geared toward private, secure chats, similar to SMS. It also requires a phone number.\nCheck them both out. The idea here is to have options and alternative channels of communication, not to become dependent on just one or the other.\nStop using Gmail # Please, please, PLEASE stop using Gmail, and tell your friends to stop using it, too. Use Fastmail, Protonmail, or something else.\nGmail is infamous for putting your most interesting emails into the spam folder. And you already knew their algorithms are scanning your emails to target you for advertising and who-knows-what-else!\nGo ahead and throw Yahoo! mail in there also. It\u0026rsquo;s just as bad.\nStrategies for Avoiding Censorship # Whatever you do, don\u0026rsquo;t trigger the algorithm! But how do you do that if you don\u0026rsquo;t know what the algo is looking for? The trick is to make your content blend in with everyone else\u0026rsquo;s. Hide the signal in the noise.\nCode words and euphemisns # The most natural and easiest way to discuss a touchy subject without tripping any alarms is to use code words and euphemisms. Read the following examples and see if you can figure out the message based on the context:\n\u0026ldquo;Since my appointment, my HR has been elevated and my doc says I have some sort of itis\u0026rdquo;\n\u0026ldquo;Aunt Talatha was a little overweight, but she was still healthy. Nobody can explain why she passed so soon after receiving \u0026lsquo;protection\u0026rsquo;\u0026rdquo;\n\u0026ldquo;Started having symptoms 3 days ago. Did a televisit and got some medicine supposedly for animals that neigh. Feel soo much better now.\u0026rdquo;\nYou probably understood each message perfectly just by reading between the lines. It took a little thought and effort to avoid using certain words, and the sentences are longer than they could\u0026rsquo;ve been, but nothing in them would raise any red flags.\nThis approach works only if the people reading it have sufficient context. Speaking of using euphemism in music lyrics, Brady Goodwin, Jr. put it this way:\n\u0026hellip;we can speak to those who are \u0026lsquo;in the know\u0026rsquo; without unnecessarily informing those who do not need to know. To accomplish this, artists must become acquainted with and skilled in the art of euphemism—saying it without saying it.\nHence, this isn\u0026rsquo;t a good strategy for communicating new information. For that, you\u0026rsquo;ll have to use another approach.\nCrazy, phonetic spellings for troublesome words # For technical topics, you\u0026rsquo;re going to have to use technical words. And algorithms love technical words because they have a very well defined meaning. Take the following example which would likely trigger something:\nComirnaty induces antibodies against the spike S1 protein antigen, whereas natural infection generates antibodies against multiple viral proteins.\nEven if you dumb down the language, you\u0026rsquo;ll still have some potentially problematic technical terms that are hard to get rid of:\nThe you-know-what gives you antibodies against only one part of the virus, but natural infection creates antibodies against many of its parts.\nThe challenge with technical content is that you can\u0026rsquo;t get rid of the technical terms without losing the impact, and possibly the meaning. One way around this—and it\u0026rsquo;s not perfect—is to use shorthand and phonetic spellings that look nothing like the word, but sound like it when spoken.\nThe v. induces anty botties against the S1 Pro, but nat. infection creates anty botties against many of its parts.\nDoes that look stupid? Yes. Will it fly under the algorithm\u0026rsquo;s radar? Also yes. Algorithms are terrible at understanding context because algorithms don\u0026rsquo;t understand anything. They\u0026rsquo;re just computer programs.\nNotice I used \u0026ldquo;S1 Pro\u0026rdquo; instead of \u0026ldquo;S1 protein\u0026rdquo;. The latter has one very specific meaning, whereas \u0026ldquo;S1 Pro\u0026rdquo; can refer to speakers, auto parts, viruses, or a number of other different things. Imagine the reaction if a rigid algorithm flagged every audio enthusiast bragging about their new \u0026ldquo;S1 Pro\u0026rdquo; because it might be \u0026ldquo;misinformation!\u0026rdquo;\nMemes and other images # Memes are essentially visual metaphors. They\u0026rsquo;re extremely powerful and, if done right, nearly impossible for an algorithm to detect because algorithms aren\u0026rsquo;t people and can\u0026rsquo;t understand metaphor (this is why your computer doesn\u0026rsquo;t laugh when you tell it a hilarious joke).\nThe meme below features the rapper Drake comparing\u0026hellip; well, it speaks for itself.\nMemes like this are ridiculously easy to create. https://imgflip.com/memegenerator is my favorite but there are others. Pick a meme, type some text, download it, and share away.\nKeep in mind that algorithms can easily read any text you put into an image, however, because it\u0026rsquo;s more computationally intensive to scan every single image anyone shares or uploads, there\u0026rsquo;s usually a delay before the algorithm deciphers your awesome meme and flags it. To avoid this, apply the preceding circumvention tips to any text your put into your memes.\nOr\u0026hellip;\nTuring-safe images # You know how a site will sometimes ask you to look at a mangled picture of some letters or numbers and type them in a box to prove you\u0026rsquo;re not a robot? This is called a Turing test, and it\u0026rsquo;s designed to be difficult for computers to solve but easy for humans. Below is an image I created using https://fakecaptcha.com:\nI ran this through multiple optical character recognition (OCR) tools and none of them could recognize the first word. Some couldn\u0026rsquo;t even recognize any of the words. N.B., this is of limited usefulness because the text is intentionally difficult to read.\nTry combining a Turing-safe image with a meme and you\u0026rsquo;ll be unstoppable.\nArchive stuff before it gets dirty deleted or memory-holed # Have you ever heard that stuff you put on the internet lives forever? It\u0026rsquo;s not true.\nAbout 15 years ago I was doing work for an accounting firm owned by an older gentleman who made it a point to turn off the internet router every day before leaving the office. One day as we were discussing this peculiar habit, the conversation took an interesting turn. He pulled an old book off a nearby shelf and pointed out that unlike information on the internet, once a book was published, no one could go back in and change it.\nIndeed.\nEven medical journals and official government sites have removed published papers because they were radioactive. That\u0026rsquo;s why when you find something interesting that\u0026rsquo;s apt to get edited or removed, take a moment to capture an archive of it. Archive.today is my go-to because they won\u0026rsquo;t delete archived pages just because someone requests it. Contrast this with Archive.org which blacklists certain sites and even removes them (perhaps for the right price).\nTake screenshots, or use the Print to/Save as PDF or Web capture functions in your browser to keep local copies of interesting things you find.\nShare files and images with others using sites like https://anonymshare.com, https://imgbb.com, or https://anonfiles.com.\nHave separate public and private accounts # Just as you should have a backup of your contacts and posts, you may want to have multiple accounts for each service you use. Your accounts should not be in any way linked. Don\u0026rsquo;t use the same name, email address, or phone number for multiple accounts, and don\u0026rsquo;t allow the accounts to interact with each other in any way (e.g. \u0026ldquo;like, follow,\u0026rdquo; comment, etc.)\nPublic # One account can be public and highly visible, used for blasting info to anyone who will listen.\nYour public posts should appear \u0026ldquo;safe\u0026rdquo; and be rational and level-headed. Avoid hysterics and emotional manipulation techniques like the clickbait media uses. For example, state \u0026ldquo;x deaths caused by lung cancer\u0026rdquo; instead of \u0026ldquo;Heartless big tobacco sacrificed x lives for profit!\u0026rdquo; You get the picture. Use your public presence to slyly invite like-minded people into your inner circle. For example, on my Contact page you can find my email address and a link to my Telegram.\nPrivate # The other account should be private, low-key, and not obviously tied to your public persona. The most controversial and sensitive posts should go only to a select group that you trust not to report you. You still must avoid triggering the algorithms, but you\u0026rsquo;re free to be more blunt if you know no one is going to turn you in to the stasi.\nA word of wisdom: Save the unbridled venting for your secret diary. I cringe when I see people giving full vent to their anger, rage, and frustration online. This is a fool\u0026rsquo;s errand. Even in your private, inner circle, be circumspect about what you say. Assume that someone outside of your circle is going to see it, because they eventually will. Judgment day, remember?\nYou\u0026rsquo;ve been censored. Now what? # Remember that false positives are inevitable, so even if you do everything right, one of your posts is going to get flagged. Let\u0026rsquo;s talk about the proper way to respond.\nThink carefully before you react, and resist the urge to immediately announce that you\u0026rsquo;ve been censored. There\u0026rsquo;s a saying that if you throw a rock at a pack of dogs, the one that yelps is the one you hit. When you publicly start complaining about how you were censored, you actually may unwittingly encourage others to start censoring themselves out of fear. Silence is golden.\nVague warning # Some sites take a behavior-modification approach by giving you some vague warning that your content violated some set of rules that\u0026rsquo;s 30 pages long, but stop short of telling you precisely how you violated the rule. Or they claim you violated a specific rule that you did not actually violate.\nThis is a lazy mind game and the primary goal is to get you to censor yourself. The secondary goal is to get you to tell others that you\u0026rsquo;ve had your hand slapped so they\u0026rsquo;ll get spooked and fall in line. It\u0026rsquo;s a trap. Just ignore the warning, say nothing about it, and move on.\nPost hidden or deleted # If your post was hidden or deleted, post it again with modifications. Try to reword the entire thing, if you can, so that it isn\u0026rsquo;t detected as a duplicate. Also, if the original post was simply hidden and not deleted, delete it before reposting.\nContent removal is a game of whack-a-mole. Having content detected and deleted is usually just because your number came up. Roll again and you\u0026rsquo;ll probably win.\nAccount suspended or banned # Once this happens, your account has a black mark on it indefinitely. The best option is to delete the account, wait a while, and create a new one. Social platforms are wise to this, so use a different email, name, phone number, and preferably IP address when signing up.\nShadowbans # Shadowbans are quite possibly the most effective way to remove inconvenient content from a platform. When shadowbanned, your content is visible to you but hidden to others—either by being invisible or just buried beneath layers of \u0026ldquo;click here to see more.\u0026rdquo;\nHaving multiple accounts makes it easy to detect if you\u0026rsquo;re being shadowbanned. If you suspect one account is being shadowbanned, for example, just log in with an alternate account and see if you can see the content. If not, you\u0026rsquo;re shadowbanned. Dealing with a shadowban is the same procedure as dealing with a normal ban: delete the account and start over.\nCensorship-resistant platforms # If you\u0026rsquo;re not keen on flying under the radar of the all-seeing algorithm, you may want to move to friendlier pastures where you\u0026rsquo;re free to be less reticent.\nThe following are various chat and publishing platforms that have a decent track record of not being heavy handed. If you have any to add, let me know.\nLong-form publishing # Substack is designed for long-form content such as articles or blogs. I follow a few different blogs hosted there, and have detected no signs of censorship thus far. Of course, keep a backup of any posts you don\u0026rsquo;t want to lose.\nSocial media # You\u0026rsquo;re probably already aware of these, nevertheless, here they are in no particular order:\nParler https://parler.com and Gettr https://gettr.com are for short-form posts, like that awful site that starts with a T\nGab https://gab.com and Mewe https://mewe.com are fashioned after Fakebook, but aren\u0026rsquo;t funded by the CIA (as far as you know).\nConclusion # They can\u0026rsquo;t censor what they can\u0026rsquo;t control. As long as you have access to your contacts and content, you can find a way to distribute information.\nIn addition to flying under the radar of the dumb-but-smart algorithms, there are other ways to circumvent censorship that are a bit more technical and require some time and effort to implement, such as:\nVirtual private networks (VPNs)\nThrowaway email addresses\nTracker blocking\nAnd yes, you hear commercials for these kinds of services making it sound like you can just push a button, and suddenly you\u0026rsquo;re anonymous or invisible. Unfortunately, it\u0026rsquo;s not that simple. An algorithm may be aware of these tools and become more touchy when it detects them, thinking that they indicate a bot. To avoid triggering the algorithms, you want to appear as normal as possible. I therefore recommend keeping it simple and adding the aforementioned tools one at a time, learning as you go.\n","date":"14 December 2021","externalUrl":null,"permalink":"/articles/overcoming-censorship/","section":"Articles","summary":"","title":"Overcoming Censorship","type":"post"},{"content":"Now that GitHub has been hacked/DDoS\u0026rsquo;d, you might find it difficult to access the course exercise files for some of my IT training courses. I\u0026rsquo;ve begun adding some of these files to GitLab, and you can find them at https://gitlab.com/benpiper\nFeel free to contact me if you can\u0026rsquo;t find what you\u0026rsquo;re looking for.\n","date":"27 November 2021","externalUrl":null,"permalink":"/post/2021/2021-11-27-course-exercise-files-available-on-gitlab/","section":"Posts","summary":"","title":"Course Exercise Files Available on GitLab","type":"post"},{"content":"","date":"27 November 2021","externalUrl":null,"permalink":"/tags/git/","section":"Tags","summary":"","title":"Git","type":"tags"},{"content":"","date":"9 November 2021","externalUrl":null,"permalink":"/multicast-inet/","section":"Ben Piper","summary":"","title":"IPv4 Multicast Address Space Registry, Internetwork Control Block (224.0.1.0 - 224.0.1.255 (224.0.1/24))","type":"page"},{"content":"","date":"9 November 2021","externalUrl":null,"permalink":"/tags/multicast/","section":"Tags","summary":"","title":"Multicast","type":"tags"},{"content":" Previous edition — CV0-003 (updated to CV0-004) # This is the previous edition covering CV0-003 — cloud architecture, deployment, security, and troubleshooting fundamentals that still matter for real-world ops, even though the current exam is CV0-004 (2025).\nSales proof: 5,000+ net copies lifetime per Wiley (3,000+ print) — $100k+ publisher net, part of 6,000+ across CompTIA Cloud+ franchise ($150k+ net). Solo-authored.\nIf you need current 2025 objectives, see CompTIA Cloud+ Study Guide CV0-004, 4th Edition — 480 pages, updated domans, 1,200+ copies sold already.\nWhat this edition covers (still useful) # Cloud architecture — high availability, scaling, performance Deployment — compute, storage, network Security — IAM, network security, compliance Operations and troubleshooting — backup/DR, monitoring, failure scenarios Who this is for # Readers who bought CV0-003 and want reference for fundamentals Teams still validating against CV0-003 before migrating to CV0-004 prep Buy / Next steps # View on Amazon (affiliate: benpiperblog-20) Current edition: CV0-004 4th Ed — 1,200+ copies, new 2025 objectives Work with me: Work With Me — private workshops for Cloud+ prep Get notified: Contact ","date":"15 September 2021","externalUrl":null,"permalink":"/books/comptia-cloud-cv0-003/","section":"Books","summary":"","title":"CompTIA Cloud+ Study Guide: Exam CV0-003, Third Edition","type":"page"},{"content":"","date":"15 September 2021","externalUrl":null,"permalink":"/tags/cv0-003/","section":"Tags","summary":"","title":"Cv0-003","type":"tags"},{"content":"","date":"8 January 2021","externalUrl":null,"permalink":"/tags/amazon/","section":"Tags","summary":"","title":"Amazon","type":"tags"},{"content":"Whether you prefer to read or watch a video, here are some AWS certification training resources I\u0026rsquo;ve put together for you.\nStudy Guides # The following study guides include hundreds of assessment questions and answers as well as online access to graded practice exams.\nThe AWS Certified Solutions Architect Study Guide: Associate (SAA-C02) Exam by David Clinton and myself covers more than you need to know to pass the exam. If you don\u0026rsquo;t believe me, just click the link and look at the reviews on Amazon.\nIf you are fairly new to AWS, you\u0026rsquo;re better off starting with the AWS Certified Cloud Practitioner Study Guide: CLF-C01 Exam, also by David Clinton and yours truly. Even if you don’t plan to take the entry-level Cloud Practitioner exam, this book will give you a solid foundation on which to build.\nVideo Courses # The Solutions Architect: Associate exam focuses heavily on the Well-architected Framework. The following courses cover these:\nArchitecting for Reliability on AWS Architecting for Security on AWS Architecting for Performance Efficiency on AWS Architecting for Cost on AWS Architecting for Operational Excellence on AWS If you don’t have a solid networking background, you may find AWS networking a bit confusing. To get you up to speed, I’ve created three AWS networking deep-dive courses:\nAWS Networking Deep Dive: Virtual Private Cloud (VPC)\nAWS Networking Deep Dive: Elastic Load Balancing (ELB)\nAWS Networking Deep Dive: Route 53 DNS\nIn addition to videos, you get exercise files so that you can follow along with the demonstrations and access to discussion boards.\n","date":"8 January 2021","externalUrl":null,"permalink":"/post/2021/2021-01-08-studying-for-the-aws-certified-solutions-architect-associate-exam-saa-c02/","section":"Posts","summary":"","title":"Studying for the AWS Certified Solutions Architect: Associate Exam","type":"post"},{"content":"Despite the proliferation and availability of information, good information is hard to come by. Finding the right data is often a matter of quickly dismissing sources of bad data, allowing the cream to rise to the top. To speed up this process, I\u0026rsquo;ve created the following list of sources that I\u0026rsquo;ve found to consistently provide false information.\nThese unreliable sources and websites are divided into three categories.\nNews or \u0026ldquo;infotainment\u0026rdquo; media Curated online references (including \u0026ldquo;fact-checking\u0026rdquo; sites) Social media News or \u0026ldquo;infotainment\u0026rdquo; media # These sites depend on ad revenue for their existence, so they sadly resort to dishonest tactics to get as many eyeballs as possible. They often utilize a deception technique called clickbait, using false or misleading headlines to get you to click on a link, only to bring you to a story that contradicts the headline. They also have a pattern of suppressing or dismissing facts, usually by discrediting the source of those facts (\u0026ldquo;poisoning the well\u0026rdquo;)\nThe list is long and by no means comprehensive: BuzzFeed, CNN, Fox, MSNBC, New York Times, Newsweek, Time, Vox, Washington Examiner, Washington Post\nIf a site displays ads or requires you to subscribe to read an article, ask yourself why.\nCurated online references # Sources on this list routinely publish false information, often while positioning themselves as unbiased and impartial. As the old saying goes, follow the money. The following \u0026ldquo;fact-checking\u0026rdquo; sites are funded by political organizations and exist to promote an agenda, not to get at the truth.\nPolitiFact, Snopes, FactCheck.org, and any \u0026ldquo;fact checking\u0026rdquo; site\nScienceBasedMedicine.org (Dressed up to look like a sci-med site, closer inspection reveals it\u0026rsquo;s a political site run by a group of atheists)\nWikipedia (Although it\u0026rsquo;s full of misinformation, the bottom of articles contain links to other sources that may be useful.)\nSocial media # Social media companies including Facebook, Reddit, and Twitter publish two types of content: curated and user-generated.\nCurated content comes almost exclusively from the aforementioned news and \u0026ldquo;infotainment\u0026rdquo; sources. Social media companies tend to favor user-generated content shared from the same. In short, these sites are an echo chamber of unreliable information.\nIt goes without saying that user-generated content can range from 100% true to completely fabricated. There\u0026rsquo;s an epidemic of fake social media accounts, many of which appear to be for the sole purpose of influencing others. You\u0026rsquo;ve probably noticed that during high profile news events, real-looking accounts start posting similar or identical opinions and calls-to-action, almost in unison. Then after a period of time, they abruptly stop. It looks like an advertising campaign because it is, except instead of trying to sell a product, it\u0026rsquo;s a campaign to sell an idea by creating the illusion that thousands of real people are demanding some particular action.\nIf you doubt the prevalence of fake accounts, just look at all the twitter, reddit, and facebook accounts you can buy on the cheap.\nA Reliable Source # Where can you find reliable sources? I hesitate to provide a list because what\u0026rsquo;s reliable one day could become unreliable the next. One marker of a reliable source is that they willingly share their primary sources. For example, rather than just telling you what\u0026rsquo;s in a document or recording, they actually give you the source material to view for yourself.\nWhat is always reliable is God\u0026rsquo;s Word. Test everything against that, and you\u0026rsquo;ll be in good shape. If a source consistently presents a worldview that\u0026rsquo;s contrary to Scripture, then you know it\u0026rsquo;s unreliable.\nBeloved, do not believe every spirit, but test the spirits, whether they are of God; because many false prophets have gone out into the world. By this you know the Spirit of God: Every spirit that confesses that Jesus Christ has come in the flesh is of God, and every spirit that does not confess that Jesus Christ has come in the flesh is not of God\u0026hellip; -1 John 4:1-3\n","date":"3 January 2021","externalUrl":null,"permalink":"/unreliable-sources/","section":"Articles","summary":"","title":"Unreliable Sources","type":"post"},{"content":"","date":"22 November 2020","externalUrl":null,"permalink":"/tags/2020/","section":"Tags","summary":"","title":"2020","type":"tags"},{"content":" About three years ago, the following phrase popped into my head:\n\u0026ldquo;Social media is making you have stupid opinions.\u0026rdquo;\nNow that\u0026rsquo;s obviously not directed at you, and when I had the thought it wasn\u0026rsquo;t about anyone in particular. It was more of a general observation that social media is antithetical to critical thought and careful, rational reasoning. It is, however, very conducive to emotionally driven snap judgments, many of which contradict each other.\nI want to be very clear: if you regularly use Twitter, Facebook, or Reddit, dumping them today will improve your career and your life overall. And if you can bring yourself to get rid of only one, let it be Twitter.\nTwitter won\u0026rsquo;t help your career # Especially in the IT world, people fear that not having a social media presence will hurt their brand or make them essentially undiscoverable. Friends, I promise you, the kind of employers you want to work for are not scouring Twitter looking for their next hire. 81% of Twitter users are not in the United States. That means if you\u0026rsquo;re looking for an IT/dev job with a U.S. company, you\u0026rsquo;ll have better chances standing on the street corner with a \u0026ldquo;geek for hire\u0026rdquo; LED display.\nQuick: within the past year, how many people have you ever heard of getting a job via Twitter? I\u0026rsquo;d be willing to bet the number is very close to zero. Offhand, I can\u0026rsquo;t name a single person. That\u0026rsquo;s because hiring managers and recruiters aren\u0026rsquo;t looking there.\nNow you might find a company advertising a job opening on Twitter. (This is much less common than it used to be because marketers figured out that Twitter ads have poor engagement and aren\u0026rsquo;t worth it.) But in the unlikely event you stumble across a job ad on Twitter, chances are it\u0026rsquo;s a job that was posted on a job board a month earlier. And nobody is going to ask you to apply via Twitter. If you delete your Twitter account today, it\u0026rsquo;s unlikely you\u0026rsquo;ll miss out on anything.\nBut what if you use Twitter to keep up with tech trends? There\u0026rsquo;s actually a better way: real simple syndication (RSS) feeds. Almost every blog and website has an RSS feed you can tap into using an RSS reader (like QuiteRSS). You can aggregate everything in one place and check it at your leisure. (The RSS feed for this site is https://benpiper.com/index.xml)\nThere\u0026rsquo;s another hook that draws people to Twitter: interacting with famous or pseudo-famous people. Let\u0026rsquo;s call it what it is: vanity. Yeah, it\u0026rsquo;s cool when a celebrity hearts your comment (that they\u0026rsquo;ll forget about 5 seconds later). But is it worth all the negativity, lies, arrogant self-promotion, nutty conspiracy theories, death threats, violence, and toxic people you have to put up with by virtue of being on Twitter?\nYou won\u0026rsquo;t get accurate news # Twitter has an endemic problem of verified accounts—many of whom are news media outlets or journalists—making false statements. Not only are they false, they\u0026rsquo;re so obviously false that a quick search can debunk them within seconds.\nI\u0026rsquo;ll give you an example that I just happened to stumble across it weeks ago. Keep in mind this isn\u0026rsquo;t an isolated example, and I didn\u0026rsquo;t even have to go looking for it. Here it is: News anchor Lawrence O\u0026rsquo;Donnell tweeted from his verified account:\nHow many times will Trump’s doctor [Dr. Scott Conley], who is actually not an MD, have to change his statements?\nMy quick search revealed the following: one of Dr. Conley\u0026rsquo;s credentials is \u0026ldquo;FACEP\u0026rdquo;, an acronym for \u0026ldquo;Fellow of the College of Emergency Physicians.\u0026rdquo; In other words, Dr Conley is an MD. O\u0026rsquo;Donnell didn\u0026rsquo;t even bother to look up what \u0026ldquo;FACEP\u0026rdquo; stood for. Yet I was able to find this out in seconds. Some people identifying as MDs chimed in and called out his error. Despite this, he didn\u0026rsquo;t correct himself or delete the tweet, and Twitter didn\u0026rsquo;t label it as false information. This is a common pattern.\nHere\u0026rsquo;s the scary part: a lot of intelligent people are routinely deceived by such false information. People can be trusting, especially if the source appears authoritative, as in the case of a \u0026ldquo;blue check\u0026rdquo; tweeting something. Almost everything on Twitter—especially from \u0026ldquo;fact-checked,\u0026rdquo; \u0026ldquo;verified,\u0026rdquo; or anonymous sources—should be regarded as highly suspect. You don\u0026rsquo;t want to end up making a fool of yourself liking, retweeting, or quoting some bogus story.\nHere\u0026rsquo;s another example of false information making the rounds. Sheryl Stolberg, a New York Times reporter, posted this:\nNEW: A 32-year-old close to Dr. Fauci \u0026ndash; the brother of his daughter\u0026rsquo;s boyfriend \u0026ndash; has died of Covid-19, he just told me:\n\u0026ldquo;He\u0026rsquo;s a perfectly healthy 32-year old guy who got COVID, got the cardiac complications and died within like a week.\u0026rdquo;\nThe problem? It\u0026rsquo;s not true. The man in question, Christopher Washington, did not have the virus. He tested negative. He had an enlarged heart and infection in his lungs, but did not have any other symptoms.\nThis example is especially egregious because here we have a politician fabricating information, sharing it with a reporter who repeats the information as fact without verifying it, and then Twitter allows it all to go by unchecked.\nIt would be one thing if Twitter just ignored false information. But they actively and passively promote it. The blue checkmark verification badge on accounts is a tacit endorsement of the content they post, whether Twitter likes it or not. Twitter is fine with being the conduit for false information if it keeps you on the platform.\nIn some cases, Twitter selectively suspends accounts that tweet things Twitter management doesn\u0026rsquo;t like. In other cases, they slap negative labels on such tweets. Twitter claims these labels are to protect people from false information, when in reality they\u0026rsquo;re designed to promote one side of a controversial topic. For instance, after Dr. Scott Atlas\u0026rsquo; cited evidence that masks don\u0026rsquo;t work against coronaviruses, Twitter suspended his account, extorting him into deleting the tweet before they would let him back in. Their absurd rationale was that he was posting false information. Dr. Atlas is one of the top MDs in the country, and he offered plenty of evidence to support his claim. It\u0026rsquo;s an obvious lie for Twitter to claim that he was posting false information.\nFake accounts # As of November 2020, Twitter has 187 million monetizable daily active users (mDAUs). Many of these are bots and just fake accounts. Twitter knows these fake accounts exist and does not remove them. I think if they did, their mDAU would drop significantly and it would hurt their revenue.\nFake accounts have real people operating them. Automated bot accounts are easy to detect algorithmically, and human intervention is required to get around captchas that Twitter inevitably throws at them. A sort of mythology has grown up around \u0026ldquo;Russian bots\u0026rdquo; just autonomously tweeting. This isn\u0026rsquo;t happening. Even semi-automated bot accounts have real people operating them.\nFake accounts are extremely common. You can actually buy Twitter accounts, even verified accounts, from places like PlayerUp. Here\u0026rsquo;s a snippet from a sample listing:\n-Accounts have random amount of tweets and followers (0-50), registered in at least 5 years.\n-These accounts are pefect for your first experiments with automation Hear that? Perfect for creating your very first Twitter bot. The price? $70 for 25 accounts. And they take Bitcoin. You can\u0026rsquo;t make this stuff up.\nTell-tale signs of fake accounts # If you want to get an idea of just how many fake accounts are out there, there are some tell-tale signs that make them easy to spot.\nThe Name # The name will be either:\nGeneric and vanilla, usually given as first and last name (\u0026ldquo;Becky Smith\u0026rdquo;, \u0026ldquo;Daisy Walker\u0026rdquo;)\nCompletely made up, but referencing a current topic or event (\u0026ldquo;Socially Distant Introvert\u0026rdquo;, \u0026ldquo;Solidarity Protest Warrior\u0026rdquo;)\nA big clue is the excessive use of symbols like emojis and other nonalphanumeric characters in the nick. Most people aren\u0026rsquo;t going to bother with a highly stylized nickname like \u0026ldquo;🎀𝒩𝒾𝑔𝒽𝓉_𝒮𝒽𝒶𝒹𝑒_𝐵𝒶𝒷𝓎𝑔𝓊𝓇𝓁🎀\u0026rdquo;.\nThe Link # The bio will have a link, typically to either a defunct site (like an unused blog) or a purported employer. If the link is to a blog or personal site, the defunct status is an important clue because a real person who is actively tweeting isn\u0026rsquo;t going to link to a blog that they haven\u0026rsquo;t written in for 10 years. What\u0026rsquo;s more likely is that the person who actually owns the blog started it 10 years ago and forgot about it is never going to find that someone is linking to it, claiming it as their own.\nFor accounts without a \u0026ldquo;real\u0026rdquo; name, the link may be to the person\u0026rsquo;s supposed employer. In this case, the person will not reveal their real name so as to make it impossible to disprove their claim of employment.\nThe tweets # Fake accounts typically have lots of retweets with few or no original tweets. \u0026ldquo;Original\u0026rdquo; tweets will sometimes appear almost verbatim on numerous other fake accounts. One pattern I\u0026rsquo;ve seen recently on numerous accounts begins with something like \u0026ldquo;That\u0026rsquo;s it, I\u0026rsquo;m leaving the US and moving to Hawaii.\u0026rdquo; We can forgive Twitter\u0026rsquo;s bot-detecting algorithm for missing the hilarious oversight of a person clearly unversed in U.S. geography. What we can\u0026rsquo;t excuse is Twitter ignoring these obviously fake accounts.\nThe Bio # The fake account bio tries too hard to look real. It tends to follow two general formats:\nAn occupation combined with a political slogan or edgy statement\n\u0026ldquo;Graphic artist and unabashed liberal and feminist\u0026rdquo; \u0026ldquo;Boxing (yes girls like boxing get over it)\u0026rdquo; \u0026ldquo;I believe in free speech, but if you\u0026rsquo;re a bigot don\u0026rsquo;t follow me\u0026rdquo; Brief but mechanical, such as a list of generic interests. For example, a bunch of nouns with corresponding emojis.\n\u0026ldquo;Dog lover 🐕, food lover 🍔, patriot 🇺🇸\u0026rdquo; A real person will gravitate towards either words or emojis, not both. They\u0026rsquo;ll either have a list of nouns without a bunch of emojis, or they\u0026rsquo;ll have lots of emojis with maybe one noun. The pictures # I\u0026rsquo;ve found pictures to be one of the most accurate indicators of a fake account.\nThe profile picture may be old/blurry or doctored (recolored with added effects). It doesn\u0026rsquo;t show up in an image search, so is probably ripped off from a private Facebook account. The profile pic rarely changes, if ever. Contrast this with a real person who would periodically change it. Other than the profile pic (which isn\u0026rsquo;t really them anyway), fake accounts never post pictures of themselves. Instead, they post memes and animated GIFs pulled from various reaches of the interwebs. ","date":"22 November 2020","externalUrl":null,"permalink":"/2020/11/dumping-twitter-will-make-you-smarter/","section":"Posts","summary":"","title":"Dumping Twitter Will Make You Smarter","type":"post"},{"content":"","date":"22 November 2020","externalUrl":null,"permalink":"/tags/health/","section":"Tags","summary":"","title":"Health","type":"tags"},{"content":" The phrase \u0026ldquo;coronavirus hype bubble\u0026rdquo; refers to misinformation and hyperbole about the novel coronavirus. The virus is not a hoax, but it\u0026rsquo;s not anywhere nearly as bad as you\u0026rsquo;ve been led to believe. It is mild for most, but it can cause serious disease in a miniscule portion of people, particularly the elderly.\nEarly in the Spring, it seemed that some of the response to the new SARS-CoV-2 coronavirus was not based on evidence. And I think many of us in the technology world thought the same thing.\nWhen you work in IT for a long time, you develop a sixth sense for when things just don\u0026rsquo;t add up. Having to make decisions based on data—and then being held responsible for those decisions—tends to sharpen one\u0026rsquo;s critical thinking skills. More to the point, IT work entails technology, engineering, and math, and these are the same skills required to analyze and understand the data regarding the novel coronavirus.\nGetting the right data # One thing you learn from troubleshooting is that you need the right data. When a user is dealing with a problem, they may offer a lot of facts that may or may not be relevant to the issue at hand. As an IT professional, your job is to determine what data is relevant. When it comes to the virus, there are only two metrics that matter:\nThe percent of positive tests—the number of positive tests divided by the number of total tests. The number of deaths caused by infection The percent of positive tests # The percent of positive tests metric is more important than the absolute number of cases because the number of cases depends on the number of tests. All things being equal, if you do more tests, you show more cases. If you do fewer tests, you show fewer cases. In statistical terms, the number of tests is a counfounding variable because it influences the number of cases in an unpredictable way.\nUntil testing became widespread, we didn\u0026rsquo;t have a good grasp of the percent of people infected. We were testing only people with severe symptoms, which led to the false impression that percent positives were higher than they were. When extrapolating these inflated numbers to the whole population, it led to some silly and irresponsible predictions that we now know are wrong.\nThe number of deaths # The number of deaths is significant because it gives us an idea of just how bad the virus is, and that should inform how we deal with it. Two things became became clear early on.\nOne. For children, the risk of the virus causing serious illness is virtually zero. According to Dr. Scott Atlas of the U.S. coronavirus task force:\nChildren are a very low-risk population. There is virtually zero risk of death and low risk of hospitalization.\nTwo. The virus can cause serious and life-threatening illness in the elderly and people with compromised respiratory, immune, or vascular function. But if you\u0026rsquo;re healthy and under 60, your risk is extremely low.\nMost people may never get sick # In the U.S., events were cancelled and businesses were closed for months. Almost everyone has made the assumption that the virus could spread through the entire population. But the data suggests that only about 20% of the population is susceptible to significant illness from the coronavirus. According to a German study, 81% of people who have never been exposed to the coronavirus show T-cell activity against it:\nCross-reactive SARS-CoV-2 T-cell epitopes revealed preexisting T-cell responses in 81% of unexposed individuals, and validation of similarity to common cold human coronaviruses provided a functional basis for postulated heterologous immunity\nIn other words, if the other coronaviruses that cause the common cold confer some immunity to SARS-CoV-2, then most of the population may not get sick from the virus at all, or if they do, will have only a mild case.\nHerd immunity works # Herd immunity is the phenomenon that when a certain percentage of the population develops immunity to a virus, it protects the rest of the population that doesn\u0026rsquo;t have immunity. The percent of the population that has to be immune to a virus for herd immunity to kick in varies by virus, but it\u0026rsquo;s typically between 80%-95%.\nIn March, the Diamond Princess cruise ship had an outbreak, and only 19.2% of the occupants tested positive. Cruise ships are notorious for being incubators for outbreaks, so the Diamond Princess was an ideal petri dish for the virus. But despite this, 80% of the occupants did not get infected. Another ship, the Grand Princess, also had an outbreak and its occupants had a percent positive rate of only 16.6%. Are you seeing a pattern? The innate immunity always seems to be around 80%.\nOnce 16%-20% of people get infected, the virus seems to hit a wall. This is based on two small sample sizes, but if we take much larger samples from states and even countries, we see that it pans out.\nOf everyone who has been tested for the coronavirus in the U.S., 18% have tested positive. If past experience is any indicator, we are close to reaching herd immunity, if we haven\u0026rsquo;t reached it already.\nSweden was right: Shutdowns didn\u0026rsquo;t work # Now here\u0026rsquo;s something that\u0026rsquo;s going to blow your mind. There\u0026rsquo;s one country that didn\u0026rsquo;t shut down at all: Sweden. Sweden never shut down, and they got to herd immunity within a few months. In the following chart, look at how Sweden\u0026rsquo;s curve begins to flatten in late July, marking the point at which they began to hit herd immunity. Compare this with the U.S. where the number was still sharply increasing.\nProportionally to population, Sweden has had fewer deaths than the U.S. As of this post Sweden has 819 deaths per million, and the U.S. has 1044. But as you can see, the U.S. curve hasn\u0026rsquo;t even begun to flatten. Shutdowns that were designed to \u0026ldquo;flatten the curve\u0026rdquo; didn\u0026rsquo;t work, and the curve kept growing.\nNow let\u0026rsquo;s look at the percent of positive tests shown in the following chart. Notice that during the time the U.S. was shutdown, Sweden\u0026rsquo;s percent positives stayed up because they allowed the virus to burn through the population. Then at the beginning of July, Sweden\u0026rsquo;s percent positive rate dropped precipitously and remained low, which matches the flattening of the deaths-per-million curve.\nThe percent positives remained low until November, which is when the weather there begins to get cold. Cold weather always brings an increase in respiratory illnesses, and this virus is no different. Both Sweden and the U.S. are going to see weather-related spikes in illness, and this is to be expected.\nThe U.S. saw a drop in April and May because everything was shut down. But starting in late June, we saw an increase that coincides with the reopenings. The virus arrived in both the U.S. and Sweden at almost exactly the same time and peaked at the same time, but Sweden began to hit herd immunity faster.\nImmunity can wane over the course of months or—more commonly—years. This is why you have to get boosters for certain vaccines. It\u0026rsquo;s likely that SARS-CoV-2 is going to be endemic, meaning it\u0026rsquo;s not going away. Most people will develop immunity to it, either through being exposed to it or getting vaccinated, but some people will not develop immunity. The bottom line is that we should expect the virus to remain with us indefinitely.\nThere\u0026rsquo;s a myth that once you get sick from the virus, you can get sick from it again and again. This is false. Once you get sick and recover, you develop antibodies that protect you in the short term (a few months). You also develop memory B-cells and memory T-cells that protect you over the long term (years).\nNote: I created these graphs using the R programming language. You can download the code as a Jupyter notebook to recreate the graphs yourself.\nThe total death count is unknown # The actual number of deaths from the virus (and not just with it) is unknown. What we do know is that the CDC guidance allows a death to be counted as a coronavirus death even with a negative test. A positive test is not required to code a death as a coronavirus death. Furthermore, if someone tests positive and dies, that death may still be counted as a coronavirus-related death, regardless of the surrounding circumstances. That means, for example, if someone gets seriously injured in a car accident then later dies, they may be counted among the SARS-CoV-2 deaths as long as they test positive. If there\u0026rsquo;s any doubt whether the coronavirus contributed to a death, doctors generally err on the side of assuming it was.\nThe guidelines are to streamline recordkeeping because conclusively determining a cause of death takes time. The CDC is more concerned with gathering statistics rapidly, even if they\u0026rsquo;re not 100% accurate. This is just common sense. Anyone who attributes this process to malice has watched too many movies. Likewise, anyone who says that this is a conspiracy theory is promoting ignorance and denialism of the CDC\u0026rsquo;s own guidelines and data.\nDeaths not undercounted # Some have claimed—without evidence—that deaths might be undercounted. Very early on when testing wasn\u0026rsquo;t widely available and not everyone was looking for the virus, this was a reasonable concern. But today it\u0026rsquo;s virtually impossible that a death caused by the virus will be missed. Everyone is looking for cases, and testing is widespread. If there\u0026rsquo;s even a hint that a death is related to the virus, the person will be tested. Depending on the circumstances, they may be counted as a coronavirus death even without a positive test.\nYou might wonder, if the death count is unknown, how do we know that the deaths per million is accurate? I think the actual U.S. deaths count may be a bit lower, because if it is accurate, then the U.S. is going to end up with a disturbingly high number by the time we\u0026rsquo;re done. However, regardless of how accurate the number is, the fact remains that the U.S. shutdowns did not flatten the curve. Sweden\u0026rsquo;s herd immunity strategy did.\nThe CDC\u0026rsquo;s estimated death rate # The CDC estimates that the death rate for the virus is about 0.065%. However, the current death count stands at about 180,000, and there are almost 6 million cases. That yields an overall death rate of 3%. Why is there such a discrepancy between the CDC\u0026rsquo;s estimate and the calculated rate? The CDC\u0026rsquo;s answer:\nwe have replaced the Symptomatic Case Fatality Ratio and the Symptomatic Case Hospitalization Ratio with the Infection Fatality Ratio (IFR), which takes into account both symptomatic and asymptomatic cases and may therefore be a more directly measurable parameter for disease severity.\nEssentially, the CDC seems to be assuming that the real number of cases is 4.5 times higher than what\u0026rsquo;s reported. Right now, there are about 6 million reported cases, so the actual number of cases would be 25 million. 25 million people happens to be about 8% of the U.S. population, a number that jives perfectly with the current total percent positive rate.\nIt\u0026rsquo;s worth noting that what the CDC calls \u0026ldquo;asymptomatic\u0026rdquo; spread likely refers to people with mild symptoms. True asymptomatic spread—that is, spread by people who have the virus and have zero symptoms—almost never happens.\nEpidemiological models were doomed from the beginning # By now, everyone knows that the predictions by the Institute for Health Metrics and Evaluation (IHME) and the Imperial College London were wrong. But why were they wrong? The answer is so simple that it might even make you angry.\nAll the epidemiological models assumed that everyone was susceptible to infection!\nAs we\u0026rsquo;ve established based on the percentage of positive tests, most people may never get infected. But the models assumed everyone will eventually get infected. To truly appreciate why this is such a wrong assumption, let\u0026rsquo;s look at a classic epidemiological model.\nI plugged the CDC\u0026rsquo;s numbers into a model that assumes a population of about 330 million people (the population of the U.S.), and the results just didn\u0026rsquo;t seem believable. This ridiculous result shows over 600,000 deaths! But deaths peaked months ago, and the current count is about 180,000. There\u0026rsquo;s no way we\u0026rsquo;ll ever get anywhere close to 600,000 deaths.\nNow let\u0026rsquo;s try different numbers. If we assume that only 20% of the population (66 million people) could even get seriously sick from the virus, the model looks dramatically different. It shows a total of about 120,000 deaths, which is much closer to the current count.\nMasks don\u0026rsquo;t work # Masks just don\u0026rsquo;t work. It would be nice if they did, but they don\u0026rsquo;t. The data all but proves it. A study published in the Annals of Internal Medicine concluded that general mask usage doesn\u0026rsquo;t reduce community spread:\n\u0026hellip;a recommendation to wear a surgical mask when outside the home among others did not reduce, at conventional levels of statistical significance, incident SARS-CoV-2 infection compared with no mask recommendation\u0026hellip;\nDr. Scott Atlas stated it succinctly when he said: \u0026ldquo;Masks work? NO\u0026rdquo;\nThe CDC even tacitly admits the ineffectiveness of masks. When it comes to people with exposure or potential exposure to an infected person, the CDC recommends quarantining for 14 days\u0026hellip;\n\u0026hellip; irrespective of whether the person with COVID-19 or the contact was wearing a mask or whether the contact was wearing respiratory personal protective equipment (PPE)\nThe CDC is careful to say only that masks may work because they know there\u0026rsquo;s no scientific evidence that they do. Whatever effect masks might have is minimal. The Norweigan Institute of Public Health had this to say about it:\nAssuming that 20% of people infectious with SARS-CoV-2 do not have symptoms, and assuming a risk reduction of 40% for wearing facemask, 200 000 people would need to wear facemasks to prevent one new infection per week in the current epidemiological situation.\nAssuming a 40% reduction flies in the face of evidence, as the Danish study suggests the reduction is somewhere around 2%—statistically insignificant.\nIf you know anyone who is at high risk, make sure they understand that masks are unproven. They may choose to wear one regardless, but they should take precautions as if they\u0026rsquo;re not wearing one at all.\nIf masks were effective, you would expect that areas where mask-wearing is common to have a lower percent of positive tests. But that\u0026rsquo;s not what we see. Instead, in some cities that enacted mask requirements, the number of cases went up. But in other cities, cases went down. Obviously, masks had nothing to do with the number of cases changing. Rather, it\u0026rsquo;s all about the timing. Places that required masks early saw the cases go up. Places that waited until later saw cases drop because the virus had already peaked on its own.\nTo really appreciate the insignificance of mask wearing, it\u0026rsquo;s instructive to compare two counties side-by-side. In South Carolina, Charleston county has had a mask ordinance since late June.\nNeighboring Berkeley county, on the other hand, has never had a mask ordinance. Notice how the peaks and valleys occur in the same places and the overall percent positive follows the same trajectory in both counties.\nMasks don\u0026rsquo;t move the needle # In other places, masks seem to make no difference one way or another. For example, on July 16, Colorado enacted a statewide mask mandate, and the percent of positive tests was at 7%. Three weeks later, the percentage was still at 7%. On August 15, the percent of positive tests was still 7%. Masks literally made zero difference.\nAnother example is Alabama. When their mask mandate began on July 16, percent positives were at 17%. About two weeks later, on August 3, that number peaked at 22%. As of August 31, percent positives are still at 17%. Masks didn\u0026rsquo;t work.\nHawaii has been under a mask mandate since April 2020. On August 26, they saw the percent of positive cases peak at 11%. Masks didn\u0026rsquo;t work.\nRegardless of where you look, the percent of positive cases always tops out around 22%-24%. One could argue that without masks, Alabama\u0026rsquo;s peak would have been higher. However, the Diamond Princess and Grand Princess cases weigh heavily against that possibility. They weren\u0026rsquo;t wearing masks, and the percent of positive cases didn\u0026rsquo;t exceed 20%.\nPercent of positive tests increased after mask requirements # In many places that have been requiring masks for months, the percent of positive tests is increasing! People who were quick to tout the benefits of masks are now eating their words as the percent of positive tests is increasing in areas that have had mask mandates for weeks if not months.\nIn late June and early July, some of the largest cities in South Carolina enacted mask ordinances. Columbia and Greenville saw cases increase, whereas Charleston saw them go down. Those in the latter group patted themselves on the back, believing that masks were to credit. Well, now South Carolina is seeing a significant spike in the percent of positive tests, between 21%-24%. Masks didn\u0026rsquo;t work.\nThe Masks \u0026amp; COVID-19 interactive tool lets you look at the correlation between mask wearing and cases or deaths at the state and county level.\nUnfortunately, some media outlets have cherry-picked data that shows cases going down after mask rules went into effect, perpetuating the unproven claim that masks are effective against the virus. This is the sort of confirmation bias that has always fueled junk science claims, like cell phones causing cancer. You can easily spot such sloppy stories by the fact that they focus on the absolute number of cases instead of the percent of positive tests. This Newsweek article on Alabama\u0026rsquo;s mask mandate is one such example:\n[T]he state\u0026rsquo;s average daily case count has been on a downward trend from late July, just days after a statewide mask mandate was issued on July 15. After peaking on July 24, the state\u0026rsquo;s three-day moving average of new cases mostly decreased to August 5\u0026hellip;\nWhere the article does make mention of the state\u0026rsquo;s percent positives, it again cherry picks two data points that paint a false picture:\nThe average percentage of positive tests in Alabama reported over the past week was 18.1 percent, a slight drop from the 19.1 percent average reported two weeks ago.\nNotice the omission of the percent positive average from one week ago, which was 20%. A few days later, it went up to 22%. That data wasn\u0026rsquo;t given in the story. I had to look it up, and it\u0026rsquo;s in the screenshot below. No wonder people are skeptical! Incidentally, when I just checked, the current percent positive rate is 17%. Masks didn\u0026rsquo;t work.\nOxford\u0026rsquo;s Centre for Evidence-Based Medicine gives some stern warnings about this sort of bias:\nWe consider it is unwise to infer causation based on regional geographical observations as several proponents of masks have done. Spikes in cases can easily refute correlations, compliance with masks and other measures is often variable, and confounders cannot be accounted for in such observational research.\nAnd\nThis abandonment of the scientific modus operandi and lack of foresight has left the field wide open for the play of opinions, radical views and political influence.\nAnd\nIt would appear that despite two decades of pandemic preparedness, there is considerable uncertainty as to the value of wearing masks.\nHere\u0026rsquo;s another overlooked bit of evidence that masks don\u0026rsquo;t work: many Asian countries have been wearing masks for years, especially during outbreaks. Despite heavy mask-wearing, the virus ravaged Wuhan, China. Masks didn\u0026rsquo;t seem to help.\nWhy masks don\u0026rsquo;t stop the virus # Masks don\u0026rsquo;t work against airborne viruses such as SARS-CoV-2. It can become aerosolized and escape into the air every time you breathe. Obviously, masks allow air to pass through the fabric and around the edges, so they also allow the virus to escape. If you\u0026rsquo;ve ever worn a mask and glasses, you\u0026rsquo;ve probably had your glasses fog a bit. That\u0026rsquo;s potentially virus-laden air escaping the mask.\nYou may have heard that the virus attaches itself to respiratory droplets, and that the mask captures those droplets. This is true for large droplets, like the kind you can visibly see when you cough or sneeze. But there are much smaller microscopic water particles that you release every time you exhale. (If you go outside on a cold day and exhale, you can see these condense into a visible vapor.) Many of these either pass through the fabric, or they escape around the edges of the mask. But stopping large droplets isn\u0026rsquo;t going to be much help if you\u0026rsquo;re releasing the virus into the air simply by breathing.\nIf you have a mask, try this experiment: Put on your mask normally and place a clear glass directly in front of your mouth, being careful not to touch the mask. Exhale forcefully, and see if the glass fogs up. If it does, your mask is letting the virus through.\nNow look in the mirror and look for any gaps around the edge of your mask. Hold the glass right next to one of the gaps, and exhale forcefully again. If the glass fogs up\u0026hellip; well, you already know what I\u0026rsquo;m going to say.\nCan masks capture at least some of these tiny droplets? Probably. But I\u0026rsquo;ve seen no evidence that they capture enough to make a difference. If you have a natural gas leak in your home, can wrapping a towel around the leaking pipe stop some of the gas from escaping? Sure. But is it enough to make a meaningful difference? Probably not.\nScientific studies are sparse and inconclusive # Thus far there have been no large, randomized, controlled, peer-reviewed studies on mask effectiveness against SARS-CoV-2 because it\u0026rsquo;s relatively new. The studies that have been done in 2020 are either non-randomized, not controlled, and not peer reviewed, or they\u0026rsquo;re done using a very small sample size, making the results statistically insignificant. In a meta-analysis of such unscientific studies that specifically looked at SARS-CoV-2, the Lancet said:\nFurther high-quality research, including randomised trials of the optimum physical distance and the effectiveness of different types of masks in the general population and for health-care workers\u0026rsquo; protection, is urgently needed.\nIncidentally, media outlets have picked up on this meta-analysis and have been touting it as proof that masks work. They obviously missed the part that said the studies The Lancet analyzed were unscientific observational studies.\nPrior to 2020, there were many studies done on the effectiveness of masks against the transmission of other viruses. All of these studies have found that when it comes to spreading aerosolized virus particles, there\u0026rsquo;s no statistically significant difference between wearing a mask and not wearing one.\nA false sense of security # So, there\u0026rsquo;s no evidence that masks are helping. But are they hurting? Masks make it easier for a person to conceal their illness. Temperature checks are easily defeated by taking analgesics. Throw in a little Benadryl, and you can\u0026rsquo;t tell the difference between someone who\u0026rsquo;s sick and someone who isn\u0026rsquo;t.\nFor people who are at high risk, masks may present a dangerous false sense of security . Rather than avoiding crowds, an elderly person might attend a large gathering, thinking that they\u0026rsquo;re protected by their own mask or by someone else\u0026rsquo;s. Relying on such an unproven measure as masks is a risky proposition.\nMask are killing small business # Masks are killing small businesses. There are two reasons behind this. First, when people see everyone wearing masks, they conclude that this virus must be really bad, and many will opt to stay home. The psychological weight of seeing masses of people with masks is huge.\nSecond, small businesses have been put in the awkward situation of being told by their local governments that they must enforce masks for employees, and in some cases, for customers. This introduces more friction into an already tense situation. Business owners want to give the customers a pleasant shopping experience, but they\u0026rsquo;re afraid of being fined or shut down by the authorities if the wrong person complains.\nNew doesn\u0026rsquo;t mean different # One of the things that rubbed me wrong about the coverage of the coronavirus was the incessant insistence that it was somehow wildly different than anything we\u0026rsquo;ve ever seen. \u0026ldquo;Unprecedented\u0026rdquo; is a word that suddenly entered the running for most overused words of 2020. But despite what you see in the movies, viruses aren\u0026rsquo;t magic. They can\u0026rsquo;t turn people into zombies, they can\u0026rsquo;t grow wings and fly miles through the air unaided, and they\u0026rsquo;re not indestructible.\nImagine if someone told you that there was a new sort of ransomware that could not only encrypt your data, but could also place a boot on your car and turn your refrigerator into an oven. Would you believe it? Not only would you not believe it, you would probably wonder whether the person telling you this is on drugs. Software isn\u0026rsquo;t magic. Computers operate on a set of rules. So do viruses.\nWhen there\u0026rsquo;s a new or unusual problem, a common mistake is to assume that it requires a new or unusual solution. There\u0026rsquo;s a propensity to assume that the features of other human coronaviruses don\u0026rsquo;t hold true for SARS-CoV-2. But this turns out to be a wrong assumption. SARS-CoV-2 is part of the family of human coronaviruses. Here\u0026rsquo;s what we know about those:\nMost human coronaviruses—such as OC43, NL63, HKU1, and 229E—cause the common cold, which has a typical incubation period of 1-3 days.\nSARS-CoV-2 gains entry into cells by attaching to the ACE2 and TMPRSS2 receptors.\nACE2 receptors are found in significant numbers on the surface of cells in the lungs, intestines, and arteries.\nTMPRSS2 receptors are found in the intestinal tract, kidneys, prostate, and pancreas.\nBoth the NL63 coronavirus which causes the common cold and the original SARS coronavirus use the ACE2 receptor also. 229E and the original SARS also use TMPRSS2.\nThe symptoms of the NL63 coronavirus are remarkably similar to SARS-CoV-2—lower respiratory problems like bronchitis and pneumonia.\nAlmost everyone has been exposed to one of these other coronaviruses, some of which can cause serious illness. They are endemic, and we live with them.\nTrying to slow the spread is futile # In April 2020, Swedish physician Johan Giesecke said in a letter published in The Lancet:\nMeasures to flatten the curve might have an effect, but a lockdown only pushes the severe cases into the future—it will not prevent them.\nHe turned out to be right. Countries like Sweden that didn\u0026rsquo;t lock down are already well past the peak. Countries that did lock down delayed cases to the present, and we\u0026rsquo;re now experiencing that peak.\nIt is often quite symptomless and might pass unnoticed, but it also causes severe disease, and even death, in a proportion of the population, and our most important task is not to stop spread, which is all but futile, but to concentrate on giving the unfortunate victims optimal care.\nIt\u0026rsquo;s time to accept that SARS-CoV-2 is not going away. We\u0026rsquo;re stuck with it. But the good news is that most people will develop immunity to it. And once we reach herd immunity, those few that don\u0026rsquo;t have immunity will be protected.\n","date":"13 October 2020","externalUrl":null,"permalink":"/2020/08/bursting-coronavirus-hype-bubble/","section":"Posts","summary":"","title":"Bursting the Coronavirus Hype Bubble","type":"post"},{"content":"Following are free resources that I\u0026rsquo;ve created or collected.\nBy me # Repositories # My GitHub repo\nMy Docker images repository\nScience Links # One Reason I am Skeptical of an Ancient Earth – Dr. Jay Wile\nAbortion is wrong—ARTL\nCreation.com\nPatterns of Evidence\nReal Science Radio\nThe Steve Deace Show\n","date":"23 August 2020","externalUrl":null,"permalink":"/links/","section":"Ben Piper","summary":"","title":"Free Resources","type":"page"},{"content":"","date":"18 August 2020","externalUrl":null,"permalink":"/tags/2016/","section":"Tags","summary":"","title":"2016","type":"tags"},{"content":"","date":"18 August 2020","externalUrl":null,"permalink":"/categories/ben-pipers-blog/","section":"Categories","summary":"","title":"Ben Piper's Blog","type":"categories"},{"content":"","date":"18 August 2020","externalUrl":null,"permalink":"/categories/blog-feed/","section":"Categories","summary":"","title":"Blog Feed","type":"categories"},{"content":"You took one of the Cisco CCNP exams. You went to the exam center, sat down, and started the exam. About 2 hours later, you saw the dreaded news appear on the screen:\nYou didn’t pass.\nI’ve failed certification exams in the past, so I can relate to the facepalm-worthy feeling you get when you realize you dropped a couple of Benjamins on an exam that you just failed. I know the feeling of wanting to give up, the thoughts of thinking that this whole certification thing is stupid, and the desire to assign blame to whomever or whatever led to your failure.\nFailing certification exams is a reality of any IT professional. And from what I’ve seen, sadly, not many people handle failure very well. I want to talk through this.\nThis isn’t meant to be a pep talk or a “you’ll do better next time” motivational speech. Neither is it meant to be an assignment of blame to you or anyone else. Rather it’s a cold, hard look at why you failed, and how you can pass next time.. or the time after that.\nWhy you failed # I’ve taken a lot of Cisco certification exams and read a lot of Cisco books over the years and I’ve noticed a pattern. Cisco likes to play off of common misconceptions and little known technical facts. Here’s a non-real but representative example:\nTwo switches are connected via an 802.1Q trunk. You delete the switched virtual interface for VLAN 1 but both switches still exchange CDP messages. What will prevent CDP messages from traversing VLAN 1 without affecting Cisco IP phones?\nSelect the best answer:\nA. Prune VLAN1 from the trunk\nB. Disable VLAN1\nC. Disable CDP globally\nD. Disable CDP on the trunk\nE. None of these\nIf you’ve watched my CCNP courses, you’ll recall that you can’t disable VLAN1 or prune it from a trunk. Well, you can try to prune it, but CDP messages will still pass. But do you disable CDP globally or just on the trunk interface? This is where obscure knowledge comes in. Cisco IP phones use CDP to get voice VLAN information, so disabling CDP globally is out. That leaves only two answers: disable CDP on the trunk interface or none of the above. Disabling CDP on the trunk interfaces will certainly stop the CDP messages from moving between the switches, and it won’t affect Cisco IP phones since CDP messages never leave a collision domain.\nNow here’s the thing: I made that question and answer up on the fly. You have to be able to do that if you want to do well on the exam.\nThe exam blueprint is like The Oracle, and sometimes just as wrong # In The Matrix movies, you may remember the Oracle, a computer program that supposedly knows all. After seeing the Oracle for the first time, Neo asks Morpheus how accurate the Oracle’s “prophecies” are. Morpheus responds with something to the effect of, “Try not to think of it in terms of right and wrong. The Oracle is a guide to help you find the path.” Not surprisingly, it turned out the Oracle was kinda wrong on some stuff.\nWell, the blueprint is a lot like that. It has stuff that never shows up on any exam. This is mainly because if the exam covered the entire blueprint, it would be 8 hours long. It also leaves off some topics that do appear on the exam. The lesson here is don’t depend on the exam blueprint. Make sure you know the topics for prerequisite and related exams. If you’re taking CCNP ENARSI, make sure you know the topics for ENCOR. Of course, make sure you know all the CCNA topics upside down and backwards.\nEach exam blueprint is a guide. It’s a guide to the other exam blueprints.\nHow to pass next time.. or the time after # Once you’ve already taken a CCNP exam, the next time you go in to take the same exam, you’re technically “brain dumping” parts of it. I’m not talking about cheating. I mean you’ve seen the exam already, and you have a feel for what the questions are like. If you’ve got lots of time and money, you can take the same exam over and over again, getting slightly better each time until you pass. I don’t recommend this strategy, not just because it’s expensive, but because it puts you in the super awkward situation of telling others how many times you took the exam. Trying until you pass is respectable, but you should have some serious expertise to show for it. If I’m interviewing you and it took you 5 tries to pass a CCNP exam, I’m going to grill you hard on the technical questions.\nIf you want to have a great chance of passing the next time, then study for the certification one step higher than the one you want to attain. If you’re studying for the CCNA, act like you’re studying for the CCNP. If you want the CCNP, act like you’re studying for the CCIE . Obviously the topics are different. You don’t need to study multicast in-depth for your CCNP. But for the topics that overlap, it’s better to overshoot than aim for the bare minimum.\n","date":"18 August 2020","externalUrl":null,"permalink":"/2020/08/you-failed-your-ccnp-exam-now-what/","section":"Posts","summary":"","title":"You failed your CCNP exam. Now what?","type":"post"},{"content":"Note: This is a previously unpublished post I wrote in early 2020. I\u0026rsquo;m posting it now (late 2022) as a reminder that critical thinking based on existing scientific knowledge turned out to be right, while the \u0026ldquo;experts\u0026rdquo; were wrong. Your worldview matters. The \u0026ldquo;experts\u0026rsquo;\u0026rdquo; by and large operate on an evolutionary, progressive worldview that borders on magical thinking. This led them to believe that SARS-2 was capable of doing things no virus in history has been able to do. At the same time, they blindly denied the scientific and common-sense knowledge that masks could not stop an airborne virus. Science-denial, magical thinking, and superstition were hallmarks of \u0026ldquo;the experts\u0026rdquo;. In the end, they were wrong, and traditional (evidence-based) thinking about disease and epidemics was right. Many of the \u0026ldquo;experts\u0026rdquo; were imposters, and not true experts at all.\nLike HIV, the novel coronavirus (SARS-CoV-2) discriminates harshly against certain people and spares others. In healthy individuals, this coronavirus tends to spread more easily than the flu, but is less severe. In unhealthy individuals, who tend to be older, smoke, or have preexisting health conditions, the virus tends to spread less easily than the flu, but is more severe.\nSpread and Severity are Inversely Proportional # Virologists have known for a long time that as a general rule, the more lethal a virus is, the less easily is spreads. A good example of this is rabies which is highly lethal, but which does not spread easily (you have to be bitten to get it).\nOn the flip side, the less virulent a virus is, the easier it spreads. Common cold viruses are a\u0026hellip; common example. Everyone has gotten a cold, and almost nobody has serious complications from it.\nBut this is a generalization, and we need to be more specific. Viruses don\u0026rsquo;t spread by themselves. They need a host, so how easily a virus spreads and how severe it is depend on the host. After being in the US for at least two months, it\u0026rsquo;s clear that the novel coronavirus (SARS-CoV-2) causes mild or no symptoms in healthy, young people, and very severe symptoms in unhealthy people, particularly the elderly. We can break down this distinction between healthy and unhealthy recipients of the virus as follows:\nHealthy Unhealthy Mild symptoms Severe symptoms Good outcomes Poor outcomes Young (\u0026lt; 50 years) \u0026gt; 50 years Never-smoker Smoker No pre-existing health conditions Hypertension, heart or lung disease, diabetes To sum it up, if you\u0026rsquo;re young and healthy, then your risk of suffering serious complications from the virus is lower than that of the flu. On the other hand, if you\u0026rsquo;re unhealthy, you\u0026rsquo;re at a much greater risk of needing more intense medical treatment should you become infected. If you do have severe symptoms, however, you\u0026rsquo;re less likely to spread it because you\u0026rsquo;re going to avoid others, and they\u0026rsquo;re going to avoid you.\nNow here\u0026rsquo;s the good news. About 2/3 of the US population is under 50, and tend to have better outcomes with this novel coronavirus. Younger people move around more, and are thus more likely to contract it and develop immunity to it. Therefore, even though a lot of people under 50 will likely get infected, most of those infections will result in mild symptoms and herd immunity that will protect the unhealthy population. This is the principle behind vaccinations, and we know it works.\nHere is the bad news: as the virus spreads, unhealthy, high-risk people will inevitably get it. Isolation is especially important for unhealthy people until herd immunity develops in the less vulnerable population. Sadly, we seems to be taking the opposite approach. Stores are encouraging senior citizens to shop together by setting special store hours just for them! This is a terrible idea. Strangely, in some states, if those same senior citizens wanted to meet at a restuarant for coffee and conversation, they wouldn\u0026rsquo;t be allowed to.\nThe Diamond Princess: A Petri Dish # The novel coronavirus causes severe symptoms in a fair number of vulnerable people, so we can be quite certain that it doesn\u0026rsquo;t spread nearly as easily as many people fear. But just how easily does it spread? The Diamond Princess cruise ship is an instructive example.\nCoronavirus infections broke out on this ship of over 3,700 passengers, about 712 of whom tested positive. That\u0026rsquo;s about a 19% infection rate under nearly optimal conditions. Passengers on the Diamond Princess cruise ship didn\u0026rsquo;t practice \u0026ldquo;social distancing.\u0026rdquo; Quite the opposite. Everyone was breathing the same air, touching the same objects, and being in close quarters with everyone else for weeks on end. This data point should have clued us into the fact that this thing doesn\u0026rsquo;t spread all that easily. If it did, most people would\u0026rsquo;ve gotten infected.\nSARS-CoV-2 will mutate to become more mild but spread more easily # Only in the movies do viruses mutate and become more severe. In reality, the opposite usually occurs: the virus either mutates and becomes less severe (as the H1N1 swine flu did), or it just disappears (like SARS). Community-spread coronaviruses either disappear or turn into the common cold. The same thing is already happening with the SARS-CoV-2 virus. There are two types: S and L. The S type is what blew up in Wuhan and caused havoc. The L type is milder and more prevalent, but spreads more easily, and is already overtaking the S type. As time goes on, the virus will mutate to become more transmissible, but less lethal. This is, quite literally, devolution.\nIt May Spread More Easily Than the Flu # In the span of 3 months (January 2020 through March 2020), the US has had about 200,000 cases of novel coronavirus. That comes to about 3,000 people per day. Compare that with the number for the flu. According to the CDC, between September 2019 and March 2020, there were over 220,000 positive flu tests in the US. That comes to over 1,200 per day. (And imagine how much higher the flu numbers would be if there weren\u0026rsquo;t a flu vaccine!)\nOf course, we need to consider that this isn\u0026rsquo;t an apples-to-apples comparison. The high number of flu cases is due to the fact that flu viruses are always circulating, and anyone with symptoms can get a flu test. With few exceptions, the only people who can get a coronavirus test are those with known contact with a coronavirus patient and symptoms. Consequently, there haven\u0026rsquo;t been nearly as many coronavirus tests as flu tests. This is where looking at the rate of positives can help us. The positive rate is important because it gives us an idea of how much the virus has actually spread, and hence, how contagious it is. The following table contrasts the rate of positive flu tests and coronavirus tests in the US.\nVirus Rate of positive tests in the US Flu viruses 20.5% Novel coronavirus 17% Over 80% of people tested were negative for the coronavirus. These are people who came in contact with an infected person and had symptoms. But we have to be careful not to jump to conclusions. The number varies drastically by state, as follows:\nState Rate of positive tests New York 35.7% New Jersey 39.7% Washington 7.5% New Mexico 2.1% The population density correlates to the rate of positive tests. New York and New Jersey have incredbly high densities. Washington\u0026rsquo;s population density is somewhat lower, and New Mexico\u0026rsquo;s is incredibly low. This makes sense considering that SARS-CoV-2 is a respiratory virus that spreads through coughing and sneezing. This tells us that general quarantines and other drastic measures were overkill, and should be limited to densely populated areas.\nAsymptomatic People Aren\u0026rsquo;t Spreading It # Keep in mind that until recently, in order to even get a test, you must have symptoms and have had contact with someone else who tested positive. Some say that if we tested asymptomatic people, the rate of positives would be much higher. But remember that symptomatic people with known contacts are testing positive at a rate of 17% or less in most areas of the country. Therefore, asymptomatic people with known contacts would test positive at an even lower rate.\nBut for the sake of argument, let\u0026rsquo;s assume that we test asymptomatic people and the number of positives is high, let\u0026rsquo;s say 80%. That would suggest that this virus causes mostly mild illness. And if that were true, the number of symptomatic people testing positive in New York would be much higher than 39.7%. The math tells the story. Asymptomatic people just aren\u0026rsquo;t spreading this virus around.\nAll this strongly suggests one conclusion: the virus causes mild but noticeable symptoms and spreads easily. And that means quarantines and other isolation measures should be limited to high-risk populations.\nWe Need Honest Experts # Why all the shutdowns, lockdowns, quarantines, and cancellations? If you listen to the epidemiologists, virologists, and medical doctors, speak on the coronavirus you may notice a particular phrase that they keep using regarding the virus. The phrase is:\n\u0026ldquo;We don\u0026rsquo;t know\u0026rdquo;\nThe moment an expert utters the phrase, \u0026ldquo;I don\u0026rsquo;t know\u0026rdquo; in regards to a topic, that topic is outside their field of expertise. Because the medical experts don\u0026rsquo;t know where and when the virus will spread, they\u0026rsquo;re erring on the side of extreme caution by suggesting avoiding gathering in groups and staying home if you\u0026rsquo;re in a high-risk group. I believe much of the panic we\u0026rsquo;ve seen is due to people failing to making this critical distinction.\nThe experts\u0026rsquo; blanket isolation suggestion is not based on evidence, but on the absence of evidence. The experts aren\u0026rsquo;t recommending shutdowns and cancellations because they\u0026rsquo;re necessary. They\u0026rsquo;re recommending them because they believe they\u0026rsquo;re the safest option. Both personally and professionally, there is little downside if they err on the side of caution, but plenty of downside if they don\u0026rsquo;t. We have to remember that the medical experts are scientists, and they will not recommend returning to normal until they have solid data that the danger has passed. That means only after this is over will they say it\u0026rsquo;s safe, and right now, we don\u0026rsquo;t know when that will be.\nIt sounds strange, but those of us who aren\u0026rsquo;t experts may have to say what the experts are thinking but just can\u0026rsquo;t say. They know how viruses work. They know that the odds of this thing turning into a 1918 Spanish Flu is extremely unlikely. They also know that they can\u0026rsquo;t afford to be wrong. Even a slight error could be career-ending. The experts have a vested interest in not being honest about good news.\nErring on the side of caution is generally wise. But an indefinite shutdown isn\u0026rsquo;t going to work. People are losing jobs, money, and the opportunity to see the people they love and to do the things they enjoy. Life-saving surgeries and treatments are being cancelled. And not even high-risk people can live in perpetual isolation.\nWe non-experts with no academic or career skin in the game need to look at the data, think carefully about it, and come to a conclusion about when we\u0026rsquo;re going to go outside and play again.\nThe Curve is Barely a Speedbump # You may have heard the mantra about \u0026ldquo;flattening the curve\u0026rdquo;. This refers to slowing the spread so that the healthcare system isn\u0026rsquo;t overwhelmed by a surge of new cases requiring critical care. This seemingly soberminded assertion is based on the assumption that this virus will put some sort of an unusual or even unprecedented strain on limited medical resources.\nBut for the reasons I just laid out, there simply won\u0026rsquo;t be enough cases to strain the medical system across the US. Not even close. And of the cases that occur, most (~80%) won\u0026rsquo;t require hospitalization because they cause only mild symptoms. Right now the curve is barely a speedbump. Of course, don\u0026rsquo;t take my word for it. Try to find a story about US hospitals being overwhelmed with coronavirus patients. The only stories you\u0026rsquo;ll find will be about hospitals that were already under strain even before this virus, particularly in large cities (New York, Seattle, and cities in California).\nBetter Safe Than Sorry? # The amount of attention on this new coronavirus\u0026ndash;particularly of the panic-driven variety\u0026ndash;has been like nothing I\u0026rsquo;ve seen. The closest I can remember was in the 1990s when everyone was afraid of catching HIV from a toilet seat.\nCancelling large gatherings will save lives regardless of whether there\u0026rsquo;s a pandemic. It will reduce traffic accidents, violent encounters, drunk driving, heart disease, cancer, and a lot of other things. But we don\u0026rsquo;t need a nuclear bomb to kill a cockroach.\nIf the criteria for cancelling events is that it will reduce some risk, then we can justify cancelling anything at any time. But as we\u0026rsquo;ve established, the relative risk of getting this virus is low. And if you\u0026rsquo;re healthy, the risk of serious symptoms is also quite low.\nQuarantines work on a small scale. In densely populated countries like Italy, they make sense. In a vast country like the United States, a nationwide suggestion to avoid groups is both unnecessary and unrealistic. Viruses can\u0026rsquo;t rocket through the air over miles. They can only travel as fast as people can. Shutdowns and cancellations should be limited to densely populated areas or areas with populations that are at especially high risk. For instance, a convention for elderly cancer patients is not a good idea right now. But this virus just doesn\u0026rsquo;t spread that easily, so everyone else should go about their daily business, taking all the same precautions that they should normally take during flu season.\nShutdowns should also apply consistently. It makes no sense to close restaurants but keep stores open. Shopping in a store with 50 other people isn\u0026rsquo;t any safer than being at a restaurant with 50 other people.\nViruses Do Discriminate # Thousands of people have died from this virus, so we should take it seriously. And taking it seriously means doing serious thinking, not just reacting. Those with the worst outcomes tend to be older than 50 or have preexisting health conditions, particularly heart or lung conditions, cancer, or diabetes. Some people are born with or develop these conditions through no fault of their own. Others cause or exacerbate their conditions through their behaviors, such as smoking, drinking or eating too much, or promiscuity.\nSome countries are healthier than others. China and Italty, which have a high case fatality rate, both have large smoking populations. And in Italy, it\u0026rsquo;s customary to kiss someone when you greet them. As with any respiratory illness, those with reduced lung function, diabetes, cancer, or anything else that suppresses the immune system are at much higher risk. The unhealthier the population, the higher the case fatality rate.\nThis leads us back to the commonsense advice everyone should have been following all along, and that would have prevented much of the pandemic. Wash your hands. Eat healthy. Don\u0026rsquo;t smoke, drink excessively, or do drugs. Be monogamous. Keep your weight in check.\nPredictions # I\u0026rsquo;ll end this with my predictions:\nThe mass quarantines and isolation (\u0026ldquo;social distancing\u0026rdquo;) will prove to have been unnecessary. One of the biggest risk factors for death will turn out to be smoking. Many people won\u0026rsquo;t learn from this pandemic. They\u0026rsquo;ll fail to evaluate their own response to it, and will fail to acknowledge that their reaction was disproportionate. Instead, they\u0026rsquo;ll just live in fear of the next virus. But I hope I\u0026rsquo;m wrong about this one. Agree or disagree with them, I urge you to do a couple of things. Carefully study the raw data from primary sources (e.g. CDC, WHO, etc.) and think about what it all means. Ignore charts and infographics that don\u0026rsquo;t include a citation. And verify any citations to make sure the pretty picture accurately reflects the data.\n","date":"30 March 2020","externalUrl":null,"permalink":"/post/2020/sars-cov-2-coronavirus/","section":"Posts","summary":"","title":"The SARS-CoV-2 Coronavirus Discriminates","type":"post"},{"content":" For engineers who need networking to stay debuggable # Sales proof: 2,000+ net copies lifetime — solo-authored (1,800+ print) — $60k+ publisher net. Wiley/Sybex.\nCovers architecture, virtualization, infrastructure, network assurance, security, and automation — with emphasis on fundamentals that prevent \u0026ldquo;IP names the device\u0026rdquo; and \u0026ldquo;bits is bits\u0026rdquo; assumptions.\nWho this is for # CCNP candidates, network engineers moving from CCNA Teams that need senior-level troubleshooting rigor Buy # View on Amazon (affiliate) Errata: benpiper.github.io/encor ","date":"15 March 2020","externalUrl":null,"permalink":"/books/ccnp-encor-350-401/","section":"Books","summary":"","title":"CCNP Enterprise Certification Study Guide: Implementing and Operating Cisco Enterprise Network Core Technologies (350-401 ENCOR)","type":"page"},{"content":"","date":"1 February 2020","externalUrl":null,"permalink":"/encor/","section":"Ben Piper","summary":"","title":"Resources for the CCNP Enterprise Certification Study Guide: Exam 350-401","type":"page"},{"content":"January 31, 2020 update: No, you\u0026rsquo;re not crazy. Cisco changed the exam number from 300-401 to 350-401 .\nFor your convenience, I\u0026rsquo;ve put together the following list of my courses that cover the new CCNP ENCOR exam. By watching and following along with the hands-on demos in these courses, you can\u0026rsquo;t go wrong.\nRouting # Cisco Enterprise Networks: Basic Networking and IP Fundamentals\nCisco Enterprise Networks: Implementing OSPF\nCisco Enterprise Networks: Implementing EIGRP\nCisco Enterprise Networks: BGP and Path Control\nCisco Enterprise Networks: NAT and Security\nSwitching # Cisco Enterprise Networks: VLANs and Trunking\nCisco Enterprise Networks: Spanning Tree Protocols and EtherChannels\nCisco Enterprise Networks: First Hop Redundancy Protocols\nCisco Enterprise Networks: Infrastructure Security (DHCP snooping, dynamic ARP inspection, port-based access control, TACACS+/RADIUS)]\nTroubleshooting # Cisco Enterprise Networks: Layer 2 Troubleshooting\nCisco Enterprise Networks: Troubleshooting BGP and GRE Tunnels\nCisco Enterprise Networks: Troubleshooting OSPF and EIGRP for IPv4\nCisco Enterprise Networks: Troubleshooting OSPF and EIGRP for IPv6\nBy the way, the blueprint for the ENCOR exam is mostly the same as the CCNP Routing \u0026amp; Switching track. In fact, the fundamentals are almost 100% identical. That means that you can prepare for the CCNP ENCOR exam by using existing R\u0026amp;S training materials.\n","date":"10 January 2020","externalUrl":null,"permalink":"/2020/01/preparing-ccnp-350-401-encor-exam/","section":"Posts","summary":"","title":"Preparing for the CCNP 350-401 ENCOR Exam","type":"post"},{"content":"","date":"22 December 2019","externalUrl":null,"permalink":"/tags/2019/","section":"Tags","summary":"","title":"2019","type":"tags"},{"content":"In his piece on the topic of pseudoscience, Prof. Steven Dutch of the University of Wisconsin says:\nTheories that claim to be scientific but fly in the face of scientific consensus are often called pseudoscience\nThis is a strange definition of pseudoscience. It\u0026rsquo;s tempting to try to tighten the definition, but as I\u0026rsquo;ll argue, the very term pseudoscience is meaningless and not worth saving. Dutch provides three criteria for calling something the \u0026ldquo;p\u0026rdquo; word:\nDemonstrably faulty observations or theories, or elaborate speculation without an adequate basis. This is so vague it could be applied to theoretical astrophysics and quantum field theory. Will he narrow down this definition a little more later on?\nUsually Supported by logical fallacies. The only way it\u0026rsquo;s possible to accept faulty data is through faulty reasoning. This is full of irony, as it is itself a logical fallacy (affirming the consequent). Certainly one way people accept faulty data is through faulty reasoning, but it\u0026rsquo;s not the only way. Something as simple as a broken instrument can lead one to accept faulty data, even though their reasoning may be perfectly sound.\nIn open defiance of scientific consensus Science advances by new evidence, new discoveries, and new ways of thinking about things. Throughout history there\u0026rsquo;s been \u0026ldquo;scientific consensus\u0026rdquo; on all sorts of stupid ideas. When a minority of scientists came along to correct it, were they practicing \u0026ldquo;pseudoscience?\u0026rdquo; No. It\u0026rsquo;s a silly point. It needs a retraction.\nHe then goes on to provide a much longer list of what pseudoscience is not. He says pseudoscience is not \u0026ldquo;Defined by personal disagreement\u0026rdquo;. Well, now things are getting interesting! Couldn\u0026rsquo;t people legitimately disagree on what constitutes a \u0026ldquo;faulty observation\u0026rdquo; or \u0026ldquo;adequate basis?\u0026rdquo; And how does this square with the idea that anything that goes against the \u0026ldquo;scientific consensus\u0026rdquo; (whatever that is) is \u0026ldquo;pseudoscience?\u0026rdquo;\nDutch goes into listing what he calls branches of pseudoscience, including \u0026ldquo;mystical\u0026rdquo; and \u0026ldquo;resentment of authority\u0026rdquo;. At this point, I began to suspect that he was placing certain things under the heading of \u0026ldquo;pseudoscience\u0026rdquo; that were never put forth by anybody as real science. For example, under the \u0026ldquo;mystical\u0026rdquo; branch of pseudoscience, he gives the examples of \u0026ldquo;Psychic\u0026rdquo; and \u0026ldquo;Astrology.\u0026rdquo; While I\u0026rsquo;m sure Miss Cleo and others who stand to profit from it have claimed astrology is scientific, I don\u0026rsquo;t think most people who read horoscopes think that there\u0026rsquo;s anything scientific about astrology. Quite the opposite. If astrologers presented horoscopes as scientific, they wouldn\u0026rsquo;t be mystical, and that would make them boring to free-spirit types.\nThink of this it this way: If a person believes that fairies speak to her through the television and give her visions of kittens eating rainbows and humming jazz tunes, would Dutch call this \u0026ldquo;pseudoscience?\u0026rdquo; I certainly hope not. It\u0026rsquo;s not even ostensibly scientific. It\u0026rsquo;s in a whole different realm.\nAnother branch he lists as a pseudoscience is \u0026ldquo;junk science.\u0026rdquo; He gives as an example, \u0026ldquo;Dismissal of dangers of marijuana by legalization advocates\u0026rdquo;. Again, this is not an example of wishful thinking put forth as science. Rather, it\u0026rsquo;s just denial of an conclusion supported by scientific evidence. He also lists \u0026ldquo;Diet fads\u0026rdquo; and \u0026ldquo;Quack medical cures\u0026rdquo; under this heading. These are his best examples of pseudoscience, and I think where his definition should focus. But the rest of his examples nobody even considers to be science.\nPseudoscience or pseudohistory? # Dutch then charges into a long bulleted list of the supposed reasons people believe in pseudoscience. One thing that caught my eye was the prediction that Muslims might begin to deny the Apollo moon landing. Of course, many people of other religions have already done this. But is this really pseudoscience, or pseudohistory? While the Apollo moon landing certainly involved a tremendous amount of scientific effort, and while landing on the moon was quite an experiment, the event itself is an historical event. Those who claim the U.S. never landed on the moon don\u0026rsquo;t dispute that lots of science was involved. In fact, many conspiracy theorists claim a lot of science went into faking the moon landing. They don\u0026rsquo;t dispute the science. What they dispute is the historicity. This isn\u0026rsquo;t pseudoscience. It\u0026rsquo;s just denying history.\nBizarrely, Dutch includes this gem among the reasons people believe in pseudoscience:\nCreationism. Anti-evolutionists attribute all the ills of society to evolution and its alleged weakening of belief in the Bible.\nNo anti-evolutionist (e.g. creationist) attributes \u0026ldquo;all the ills of society\u0026rdquo; to belief in evolution. If Dutch simply read the first few chapters of Geneis, he\u0026rsquo;d realize that Scripture traces \u0026ldquo;all the ills of society\u0026rdquo; back to original sin. Giving him the benefit of the doubt, I won\u0026rsquo;t assume he included this simply as an excuse to take an embarrassingly weak cheap shot at Christians. Being charitable, I\u0026rsquo;ll assume his intellectual circle is insular, and he simply doesn\u0026rsquo;t know many Christians and doesn\u0026rsquo;t read the Bible all that much.\nInventing new logical fallacies # Many who write about science (be they scientists or not) either aren\u0026rsquo;t well trained in logic or have forgotten their training. While I don\u0026rsquo;t accuse Dutch of falling into this category, some of the \u0026ldquo;logical fallacies\u0026rdquo; he presents as markers of pseudoscience aren\u0026rsquo;t really fallacies at all.\nThe first \u0026ldquo;fallacy\u0026rdquo; that I had to do some research on is the \u0026ldquo;Residue fallacy.\u0026rdquo; The fallacy is that if you have a phenomenon, like a UFO sighting, and you can explain away 95% of the cases, then the remaining 5% might be legitimate sightings. As someone who wants to combat pseudoscience, Dutch needs to be careful with this one because it cuts both ways. Consider the statement, \u0026ldquo;85% of smokers who died had lung cancer. The remaining 15% died of unexplained causes.\u0026rdquo; If you conclude that the remaining 15% might not have had lung cancer, then you\u0026rsquo;re guilty of the \u0026ldquo;residue fallacy\u0026rdquo;. Clearly, this isn\u0026rsquo;t a fallacy at all.\nConspiracy theories # The last and most intriguing one is \u0026ldquo;Conspiratorial outlook\u0026rdquo; and it deserves a closer look because Dutch himself is himself engaging in a logical fallacy by listing this. Dutch writes:\nThe single most reliable indicator of pseudoscience. Almost every pseudoscientist sooner or later (usually sooner) claims to be the victim of a conspiracy to suppress his discoveries, or the theory itself revolves around a conspiracy.\nReplace the word \u0026ldquo;suppress\u0026rdquo; with \u0026ldquo;deny\u0026rdquo; and you\u0026rsquo;ll quickly see where I\u0026rsquo;m going with this. The first conspiracy theory that came to my mind was, \u0026ldquo;Big oil denying evidence of global warming.\u0026rdquo; The second was, \u0026ldquo;Intelligent design advocates suppressing the teaching of evolution in public schools.\u0026rdquo; According to this most reliable indicator, global warming and evolution are pseudoscience! Dutch really needs to rethink this one. Claiming a conspiracy isn\u0026rsquo;t a logical fallacy, nor is it even a sign of incorrectness. There are people who believe in conspriacy theories who also believe in real science. Saying that people who claim conspiracy theories are practicing pseudoscience, however, is a genetic logical fallacy \u0026ndash; ad hominem.\nDutch follows with a more in-depth discussion of conspiracy theories. He says, \u0026ldquo;They are impossible to disprove so they can\u0026rsquo;t be tested.\u0026rdquo; That statement itself is impossible to disprove, and hence can\u0026rsquo;t be tested. In fact, some of what passes as science can\u0026rsquo;t be tested, let alone disproved. On the whole, however, he\u0026rsquo;s correct in his assessment that conspiracy arguments strike at the emotions and promote fantastical thoughts of forces so intelligent and powerful that they leave behind no evidence. But yet again, this is irrelevant to pseudoscience per se, and is only tangentially relevant to the supposed reasons people believe in pseudoscience \u0026ndash; a term he still hasn\u0026rsquo;t defined very well.\nDutch somewhat clarifies his position at the end by saying, \u0026ldquo;It\u0026rsquo;s not proper to dismiss an idea solely because it postulates a conspiracy.\u0026rdquo; I can\u0026rsquo;t help but come away from this section thinking that this all has very little to do with pseudoscience. Many who believe in conspiracy theories are mentally ill, or at least have some psychological issues. Someone who believes aliens are conspiring with the government to control the weather isn\u0026rsquo;t necessarily practicing pseudoscience \u0026ndash; maybe they\u0026rsquo;re just crazy. Once again, he\u0026rsquo;s stretching the definition of pseudoscience too far.\nScience can\u0026rsquo;t prove itself right, so it must be wrong? # In the next section, Dutch makes a wild claim: \u0026ldquo;ideas are wrong until proven right\u0026rdquo;. If you buy that, then his statement is wrong until proven right. But Dutch never proves it right. He just puts it out there. So Dutch, according to his own statement, is wrong. Obviously, we have to start somewhere. But why start from the assumption that ideas are wrong until proven right? Why not start by assuming they\u0026rsquo;re right until proven wrong? He doesn\u0026rsquo;t answer this, which is a shame because he missed an opportunity to tighten his definition of pseudoscience and make his case against it much more compelling.\nI\u0026rsquo;ll briefly address this notion of the benefit of the doubt \u0026ndash; the question of whether we should consider ideas right or wrong until proven otherwise. Let\u0026rsquo;s take two examples.\nExample 1 # Your spouse comes up to you and asks to have $20 to go get gas in the car because it\u0026rsquo;s almost empty. Do you demand proof that the gas tank is almost empty? Or do you believe that it\u0026rsquo;s almost empty absent any evidence to the contrary?\nExample 2 # A stranger approaches you on the street and asks to have $20 to go get gas in his car because it\u0026rsquo;s almost empty. Do you demand proof that the gas tank is almost empty? Or do you believe that it\u0026rsquo;s almost empty absent any evidence to the contrary?\nWhere the burden of proof rests \u0026ndash; with the claim or against it \u0026ndash; depends on the circumstances and the people involved. I think many, especially those involved with science, don\u0026rsquo;t like to admit this because it looks biased. It\u0026rsquo;s hard to maintain the image of a dispassionate, objective scientist when you admit that you sometimes practice favoritism and appeal to authority. But the fact is everyone does it, even scientists. In fact, even Dutch himself alluded to this when he defended \u0026ldquo;scientific consensus\u0026rdquo; which is nothing more than appeal to authority\u0026ndash;a real logical fallacy.\nConclusion # The bottom line is that \u0026ldquo;pseudoscience\u0026rdquo; is, at best, a useless term. At worst, it\u0026rsquo;s a propagandistic tool to stifle debate and free inquiry. Unfortunately, it seems most uses of the word fall under the latter. If your conclusion doesn\u0026rsquo;t agree with the scientific consensus (whatever that is), it\u0026rsquo;s therefore pseudoscience. Be gone! It\u0026rsquo;s time to let the word die. Rather than branding a wrong idea as pseudoscience, just call it what it is: wrong.\n","date":"22 December 2019","externalUrl":null,"permalink":"/articles/pseudoscience-doesnt-mean-what-you-think/","section":"Articles","summary":"","title":"Pseudoscience: The word doesn't mean what you think it means","type":"page"},{"content":"While playing around with AWS CloudWatch Log Insights to analyze VPC flow logs, I thought of a couple of fun ways to identify (probably) malicious traffic.\nFinding Vulnerability Scanners # These are the guys that hammer your box looking for anything from silly SQL injection attacks (so 2005) to CSRF vulnerabilities . The tell: look for hosts that reuse the same source port.\nThe Query # filter (srcPort \u0026amp;gt; 1024 and srcAddr != \u0026#34;private-IP\u0026#34;) | stats count(*) as records by srcAddr,srcPort | sort records desc | limit 5 The Results # Suspicious traffic from the same source port\nFinding Port Scanners # They just want to know if anybody’s listening. The tell: sending packets to a bunch of closed ports.\nThe Query # filter (action=\u0026#34;REJECT\u0026#34;) | stats count_distinct(dstPort) as portcount by srcAddr | sort portcount desc | limit 5 The Results # The same source sending packets to a bunch of different ports\n","date":"28 July 2019","externalUrl":null,"permalink":"/2019/07/finding-suspicious-traffic-using-cloudwatch-log-insights-and-vpc-flow-logs/","section":"Posts","summary":"","title":"Finding Suspicious Traffic using CloudWatch Log Insights and VPC Flow Logs","type":"post"},{"content":" For those new to AWS cloud — fundamentals without hype # Sales proof: 32,000+ copies of AWS Cloud Practitioner (CLF-C01) 1st Ed lifetime (25,000+ print) — $690k+ publisher net, part of 44,000+ across AWS Cloud Practitioner (CLF) franchise ($1M+ net). Co-authored with David Clinton, Wiley/Sybex — Amazon bestseller history.\nThis book covers core services, pricing models, billing, and security fundamentals — the basics that prevent \u0026ldquo;cloud is cheaper\u0026rdquo; misconceptions later.\nWho this is for # True beginner to cloud, junior engineers needing basics repeated Teams evaluating train vs hire for cloud skills Foundation for SAA-C03 path Buy # View on Amazon (affiliate) Errata: awsccp.github.io ","date":"15 July 2019","externalUrl":null,"permalink":"/books/aws-clf-c01/","section":"Books","summary":"","title":"AWS Certified Cloud Practitioner Study Guide: CLF-C01 Exam","type":"page"},{"content":"","date":"15 July 2019","externalUrl":null,"permalink":"/tags/clf-c01/","section":"Tags","summary":"","title":"Clf-C01","type":"tags"},{"content":"","date":"6 June 2019","externalUrl":null,"permalink":"/categories/2019/","section":"Categories","summary":"","title":"2019","type":"categories"},{"content":"As an AWS customer, you share responsibility with AWS for the security of your data the cloud. There’s a mantra: AWS handles the security of the cloud, but you handle security in the cloud.\nBut it turns out that’s not quite true. For more, check out my guide ","date":"6 June 2019","externalUrl":null,"permalink":"/2019/06/understanding-the-aws-shared-responsibility-model/","section":"Posts","summary":"","title":"Understanding the AWS Shared Responsibility Model","type":"post"},{"content":"As someone who works in IT, I hear and read a lot of comments about science. One common but unfortunate claim is that “science is not about finding truth.” While I won’t get into the underlying philosophical reasons behind this claim, I do want to at least respond to it on its face.\nEtymology of the word “science” # The word science comes from the Latin scientia, meaning knowledge.\nPlato said that knowledge is “justified true belief.” I’m not a big fan of Plato, but this is a good definition. Put another way, knowledge is what you believe to be true (a) that actually is true and (b) for which you have reason to believe is true. That’s less concise, but it hits all the important points.\nIf that’s not convincing, we could just skip to Encyclopedia Britannica, which says:\nIn general, a science involves a pursuit of knowledge covering general truths or the operations of fundamental laws.[1]\nWhat’s the point of science? # As practical matter, if science isn’t about finding truth, then why should anyone care about it at all? If the purpose of science isn’t to discover truth, then it’s nothing more than fictional storytelling.\nScience should be about finding truth. The concept of truth us, at its core, a fundamental component of logic. The proposition that 2 +2 = 4 is either true or false. Some have said that science deals with facts and not truth, but this is a distinction without a difference. Science has to make decisions about facts and come to conclusions based on them. Saying that science deals with facts and not truth is like saying math deals with numbers but not equations. It’s, well, false.\nThe imprecise language of “science communicators” doesn’t help # Although scientists carefully think about their craft, many “science lovers” and “science communicators” do not. They throw around words like “facts” in completely wrong ways. One of the more common cliches is, “gravity is a fact.” Gravity is a force. It’s no more a “fact” than electromagnetism. A fact would be a measurement of gravitational energy. This might sound nit-picky, but when you’re dealing with science, nit-pickiness is important. You can’t just fudge definitions and assume everyone understands what you mean. But this is exactly what happens in popular science.\nIt’s probably science? # There’s been a shift towards saying that science deals not with certainty but only with probabilities. The insinuation is that the probability of a scientific claim is never 100%. Hence, you’ll see a scientific claim couched with a “probably” and usually with the disclaimer that it’s “the best explanation”. Take for example this bit from the National Institutes of Health:\nDepression, like other mental illnesses, is probably caused by a combination of biological, environmental, and social factors, but the exact causes are not yet known.[2]\nYou’ll likely never see a research paper that claims depression is certainly, without a doubt caused by a combination of those factors. The only assurance you get is that it’s probably the best explanation.\nBut now you have another problem: What’s the probability that is really is the best explanation? Perhaps some obscure researcher has a better explanation and hasn’t published it yet. The notion of “a best explanation” isn’t possible when you are only allowed to deal in probabilities. The “best explanation” then becomes “probably the best explanation.” So the whole thing falls apart.\nEarth is certainly, and not probably, a sphere # Let’s take a more concrete example. There’s a 100% probability that Earth is a sphere. It’s not 99.9% or 99.0% or anything less. In fact, we can just forget probabilities altogether. It’s a scientific certainty that Earth is round. But as soon as you adopt the belief that science deals only in probabilities, you can no longer claim with 100% certainty that it’s a sphere. Instead, you’d have to say, “It’s probably a sphere” or “Earth being a sphere is the best explanation for why it looks round.” That’s ridiculous!\nKnowledge is necessarily certain # Science means knowledge, and knowledge is necessarily certain. If you think you know something but aren’t certain, then you don’t truly know it.\nPart of the solution then to the watering down of the word “science” is to avoid misusing it. That means, to the chagrin of many, removing the moniker of “science” from disciplines that don’t always deal in certainties, i.e. knowledge. That means psychology, anthropology, and history aren’t science, just to name a few. That doesn’t mean they’re less valuable or less worthy of study, it just means they don’t meet the strict criteria of science.\n","date":"3 June 2019","externalUrl":null,"permalink":"/2019/06/science-discovering-truth/","section":"Posts","summary":"","title":"Science is About Discovering the Truth","type":"post"},{"content":"Whether you prefer to read or watch a video, here are some AWS certification training resources I\u0026rsquo;ve put together for you.\nStudy Guides # The following study guides include hundreds of assessment questions and answers as well as online access to graded practice exams.\nThe AWS Certified Solutions Architect Study Guide: Associate by David Clinton and myself covers more than you need to know to pass the exam. If you don\u0026rsquo;t believe me, just click the link and look at the reviews on Amazon.\nIf you are fairly new to AWS, you\u0026rsquo;re better off starting with the AWS Certified Cloud Practitioner Study Guide, also by David Clinton and yours truly. Even if you don’t plan to take the entry-level Cloud Practitioner exam, this book will give you a solid foundation on which to build.\nVideo Courses # The Solutions Architect: Associate exam focuses heavily on the Well-architected Framework. The following courses cover these:\nArchitecting for Reliability on AWS Architecting for Security on AWS Architecting for Performance Efficiency on AWS Architecting for Cost on AWS Architecting for Operational Excellence on AWS If you don’t have a solid networking background, you may find AWS networking a bit confusing. To get you up to speed, I’ve created three AWS networking deep-dive courses:\nAWS Networking Deep Dive: Virtual Private Cloud (VPC)\nAWS Networking Deep Dive: Elastic Load Balancing (ELB)\nAWS Networking Deep Dive: Route 53 DNS\nIn addition to videos, you get exercise files so that you can follow along with the demonstrations, access to discussion boards, and graded assessments. If you\u0026rsquo;re not a subscriber, you can still take advantage of a 10-day free trial.\n","date":"1 May 2019","externalUrl":null,"permalink":"/2019/05/studying-for-the-aws-certified-solutions-architect-associate-exam-saa-c01/","section":"Posts","summary":"","title":"Studying for the AWS Certified Solutions Architect: Associate Exam","type":"post"},{"content":"","date":"2 April 2019","externalUrl":null,"permalink":"/tags/cloudformation/","section":"Tags","summary":"","title":"Cloudformation","type":"tags"},{"content":"","date":"2 April 2019","externalUrl":null,"permalink":"/tags/infrastructure-as-code/","section":"Tags","summary":"","title":"Infrastructure-as-Code","type":"tags"},{"content":"People use the term “operational excellence” in a lot of different ways. In its vaguest sense, it means continuous improvement as applied to operations. But you’re interested in what it means in the context of technology operations. And I’m here to tell you that it means automation.\nOperational Excellence is one of the five pillars of the AWS Well-architected Framework. The AWS whitepaper lists six design principles for achieving operational excellence. I’ve paraphrased these principles for clarity. Here they are:\nDefine everything as code # This is easily the most obvious. Turn everything into code that can be automatically executed by a machine. This includes the building of infrastructure, application deployments, testing, recovery, and anything that requires or benefits from being defined in a runbook. If it’s a repeatable process, code it and let a machine do it.\nDocumentation as input and output # The delightful side-effect of defining everything as code is that code can serve as documentation. It becomes trivial to have a machine take code as input, execute it, and then generate some pretty documentation based on a template. The resulting documentation can then be used by another machine. All automatically, of course.\nChanges should be as small and frequent as possible # Without getting into the rationale behind this, the point is that the only way to make small changes as frequently as possible is to use automation . Pushing a code change to a repo whence it’s automagically built, deployed, and documented is faster than doing any of that manually. Reversing a change automatically is faster, too.\nLook for things to automate # If you’re not automating something, and you can, then do it. Of course, you should avoid automating a bad process. Fix the process and automate it. And if there’s nothing to automate right now, keep looking, because changes will inevitably bring opportunities for automation.\nInject failures # Break things to cause failures. If recovering from those failures requires manual intervention, automate the recovery steps.\nTell other people in the organization to automate # The idea is to share what you’ve learned with others. Of course, what you’ve learned is that automation is the key to achieving operational excellence. So just keep it simple and tell them to automate.\nBut isn’t operational excellence more than just automation? # What operational excellence actually looks like depends on the organization. But no matter how you slice it, you’re closer to operational excellence if you automate than you are if you don’t. So yes, there is more to it than just automation, just as there’s more to driving than going from point A to point B. But if operational excellence is the goal, you need the vehicle to get there, and the only vehicle that will do it is automation.\n","date":"2 April 2019","externalUrl":null,"permalink":"/2019/04/operational-excellence-means-automation/","section":"Posts","summary":"","title":"Operational Excellence Means Automation","type":"post"},{"content":"","date":"2 April 2019","externalUrl":null,"permalink":"/tags/operational-excellence/","section":"Tags","summary":"","title":"Operational-Excellence","type":"tags"},{"content":"","date":"22 March 2019","externalUrl":null,"permalink":"/tags/osi/","section":"Tags","summary":"","title":"Osi","type":"tags"},{"content":"","date":"22 March 2019","externalUrl":null,"permalink":"/tags/tcp/ip/","section":"Tags","summary":"","title":"Tcp/Ip","type":"tags"},{"content":"2022 Update: If you want a clear technical explanation of the OSI model, click on the cover of my book CCNP Enterprise Certification Study Guide: Implementing and Operating Cisco Enterprise Network Core Technologies for a free preview of Chapter 1 which explains each layer of the OSI model in intricate detail.\nI recently got an email from a viewer of my Practical Networking course who asked how the TCP/IP networking terms I used mapped to the Open Systems Interconnect (OSI) model.\nFirst, a bit of background. The OSI model is a generic networking model that is supposed to describe conceptually how networks carry data. Within the last four decades or so, 99.9% of all computer networking curricula for beginners has started by rehashing the OSI model.\nWhen I first started out learning networking, I paid my dues by memorizing the 7 layers of the OSI model: application, presentation, session, transport, network, data link, and physical. But I found it almost useless in understanding how modern TCP/IP networks actually work.\nWhen I began teaching networking, I found that it was clearer to simply explain things without ever explaining the OSI model. It’s an approach that’s worked well, as evidenced by the many compliments I’ve gotten on my networking courses and books.\nThe sad fact is that you don’t need to know the OSI model. All you need to know is how people use the terms. Here you go:\nflowchart LR %% Styles classDef osi fill:#e1e1e1,stroke:#666,stroke-width:1px,color:#333 classDef reality fill:#e6f3ff,stroke:#4a90e2,stroke-width:2px,color:#333 subgraph The Textbook Model L7[Layer 7 - Application] L6[Layer 6 - Presentation] L5[Layer 5 - Session] L4[Layer 4 - Transport] L3[Layer 3 - Network] L2[Layer 2 - Data Link] L1[Layer 1 - Physical] end subgraph The Real World R7[\"HTTP / APIs / DNS \"] R6[\"(Nobody talks about this)\"] R5[\"(Or this)\"] R4[\"TCP/UDP Ports, Firewalls\"] R3[\"IP Routing, BGP , Subnets\"] R2[\"VLANs, MAC Addresses\"] R1[\"Cables, Fiber, SFPs\"] end L7 -.-\u003e R7 L6 -.-\u003e R6 L5 -.-\u003e R5 L4 -.-\u003e R4 L3 -.-\u003e R3 L2 -.-\u003e R2 L1 -.-\u003e R1 class L1,L2,L3,L4,L5,L6,L7 osi class R1,R2,R3,R4,R5,R6,R7 reality Layer 1 – Physical # The electrical signaling, physical connections, the bits. “We have a layer 1 problem” sometimes means “a rat chewed through the cable” or “it’s raining and the humidity is attenuating the signal.”\nLayer 2 – Data link # Ethernet technologies, including MAC addresses, Ethernet frames, VLANs and VLAN tags; serial encapsulation such as the point-to-point protocol (PPP). Much of the time “the problem is at layer 2” means “it’s in the wrong VLAN”.\nLayer 3 – Network # IP addressing, IP routing, and address resolution protocol (ARP); IPv6, neighbor discovery (ND), and the like. “We have a layer 3 problem” can mean “we have a routing problem” or “someone put in the wrong IP address.”\nLayer 4 – Transport # Transmission control protocol (TCP) and User datagram protocol (UDP); This includes TCP and UDP port numbers. Incidentally, few people use this in conversation. Instead, they say “layer 7” when they mean layer 4, which brings us to…\nLayer 7 – Application # Technically, this is just the data payload that the network carries. Strangely, in troubleshooting conversations, “a layer 7 problem” often means “a firewall is blocking that port”, referring to a TCP or UDP port number, distinctly a layer 4 problem. The confusion arises from the fact that most standard applications have a registered port number they use. For example, TCP port 80 is for the HTTP application, so people use the two interchangeably.\nWhat about the other layers? # Nobody uses them. Seriously. In TCP/IP networks, session and presentation are rolled up into the application layer, which is itself just the data that you’re sending across the network. In fact, when you think about it, it makes perfect sense. What’s the point of a network? To transport data. What’s the highest layer that actually is part of the network infrastructure? That’s right, the transport layer.\n","date":"22 March 2019","externalUrl":null,"permalink":"/2019/03/why-i-dont-teach-the-osi-model/","section":"Posts","summary":"","title":"Why I Don’t Teach The OSI Model","type":"post"},{"content":"After years of manually upgrading my self-hosted WordPress installation, I decided it was finally time to apply some devops principles (namely automation) to this process.\nI decided to use AWS Systems Manager (aka SSM). I started out by creating the following Command Document (which happens to be in YAML format because JSON is ugly):\nschemaVersion: \u0026#34;2.2\u0026#34; description: \u0026#34;Download and install WordPress\u0026#34; mainSteps: - action: \u0026#34;aws :runShellScript\u0026#34; name: \u0026#34;example\u0026#34; inputs: runCommand: - \u0026#34;wget https://wordpress.org/latest.zip\u0026#34; - \u0026#34;mv latest.zip /var/www/html\u0026#34; - \u0026#34;cd /var/www/html\u0026#34; - \u0026#34;service httpd stop\u0026#34; - \u0026#34;unzip -o latest.zip\u0026#34; - \u0026#34;service httpd start\u0026#34; - \u0026#34;rm -f latest.zip\u0026#34;\u0026lt;/code\u0026gt;\u0026lt;/pre\u0026gt; The Command Document executes the bash commands in the runCommand section. It downloads the latest version of WordPress, stops Apache, unzips the files, restarts Apache, and then cleans up.\nSSM uses an agent to carry out the bash commands. My instance runs Amazon Linux which comes with the agent preinstalled, so I didn’t need to install it.\nSystems Manager can execute the Command Document at regular intervals to keep up with the typical WordPress release schedule of every 1-2 months. I can also trigger it manually if there’s a security or bugfix release I need.\nTo avoid catastrophe, I have the Amazon Data Lifecycle Manager for EBS Snapshots take daily snapshots of the instance, just in case something goes terribly wrong with an upgrade.\n","date":"19 March 2019","externalUrl":null,"permalink":"/2019/03/using-aws-systems-manager-to-upgrade-wordpress/","section":"Posts","summary":"","title":"Using AWS Systems Manager to Upgrade WordPress","type":"post"},{"content":"","date":"19 March 2019","externalUrl":null,"permalink":"/tags/wordpress/","section":"Tags","summary":"","title":"Wordpress","type":"tags"},{"content":"If you’ve ever created a private hosted zone in Route 53, you may have noticed it always assigns the same name servers:\nns-1536.awsdns-00.co.uk. ns-0.awsdns-00.com. ns-1024.awsdns-00.org. ns-512.awsdns-00.net. The numbers don’t seem to be coincidental.\n1536 is the RFC number for “Common DNS Implementation Errors.”\n512 and 1024 (binary 2^9 and 2^10 respectively) are common numbers in computing.\n0 is just, well, 0.\n","date":"14 March 2019","externalUrl":null,"permalink":"/post/2019/2019-03-14-route-53-name-servers-sending-secret-message/","section":"Posts","summary":"","title":"Route 53’s Name Servers are Sending a Secret Message","type":"post"},{"content":"","date":"20 February 2019","externalUrl":null,"permalink":"/aws-cd-leh/","section":"Ben Piper","summary":"","title":"AWS CodeDeploy Lifecycle Event Hook Availability","type":"page"},{"content":" Earlier edition - still useful for fundamentals # Sales proof: 17,000+ net copies lifetime across 8 SKUs (12,000+ print) — $420k+ publisher net, part of 50,000+ AWS Solutions Architect Associate (SAA) franchise ($1.3M+ net). Co-authored with David Clinton, Wiley/Sybex.\nCovers multi-tier architectures, loose coupling and stateless systems, AWS security features, and designing large-scale distributed systems.\nBuy # View on Amazon (affiliate) ","date":"15 February 2019","externalUrl":null,"permalink":"/books/aws-saa-c01-2nd-edition/","section":"Books","summary":"","title":"AWS Certified Solutions Architect Study Guide: Associate SAA-C01 Exam, 2nd Edition","type":"page"},{"content":"","date":"15 February 2019","externalUrl":null,"permalink":"/tags/saa-c01/","section":"Tags","summary":"","title":"Saa-C01","type":"tags"},{"content":"","date":"21 January 2019","externalUrl":null,"permalink":"/aws-cf-if/","section":"Ben Piper","summary":"","title":"AWS Intrinsic Function Reference","type":"page"},{"content":"","date":"19 January 2019","externalUrl":null,"permalink":"/aws-cli/","section":"Ben Piper","summary":"","title":"Installing the AWS CLI","type":"page"},{"content":"","date":"17 January 2019","externalUrl":null,"permalink":"/awscf1/","section":"Ben Piper","summary":"","title":"AWS Resource and Property Types Reference","type":"page"},{"content":"","date":"29 October 2018","externalUrl":null,"permalink":"/tags/2018/","section":"Tags","summary":"","title":"2018","type":"tags"},{"content":"","date":"29 October 2018","externalUrl":null,"permalink":"/tags/books/","section":"Tags","summary":"","title":"Books","type":"tags"},{"content":"Tell them what you’ll tell them, tell them, then tell them what you told them.\nThis advice, although well meaning, isn\u0026rsquo;t always the best approach. Although repetition has its place, repeating information three times is by no means the gold standard of teaching. I want to explore a different and perhaps more interesting way of conveying information.\nThe Introduction # This connects your topic or thesis to something broader that the reader is already familiar with. In other words, it places the topic in a context that the reader recognizes. At this point you might think, “My reader already knows the context, or at least they should.” This is often the case with a book where you expect the reader to have read previous chapters (or posts, or whatever designation you’re using to break up your content).\nBut why do chapters exist? Originally their intention was to provide a way to locate information in a book. That’s still their primary purpose, although authors use them to give the reader a natural stopping point. In fact, I’d venture that most authors expect readers to work through a chapter in one sitting. Hence, as authors, we rightly expect the reader to remember the context of a chapter while they’re in it. But it’s not necessarily reasonable to expect a reader to remember the details of the previous chapter when starting a new one. Using the introduction to restate relevant information from previous chapter gives you additional freedom later on, knowing that you and the reader are on the same page. You don’t have to interrupt your epic flow with an, “Oh by the way, remember that thing you read about 8 chapters ago? Let me remind you.” Get that out of the way in the introduction.\nBut what about cases where the topic you’re writing about isn’t connected with previous chapters? Perhaps you’re bringing in a completely new idea. This is the case with “check the box” content like textbooks that need to cover various unrelated topics. You need to tie the topic into your reader’s existing context. But how do you do that when you don’t know what their context is? For example, suppose you’re writing about an information security product that uses machine learning to detect and respond to threats. Does your reader know what machine learning is? Do they understand what a “threat” is?\nYou have to make some assumptions about what your reader already knows. If you assume they know little, you’ll need to fill them in at the risk of stating the obvious. If you assume they know everything, you may go right over their heads and lose them at the beginning. A rule of thumb I like to use is this: tell them enough to make them feel smart if they’re with you, and lost if they’re not. For example, you may say something like, “Our product uses machine learning to analyze attack patterns from around the world to predict and stop new emerging threats from hackers attempting to steal trade secrets.” In doing this, you’re doing a couple of key things:\nFirst, you’re forcing the reader to categorize himself. The reader who thinks, “I get what this means,” will feel smart and – if interested in the topic – will keep reading. The reader who thinks, “What the heck is an ‘attack pattern?\u0026rsquo;” is going to realize they’re not in the right place, and will backspace and go elsewhere.\nSecond, you’re giving the rest of your chapter (or article) a direction. Actually, it’s more like you’re pointing it in a certain direction and getting ready to kick it hard in the rear. Once you pen your introduction in the way I’ve described, there’s no going back. And there’s freedom in that. Your reader won’t expect you to go elsewhere.\nThere’s another advantage to projecting the direction of your chapter. People often think they know things they don’t. It sounds weird, but people who casually read about topics (rather than deeply studying them) tend to develop incorrect conceptions of those topics, especially when it comes to technology. This is your chance to correct those misconceptions, and also establish your own credibility. A reader who thought “machine learning” was computers developing emotions and laughing at jokes will feel satisfied having learned that it’s just a type of predictive analysis.\nSo, the introduction is not where you “tell them what you’re going to tell them.” Yuck.\nThe Summary # You probably won’t fall out of your chair if I tell you the word “summary” means sum or substance. Basically, it means everything you covered in the chapter minus the junk. This is the definition of “tell them what you told them”.\nI know what you’re thinking: “I don’t have any junk or fluff in my writing. It’s all important.” You’re right. So what’s the point of a summary? The only time you should use a summary is when you’re summarizing someone else’s content. Summarizing your own content is like washing your hands, drying them, then immediately washing them again. It makes no sense. The obvious takeaway is don’t write a summary. Instead, write a conclusion.\nThe Conclusion # When people say “summary” they almost always mean conclusion, which means “outcome,” “deduction,” or “inference .” Do you see the pattern? The conclusion takes your topic and considers the implications of what you’ve written.\nRemember that the introduction is where you point your topic in a specific direction and give it a swift kick. Well the conclusion is when your topic reaches a fork in the road. There’s a balancing act here. You’ve taken it as far as you want to for the moment, but now it’s time to advise the reader on where this topic could (or should) lead. If you’re writing a book in which the chapters are topically connected, this would be the obvious place to hint at the next chapter. This is the place to pontificate about the implications of the topic, to get “meta” if you will. This will naturally require restating some points about it. For example, if you want to wax philosophical about how government-sponsored attacks are more sophisticated and harder to detect, you’ll naturally have to revisit the technical details of cyber attacks.\nFor people like me, delving into related ideas will lead to the inevitable, “Maybe I should add this to the chapter.” Don’t. It’s the equivalent of rambling. The goal of the conclusion is to close out the discussion of the topic at hand, while opening (and leaving open) the implications of your topic. Your conclusion is not the conclusion. It’s okay to leave some things open ended.\n","date":"29 October 2018","externalUrl":null,"permalink":"/post/2018/2018-10-29-writing-purpose-introduction-summary-conclusion/","section":"Posts","summary":"","title":"Writing: The Purpose of the Introduction, Summary, and Conclusion","type":"post"},{"content":"My latest course “Architecting for Security on AWS” is now available on Pluralsight!\nYou’ll learn how to secure your data and AWS services using a defense-in-depth approach, including:\nProtecting your AWS credentials using identity and access management Capturing and analyze logs using CloudTrail, CloudWatch, and Athena Implementing network and instance security Encrypting data at rest and in-transit Setting up data backup, replication, and recovery Go check it out!\n","date":"7 September 2018","externalUrl":null,"permalink":"/2018/09/architecting-security-aws/","section":"Posts","summary":"","title":"Architecting for Security on AWS","type":"post"},{"content":"Puzzled by networking on AWS? Check out my AWS networking deep dive series!\n","date":"25 August 2018","externalUrl":null,"permalink":"/2018/08/aws-networking-deep-dive-courses/","section":"Posts","summary":"","title":"AWS Networking Deep Dive Courses","type":"post"},{"content":"Many of you have been asking for months when my Route 53 course would release. Well, it’s finally here! AWS Networking Deep Dive: Route 53 DNS is now available on Pluralsight.\nTopics covered include:\nConfiguring Route 53 to work with any domain name, even one registered with a different registrar DNS concepts and how Route 53 fits in with the internet’s domain name system Creating public hosted zones, health checks, and routing policies Using private hosted zones with multiple VPCs ","date":"28 May 2018","externalUrl":null,"permalink":"/2018/05/aws-networking-deep-dive-route-53-dns/","section":"Posts","summary":"","title":"AWS Networking Deep Dive: Route 53 DNS","type":"post"},{"content":"You probably know the popular Google DNS server IP addresses by heart: 8.8.8.8 and 8.8.4.4. Before those were around you might have even used Level3’s 4.2.2.1 and 4.2.2.2. Of course, everyone else uses these too, which means these popular servers are under a pretty heavy load.\nFortunately, there are faster public DNS servers out there. Much faster.\n101 DNS Servers # I’ve compiled a list of 101 public DNS servers (PDF), sorted in order of fastest to slowest (for me).\nA few things to keep in mind # This is not an exhaustive list of all public name servers, nor are these necessarily the fastest servers that exist. But if you’re using one of the more popular public name servers, you can easily see how other servers rank against those in terms of speed.\nNot all DNS servers behave the same way. Some will return intentionally incorrect responses, usually if the query is for a malicious domain. Others will return inconsistent results, which can be problematic if you’re testing for recently changed records.\nOne name server in particular seemed to rate-limit my queries, and this behavior seemed to change based on the query type. For instance, queries for * (all) would time out, while queries for SOA records would work. After waiting a little while and trying again, the server answered all my queries quickly.\nThe lesson here is test the server thoroughly and get familiar with its quirks before using it everywhere.\n","date":"4 March 2018","externalUrl":null,"permalink":"/2018/03/public-dns-servers-sorted-speed/","section":"Posts","summary":"","title":"101 Public DNS Servers Sorted by Speed","type":"post"},{"content":"In preparation for my latest course in the AWS Networking Deep Dive series, I wanted to install PowerShell Core on an Amazon Linux instance to test out cross-platform compatibility for some scripts.\nSpecifically, I wanted to see if I could use methods in the System.Net.Dns class to perform name resolution. The dnsclient PowerShell module provides some cmdlets for this very purpose, but that module is Windows-only, and I needed something that would work on across different platforms.\nTo my surprise, it wasn’t as easy as just running sudo yum -y install powershell. Fortunately, it wasn’t as difficult as building from source. Here’s what I did:\nInstall the dependencies # sudo yum install -y curl libunwind libicu libcurl openssl libuuid.x86_64 Download the installation script # This script just fetches the tarball and extracts it to /opt/microsoft/powershell\nwget https://raw.githubusercontent.com/PowerShell/PowerShell/master/docker/InstallTarballPackage.sh Set the script to be executable # chmod +x InstallTarballPackage.sh Run the script, specifying the PowerShell version (6.0.1) and package tarball as the arguments:\nsudo ./InstallTarballPackage.sh 6.0.1 powershell-6.0.1-linux-x64.tar.gz If you want to install a specific version (like the latest), then refer to the releases on the PowerShell repo.\nRun PowerShell! # The command is pwsh, as in “Present Working SHell” (clever points). Be sure to use sudo, as it does require root privileges:\nsudo pwsh Get Your .NET On # The whole point of this exercise was to see if I could use .NET to perform DNS name resolution without any of the cmdlets in the Windows-only dnsclient module. Did it work? Let’s see.\nPowerShell v6.0.1 Copyright (c) Microsoft Corporation. All rights reserved. https://aka.ms/pscore6-docs Type \u0026#39;help\u0026#39; to get help. PS /home/ec2-user\u0026gt; [System.Net.Dns]::GetHostAddresses(\u0026#34;benpiper.com\u0026#34;).IPAddressToString 52.205.213.4 Yes indeed! Of course, I can still use the usual PowerShell tricks to extract just the data I want:\nPS /home/ec2-user\u0026gt; [System.Net.Dns]::GetHostByName(\u0026#34;pluralsight.com\u0026#34;) | Select-Object AddressList AddressList ----------- {54.213.174.143, 35.164.44.204, 52.39.160.43} I can also drill down to pick out just the first IP address in the list:\nPS /home/ec2-user\u0026gt; ([System.Net.Dns]::GetHostByName(\u0026#34;pluralsight.com\u0026#34;)).AddressList[0].IpAddressToString 54.213.174.143 Run it again, and I get a different address:\nPS /home/ec2-user\u0026gt; ([System.Net.Dns]::GetHostByName(\u0026#34;pluralsight.com\u0026#34;)).AddressList[0].IpAddressToString 52.39.160.43 Looks like round-robin DNS! But will this command work cross-platform? Let’s try it on my Windows 10 machine:\nPS C:\\Users\\admin\u0026gt; ([System.Net.Dns]::GetHostByName(\u0026#34;pluralsight.com\u0026#34;)).AddressList[0].IpAddressToString 35.164.44.204 Yes! This is exactly why I chose PowerShell. The same command that works on Linux also works on Windows, which makes it perfect for an OS-agnostic course.\nReady to learn more PowerShell? Sign up for a free trial with Pluralsight and get unlimited access to every course in their humongous library!\n","date":"25 February 2018","externalUrl":null,"permalink":"/2018/02/installing-powershell-core-amazon-linux/","section":"Posts","summary":"","title":"Installing PowerShell Core on Amazon Linux","type":"post"},{"content":"","date":"25 February 2018","externalUrl":null,"permalink":"/tags/powershell/","section":"Tags","summary":"","title":"Powershell","type":"tags"},{"content":"Most of us have tossed around the idea of restricting our social media consumption, or even giving it up altogether. It’s not that we don’t like it. We love it, sometimes too much. But inherently, something about social media just seems wrong. But what is it?\nSocial is Not a Neutral Tool # People often say that social media is just a tool, and like any other tool, it can be abused, but it can also be used for good. After mulling on this for several months, I have to disagree. Social media is not a tool. It’s not neutral. And that has nothing to do with the platform. Social can’t be neutral because it’s composed of people, and people are not neutral.\nThink of it this way. Imagine you’re at your favorite hangout. Maybe it’s a coffee shop, restaurant, the library, zoo, whatever. You’re having a good time, when suddenly, a large group of people appears. They all start talking to each other, LOUDLY, and what they’re saying is seriously ticking you off. They’re spewing some of the most unpleasant, irritating, obnoxious garbage you’ve ever heard.\nWhat do you do? Most likely you’d put on your headphones, if you have any, or you’d leave. Yeah, you might engage some of the people for a while, if that’s your personality. But would you purposely subject yourself to that noxious experience day after day? Probably not.\nAnd yet, when it comes to social media, many continually subject themselves to that kind of toxic social interaction multiple times a day.\nTechnical Solutions Don’t Work # Even before social media was big, people have tried to come up with a technical solution to this problem. Banning, shadowbanning, muting, blocking, throttling, etc. have all been tried.\nBut none of it has worked, or even helped much. If anything, social media interaction has gotten worse, not better. These solutions are predicated on the notion that social media is just a neutral platform, and if we enforce the right rules, we can maintain that neutrality. But that’s a false notion. Again, social media can’t be neutral because people are not neutral.\nThe only way for social media to work is for people to properly police their own behavior. This is exactly what happens in real life social situations. Nobody dares to walk into a noisy restaurant and launch into a profanity-laced tirade against a perfect stranger. But much of the time, that inhibition is driven by self-preservation rather than a moral imperative. Remove the risk of getting physically assaulted, and many won’t hesitate to say the vilest, ugliest stuff. That’s what social media does.\nBad Behavior is Contagious # Is social media bad? Not inherently. But it’s not inherently good either. People choose to behave in morally good or bad ways. When immoral speech spills over into social media, it spreads like a cancer. We love to think of ourselves as being in control of our own thoughts and choosing our own influences. But that’s just not true. Bad company corrupts good morals, as the Apostle Paul said, and being exposed to trash on social media day after day does affect you, even if you don’t consciously realize it.\nHow often have you gotten viscerally angry at something you read on Twitter or Facebook? Sure, you can get mad reading something on any website or even in a book. But those occurrences are few and far between. On social, they’re the norm. When you saw something that made you really mad, how long did you stew about it? Did your mood affect your interactions with other people?\nThis domino effect isn’t unique to social, of course, but it is amplified. Our use of social media is 180 degrees out of phase. For our own sanity, it should comprise seconds, maybe minutes of our day. Our one-on-one and in-person interactions should be the bulk. That tweet that made you burning mad should be a once-a-week event. Most of your disagreements with another person should be hashed out one-on-one, privately, not in a public forum with spectators.\nIs Social Media Worth It? # Should you stop using social media? I think that’s the wrong question. A better question is why should you use it? What value does it hold for you? And is it worth the price you pay in terms of time, sanity, and relationships with others?\nIt’s not unusual to see someone take a break from social, usually for a week or two, but sometimes a month or more. This is common and doesn’t usually raise any eyebrows. But if you heard someone say, “I’m taking a break from all social interaction for a month!” you’d immediately think something was amiss. This is evidence that instinctively, we know something is off about social. You only take long breaks from something when you detect that it’s not healthy to continue at your current pace.\nAs ironic as it seems, cutting back on social media would probably make everyone more social.\n","date":"21 February 2018","externalUrl":null,"permalink":"/2018/02/social-media-bad/","section":"Posts","summary":"","title":"Is Social Media Bad?","type":"post"},{"content":" Search Results # gcse:searchbox-only\u0026lt;/gcse:searchbox-only\u0026gt;\ngcse:searchresults-only\u0026lt;/gcse:searchresults-only\u0026gt;\n","date":"12 February 2018","externalUrl":null,"permalink":"/search/","section":"Ben Piper","summary":"","title":"Search Results","type":"page"},{"content":" Learn to subnet in your head in just seconds! If you like what you see, check out Cisco Enterprise Networks: Basic Networking and IP Fundamentals.\n","date":"9 February 2018","externalUrl":null,"permalink":"/2018/02/video-subnet-head/","section":"Posts","summary":"","title":"Video: How to Subnet in Your Head","type":"post"},{"content":"AWS Networking Deep Dive: Virtual Private Cloud (VPC)\n","date":"9 February 2018","externalUrl":null,"permalink":"/aws-net-vpc/","section":"Ben Piper","summary":"","title":"AWS Networking Deep Dive: Virtual Private Cloud (VPC)","type":"page"},{"content":"","date":"9 February 2018","externalUrl":null,"permalink":"/ec2-ipv6/","section":"Ben Piper","summary":"","title":"AWS EC2 Instance Types","type":"page"},{"content":" AWS Networking Deep Dive: Elastic Load Balancing (ELB) ","date":"9 February 2018","externalUrl":null,"permalink":"/ps-aws-elb-li/","section":"Ben Piper","summary":"","title":"AWS Networking Deep Dive: Elastic Load Balancing (ELB)","type":"page"},{"content":"Cisco CCNP Routing and Switching learning path\n","date":"9 February 2018","externalUrl":null,"permalink":"/ps-ccnp/","section":"Ben Piper","summary":"","title":"Cisco CCNP Routing and Switching Learning Path","type":"page"},{"content":"Thank you for subscribing to my newsletter! I invite you to browse around my blog, and feel free to reach out to me personally at ben@benpiper.com.\n-Ben\n","date":"24 January 2018","externalUrl":null,"permalink":"/subscription-confirmed/","section":"Ben Piper","summary":"","title":"Subscription Confirmed","type":"page"},{"content":"Windows Server 2016 ISO Download\n","date":"20 January 2018","externalUrl":null,"permalink":"/win2016iso/","section":"Ben Piper","summary":"","title":"Windows Server 2016 ISO Download","type":"page"},{"content":"","date":"20 January 2018","externalUrl":null,"permalink":"/invalid-vpc/","section":"Ben Piper","summary":"","title":"Invalid VPC Peering Configurations","type":"page"},{"content":" Implementing Cisco IP Routing (300-101) Exam Topics # ","date":"20 January 2018","externalUrl":null,"permalink":"/routev2/","section":"Ben Piper","summary":"","title":"Implementing Cisco IP Routing (300-101) Exam Topics","type":"page"},{"content":" Cisco CCNA Routing and Switching learning path on Pluralsight # ","date":"20 January 2018","externalUrl":null,"permalink":"/ps-ccna/","section":"Ben Piper","summary":"","title":"Cisco CCNA Routing and Switching","type":"page"},{"content":"This month, security researchers released a whitepaper describing the Meltdown attack, which allows anyone to read the full physical memory of a system by exploiting a vulnerability in Intel processors. If that sounds bad, that’s because it is. It means that if you’re running workloads on a public cloud provider, and you don’t have a dedicated server, an attacker can read what your workloads are putting into memory. This includes passwords, private keys, credit card numbers, your cat’s middle name, etc.\nHow Meltdown works # As a way of eking out every ounce of speed, modern processors perform out-of-order execution. Rather than executing a program one instruction at a time, the processor fetches multiple instructions at once and places them in an instruction queue. It then executes each instruction as soon as possible (and usually out-of-order) and stores each instruction’s output (if there is any) in a cache.\nNow here’s the kicker. An instruction can do nasty things. Out-of-order execution runs instructions that the program isn’t allowed to run. Take the following assembly instruction:\n; rcx = kernel address mov al, byte [rcx] This copies one byte of data from the kernel memory and places it in a temporary portion of CPU memory, called a register. With in-order processing, the CPU would not allow this instruction to execute.\nBut with out-of-order execution, the CPU does execute the instruction, and it stores the resulting byte value in a temporary cache. The CPU then raises an exception and terminates the program.\nBut the byte value is still stored in the cache. This is where the flaw in Intel’s microcode lies. The CPU should clear the cache as soon as the exception is raised. But it doesn’t. It leaves it there, vulnerable to another type of side-channel attack called a cache attack.\nsequenceDiagram participant P as Program (User Space) participant C as CPU (Execution Engine) participant M as Kernel Memory participant X as CPU Cache P-\u003e\u003eC: Request Kernel Memory Byte note over C: Out-of-Order Execution begins C-\u003e\u003eM: Fetch Byte (Speculative) M--\u003e\u003eC: Returns Restricted Byte C-\u003e\u003eX: Store Byte in Temporary Cache note over C: Privilege Check Occurs C--\u003e\u003eP: Throw Exception (Access Denied) note right of P: Program is Terminated note over X: VULNERABILITY:Cache is NOT flushed note right of X: Attacker uses timing attackto read the trapped byte Cache attacks have been around for years, and there are several different types which an hacker can use in conjunction with Meltdown to figure out the data stored in cache. For a great explanation of how these attacks work, check out Bert Hubert’s article on Spectre and Meltdown. It’s trivial for an attacker to pull one off, quickly.\nOnly Intel Processors were Shown to be Vulnerable # The researchers were not able to duplicate the results on AMD or ARM processors, which also use out-of-order execution. They speculate that they theoretically could, but they were not able to at the time they released the paper. You certainly shouldn’t assume that all non-Intel processors are immune to Meltdown.\nDisabling out-of-order execution isn’t the answer # In order to be effective, the Meltdown attack depends on out-of-order execution as a necessary but not sufficient condition. Thus, simply having out-of-order execution enabled is not enough to make Meltdown possible. Disabling out-of-order execution does prevent Meltdown, but the performance impact is substantial.\nWhat about Spectre? # Spectre is not the same as Meltdown. Although Spectre works against all CPUs, including Intel, AMD, and ARM, pulling off a Spectre attack is trickier. But both are equally bad and rely on out-of-order execution, which is why you usually see them lumped together.\nYou don’t need to replace your hardware # You don’t need to replace your hardware, and anyone who says you do is probably trying to tell you something. Now for the obvious part. To mitigate Meltdown and Spectre, install the latest security patches for your operating system, BIOS, and CPU firmware — after sufficient testing, of course.\n","date":"5 January 2018","externalUrl":null,"permalink":"/2018/01/understanding-meltdown-attack/","section":"Posts","summary":"","title":"Understanding the Meltdown Attack","type":"post"},{"content":"","date":"31 December 2017","externalUrl":null,"permalink":"/tags/2017/","section":"Tags","summary":"","title":"2017","type":"tags"},{"content":"As 2018 draws near, companies go into hiring mode, and people come and go, which often leaves a lot of open positions. If you qualify to fill one of the more in-demand positions, you can often negotiate a higher salary.\nMy biggest salary jumps have always come in the first quarter of the year. To increase your chances of getting that salary boost, here are three tips that you should start implementing right now.\nTip #1 – Shun the Snake Oil Tech Fads # These are technologies that sound interesting, seem promising, but either have no real-world use case or are actually impossible. Some current examples include blockchain and quantum computing. If you’re interested in these from a theoretical perspective, by all means, indulge yourself. But don’t expect that a real company is going to hire you as a blockchain or quantum computing expert. These are fads, and like all fads, they’ll die. Don’t let your career die with them.\nAn easy way to spot nonsense tech fads is to ask yourself, “Is this new technology an improvement over what we have now? If so, is it even possible?” Clearly, blockchain isn’t an improvement over any other database, distributed or otherwise. Quantum computing could theoretically blow classical computing out of the water, but quantum computers require temperatures close to absolute zero, making them practically impossible.\nAnother tech fad that’s captured the attention of the media is artificial intelligence (AI). Not to be confused with machine learning, the AI hype claims that computers will somehow begin working as good as or better than the human brain, perhaps even to the point of developing consciousness and understanding. Machine learning, on the other hand, deals with statistical analysis and making predictions based on large data sets. It has nothing to do with mimicking the human brain or consciousness.\nTip #2 – Get Certified # Rid your mind of the tripe that “certifications are just paper” and “they don’t prove that you know anything.” The fact is that more certifications = more money. But you have to get certified. Just taking courses isn’t enough. I’ve interviewed people whose resumes listed what courses they took, but they didn’t have the corresponding cert. Don’t do this. It’s a huge strike against you. Take all the courses you need to attain the cert, but then go and get it.\nHere are some of the most lucrative and in-demand certification categories going into 2018: # Cloud and networking # Three of the most popular certifications are the AWS Certified Solutions Architect – Associate, and the Cisco Certified Network Associate (CCNA ) and ","date":"31 December 2017","externalUrl":null,"permalink":"/2017/12/increase-earnings-2018/","section":"Posts","summary":"","title":"3 Ways to Increase Your IT Earnings in 2018","type":"post"},{"content":"Security usually requires sacrificing convenience (or money). So naturally, we tend to get away with as little security as possible. But if you’re a glutton for punishment, here are 4 very inconvenient but highly effective measures you can take right now to protect yourself from the evils lurking on the interwebs.\nDisable JavaScript # Yeah, I know. Every site made since the Web 2.0 days needs JavaScript just for a text input field to work right. It’s a shame, really. But disabling JavaScript isn’t an all-or-nothing deal. Browser extensions lets you allow JavaScript for sites you trust and block them for all others. If you’re still using Firefox (the most obnoxious browser today), you can use the NoScript extension. Chrome users, check out uMatrix.\nDisable XSS # Cross-site scripting (XSS) occurs when you go to one website and it loads JavaScript from a different domain. Sadly, this practice has become normal with the advent of CDNs. What makes it risky is not so much the cross-site request, but the fact that it happens without you knowing it. You don’t see that legitwebsite.com is loading Nasty.js from someone’s hijacked blog site. Using one of the script blocking extensions I just mentioned will warn you about XSS and let you decide whether to allow it. I’ve stopped several malicious scripts this way over the years.\nBlock wide categories of websites # Taking a whitelist approach is too inconvenient, as there are just way too many sites out there to keep up with. Your next best option is to use content-based filtering to block websites by category. I use OpenDNS to achieve this, and below is my current list of blocked categories. As you can see, it’s pretty broad.\nThis list covers some sites I don’t want blocked, so I allow those on a case-by-case basis. You might notice that some of these categories tend to carry malware more than others, so blocking them wholesale is a pretty effective way to avoid fallout from clicking the wrong link.\nDon’t use the app # Smartphones normalized a concept that would’ve been considered bizarre just a few years ago: installing an app for every website you use regularly. We’ve got Twitter, Facebook, Gmail, LinkedIn, etc. Can you imagine installing “the MySpace app” on your Windows XP machine in 2005? Some sites just don’t need an app. You can browse to them on your phone and they work fine.\nWhen you install an app, you usually give it permissions to various system resources – photos, call logs, camera, microphone, etc. Chances are the core functionality doesn’t require most of those. If that app has a vulnerability – or worse, malicious code – then you’ve just turned your phone into a neat little hacker toolkit.\n","date":"5 October 2017","externalUrl":null,"permalink":"/2017/10/4-inconvenient-but-effective-security-measures/","section":"Posts","summary":"","title":"4 Inconvenient but Effective Security Measures","type":"post"},{"content":"Whenever a tech fad comes to an end, it becomes so obvious why it failed. Yet during the hype, it’s easy to miss the problems lurking just below the surface. I want to explore some of the problems I see with public blockchain and why I think it’s not going to live up to the hype.\nBlockchain can’t track real things # Whenever a new technology comes along, there’s always a temptation to use it in ways above and beyond it was originally intended. Blockchain came to popularity because of Bitcoin, and as Bitcoin grew, people became fascinated by its underlying technology.\nBut what made Bitcoin popular wasn’t the technology. The whole idea behind Bitcoin was to create a global currency that didn’t have a central monetary authority. Blockchain was just a good means to achieve that.\nThe fact that blockchain works well for cryptocurrency doesn’t mean that it works well for any sort of transactional database. The idea of digitally moving funds from one account to another doesn’t translate to moving goods along a supply chain. Why not? Because with Bitcoin, the blockchain is currency that you’re moving around. You can’t separate a Bitcoin from the blockchain. If you do, the Bitcoin ceases to exist.\nWhen it comes to supply chain, you’re only moving representations of goods, not the goods themselves. This is a key distinction that people miss. You can assert that a certain string of data represents a tangible thing in the real world, but now that linkage is based on your assertion, not on the blockchain itself. Hence, the blockchain doesn’t add much value.\nAnyone can create a blockchain # A blockchain is a database, and as anyone who has dealt with those knows, a database is worthless if no one uses it. There are hundreds, probably thousands of different blockchains. If people who work together every day can’t even agree on where to eat lunch, how is everyone in the world going to agree on a single blockchain for any given application? It’s not going to happen.\nRidiculous bandwidth and storage requirements # Right now blockchain is being touted as a security panacea, especially for IoT. There’s just one big problem: IoT devices have small storage and bandwidth capacity, and blockchain requires enormous amounts of storage and bandwidth.\nInconvenient but not more secure # Security always requires giving up some convenience. But the inverse isn’t necessarily true. When I go to pay for my coffee, I can use a piece of plastic, cash, or scan a barcode on my phone. It’s convenient and mostly secure. But if I want to pay with Bitcoin or some other cryptocurrency, I have to drop some bits onto a blockchain and wait minutes or even hours for the hivemind to “confirm” my transaction.\nAnd what benefit do I get in return? Nothing. No, it’s worse than nothing. I lose my ability to dispute the transaction or get a refund because blockchains are designed to be unchangeable (aka immutable).\nControlled by anonymous # Public blockchains are not inherently decentralized. Distributed, yes. Decentralized, no.\nWhen dealing with a credit or debit card, your bank is in charge of keeping track of the transactions. When dealing with cash, keeping up with your spending is entirely up to you. But when it comes to blockchain, thousands of anonymous strangers are in charge of your transactions.\nThese anonymous strangers are divided into two groups. You’ve got the developers who create and maintain the software required to interact with the blockchain. This gives them the power to change it in any way they see fit, as well as allow or disallow other people to use it (this actually happened recently with the Bitcoin Core/Cash split).\nThe other group is the people running the nodes which perform validation of blockchain transactions. Ideally this would be a diverse group of honest people spread all over the world. But the reality is that anyone with enough money (e.g. gov’t) can purchase the compute power to comprise the majority of nodes. Whoever controls the majority of nodes controls the blockchain.\nThis is arguably the biggest strike against public blockchains because it’s not just a theoretical possibility. It’s already happened. 70% of Bitcoin mining is done in China, only 1% in the US.\nRipe for attack # Even if you assume that most people are honest and will operate clean nodes, there’s still the small problem of security. Imagine that former Soviet spies Boris and Natasha develop a worm targeting a particular blockchain implementation like Ethereum. They’re so 1337 that they manage to infect 80% of the nodes, allowing them to inject bogus data into the chain and validate it.\nDon’t underestimate the fallout of this. Even if the participants discover the attack quickly, the damage has already been done. Everyone else now has to face the ugly decision of whether to trust a blockchain they know has already been compromised. This isn’t just a theoretical scenario. Something similar already happened with Ethereum. It resulted in the developers forking the Ethereum chain. That’s why we now have two Ethereums (ETH and ETC).\nArchitected insecurely # The Boris and Natasha scenario might sound a little bit too spy-movie-ish, but the nature of a public blockchain requires it to be open to the internet. This isn’t a private database locked down behind layers of security. It’s a peer-to-peer app that is more than happy to accept your malformed TCP packet.\nDoes that mean it’s impossible to implement a secure, public blockchain? No. But it does mean that it’s much, much harder than to just use a private database behind more proven layers of security. Once again, why not just use a traditional database? Blockchain doesn’t offer enough of an advantage to outweigh the risks.\n","date":"4 October 2017","externalUrl":null,"permalink":"/2017/10/blockchain-is-a-passing-fad/","section":"Posts","summary":"","title":"Blockchain is a Passing Fad","type":"post"},{"content":"","date":"30 September 2017","externalUrl":null,"permalink":"/tags/citrix/","section":"Tags","summary":"","title":"Citrix","type":"tags"},{"content":"Certifications are often lambasted as “worthless pieces of paper” and “experience is more important.” But for some people, certifications are more important than experience.\nA substitute for experience # Newcomers to the IT world face the classic problem: how do you get experience without a job? Sure, you can tinker around on your own time, but how do you prove that experience? That’s where certifications come in.\nCertifications show a prospective employer that you care enough and have the initiative to spend your own time and money to become a better IT professional. You might have tons of experience with IT as a hobby. But how do you prove that?\nWith a piece of paper.\nCertifications get you hired # They are what get your resume looked at, instead of being tossed into the shredder by HR.\nThey are what get you the interview.\nThey are the tie-breaker between you and that other equally qualified person who doesn’t have a cert.\nIf you have a stack of certifications under your belt, you’re going to be a step ahead of the naysayers who think certifications are a joke, a scam, or a racket.\nCertifications mean higher pay # My first IT certification was the CompTIA A+ in 2002. That helped me land one very low paying job. During that time, I also got my Microsoft MCSA.\nFast-forward a few years. I got a job at a local technology reseller where I earned my Network+, Cisco CCNA , CCDA, and finally my CCNP, all within a year. Shortly after that, I was able to get a job that almost doubled my salary.\nA couple years later, I got my Citrix CCA. My salary went up by 50%. It increased a few percent each year thereafter.\nOh, and I forgot to mention: no college degree.\nYou’re always a beginner # Even if you’ve been in the field for 20 years, you’re always a beginner when it comes to emerging technologies. You can work your tail off to get experience with the latest and greatest, but if you want to turn that experience into a raise or new position, you have to prove your skills.\nWhen you put in your resume against someone fresh out of college – and they have that highly sought after certification and you don’t – well, you can guess who’s getting the callback.\n","date":"30 September 2017","externalUrl":null,"permalink":"/2017/09/yes-you-need-it-certifications/","section":"Posts","summary":"","title":"Yes, You Need IT Certifications","type":"post"},{"content":"Many a nerd has thrown punches over the question of whether containers (e.g. Docker, LXC, etc.) are actually virtual machines. The conventional wisdom is that although containers are similar to virtual machines, they’re fundamentally different. I beg to differ.\nAre containers virtual machines or not? # There’s a common analogy that VMs are like houses and containers are like apartments. And you are the application. When you live in a house, you have free rein to do as you please. When you live in an apartment, you have to share certain spaces, and parts of the building are off-limits. Interestingly, this analogy suggests that the difference between containers and VMs is not one of architecture but of implementation!\nApartment buildings and houses both have rooms, water, electric, roofs, and doors. Containers and VMs both virtualize compute, storage, networking , and memory. So what’s the difference, really?\nShared Almost Nothing # Those who say that a container is not a virtual machine are quick to note that all containers on a host share the same kernel. Not a copy of the same kernel, but the exact same kernel running on the host.\nVirtual machines, on the other hand, have completely isolated kernels. If you’re running 100 identical Linux VMs, each VM has its own unique copy of the same kernel. You can upgrade the kernel in one, and it doesn’t affect any others. That seems like a pretty significant difference. But let’s look a little deeper.\nContainers do use virtualization, but rather than fully virtualizing compute, network, storage, and memory, containers do something a little different. They fully virtualize the compute and networking portion. But storage and memory, on the other hand, are mostly but not completely virtualized. The kernel is stored on the host, and the container is given read-only access to it. The rest of a container’s storage and memory are virtualized.\nIn a container, the operating system is necessarily separated from the rest of the VM. But that hardly means containers aren’t VMs.\nVMs that Look Like Containers? # With a little tweaking, a traditional virtual machine could meet the criteria of a container. One could, for example, create a shared, read-only filesystem containing a Linux kernel and have multiple VMware virtual machines booting from it. As those VMs boot, VMware could identify the duplicate virtual memory blocks and deduplicate them. Those VMs wouldn’t cease to be virtual machines just because they’re all sharing a kernel.\nLet’s take a more realistic example: multiple virtual machines booting Kali Linux from a shared, read-only ISO. Each VM has its own virtual disk for persistence, but the operating system kernel is shared. Is that a container?\nContainers Were Born On Linux # There’s a reason containers were born on Linux and not Windows. The Linux architecture lends itself to the clean separation of the kernel from everything else. Windows, on the other hand, just mashes it all together. That’s why Windows and *nix went into opposite directions. To get more efficient use of system resources, FreeBSD got jails, and Linux got OpenVZ, LXC, and eventually Docker. Windows, on the other hand, just got full-on x86 virtualized.\nContainers Mimic Physical Machines # As I said in an earlier post, virtualization is mimicry. Containers present applications with compute, memory, storage, and networking, and control how applications can use those resources. Virtual machines do the exact same thing. Not only that, you can start, stop, pause, and shutdown containers, just like with VMs!\nAt this point, it’s starting to become clear that the earlier analogy – VMs being like houses – is flawed. Virtual machines aren’t like houses per se, but like buildings in general. Containers are a particular implementation of virtual machine, like an apartment is a particular instance of a building.\nContainers Aren’t Those VMs # Let me be clear that I’m not suggesting that people who say containers aren’t VMs are wrong.\nWhen people say containers aren’t VMs, they’re trying to explain that a container is not the kind of virtual machine you’d find in VMware or Hyper-V. It’s not the type of VM you attach an ISO to, boot up, and install an operating system on. It’s perfectly valid to insist that containers are not those types of virtual machines because, well, they’re not. They’re very different. My goal here is to highlight the similarities so that the differences become more apparent.\nAlso, I’m not saying containers are bad. Far from it. I’ve been using Docker since 2014 and I love it. And I’m excited to see how Docker for Windows Server will fare. Application virtualization has been a holy grail of Windows for a long time, and Docker just might finally deliver it.\n","date":"15 September 2017","externalUrl":null,"permalink":"/2017/09/containers-are-virtual-machines-after-all/","section":"Posts","summary":"","title":"Containers are Virtual Machines After All","type":"post"},{"content":"","date":"15 September 2017","externalUrl":null,"permalink":"/tags/docker/","section":"Tags","summary":"","title":"Docker","type":"tags"},{"content":"","date":"15 September 2017","externalUrl":null,"permalink":"/tags/virtualization/","section":"Tags","summary":"","title":"Virtualization","type":"tags"},{"content":"I’m trying out different services to import an AWS environment and turn it into a technically correct and aesthetically pleasing diagram. Surprisingly, although most of the services can correctly identify the resources, none of them are able to identify network connections. If you’re hoping for something to autogenerate detailed visual documentation of your AWS environment, well, sorry, but we’re not there yet. However, if you’re okay with copy/paste and making some manual tweaks, one of these services might be right for you.\nLucidchart # Cons: # By default, the import function doesn’t actually create a diagram for you. It just imports the elements and it’s up to you to arrange them.\nIf you use the auto layout feature (beta), each VPC gets put on a separate page, and the diagram doesn’t show VPC peerings.\nPros: # Free for a single user\nThe auto layout feature (did I mention it’s in beta?) arranges resources for you, placing each VPC on a separate page. Copying and pasting from one page to another is seamless.\nClear instructions to help you setup an IAM user and policy for importing from AWS Rating: 3/5 # Hava # Cons: # Each VPC has its own diagram, and there doesn’t seem to be a way to edit them.\nIf you want to export diagrams, you have to pay $39/month.\nThe signup and login forms are quirky and make odd asynchronous requests to the far reaches of the interwebs for no apparent reason. If you use any sort of security software, you may have a problem even signing up.\nPros: # They offer a free 2-week trial without requiring a credit card.\nThe diagrams are detailed and give you the option to show or hide resource names.\nRating: 3/5 # Cloudcraft # Cons: # You can’t import from AWS unless you sign up for the Pro Solo plan ($49/month). They require a credit card up front before you can even try the service out.\nPros: # The diagrams are 3-D and have a game board feel. As you add resources to the diagram, it tells you the monthly AWS cost based on usage.\nThe signup process is super easy, requiring only a name, email and password. You don’t even have to confirm your email before you can use the service.\nRating: 2/5 # Promising contenders that need work # VisualOps.io looked great, but the signup form wouldn’t submit.\nSoftware/services that don’t offer an AWS import feature # Cacoo, ConceptDraw, Creately, and Solution Assembly Line do not offer an AWS import feature.\nThe Winner? # There is no winner yet. All of the services I reviewed more-or-less mimic Amazon’s own high-level documentation diagrams. Such diagrams are useful, but they’re too high-level to suffice as technical documentation. What’s needed are diagrams that reflect the underlying AWS architecture, and I recognize that’s not an easy task. Such diagrams are far more complex than “this box goes inside of that box.” For now, if you want an AWS diagram that meets your needs, someone is going to have to do it by hand.\n","date":"7 September 2017","externalUrl":null,"permalink":"/2017/09/a-quick-and-dirty-review-of-aws-diagramming-software/","section":"Posts","summary":"","title":"A Quick and Dirty Review of AWS Diagramming Software","type":"post"},{"content":"I think it’s time to stop using the term “network function virtualization”. Why? Because it doesn’t exist, at least not in the way the term suggests. The term is a category error, and when people try to make sense of the term, confusion and frustration ensue.\nThink of it like this: what’s the difference between a “virtual network function” and a “non-virtual network function”? For example, how is “virtual IP forwarding” different than “non-virtual IP forwarding?” Answer: it’s not.\nSo what then exactly is network function virtualization?\nThe Right Idea, The Wrong Term # The European Telecommunications Standards Institute, which arguably coined the term NFV, said the following in a 2012 whitepaper (emphasis mine):\nNetwork Functions Virtualisation aims to address these problems by leveraging standard IT virtualisation technology to consolidate many network equipment types onto industry standard high volume servers\nLook at the bold text. How does one consolidate many network equipment types onto commodity servers? Let’s add some specifics to make it more concrete. How does one consolidate a firewall , router, switch, and load-balancer onto a server? By implementing those network functions in software and putting that software on the server.\nBut here’s the problem with calling that “network function virtualization”: **virtualization has nothing to do with implementing network functions in software. **In the early days of the Internet, routers (gateways as they were called back then) ran on commodity x86 machines with no virtualization (with the exception, maybe, of virtual memory).\nNetwork functions don’t need virtualizing, and in fact, can’t be virtualized. But the term NFV suggests otherwise.\nAnd that’s where the confusion started….\nNFV is like dividing by zero: undefined # Conceptually, NFV is just implementing network functions in software. That’s easy enough to understand. And yet it’s hard to find an actual definition of it anywhere. Instead, you’ll see a lot of hand-wavy things like this:\n_NFV is a virtual networking concept…\n_ NFV is a network architecture concept that uses the technologies of IT virtualization…\nHence the letters “N” and “V”. And then you have those who gave up on a definition and just went straight for the marketing lingo:\nNFV is the next step…\n…is the future…\n…is the progression/evolution…\nOthers get closer by hinting at what NFV does, but stop short of actually saying what it is:\nNFV consolidates multiple network functions onto industry standard equipment\nThis seems to be pretty close, but where’s the virtualization part come in? Let’s try this blurb from Angela Karl at TechGenix:\n[NFV lets] service providers and operators… abstract network services, including things such as load balancing, into a software that can run on basic server.\nBingo. NFV is not virtualizaton at all. It’s an abstraction of network functions!\nNFV is Abstraction, not Virtualization # Before you accuse me of splitting hairs, let me explain the distinction between virtualization and abstraction. Put simply, virtualization is an imitation, while abstraction is a disguise.\nVirtualization is an imitation # When you virtualize something, you’re creating an imitation of the thing you’re virtualizing.\nFor example, when you create a virtual disk in your favorite hypervisor, you’re hiding the characteristics of the underlying storage (disk geometry, partition info, formatting, interface, etc.). But in the same motion, you give the virtual disk the same types of characteristics: disk geometry, partition info, formatting, interface, and so on. To put it in programming lingo, the properties are the same, but the values are different.\nVirtualization preserves the underlying properties and doesn’t add any property that’s not already there. Have you ever pinged a virtual disk? Probably not, because virtual disks, like real disks, don’t have network stacks.\nVirtualization also preserves the behavior of the thing being virtualized. That’s why you can “shut down” and “power off” virtual machines and “format” and “repartition” virtual disks.\nNow try fitting NFV into this definition of virtualization. How do you “virtually route” or “virtually block” a packet? It’s a category error.\nAbstraction is a disguise # When you create an abstraction, you’re creating a disguise. Unlike virtualization, with abstraction you’re changing some of the properties of the thing you’re abstracting. You’re taking something and dressing it up to look and act completely different.\nSwap space is a good example of an abstraction. It’s data on storage that looks and acts like random access memory (but way slower). Before the days of SSDs, swap was stored on spinning disks which were read and written sequentially. This is completely different than memory which can be read and written randomly. Swap space is a file (Windows) or partition (Linux) disguised as RAM.\nThe Case for Abstracting Network Functions # Let’s bring this around to networking. What’s it mean to abstract network functions like IP routing and traffic filtering? More importantly, why would you want to? Why not just use virtual routers, switches, and firewalls?\nSimply put, virtualized network devices don’t scale. The reasons for this are too numerous to list here, but suffice it to say that TCP/IP and Ethernet networks have a lot of built-in waste and aren’t the most efficient. This is why cloud providers do network function abstraction to an extreme. It’s utterly necessary. Let’s take Amazon AWS as an example.\nIn AWS, an instance has a virtual network interface. But what’s that virtual network interface connected to? A virtual switch? Nope. Virtual router? Try again. A virtual firewall . Negative. Virtual routers, switches, and firewalls don’t exist on the AWS platform. So the question remains: what’s that virtual NIC connected to?\nThe answer: nothing. The word “connected” here is a virtual concept borrowed from the real world. You “connect” NICs to switches. In your favorite hypervisor, you “connect” a vNIC to a vSwitch.\nBut there are no virtual switches or routers in this cloud. They’ve been abstracted into network functions. AWS presents this as if you’re connecting a virtual interface to a “subnet” rather than a router. That’s because AWS has abstracted IP routing away from you, leaving you with nothing to “connect” to. After all, we’re dealing with data. Not devices. Not even virtual devices._ _So what happens? The virtual NIC passes its traffic to some software that performs network functions. This software does a number of things:\nSwitching – It looks at the Ethernet frame and checks the destination MAC address. If the frame contains an ARP request seeking the default gateway, it replies. Traffic Filtering – If it’s a unicast for the default gateway, it looks at the IP header and checks the destination against the security group rules, NACLs, and routing rules. Routing – If it needs to forward the packet, it forwards it (although forwarding may simply consist of passing it off to another function.) This is a massive oversimplification, of course, but you get the idea. There’s no reason to “virtualize” anything here because all you’re doing is manipulating bits!\nOvervirtualizing the Network # It’s possible to over-virtualize. To give an analogy, suppose you wanted to write a calculator application (let’s call it a virtual calculator). You’d draw a little box with numbers and operators, and let the user click the buttons to perform a calculation. Now imagine that you also decided to write a “virtual hand” application that virtually pressed buttons on the virtual calculator. That would be ridiculous, but that’s essentially what happens when you connect two virtual network devices together.\nThere an especially great temptation to do this in the cloud. Folks may spin up virtual firewalls, cluster them together, connect them to virtual load-balancers, IDSes, and whatnot. That’s not bad or technically wrong, but in many cases it’s just unnecessary. All of those network functions can be performed in software, without the additional complexity of virtual NICs connecting to this and that.\nThe Difference Between a Virtual Network Device and a Network Function # When it comes to the cloud, it’s not always clear what you’re looking at. Here are some questions I ask to figure out whether a thing in the cloud is a virtual device or just a abstracted network function:\nIs there an obvious real world analog? # There’s a continuum here. An instance has a clear real world analog: a virtual machine. An Internet gateway sounds awfully like the router your ISP puts at your site, but “connecting” to it is a bit hand-wavy. You don’t get a next-hop IP or interface. Instead, your next hop is igw- followed by some gibberish. That smacks of an abstraction to me.\nCan you view the MAC address table or create bogus ARP entries? # If you can, it’s a virtual device (maybe just a Linux VM). If not, it’s likely some voodoo done in software.\nCan you blackhole routes? # In AWS you can create blackhole routes, although people usually do it by accident. You can create a route with an internet gateway as a next hop, then delete the gateway. But can you create a route pointing to null0? If not, you have an abstraction, not a virtual device.\nDoes the TTL get decremented at each hop? # A TTL in an overlay can get decremented based on the hops in the underlay. But what I’m talking about here is not decrementing the TTL when you normally would. AWS doesn’t decrement the TTL at each hop. If you were to get into a routing loop, you’d have a nasty problem. Hence, AWS doesn’t allow transitive routing through its VPCs. So if your TTLs don’t go down at each hop, as with AWS, you’re probably dealing with an abstraction.\n","date":"25 August 2017","externalUrl":null,"permalink":"/2017/08/its-time-to-stop-using-the-term-network-function-virtualization-nfv/","section":"Posts","summary":"","title":"It’s Time to Stop Using the Term Network Function Virtualization (NFV)","type":"post"},{"content":"I know what you’re thinking. “Why use Visual Studio Code instead of the PowerShell ISE?” Well, if you’re using Mac OS or Linux, you don’t have the option to use the PowerShell ISE natively. And that’s a problem if you want to take advantage of the cross-platform capabilities of PowerShell Core. In this article, I’ll show you how to use Visual Studio Code (free!) to perform the key functions of the PowerShell ISE, namely:\nSimultaneously view code and execute it in the PoSh terminal Execute code on a selection or line-by-line basis (F8) Syntax highlighting (for people who are easily bored like me) Installing Visual Studio Code # The best way to install most things is with a package manager. This would be something like apt-get or yum for Linux distros, homebrew for Mac OS, and Chocolatey for Windows. Or you could go old school and download it here.\nInstalling the PowerShell Extension # Go to the Extensions button (looks like a busted up square) or View \u003e Extensions. If the PowerShell extension doesn\u0026#8217;t show up under the bombastic \u0026#8220;RECOMMENDED\u0026#8221; heading, just search for it in the \u0026#8220;Search Extensions\u0026#8221; field. Then install it. Integrating the PowerShell Terminal # Open up a PowerShell script of your choice. Then in the menu, go to View \u003e Integrated Terminal. You should see the following. If you don’t see the PS prompt Make sure you select “TERMINAL” and “PowerShell Integrated” from the drop-down menu.\nRunning Only Selected Code # In the PowerShell ISE, you can select a block of text and hit F8, and the ISE runs only that code. Or you can position your cursor at the end of a line and hit F8, and the ISE runs only the code on that line. Next we’ll enable the exact same behavior in Visual Studio Code.\nGo To File \u003e Preferences \u003e Keyboard Shortcut In the text entry field at the top, type “runsel”. You should see two items:\n“Run Selection” with a keybinding to F8 “Run Selected Text In Active Terminal” with no keybinding This is not what we want because it will not run the selected text in the PowerShell terminal. It will run the selection in the “OUTPUT” section, but not in the terminal. Obviously, that’s not the normal behavior of the PowerShell ISE. Let’s fix it.\nRight-click the \u0026#8220;Run Selection\u0026#8221; item and select \u0026#8220;Remove keybinding\u0026#8221; Right-click the \u0026#8220;Run Selected Text in Active Terminal\u0026#8221; item and select \u0026#8220;Add Keybinding\u0026#8221; Depress the F8 key (or whatever you want to use) then hit Enter. Testing It Out # Go back to your code and select a block of code. Hit F8 and watch the magic! That’s what I’m talking about!\nBut… as of this writing, there’s an issue with this that’s being tracked on the vscode-powershell GitHub repo, and it’s this: multi-line input in the integrated console doesn’t work. That means you can’t select a function block, hit F8, and have it work. It will throw ugly errors in your face.\n","date":"15 August 2017","externalUrl":null,"permalink":"/2017/08/visual-studio-code-as-a-powershell-integrated-scripting-environment/","section":"Posts","summary":"","title":"Visual Studio Code as a PowerShell Integrated Scripting Environment","type":"post"},{"content":"Check out my newest book, Learn Cisco Network Administration in a Month of Lunches.\nAnd in case you didn’t know, I have over 16 Cisco CCNP and Windows networking training courses available on Pluralsight.\nBefore you go, sign up for my free newsletter using the box on the right.\nThanks again!\nBen\n","date":"28 February 2017","externalUrl":null,"permalink":"/thanks-for-the-follow/","section":"Ben Piper","summary":"","title":"Thanks for the follow!","type":"page"},{"content":"","date":"1 January 2017","externalUrl":null,"permalink":"/tags/humor/","section":"Tags","summary":"","title":"Humor","type":"tags"},{"content":"","date":"1 January 2017","externalUrl":null,"permalink":"/tags/ipv6/","section":"Tags","summary":"","title":"Ipv6","type":"tags"},{"content":"","date":"1 January 2017","externalUrl":null,"permalink":"/tags/nat/","section":"Tags","summary":"","title":"Nat","type":"tags"},{"content":"If you haven’t learned IPv6 yet, well, you’re not the only one. In December 2016, IPv6 (as we know it today) turned 18 years old. Children who were in the womb when RFC 2460 was being drafted are now old enough to vote, get married, and purchase firearms in some states.\nIn honor of IPv6’s 18th birthday, allow me to share my theories on why people have been so slow to adopt it. And why you still should consider learning it.\nThe “Lame name” theory # IPv6 terminology makes it sound like a new version of IPv4 and it’s not. It’s a totally different protocol with a similar name. If you’re familiar with the confusion between Java and JavaScript, you know what I’m talking about. People who set out to learn IPv6 are disappointed when they find out it’s almost nothing like IPv4.\nThe “Let’s split DHCP in half and spread its most popular functions across two protocols” theory # DHCP for IPv4 can provide clients with IP addresses, DNS servers, default gateways, TFTP servers, and pretty much anything else. DHCPv6 doesn’t have an option for providing a default gateway. If you want to push a default gateway to clients, you have to use SLAAC.\nThe “all things to all people, places, animals, plants” theory # IPv4 has only a few address types that anyone actually uses. Colloquially, they’re public, private (RFC 1918 addresses like 192.168.1.1), and multicast (which includes broadcast). IPv6 has approximately one zillion different address types, including unique-local, link-local, unspecified, and global unicast. Although there are technical justifications for some of these, the plethora of address types makes no sense to anyone who doesn’t deeply understand why “layer 2” is even in the IT lexicon.\nThe “IPv4 apocalypse” theory # We’ve all heard the constant chicken-little talk about how we have to move to IPv6 yesterday or the internet will die. Driving this is the myth that all IPv4 addresses are gone. They’re not, and the U.S. government is sitting on tens of thousands it’s never going to use. What really happened was that in 2011, the Internet Assigned Numbers Authority (IANA) assigned the last of its available IP address space to regional internet registries (RIRs) which are responsible for doling out addresses. But the IPv4 addresses didn’t just go away. They still exist, and many of them are unused and can be reassigned.\nThe “NAT is a tool of the devil” theory # If you ever want to have fun, go on any IT forum and ask, “Why do we need IPv6 when we have NAT?” Actually, don’t. That would be trolling. But if you were to ask that question, you’d probably get a few responses hating on IPv4 NAT as a tool of the devil, which IPv6 will save us from… except it does NAT, too.\nThe “Why do I need both again?” theory # Implementing IPv6 almost always requires a multihomed (dual-stack) implementation, which people figured out about 30 years ago was a bad idea with IPv4 because it confuses everybody. IT admins translate this as, “More work for me.”\nThe “Because we can” theory # There are enough IPv6 addresses for every cell in your body to have its own internet. Seriously? This, like NAT, is another non-reason to adopt it. Yes, it’s cool that I can give my Uncle Milton’s ant farm its own Internet. But as far as business justification goes, nope.\nWhy you might want to learn IPv6 (hint: money) # Although it’s been poorly marketed, it’s still worth learning. In fact, I believe in IPv6 so strongly that I’ve created several courses on configuring and troubleshooting it.\nHere are three big reasons to consider adding it to your set of skills: # It’s like a sports team. The big boys are rooting for it. I’m talking about Cisco , Juniper, ISPs, Google, et alia. They want to see it win, and they’ll pay to make it happen. You can be on the receiving end of some of those payments. The confusion and complexity around IPv6 has made experts that much more valuable to companies who have already invested in new infrastructure. If you know IPv4, IPv6 isn’t that hard to learn once you realize that it’s a distinct protocol and not a new version of IPv4. For further IPv6 learning, check out my Practical Networking course.\n","date":"1 January 2017","externalUrl":null,"permalink":"/2017/01/people-still-havent-adopted-ipv6-learn-anyway/","section":"Posts","summary":"","title":"Why People Haven’t Adopted IPv6 (And Why You Should Learn It Anyway)","type":"post"},{"content":"Recently I needed a way to copy a certificate file from within a PowerShell session to another Windows machine without opening a nested PowerShell session. But I ran into a little snag along the way: Copy-Item‘s dreaded Access is denied error.\nHere’s my setup # A Windows 10 laptop, from which I’m remoting NC1, a Server 2016 virtual machine I’m remoted into. It’s a member of a domain. HYPERV1, the Server 2016 machine I want to copy a certificate file to. It’s not a member of a domain. I execute all of the following commands on NC1, the VM I’m remoted into.\nHere’s the first thing I tried. The HYPERV1 machine is not a member of a domain, so the following doesn’t work:\n$ Copy-Item .\\nccert.cer \\\\hyperv1\\c$ Access is denied + CategoryInfo : NotSpecified: (:) [Copy-Item], UnauthorizedAccessException + FullyQualifiedErrorId : System.UnauthorizedAccessException,Microsoft.PowerShell.Commands.CopyItemCommand What about specifying the -Credential parameter? That doesn’t work either.\n$ Copy-Item .\\nccert.cer \\\\hyperv1\\c$ -Credential hyperv1\\administrator The FileSystem provider supports credentials only on the New-PSDrive cmdlet. Perform the operation again without specifying credentials. + CategoryInfo : NotImplemented: (:) [], PSNotSupportedException + FullyQualifiedErrorId : NotSupported And that error pretty much tells me what I need to do: use the New-PSDrive cmdlet!\nNew-PSDrive -Name H -PSProvider FileSystem -root \\\\hyperv1\\c$ -Credential hyperv1\\administrator Copy-Item .\\nccert.cer h:\\ Remove-PSDrive -Name H Ready to beef up your PowerShell skills? Get unlimited access to every course in Pluralsight\u0026rsquo;s online training library!\n","date":"25 October 2016","externalUrl":null,"permalink":"/2016/10/copying-a-file-from-within-a-remote-powershell-session/","section":"Posts","summary":"","title":"Fixing PowerShell’s Copy-Item “Access is Denied” Error","type":"post"},{"content":"","date":"25 October 2016","externalUrl":null,"permalink":"/tags/windows-server/","section":"Tags","summary":"","title":"Windows-Server","type":"tags"},{"content":"If you have a home lab and don’t need vCenter, thee ESXi Embedded Host Client gives you web-based access to hidden features of your standalone ESXi host… without having to spin up a real vCenter server.\nAs most everyone knows, the old VMware vSphere C# client has been on its way out for years. One of the things keeping it alive is the fact that not everyone has a vCenter Server, and even those who do don’t necessarily use the Web Client. Sadly, there are some really cool features the old Windows client can’t touch, such as exposing hardware -assisted virtualization to individual VMs.\nHere’s how to install it # Shut down all VMs and place the host in maintenance mode\nSSH into ESXi and execute the following\n[root@esxi:~] esxcli software vib install -v http://download3.vmware.com/software/vmw-tools/esxui/esxui-signed-4393350.vib\nBrowse to https://[ESXi]/ui You should see the login screen:\nLog in using whatever credentials you use in the old C# vSphere client. You should see something that looks an awful lot like the vSphere Web Client: ","date":"24 September 2016","externalUrl":null,"permalink":"/2016/09/installing-the-vmware-esxi-embedded-host-client/","section":"Posts","summary":"","title":"Installing the VMware ESXi Embedded Host Client","type":"post"},{"content":"After upgrading my Lenovo ThinkPad to Windows 10, I was so pumped. The upgrade went smoothly, all my apps worked, but then I noticed something: some apps had blurry, fuzzy text.\nUgly, blurry, fuzzy text on Windows 10: # This might not bother some people, but to me it felt like trying to read a wet book with my glasses off. Most everything else looked sharp and normal, so I knew it wasn’t a native resolution or global DPI scaling issue, which is what most of my Google-fu turned up.\nThe fix (hint: not prescription eyeglasses) # The fix turned out to be crazy stupid. Well, more stupid than crazy. Go into the Properties of the app that’s rubbing salt water in your eyes:\nNavigate to the Compatibility tab. Check that “Disable display scaling on high DPI settings” check box, apply the settings, then launch the app again.\nThat’s what I’m talking about. The window is bigger, and the text doesn’t look like garbage.\nBut wait, there’s more! (PowerShell) # If you’re a PowerShell 1337 scripter, you may run into a similar issue. Check this out:\nIf you’ve ever hooked up a computer to an old CRT television using an RF converter, well, this is about what it looks like. Ugly as homemade sin, as they used to say. Don’t worry about the error. I left it to highlight how horrendously eye-stab-worthy this console looked when I first opened up a can of PoSH on my newly minted Windows 10 upgrade.\nThe fix? Go to PowerShell properties:\nNavigate to the Options tab (intuitive, right?). Check the box “Use legacy console” (duh), then apply the settings. Relaunch PowerShell.\nThe image makes it look a bit fuzzy still, but on my screen it looks crisp and sharp.\n","date":"7 July 2016","externalUrl":null,"permalink":"/2016/07/how-to-fix-the-blurry-fuzzy-ugly-text-in-windows-10/","section":"Posts","summary":"","title":"How to Fix the Blurry, Fuzzy, Ugly Text in Windows 10","type":"post"},{"content":"Still not convinced that you should learn Windows PowerShell? A popular conspiracy theory asserts that Russia used some awesome PowerShell tricks to hack the Democratic National Committee and get Donald Trump’s opposition research file.\nWhile you shouldn’t (and hopefully won’t) use PowerShell for international espionage, there are some really awesome things you can do with it, like building out an entire Windows server start-to-finish without a GUI.\n","date":"15 June 2016","externalUrl":null,"permalink":"/2016/06/powershell-and-donald-trump/","section":"Posts","summary":"","title":"PowerShell and Donald Trump","type":"post"},{"content":"The pre-release of my new book, Learn Cisco Network Administration in a Month of Lunches, is available from Manning Publications’ early access program.\nThe book is a tutorial designed for beginners who want to learn how to administer Cisco switches and routers. Set aside a portion of your lunch hour every day for a month, and you’ll start learning practical Cisco Network administration skills faster than you ever thought possible.\n","date":"15 March 2016","externalUrl":null,"permalink":"/2016/03/learn-cisco-network-administration-in-a-month-of-lunches/","section":"Posts","summary":"","title":"New book! Learn Cisco Network Administration in a Month of Lunches","type":"post"},{"content":"News outlets and other publications I’ve been quoted in\n10 bad habits network administrators should avoid at all costs\nCyberCoders – 5 Questions to Ask Before You Take the Job\nCIO – Has public Wi-Fi outlived its usefulness?\nLinuxInsider – New SourceForge Owners Start Trust Repair\nTechTarget – Build a shadow IT strategy all departments will love\nEU Could Rain On Cloud Strategy With Too-Tight Data Rules\nCNBC – Revising an Outdated Business Model? Try Predictive Analytics\nNetworkWorld – When in China, don’t leave your laptop alone\nMonster.com – Holiday Hiring: Naughty or Nice? NBC Chicago – How Internet Explorer 10’s “Do Not Track” Option Affects Your Marketing\nAmerican Medical News – Desktops still dominate at physician offices\n","date":"13 February 2016","externalUrl":null,"permalink":"/newsroom/","section":"Ben Piper","summary":"News outlets and other publications I’ve been quoted in\n","title":"Newsroom","type":"page"},{"content":"","date":"15 August 2015","externalUrl":null,"permalink":"/tags/beginner/","section":"Tags","summary":"","title":"Beginner","type":"tags"},{"content":" For beginners who need Cisco basics repeated without judgment # 22 bite-sized lessons covering networking fundamentals, routing, switching, VLANs, and security — even if you\u0026rsquo;ve never touched a Cisco device.\nBased on teaching approach that asks what matters day-to-day, so juniors get basics repeated and seniors get acknowledgment for what they built.\nBuy # View on Amazon (affiliate) ","date":"15 August 2015","externalUrl":null,"permalink":"/books/learn-cisco-month-lunches/","section":"Books","summary":"","title":"Learn Cisco Network Administration in a Month of Lunches","type":"page"},{"content":"","date":"23 June 2015","externalUrl":null,"permalink":"/tags/2015/","section":"Tags","summary":"","title":"2015","type":"tags"},{"content":"You can pass the CCNP R\u0026amp;S exams the first time, but it’s not as simple as just studying everything. Here are a few things to keep in mind when preparing…\nThe CCNP exams test CCNA-level skills and knowledge, too # That’s a good thing, because it helps weed out those who “brain dump” the exams. If you got lucky with OSPF on your CCNA exam, you’re not going to get lucky on the CCNP ROUTE exam. You really DO need to know this stuff. You can’t just pass the CCNA composite exam and then forget everything. You have to have a solid foundation to build on. You’re never too educated to go back and revisit the fundamentals.\nSpend most of your time studying configuration and troubleshooting at the command line interface. # There’s no hard and fast rule on this, but a good rule of thumb is this: make sure you spend AT LEAST 50% of your time in IOS. Both the ROUTE and SWITCH exams have some simulations, but the TSHOOT exam has a LOT. If you’re not proficient with the command line interface, you won’t pass. Again, this weeds out the dumpers, and it raises the difficulty level of attaining the cert.\nWrite down all your questions in one place and periodically revisit them. # You’ll be amazed at how many questions you will learn the answer to without realizing it. Some questions you’ll look at and think, “Duh, that one’s easy. How did I not know that before?” From my CCIE studies, I have a list of questions that I organized by category: Layer 2, Layer 3, Security, QoS, etc. Writing down questions also reminds you of how much you DON’T know, highlights your misconceptions, and becomes a de-facto study guide. The last thing you want going into the exam is a false sense of security.\nThe exams cover a LOT of topics, and some of them are pretty in depth. # This is where a lot of people get frustrated, confused, or just overwhelmed. They look at the exam topics, see the magnitude of it all, and try to study and memorize everything about everything.\nThat’s one of the biggest reasons I’m creating a series of CCNP R\u0026amp;S courses for Pluralsight. # In each course I focus on real-world customer requirements and then demonstrate how to configure them step-by-step, explaining each command as I go. When watching the courses, you’ll quickly get an idea of what areas you need to study more and what areas you already know.\nNot only that, each course module includes an assessment which thoroughly tests your knowledge of the relevant exam material. And, if you get an answer wrong, it will take you to the exact spot in the course where I cover that particular topic. It’s an incredibly effective way to study and learn quickly.\n","date":"23 June 2015","externalUrl":null,"permalink":"/2015/06/study-tips-ccnp-routing-switching-certification/","section":"Posts","summary":"","title":"Pass the First Time: Study Tips for the CCNP Routing and Switching Certification","type":"post"},{"content":"Sometimes you just need to create a file share.\nWith Windows Server Core, you don’t have all the old GUI tools that we’re all used to. So you have to make do with PowerShell and the old fake DOS prompt. Fortunately, with a little help, it’s pretty easy.\nFirst, create the folder you want to share. In this case, c:\\share\nNext, modify the ACL to grant the DOMAIN\\File Server Admins group full control\n$sharepath = \u0026#34;c:\\share\u0026#34;\u0026lt;br /\u0026gt; $Acl = Get-ACL $SharePath\u0026lt;br /\u0026gt; $AccessRule= New-Object System.Security.AccessControl.FileSystemAccessRule(\u0026#34;DOMAIN\\File Server Admins\u0026#34;,\u0026#34;full\u0026#34;,\u0026#34;ContainerInherit,Objectinherit\u0026#34;,\u0026#34;none\u0026#34;,\u0026#34;Allow\u0026#34;)\u0026lt;br /\u0026gt; $Acl.AddAccessRule($AccessRule)\u0026lt;br /\u0026gt; Set-Acl $SharePath $Acl Finally, create the share and grant everyone full access. NET SHARE sharename=c:\\share \u0026#34;/GRANT:Everyone,FULL\u0026#34;\nDone.\n","date":"2 June 2015","externalUrl":null,"permalink":"/2015/06/creating-file-share-powershell-windows-server-2012-core/","section":"Posts","summary":"","title":"Creating a File Share with PowerShell and Windows Server Core","type":"post"},{"content":"Remember when everyone had to have an Apple product — an iPhone, Macbook, or iPad? Look at how fast things changed. Android has been leading the tablet and smartphone market and crushing Apple for years now. So what does this mean for Apple?\n#1 – Apple is now Apple, circa 1997. # Apple is trying to “me-too” its way back to success with its Apple Watch. We already have fitness bands that tell time. Apple’s desperate desire to “innovate” has ironically had the opposite effect — they’re just copying the success of others. It’s the same mistake they made in the late 1990’s after firing Steve Jobs. They copied IBM and almost went bankrupt. When Steve Jobs returned, Apple made a comeback.\nBut Steve Jobs is dead. This sounds harsh, but the fact is that Apple never did well without him. I remember owning Apple stock when it was $6 a share. That’s six dollars. With Jobs gone, it’s back to the 1990’s in terms of leadership.\n#2 – Apple is falling behind. # Their initial success with the iPhone was because they got it to market faster than Google got Android out. Android predates the iPhone, but most people don’t know that and frankly don’t care. The iPhone got there first so Apple won.\nFast-forward several years. Samsung released an Android version of the Apple Watch before Apple did. They copied Apple before Apple could even get their own product out the door! Bottom line: Apple has lost its competitive edge.\n#3 – Apple picks fights it can’t win. # Apple has notoriously sued other companies for various things. Now everyone else is suing apple for patent infringement and a slew of other offenses, and some of them have pretty strong cases. Their fat bank account makes it a prime target for litigation, which only detracts from its ability to provide valuable products and services.\n#4 – Their products spy on you. # This isn’t news, and Apple certainly isn’t the only company with espionage built-in. But they really don’t like the idea of “hackers” poking around iOS. With Android and, to a lesser extent, Microsoft products it’s trivial for an experienced security professional to figure out what information is being collected. iOS can be jailbroken and analyzed just as well, but woe unto those who receive an update and have their iPhone bricked because they dared to jailbreak.\n#5 – Apple’s leadership is alienating its customers. # In 2014 CEO Tim Cook famously said that those who aren’t of a particular political persuasion should sell Apple stock. He also said that he doesn’t always consider return-on-investment (ROI) when making business decisions. Perhaps people have different reasons for owning stock, but the most common is to get a return-on-investment. But it’s also more than that. People also buy Apple products to get a return-on-investment, whether its financial, emotional, or something else. Tim Cook’s comments indicate that he isn’t interested in serving customers in this way.\nIs it too late for Apple? # Flexibility is a vital aspect of any technology. If it isn’t flexible, it can’t change rapidly to meet business or personal goals. Apple just might be turning back into the rigid, sluggish, and expensive relic it was in the late 1990’s. Just think of how AT\u0026amp;T is today. That could change, of course, but their ecosystem is set up in such a way that the longer you’re invested in their products, the harder it is to leave. Maybe we should take Tim Cook’s advice until Apple can get its act together.\n","date":"6 May 2015","externalUrl":null,"permalink":"/2015/05/5-reasons-consider-leaving-apple/","section":"Posts","summary":"","title":"5 Reasons to Consider Leaving Apple","type":"post"},{"content":"Forget using scripts and group policies to configure a new Windows Server machine. Using Chocolatey and Puppet, you can do it faster \u0026amp; easier than ever (and it’s more fun too). This is especially true if you’re using a Server Core installation and don’t have a GUI to help you along. Oh, and if you don’t know Puppet, you really should watch my course Puppet Fundamentals for System Administrators on Pluralsight 🙂\nAssign IP address using PowerShell: # $ New-NetIPAddress –InterfaceAlias \u0026#34;Ethernet\u0026#34; –IPAddress \u0026#34;192.168.51.29\u0026#34; –PrefixLength 24 -DefaultGateway 192.168.51.8 $ Set-DnsClientServerAddress -InterfaceAlias \u0026#34;Ethernet\u0026#34; -ServerAddresses 192.168.50.20, 192.168.50.21 Install Chocolatey: # $ set-executionpolicy unrestricted\u0026lt;br /\u0026gt; $ iex ((new-object net.webclient).DownloadString(\u0026#39;https://chocolatey.org/install.ps1\u0026#39;)) Restart PowerShell # Install VMware tools # $ choco install vmware-tools The server will automatically restart.\nRename server # $ rename-computer -newname newservername Reboot # restart-computer Join to domain add-computer -domain benpiper.com Reboot again restart-computer Install Puppet choco install puppet Configure Puppet Configure c:\\programdata\\puppetlabs\\puppet\\etc\\puppet.conf Generate puppet certificate puppet_interactive Sign puppet certificate on puppet master puppet cert sign newservername Apply appropriate profiles to server. Remember to restart the Puppet master if you change your Hiera configuration.\nRun Puppet agent puppet_interactive Verify puppet resource dism puppet resource package\n","date":"5 May 2015","externalUrl":null,"permalink":"/2015/05/windows-server-2012-using-puppet-chocolatey/","section":"Posts","summary":"","title":"Building Windows Server with Puppet and Chocolatey","type":"post"},{"content":"","date":"5 May 2015","externalUrl":null,"permalink":"/tags/configuration-management/","section":"Tags","summary":"","title":"Configuration-Management","type":"tags"},{"content":"","date":"5 May 2015","externalUrl":null,"permalink":"/tags/puppet/","section":"Tags","summary":"","title":"Puppet","type":"tags"},{"content":"Years ago when I was active on twitter, I made a few passing observations about this strange place called Twitter:\n“A lot of people follow me for a few days then unfollow me if I don’t follow them back” There are so many things wrong with this. Following someone just so they’ll follow you back is selfish. It’s pretty obvious these folks are just using others to increase their follower count. They follow 5,000 people and have 4,999 people following them. Yeah, not impressed. Seeing this doesn’t make me think that person is influential. It makes me think they’re obsessive.\nWhich naturally leads into the next observation…\n“If everyone follows everyone else then what’s the point of following?” There is no way anyone who follows 5,000 people is keeping up with their timeline. And there’s also no way that many people are simultaneously tweeting things that are that interesting. It’s like having 5,000 radios all tuned to different stations, and constantly jumping around to each one to hear what is being said at that moment. Nobody does that. Well, maybe someone does. But I don’t want them following me.\n“Why is he/she/it following me?” Sometimes I get followed by strange accounts with interests nowhere in the same universe as what I tweet about. Most of them seem to be based on keywords or favorites, and it’s obvious the majority of these are automated. Of course, if I don’t follow them back, they go away on their own, thankfully. These accounts can range from the innocuous joke account to things I won’t even mention.\n“People spend a ridiculous amount of time on here” Sometimes I will go back and try to find a particular tweet from someone. I usually give up after I have to scroll through 50 pages of that person’s tweets just from the last 4 hours. I envision such people with their neck cricked downward, tweeting on their phones every 5 minutes. I understand the whole “staying top of mind” thing if you’re marketing, but I doubt you’re going to miss out on anything if you take your tweeting frequency down a notch.\n“People are really rude/inappropriate/mean” I don’t care much for Twitter ads (aka “sponsored tweets”) that have no relevance to my interests. I usually ignore them, but I’ve seen people reply to them with the filthiest, vilest language you can imagine. I can only imagine the verbal abuse taken by their TV and radio.\n“Twitter is uncensored and unpatrolled” There’s a way to report content that violates Twitter’s terms. The caveat, however, is that all it does is make you feel like you did something. It’s sort of like spraying perfume on a dead cat. The perfume might smell alright, but the cat’s still dead, and it’s not going anywhere. Twitter rarely seems to take action on tweets unless it’s about something blatantly illegal. In other words, Twitter isn’t the place to visit when children are near by, and probably never will be.\n“Twitter suffers from ‘LinkedIn Profile Fail Syndrome\u0026rsquo;” A while back I noticed that LinkedIn will show you people’s full names if you’re not logged in, but once you log in, it will hide them if you’re not “connected.” I dubbed this the LinkedIn Profile Fail Syndrome or LPFS, and Twitter suffers a similar ailment. You can block a user on Twitter, which prevents them from seeing your tweets and also stops anything from them showing up in your timeline. If the blocked person, however, logs out, they can see everything of yours, as long as it’s public. Yeah, that makes sense.\nMy Twitter Manifesto # I no longer use twitter because it\u0026rsquo;s a garbage dump. But when I was using it, to combat the above deficiencies, I came up with a set of rules that applies not just to Twitter, but all social media in general.\n1. I only follow people who post things I find interesting. # In other words, whether I follow you or not has nothing to do with you personally. There are people I know and love personally that I do not follow. It’s not personal. I only want to see certain things in my timeline, so I only follow a very small number of people.\n2. I don’t live on twitter. # I have an offline life. I work, do courses for Pluralsight, and study my craft. Twitter is recreational. I might find your tweets eminently interesting and profound, but I might not read them until weeks after they’ve floated down the twitter stream.\n3. I don’t get into lengthy discussions or debates on twitter. # The only exception is if I think a public discourse will be helpful to others. This implies it has to be coherent and easy to follow, which is pretty rare.\n4. I don’t post detailed personal information. # Ever. Anywhere. This includes where I work, where I shop, where I eat, who I’m with, etc. There are far too many criminals, fraudsters, and just plain weirdos who have nothing better to do than grab onto some low hanging social media fruit and indulge their sociopathic tendencies. No thank you.\n5. The Internet is forever. # Not really. Nothing material lasts forever. But, like a diamond, the Internet is pretty close. I don’t post anything online that I don’t want everyone to see.\n","date":"4 April 2015","externalUrl":null,"permalink":"/2015/04/twitter-philosophy-manifesto/","section":"Posts","summary":"Years ago when I was active on twitter, I made a few passing observations about this strange place called Twitter:\n“A lot of people follow me for a few days then unfollow me if I don’t follow them back” There are so many things wrong with this. Following someone just so they’ll follow you back is selfish. It’s pretty obvious these folks are just using others to increase their follower count. They follow 5,000 people and have 4,999 people following them. Yeah, not impressed. Seeing this doesn’t make me think that person is influential. It makes me think they’re obsessive.\n","title":"My Twitter Philosophy","type":"post"},{"content":"I recently ran into a bizarre issue with users not being able to launch applications from a very old Citrix Presentation Server 4.0 farm when trying to launch from Citrix Web Interface 5.4. They were getting the eminently unhelpful, “An error occurred while making the requested connection.”\nThe Diagnosis # In the web interface application logs, I noticed this:\nAn error of type IMA with an error ID of 0x80000003 was reported from the Citrix XML Service at address (servername)\nAnd this:\nThe farm MyFarm has been configured to use launch references, but a launch reference was not received from the Citrix XML Service. Check that the farm supports launch references or disable launch reference requests.\nThe Solution # To resolve this, I modified C:\\inetpub\\wwwroot\\Citrix\\XenApp\\conf\\WebInterface.conf on the Web Interface servers and changed the RequireLaunchReference directive as follows:\nRequireLaunchReference=Off\n(It was set to On)\nAnd it worked. Supposedly, that directive must be set to Off when using Web Interface 5.4 with PS 4.0. But, I’ve been running for years with it set to On and it worked fine until recently. Another Citrix mystery.\nWant more Citrix tips and tricks? Watch my Citrix NetScaler course!\n","date":"17 February 2015","externalUrl":null,"permalink":"/2015/02/error-occurred-making-requested-connection-citrix-web-interface-5-4/","section":"Posts","summary":"","title":"Citrix Web Interface: Error occurred while making the requested connection","type":"post"},{"content":"","date":"17 February 2015","externalUrl":null,"permalink":"/categories/free-resources/","section":"Categories","summary":"","title":"Free Resources","type":"categories"},{"content":"","date":"17 February 2015","externalUrl":null,"permalink":"/tags/netscaler/","section":"Tags","summary":"","title":"Netscaler","type":"tags"},{"content":"One of the biggest scams of the Internet is in full swing right now. You may have heard of it. It’s called “net neutrality.”\nFundamentally, net neutrality is about preventing Internet service providers (ISPs) from throttling or blocking traffic or providing paid prioritization of certain content. In addition, specific rules proposed by the FCC Chairman Tom Wheeler would allow the FCC to arbitrate peering disputes between carriers. Traditionally, carriers have connected each other’s networks with each other for a nominal cost or none at all. The idea being that the mutual benefit of using each other’s network for transit is payment enough. The proposed FCC rules, however, will turn this once amicable transaction into a litigious battleground that could result in the destabilization of the Internet’s backbone.\nI recall an article from a 1997 issue of Wired magazine which predicted the collapse of the Internet would be caused by increased growth without the infrastructure to support it. That never happened, in part due to technical innovation which kept up with growth, but also because ISPs and backbone carriers were able to throttle traffic during peak times to ensure everyone could have reasonably fast and reliable internet access. Now, almost 20 years later, we\u0026#8217;re looking at potential regulation that will micromanage how ISPs manage and build out their networks. As a network engineer, I understand the need to throttle or simply block certain types of traffic. But unfortunately, the technical facts have gotten lost amidst the raw politicization of the net neutrality debate. I recently saw a graphic put out by the pro-net neutrality group \u0026#8220;Battle for the Net\u0026#8221; that shows a picture of the United States Senate and a caption that asks, \u0026#8220;Does your state have the Internet\u0026#8217;s worst enemy?\u0026#8221; It then proceeds to list all the Senators that are supposedly trying to \u0026#8220;kill Net Neutrality.\u0026#8221; And this is the problem with the net neutrality movement. It\u0026#8217;s purely political and devoid of any thoughtful technical or practical discussion. Organizations like Battle for the Net don\u0026#8217;t bother to make a case for net neutrality. They assume that it is an absolute good and that being for the Internet means being for net neutrality. The discussion has devolved from a debate into a marketing battle plagued by word games and politics. Net neutrality advocates have adopted the language that this is “a battle for the Internet” and an effort to “keep the internet open.” Apparently, by breaking decades of precedent and giving the FCC more power to control what Internet service providers do, the Internet will somehow become better. The narrative they put forth is that the big bad cable companies with their zillions of dollars are trying to make end users’ Internet experience slow and expensive, and are fighting valiant efforts to “keep the internet free” (Nevermind the fact that the cable companies gave us broadband Internet and brought us out of the dial-up era to begin with.) This David versus Goliath theme is great for stirring emotions, but it falls flat in the face of a little bit of scrutiny. Google, whose income is more than double that of Comcast, is strongly in favor of “net neutrality” regulations. So is Netflix. And Facebook.\nRegardless of where you stand on net neutrality, one thing is certain: this is not about big money corporations versus the gentle folks of the Internet. It is about giant corporations duking it out for power, control, and government favor. As usual, the politics of net neutrality has turned the debate into more of a sporting event where everyone roots for his own team no matter what. But it’s actually worse than that. If you’re against net neutrality, some will perceive you as being anti-Internet or against Internet freedom. I find this both amusing and disturbing. Amusing, because the notion that giving the FCC unprecedented regulatory power over the Internet will somehow increase freedom to be absurd. And disturbing, because so many have blindly taken sides on this debate without an understanding of its implications or what it’s even about.\nOne such implication is privacy. How will the FCC ensure that ISPs are complying with the new regulations and not throttling or blocking certain types of traffic? The only way to know is by looking at the traffic, which can only be done with detailed logs of what an ISP’s users are doing. This goes beyond what websites you visited or how many gigabytes you downloaded. This gets down to individual connections. What IP address and port did you connect to? What protocol were you using? Certainly, these things can be logged now, and in fact probably are. But the difference is that, as of now, the FCC has no authority to demand such logs. With net neutrality regulations in place, they will, and they will also have the power to exact fines if ISPs fail to retain logs for a certain period of time. So, you will be able to BitTorrent without restriction, but Uncle Sam is probably going to know about it. Of course, this is already happening with the NSA pretty much spying on everything. But again, the difference is that instead of spying secretly, the collection of your Internet activity will be open and shameless. That may not bother you. Honestly, it doesn’t really bother me. The point is that net neutrality regulations come with some pretty long and tangled strings attached. And it’s wise to unravel them and see where they lead before throwing in your support for the wolf in sheep’s clothing.\n","date":"6 February 2015","externalUrl":null,"permalink":"/2015/02/net-neutrality-scam/","section":"Posts","summary":"","title":"Net Neutrality is a Scam","type":"post"},{"content":" BitTorrent # CentOS 6.5 for VirtualBox via bittorrent\nDropbox # CentOS 6.5 for VirtualBox via dropbox\n","date":"14 December 2014","externalUrl":null,"permalink":"/vagrant-boxes/","section":"Ben Piper","summary":"","title":"Vagrant Boxes","type":"page"},{"content":"","date":"13 December 2014","externalUrl":null,"permalink":"/tags/2014/","section":"Tags","summary":"","title":"2014","type":"tags"},{"content":"IT people often intentionally withhold knowledge from those outside of IT. There are different reasons for this — some good and some very bad.\nOne reason IT folks withhold knowledge is that they believe the best way to learn is to teach yourself. After all, that’s how many of them learned. Unlike many others in business, most IT folks didn’t attain their skills through traditional education. They were self-starters when it came to their own education and taught themselves much of what they know. Such an approach has served them well, so they believe it will serve others well also.\nWhile well-intentioned, this attitude is detrimental in business. Companies don’t hire IT people to mentor others to be like themselves. Rather, companies hire IT people to leverage their knowledge, skills, and expertise to achieve business objectives.\nContrast IT with the Legal department in this regard. People in Legal don’t withhold knowledge when asked. They are quick to “give the answer” and engage in discussion not only about Legal matters, but how those matters relate to the rest of the business. They aren’t threatened by sharing what they learned from their years in law school and real-world experience. But IT people often are reluctant, even averse to such self-exposure.\nThe reasons behind this apprehension when it comes to sharing knowledge aren’t important. It’s not your job to untrain this bad habit. What’s important is that the people you hire don’t try to hoard the “keys to the kingdom.” When you are interviewing candidates, make sure you find out whether a potential employee is willing to share his or her knowledge and expertise with others openly and candidly. If he’s not, politely show him the door.\nAn IT organization is only as good as the sum of its parts. Folks who hold tightly onto their knowledge like Frodo holding onto the One Ring are dragging your IT organization down and inhibiting the value it can provide. Don’t let that happen. Expect and demand open dialogue, widespread sharing, and consideration of the needs and objectives of the business. If IT can’t do that, it might as well not even be a part of the business.\n","date":"13 December 2014","externalUrl":null,"permalink":"/2014/12/knowledge-can-kill-value/","section":"Posts","summary":"","title":"How Knowledge Can Kill IT’s Value","type":"post"},{"content":"Where is SSMS 2012? # Microsoft decided to make it confusing and difficult to install SQL Server Management Studio (SSMS) 2012. Since my slogan is, “Business at the speed of light,” I’m going to to show you the quickest way I’ve found to install SSMS 2012.\nSSMS 2012 installation steps # Download and run SQLEXPRWT_x64_ENU.exe\nSelect “New SQL Server…”\nWait a while then click Next.\nWait some more, accept the license, and click Next\nMake sure the highlighted boxes are checked: Management Tools – Basic, Management Tools – Complete, and SQL Client Connectivity SDK. Click Next Finish the install\nLaunch SSMS 2012 and log in.\n","date":"11 December 2014","externalUrl":null,"permalink":"/2014/12/installing-sql-server-management-studio-ssms-2012/","section":"Posts","summary":"Where is SSMS 2012? # Microsoft decided to make it confusing and difficult to install SQL Server Management Studio (SSMS) 2012. Since my slogan is, “Business at the speed of light,” I’m going to to show you the quickest way I’ve found to install SSMS 2012.\n","title":"Installing SQL Server Management Studio (SSMS) 2012","type":"post"},{"content":"","date":"11 December 2014","externalUrl":null,"permalink":"/tags/sql/","section":"Tags","summary":"","title":"Sql","type":"tags"},{"content":"Recently I had an Oracle database server used by some developers that was running out of space on its data volume mounted at /u02. The volume was a simple MBR volume (think fdisk), so it couldn’t be non-destructively extended without using a third-party utility like gparted. That would have been fine, but rather than leave the volume as MBR, I decided to create a new iSCSI SAN-backed Logical Volume Manager (LVM) volume, which can be extended and resized pretty easily.\nIn this post, I’ll show you how to create a logical volume stored on an iSCSI SAN. Even though I did this on Red Hat Enterprise Linux 6.5 (RHEL), these steps should work on any distribution of Linux.\nCreating the LUN # First, you’ll need to create the LUN on the SAN. Depending on your organization, a storage administrator may have to do this. In my case, I administer the NetApp SANs (and almost everything else) so I just created a 151 GB LUN. When using LVM, I suggest sizing the LUN a little larger than your storage requirement, about 5-10% larger.\nCreating an Oracle LUN on a NetApp SAN The next step is to rescan the SAN to pick up the new LUN.\n[root@oracledb01 ~]# iscsiadm -m node -R Rescanning session [sid: 1, target: iqn.1992-08.com.netapp:sn.112133379, portal: 192.168.96.30,3260] If you don’t already have the SAN set as a target, you can add it with the command\niscsiadm -m node -T 192.168.96.30 , where 192.168.96.30 is the iSCSI IP of your SAN.\nNext, let’s find the new block device.\n[root@oracledb01 ~]# fdisk -l ... Disk /dev/sdc: 162.1 GB, 162143404032 bytes 255 heads, 63 sectors/track, 19712 cylinders Units = cylinders of 16065 * 512 = 8225280 bytes Sector size (logical/physical): 512 bytes / 512 bytes I/O size (minimum/optimal): 4096 bytes / 65536 bytes Disk identifier: 0x00000000 I’ve cut out some of the irrelevant output, but we can see the device is /dev/sdc. Let’s run fdisk against this device.\n[root@oracledb01 ~]# fdisk /dev/sdc Device contains neither a valid DOS partition table, nor Sun, SGI or OSF disklabel Building a new DOS disklabel with disk identifier 0xccf1891a. Changes will remain in memory only, until you decide to write them. After that, of course, the previous content won't be recoverable. Warning: invalid flag 0x0000 of partition table 4 will be corrected by w(rite) WARNING: DOS-compatible mode is deprecated. It's strongly recommended to switch off the mode (command 'c') and change display units to sectors (command 'u'). Command (m for help): p Disk /dev/sdc: 162.1 GB, 162143404032 bytes 255 heads, 63 sectors/track, 19712 cylinders Units = cylinders of 16065 * 512 = 8225280 bytes Sector size (logical/physical): 512 bytes / 512 bytes I/O size (minimum/optimal): 4096 bytes / 65536 bytes Disk identifier: 0xccf1891a Device Boot Start End Blocks Id System The ‘p’ (print) command should yield nothing since we haven’t created a partition table yet. Let’s create a new primary partition.\nCreating the Partition # Command (m for help): n Command action e extended p primary partition (1-4) p Partition number (1-4): 1 First cylinder (1-19712, default 1): Using default value 1 Last cylinder, +cylinders or +size{K,M,G} (1-19712, default 19712): Using default value 19712 Now that it’s created, we need to change the type to 8e which is Linux LVM.\nCommand (m for help): t Selected partition 1 Hex code (type L to list codes): L 0 Empty 24 NEC DOS 81 Minix / old Lin bf Solaris 1 FAT12 39 Plan 9 82 Linux swap / So c1 DRDOS/sec (FAT- 2 XENIX root 3c PartitionMagic 83 Linux c4 DRDOS/sec (FAT- 3 XENIX usr 40 Venix 80286 84 OS/2 hidden C: c6 DRDOS/sec (FAT- 4 FAT16 Now, print the partition table again to verify.\nCommand (m for help): p Disk /dev/sdc: 162.1 GB, 162143404032 bytes 255 heads, 63 sectors/track, 19712 cylinders Units = cylinders of 16065 * 512 = 8225280 bytes Sector size (logical/physical): 512 bytes / 512 bytes I/O size (minimum/optimal): 4096 bytes / 65536 bytes Disk identifier: 0xccf1891a Device Boot Start End Blocks Id System /dev/sdc1 1 19712 158336608+ 8e Linux LVM Partition 1 does not start on physical sector boundary. [amazon_link asins=’020178419X,B01C1TYTPE,1617293288′ template=’ProductCarousel’ store=’benpiperbloginline-20′ marketplace=’US’ link_id=’194723f3-f7c5-11e7-9a49-638a440dbdd7′]\nEverything looks good, so we’ll write it to disk.\nCommand (m for help): w The partition table has been altered! Calling ioctl() to re-read partition table. Syncing disks. The partition table is created.\nCreating the Physical Volume # Now it’s time to create the physical volume (PV) on /dev/sdc1. The physical volume is the link between the partition and the logical volume.\n[root@oracledb01 ~]# pvcreate /dev/sdc1 Physical volume \"/dev/sdc1\" successfully created Now let’s create the volume group (VG). The volume group is a container for logical volumes. We need to specify the volume group name and the physical volume.\n[root@oracledb01 ~]# vgcreate vg_oracle_u02 /dev/sdc1 Volume group \"vg_oracle_u02\" successfully created Finally, we need to create the logical volume (LV). We need to specify the volume group we want to store the new logical volume in, the size of the volume (150G), and the name of the logical volume.\n[root@oracledb01 ~]# lvcreate vg_oracle_u02 -L 150G -n lv_oracle_u02\nLogical volume “lv_oracle_u02” created\nNow let’s verify the size and get the path.\n[root@oracledb01 ~]# lvdisplay vg_oracle_u02 --- Logical volume --- LV Path /dev/vg_oracle_u02/lv_oracle_u02 LV Name lv_oracle_u02 VG Name vg_oracle_u02 LV UUID l54y1Z-l3w0-UDtn-STVu-m77T-sX0S-SzOBIK LV Write Access read/write LV Creation host, time oracledb01.benpiper.com, 2014-12-08 12:42:29 -0500 LV Status available # open 0 LV Size 150.00 GiB Current LE 38400 Segments 1 Allocation inherit Read ahead sectors auto - currently set to 256 Block device 253:3 Now let’s format the new volume as ext4.\n[root@oracledb01 ~]# mkfs.ext4 /dev/vg_oracle_u02/lv_oracle_u02 mke2fs 1.41.12 (17-May-2010) Discarding device blocks: done Filesystem label= OS type: Linux Block size=4096 (log=2) Fragment size=4096 (log=2) Stride=1 blocks, Stripe width=16 blocks 9830400 inodes, 39321600 blocks 1966080 blocks (5.00%) reserved for the super user First data block=0 Maximum filesystem blocks=4294967296 1200 block groups 32768 blocks per group, 32768 fragments per group 8192 inodes per group Superblock backups stored on blocks: 32768, 98304, 163840, 229376, 294912, 819200, 884736, 1605632, 2654208, 4096000, 7962624, 11239424, 20480000, 23887872 Writing inode tables: done Creating journal (32768 blocks): done Writing superblocks and filesystem accounting information: done This filesystem will be automatically checked every 38 mounts or 180 days, whichever comes first. Use tune2fs -c or -i to override. Now let’s create a mount point and mount the new volume.\nMounting the Volume # [root@oracledb01 ~]# mkdir /u02new [root@oracledb01 ~]# mount /dev/vg_oracle_u02/lv_oracle_u02 /u02new/ Now let’s verify the volume is mounted and has the expected amount of free space.\n[root@oracledb01 ~]# df /u02new/ -h Filesystem Size Used Avail Use% Mounted on /dev/mapper/vg_oracle_u02-lv_oracle_u02 148G 60M 140G 1% /u02new Looks good. And that’s it!\n","date":"8 December 2014","externalUrl":null,"permalink":"/2014/12/creating-linux-lvm-logical-volume-iscsi-san/","section":"Posts","summary":"Recently I had an Oracle database server used by some developers that was running out of space on its data volume mounted at /u02. The volume was a simple MBR volume (think fdisk), so it couldn’t be non-destructively extended without using a third-party utility like gparted. That would have been fine, but rather than leave the volume as MBR, I decided to create a new iSCSI SAN-backed Logical Volume Manager (LVM) volume, which can be extended and resized pretty easily.\nIn this post, I’ll show you how to create a logical volume stored on an iSCSI SAN. Even though I did this on Red Hat Enterprise Linux 6.5 (RHEL), these steps should work on any distribution of Linux.\n","title":"Creating a Linux LVM Logical Volume on an iSCSI SAN","type":"post"},{"content":"","date":"8 December 2014","externalUrl":null,"permalink":"/tags/iscsi/","section":"Tags","summary":"","title":"Iscsi","type":"tags"},{"content":"","date":"8 December 2014","externalUrl":null,"permalink":"/tags/lun/","section":"Tags","summary":"","title":"Lun","type":"tags"},{"content":"","date":"8 December 2014","externalUrl":null,"permalink":"/tags/netapp/","section":"Tags","summary":"","title":"Netapp","type":"tags"},{"content":"","date":"8 December 2014","externalUrl":null,"permalink":"/tags/san/","section":"Tags","summary":"","title":"San","type":"tags"},{"content":"","date":"8 December 2014","externalUrl":null,"permalink":"/tags/storage/","section":"Tags","summary":"","title":"Storage","type":"tags"},{"content":"In this demonstration, we’re going to configure a basic OpenStack cluster on RedHat/CentOS 6.5.\nHardware # We’ll need at least two servers: a controller node to host the various OpenStack services, and a compute node to run our virtual instances. I always like to start with the fundamentals and then add complexity incrementally, so we’ll start with just these two servers and utilize local storage. We can always add a SAN later.\nController node\n12 GB RAM, 146 GB\nCompute node\n32 GB RAM, 146 GB system, 294 GB local storage 192.168.1.211/24\nOperating System\nWe’ll be using RedHat Enterprise Linux 6.5 for everything. CentOS 6.5 will work too.\nNetworking\nWe need two subnets, one for management and OpenStack service communication, and another for the instances to use. The latter is analogous to an Amazon EC2 Virtual Private Cloud (VPC) subnet. We’ll call these the Instance and OpenStack networks, respectively.\nInstance Network – 192.168.2.208/28 OpenStack external 192.168.2.222 gw (for VMs)\nOpenStack Network – 192.168.1.0/24 OpenStack internal 192.168.1.8 gw\nController Node Setup # First, we’ll name the controller node osctl01 and give it an IP of 192.168.1.210/24.\nOpenStack services require a database. They don’t have to be on the same database, or even the same server, but for the sake of simplicity, we’ll use one MySQL server for everything. We also need NTP to ensure the time is synchronized.\nInstall MySQL server, NTP, and MySQL-python:\nyum -y install ntp mysql mysql-server MySQL-python If you don’t want to use the default NTP servers that ship with RedHat, configure /etc/ntp.conf and add a server directive to point to the server you want to receive time from.\nStart NTP and set it to start at boot:\nservice ntpd start chkconfig ntpd on If you’re using DNS, you can skip this step and just add the hosts to DNS. Otherwise, change /etc/hosts to add the controller and compute nodes for name resolution:\n192.168.1.210 osctl01 192.168.1.211 oscompute01 Configure mysql Add to /etc/my.cnf bind-address = 192.168.1.210 Start MySQL and set to start at boot:\nservice mysqld start chkconfig mysqld on Run the MySQL Secure Installation utility to disable test databases and change the root password. We’ll change the password to 0p3nR0ot!!\nmysql_secure_installation If you have a RedHat subscription and your system is registered, you can skip this step. Otherwise, install the Extra Packages for Enterprise Linux (EPEL) repository.\nyum install http://dl.fedoraproject.org/pub/epel/6/x86_64/epel-release-6-8.noarch.rpm Set up the OpenStack repo and install Openstack packages\nyum install http://repos.fedorapeople.org/repos/openstack/openstack-havana/rdo-release-havana-7.noarch.rpm yum install openstack-utils yum install openstack-selinux Ensure everything is up-to-date, then reboot.\nyum upgrade reboot Message Broker # We’re going to install the Apache qpid daemon. qpid is a messaging broker that the OpenStack services use to communicate with each other.\nyum -y install qpid-cpp-server memcached Qpid has some pretty advanced security features that can be configured for high-risk environments. Since we’re in a lab setting, we can just disable this:\nedit /etc/qpidd.conf and set auth=no Start the Qpid daemon (qpidd) and enable it:\nservice qpidd start chkconfig qpidd on Keystone Identity Service # Keystone is at the heart of OpenStack’s security (hence the name). Configuration can be a little unwieldy, so make use of copy-and-paste and type carefully!\nInstall Keystone:\nyum -y install openstack-keystone python-keystoneclient Configure Keystone to use a MySQL database:\nopenstack-config --set /etc/keystone/keystone.conf sql connection mysql://keystone:b973b5a7e8247adcb628@osctl01/keystone openstack-db --init --service keystone --password b973b5a7e8247adcb628 We need to create an admin token which will allow us to initially authenticate to OpenStack. Note that when you echo the $ADMIN_TOKEN variable, you will get a different result because it’s just a random hex string generated by OpenSSL.\nADMIN_TOKEN=$(openssl rand -hex 10) echo $ADMIN_TOKEN 0cda5342682b495ecf9e openstack-config --set /etc/keystone/keystone.conf DEFAULT admin_token $ADMIN_TOKEN Now we need to generate SSL certificates. The OpenStack folks recommend using a certificate issued by a certification authority (CA), but for our lab this will do just fine:\nkeystone-manage pki_setup --keystone-user keystone --keystone-group keystone chown -R keystone:keystone /etc/keystone/* /var/log/keystone/keystone.log Start and enable the Keystone service:\nservice openstack-keystone start chkconfig openstack-keystone on Adding Tenants # Remember the admin token we created just a couple steps ago? We need to use that now to authenticate to Keystone so we can finish configuring it.\nSet the OS_SERVICE_TOKEN environment variable to the same value as the admin token from earlier.\nexport OS_SERVICE_TOKEN=0cda5342682b495ecf9e Set the OS_SERVICE_ENDPOINT variable. The format is “http://[servername]:35357/v2.0”:\nexport OS_SERVICE_ENDPOINT=http://osctl01:35357/v2.0 Keystone tenants are simply containers that hold users. These are sometimes represented as “projects” as you’ll see later after we install the OpenStack dashboard.\nLet’s create an admin tenant for our administrator user:\nkeystone tenant-create --name=admin --description=\"Admin Tenant\" +-------------+----------------------------------+ | Property | Value | +-------------+----------------------------------+ | description | Admin Tenant | | enabled | True | | id | ffea20d6a4ae483bb62a46c8246d1a1b | | name | admin | +-------------+----------------------------------+ Now let’s create a service tenant:\nkeystone tenant-create --name=service --description=\"Service Tenant\" +-------------+----------------------------------+ | Property | Value | +-------------+----------------------------------+ | description | Service Tenant | | enabled | True | | id | 3fd349e09927432f95fbd00cc8534744 | | name | service | +-------------+----------------------------------+ Adding Users and Roles\nNow we need to do three things: create the admin user, create the admin role, and then add them to the admin tenant container. Make a note of the username and password because you’ll need it later to login.\nkeystone user-create --name=admin --pass=s7@ck@dmyn20 --email=alerts@benpiper.com keystone role-create --name=admin keystone user-role-add --user=admin --tenant=admin --role=admin Keystone Service and API Endpoint\nEven though we’ve done a lot of configuration, one thing we have not yet done is created the Keystone service. Let’s do that now:\nkeystone service-create --name=keystone --type=identity --description=\"Keystone Identity Service\" +-------------+----------------------------------+ | Property | Value | +-------------+----------------------------------+ | description | Keystone Identity Service | | id | 61f9e9edba4141ca8395fd116a038315 | | name | keystone | | type | identity | +-------------+----------------------------------+ Other OpenStack services authenticate to the Keystone service using an endpoint API. Let’s create an endpoint and link it to the service. Note the service-id matches the id from the last step. The publicurl and internalurl format is “http://[servername]:5000/v2.0”. The value of adminurl is the same as the OS_SERVICE_ENDPOINT variable from earlier.\nkeystone endpoint-create --service-id=61f9e9edba4141ca8395fd116a038315 --publicurl=http://osctl01:5000/v2.0 --internalurl=http://osctl01:5000/v2.0 --adminurl=http://osctl01:35357/v2.0 +-------------+----------------------------------+ | Property | Value | +-------------+----------------------------------+ | adminurl | http://osctl01:35357/v2.0 | | id | a88018578c724b36903d6b3913c302fc | | internalurl | http://osctl01:5000/v2.0 | | publicurl | http://osctl01:5000/v2.0 | | region | regionOne | | service_id | 61f9e9edba4141ca8395fd116a038315 | +-------------+----------------------------------+ Verify\nNow we’re ready to check our work. First, we need to unset the variables we set at the beginning. That way we know we’re not cheating.\nunset OS_SERVICE_TOKEN OS_SERVICE_ENDPOINT Now run the following commands to fetch two tokens. The tokens should be long strings. If you see long strings, it means Keystone authentication is working as expected:\nkeystone --os-username=admin --os-password=s7@ck@dmyn20 --os-auth-url=http://osctl01:35357/v2.0 token-get keystone --os-username=admin --os-password=s7@ck@dmyn20 --os-tenant-name=admin --os-auth-url=http://osctl01:35357/v2.0 token-get Administering Keystone\nAt this point, you have to authenticate to Keystone before you can manage it. What we saw in the last step is an example of this. Of course, having to tack the admin username, password, tenant name, and URL onto every command isn’t gonna fly. We can avoid this by setting some environment variables. These can be incorporated into a Linux user’s bashrc or just set ad hoc:\nexport OS_USERNAME=admin export OS_PASSWORD=s7@ck@dmyn20 export OS_TENANT_NAME=admin export OS_AUTH_URL=http://osctl01:35357/v2.0 Glance Image Service # Glance is the service that manages instance images. An image is just a binary file with a pre-configured operating system like Ubuntu, CoreOS, or Windows. Why are we installing Glance on the controller node and not the compute node? Well, in a production environment, the other OpenStack services are generally separated from the Nova service on the compute node. Having images stored on one server and the instances running on another creates an interesting dynamic, because you end up streaming the images across the network. Learning to troubleshoot the problems that may arise doing that is a great skill to hone in the lab before trying to implement OpenStack in production.\nInstalling Glance\nyum -y install openstack-glance The following commands modify the glance-api.conf and glance-registry.conf files to point to the MySQL server. The “glance” in “mysql://glance…” stanza is the username, and the string after the colon is the password. The glance user and password don’t exist in MySQL yet. We’ll create that in the next step.\nopenstack-config --set /etc/glance/glance-api.conf DEFAULT sql_connection mysql://glance:8bc00a75df06c01fa106@osctl01/glance openstack-config --set /etc/glance/glance-registry.conf DEFAULT sql_connection mysql://glance:8bc00a75df06c01fa106@osctl01/glance I told you we’d create them:)\nopenstack-db --init --service glance --password 8bc00a75df06c01fa106 Now we need to create a glance user in Keystone. Let’s give this one a different password, not just because it’s good security, but because it will help us distinguish the glance Keystone user from the glance MySQL user:\nkeystone user-create --name=glance --pass=7a9915b6b5f5b6784cf4 --email=alerts@benpiper.com Add the new glance user to the service tenant container and admin role.\nkeystone user-role-add --user=glance --tenant=service --role=admin Now we need to tell Glance about the Keystone endpoint. Glance can actually can talk to the database through two different paths, the API or the registry. Leaving out the details, let’s configure both:\nopenstack-config --set /etc/glance/glance-api.conf keystone_authtoken auth_uri http://osctl01:5000 openstack-config --set /etc/glance/glance-api.conf keystone_authtoken auth_host osctl01 openstack-config --set /etc/glance/glance-api.conf keystone_authtoken admin_tenant_name service openstack-config --set /etc/glance/glance-api.conf keystone_authtoken admin_user glance openstack-config --set /etc/glance/glance-api.conf keystone_authtoken admin_password 7a9915b6b5f5b6784cf4 openstack-config --set /etc/glance/glance-api.conf paste_deploy flavor keystone openstack-config --set /etc/glance/glance-registry.conf auth_uri http://osctl01:5000 openstack-config --set /etc/glance/glance-registry.conf keystone_authtoken auth_host osctl01 openstack-config --set /etc/glance/glance-registry.conf keystone_authtoken admin_tenant_name service openstack-config --set /etc/glance/glance-registry.conf keystone_authtoken admin_user glance openstack-config --set /etc/glance/glance-registry.conf keystone_authtoken admin_password 7a9915b6b5f5b6784cf4 openstack-config --set /etc/glance/glance-registry.conf paste_deploy flavor keystone Modify the /etc/glance/glance-api-paste.ini and glance-registry-paste.ini files to add the following, changing parameters as needed:\nauth_host=osctl01 admin_user=glance admin_tenant_name=service admin_password=7a9915b6b5f5b6784cf4 keystone service-create --name=glance --type=image --description=\"Glance Image Service\" keystone endpoint-create --service-id=718aeb6749554deaa2bf7d8421fe95a3 --publicurl=http://osctl01:9292 --internalurl=http://osctl01:9292 --adminurl=http://osctl01:9292 Start the Glance API and registry services and enable both:\nservice openstack-glance-api start service openstack-glance-registry start chkconfig openstack-glance-api on chkconfig openstack-glance-registry on Creating an Image # Now, if you don’t have a /var/lib/glance/images directory, now is the time to create it. If you’re feeling adventurous and want to use a SAN for image storage, you can create a mount point here. Make sure the glance user has +rw permissions to /var/lib/glance/images.\nWe’ll grab the CirrOS image which is a small image used for testing cloud deployments.\nwget http://cdn.download.cirros-cloud.net/0.3.1/cirros-0.3.1-x86_64-disk.img Add the image to Glance:\nglance image-create --name=cirros-0.3.1 --disk-format=qcow2 --container-format=bare --is-public=true \u0026lt; cirros-0.3.1-x86_64-disk.img +------------------+--------------------------------------+ | Property | Value | +------------------+--------------------------------------+ | checksum | d972013792949d0d3ba628fbe8685bce | | container_format | bare | | created_at | 2014-07-25T20:31:47 | | deleted | False | | deleted_at | None | | disk_format | qcow2 | | id | 0c71c5bb-51cd-4afe-880f-6c616b89bfcb | | is_public | True | | min_disk | 0 | | min_ram | 0 | | name | cirros-0.3.1 | | owner | ffea20d6a4ae483bb62a46c8246d1a1b | | protected | False | | size | 13147648 | | status | active | | updated_at | 2014-07-25T20:31:48 | +------------------+--------------------------------------+ Compute Node Setup # The compute node needs two network interfaces.\nOpenStack Network – oscompute01 192.168.1.211/24 internal eth2\nInstance Network – 192.168.2.211/28 external eth3\nRemember to modify the hosts file on the compute node if you’re not using DNS.\nOn the compute node, we’re going to install the Nova service. Nova manages the compute resources. It’s what actually provisions the individual instances.\nInstall NTP and the MySQL client:\nyum -y install ntp mysql MySQL-python Configure NTP if necessary, start it, and enable it.\nInstall Nova:\nyum -y install openstack-nova-compute openstack-nova python-novaclient Configure Nova to use Keystone:\nopenstack-config --set /etc/nova/nova.conf DEFAULT auth_strategy keystone openstack-config --set /etc/nova/nova.conf keystone_authtoken auth_host osctl01 openstack-config --set /etc/nova/nova.conf keystone_authtoken auth_protocol http openstack-config --set /etc/nova/nova.conf keystone_authtoken auth_port 35357 openstack-config --set /etc/nova/nova.conf keystone_authtoken admin_user nova openstack-config --set /etc/nova/nova.conf keystone_authtoken admin_tenant_name service openstack-config --set /etc/nova/nova.conf keystone_authtoken admin_password 6a7d44ef52d1fe0848fb Configure Nova to use Qpid:\nopenstack-config --set /etc/nova/nova.conf DEFAULT rpc_backend nova.openstack.common.rpc.impl_qpid openstack-config --set /etc/nova/nova.conf DEFAULT qpid_hostname osctl01 Enable VNC so we can VNC to our instances:\nopenstack-config --set /etc/nova/nova.conf DEFAULT my_ip 192.168.1.211 openstack-config --set /etc/nova/nova.conf DEFAULT vnc_enabled True openstack-config --set /etc/nova/nova.conf DEFAULT vncserver_listen 0.0.0.0 openstack-config --set /etc/nova/nova.conf DEFAULT vncserver_proxyclient_address 192.168.1.211 openstack-config --set /etc/nova/nova.conf DEFAULT novncproxy_base_url http://osctl01:6080/vnc_auto.html Set the default Glance host:\nopenstack-config --set /etc/nova/nova.conf DEFAULT glance_host osctl01 KVM is the hypervisor we’ll use to launch our instances. Let’s enable it now:\nchkconfig libvirtd on Enable the messagebus and openstack-nova-compute services:\nchkconfig messagebus on chkconfig openstack-nova-compute on Configure Nova to use MySQL and Qpid:\nopenstack-config --set /etc/nova/nova.conf database connection mysql://nova:530c8af9db415ff16819@osctl01/nova openstack-config --set /etc/nova/nova.conf DEFAULT rpc_backend nova.openstack.common.rpc.impl_qpid openstack-config --set /etc/nova/nova.conf DEFAULT qpid_hostname osctl01 openstack-db --init --service nova --password 530c8af9db415ff16819 Create the nova user in Keystone and add to the service tenant container:\nkeystone user-create --name=nova --pass=6a7d44ef52d1fe0848fb --email=alerts@benpiper.com keystone user-role-add --user=nova --tenant=service --role=admin Configure Nova to use Keystone:\nopenstack-config --set /etc/nova/nova.conf DEFAULT auth_strategy keystone openstack-config --set /etc/nova/nova.conf keystone_authtoken auth_host osctl01 openstack-config --set /etc/nova/nova.conf keystone_authtoken auth_protocol http openstack-config --set /etc/nova/nova.conf keystone_authtoken auth_port 35357 openstack-config --set /etc/nova/nova.conf keystone_authtoken admin_user nova openstack-config --set /etc/nova/nova.conf keystone_authtoken admin_tenant_name service openstack-config --set /etc/nova/nova.conf keystone_authtoken admin_password 6a7d44ef52d1fe0848fb Modify /etc/nova/api-paste.ini as follows:\nauth_host = osctl01 auth_port = 35357 auth_protcol = http auth_uri = http://osctl01:5000/v2.0 admin_tenant_name = service admin_user = nova admin_password = 6a7d44ef52d1fe0848fb Make sure /etc/nova/nova.cfg has the directive api_paste_config=/etc/nova/api-paste.ini\nCreate the nova service in Keystone:\nkeystone service-create --name=nova --type=compute --description=\"Nova Compute service\" +-------------+----------------------------------+ | Property | Value | +-------------+----------------------------------+ | description | Nova Compute service | | id | 4624b2b75a6b475895412a2149999001 | | name | nova | | type | compute | +-------------+----------------------------------+ Register the Nova endpoint with Keystone:\nkeystone endpoint-create --service-id=4624b2b75a6b475895412a2149999001 --publicurl=http://osctl01:8774/v2/%\\(tenant_id\\)s --internalurl=http://osctl01:8774/v2/%\\(tenant_id\\)s --adminurl=http://osctl01:8774/v2/%\\(tenant_id\\)s +-------------+----------------------------------------+ | Property | Value | +-------------+----------------------------------------+ | adminurl | http://osctl01:8774/v2/%(tenant_id)s | | id | e92f90f26d504e699fb4df2c5291f967 | | internalurl | http://osctl01:8774/v2/%(tenant_id)s | | publicurl | http://osctl01:8774/v2/%(tenant_id)s | | region | regionOne | | service_id | 4624b2b75a6b475895412a2149999001 | +-------------+----------------------------------------+ Enable everything:\nchkconfig openstack-nova-api on chkconfig openstack-nova-cert on chkconfig openstack-nova-consoleauth on chkconfig openstack-nova-scheduler on chkconfig openstack-nova-conductor on chkconfig openstack-nova-novncproxy on Networking # The legacy architecture OpenStack used for provisioning networks for instances is called Nova Network. It has been phased out and replaced by Neutron, but we’re going to use Nova Network because it’s simple and does the job for a lab environment. Just don’t use it in production.\nInstall Nova Network\nyum -y install openstack-nova-network We want to set up a flat network, which means one subnet that all our instances will share. Since our instance subnet is 192.168.2.208 subnet has a 28 bit netmask, we have 14 usable host addresses.\nopenstack-config --set /etc/nova/nova.conf DEFAULT network_manager nova.network.manager.FlatDHCPManager openstack-config --set /etc/nova/nova.conf DEFAULT firewall_driver nova.virt.libvirt.firewall.IptablesFirewallDriver openstack-config --set /etc/nova/nova.conf DEFAULT network_size 14 openstack-config --set /etc/nova/nova.conf DEFAULT allow_same_net_traffic False openstack-config --set /etc/nova/nova.conf DEFAULT multi_host True openstack-config --set /etc/nova/nova.conf DEFAULT send_arp_for_ha True openstack-config --set /etc/nova/nova.conf DEFAULT share_dhcp_address True openstack-config --set /etc/nova/nova.conf DEFAULT force_dhcp_release True openstack-config --set /etc/nova/nova.conf DEFAULT flat_interface eth3 openstack-config --set /etc/nova/nova.conf DEFAULT flat_network_bridge br100 openstack-config --set /etc/nova/nova.conf DEFAULT public_interface eth3 Now let’s install the Nova API, start it, and enable it:\nyum -y install openstack-nova-api chkconfig openstack-nova-metadata-api on chkconfig openstack-nova-network on Let’s create a network (similar to an EC2 VPC) that the instances will use:\nnova network-create vmnet --fixed-range-v4=192.168.2.208/28 --bridge=br100 --multi-host=T Now let’s create a public-private keypair:\nssh-keygen Add the keypair to Nova:\nnova keypair-add --pub_key id_rsa.pub mykey Add rules to allow ICMP and SSH to the instances:\nnova secgroup-add-rule default tcp 22 22 0.0.0.0/0 nova secgroup-add-rule default icmp -1 -1 0.0.0.0/0 And finally, let’s boot up the CirrOS image:\nnova boot --flavor 2 --key_name mykey --image 0c71c5bb-51cd-4afe-880f-6c616b89bfcb --security_group default cirrOS +--------------------------------------+-----------------------------------------------------+ | Property | Value | +--------------------------------------+-----------------------------------------------------+ | OS-DCF:diskConfig | MANUAL | | OS-EXT-AZ:availability_zone | nova | | OS-EXT-SRV-ATTR:host | - | | OS-EXT-SRV-ATTR:hypervisor_hostname | - | | OS-EXT-SRV-ATTR:instance_name | instance-00000001 | | OS-EXT-STS:power_state | 0 | | OS-EXT-STS:task_state | scheduling | | OS-EXT-STS:vm_state | building | | OS-SRV-USG:launched_at | - | | OS-SRV-USG:terminated_at | - | | accessIPv4 | | | accessIPv6 | | | adminPass | y4LrfrH8oW4h | | config_drive | | | created | 2014-07-27T06:05:01Z | | flavor | m1.small (2) | | hostId | | | id | 08513282-e861-4f85-b31f-deddc865e7f2 | | image | cirros-0.3.1 (0c71c5bb-51cd-4afe-880f-6c616b89bfcb) | | key_name | mykey | | metadata | {} | | name | cirrOS | | os-extended-volumes:volumes_attached | [] | | progress | 0 | | security_groups | default | | status | BUILD | | tenant_id | ffea20d6a4ae483bb62a46c8246d1a1b | | updated | 2014-07-27T06:05:01Z | | user_id | 7538cee43aa8428bbb26c9ab28a2adca | +--------------------------------------+-----------------------------------------------------+ Once it’s built, we can SSH to the IP address. Congratulations! You’ve launched your very first instance on OpenStack!\n","date":"5 December 2014","externalUrl":null,"permalink":"/2014/12/configuring-openstack-havana-lab-step-step/","section":"Posts","summary":"In this demonstration, we’re going to configure a basic OpenStack cluster on RedHat/CentOS 6.5.\n","title":"Configuring an OpenStack Havana Lab Step-by-step","type":"post"},{"content":"webdock is a virtual machine (OVF) that uses Docker to spin up multiple web servers for testing NetScaler load-balancing. Designed for my course Citrix NetScaler 10: Design and Deployment. If you\u0026rsquo;d like to download webdock, please email me.\n","date":"16 October 2014","externalUrl":null,"permalink":"/webdock/","section":"Ben Piper","summary":"","title":"Download webdock","type":"page"},{"content":"","date":"28 July 2014","externalUrl":null,"permalink":"/tags/cifs/","section":"Tags","summary":"","title":"Cifs","type":"tags"},{"content":"Recently I needed to build a multipurpose file server to host CIFS and NFS shares — CIFS for the Windows users, and NFS for VMWare to store ISOs. It needed to utilize back end storage (NetApp via iSCSI), provide Windows ACLs for the CIFS shares, and be able to authenticate against two different Active Directory domains. After careful consideration, I decided to use Red Hat Enterprise Linux 6.5 (RHEL) instead of Windows Server 2012.\nNow you might be wondering, “Why on earth would you want to build a Linux file server to do all that when you can just use Windows?” There are a few reasons:\nResources – Linux has a much, much smaller footprint than even a Server Core install of Windows Server 2012. If you’re building a file server for a branch office with limited server resources, this can be a big deal.\nSecurity – Yes, Red Hat Linux really is more secure out-of-the-box than Windows, plus it’s less of a target — at least for now.\nCost… maybe – The cost of Linux vs. Windows is a funny thing. Obviously, Linux is free and Windows isn’t. But if you purchase enterprise Linux support from, say, Red Hat, the cost comes out nominally less for Linux. On the other hand, if your organization doesn’t require enterprise-level support on every server, building redundant Linux file servers is free. The cost is ultimately dependent upon the level of support needed.\nIn this post I’m going to show you how I built a fully-functional, Active Directory-friendly Linux file server in less than half-a-day.\nInstall Red Hat # The first step, of course, is to install Linux. I created a VMWare virtual machine with 4GB RAM and 1 vCPU. Having decided to go with RHEL 6.5, I first created a Kickstart script with the following packages:\n@base\n@console-internet\n@network-tools\n@core\n@directory-client\n@internet-browser\n@large-systems\n@network-file-system-client\n@performance\n@server-platform\n(Kickstart is the name of Red Hat’s automated installation method. If you don’t want to use Kickstart, you can just install RHEL 6.5 the old fashioned way and select the above package groups when prompted)\nI placed the Kickstart file and the Red Hat installation files on an FTP server, booted the RHEL ISO, and pointed the bootloader to the Kickstart file as shown here:\nSetup the Red Hat Repositories # After the installation is complete, you’ll need to ensure yum, Red Hat’s package installer, knows where to find the Red Hat installation files as you be installing more things shortly. Log in as root and edit the file /etc/yum.repos.d/rhel-source.repo. Add the text enclosed in the yellow rectangle below, changing the path as necessary to suit your environment, then save it.\nIn the example above, I’m logging into the FTP server at 192.168.1.11 with the username and password “redhat”. Alternatively, you can just mount the Red Hat ISO into /media with the command\nmount -o loop /dev/cdrom /media and point the baseurl path to file:///media.\nBecome Active Directory friendly # Now we’re going to install Samba4, Winbind, Kerberos, NTP, and NFS.\nyum -y install samba4 samba4-client samba4-winbind krb5-workstation ntp nfs Configure your NTP servers (typically your AD domain controllers) in /etc/ntp.conf, start the NTP daemon, and set it to start at bootup.\nchkconfig ntpd service ntpd start Next, since we’ll be dealing with the ever-picky Active Directory, we’ll need to ensure DNS is configured properly. Modify /etc/resolv.conf to add your DNS servers and any DNS suffixes you want Linux to search when it tries to look up a non-fully qualified domain name (For example, if I try to ping webserver01, I want Linux to perform a DNS lookup for webserv01.benpiper.com, so I’d add the suffix benpiper.com to the search space.)\nNow configure /etc/hosts and put this server’s fully-qualified domain name (FQDN) right after 127.0.0.1.\nConfigure Samba to use Winbind, Kerberos, and NTFS ACLs # Next we need to modify /etc/samba/smb.conf. Under the [config] section we need to add or change the following lines:\nworkgroup = BENPIPER server string = FILE SERVER SAMBA V %v netbios name = DCASFIS01 security = ADS realm = BENPIPER.COM encrypt passwords = yes winbind trusted domains only = no winbind use default domain = yes winbind enum users = yes winbind enum groups = yes idmap uid = 15000-20000 idmap gid = 15000-20000 vfs objects = acl_xattr map acl inherit = Yes nt acl support = yes store dos attributes = Yes A little explanation is in order. The workgroup directive is the NetBIOS name of the domain the server is going to join.\nnetbios name is the NetBIOS name of the server that’s going to be joining the domain.\nrealm is the Kerberos realm which we are going to specify when we configure Kerberos. A common misconception is that the Kereros realm is just the FQDN of the domain. Even though we’ll be using the FQDN for clarity, this could actually be any value we want, as long as it matches what we specify later on /etc/krb5.conf.\nnt acl support = yes tells Samba to store NTFS Access Control Lists (ACLs) as Linux File Access Control Lists.\nIntegrate with Active Directory # Join the domain. Be sure to replace \u0026lt;em\u0026gt;domainadmin\u0026lt;/em\u0026gt; with an actual domain adminsitrator.\nnet ads join -U domainadmin Samba’s name service switch module sits in the 32-bit /usr/local.samba/lib directory by default. Samba running on our 64-bit system is not going to look there, so we’ll need to create a symbolic link to the /lib64 directory.\nln -s /usr/local/samba/lib/libnss_winbind.so /lib64 ldconfig Add the following to /etc/nsswitch.conf\npasswd: compat winbind group: compat winbind Modify /etc/krb5.conf as follows.\n[logging] default = FILE:/var/log/krb5libs.log kdc = FILE:/var/log/krb5kdc.log admin_server = FILE:/var/log/kadmind.log [libdefaults] default_realm = BENPIPER.COM dns_lookup_realm = true dns_lookup_kdc = true ticket_lifetime = 24h renew_lifetime = 7d forwardable = true [realms] BENPIPER.COM = { } SECONDARYDOMAIN.COM = { } [domain_realm] .benpiper.com = BENPIPER.COM benpiper.com = BENPIPER.COM .secondarydomain.com = SECONDARYDOMAIN.COM secondarydomain.com = SECONDARYDOMAIN.COM Start winbind, smb, and nmb.\nservice winbind start service smb start service nmb start chkconfig winbind on chkconfig smb on chkconfig nmb on Create a test CIFS share # Now we’re ready to test whether CIFS sharing actually works. Create a test folder to share via CIFS.\nmkdir /var/lib/samba/testshare Grant rwx permissions to the directory owner and group.\nchmod 770 /var/lib/samba/testshare/ Give ownership to user “root” and Active Directory group BENPIPER\\file server admins. This will ensure both “root” and members of the “file server admins” group can modify ACLs. Note that\nchown root:\u0026#34;BENPIPER\\file server admins\u0026#34; /var/lib/samba/testshare/ Modify the ACL to grant the BENPIPER\\file server admins AD group read, write, and execute access to the new folder.\nsetfacl -m g:\u0026#34;BENPIPER\\file server admins\u0026#34;:rwx /var/lib/samba/testshare/ setfacl -m g::--- /var/lib/samba/testshare Now try to access the share from a Windows machine. If you are a member of the BENPIPER\\file server admins group, you should be able to modify ACLs directly from Windows Explorer.\niSCSI setup # If you’re not going to be using shared storage, you can skip this section. Here we’re going to configure an iSCSI connection to our NetApp SAN. We’ve already created a 200 GB LUN and made it available to the iQN initiator name that we’ll set in just a moment.\nFirst, install the iSCSI initiator utilities.\nyum -y install iscsi-initiator-utils Change the initiator name in /etc/iscsi/initiatorname.iscsi to whatever you want. I usually use the hostname for the storage identifier (for example, iqn.1994-05.com.benpiper:dcasfis01)\nIf you don’t want iSCSI traffic to ride over a separate NIC, skip this step. Assuming iSCSI traffic will use eth1, modify /var/lib/iscsi/ifaces/iface.eth1 as follows:\niface.transport_name = tcp iface.iscsi_ifacename = eth1 Run discovery against the NetApp SAN with IP 192.168.59.31 and login.\niscsiadm -m discovery -t st -p 192.168.59.31 iscsiadm -m node -l Now verify. You should see the IP addresses, ports, and iQN of the SAN.\n# iscsiadm -m node 192.168.59.31:3260,2001 iqn.1992-08.com.netapp:sn.437593081 192.168.60.31:3260,2001 iqn.1992-08.com.netapp:sn.437593081 Rescan the session to pick up the LUNs.\niscsiadm -m node -R Verify the new storage is there. Note the name of the disk (/dev/sdb).\n# fdisk -l ... Disk /dev/sdb: 214.7 GB, 214748364800 bytes 255 heads, 63 sectors/track, 26108 cylinders Units = cylinders of 16065 * 512 = 8225280 bytes Sector size (logical/physical): 512 bytes / 512 bytes I/O size (minimum/optimal): 4096 bytes / 65536 bytes Disk identifier: 0x00000000 ... Create an LVM Volume # We’re going to use the Linux Logical Volume Manager (LVM) to partition the block storage. The advantage of using LVM over using fdisk to create MBR partitions is that resizing LVM volumes is much easier. If you don’t know your storage requirements up front, you can create relatively small logical volumes and leave the rest of the disk unallocated. When you have a better idea of what size the volumes should be (like when you run out of space), you can non-destructively resize them.\nCreating an initial LVM volume requires a few steps. We’ll still have to use fdisk to create a primary partition, but instead of creating it as ext4 partition type, we’ll select Linux LVM (type 8e). Then we’ll create a physical LVM volume on the partition, followed by a logical volume group, and finally a logical volume.\nCreate a primary partition for the Linux Logical Volume Manager (LVM).\n# fdisk /dev/sdb WARNING: DOS-compatible mode is deprecated. It`s strongly recommended to switch off the mode (command \u0026#39;c\u0026#39;) and change display units to sectors (command \u0026#39;u\u0026#39;). Command (m for help): n Command action e extended p primary partition (1-4) p Partition number (1-4): 1 First cylinder (1-26108, default 1): Using default value 1 Last cylinder, +cylinders or +size{K,M,G} (1-26108, default 26108): Using default value 26108 Command (m for help): t Selected partition 1 Hex code (type L to list codes): 8e Changed system type of partition 1 to 8e (Linux LVM) Command (m for help): w The partition table has been altered! Calling ioctl() to re-read partition table. Syncing disks. Create the LVM physical volume on /dev/sdb1\n# pvcreate /dev/sdb1 Physical volume \u0026#34;/dev/sdb1\u0026#34; successfully created Create a volume group called volgroup1\n# vgcreate volgroup1 /dev/sdb1 Volume group \u0026#34;volgroup1\u0026#34; successfully created Now we’ll create a small 40GB volume for ISO storage. LVM sizes volumes based on the number of extents. When we created the logical volume group we didn’t select an extent size, so it used the default which is 4MB. The size of the logical volume must be an integer multiple of the extent size. Since we’re creating a 40GB volume and the extent size is 4MB, we’ll specify 10240 extents (40960MB / 4MB).\n# lvcreate -l 10240 -n ISO volgroup1 Logical volume \u0026#34;ISO\u0026#34; created Verify the new volume information is correct. Note the path of the new volume as this is what we’re going to be formatting.\n# lvdisplay --- Logical volume --- LV Path /dev/volgroup1/ISO LV Name ISO VG Name volgroup1 LV UUID apui74-26k5-AcWK-VtaF-UTbY-DuKp-QsCXf1 LV Write Access read/write LV Creation host, time dcasfis01.benpiper.com, 2014-07-07 00:00:00 -0000 LV Status available # open 0 LV Size 40.00 GiB Current LE 10240 Segments 1 Allocation inherit Read ahead sectors auto - currently set to 256 Block device 253:4 Create an ext3 filesystem.\n# mkfs.ext3 /dev/volgroup1/ISO mke2fs 1.41.12 (17-May-2010) Discarding device blocks: done Filesystem label= OS type: Linux Block size=4096 (log=2) Fragment size=4096 (log=2) Stride=1 blocks, Stripe width=16 blocks 2621440 inodes, 10485760 blocks 524288 blocks (5.00%) reserved for the super user First data block=0 Maximum filesystem blocks=4294967296 320 block groups 32768 blocks per group, 32768 fragments per group 8192 inodes per group Superblock backups stored on blocks: 32768, 98304, 163840, 229376, 294912, 819200, 884736, 1605632, 2654208, 4096000, 7962624 Writing inode tables: done Creating journal (32768 blocks): done Writing superblocks and filesystem accounting information: done This filesystem will be automatically checked every 33 mounts or 180 days, whichever comes first. Use tune2fs -c or -i to override. By default, Samba looks for shares in the /var/lib/samba folder, so we’ll create mount point for for our new ISO volume and then mount it there.\nmkdir /var/lib/samba/iso mount /dev/volgroup1/ISO /var/lib/samba/iso In order to ensure that the volume is mounted when the system reboots, we need to add the volume’s UUID to /etc/fstab.\n# blkid /dev/volgroup1/ISO /dev/volgroup1/ISO: UUID=\u0026#34;a8c77eb9-422a-4d8c-bec6-46cc811dc535\u0026#34; SEC_TYPE=\u0026#34;ext2\u0026#34; TYPE=\u0026#34;ext3\u0026#34; Add the above UUID to /etc/fstab:\nUUID=a8c77eb9-422a-4d8c-bec6-46cc811dc535 /var/lib/samba/iso ext3 _netdev,acl 0 0 The _netdev directive indicates that this is an iSCSI-bound volume, and the acl directive indicates that the filesystem should be mounted with ACL support.\nNow we’re ready to create a CIFS share for the new volume. Edit /etc/samba/smb.conf as follows:\n[iso] comment = ISO share browseable = yes writable = yes path = /var/lib/samba/iso inherit acls = yes inherit permissions = yes Reload the Samba config to apply the changes.\nsmbcontrol smbd reload-config Set the permissions on the new share to make root the user owner and BENPIPER\\file server admins the group owner. Add BENPIPER\\file server admins to the ACL and grant rwx access.\nchmod 770 /var/lib/samba/iso/ chown root:\u0026#34;BENPIPER\\file server admins\u0026#34; /var/lib/samba/iso/ setfacl -m g:\u0026#34;BENPIPER\\file server admins\u0026#34;:rwx /var/lib/samba/iso/ setfacl -m g::--- /var/lib/samba/iso/ Now it’s time to test. Go to a Windows machine and browse to the new share.\nIt works! But before we get too excited, let’s reboot. When the system comes back up, verify that the volume is still mounted in the right location.\n# df -h Filesystem Size Used Avail Use% Mounted on /dev/mapper/vg_dcasfis01-root 18G 1.5G 15G 10% / tmpfs 1.9G 0 1.9G 0% /dev/shm /dev/sda1 485M 39M 421M 9% /boot /dev/mapper/vg_dcasfis01-home 9.9G 151M 9.2G 2% /home /dev/mapper/vg_dcasfis01-var 7.9G 223M 7.3G 3% /var /dev/mapper/volgroup1-ISO 40G 177M 38G 1% /var/lib/samba/iso Looks good. Add some ISOs to the share for VMWare to use and let’s start configuring NFS.\nConfigure NFS # Modify /etc/exports to share the volume as read-only.\n/var/lib/samba/iso *(ro,sync) Start NFS and configure it to start at boot.\nservice nfs start chkconfig nfs on Grant others read-only access so VMWare can see the ISOs.\nchmod o+r /var/lib/samba/iso Now mount the NFS volume in VMWare as read-only. The path is going to be /var/lib/samba/iso. Open the datastore browser and verify you can see the ISOs.\nWe’re done! If you’re feeling adventurous you can even install Apache or another webserver and give access to these ISOs via HTTP. This is perfect for providing images to OpenStack’s Glance or CloudStack’s Secondary Storage.\nI hope you enjoyed this little tutorial. If you have any questions or comments please feel free to leave them below.\n","date":"28 July 2014","externalUrl":null,"permalink":"/2014/07/creating-a-multipurpose-linux-fileserver-for-windows-cifssmb-nfs-and-everything-else/","section":"Posts","summary":"Recently I needed to build a multipurpose file server to host CIFS and NFS shares — CIFS for the Windows users, and NFS for VMWare to store ISOs. It needed to utilize back end storage (NetApp via iSCSI), provide Windows ACLs for the CIFS shares, and be able to authenticate against two different Active Directory domains. After careful consideration, I decided to use Red Hat Enterprise Linux 6.5 (RHEL) instead of Windows Server 2012.\nNow you might be wondering, “Why on earth would you want to build a Linux file server to do all that when you can just use Windows?” There are a few reasons:\n","title":"Creating a Linux File Server for Windows CIFS/SMB, NFS, etc.","type":"post"},{"content":"","date":"28 July 2014","externalUrl":null,"permalink":"/tags/kerberos/","section":"Tags","summary":"","title":"Kerberos","type":"tags"},{"content":"","date":"28 July 2014","externalUrl":null,"permalink":"/tags/lvm/","section":"Tags","summary":"","title":"Lvm","type":"tags"},{"content":"","date":"28 July 2014","externalUrl":null,"permalink":"/tags/redhat/","section":"Tags","summary":"","title":"Redhat","type":"tags"},{"content":"","date":"28 July 2014","externalUrl":null,"permalink":"/tags/smb/","section":"Tags","summary":"","title":"Smb","type":"tags"},{"content":"","date":"9 July 2014","externalUrl":null,"permalink":"/tags/active-directory/","section":"Tags","summary":"","title":"Active-Directory","type":"tags"},{"content":"","date":"9 July 2014","externalUrl":null,"permalink":"/tags/dhcp/","section":"Tags","summary":"","title":"Dhcp","type":"tags"},{"content":"How to Configure Server Core with Active Directory Services, DNS, and DHCP Using Nothing But PowerShell # Windows Server 2012 offers two installation options: Server Core or “Server with a GUI”. This begs the question: Why would you want to install Server Core instead of the GUI? One reason may be that you have limited physical hardware resources and want to keep the footprint as small as possible.\nRecently I needed to build a domain controller, DHCP, and DNS server for a branch office. This office has a Riverbed Steelhead WAN optimization appliance which runs a nested VMware ESXi hypervisor. The appliance has limited memory and disk space, so I needed to keep the installation as small as possible (Incidentally, if I only needed DNS and DHCP, I would have just installed RedHat Enterprise Linux, but having the server be an Active Directory domain controller was also a requirement.)\nI’m going to show you step-by-step how I configured Active Directory Services, DNS, and DHCP on a Windows Server 2012 Server Core installation.\nTo begin you will need the following:\nA physical or virtual server with a fresh install of Windows Server 2012 Server Core At least one connected network interface 2 GB RAM minimum 40 GB virtual or hard disk for the Server installation 4 GB virtual or hard disk for the swap file (NTFS-formatted during the installation) A management workstation with PowerShell installed Log in as the local administrator, and we’ll begin by configuring basic networking.\nNetwork Configuration # First we’re going to get the name of the network adapter so we can rename it to something more friendly. get-netadapter Now let’s rename it to “LAN” and assign it a unicast IP address of 192.168.9.6/24 with a default gateway of 192.168.9.8. Rename-NetAdapter -name \u0026#34;Ethernet\u0026#34; LAN get-netadapter -name LAN | new-netipaddress -addressfamily IPv4 -IPaddress 192.168.9.6 -prefixlength 24 -type unicast -defaultgateway 192.168.9.8 Set the DNS servers to 192.168.20.80 and 192.168.20.81 set-dnsclientserveraddress -interfacealias LAN -serveraddresses 192.168.20.80,192.168.20.8 Verify the configuration with: $ Get-DnsClientServerAddress -interfacealias LAN | format-list InterfaceAlias : LAN InterfaceIndex : 12 AddressFamily : IPv4 ServerAddresses : {192.168.20.80, 192.168.20.81, 127.0.0.1} InterfaceAlias : LAN InterfaceIndex : 12 AddressFamily : IPv6 ServerAddresses : {::1} Enable Remote Access # I always like to have three methods of accessing a server. In this case, I have console access through VMware ESXi, but I also want to be able to use RDP and PowerShell Remoting. Let’s configure the latter two now. enable-psremoting cscript C:\\Windows\\System32\\Scregedit.wsf /ar 0 Temporarily turn off the Windows Firewall. netsh advfirewall set allprofiles state off Configure PowerShell Remoting # From this point forward, we will use PowerShell Remoting to finish the configuration of the server.\nSwitch to your management workstation and launch PowerShell as an Administrator\nAllow connections to any host and open a new PowerShell session to the target server.\nSet-Item WSMan:\\localhost\\Client\\TrustedHosts -Value \u0026#34;*\u0026#34; -Force New-PSSession -computername 192.168.9.6 -credential administrator If the connection is successful, PowerShell will display the new connection as follows:\nEnter the new PowerShell session Enter-PSSession 1 The PowerShell prompt will change indicating you are now connected to the target server.\nSet Swap/Paging File Location # Since our server has a small amount of RAM, the paging or swap file is going to be very important to the reliability of the server. We want to keep it on a separate volume so that an out-of-control process filling up the system volume doesn’t prevent the server from growing the paging file as needed. In this case, C: is the system volume and D: is the volume for the paging file.\nGet free space on D: get-wmiobject win32_logicaldisk Set the paging file to fill almost all free space on D: $CurrentPageFile = gwmi -Query \u0026#34;select * from Win32_PageFileSetting where name=\u0026#39;c:\\\\pagefile.sys\u0026#39;\u0026#34; -EnableAllPrivileges If($CurrentPageFile){$CurrentPageFile.Delete()} swmi Win32_PageFileSetting -Arguments @{Name=\u0026#39;D:\\pagefile.sys\u0026#39;; InitialSize=4036; MaximumSize=4036} Verify the paging file was created get-childitem d: -attributes hidden Disable automatic paging file size gwmi Win32_ComputerSystem -EnableAllPrivileges | swmi -Arguments @{AutomaticManagedPagefile=$false} Join the server to Active Directory and Promote it to Domain Controller Status # Rename the computer if needed using the cmdlet Rename-Computer Add the computer to the domain benpiper.com and reboot add-computer -domainname benpiper.com Install Active Directory Domain Services Install-WindowsFeature -name AD-Domain-Services If all is well, you should see the “Success” exit code.\nPromote the server to a domain controller Install-ADDSDomainController -credential (get-credential) After running through some tests and making changes to Active Directory, the server should now be a replica domain controller. Go ahead and reboot it again for good measure.\nInstall and Configure DHCP # We’re going to initially create just one IPv4 scope. The server will provide an IP address, DNS and WINS servers, and a default gateway.\nInstall DHCP services install-windowsfeature -name dhcp Create the IPv4 scope Add-DhcpServerv4Scope -StartRange 192.168.9.100 -EndRange 192.168.9.240 -SubnetMask 255.255.255.0 -LeaseDuration 14.0:0:0 -Name \u0026#34;Data\u0026#34; -ActivatePolicies 0 This newly created scope will be identified with a Scope ID which can be retrieved with the cmdlet\nget-dhcpserverv4scope Add DHCP options to the scope: DNS, default gateway (router), and WINS Set-DhcpServerv4OptionValue -scopeID 192.168.9.0 -DNSServer 192.168.9.6,192.168.20.80,192.168.20.81 -DNSDomain benpiper.com -Router 192.168.9.8 -WinsServer 172.16.51.5,172.17.51.2 Finally, verify the scope and options with $ Get-DhcpServerv4OptionValue -scopeid 192.168.9.0 | Format-List OptionId : 51 Name : Lease Type : DWord Value : {1209600} VendorClass : UserClass : PolicyName : OptionId : 15 Name : DNS Domain Name Type : String Value : {benpiper.com} VendorClass : UserClass : PolicyName : OptionId : 3 Name : Router Type : IPv4Address Value : {192.168.9.8} VendorClass : UserClass : PolicyName : OptionId : 6 Name : DNS Servers Type : IPv4Address Value : {192.168.9.6, 192.168.20.80, 192.168.20.81} VendorClass : UserClass : PolicyName : OptionId : 44 Name : WINS/NBNS Servers Type : IPv4Address Value : {172.16.51.5, 172.17.51.2} VendorClass : UserClass : PolicyName : Notice that I added this new server’s IP (192.168.9.6) as the primary DNS server. When we promoted this server to a domain controller, DNS was automatically installed and configured as part of Active Directory integrated DNS.\nPrior to this new server, DHCP was handled by a Cisco L3 switch. Since there are existing leases and since we may add a secondary server in the future, we want to enable conflict detection. Set-DhcpServerSetting -ConflictDetectionAttempts 1 Verify the setting with\n$ Get-DhcpServerSetting IsDomainJoined : True IsAuthorized : False DynamicBootp : True RestoreStatus : False ConflictDetectionAttempts : 1 NpsUnreachableAction : Full NapEnabled : False ActivatePolicies : True Last but not least, we must authorize this DHCP server in Active Directory. Add-DhcpServerInDC Your DHCP server is now up and running. Verify DHCP bindings/leases with\nGet-DhcpServerv4Lease -scope 192.168.9.0","date":"9 July 2014","externalUrl":null,"permalink":"/2014/07/windows-server-core-full-configuration-powershell/","section":"Posts","summary":"How to Configure Server Core with Active Directory Services, DNS, and DHCP Using Nothing But PowerShell # Windows Server 2012 offers two installation options: Server Core or “Server with a GUI”. This begs the question: Why would you want to install Server Core instead of the GUI? One reason may be that you have limited physical hardware resources and want to keep the footprint as small as possible.\nRecently I needed to build a domain controller, DHCP, and DNS server for a branch office. This office has a Riverbed Steelhead WAN optimization appliance which runs a nested VMware ESXi hypervisor. The appliance has limited memory and disk space, so I needed to keep the installation as small as possible (Incidentally, if I only needed DNS and DHCP, I would have just installed RedHat Enterprise Linux, but having the server be an Active Directory domain controller was also a requirement.)\nI’m going to show you step-by-step how I configured Active Directory Services, DNS, and DHCP on a Windows Server 2012 Server Core installation.\n","title":"Windows Server Core Full Configuration with PowerShell","type":"post"},{"content":" Examples of typical client results: # Helped a national payroll processing company achieve 99.99% uptime for their online payroll services.\nImproved application launch times for Citrix by 17%.\nAverted potential client losses and helped secure new and sustainable business.\nImproved stability of Citrix XenApp servers by ensuring consistent nightly reboots. ","date":"13 June 2014","externalUrl":null,"permalink":"/results/","section":"Ben Piper","summary":"","title":"Results","type":"page"},{"content":"When it comes to security, IT leaders focus so much on preventive action that they don’t plan for contingent action. What would you do if you were hacked and confidential information was stolen? If you can’t confidently answer that right off the top of your head, you’re one breach away from looking for a new job.\nHumans are bad at accurately assessing risk. The likelihood of getting hacked is next to zero unless you’re a big target or haven’t taken appropriate preventative security measures. But if you do get hacked, the consequences can be catastrophic. Yet IT focuses almost exclusively on prevention. Why? For starters, preventive action is easier. Setting up firewalls and security software and following well-documented security practices are all straightforward steps. Preventive actions are also highly visible. When you’re blocking and filtering things, people notice, and you can easily prove that you’re on the ball if anyone ever asks. Contingent action is also not nearly as glamorous. Blocking an attack against your network is much more exciting and rewarding than responding after the horse has left the barn.\nStrangely, IT takes a completely different attitude toward backups. IT doesn’t put the bulk of its efforts into preventing data loss or corruption from ever occurring. Instead, it focuses on contingent actions — keeping backups and restoring from them when data loss does occur. The likelihood of data disappearing due to bit rot or user error is on par with being hacked. But, as many of us in IT are fond of saying, whether you lose data is not a question of “if,” but “when.” Yet IT doesn’t adopt the same attitude toward security. It’s not a question of “if” you’ll have a breach, but “when.”\nIt’s no fun planning for a scenario that begins with, “What do we do if all these security measures fail?” But failures happen. IT has to let go of the “no mistakes allowed” attitude. It’s better to make a mistake and deal with it properly than to try to be mistake-free and have no clue what to do when a mistake does occur (and it will). IT needs to take appropriate preventive security measures, but it needs to spend the bulk of its time on planning for contingent action.\nImagine for a moment that you are awakened at some unholy hour of the morning with the news that someone, somewhere is in your network, downloading confidential data. What do you do? Pull the plug? Then what? Without a contingency or crisis plan in place, you will have to figure it out as you go.\nFormulate a contingency plan for each plausible scenario. When I say “plausible” I don’t mean “possible under extremely unlikely circumstances.” I’m talking about scenarios that actually might happen. For example:\nA rogue employee makes off with confidential data\nAn attacker breaches your network and begins collecting data\nData is intermittently leaking out, but you don’t know how or when\nA solid contingency plan has the following elements:\nStopping – Cutting off access, at the source if necessary\nFreezing – Preserving the “scene of the crime” for forensic analysis\nRecovering – Revising your preventive action plan and getting back to normal\nNotice I said nothing about “getting back” any data. That’s impossible. In contingent action, the best you can hope for is to limit the damage and prosecute the responsible party. There are no winners, and that’s why contingent action is rarely on IT’s radar.\nWhat other areas of your life and organization have you failed to create contingency plans for? The axiom that it’s not a matter of “if” but “when” applies to more than just data loss.\n","date":"26 September 2012","externalUrl":null,"permalink":"/2012/09/too-much-prevention-not-enough-cure/","section":"Posts","summary":"","title":"Too Much Prevention, Not Enough Cure","type":"post"},{"content":"Virtually every business I have ever worked with had one “hero” in its IT organization — that one person who was considered almost indispensable because he had the “keys to the kingdom” and knew things others didn’t. I believe many IT leaders allow such a scenario to persist in their organization because they’re either not sure how to handle the situation, or they are simply unaware the situation exists. If the latter applies to you, here is your wake-up call. If you already know of a “hero” in your organization, here is my advice on eliminating hero dependency.\nTwo Types of Heroes # You need to understand which type of hero you are dealing with. There are two types of heroes: good and bad.\nGood heroes # Share information when asked Often assume that others know what they know Don’t want to be the only ones holding the “keys to the kingdom” Don’t desire to “own” any system or process Bad heroes # Resist sharing information, or offer minimal information when asked Offer excuses for doing so, usually by citing bogus security concerns Know they are the only ones with certain knowledge Want to maintain “hero” status for job security or power Are protective and territorial about critical systems The presence of a good hero is rarely regarded as a problem. But it is just as much of a problem as a bad hero. The only difference is that a good hero is more than willing to take on the task of “brain dumping” to others in the organization and telling them everything he knows. All IT leaders have to do is facilitate that transfer. Dealing With a Bad Hero # Dealing with a bad hero is a bit more complex. In effect, the hero has the entire business “over a barrel.” IT leaders know this and may fear that simply demanding that the hero document all his knowledge will threaten him, possibly causing him to resign, taking the vital knowledge with him. Another fear is that he may sabotage systems and then demand a ransom. Both of theses fears are unfounded.\nIronically, the bad hero’s motivation for withholding information will ensure that he does not leave. He wishes to retain his job, and will sacrifice his “security” (knowledge) to do so.\nWhen dealing with a bad hero, you must be prepared to terminate him on-the-spot. A bad hero may “see the light” and turn into a good hero, but this doesn’t always happen. Allowing a bad hero to remain in your organization is like allowing cancer to stay in your body. You may be fine today, but if you don’t get rid of it, it will come back to haunt you later.\nIt is unreasonable and unnecessary for any employee to recall and share every bit of information that could possibly be needed at some point in the future. The nature of technology is that what is important today will have a different degree of importance later. Focus on getting the information that you know matters right now and in the foreseeable future.\nHow to deal with a bad hero # Determine the most important information you know you’ll need now and in the near future Be prepared to fire him immediately if he doesn’t comply Request the information and set a short deadline If the bad hero presents you with another job offer and makes demands (higher pay, promotion, etc.), refuse to discuss such matters until he delivers the information you request. If he refuses, you must negotiate. Yes, I said negotiate. You can make a conditional acceptance. Come to an agreement on terms but on the condition that he documents the critical information to you within a short time period. Once you have the most information and have verified it, fire the bad hero. Yes, again, I said fire the bad hero. You don’t want such a poisonous person in your organization.\nPreventing Heroics # Ideally, your business will never have a single hero. The best way to prevent the rise of a single hero is to mandate that critical knowledge be shared. Don’t worry about documenting everything. I cringe at some attempts to document every little thing. The fact is that most documents get lost, misplaced, or simply forgotten, and they never serve the purpose for which they were intended. It is far better to have undocumented knowledge among three employees than to have documented knowledge that nobody knows exists.\nCross-training is an excellent way to keep vital information from residing solely in-between the ears of one person. One of my favorite suggestions by Peter Drucker is thus: Whenever you have a person who is great at one thing, move him to another position. Not only does this keep the employee from burning out, it also builds their skills and knowledge. There is a sense of peace that comes from not being the only person in the organization that can do __ (fill in the blank).\nA word of caution: Not everyone needs to know everything. You’re running a business, not a school. The operational objective is to keep things running smoothly even if many employees quit or are otherwise unavailable. Focus on having the most critical and frequently used knowledge and skills always available. Depending on the size of your organization, that could mean two people, or it could mean 22. As with everything else, there is a calculated risk inherent. You must decide what level of risk is tolerable.\nConclusion # Mandate knowledge be shared\nSet a deadline for heroes to “release” information and enforce it\nCross-train\nDocument the most critical information\nFire bad heroes who resist\n","date":"3 July 2012","externalUrl":null,"permalink":"/2012/07/depending-on-heroes/","section":"Posts","summary":"","title":"Depending on Heroes","type":"post"},{"content":"A common question facing service providers that use XenApp to provide published applications to multiple clients is whether to use a single, large farm for all clients, or to dedicate a separate farm to each client.\nOften the degree to which infrastructure is shared among clients is a matter of philosophy and preference. Some organizations will dedicate separate storage, networking, even virtual machine hosts for each client. The decision to share or not share infrastructure could be based on a variety of things, including client preference, past experiences, or the proverbial “that’s-just-the-way-it’s-always-been.”\nThe decision whether to share infrastructure among clients, and how much, must take into account many factors, not just the technical ones. If a client wants a dedicated virtual machine host, and is willing to pay for it, technical reasons probably won’t matter. But in some cases technical considerations leave little room for the client’s or organization’s preference. Sharing XenApp farms among multiple clients is one of those cases.\nPrior to XenApp 6.5, the Citrix Independent Management Architecture (IMA) operated in a hub-and-spoke configuration, where each XenApp server communicated directly with the data store, which is often a SQL database. This many-to-one configuration works fine for a relatively low number of servers, but it does not scale well. As the number of clients in a single XenApp farm increases, so does the load on the poor data store, as does the amount of time it takes the IMA service to start. And until the IMA service starts on a XenApp server, it will not be able to service end users.\nPlacing multiple clients in a single farm also means that Client A’s XenApp servers could be sharing dynamic farm information with Client B’s XenApp servers. This can be mitigated with dedicated Zone Data Collector servers (ZDCs), however, only one ZDC can be active at a time. This configuration also does not scale well as more clients are added to the farm. Too many servers in a farm is also one of the leading causes of slow discovery in the Citrix Delivery Services/Access Management/Presentation Server Console.\nOne question that sometimes comes up during this thought-exercise is, “Why not just use multiple zones in a single farm?” The answer is that zones are the solution to a specific problem. Traffic between XenApp servers and the ZDCs can be voluminous. If a XenApp farm is spanning two or more geographically separate sites, connected via a WAN link, the WAN link will be saturated unless it’s very robust. Zones were developed as a way to logically separate servers so that XenApp servers only talk to the ZDCs close to themselves. The ZDCs then share information with each other across the WAN in a bandwidth-friendly fashion. Citrix recommends minimizing the number of zones in a farm.\nXenApp 6.5 includes changes to the IMA architecture that mostly eliminate the above considerations. However, even in XenApp 6.5 there are good business and technical reasons to use a separate farm for each client.\nA single farm for all clients means a single point of failure at the data store level. A SQL server failure can be mitigated with database mirroring, however, a corrupt data store has only two solutions: restore from backup, or start over. Both options require down time for every client in the farm. This is probably the most significant reason to separate clients into separate farms. Multiple data stores means multiple databases, and this is desirable. Separate databases for each client allow distribution of load across SQL servers without clustering, as well as database-level snapshots, backups, and restores. Imagine if someone accidentally deleted a client’s published applications from the farm and the quickest option was to restore the database. You can explain to that client why you require downtime to perform the restore, but the other clients that are affected will not be so understanding. In a best-case scenario, the actual downtime would be only a few seconds, and it would not affect existing connections. But best-case scenarios are not the rule of the day, and if that risk can be reasonably avoided, it should be.\nSingle farm, multi-client deployments will likely have only one zone (as they should, unless there is a geographic separation of sites). Since only one ZDC can be active at a time in a zone, a ZDC failure can cause a service outage for all clients. In theory, another XenApp server should take over immediately in the case of a ZDC failure, but until this happens, all new connections to the farm will be impacted.\nIn addition to technical considerations, there are good business reasons to separate clients into separate farms. Giving each client its own farm facilitates change control, requiring only the client and the service provider to coordinate changes. If all clients share a single farm, changes to the farm would require buy-in from all clients on the farm, assuming such a change control is in place. Separate farms also allow for more farm customization for each client. XenApp 6 has largely moved many farm-level settings into Active Directory Group Policy Objects (GPOs) which allow changes to be applied at an Organization Unit (OU) level. However, some settings are still applied on a per-farm basis.\nPlacing all clients in a single farm can also impede disaster recovery (DR) time objectives (RTO). In the event of a disaster, separate farms allow an organization to move one client at a time. A disaster recovery plan could involve two live sites simultaneously servicing clients (active-active) or one live site with failover (active-passive). In an active-active scenario, a single farm deployment will likely not pose a problem. However, in an active-passive scenario, the entire farm must be completely moved to the disaster recovery site before any client can be back up and running. This could lead to a significant client satisfaction issue (above and beyond the expected “What do you mean everything is down?”) if a particular client needs to access their applications immediately, while other clients could wait until the next morning.\nThe question is not “Can all clients reside in a single farm?” but “Should they all reside in a single farm?” The answer will depend on the needs, preferences, and priorities of both the service provider and the clients. But more often than not, using separate farms is the best long-term strategy. XenApp 6.5 offers significant advantages for a single-farm, multi-client deployment, so if you decide to go the single-farm route, XenApp 6.5 should be an absolute requirement. If you’re using a single-farm deployment, and decide to break it out into separate farms, the good news is that it can be done gradually, client-by-client, and you will likely see increasingly better performance and stability as each client is migrated to its own farm.\n","date":"24 March 2012","externalUrl":null,"permalink":"/2012/03/using-separate-xenapp-farms-for-shared-hosted-deployments/","section":"Posts","summary":"","title":"Using Separate XenApp Farms for Shared Hosted Deployments","type":"post"},{"content":"If you’re familiar with networking you know that when a device is directly connected to two separate IP networks, traffic destined for one of those networks should egress on the interface that is directly connected to that network. For example, if your storage appliance is directly connected to the 172.16.1.0/24 network, and you want to send a packet to a device with the IP of 172.16.1.55, traffic should egress on the interface connected to that network. Unfortunately, in the case of some NetApp filers, this does not always happen.\nI ran into a peculiar issue when trying to force NetApp’s Snapmirror to replicate across a specific interface, only to be met with an ugly “Snapmirror error: cannot connect to source filer (Error: 13102)”. I confirmed with NetApp support that the Snapmirror configuration was correct for what I was trying to accomplish.\nTo troubleshoot, I started a packet trace on the destination filer using the command:\npktt start all -d /etc I then kicked off the snapmirror initialization, waited for it to fail, then stopped the packet trace with\npktt stop all Since I directed the trace files to be placed in /etc on the filer I just browsed to the hidden etc$ CIFS share on the filer and opened the traces in Wireshark. What I found was that the traffic that should have been egressing on the iSCSI VIF was actually going out on the LAN VIF. Not only that, the filer was using its iSCSI address on the LAN VIF! I’m always hesitant to label every quirk a “bug,” but this is definitely not correct behavior.\nThe remedy was as simple as adding a route statement similar to this:\nroute add inet 172.16.1.0/24 172.16.2.1 1 where 172.16.1.0/24 is the iSCSI network I want to traverse to reach the Snapmirror partner, and 172.16.2.1 is the gateway on my locally connected iSCSI network. The 1 specifies the cost metric for the route, which will always be 1 unless you need to add additional gateways.\nTo make the change permanent, simply add the route statement to the /etc/rd file on the filer.\nSpecial thanks to NetApp’s Scott Owens for pointing me in the right direction on this.\n","date":"25 January 2012","externalUrl":null,"permalink":"/2012/01/forcing-netapp-to-use-the-correct-network-interface/","section":"Posts","summary":"","title":"How to Make NetApp Use the Correct Interface for iSCSI","type":"post"},{"content":"","date":"25 January 2012","externalUrl":null,"permalink":"/tags/snapmirror/","section":"Tags","summary":"","title":"Snapmirror","type":"tags"},{"content":"It came to my attention today that there is a seemingly new issue with XenServer that is causing the time in Windows VMs to become offset by one day. My first thought was that this could be related to 2012 being a leap year, so I pulled up the source code for the Xen 4.1 hypervisor that handles leap years from http://fossies.org/unix/misc/xen-4.1.2.tar.gz:a/xen-4.1.2/xen/common/time.c.\nI ran through the code with a calculator for today’s date (January 18, 2012) and ended up with tbuf.tm_mday being 19 because line 84 of the code adds one day for some reason. I can see this causing a VM’s time to be offset ahead by one day, but not backward. Can anyone validate or correct my thinking on this?\n1 /****************************************************************************** 2 * time.c 3 * 4 * This program is free software; you can redistribute it and/or modify 5 * it under the terms of the GNU General Public License as published by 6 * the Free Software Foundation; either version 2 of the License, or 7 * (at your option) any later version. 8 * 9 * This program is distributed in the hope that it will be useful, 10 * but WITHOUT ANY WARRANTY; without even the implied warranty of 11 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the 12 * GNU General Public License for more details. 13 * 14 * You should have received a copy of the GNU General Public License 15 * along with this program; if not, write to the Free Software 16 * Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA 17 */ 18 19 #include \u0026amp;lt;xen/config.h\u0026gt; 20 #include \u0026amp;lt;xen/time.h\u0026gt; 21 22 /* Nonzero if YEAR is a leap year (every 4 years, 23 except every 100th isn\u0026#39;t, and every 400th is). */ 24 #define __isleap(year) \\ 25 ((year) % 4 == 0 \u0026amp;\u0026amp; ((year) % 100 != 0 || (year) % 400 == 0)) 26 27 /* How many days are in each month. */ 28 const unsigned short int __mon_lengths[2][12] = { 29 /* Normal years. */ 30 {31, 28, 31, 30, 31, 30, 31, 31, 30, 31, 30, 31}, 31 /* Leap years. */ 32 {31, 29, 31, 30, 31, 30, 31, 31, 30, 31, 30, 31} 33 }; 34 35 #define SECS_PER_HOUR (60 * 60) 36 #define SECS_PER_DAY (SECS_PER_HOUR * 24) 37 38 struct tm gmtime(unsigned long t) 39 { 40 struct tm tbuf; 41 long days, rem; 42 int y; 43 const unsigned short int *ip; 44 45 y = 1970; 46 #ifdef __x86_64__ 47 /* Allow the concept of time before 1970. 64-bit only; for 32-bit 48 * time after 2038 seems more important than time before 1970. */ 49 while ( t \u0026amp; (1UL\u0026amp;lt;\u0026amp;lt;39) ) 50 { 51 y -= 400; 52 t += ((unsigned long)(365 * 303 + 366 * 97)) * SECS_PER_DAY; 53 } 54 t \u0026amp;#038;= (1UL \u0026amp;lt;\u0026amp;lt; 40) - 1; 55 #endif 56 57 days = t / SECS_PER_DAY; 58 rem = t % SECS_PER_DAY; 59 60 tbuf.tm_hour = rem / SECS_PER_HOUR; 61 rem %= SECS_PER_HOUR; 62 tbuf.tm_min = rem / 60; 63 tbuf.tm_sec = rem % 60; 64 /* January 1, 1970 was a Thursday. */ 65 tbuf.tm_wday = (4 + days) % 7; 66 if ( tbuf.tm_wday \u0026amp;lt; 0 ) 67 tbuf.tm_wday += 7; 68 while ( days \u0026gt;= (rem = __isleap(y) ? 366 : 365) ) 69 { 70 ++y; 71 days -= rem; 72 } 73 while ( days \u0026amp;lt; 0 ) 74 { 75 --y; 76 days += __isleap(y) ? 366 : 365; 77 } 78 tbuf.tm_year = y - 1900; 79 tbuf.tm_yday = days; 80 ip = (const unsigned short int *)__mon_lengths[__isleap(y)]; 81 for ( y = 0; days \u0026gt;= ip[y]; ++y ) 82 days -= ip[y]; 83 tbuf.tm_mon = y; 84 tbuf.tm_mday = days + 1; 85 tbuf.tm_isdst = -1; 86 87 return tbuf; 88 } ","date":"18 January 2012","externalUrl":null,"permalink":"/2012/01/windows-vms-on-xenserver-mysteriously-jumping-a-day-ahead/","section":"Posts","summary":"","title":"Windows VMs on XenServer Mysteriously Jumping a Day Ahead","type":"post"},{"content":"A lot of users who upgraded to the recently released Adobe Reader X 10.1.2 are finding that it crashes when trying to print a PDF.\n","date":"13 January 2012","externalUrl":null,"permalink":"/2012/01/avoid-upgrading-to-adobe-reader-x-10-1-2/","section":"Posts","summary":"","title":"Avoid Upgrading to Adobe Reader X 10.1.2","type":"post"},{"content":"If you have two Netapp filers and want to use Snapmirror to replicate volumes or qtrees between the two, but want to force the replication traffic to traverse a specific network, there is a quick and easy way to do it.\nYou’ll need a few things to get started:\n– SSH access to both filers\n– Network configuration on and connectivity to both filers for the network you want to use for replication traffic\n– System Manager 2.0 or later\nSSH to both filers and issue the command: options snapmirror.access legacy Browse to the hidden etc share on the filer that will be the Snapmirror destination by browsing to \\\\destfiler\\etc$ Open snapmirror.conf in a text editor and on the first line after any comments (any line starting with a hash ‘#’) type: connection_definition = multi(srcip,destip) I’ll start at the end of this string and work back to the beginning. src and destip are the source and destination IPs of the filers that will form a Snapmirror relationship. Let’s call this a connection pair. Be sure to put the IPs that correspond to the network interfaces you want Snapmirror to use for replication.\nmulti is short for multiplexing. Snapmirror supports multiplexing replication jobs across multiple interfaces to enhance throughput. For now, just specify one connection pair. You can always go back and add more later.\nconnection_definition is a name of your choosing that will be used as a reference to tell Snapmirror which network(s) to use for each replication job.\nFor example, if your source filer is named srcfiler with an IP of 172.16.1.50/24 and your destination filer is named destfiler with an IP of 172.16.2.50/24, you would add:\nfilers-rep = multi(172.16.1.50,172.16.2.50) When finished, save the file.\nIn System Manager, launch the Snapmirror relationship wizard (Filer Name -\u0026gt; Snapmirror -\u0026gt; Create)\nWalk through the wizard as if you normally would to create a Snapmirror relationship, but do not click “Initialize SnapMirror relationship”\nEdit snapmirror.conf on the destination filer and change the name of the source filer to the connection definition you specified in step 3.\nFor example, if the snapmirror.conf file shows:\nsrcfiler:volumeToReplicate destfiler:volumeToReplicate_SnapMirror - * * * * You would change it to:\nfilers-rep:volumeToReplicate destfiler:volumeToReplicate_SnapMirror - * * * * Save the file.\nSSH to the source and destination filers and issue the following two commands: snapmirror off snapmirror on This will force a re-read of the snapmirror.conf\nClose out of System Manager completely, reopen it, and connect to the destination filer.\nSelect the Snapmirror relationship you just created and click SnapMirror -\u0026gt; Operations -\u0026gt; Initialize\nAlternatively, you can SSH to the destination filer and issue the command:\nsnapmirror initialize -S filers-rep:volumeToReplicate destfiler:volumeToReplicate_SnapMirror I have noticed that System Manager did not immediately understand the changes I had made to Snapmirror.conf. If you get an error in System Manager, close it out, wait several minutes, then try again. Once System Manager recognizes the changes, you can use it to schedule replication jobs.\n","date":"28 December 2011","externalUrl":null,"permalink":"/2011/12/make-netapp-snapmirror-use-specific-interface/","section":"Posts","summary":"","title":"How to Make NetApp SnapMirror Use a Specific Interface","type":"post"},{"content":"1. Disable unused Group Policy sections\nIn each of the GPOs that are applied to your servers and users, both User and Computer processing is enabled by default. Disabling unused parts of a GPO can shave some time off both logons and server booting. You can do this in the GPO properties. Just bring up the GPO in Group Policy Management Editor, right-click the policy name, and click Properties.\nIf you have a GPO that only has User settings, disable Computer Configuration settings. If you have a GPO that only has user settings, disable User Configuration settings. When your Citrix servers are busy, having only the necessary parts of your GPOs enabled for processing could make a big difference.\n2. Redirect user profile folders\nCreate a GPO for folder redirection and load it up in the Group Policy Management Editor. Look under User Configuration \u0026gt; Policies \u0026gt; Windows Settings \u0026gt; Folder Redirection. You’ll see a list of folders that can be redirected.\nRight-click the folder to redirect, then select “Basic – Redirect everyone’s folder to the same location.” Under Target folder location, select “Create af older for each user under the root path” and specify the UNC to your repository for storing redirected user folders. It is not necessary to specify a username variable as Windows will add that automatically. Also, there is no need to add a trailing backslash.\nRepeat for each folder you wish to redirect. If you redirect AppData, be sure to test all of your applications with the redirection. Some applications (Outlook 2007 for example) will ignore AppData redirection and will just store user settings locally. It is definitely worth testing AppData redirection because if you can move it out of the user’s profile, it will dramatically improve logon times.\n3. Reduce the number of User GPOs processed\nConsolidate as many User GPOs as possible. If you have several GPOs to control application settings, see if you can consolidate them into one. The fewer GPOs that have to be processed at logon, the faster the logon process will be.\n4. Use asynchronous group policy processing\nAsynchronous group policy processing simply processes multiple User GPOs simultaneously instead of waiting for one to finish before starting the next. Some third-party products like AppSense have incorporated this approach to speed up logon times. In Windows Server 2008 and later, asynchronous group policy processing is enabled by default.\n5. Adjust visual effects preferences via GPO\nMany of the bells and whistles can be disabled in your user sessions in one fell swoop. In one of your user GPOs, browse to User \u0026gt; Preferences \u0026gt; Windows Settings \u0026gt; Registry.\nRight-click Registry, click New, then click Registry Item.\nCreate the registry item with the following data:\nHive: HKCU\nKey Path: Control Panel\\Desktop\nValue Name: UserPreferencesMask\nValue Type: Reg_Binary\nValue Data: 9012018010000000\nThis registry key-value will turn off all visual effects (except for font-smoothing) and animations.\n6. Disable font smoothing on the Web Interface\nSome users don’t like the font-smoothing effect provided by Windows Server 2008 and Web Interface. Others like it or just don’t notice it. But one thing is certain: ClearType font-smoothing generates three time the network traffic and can negatively impact a user’s experience.\nTurning off font-smoothing globally or on a per-user basis is quick and easy. Click here for the instructions from Citrix eDocs. Note that font-smoothing only occurs in ICA sessions when the user is using the Online Plugin/Receiver Enterprise client.\n7. Remove all unnecessary printer mappings from users’ workstations and sessions.\nIt’s not an option in all environments, but if you can swing this, it can make a big difference in logon times. Even though Citrix will not, by default, wait for printers to be created before starting a published application, the mapping still occurs in the background during the logon process and can slow things down.\nAnd if you’re really hardcore when it comes to optimizing logon times, you can just force everyone to use the Citrix Universal Printer and disallow all printer mappings!\n","date":"13 December 2011","externalUrl":null,"permalink":"/2011/12/7-ways-speed-citrix-xenapp-logons/","section":"Posts","summary":"1. Disable unused Group Policy sections\nIn each of the GPOs that are applied to your servers and users, both User and Computer processing is enabled by default. Disabling unused parts of a GPO can shave some time off both logons and server booting. You can do this in the GPO properties. Just bring up the GPO in Group Policy Management Editor, right-click the policy name, and click Properties.\n","title":"7 Ways To Speed Up Citrix XenApp Logons","type":"post"},{"content":"Do you have a workstation that intermittently boots up with both the black Citrix Receiver icon and the old blue Program Neighborhood Agent/Online Plugin icon? And does it fail to launch published applications?\nThis is a very common problem that affects both Windows XP and Windows 7 machines. Sometimes when the workstation boots, only the Citrix Receiver icon shows up and apps launch fine. But occasionally it will boot with both the Receiver icon and the blue PNAgent icon, and apps will just not launch.\nA typical workaround for this has involved terminating the pnamain.exe process, thus killing the blue PNAgent icon, and allowing apps to launch successfully. But this manual workaround gets old after a while.\nYour results may vary, but I have found that deleting the registry keys HKEY_CURRENT_USER\\Software\\Citrix\\ICA Client\\Engine\\Configuration and HKLM\\Software\\Citrix\\ICA Client\\Engine\\Configuration (on 64-bit systems: HKLM\\Software\\Wow6432Node\\Citrix\\ICA Client\\Engine\\Configuration) will allow applications to launch consistently, and will cause both the Receiver and PNAgent icons to appear consistently and behave normally.\nIf you have any workstations with this issue, try deleting the above keys and let me know what kind of results you get.\nWant more Citrix tips and tricks? Watch my Citrix NetScaler course!\n","date":"10 December 2011","externalUrl":null,"permalink":"/2011/12/how-to-fix-applications-intermittently-failing-to-launch-with-citrix-receiver-3-0/","section":"Posts","summary":"","title":"How To Fix Applications Failing To Launch With Citrix Receiver 3.0","type":"post"},{"content":"I accidentally discovered a potential security issue with server-to-client URL redirection that affects Receiver 3.0 (ICA Client 13), ICA Client 12.1.44, and XenApp 6.\nURL Redirection is often used to prevent end users from launching instances of Internet Explorer on a Citrix server and accessing the Internet. When URL redirection is enabled and a user clicks on a web hyperlink in a published application, the default web browser on the user’s client device is launched instead of spawning a web browser instance inside the user’s Citrix session. This feature helps to keep malware and other nasties from the Internet from dirtying up the Citrix servers, and it also reduces resource utilization as many web browsers can be very resource intensive.\nBut URL redirection can be easily defeated. All your user needs is Firefox set as the default browser and a quick finger. Here’s how it’s done:\nLaunch a published application via Citrix and locate the hyperlink to open\nOn the client device, open Firefox (I tested this with Firefox 8.0)\nClose Firefox\nImmediately and rapidly click the hyperlink in the published application several times\nAfter a short delay, Internet Explorer will launch on the Citrix server. And unless there are tight security or network restrictions in place on the Citrix side, a user who discovers this trick is free to surf and put your server at risk.\nIf you have total control over your user’s client devices, this issue is probably not a big deal. But if you do not control the client devices, this flaw could potentially be disastrous if your Citrix servers are not properly secured. I’ll soon be covering step-by-step exactly how to lock down your Citrix servers so that unforeseen “gotchas” like this don’t ruin your day.\n","date":"8 December 2011","externalUrl":null,"permalink":"/2011/12/a-secret-for-defeating-server-to-client-url-content-redirection/","section":"Posts","summary":"","title":"A Secret For Defeating Server-to-Client URL Content Redirection","type":"post"},{"content":"The recent Virginia earthquake that rocked much of the East coast was an unusual event. But it was not unpredicted or surprising. Unfortunately, the failure of the commonly accepted plate tectonics theory to predict or even explain the recent earthquake has raised many questions.\nBut first, what is plate tectonics? The plate tectonics theory is built upon “continental drift,” the old idea that all modern continents were once part of a single continent that slowly drifted apart. Plate tectonics attempts to explain this drift as the product, in part, of the hypothetical geological processes of subduction, or the process by which a tectonic plate 20-30 miles thick slides underneath another plate of similar width. Subduction by itself is incapable of explaining continental drift, and scientists do not agree on the other possible causes of plate motion.\nNow, onto some of the questions raised by the recent earthquake:\nWhy was the Virginia quake felt almost 500 miles away from its epicenter, considering that West coast earthquakes are never felt this far away? # The answer to this lies in the composition of the Earth’s crust East of the Rocky Mountains. The rocks in the East are denser and colder, and thus more efficient at transferring energy long distances. In the West, the rocks in the earth’s crust are fractured and warmer, and do not transfer energy as readily.\nWhy did the earthquake occur hundreds of miles from the New Madrid fault? # The plate tectonics theory attempts to explain earthquakes at the result of two slowly moving plates overcoming friction along their intersecting boundaries called “faults.” If you place a brick on a concrete floor and apply just a little horizontal pressure to it, the brick will not move. But if you gradually increase the pressure on the brick, the force will overcome the friction between the brick and the floor and the brick will suddenly move. This is the principle by which plate tectonics theory explains earthquakes.\nBut there is one huge problem with the theory: Most earthquakes do not occur along faults. In fact, they typically occur hundreds of miles away. If the current plate tectonics theory is accurate, we should see most earthquakes occurring on or very near faults.\nIs there a better model for explaining and predicting earthquake activity? # Scientists have been using GPS to track the movement of the earth’s crust over the years. What they have found is that all the continents are moving toward the Pacific ocean. This is significant because in the Pacific lie the Marianas trench and the Ring of Fire. Plate tectonics theory suggests that the Marianas trench is a site where subduction is taking place. But as stated earlier, subduction by itself is insufficient. Gravity is also not a likely explanation, as the force of gravity over the trench is the lowest in the world.\nHere’s another interesting find: What lies on the exact opposite of Earth from the Marianas trench? The Mid-Atlantic ridge, part of the world’s largest mountain range, the Mid-oceanic ridge.\nSomething else is clearly occurring that plate tectonics is incapable of explaining.\n","date":"30 November 2011","externalUrl":null,"permalink":"/2011/11/problem-plate-tectonics/","section":"Posts","summary":"","title":"The Problem with Plate Tectonics","type":"post"},{"content":"Yes, it will work under very limited circumstances, but it is not supported by Citrix. It is officially supported only for XenApp 5 and up.\n","date":"29 November 2011","externalUrl":null,"permalink":"/2011/11/citrix-receiver-3-0-is-not-compatible-with-presentation-server-4-0/","section":"Posts","summary":"","title":"Citrix Receiver 3.0 is not compatible with Presentation Server 4.0","type":"post"},{"content":"You’ve got a sinking feeling in your gut. You were working on a text document in your web browser when suddenly you accidentally clicked the wrong button or hit the wrong key combination, and POOF, it’s all gone. I will show you how to get it all back.\nNecessity is the mother of invention. If you’ve been looking for ways to recover a lost form in your web browser, you’ve likely come across a lot of unhelpful information. Certainly if you had been using one of those utilities that automatically save your work for you, you wouldn’t be searching for a how-to on getting your lost data back. This article is for you.\nTo recover your lost form data, you will need:\n– HxD Hex Editor\n– Notepad or your favorite text editor\n– A little patience\nStep 1.\nDownload and install the HxD hex editor from the link above and load it up.\n**Step 2.\n** In the menu bar, select Extras -\u0026gt; Open RAM…\n**Step 3.\n** Here you will see a list of all running processes. If you lost your form data in Internet Explorer, select iexplore.exe. Or if you were using Firefox, select firefox.exe. Now hit OK.\n**Step 4.\n** The hex editor will load the appropriate portion of your system’s RAM (random-access memory) that contains your lost form data. In the menu bar, select Search -\u0026gt; Find.\n**Step 5.\n** In the Find box, enter a portion of text from the form that you lost. Here you may have to go through a little trial-and-error. If you enter just one word, you may be sorting through a lot of data to find the proverbial needle in the haystack. If you enter too many words, you may skip right over some useful form data. I recommend starting with just two words that you know were in your lost form. Each time the hex editor finds a match, it will stop. Just hit F3 on your keyboard to continue searching.\n**Step 6.\n** Once you find what looks like a portion of your lost form data, copy it into your text editor. Select the text on the right-hand side, then click Edit -\u0026gt; Copy on the menu bar. Now paste the text into notepad or your favorite text editor.\nStep 7.\nGo back to Step 5 and continue the process until you have recovered your entire form.\nSometimes you will find almost 100% of the lost data sitting there untouched, but you will still need a little patience to piece together any missing pieces. And yes, you will probably have to retype a few words at the end. But doing it the way I have suggested will take much less time than retyping the entire form by hand.\nReady to start a career in IT? Sign up for a FREE trial from Pluralsight, the leading technology training platform!\n","date":"27 November 2011","externalUrl":null,"permalink":"/2011/11/how-to-recover-a-lost-form-in-internet-explorer-or-firefox-without-any-add-ons-or-pre-installed-utilities/","section":"Posts","summary":"","title":"How to Recover a Lost Form in Internet Explorer or Firefox Without Any Add-Ons or Pre-Installed Utilities","type":"post"},{"content":"If you’ve unwittingly discovered that the new Citrix Receiver 3.0 is not compatible with your old Presentation Server 4.0 farm, you’ve perhaps encountered a little trouble after rolling back to the previous version of the ICA client. If you have uninstalled Receiver and reverted to an older ICA client, you may receive the following error when trying to launch a published application:\nError number 2320\u0026lt;br /\u0026gt; Citrix online plug-in Configuration Manager: No value could be found for (ClientHostedApps) that satisfies all lockdown requirements. The lockdown requirements in force may be conflicting.\n(If you are getting this error with Receiver 3, refer to How To Fix Citrix Receiver Error 2320 instead for the solution)\nEven after uninstalling the ICA client, removing all its leftover program files and application data, and reinstalling an earlier ICA client version, you may still receive the error. The solution is as follows:\nUninstall all versions of the ICA Client and Receiver\nRemove all “Receiver” and “ICA Client” folders from the Program Files\\Citrix, Program Files\\Common\\Citrix, and the user’s AppData\\Citrix folders.\nInstall the ICA 12.1 client\nOn a 32-bit system: Create a registry string value called “ClientHostedApps” in HKLM\\SOFTWARE\\Wow6432Node\\Citrix\\ICA Client\\Engine\\Lockdown Profiles\\All Regions\\Lockdown\\Virtual Channels\\Control. Put a single asterisk (*) for the value data.\nOn a 64-bit system: Create a registry string value called “ClientHostedApps” HKLM\\SOFTWARE\\Wow6432Node\\Citrix\\ICA Client\\Engine\\Lockdown Profiles\\All Regions\\Lockdown\\Virtual Channels\\Control. Put a single asterisk (*) for the value data.\nThe end result should look like this:\nNow refresh your applications, and when you try to launch a published application, it should launch normally.\nWant more Citrix tips and tricks? Watch my course Citrix NetScaler 10: Design and Deployment!\n","date":"23 November 2011","externalUrl":null,"permalink":"/2011/11/how-to-fix-citrix-ica-client-error-2320-for-older-client-versions-non-receiver/","section":"Posts","summary":"","title":"How To Fix Citrix Error 2320 For ICA Client 12.1","type":"post"},{"content":"","date":"19 November 2011","externalUrl":null,"permalink":"/tags/printing/","section":"Tags","summary":"","title":"Printing","type":"tags"},{"content":"One of the problems that has plagued Citrix admins and engineers has been third party print drivers. All it takes is for one bad print driver to misbehave, crash the print spooler, and generate dozens of support calls from users who suddenly cannot print.\nThis common problem led to Citrix including the Citrix Universal Print Driver (Citrix UPD) which is compatible with many popular printers, and is much easier on the Windows print spooler. In cases where the Citrix Universal Print Driver does not play well with an application or a particular printer, the Citrix Universal Printer can be mapped into a user’s session as a virtual printer that offloads the print job to the user’s client machine, using the native or third-party print driver installed on the client machine.\nBetween these two wonderful gifts from Citrix, why even consider using a third-party print driver like the HP Universal Print Driver?\nDespite the stability and compatibility of the Citrix Universal Print Driver, I have found that even it sometimes causes the Windows print spooler to crash. I’m not saying that the driver itself is at fault. There could be a problem with the data an application is sending to the print subsystem and the Citrix UPD. Regardless, the print spooler sometimes crashes and has to be restarted to restore printing on the affected XenApp server.\nThere are three approaches to resolving the problem of the Citrix UPD crashing the spooler-\nEliminate the driver itself as the cause (blame an application, an OS patch, or something else)\nDo not map client printers into a user’s session, and instead allow them to only use the Citrix Universal Printer\nAllow use of native or third-party print drivers\nOption 1 is the most time-consuming and possibly the least rewarding because you may find that the problem actually is the driver, or an application that cannot be rewritten for whatever reason, or an OS patch that is absolutely necessary.\nOption 2, forcing users to use the Citrix Universal Printer, can potentially work marvelously for small print jobs provided the user understands how to use the Universal Printer options.\nOption 3, using native or third-party print drivers, makes many of us cringe. In Windows Server 2008 R2, some native HP drivers simply cannot be used. The native drivers HP gave to Microsoft to include in Windows included a bug which prevented the drivers from being used. This problem leaves the HP Universal Print Driver as the only native option for HP printers in Windows Server 2008 R2. If you have other printer brands in your environment, native drivers included with Windows will probably work. But remember that there is no guarantee that the native drivers will not crash the print spooler.\nSo which option is best? As usual, it depends on your environment. Despite the issues, I propose that option 3 can be a good option for XenApp 6 environments where printing is not heavy. Allowing native and third-party print drivers in addition to the Citrix Universal Printer and the Citrix UPD offers the most flexibility. The biggest problem I have seen with using the HP Universal Print driver is that it can consume the entire CPU and render the server almost useless. If users in your XenApp environment are doing a lot of printing, don’t use the HP Universal Print driver. Don’t even install it. Otherwise, test it out and see how it holds up under your workload.\nIf you decide to try third-party printer drivers, you don’t have to worry about these drivers crashing the print spooler thanks to the inclusion of a new feature in Windows Server 2008 R2 that allows print drivers to be isolated from the spooler. Print driver isolation works by creating a separate process, PrintIsolationHost.exe, for each session. Instead of a faulty driver crashing the spooler, it will only crash the PrintIsolationHost process, impacting only the user whose print job triggered the crash. Recovery is as simple as having the user log out and back in.\nEnabling print driver isolation is easy and is done on a per-driver basis. In Windows, just launch Print Management under Administrative Tools. Right-click the driver you wish to isolate, and select “Isolated”\nThe change takes effect immediately and no restart of the spooler is required. While print driver isolation is a valuable and much-needed feature, it is not compatible with all print drivers. And it is absolutely not compatible with the Citrix Universal Print driver! If there were a way to isolate it without breaking printing, it would save almost everyone from having to use native or third-party print drivers.\nOf course, isolating native and third-party drivers is only part of the solution. For maximum flexibility and compatibility, we need to automatically map the Citrix Univeral Printer into all user sessions, and set policies regarding the use of the Citrix UPD.\nMapping the Citrix Universal Printer to all user sessions is done through Citrix user printing policies. When it comes to how the Citrix UPD is used, we have two options. We can either disallow the use of native and third-party print drivers, and allow only the use of Citrix UPD-\nOr we can allow the use of native or third-party print drivers, if present, and fallback to the Citrix UPD if native drivers are unavailable.\nThe beauty of this configuration is that we can use Citrix policies to control when, if, and which print drivers are allowed without having to make any modifications to the XenApp server itself. Native and third-party print drivers are installed and isolated, but we can choose to disallow them by simply modifying the Citrix user policies. If the Citrix UPD causes problems with the print spooler, we can switch over to native and third-party drivers by simply changing the policies. And as if that weren’t enough, the Citrix policies can be filtered on a per-user basis. This means one group of users can be forced to use Citrix UPD, while another group can be permitted to use native drivers! Now you can see why I chose this configuration to provide the most control and flexibility without sacrificing stability of the XenApp environment.\nEarlier I mentioned that the Citrix Universal Printer is useful for small print jobs when the user understands how to use it. Rendering larger print jobs through the Universal Printer is extremely slow, and if users are trained in its use they can end up unintentionally printing to the wrong printer. Also, the Citrix Universal Printer requires the appropriate print drivers be installed on the user’s client machine, making its universal use a potential administrative nightmare. In the future I hope to see some intelligence built into XenApp and the ICA client that automatically detects and selects the best method of printing based on the user’s unique configuration.\nCitrix printing has improved tremendously over the years. One size still does not fit all, but we are getting there. Hopefully the Citrix Universal Print Server (Project Phaser) will be the silver bullet that solves printing in Citrix forever.\n","date":"19 November 2011","externalUrl":null,"permalink":"/2011/11/should-you-use-the-hp-universal-print-driver-or-other-third-party-print-drivers-in-xenapp-6/","section":"Posts","summary":"","title":"Should You Use The HP Universal Print Driver or Other Third-Party Print Drivers In XenApp 6?","type":"post"},{"content":"","date":"19 November 2011","externalUrl":null,"permalink":"/tags/xenapp/","section":"Tags","summary":"","title":"Xenapp","type":"tags"},{"content":"Have you ever had an application that seemed to initially run fine under Windows x64, only to have it crash or complain when performing a certain function inside the app? If you’ve run into this problem, take heart because the fix is really simple.\nBut first, it’s helpful to understand what happens when you run an application under 64-bit Windows. Some applications and libraries (DLLs) are compiled in such a way that they can run either as native 64-bit or 32-bit mode. Other applications and DLLs, however, can only run as 32-bit.\nLet’s say you have an application that easily runs as a 64-bit app under Windows 2008 R2 (which is a 64-bit OS). No problem, right? But what if that app makes a call to a Crystal Reports DLL that is compiled only as a 32-bit DLL? Trouble! That’s what happens! The application will not be able to find the DLL. As far as the app is concerned, the DLL doesn’t exist.\nTo understand why, we must understand how Windows separates 32 and 64-bit components. Windows x64 stores 32-bit DLLs in the Windows\\SysWoW64 folder, while 64-bit DLLs go in the Windows\\System32 folder. That seems backwards, doesn’t it? But it gets even more counter-intuitive. When a 32-bit mode application runs under Windows x64 and wants a DLL from “c:\\windows\\system32”, Windows will “lie” to the app and give it the DLL from C:\\windows\\syswow64!\nThe flipside of this redirection scheme is that 64-bit apps are affected as well. 64-bit applications cannot see or access the Windows\\SysWoW64 folder. They can only see Windows\\System32. If an application installer places a 32-bit DLL in Windows\\SysWoW64, then later a 64-bit application tries to call that DLL, it will simply fail because, to the application, that DLL doesn’t exist.\nBut what if we get sneaky and copy that 32-bit DLL to the System32 folder? Our 64-bit app will find the DLL, but it will not be able to load it into its memory space (For a technical explanation why, see Why can’t you thunk between 32-bit and 64-bit Windows?). Once again, the app will crash or yield an error.\nThe Solution # So what is the solution? We just have to get the 64-bit app to run as a 32-bit application. This will allow the app to see the 32-bit DLLs in the Windows\\SysWoW64 folder and load them into its memory space. We will lose some of the benefits of 64-bit execution, but at least the app will work properly. And fortunately, we don’t have to get the vendor to send us a recompiled executable. We can force the app to run as a 32-bit app by changing the execution headers using the Microsoft CorFlags utility. All you have to do is install the Microsoft Windows SDK and grab CorFlags.exe from the Bin folder of the SDK program files directory.\nThen all you have to do is run:\nCorFlags /32BIT+ application.exe\nwhere application.exe is the application you want to force to run as 32-bit. The next time you execute the application, Windows will see the new header and will execute it as a 32-bit application.\n","date":"18 November 2011","externalUrl":null,"permalink":"/2011/11/forcing-apps-to-run-in-32-bit-mode-in-a-64-bit-windows-environment/","section":"Posts","summary":"","title":"Forcing Apps to Run in 32-bit mode in 64-bit Windows","type":"post"},{"content":"Atheists by and large believe that science somehow disproves the existence of anything outside of the material world. This would, of course, include God.\nBut the atheists are so blind and darkened in their understanding that they fail to realize that the most popular approach to science, called methodological materialism, assumes that only the material world exists. Obviously, assuming something is the exact opposite of proving it.\nIf you ask an atheist to prove only the material world exists, you will not get any proof whatsoever. All you\u0026rsquo;ll get is his or her assumption, veiled in a statement something like, \u0026ldquo;You can\u0026rsquo;t prove there is anything other than the material world.\u0026rdquo; Of course, that statement would be 100% inaccurate because of two things we do know from science:\nMatter and usable energy cannot have always existed\nMatter and energy cannot be created or destroyed by any known process within the material universe\nEven the atheists recognize these two facts, and that\u0026rsquo;s why they have resorted to silly notions such as \u0026ldquo;the Big Bang\u0026rdquo; theory, which assumes — wait for it — something from nothing! Yes, that\u0026rsquo;s right. Even atheists resort to non-material explanations of the origin of the universe, while simultaneously denying the non-material world exists.\nBut please don\u0026rsquo;t take my word for it. Read for yourself one of the most famous quotes from formerly atheist physicist Steven Hawking:\nThe inflation was also a good thing in that it produced all the contents of the universe, quite literally out of nothing\u0026hellip;\nYes, you read that right. Atheists do believe in the non-material world, but they like to say they don\u0026rsquo;t.\nHawking continues:\nSo, where did the energy come from, to create the matter [in the universe]? The answer is, that it was borrowed, from the gravitational energy of the universe.\nSo let me get this straight. The universe was created from its own gravitational energy? That\u0026rsquo;s like saying a baby created itself from its own DNA. It\u0026rsquo;s nonsense.\nCreation of matter from nothing, by definition, proves the non-material. Bend it any way you like, you cannot escape the fact that atheists physicists have to resort to traveling outside the material world to explain the universe.\n","date":"17 October 2011","externalUrl":null,"permalink":"/articles/matter-proves-the-non-material/","section":"Articles","summary":"","title":"Matter Proves the Non-material","type":"page"},{"content":"","date":"5 October 2011","externalUrl":null,"permalink":"/tags/github/","section":"Tags","summary":"","title":"Github","type":"tags"},{"content":"In many Citrix environments it’s common to have a large variety of ICA client versions. One thing that sometimes surprises users and IT folks alike is how much of a performance increase can be seen after upgrading an old ICA client. But how do you know which clients need upgrading?\nOne of the biggest challenges has been deciphering what ICA client version the cryptic “client build number” in a user’s session information translates to. Well thanks to the XenApp 6 PowerShell SDK and Get-XASession, we can easily find Citrix ICA client version information in a snap with the following script (download the script here):\n################################################# # XenApp 6 Client Version Retrieval Script # Created by Ben Piper # http://benpiper.com, ben@benpiper.com ################################################# function convertToVersion($build) { switch($build){ 6685 {\u0026#34;13.0\u0026#34;; break}30 {\u0026#34;12.1\u0026#34;; break}6 {\u0026#34;12.0.3\u0026#34;; break}6410 {\u0026#34;12.0\u0026#34;; break}142{\u0026#34;Java\u0026#34;; break}317{\u0026#34;3.0\u0026#34;; break}324{\u0026#34;3.0\u0026#34;; break}330{\u0026#34;3.0\u0026#34;; break}349{\u0026#34;3.0\u0026#34;; break}304{\u0026#34;MAC 6.3\u0026#34;; break}314{\u0026#34;MAC 6.3\u0026#34;; break}323{\u0026#34;MAC 6.3\u0026#34;; break}326{\u0026#34;MAC 6.3\u0026#34;; break}400{\u0026#34;MAC 7.0\u0026#34;; break}402{\u0026#34;MAC 7.0\u0026#34;; break}405{\u0026#34;MAC 7.0\u0026#34;; break}406{\u0026#34;MAC 7.0\u0026#34;; break}407{\u0026#34;MAC 7.0\u0026#34;; break}402{\u0026#34;MAC 7.0\u0026#34;; break}411{\u0026#34;MAC 7.0\u0026#34;; break}500{\u0026#34;MAC 7.1\u0026#34;; break}600{\u0026#34;MAC 10.0\u0026#34;; break}601{\u0026#34;MAC 10.0\u0026#34;; break}581{\u0026#34;4.0\u0026#34;; break}606{\u0026#34;4.0\u0026#34;; break}609{\u0026#34;4.0\u0026#34;; break}614{\u0026#34;4.0\u0026#34;; break}686{\u0026#34;4.0\u0026#34;; break}715{\u0026#34;4.2\u0026#34;; break}727{\u0026#34;4.2\u0026#34;; break}741{\u0026#34;4.2\u0026#34;; break}779{\u0026#34;4.21\u0026#34;; break}730{\u0026#34;wyse1200le\u0026#34;; break}910{\u0026#34;6.0\u0026#34;; break}931{\u0026#34;6.0\u0026#34;; break}961{\u0026#34;6.01\u0026#34;; break}963{\u0026#34;6.01\u0026#34;; break}964{\u0026#34;6.01\u0026#34;; break}967{\u0026#34;6.01\u0026#34;; break}985{\u0026#34;6.2\u0026#34;; break}986{\u0026#34;6.2\u0026#34;; break}1041{\u0026#34;7.0\u0026#34;; break}1050{\u0026#34;6.3\u0026#34;; break}1051{\u0026#34;6.31\u0026#34;; break}1414{\u0026#34;Java 7.0\u0026#34;; break}1679{\u0026#34;Java 8.1\u0026#34;; break}1868{\u0026#34;Java 9.4\u0026#34;; break}1876{\u0026#34;Java 9.5\u0026#34;; break}2600{\u0026#34;RDP 5.01\u0026#34;; break}2650{\u0026#34;10.2\u0026#34;; break}3790{\u0026#34;RDP 5.2\u0026#34;; break}6000{\u0026#34;RDP 6.0\u0026#34;; break}2650{\u0026#34;10.2\u0026#34;; break}5284{\u0026#34;11.0\u0026#34;; break}5323{\u0026#34;11.0\u0026#34;; break}5357{\u0026#34;11.0\u0026#34;; break}6001{\u0026#34;RDP 6.0\u0026#34;; break}8292{\u0026#34;10.25\u0026#34;; break}10359{\u0026#34;10.13\u0026#34;; break}128b1{\u0026#34;MAC 10.0\u0026#34;; break}12221{\u0026#34;Linux 10.x\u0026#34;; break}13126{\u0026#34;Solaris 7.0\u0026#34;; break}17106{\u0026#34;7.0\u0026#34;; break}17534{\u0026#34;7.0\u0026#34;; break}20497{\u0026#34;7.01\u0026#34;; break}21825{\u0026#34;7.10\u0026#34;; break}21845{\u0026#34;7.1\u0026#34;; break}22650{\u0026#34;7.1\u0026#34;; break}24737{\u0026#34;8.0\u0026#34;; break}26449{\u0026#34;8.0\u0026#34;; break}26862{\u0026#34;8.01\u0026#34;; break}28519{\u0026#34;8.05\u0026#34;; break}29670{\u0026#34;8.1\u0026#34;; break}30817{\u0026#34;8.26\u0026#34;; break}31327{\u0026#34;9.0\u0026#34;; break}31560{\u0026#34;11.2\u0026#34;; break}32649{\u0026#34;9.0\u0026#34;; break}32891{\u0026#34;9.0\u0026#34;; break}34290{\u0026#34;8.4\u0026#34;; break}35078{\u0026#34;9.0\u0026#34;; break}36280{\u0026#34;9.1\u0026#34;; break}36824{\u0026#34;9.02 WinCE\u0026#34;; break}37358{\u0026#34;9.04\u0026#34;; break}39151{\u0026#34;9.15\u0026#34;; break}44236{\u0026#34;9.15 WinCE\u0026#34;; break}44367{\u0026#34;9.2\u0026#34;; break}44376{\u0026#34;9.2\u0026#34;; break}44467{\u0026#34;Linux 10.0\u0026#34;; break}45418{\u0026#34;10.0\u0026#34;; break}46192{\u0026#34;9.18 WinCE\u0026#34;; break}49686{\u0026#34;10.0\u0026#34;; break}50123{\u0026#34;Linux 10.6\u0026#34;; break}50211{\u0026#34;9.230\u0026#34;; break}52110{\u0026#34;10.0\u0026#34;; break}52504{\u0026#34;9.2\u0026#34;; break}53063{\u0026#34;9.237\u0026#34;; break}55362{\u0026#34;10.08\u0026#34;; break}55836{\u0026#34;10.1\u0026#34;; break}58643{\u0026#34;10.15\u0026#34;; break}\tdefault {$build; break} } } $clientUsage = @() foreach($session in Get-XASession -full | where {$_.state -eq \u0026#34;Active\u0026#34; -and $_.protocol -eq \u0026#34;Ica\u0026#34;}) { $clientUsage += new-object psobject -Property @{ User = $session.accountname Workstation = $session.clientname Client = convertToVersion($session.clientbuildnumber) } } $clientUsage | sort-object -Property Workstation | get-unique -asstring The script makes use of build-to-version information gleaned from Nick Holmquist’s ICA Client Build List and the Citrix Client Build List thread on Citrix Forums (Thanks!). The convertToVersion function uses the PowerShell switch command to identify and then return the ICA client version based on the build number. If the key-value pair is not in the list, the build number is returned. All ICA client versions in the list have at least one decimal place to make it easy to distinguish build numbers from client versions.\n","date":"5 October 2011","externalUrl":null,"permalink":"/2011/10/use-powershell-find-citrix-ica-client-versions-use-xenapp-6-farm/","section":"Posts","summary":"","title":"Use PowerShell to Find Citrix ICA Client Versions In Use On a XenApp 6 Farm","type":"post"},{"content":"","date":"26 August 2011","externalUrl":null,"permalink":"/tags/2320/","section":"Tags","summary":"","title":"2320","type":"tags"},{"content":"Recently I have seen a couple of cases where the Citrix Receiver 3 client produces the following error when trying to launch a published application:\nError number 2320\u0026lt;br /\u0026gt; Citrix online plug-in Configuration Manager: No value could be found for (ClientHostedApps) that satisfies all lockdown requirements. The lockdown requirements in force may be conflicting.\nThe most salient part of the error message is in between the parenthesis. In the error message above, ClientHostedApps is a registry value that resides in two locations: HKLM\\SOFTWARE\\Wow6432Node\\Citrix\\ICA Client\\Engine\\Lockdown Profiles\\All Regions\\Lockdown\\Virtual Channels\\Control (on 64-bit systems: HKLM\\SOFTWARE\\Wow6432Node\\Citrix\\ICA Client\\Engine\\Lockdown Profiles\\All Regions\\Lockdown\\Virtual Channels\\Control) and HKCU\\SOFTWARE\\Citrix\\ICA Client\\Engine\\Lockdown Profiles\\All Regions\\Lockdown\\Virtual Channels\\Control\nThe fix couldn’t be simpler. Just delete the value for ClientHostedApps in these locations, refresh your applications in Receiver, and you should be able to launch published applications.\nWant more Citrix tips and tricks? Watch my Citrix NetScaler course!\n","date":"26 August 2011","externalUrl":null,"permalink":"/2011/08/how-to-fix-citrix-receiver-error-2320/","section":"Posts","summary":"","title":"How To Fix Citrix Receiver Error 2320","type":"post"},{"content":"","date":"26 August 2011","externalUrl":null,"permalink":"/tags/receiver/","section":"Tags","summary":"","title":"Receiver","type":"tags"},{"content":"","date":"26 August 2011","externalUrl":null,"permalink":"/tags/registry/","section":"Tags","summary":"","title":"Registry","type":"tags"},{"content":"Sometimes there is a need to publish an application to individual XenApp servers for baselining or troubleshooting purposes. But if you have a lot of published applications in your XenApp 6 farm, this can be a huge hassle. Thankfully PowerShell allows us to quickly and easily take our existing published applications and automatically create individually published apps for each server. We can use Worker Groups to control which servers get an individually published application. Not only that, we can organize the applications neatly by creating separate console and Client folders for each server. I wrote this script to accomplish all of the above using XenApp 6 PowerShell SDK’s powerful features:\n$appFolder = \"Applications\" $testfolderpath = \"Applications/Test/Single Server Test\" $sourceAppPath = \"Applications/Test\"\t#apps in the root of this path will not be copied $publishTo = \"DOMAIN\\GroupWithAccessToIndividualServers\" $targetWorkerGroup = \"Main Farm Servers\" $clientFolder = \"Test\\Single Server Test\" $WhatIfPreference = $false\t# Simulate script but do not execute any changes (will yield errors) # Main Program $servers = Get-XAServer -workergroupname $targetWorkerGroup $sourceFolders = Get-XAFolder -folderpath $appFolder -recurse | where {$_ -notmatch $testfolderpath -and $_ -match $sourceAppPath -and $_ -ne $sourceAppPath} # Create folder for each server foreach ($server in $servers) {\t#generate folder name for each server $createfolder = $testfolderpath+\"/\"+$server.servername #create folder for each server new-xafolder -folderpath $createfolder foreach ($folder in $sourceFolders) { #get list of apps to copy in each folder $appstocopy = Get-XAApplication -folderpath $folder\tforeach ($app in $appstocopy) { ## generate name for new app $newname = $app.displayname+\" \"+$server.servername $newclientfolder = $clientfolder+\"\\\"+$server.servername ## get existing accounts to remove\t$accountsToRemove = ($app | Get-XAApplicationReport).accounts ## copy application to server's folder\t$newapp = $app | Copy-XAApplication -folderpath $createfolder ## publish application to lone server\t$newapp | set-xaapplication -servernames $server.servername -clientFolder $newclientFolder ## remove existing accounts foreach ($account in $accountsToRemove) { $newapp | remove-xaapplicationaccount -Accounts $account } ## publish application to AD group $newapp | add-xaapplicationaccount -Accounts $publishTo ## rename new application $newapp | rename-xaapplication -newdisplayname $newname\t}}} Download the script from GitHub.\nJust set the variables with what is appropriate for your environment and run the script.\nThe $appFolder variable is the root path of your applications (default is “Applications”)\n$testfolderpath is the full path of the folder where the applications published to individual servers will be published (no trailing slash)\nSet $sourceAppPath one level higher than the path of the folder containing the applications you wish to copy. The script will recurse down into child folders from this path, but will not copy applications that reside within this path.\n$publishTo is a string containing the AD users or groups the newly published applications should be published to\n$targetWorkerGroup is the name of the worker group containing the servers the applications will be published to\n$clientFolder is the root Program Neighborhood/Client folder that the individual server folders will be created under\nThe once-daunting and time-consuming task of copying and modifying applications for each server can now be done automatically in a matter of minutes!\nUpdate: It’s even easier to undo the changes made by the above script if you decide you want to scrap the newly published apps and folders and start over. Just use the following script:\n$testfolderpath = \"Applications/Test/Single Server Test\" $WhatIfPreference = $false # Main Program (get-xaapplication -folderpath (Get-XAFolder -folderpath $testfolderpath)) | remove-xaapplication (get-xafolder -folderpath $testfolderpath) | remove-xafolder ","date":"22 August 2011","externalUrl":null,"permalink":"/2011/08/instantly-publishing-citrix-apps-to-individual-servers-using-powershell/","section":"Posts","summary":"","title":"Instantly Publishing Citrix Apps to Individual Servers Using PowerShell","type":"post"},{"content":"Most people who believe in evolution do not even know what it is. And what I\u0026rsquo;ve noticed is that they will change the definition of it on the fly as soon as they realize how ridiculous the theory actually is.\nHere are the facts about evolution:\nThe variations that the theory of evolution speaks of are 100% undirected with no design and no purpose whatsoever.\nThe \u0026ldquo;natural selection\u0026rdquo; part of the theory of evolution contends that only those traits which confer a reproductive benefit to the organism will allow that organism to pass its traits on to its offspring.\nThe theory of evolution states that all life on earth descended from a common ancestor. This means evolutionists believe that the first living organism (which they have not yet defined conclusively) evolved into you over hundreds of millions of years.\nThe biggest problem for evolution is the total lack of evidence that it ever happened. It\u0026rsquo;s as simple as that. If it happened, we should have fossils galore showing one genus evolving into another. But we do not have a single one! Thus, evolution is dependent upon blind faith in a theory, and upon the rejection of scientific thought.\nAsk yourself this: Do you believe that the computer you\u0026rsquo;re using grew on a tree and was harvested by elves, put in a box, and sent to you on a flying unicorn?\nNo?\nWell, why not?\nOh, because there is absolutely no evidence for it?\nBingo.\nNow you understand why evolutionists are so desperate to obfuscate, deflect, and ignore the insurmountable problems with the theory they claim to believe. They need an excuse to stay inside their little box, protected by the dogma of blind faith in a 150+ year old story told by a man (Darwin) who hadn\u0026rsquo;t the slightest clue about biological structures.\nSome evolutionists like to claim that Christians cling to an old book written thousands of years ago. But the difference is that the Bible has been proven accurate in what it says, and fits perfectly with everything we know about the universe. The theory of evolution, on the other hand, goes completely against everything we know about the world and biology. So the next time you\u0026rsquo;re confronted with a false accusation of having \u0026ldquo;blind faith\u0026rdquo; in a Creator, remind them that some of the greatest scientists of all time were Creationists, the Bible has been proven accurate in its testable claims about the world, and that there is more evidence in the fossil record and anthropology for special creation than there is for evolution.\nGod the author of logic and reason. He is Truth. Science is the apprehension of knowledge, and knowledge belongs to God.\n","date":"11 August 2011","externalUrl":null,"permalink":"/articles/the-people-who-believe-evolution-dont-know-what-it-is-cant-defend-it/","section":"Articles","summary":"","title":"The People Who Believe in Evolution Don't Know What It Is and Can't Defend It","type":"page"},{"content":"Evolutionists are often given a false sense of security and rightness when they encounter Creationists who do not seem to understand evolutionary theory. This is both tragic and unnecessary. So to help both Bible-believing Creationists and Darwinists alike, I present a summary of the completely unfounded and baseless theory of evolution.\nFirst of all, a quick definition: Evolution is defined as the descent of all life on earth from a common ancestor through a series of random changes over time. That is not a \u0026ldquo;Creationist\u0026rdquo; definition, but the definition used by secular, evolutionary biologists around the world.\nThe first key thing to remember when discussing evolution is that it is completely undirected, with no design and no purpose. What does this mean? It means that, according to the theory, everything from the eye to the brain to the cell to the mucosal membranes are all the product of undirected or \u0026ldquo;random\u0026rdquo; variations over time. A lot of folks get hung up on this point because it is so counter-intuitive. The notion that a series of random events can result in such complexities is completely bewildering to most people. I believe this is why so many try to force some sort of design or purpose onto the theory of evolution. They are trying to make sense of it. \u0026ldquo;How can anyone believe this is random?\u0026rdquo; many people ask. But believe it they do.\nThe second key is a notion called \u0026ldquo;natural selection.\u0026rdquo; This is what I call the \u0026ldquo;adopted child of evolution\u0026rdquo; because it has a dirty little secret. But before I tell you the secret, let me explain what natural selection is. It is the phenomenon that organisms that are better at reproduction will pass their genes onto their offspring, while those organisms that are worse at reproduction will not. That\u0026rsquo;s pretty simple, right? That\u0026rsquo;s all natural selection is.\nNow for the dirty little secret: There is nothing about natual selection that is specifically tied to evolution. But evolutionists love to talk about it as if it is synonymous with evolution. Natural selection can only operate on something that confers an immediate reproductive benefit. Period. I have had people say to me that natural selection is also about survival and not just reproduction. But look closely again at my definition. A dead organism is not going to be very good at reproduction, is it? Thus, survival is a subset of reproductive \u0026ldquo;fitness,\u0026rdquo; and only insomuch as the organism can survive long enough to reproduce.\nPutting these two keys together, we end up with the basic concept behind the false theory of evolution: undirected genetic variations eventually lead to changes that confer a reproductive benefit, and those genetic variations get passed onto the next generation. Expanding on it a little more, some variations that do not confer a reproductive benefit just so happen to \u0026ldquo;stick\u0026rdquo; and eventually lead to other processes, organs, and appendages that may or may not confer a reproductive benefit.\nThat\u0026rsquo;s it. That\u0026rsquo;s all there is to it. Some call it elegantly simple, but I call it goofy. It is an interesting theory, but it\u0026rsquo;s continually being squeezed out of the realm of \u0026ldquo;scientific fact\u0026rdquo; by the utter lack of evidence for it, as well as evidence that vigorously contradicts it. There are many out there who believe in evolution who do not even understand it. Let\u0026rsquo;s help them to understand it, and then understand why it is a lie and an unscientific hoax. Then we can lead them to the truth: that Jesus Christ the the Creator of all life on earth.\n","date":"8 August 2011","externalUrl":null,"permalink":"/articles/what-evolution-isnt/","section":"Articles","summary":"","title":"What Evolution Isn't","type":"page"},{"content":"","date":"1 August 2011","externalUrl":null,"permalink":"/tags/irqbalance/","section":"Tags","summary":"","title":"Irqbalance","type":"tags"},{"content":"If you are running XenServer 5.6 FP1 or later, there is a little trick you can use to improve network throughput on the host.\nBy default, XenServer uses the netback process to process network traffic, and each host is limited to four instances of netback, with one instance running on each of dom0’s vCPUs. When a VM starts, each of its VIFs (Virtual InterFaces) is assigned to a netback instance in a round-robin fashion. While this results in a pretty even distribution of VIFs-to-netback processes, it is extremely inefficient during times of high network load because the CPU is not being fully utilized.\nFor example, suppose you have four VMs on a host, with each VM having one VIF each. VM1 is assigned to netback instance 0 which is tied to vCPU0, VM2 is assigned to netback instance 1 which is tied to vCPU1, and so on. Now suppose VM1 experiences a very high network load. Netback instance 1 is tasked with handling all of VM1’s traffic, and vCPU0 is the only vCPU doing work for netback instance 1. That means the other three vCPUs are sitting idle, while vCPU0 does all the work.\nYou can see this phenomenon for yourself by doing a cat /proc/interrupts from dom0’s console. You’ll see something similar to this:\n(The screenshot doesn’t show it, but the first column of highlighted numbers is CPU0, the second is CPU1, and so on. The numbers represent the quantity of interrupt requests.)\nIf you’ve ever troubleshot obscure networking configurations in the physical world, you’ve probably run into a router or firewall whose CPU was being asked to do so much that it was causing a network slowdown. Fortunately in this case, we don’t have to make any major configuration changes or buy new hardware to fix the problem.\nAll we need to do to increase efficiency in this scenario is to evenly distribute the VIFs’ workloads across all available CPUs. We could manually do this at the bash prompt, or we could just download and install irqbalance.\nirqbalance is a linux daemon that automatically distributes interrupts across all available CPUs and cores. To install it, issue the following command at the dom0 bash prompt:\nyum install irqbalance --enablerepo base You can either restart the host or manually start the service/daemon by issuing:\nservice irqbalance start Now restart your VMs and do another cat /proc/interrupts. This time you should see something like this:\nThat’s much better! Try this out on your test XenServer host(s) first and see if you can tell a difference. Citrix has a whitepaper titled Achieving a fair distribution of the processing of guest network traffic over available physical CPUs (that’s a mouthful) that goes into more technical detail about netback and irqbalance.\n","date":"1 August 2011","externalUrl":null,"permalink":"/2011/08/improving-network-throughput-in-xenserver-using-irqbalance/","section":"Posts","summary":"","title":"Using IRQbalance to Improve Network Throughput in XenServer","type":"post"},{"content":"Deploying CAG with Web Interface 5.4 is actually very easy, there are just some “gotchas” that you have to be ready for. This is a guide to help you avoid those snags and pitfalls that commonly occur with a CAG VPX and Web Interface integration.\nI recommend getting the Citrix Access Gateway VPX Getting Started Guide and HDX Remote Access Guide with Citrix Access Gateway VPX Express if you don’t already have them. The former document contains some inaccuracies but is has some useful reference info as well. The latter takes you through the fundamental setup of the CAG VPX and gets you to the web administration console, where most of the meaty configuration will take place.\nThere are some assumptions I’m making with this guide since it is based on my own requirements. They are:\nThe CAG VPX has two virtual NICs, external to service external users, and internal for management and communication with the XenApp servers Two logon points will be configured: One that allows user authentication to take place at the web interface, and another that uses RADIUS The CAG VPX will not reside in a DMZ. If your situation requires it to reside in a DMZ, setting it up is trivial once you’ve gotten everything else working. You’ve already got the CAG VPX appliance imported and running, but not configured You have your web interface server setup, with no websites configured. You have installed the CAG VPX license on a Citrix license server Also, a word of warning: Configuring CAG VPX with Web Interface is like playing chess. Every move you make will affect all of your successive moves. In areas where I suspect your setup might require you to deviate from this guide, I’ll offer some pointers to help you make the right move.\nLet’s get started! First, follow the Getting Started guide to configure the management interface for the CAG via the VM console. If you are unsure about a setting, just take the default by hitting Enter.\nOnce you have your management IP assigned, you’ll need to access the web administration console by browsing to https://[IP address]/lp/adminlogonpoint . Login with the default username and password “admin”. You’ll see a nice dashboard with two dials and some nasty looking red X’s. Click on the Management tab. This will take you to the Networking portion of the System Administration menu group.\nHere, enter the CAG’s hostname as an FQDN. You’ll see a list of your network interfaces (eth0, eth1, etc.) with one of them having the management IP address you assigned. To the right, there are four checkboxes labelled Internal, External, Appliance Failover, and Management.\nMoving from left to right, the interface that will be used to connect to your XenApp servers should have the Internal checkbox checked.\nThe interface for management should already have the Management checkbox checked.\nThe interface that will be receiving external requests from end users should have the External checkbox checked.\nIf need be, your Internal and External interfaces can be the same. Make sure your DNS servers have an entry for your Internal IP!\nUnder the Default Gateway section, select the interface the CAG should use to route traffic for subnets to which it is not directly connected. This will probably be your External interface. Remember, the CAG has a direct connection to the subnet your XenApp servers are on, so it doesn’t need a gateway to get to those. But it does need a gateway to get back to your external users who are connecting from the Internet!\nClick Save and restart the appliance using the big Restart button on the top right.\nLog back into the web administration console and browse to Management \u0026gt; Name Server Providers. Enter your DNS servers and DNS suffixes.\nNow go to Static Routes in the System Administration menu. Do you need a static route? If you plan on putting the CAG VPX into a DMZ later, go ahead and enter your static routes. Gateways you specify for static routes will take precedence over the default gateway you specified earlier. Remember, it does not hurt to add them now.\nNow Browse down a few rows to Licensing and click Configure. Select the Licensing type and Remote Server for the licensing server. Enter the FQDN or IP of your Citrix licensing server, and click Save. The CAG will attempt to grab its licenses and upon a successful retrieval, it will display them as shown:\nNB: If the CAG is unable to retrieve the licenses, I recommend stopping and troubleshooting until it is able to successfully pick up the licenses. You can continue your configuration, but you will not be able to test it until the license issue is resolved.\nMoving right along, click on Authentication Profiles under the Access Control menu group. It’s time to add a RADIUS authentication profile! But before you do that, you have to set up a RADIUS server. I recommend reading How to Configure Radius Authentication/Authorization on Windows 2008 for Use on Citrix Access Gateway Standard Edition. (One caveat, however: don’t perform steps 13-17 in the KB article because they’re unnecessary and will cause problems.) Click Add and enter a name for the Authentication Profile. Click New and add your RADIUS server(s) and shared secret. Leave everything under Group Authorization as-is. You’re relying on the RADIUS server to check group authorization.\nNow go to XenApp or XenDesktop under Applications and Desktops and enter the IP ranges of clients that can access XenApp servers via ICA and CGP. I really don’t know why there isn’t a checkbox that allows you the equivalent of a “permit ip all”, but there isn’t.\nNext, click Secure Ticket Authority. These settings are arguably the most common cause of application launch issues. Select your STA servers carefully, and make sure all your XenApp servers have unique STA ID’s! If you are running Provisioning Services and streaming XenApp, read before proceeding. Once you are sure your STA IDs are unique, click New and enter the FQDN of each XenApp server that will be providing STA services. By default, the connection type is Secure, but I’m guessing your XenApp servers are not using SSL for STA traffic, so select Unsecure. Leave everything else as-is and click Add. Note the servers you selected here, because you will need them later.\nAt this point you can go ahead and restart the CAG VPX appliance, because it’s now time to do some work on the Web Interface (WI) side. Log into your WI server, launch the Citrix Web Interface Management console, and create a new site.\nShould we do the easy one or the hard one first? Trick question. They’re both easy! We’ll set up a site to be used with RADIUS authentication. Click Create Site under the Actions pane on the right, name the website however you wish and click Next. Select “At Access Gateway” as the point of authentication and click Next. Here you’ll be greeted with an intimidating looking Authentication Service URL field. But as I said, this is easy! Just enter https://[cag-FQDN]/CitrixAuthService/AuthService.asmx and click Next, Next. After a few moments, your site will be created.\nRight-click the site in the XenApp Web Sites list and select Server Farms. Configure your XenApp servers like you normally would in WI. There is nothing here unique to CAG.\nNow right-click the site again and select Secure Access. Select the only item in the list and click Edit. Change Access method to Gateway direct and click Next. Next you’ll be asked for the address of the CAG. Enter the FQDN of the CAG, and optionally enable or disable session reliability. If enabled, you can request tickets from two STAs (A word on this option: When you setup a site for Citrix Receiver, this checkbox must be unchecked. This site you are creating now cannot be used for Receiver, so don’t worry about it here if you plan to use Receiver.) Click Next.\nRemember I said to note the XenApp servers you entered into the CAG VPX as your STA servers? Web Interface wants to know about these servers too. Click Add and enter the URL of the first XenApp server you entered into the CAG in the following format:\nhttp://xenapp1.baconfactory.net/scripts/ctxsta.dll\nI still do not know why it doesn’t just ask for the FQDN and assume the rest like the CAG does, but that’s how it is. Do this for all STA servers you entered into the CAG, and in the same order. Check, double check, and triple check the URLs! Also optionally change the “Bypass failed servers for” option to 1 minute. Click Finish.\nAre we done? Almost. The CAG should be back up now, so log back into it. Click Logon Points under Access Control and click New. Now don’t be intimidated by all the settings. We only care about four things here. Enter the name of the logon point. Select this name carefully because it is what users will have to type in to connect to the CAG. If you enter “cag-logonpoint1” then users will have to go to https://yourcag.yourdomain.com/lp/cag-logonpoint1 which just looks ugly! Under Type select Basic. In the Web Interface field, enter the URL of the web interface site you created (no trailing slash). Under Authentication Profiles, select the RADIUS authentication profile you created earlier. Finally, check the “Single sign-on to web interface” check box and click Save.\nNow, we are almost ready to test. But to save ourselves from a disappointing moment of temporary CAG dysfunction, click on Secure Ticket Authority again. Do you see unique STA IDs populated next to each of your XenApp servers? If not, troubleshoot until you do. If so, it’s time to test!\nBrowse to the logonpoint you just created. If you named your logonpoint “test1” and your CAG’s FQDN is yourcag.yourdomain.com, browse to https://yourcag.yourdomain.com/lp/test1.\nDo you get an SSL certificate error? Probably so. I intentionally did not cover installing a certificate because it introduces another level of complexity into the configuration. SSL Certificates are dependent on the hostname, and the hostname you use to connect to the CAG to enumerate and launch apps has to match up with the hostname on the SSL certificate. The certificate also must be signed by a trusted certificate authority. Unless you have your own certificate authority, getting a signed certificate can be a pain. Unfortunately, connecting to CAGs using untrusted SSL certs causes a lot of problems. You may encounter some of these problems or you may not. Test anyway. If you do run into problems, the good news is that the heavy lifting of configuring the CAG is done.\nNow, it’s time for a moment of truth. Once you’ve gotten a login prompt, log in with an AD account that has appropriate authorization. You may need to specify the user in UPN or down-level domain format. It depends on your AD environment, but one of those should work. If you have trouble authenticating, first check the logs on the RADIUS server to make sure the denial is not occurring there. If you continue to have issues, it’s time to get acquainted with what will become your new best friend: the CAG debug log. The CAG debug log is at your service at https://yourcag.yourdomain.com/admin/d/?req=DebugLog . Watch it for any FLEXnet or STA errors.\nOnce you get logged in, try launching a published app. If all goes well, you should see something like…\n","date":"29 July 2011","externalUrl":null,"permalink":"/2011/07/deploying-citrix-access-gateway-vpx-with-web-interface-5-4-cag-setup-with-radius/","section":"Posts","summary":"","title":"Deploying Citrix Access Gateway VPX with Web Interface 5.4 – CAG Setup with RADIUS","type":"post"},{"content":"Atheists and materialists have a chronic problem. No, not the kind you see prescription drug commercials for. Their problem is that they hold internally inconsistent beliefs.\nWhat\u0026rsquo;s that mean? It means some of their own beliefs contradict some of their other beliefs. Their own believes contradict one another. Some examples:\nThe atheist says that you can only know what your five senses tell you…\nWell, which of the five senses tells him that?\nThe materialist says his beliefs are founded on logic and reason\u0026hellip;\nUm, then what are his beliefs in logic and reason founded on? Logic can\u0026rsquo;t be founded on itself, neither can reason.\nThe atheist says the only thing that exists is the material world\u0026hellip;\nSo the atheist must not believe in consciousness, information, or logic, because those things are non-material.\nAt almost every turn, the atheist contradicts himself. He moans about all the pain and suffering in the world, but he cannot justify his concern. Why is suffering bad? Is it because most people think it\u0026rsquo;s bad? That\u0026rsquo;s not a rational argument. What if most people were masochists and considered suffering good? Would that then make it good? That\u0026rsquo;s a poor argument, and certainly not a well reasoned one! For if the definition of bad depends on majority opinion, then the word \u0026ldquo;bad\u0026rdquo; simply becomes a synonym for \u0026ldquo;unpopular.\u0026rdquo;\nThe atheist and materialist are stuck. They believe in non-material things like information, consciousness, and logic, but they contradict themselves by saying that only the material world exists. Which is it? If you believe in logic, you can\u0026rsquo;t believe that it\u0026rsquo;s simultaneously both material and non-material. The choices are mutually exclusive.\nEither you believe that only the material world exists, or you believe a world outside of the material world exists.\nSome atheists will now proceed to try to argue that consciousness, logic, and information are somehow material, or that they are illusions. Uh-oh, but an illusion isn\u0026rsquo;t material either! They could say that consciousness is material, but that would be an irrational argument because no one has ever seen, touched, heard, tasted, or smelled consciousness. The atheist is back in a catch-22! He has to either admit that the non-material world exists, or he has to again contradict his own beliefs by affirming belief in something that is material, but undetectable by his five senses.\nWhat the atheist begins to realize is that the more he tries to justify his position, the more ridiculous he sounds. Rather than reversing course and rethinking his entire worldview, the typical atheist cops out and tries to claim that some things just cannot be known. To which a sharp observer would reply, “How do you know that?\u0026quot; The atheist has no valid answer. He is again making a claim on grounds which his own worldview forbids.\nThe atheist and materialist are trapped. They retreat just a bit and begin running around the rim of nihilism, claiming that one can know almost nothing. This is their excuse. Rather than throw out their entire worldview and consider a different one, they cling tightly to their materialism but give themselves a convenient disclaimer they use to avoid addressing their internally inconsistent beliefs.\nThe fool says in his heart, \u0026ldquo;There is no God.\u0026rdquo;\n","date":"29 July 2011","externalUrl":null,"permalink":"/articles/atheists-materialists-guilty-nihilism/","section":"Articles","summary":"","title":"Are Atheists and Materialists Guilty of Nihilism?","type":"page"},{"content":"If we start with the Biblical Creation account in the book of Genesis, then take everything we know from the various fields of science including biology, genetics, mathematics, and physics, and discard all our assumptions and theories, what we will find is that the facts line up perfectly with the view that God created the world and all kinds of life in six literal days roughly 6,000 years ago.\nThe scientific approach to an idea is to gather as many facts as possible and then find the best explanation for those facts. This is something evolutionists fail miserably at. Darwinian evolutionists are very good at passing the buck to other fields of science. For example, if you ask an evolutionary biologist for solid, incontrovertible evidence that all life originated with a common ancestor, he will not be able to give you any. Instead, he will point to another field of science, like geology, and tell you to look there. If you go to an evolutionary geologist and ask him for evidence for evolution, he will point you to another branch of science, like biology. Proponents of evolution know nothing else than to pass the buck. And if you back one of them into a corner and demand evidence from the particular field of science that they are expert in, they will perform the classic “appeal to authority\u0026quot; tell you about all the people who believe in evolution. How embarrassing!\nGood creation scientists, on the other hand, can present scientific evidence in their field of expertise for the Special Creation outlined in Genesis. A good Creationist will not pass the buck, but will give you hard evidence for Biblical Creation. And when he’s done, he’ll encourage you to look at other branches of science to further validate the evidence he’s already given. This is the fundamental difference between Evolutionary scientists and Creation scientists. Only the Creation Scientists are armed with facts and evidence to bolster their position.\nThis really shouldn’t come as a surprise. Most people are indoctrinated with the science-fiction of Darwinian evolution practically from birth. Since these people assume evolution to be true anyway, evolutionary scientists get a pass at every turn. They almost never are asked to provide evidence. Creation scientists, on the other hand, are constantly having to battle against the widespread evolutionist propaganda and blatant falsehoods that are being taught as science, while at the same time having to defend the tired, predictable attacks against Christianity in general.\nIt is not enough to claim evidence for a theory. You must present the evidence and defend it in the face of scrutiny. Evolutionists hate being challenged on their evidence because they know how flimsy it is. Creationists welcome the challenges because they provide an opportunity to share the truth.\nThe theory of Evolution is about the variety of different kinds of life, not about the origin of life itself. Evolution assumes life, but does not explain it. While the term \u0026ldquo;evolution\u0026rdquo; is used to describe a lot of different things, in this context, it means only what I just explained.\nCreationism begins with no life and no Earth, and holds that God created the Earth and all the various kinds of living things. I think of the term “kinds\u0026quot; as synonymous with the term \u0026ldquo;genus.\u0026rdquo; (But \u0026ldquo;kinds\u0026rdquo; does not mean “species\u0026quot; which is a very poorly defined term itself.)\nFrom the above we see that Creationism and Evolution overlap in some areas, and in other areas they are mutually exclusive. Thus, we can make the following assertion:\nIf Creationism is true, Evolution must be entirely false.\nIf Evolution is true, Creationism must be at least partially false.\nCreationism and Evolution are historical claims, not just scientific claims. But science can be used to validate or invalidate these claims. This is a hugely important point most people miss. We are not talking about something like the boiling point of a liquid which can be tested by experimentation. We are talking about something that happened in the past and is not happening in the present in any observable fashion.\nNow, here is another fundamental difference between the two: Creationism specifically claims that God created, and then stopped creating. The theory of Evolution claims that evolution is still occurring. From a scientific standpoint, we should be able to test whether or not new kinds of living things are evolving. And guess what? They are not. Hence, the only part of Evolution that can possibly be tested has been tested and has been shown to be false. Thus, we still must conclude that both Creationism and Evolution are historical claims.\nBut not only are they both historical claims, they are quite different in terms of detail. In Genesis, Moses goes into great detail about the chronological order, duration, and hierarchy of Creation. The Theory of Evolution, however, simply states that all kinds of living things originated from a common ancestor. It does not specify an order or a chronology. Incidentally, if we can demonstrate the Earth is roughly the same age as recorded human history, we can have a high confidence that undirected evolution did not occur.\nThus, Creationism theoretically makes itself more vulnerable to being invalidated than Evolution. Why? Because the more claims you make, the more right you better be. If you are telling the truth, you can make all the claims you want and not have to worry. But if you are lying, each claim you make is another soft spot that your adversary can target.\nSo how do you validate or invalidate an historical claim? Look at the evidence from all relevant sources, and look at it holistically. Does each piece of evidence agree with every other piece of evidence, and with a particular theory? If so, that theory is likely correct. Is there an incontrovertible piece of evidence that absolutely invalidates a theory? If so, that theory is absolutely incorrect, even if other pieces of evidence seem to validate it.\nEvolution seems so simplistic and overly broad, is there really anything there to validate? Yes, but not much. We certainly have no written records indicating descent from a common ancestor. We have never observed one kind of animal giving rise to another kind. The fossil records show discrete plants and animals, but no obvious transitional forms. These are all irrefutable pieces of evidence that invalidate Evolution.\nBut is there any evidence that can validate Evolution? Some claim that genetic similarities among different kinds of animals is evidence, however, this does not suggest a common ancestor any more than all living things being carbon-based does. A common similarity does not imply a common ancestor. Also, there is more than sufficient evidence to invalidate Evolution, so a single, flimsy piece of evidence for it is coincidental at best.\nOn to Creationism. An analysis of mitochondrial DNA from the human genome suggests the first woman lived around 6,000 years ago, roughly 4,000 B.C.\nCarbon-14 (14C), a radioactive element with a half-life of less than 6,000 years, is present in animal fossils all over the world in amounts that suggest recent Creation. There is currently no other explanation for the amount of 14C present.\nT-rex fossils have been found with soft-tissue (biological tissue) still in them, suggesting an age of less than 10,000 years.\nNickel, a rare earth element, collects on the Earth’s crust from falling meteorites. If the Earth were orders of magnitude older than the Genesis Creation account suggests, there would be a lot more nickel than there is today.\nThere is also another piece of evidence for Creation: the utterly Divine authorship of the Scriptures. If the Holy Scriptures are inspired by the Creator Himself, then the Creation account is true. That is for another post, but it is ultimately more powerful than any other piece of evidence.\n","date":"27 July 2011","externalUrl":null,"permalink":"/articles/biblical-creation-account-genesis-theory-evolution/","section":"Articles","summary":"","title":"The Biblical Creation account of Genesis and the Theory of Evolution","type":"page"},{"content":"","date":"25 July 2011","externalUrl":null,"permalink":"/tags/ardence/","section":"Tags","summary":"","title":"Ardence","type":"tags"},{"content":"Citrix Provisioning Services is very nice, but it does come with a slightly annoying quirk: All of your provisioned XenApp servers end up with the same STA ID! This will cause all sorts of problems for Citrix Access Gateway, Citrix Receiver, and anything else that may depend on having unique STA IDs. The good news is that fixing this little problem is easier than you might think.\nTo resolve the duplicate STA ID issue, we’ll do the following:\nCreate personality strings in Provisioning Services for each XenApp server\nPut a PowerShell script on our golden image\nCreate a startup task to execute the PowerShell script\nLet’s begin:\nThe format of the STA ID is simple. It is “STA” followed by the MAC address of the XenApp server’s NIC. The STA ID can really be anything beginning with “STA”, so you could get creative and have “STABLEFLY”, “STANK”, “STALE”, “STARTBUTTON”, “STACKOVERFLOW”.. and the list goes on. But I recommend sticking with the MAC address because it’s unique (usually), and is easy to match up.\nIn Provisioning Services, create a personality string for each server with the Name “UID” and the String “STA001122DDEEFF”, substituting the MAC address of the server for the hex I just threw in there. Copy this PowerShell script to your scripts location on your golden image: (Note: Download the file from the above link and do not copy and paste the text below, otherwise PS will complain.) \\# STA Replacement Script for Citrix Provisioned Servers \\# Created 7-25-11 by Ben Piper (email: ben@benpiper.com, web: http://benpiper.com ) \\# Get UID string \\# Replace STA ID \\# Restart CTXHTTP service $stastr = get-content C:\\Personality.ini | Select-String -Pattern \u0026amp;#8220;UID=STA\u0026amp;#8221; $CtxStaConfig = Get-Content \u0026amp;#8216;C:\\Program Files (x86)\\Citrix\\system32\\CtxSta.config\u0026amp;#8217; | ForEach-Object {$_ -replace \u0026amp;#8216;^UID=.+$\u0026amp;#8217;, $stastr} $CtxStaConfig | Set-Content \u0026amp;#8216;C:\\Program Files (x86)\\Citrix\\system32\\CtxSta.config\u0026amp;#8217; Stop-Service CtxHTTP Start-Service CtxHTTP Create a scheduled task to execute the PowerShell script at startup. Make sure the account that will be executing the script has appropriate permissions. If you are not already running PowerShell scripts, you’ll need to set the ExecutionPolicy on your gold image to Unrestricted by issuing the cmdlet ” Set-ExecutionPolicy Unrestricted” at a PS prompt.\nI recommend testing the script first on your Master Target server before deploying it farm-wide. The script will still work as long as you have a personality string defined for your Master Target server, even if the vDisk is in Private mode.\n","date":"25 July 2011","externalUrl":null,"permalink":"/2011/07/how-to-get-a-unique-sta-id-for-each-of-your-provisioned-xenapp-servers/","section":"Posts","summary":"","title":"How To Get a Unique STA ID for each of your PVS Provisioned XenApp Servers","type":"post"},{"content":"As both major political parties in the US continue to look more and more like carbon copies of each other, there is a political movement that is picking up steam, especially among traditional Conservatives.\nThat movement is libertarianism, and it is essentially a hybrid of conservative and liberal politics. Libertarians support conservative economic values such as low taxes and minimum government regulation of the economy. But they also support liberal/left-wing positions on social issues such as abortion and illegal drugs. In other words, libertarians are moral-relativists. They do not believe in absolute right and wrong.\nMoral Relativism # Many Conservatives are almost magnetically drawn to libertarianism because, on the surface, it seems to align with what they already believe. Low taxes, free market capitalism, and a small, non-intrusive Federal government are the points that libertarians and Conservatives all agree on. And in most conversations with a libertarian, social issues never come up. Most everyone is so preoccupied with the economy that they have placed it at the top of the list, well above social issues like abortion. During the rare times a Conservative expresses a moral absolute to a libertarian, the libertarian reacts much like a slug reacts to salt being dumped on its slimy back. He squirms, winces, and tries to get away. Retired libertarian talk-show host Neal Boortz refused to allow the word \u0026ldquo;abortion\u0026rdquo; to even be mentioned on his show and avoided the topic altogether. Many libertarians react the same way. Libertarians are generally fearful of any discussion about absolute morality or religion. I think most Conservatives recognize the libertarian\u0026rsquo;s moral relativism, but they push it to the back of their minds.\nPolitics as a Religion # Libertarianism and liberalism/leftism have one thing in common: They both treat politics as a religion. In the leftist mind, the party collective is the arbiter of right and wrong, good and evil. In the libertarian mind, the individual decides what is right and wrong, and has no duty or right to impose his views on anyone else. Both liberalism and libertarianism strictly prohibit any connection between apolitical religious principles and the state. Political religious principles, however, such as equal justice under the law, and innocent until proven guilty, are allowed.\nLegislating Morality # Libertarianism is seducing Conservative Christians into supporting an amoral political philosophy. Many self-proclaimed Conservatives are quite liberal when it comes to social issues. They will promise to help restore the economy, but they will not support any laws to end abortion. They will affirm their commitment to lower taxes, but they will not do anything to stop p-rnography from littering the airwaves. In fact, they will even support the imaginary \u0026ldquo;right\u0026rdquo; of others to practice abortion and exploit women, because they aren\u0026rsquo;t in the business of legislating morality. Or so they say.\nThe stark reality is that all laws legislate morality. It is against the law to steal because it violates the right to private property. And violating another person\u0026rsquo;s God-given rights is absolutely wrong. Absolute morality is the foundation of all law. Law in and of itself is not an authority, but it supposes to receive authority by virtue of being based on morality. No law can withstand reason if it is based on the arbitrary will of a legislator.\nLaw must be discovered through morality. This is where the libertarian worldview begins to crumble. Even though libertarians proclaim the inherent rights of humans, they arbitrarily limit those rights to people who are not in utero, that is, unborn babies. Furthermore, they contend that each person owns himself, and can therefore do whatever he pleases with his own body. This, too, directly contradicts another libertarian view, that the government has a right to force a person to act against his will in certain cases. The libertarian philosophy is internally inconsistent. It does not even agree with itself.\nSince all laws should be derived from moral principles, it stands to reason that those moral principles will work in favor of that which those laws hope to achieve. This is a brief but powerful truth that we all would do well to remember. Said differently: If we speak out against the very moral principles that our laws are based on, that which our laws were designed to achieve will ultimately fail.\nIt\u0026rsquo;s not the Economy # What this means is that if our laws are based on Biblical moral principles, and the goal of those laws is to achieve a positive economic outcome, then speaking out against (or remaining silent) on moral/social issues will necessarily result in a poor economic outcome. Why? Let\u0026rsquo;s look at some examples.\nPeople are necessary for any strong economy. Some of our laws are designed to protect and empower people to succeed and prosper according to their talents, skills, and efforts. These laws are based on Biblical moral principles. But there are other laws that confer legal protection to those who murder people—unborn children, children which would otherwise grow up, join the workforce, and further strengthen the economy.\nYou would think that most Conservative politicians would gladly support the pro-economy and pro-life legislation. But, no, they would rather avoid the moral issues altogether, even when it makes no sense to do so. Why? Because our country has become scared to death of the idea of absolute morality. Absolutely terrified of it. Even Christians will refrain from taking a moral stand on a fundamentally moral issue like abortion or p-rnography. Conservative voices like Rush Limbaugh and Sean Hannity became hushed on moral issues a long time ago, preferring to adopt a libertarian stance and avoiding talk of morality altogether. And when a moral issue does come up, most people say they\u0026rsquo;d rather focus on the economy instead. South Carolina Senator Tim Scott exemplified this false dichotomy recently when he wrote:\nThe issue of same-sex marriage was decided by the Supreme Court. Working families are being crushed by inflation, high gas prices, and economic uncertainty. Right now, I am uniquely focused on helping vulnerable Americans by enacting responsible economic policies and shutting down reckless spending proposals.\nHe\u0026rsquo;s too busy to even discuss moral issues because he\u0026rsquo;s \u0026ldquo;uniquely focused\u0026rdquo; on money. Such excuses are all too common. Any philosophy that separates morality from economics is dangerous and counterproductive. Libertarianism is a convenient trap for Conservatives, but it is still a trap. Instead of giving into the increasingly popular movement, align yourself with the Truth of God\u0026rsquo;s Word and His views on politics and government. We will see little economic improvement until we bite the bullet and deal with the real problems plaguing our nation. And they are all moral problems.\n","date":"24 July 2011","externalUrl":null,"permalink":"/articles/libertarian-deception/","section":"Articles","summary":"","title":"The Libertarian Deception","type":"page"},{"content":"If God were to restrain every person from doing anything evil, not only would He have to put everyone in a veritable strait jacket, He\u0026rsquo;d also have to lobotomize everyone and literally turn every human being on the planet into a robot.\nIf God miraculously provided food for every child, many parents would stop feeding their kids. If God hugged and coddled every child, many parents would spend less time with their children. If God did everything we can do ourselves, we would become more selfish than we are now.\nWhy doesn\u0026rsquo;t God cure every disease? Diseases are caused by either behavior or a broken genome. Why doesn\u0026rsquo;t God just fix the human genome and make it perfect? He\u0026rsquo;d then have to protect it from becoming corrupted again, but why wouldn\u0026rsquo;t He do that? Come to think of it, why doesn\u0026rsquo;t He just stop all death? Of course, that would mean He\u0026rsquo;d have to stop all suicide and self-starvation. He might as well just bring us all into Heaven! But if He just let everyone into Heaven, wouldn\u0026rsquo;t things be pretty much the same as on Earth? It\u0026rsquo;s not like people undergo a \u0026ldquo;reboot of the soul\u0026rdquo; when they go to Heaven. They\u0026rsquo;re still the same people. If God let everyone into Heaven, Heaven would become Earth (a.k.a. \u0026ldquo;Hell Lite\u0026rdquo;). That is not an option, and turning everyone into a robot is not an option.\nTo answer the question of why doesn\u0026rsquo;t God stop all the pain, evil, and suffering in the world?: It is an all-or-nothing proposition. You either expect God to fix all of it, or do nothing. If He only partially fixed this broken world, people would be demanding that He do more.\nSo why doesn\u0026rsquo;t He just fix it all? Because to fix it all would mean casting the vast majority of the world\u0026rsquo;s population into Hell in one fell swoop. He doesn\u0026rsquo;t do that because He is merciful and desires that all come to repentance. He is patiently waiting for us to close our mouths, open our eyes and ears, and surrender to Him. He doesn\u0026rsquo;t want anyone to go to Hell, but anyone who pretends He doesn\u0026rsquo;t exist isn\u0026rsquo;t leaving Him much choice. Would you like to live with someone who lives as if you don\u0026rsquo;t exist, and speaks of you as if you are a fictional character? God is not mocked. He will not tolerate anyone who doesn\u0026rsquo;t acknowledge His existence, which He has clearly shown through His Creation and the evidence of the Bible.\nIf He just erased all the pain and suffering in the world, most of the world would still reject Him, and probably more than reject Him now. If the world were perfect, most people would not even give God a second thought. But because the world is so obviously broken, people are forced to ask why. They are forced to look to the Creator.\nFar from condemning God, the \u0026ldquo;argument from suffering\u0026rdquo; viciously condemns those who make it.\n","date":"24 July 2011","externalUrl":null,"permalink":"/articles/why-god-doesnt-stop-pain-evil-suffering/","section":"Articles","summary":"","title":"Why Doesn't God Stop All the Pain, Evil, and Suffering in the World?","type":"page"},{"content":"Your user is happily working in your published, seamless application via XenApp 6 running on Windows Server 2008 R2, and life is good.\nThen one day, when your user goes to print something, he is looking at the print dialog and notices this “Microsoft XPS Document Writer” printer as an option.\n“HMM I wonder what this does?”\nHe views the printer Preferences and…\n“Go online” are two words you do not want your users to see on a Citrix server. Your user, of course, has an irresistable urge to click the link.\nYour user thinks, “XML Paper Specifiation Overview? This looks interesting.. NOT! Let’s watch some videos!” A few more clicks, and…\nYour user is now on Youtube watching how-to videos about other great ways to elevate his privilege and bog down your pristine XenApp 6 server with garbage.\nHow do we fix this? As I’m sure you’ve already considered, web filtering would be a good idea to mitigate the damage an Internet-bound user can mete out on your infrastructure. There are other good reasons to block or regulate web access from your Citrix servers as well. Even server admins are not immune from falling victim to a zero-day exploit while on the web.\nYou may have also noticed that, in this case, the user’s access was severely restricted even within Internet Explorer. I used group policies to strip away the bells and whistles and enforce additional restrictions on the user. The user has no access to a published desktop or a command line or “Run” prompt.\nIn some environments, it is practical to just set file-level permissions on the Internet Explorer executable and deny access to everyone. But chances are there are some published applications that require a browser launch, even if it is only intermediate.\nThere is something else we can do. First, unless you really need it, uninstall the Microsoft XPS Document Writer. This can easily be done from an administrative shell with the commmand:\ncscript C:\\Windows\\System32\\Printing_Admin_Scripts\\en-US\\prnmngr.vbs -d -p “Microsoft XPS Document Writer”\nThe script will forcibly delete the printer for everyone. But you’re not done yet. Let’s take a second look at the print dialog box the user sees.\nYou’ll notice the user has a session mapped local printer for the XPS Document Writer on his machine. If he views the Preferences for this printer, he will get the exact same properties window he got before.\nWe could remove the XPS driver package, but if you are allowing automatic installation of native drivers on your Citrix servers, Windows will just reinstall it.\nWe need to force the user’s session mapped XPS Document Writer to use a different driver that doesn’t invite them to surf the web from our datacenter. Fortunately Citrix, drawing on their experience in working around Microsoft’s various incarnations of FAIL, has provided us a very nice solution: The Citrix XPS Universal Printer driver.\nLet’s open up our Citrix user policies in Group Policy Management. In this case, there is a separate policy that controls printers. Browse to Printing \u0026gt; Drivers…\nEdit the “Printer Driver Mapping and Compatibility” option and click the Add button…\nEnter the name of the printer driver (“Microsoft XPS Document Writer”) and set the policy to create the printer with the universal driver only.\nNow when the user goes to view the preferences of his locally mapped XPS Document Writer, all he gets is the boring Citrix print dialog, free of any web links!\n","date":"15 July 2011","externalUrl":null,"permalink":"/2011/07/how-microsofts-xps-driver-lets-citrix-xenapp-users-get-on-the-internet-and-how-to-lock-it-down/","section":"Posts","summary":"","title":"How Microsoft’s XPS Driver Lets Citrix XenApp Users Get on the Internet (and how to lock it down)","type":"post"},{"content":"Have you ever wondered how scientists calculate the age of dead plants and animals? This is a topic that has fascinated me for many years, because while it may sound very simple and straightforward on the surface, as you will see, it is really a rabbit hole that leads into all sorts of unexpected places. Come with me as we explore the strange, bizarre world of Carbon-14 dating…\nLet me start with an explanation of what Carbon-14 dating is. Like all empirical testing methods, Carbon-14 dating is based on a few assumptions (you have to start somewhere, right?) Almost all land-dwelling plants and animals absorb two elements from the environment: Carbon-12 and Carbon-14, a radioactive element formed in the upper atmosphere. The ratio of Carbon-12 to Carbon-14 is assumed to be constant. When a plant or animal dies, the Carbon-12 remains constant, but the Carbon-14, since it is radioactive, continues to decay (into Nitrogen-14). Since the Carbon-14 is not being replenished, the total amount of it reduces linearly over time.\nThe original idea behind Carbon dating was to deduce the age of an organism by looking at the amount of Carbon-14 left in it and calculating its age based on the time it should have taken for the missing Carbon-14 to decay. Pretty logical and straightforward, right?\nBut there is a problem. The assumptions are wrong.\nThe ratio of Carbon-12 to Carbon-14 in the atmosphere has not remained constant. The amount of Carbon-14 produced in the upper atmosphere is dependent upon the amount of radiation coming from the Sun, which we know has changed significantly. On top of that, the introduction of nuclear energy and nuclear weapons have affected the ratio of radioisotopes in the atmosphere.\nWhen Carbon dating was originally introduced, scientists attempted to validate it by Carbon dating dead trees and comparing the calculated age with the known age of the trees based on their rings. What they found was that Carbon dating yielded wildly inaccurate ages for the trees.\nIn order to overcome the obviously false assumption that the ratio of Carbon-12 to Carbon-14 is constant, scientists attempted to recalibrate the function by adding a second variable: the ratio of C-12 to C-14 at any given point in time. But how could they know what the past ratios were?\nThe answer? They couldn’t, at least not without a time machine or some very old documents from an obscure scientist who was measuring radioisotopes way back when. They had two choices: Throw the entire Carbon dating system out, or make another assumption.\nThey opted for another assumption, the only possible assumption left: the age of the organism itself. In the case of dating a tree of relatively known age (based on its rings), they would have recalibrated the dating function with a C-12 to C-14 ratio that would have yielded the known correct age. And, as you would imagine, when calibrated using tree rings, Carbon dating yields fairly consistent results for anything wood or made from wood, provided it\u0026rsquo;s not more than 4,000 years old. For it’s around this time that dates yielded by carbon dating and tree ring dating begin to diverge. Why this is so is another interesting topic, which I’ll touch on later.\nBut we’re not out of the rabbit hole just yet.\nCarbon dating absolutely cannot be used to accurately date aquatic plants or animals because the amount of carbon in the ocean is vastly different than the amount in the atmosphere. This also makes Carbon dating useless for animals that eat seafood. Now here’s a fun question: What happens to the ratio of C-12 to C-12 if a living animal drowns in the ocean? Will Carbon dating be able to produce an accurate age? Probably not. The nature of animals is that they have multiple pathways to absorb elements from the surrounding environment (stomach, lungs, membranes). According to the Argonne National Laboratory,\nMost carbon-14 is almost completely absorbed upon ingestion, moving quickly from the gastrointestinal tract to the bloodstream.\nThis would mean that Carbon dating would not be very useful in an area that was victimized by a flooding sea.\nWhat about a land-dwelling plant that perished in such a flood? Would Carbon dating be able to yield an accurate date for it? Since plants get their Carbon-14 from photosynthesis alone, I think it\u0026rsquo;s possible for Carbon dating to yield an accurate date for some of the larger plants, as thy would not quickly decay over the next several hundred years, whereas smaller plants would.\nWhile Carbon dating can be a useful and valid method of dating a limited number of organisms, it lacks the robustness one would expect from alternative dating methods, such as tree rings or archaeology. There are other radiometric dating methods available, but they are also rife with similar problems. The bottom line: take such dates with a grain of salt, with the understanding that, while they could be correct, they could even more likely be completely wrong.\nRead more about how carbon dating works and about Carbon-14 and dinosaur bones.\n","date":"12 July 2011","externalUrl":null,"permalink":"/2011/07/the-truth-about-carbon-dating/","section":"Posts","summary":"","title":"The Truth About Carbon Dating","type":"post"},{"content":"Prerequisite: XenApp6 PowerShell SDK\nLet’s say you want to copy all currently published applications into a folder named “Test” in the console tree, while simultaneously modifying the new published apps with different permissions and client folder settings. Here’s how:\nFirst, create the “Test” folder by hand (you can use New-XAFolder -FolderPath Applications\\Test if you are so inclined), then use the following command to copy the applications into it:\nget-XAApplication | Copy-XAApplication -folderpath Applications\\Test Second, modify the published application properties to set the client folder (what folder the applications show up under in Program Neighborhood or Web Interface), and the permissions in one fell swoop. We’ll call the client folder “Test” and publish to the groups “domain1\\citrix admins” and “domain2\\Test Users”:\nGet-XAApplication -folderpath Applications\\Test | set-xaapplication -clientfolder Test -accounts \"domain1\\citrix admins\",\"domain2\\Test Users\" That’s it! Now doesn’t that beat right-click -\u0026gt; “Duplicate Application”?\n","date":"5 July 2011","externalUrl":null,"permalink":"/2011/07/how-to-create-xenapp6-published-applications-for-test-in-just-seconds-using-powershell/","section":"Posts","summary":"","title":"How To Create XenApp Published Applications for Test In Just Seconds Using PowerShell","type":"post"},{"content":"I ran into a little snag when executing some XenApp PowerShell commands. Certain commands like Get-XAFarm and Get-XAAdministrator would always give an “0x80060016” error. Here is an example and the fix:\n`PS C:\\Windows\\system32\u0026gt; Get-XAFarm\nGet-XAFarm : Error reading the current administrator data (0x80060016)\nAt line:1 char:11\nGet-XAFarm \u0026laquo;\u0026laquo;\nCategoryInfo : InvalidResult: (:) [Get-XAFarm], CitrixException\nFullyQualifiedErrorId : GetCitrixAdminType,Citrix.XenApp.Commands.GetFarmCmdlet` Typically this error code in Citrix indicates a problem with IMA. But in this case it was even simpler than that: IMA couldn’t resolve the hostname of the database server hosting the data store. Make sure that the correct DNS suffixes are being applied so IMA can find the server, and if that fails, just add it to the hosts file and try again.\n","date":"5 May 2011","externalUrl":null,"permalink":"/2011/05/citrix-xenapp6-0x80060016-error-in-powershell/","section":"Posts","summary":"","title":"Citrix XenApp6 0x80060016 Error In PowerShell","type":"post"},{"content":"A few days ago I booted up my rather old HP workstation which is running Ubuntu 8.04.4 LTS (Hardy Heron) and Firefox 3.6. I wanted to see how it would perform playing music from last.fm, so I browsed to the site, logged in, and tried to launch a stream.\nWell, nothing happened.\nI pretty quickly realized that Flash was not installed, at least not where Firefox could see it. After browsing around about a dozen different sites and getting a dozen different answers, I figured out how to make it work.\nFirst, you need to the Flash 10 plugin for Linux from the Adobe website (http://get.adobe.com/flashplayer/otherversions/). Be sure to get the tar.gz and not the .deb package. Use the tar xvzf [filename] command to extract the single file libflashplayer.so. This is the plugin component that you will hand to Firefox in a moment. But before you do that..\nLaunch Firefox. Open a terminal and run\nps aux | grep firefox\nYou will see something like this:\nben 6203 0.0 0.1 1776 440 ? S 20:07 0:00 /bin/sh /usr/lib/firefox-3.6.13/firefox\u0026lt;br /\u0026gt; ben 6208 0.0 0.1 1776 444 ? S 20:07 0:00 /bin/sh /usr/lib/firefox-3.6.13/run-mozilla.sh /usr/lib/firefox-3.6.13/firefox-bin\u0026lt;br /\u0026gt; ben 6212 17.3 33.9 277012 86416 ? Sl 20:07 17:11 /usr/lib/firefox-3.6.13/firefox-bin\u0026lt;br /\u0026gt; ben 6545 0.0 0.3 3012 776 pts/1 S+ 21:46 0:00 grep firefox\nNote the path Firefox is running from. In my case it is /usr/lib/firefox-3.6.13. Under this directory there should be another directory, /usr/lib/firefox-3.6.13/plugins. Copy the libflashplayer.so file into this directory (if you are not already running as root, you’ll have to do a sudo cp to copy the file.)\nChange over to this directory and do a sudo chmod 777 libflashplayer.so.\nNow, close Firefox and launch it again. Before trying to use Flash, return to the terminal and do a ps aux | grep firefox again. This time you should see something similar to the following:\nben 6375 28.2 24.0 157240 61172 ? Sl 21:11 13:57 /usr/lib/firefox-3.6.13/plugin-container /usr/lib/firefox-addons/plugins/libflashplayer.so 6212 plugin\nIf you see this, congratulations! Firefox loaded the plugin. You can also verify this by browsing to about:plugins in Firefox.\nNow, browse to your Flash-enabled website and enjoy! Remember that Javascript must be enabled for Flash to launch, so if you are running NoScript be sure to whitelist the site you’re visiting.\n","date":"9 April 2011","externalUrl":null,"permalink":"/2011/04/getting-firefox-and-adobe-flash-to-work-on-ubuntu-linux/","section":"Posts","summary":"","title":"Getting Firefox and Adobe Flash to work on Ubuntu Linux","type":"post"},{"content":"","date":"13 March 2011","externalUrl":null,"permalink":"/tags/cakephp/","section":"Tags","summary":"","title":"Cakephp","type":"tags"},{"content":"","date":"13 March 2011","externalUrl":null,"permalink":"/tags/database/","section":"Tags","summary":"","title":"Database","type":"tags"},{"content":"","date":"13 March 2011","externalUrl":null,"permalink":"/tags/development/","section":"Tags","summary":"","title":"Development","type":"tags"},{"content":"A common problem programmers have with CakePHP is saving related models with a many-to-many relationship, something Cake calls “hasAndBelongsToMany” or HABTM. One of the things that makes saving HABTM models so challenging is that when you go to save your models, Cake will act like everything saved fine when in fact only one of the models saved, or in some cases, none of them saved.\nTo illustrate how to overcome this common problem, let’s say you’ve just read Dr. Seuss’ Butter Battle Book. In the book, the Yooks eat their bread butter side up, and the Zooks eat it butter side down, and they’re always fighting about it. You decide to write a social network app to try to bring these two groups together.\nOf course, as with any respectable social network, you’ll need a way to allow Zooks and Yooks to become friends. Since a Zook can have many Yook friends, and a Yook can have many Zook friends, This will require three models in a HABTM relatonship: Yooks, Zooks, and Yooks_Zooks to join the two models together (CakePHP orders the model names alphabetically, so Zooks_Yooks would not work).\nSince Zooks and Yooks still don’t see eye-to-eye on the whole butter side orientation thing, you decide it will be necessary to write separate controllers for Zooks and Yooks. You start by creating the controller for Yooks.\nIn your first action, you want a Yook to be able to invite a Zook to the new social networking site. This will require creating a new account for the Zook on the fly, as well as linking it to the Yook’s account so the site knows they are friends.\n$this-\u0026gt;Zook-\u0026gt;create(); $this-\u0026gt;Zook-\u0026gt;ZooksYook-\u0026gt;create(); $this-\u0026gt;data['ZooksYook']['Yook_id'] = $this-\u0026gt;Auth-\u0026gt;User('id'); if ($this-\u0026gt;Zook-\u0026gt;save($this-\u0026gt;data)) {\t$this-\u0026gt;data['ZooksYook']['Zook_id'] = $this-\u0026gt;Zook-\u0026gt;id; $this-\u0026gt;Zook-\u0026gt;ZooksYook-\u0026gt;save($this-\u0026gt;data); ... } Looking at it line-by-line, the first thing we do is initialize a new Zook. Next, we have to initialize a new ZooksYook, which as you recall is the model linking Zooks and Yooks. In our ZooksYook model, we only have three fields (you could have more, but for simplicity let’s stick with three): id, zook_id, and yook_id. Since this controller is for the Yook, his user id will go into the yook_id field of the new row we want Cake to create for us in the database. That is easy enough.\nBut before we can put anything in the zook_id field, we have to know what the new Zook’s id is. He doesn’t exist in the database yet and has no id, so we have to save the Zook. Upon a successful save, we then retrieve the Zook’s id and set the zook_id field in the ZooksYook model equal to it. Finally, we save the ZooksYook model.\nThe above is a unique use case for HABTM, and it is certainly not always necessary to do it the way I just showed you. Other ways of accomplishing the same thing are out there, but they didn’t neatly fit into my existing code so I experimented until I got something different that worked. Enjoy!\n","date":"13 March 2011","externalUrl":null,"permalink":"/2011/03/how-to-save-associated-habtm-models-in-cakephp/","section":"Posts","summary":"","title":"How To Save Associated HABTM Models in CakePHP","type":"post"},{"content":"","date":"13 March 2011","externalUrl":null,"permalink":"/tags/php/","section":"Tags","summary":"","title":"Php","type":"tags"},{"content":"If you have a lot of duplicate data sitting around on laptops, USB drives, and external hard drives, you probably would like to clean it up and get back some of that wasted free space. But you probably don’t have time to go through and delete all the duplicates, or you’re concerned if you do you will mis-identify a duplicate and accidentally delete your only copy.\nI ran into this problem recently when I came dangerously close to running out of storage space on my NAS box which was running Freenas 0.7. I purchased an external hard drive to handle the overflow, but it was just not convenient to keep the drive attached whenever I needed something. Nor was it fun searching through the NAS and the external drive whenever I was looking for a file and couldn’t remember where it was. I didn’t have time to go and manually delete duplicate data (and I knew I had a ton of it), so I started looking for a free NAS solution that incorporated deduplication (or dedup). I quickly discovered that Sun/Oracle’s ZFS filesystem had gotten dedup in late 2009, so I started doing some researching on how I could build a NAS box with OpenSolaris and the new and improved ZFS. After much searching (and struggling with getting OpenSolaris to even behave right in VMware ESXi 3.5) I found that someone else had already done the work for me.\nNexentaStor is a free (for home use anyway) OpenSolaris-based storage “appliance” that has ZFS and dedup! I loaded up my old Dell PowerEdge server with some hard drives, installed it, turned on deduplication, and started dumping my data onto it. I wish I could say the process of copying data went flawlessly, but it didn’t. The appliance froze up several times, requiring a hard power off, and I’m guessing it’s because the ZFS logbias was set to latency instead of throughput and it was creating some kind of weird race condition. I don’t know. But I do know that when I changed the logbias to throughput it never froze up again. Anyway, my dedup ratio ended up being around 2.20x, which basically means that for every 2.2 GB of data I was writing, it was only taking up 1 GB of disk space. I ended up with a huge amount of free space.\nBut there was one problem. When creating the ZFS storage pool, I didn’t make it redundant. I just strung all my disks together to maximize the storage space, and that’s a very bad idea. If you remember nothing else about ZFS, remember this: Once you create a non-redundant ZFS storage pool, it’s non-redundant forever. I had to pull all the data off, delete the pool, and create a new one (type raidz1, the logical equivalent of raid-5). This ate up a lot of my available storage space, and I ended up having to split some of my easily replaceable data off onto a Freenas server. I also turned on gzip compression, which didn’t do much. My compression ratio is about 1.02x, but my dedup ratio is 1.74x.\nOverall, I highly recommend trying NexentaStor if you absolutely must have deduplication or redundancy. ZFS is a rock-solid file system, despite Apple turning it down for OS X. I applaud the Nexenta folks for creating this product, and not just creating it, but making it very robust (you can get to a shell if you want or need to) and user-friendly at the same time . But if you just want a quick and dirty NAS solution and don’t care about dedup, I recommend Freenas.\n","date":"22 February 2011","externalUrl":null,"permalink":"/2011/02/deduplication-for-everyone/","section":"Posts","summary":"","title":"Deduplication For Everyone","type":"post"},{"content":"It’s not often you hear a totally rational, powerfully true and complete thought in, of all things, a rap song. But tonight while listening to “Truth” from Lecrae’s Rebel album, the following lyrics, which answer the above question, caught my attention:\nLook, man, some people say that God ain’t real ’cause they don’t see how a good God can exist with all this evil in the world. If God is real then He should stop all this evil, ’cause He’s all-powerful right? What is evil though man? It’s anything that’s against God. It’s anything morally bad or wrong. It’s murder, rape, stealing, lying, cheating. But if we want God to stop evil, do we want Him to stop it all or just a little bit of it? If He stops us from doing evil things, what about lying, or what about our evil thoughts? I mean, where do you stop, the murder level, the lying level, or the thinking level? If we want Him to stop evil, we gotta be consistent, we can’t just pick and choose. That means you and I would be eliminated right? Because we think evil stuff. If that’s true, we should be eliminated! But thanks be to God that Jesus stepped in to save us from our sin! Christ died for all evilness! Repent, turn to Jesus man!”\nMost of the time when I hear someone ask why God doesn’t stop all the evil in the world, I assume that the person asking is just being argumentative and isn’t really looking for a real answer. But there are many people who genuinely don’t understand why God, who is all-powerful, doesn’t put an end to all the evil and suffering in the world.\nThe infection of liberalism that has invaded most schools (public and private) has suppressed the teaching of critical thought and basic logic, so some who ask the above question jump to the conclusion that just because God can do something means that He should. The twisted logic goes something like this: “If God is all-powerful, and He’s good, why doesn’t He stop all the evil in the world?” The assumption is that God is somehow not good because He doesn’t step in and stop all evil. This absurd assumption leads to an even more absurd conclusion: that God must stop all evil in order to be good. This would mean that God’s goodness is dependent upon His creation’s behavior. The natural human desire is to deflect blame from the guilty party and put it into an innocent party. Why? Because it makes it easier to make excuses for our own mistakes. Could God stop all evil in the world? Yes, but the only way He could stop all evil would be to make humans into robots who could not even think for themselves. Certainly God could do this, but would that be a good thing? Certainly not.\n","date":"27 December 2010","externalUrl":null,"permalink":"/2010/12/why-doesnt-god-stop-evil/","section":"Posts","summary":"","title":"Why Doesn’t God Stop Evil?","type":"post"},{"content":"","date":"15 December 2010","externalUrl":null,"permalink":"/tags/2010/","section":"Tags","summary":"","title":"2010","type":"tags"},{"content":"“For there shall arise false Christs, and false prophets, and shall shew great signs and wonders; insomuch that, if [it were] possible, they shall deceive the very elect.” -Matthew 24:24\nWhat is so disturbing is that most of us read passages like the one above and immediately assume that we cannot or will not be deceived by those who come in Christ’s name but are really wolves in sheep’s clothing. It is almost as if we hide behind the words of Jesus as if they will shield us from being deceived by false Christs and false prophets. After all, when we do see someone claiming to be Christ, it is blatantly obvious that such a one is a liar. And when we hear a person claim to be a prophet of God, we almost reflexively disbelieve him and recognize him as a deceiver.\nBut what if the most dangerous false Christs and false prophets are not the ones who openly claim such status, but rather feign humility, love, friendship, and even a relationship with the Lord Himself? Such a prospect is frightening, but I think most every Christian in America today who is not living in a monastery or cave either is or has been friends with an unbeliever who claims the name of Christ.\nMind you, I am not talking about a person who says that they are “Christian” because that’s how they were raised, or because they go to church, or because they believe in God. We recognize that such people do not really understand what a Christian is.\nNo, I am talking about one who not only “talks the talk” but even appears to “walk the walk.” Such a person might go to Bible study, teach at the church, invite others to church, and even lead worship at services. They might be able to quote relevant verses from Scripture in a variety of situations. You may catch them offering to lead prayer before a meal. By all accounts, such a person appears to be a follower of Christ. So how do you know the difference between a false believer and a true Christian who is just struggling?\n“Wherefore by their fruits ye shall know them.” -Matthew 7:20\nThink about the Christians you know. Their identity as a Christian may be so ingrained in your mind that when they repeatedly bear “bad fruit” you might just pass it off as spiritual immaturity or simply the flesh rearing its ugly head. After all, none of us can claim that we never make mistakes.\nBut have you ever looked at any of the Christians you know and wondered, “Is (s)he really a Christian, or is it all just an act?”\nIf you have ever asked this question, beware. You may be dealing not with a false Christ or a false prophet, but with a false believer. Ask the following questions as you carefully consider the fruits they bear.\nDo they demonstrate the fruits of the spirit (love, joy, peace, patience, kindness, faithfulness, goodness, gentleness, self-control)?\nAre they trustworthy?\nDo they have a dismissive or haughty attitude toward the more “hard-to-swallow” parts of the Bible?\nAre they legalistic?\nAre they boastful, either materially or spiritually?\nAre they humble, “submitting [themselves] one to another in the fear of God?” (Ephesians 5:21)\nWhen confronted with their own error, do they become defensive or humbly accept rebuke?\nThese questions are based on my own experience with people who falsely used the name of Christ to gain trust, authority, and even material wealth. The Lord warned us about wolves in sheep’s clothing, and even had He not been so specific, we could logically conclude that if false Christs and false prophets will come, it is a certainty that false believers will come as well, and in even greater numbers.\n","date":"15 December 2010","externalUrl":null,"permalink":"/2010/12/false-believers/","section":"Posts","summary":"","title":"False Believers","type":"post"},{"content":"Nature magazine published what amounts to an evangelism tract for evolution called \u0026ldquo;15 Evolutionary Gems\u0026rdquo;. The article claims to provide the best evidence that evolution is an \u0026ldquo;empirically validated principle.\u0026rdquo; The article even states its purpose is to help Darwinian evolutionists be “secure in the knowledge that natural selection is fact.” (Incidentally, doesn\u0026rsquo;t this phrasing sound awfully religious?)\nI’m going to go through these 15 so-called gems, explain what they mean, and why they are more like dirty, jagged rocks rather than gems. As you read the explanations and rebuttals, keep in mind that this is the best evidence for evolution that Darwinists can provide.\n1. “Land-living ancestors of whales” # Explanation: Evolutionists believe that life started in the sea. They look at very slight similarities between whales and land animals and draw the conclusion that land animals must have evolved from whales. They also believe that humans evolved from land animals.\nRebuttal: The whale is a mammal. Whales have more similarities to humans than they do to land animals, so it makes no sense to claim that land animals evolved from whales, as land animals\u0026rsquo; brains are so vastly different from whales\u0026rsquo;. It would make more sense to say that whales evolved from humans, which of course Darwinists will not say because it would blow their sea-to-land theory out of the water (no pun intended).\n2. “From water to land” # Explanation: As stated above, evolutionists believe that life started in the sea and evolved into land animals. As evidence of a transitional form from sea to land, they held up a fish affectionately called Tiktaalik, which supposedly had fin-like feet and could walk on land.\nRebuttal: Evolutionists have refuted this themselves. They admit that footprints supposedly belonging to tiktaalik have been found in fossil strata formed long before Tiktaalik ever existed. Oops.\n3. “The origin of feathers” # Explanation: Evolutionists believed dinosaurs evolved into birds. Their best evidence for this is a little fossil called Epidexipteryx, which they claim was transitional form from dinosaurs to birds.\nRebuttal: Evolutionists refute this one as well. There is nothing dinosaur-like about Epidexipteryx. They have admitted that Epidexipteryx was probably just a secondarily flightless bird, that is, a bird that was once able to fly but through genetic loss of information (genetic entropy) lost the ability to fly. One evolutionist considered the evidence so flimsy that he mockingly said a chicken could be considered a dinosaur.\n4. “The evolutionary history of teeth” # Explanation: The article simply describes the order in which mice teeth form. It makes no attempt to tie this into evolution, or explain how the order of teeth formation evolved, but at the end it credits Darwinian evolution anyway.\nRebuttal: You might not believe me if I didn’t tell you to read the article yourself, but there is nothing to rebut. #4 is a wash, and downright embarrassing.\n5. “The origin of the vertebrate skeleton” # Explanation: Again, you will not believe me unless you read “gem” #5 for yourself, but there is no evidence given for evolution. The article talks about how the theory of evolution can be used to reverse-engineer old fossils that are missing vertebrae. In other words, the theory of evolution is being used here to support itself. Circulus in probando.\nRebuttal: No rebuttal required, since there is no evidence to rebut. Just remember that the slightest variation in the spinal column will likely kill whatever animal is unfortunate enough to suffer it.\n6. “Natural selection in speciation” # Explanation: Evolutionists looked at the stickleback fish and noticed that the fish would usually not reproduce with other fish of the same species if they came from significantly different environments. Based on this, they concluded that this “reproductive isolation” would lead to the stickleback species diverging into multiple species of fish.\nRebuttal: This is similar to saying that a St. Bernard evolved from a Chihuahua. Darwinists often confuse genetic expression or suppression with genetic change. A St. Bernard may not be able to mate with a Chihuahua, but that does not mean they are different species. No matter how many times you breed a dog with another breed of dog, you will still end up with a dog offspring. A particular breed of stickleback fish may not breed with another, but they are still both stickleback fish. No speciation (formation of new species from an old species) has occurred. Another thing to consider is this: Every time reproductive isolation occurs with the stickleback, genetic information is lost, not gained. And the loss of genetic information invariably leads to a decreased ability to adapt and thrive long-term. #6 unwittingly provides evidence against Darwinian evolution.\n7. “Natural selection in lizards” # Explanation: Evolutionists studied lizards and saw that the introduction of a predator into their environments caused the lizards to behave differently. No lie.\nRebuttal: The introduction of a predator triggered a pre-programmed genetic response in the lizards that resulted in a change in behavior that rendered them less vulnerable. As usual, Darwinists shoot down their own theory with their own evidence and engage in begging the question. This evidence points to an already present genetic response in the lizard.\n8. “A case of co-evolution” # Explanation: Water fleas vs. parasites. Darwinists claim water fleas and their parasites were in an “arms race” to evolve, with the water fleas becoming increasingly better at evading the parasites, and the parasites becoming sneakier and better at infecting the water fleas. Eventually the parasites won. Why? Evolutionists say the parasites “adapted” to the water fleas in “only a few years.”\nRebuttal: No explanation is given for how this adaptation took place, but we know that Darwinian evolution claims it had to have been through random genetic mutations. But how could these random mutations have occurred in just a few years? According to our Darwinian friends, evolution takes millions of years. That’s why we never observe it happening. Did the parasites win the lottery of lotteries? It gets better. The article once again refutes itself by saying that the “arms race” continues. The parasites really didn’t win after all. The evolutionists admit that no evolution took place after all! What we see instead is that water fleas and parasites respond rapidly to one another, in just the same way bacteria rapidly develop resistance to antibiotics across the globe in just a few years. Adaptation is not evolution, and it does not lead to evolution.\n9. “Differential dispersal in wild birds” # Explanation: This is a rehash of #6 and #7, except with birds as the subject.\nRebuttal: The Darwinists shoot their own theory down by claiming that when introduced to a different environment, birds will rapidly change their nestling weight in just a few generations. And once again, this is not evolution, but a genetic expression of a pre-programmed response to a change in the environment.\n10. “Selective survival in wild guppies” # Explanation: Guppies with less common colors have higher survival rates than those with common colors. According to evolution, the genetic pressure exerted against the common-colored guppies would drive them out of existence. But that is not the case. Instead, they noticed that despite the common-colored guppies being eaten at a higher rate, the proportion of the common-colored guppies did not decrease in the population. The Darwinian explanation? More evolution led to the common-colored guppies turning into the rarer-colored guppies!\nRebuttal: This is a classic example of begging the question. The example of the guppies provides powerful evidence against evolution by demonstrating that evolution did not result in “survival of the fittest”, but rather the survival of both the fittest and the least-fit. Instead of admitting this is a problem, the evolutionary scientists changed the definition of evolution to make the problem go away. The reason the guppies maintained the proportion of common colors to less-common colors is, again, an expression of a pre-programmed response. Both sets of guppies already had the genetic ability to be any color, but the expression varied based on the environment. If evolutionary theory were true, the common-colored guppies would have quickly died off and become rarer, while the less-common colored guppies would have increased in proportion.\n11. “Evolutionary history matters” # Explanation: The moray eel grabs and swallows food differently from all other fish. Like #4 and #5, no evidence is given for evolution, but the article does mention that the jaw design is vaguely similar to that of snakes.\nRebuttal: None required because no evidence was given. My favorite quote from #11: “This is an instance of convergence, the evolutionary phenomenon in which distantly related creatures evolve similar solutions to common problems.” Talk about winning the lottery! This quote exposes yet another instance of assuming the conclusion.\n12. “Darwin’s Galapagos finches” # Explanation: One of the most famous pieces of supposed evidence for evolution. Charles Darwin noticed that different types of finches had different sized beaks. He concluded that they all must have evolved from a common ancestor.\nRebuttal: This is my favorite one, not because I get to refute one of the oldest pieces of evidence for evolution, but because the evolutionary scientists do it for me! The article says\n\u0026ldquo;shape differences coincide with differing expression of the gene for calmodulin, a molecule involved in calcium signalling that is vital in many aspects of development and metabolism.”\nNothing evolved here. Even the Darwinists admit that expression of already existing genes is to thank for the variation in beak sizes. They also admit that the change in beak sizes occurs over a few years, not millions of years. Calmodulin activation can occur as a result of exposure to a number of elements found in nature, which would be an example of adaptation, not Darwinian evolution.\n13. “Microevolution meets macroevolution” # Explanation: Flies have a single gene that encodes for both pigmentation and wing development.\nRebuttal: Once again, no evidence for evolution is given. #13 starts out with a completely irrelevant discussion of genetic pressure scenarios (which evolutionists misleadingly call “microevolution”). The fact that a gene can encode for two completely different functions is just more evidence against Darwinian evolution. Now the evolutionary scientists are not only saying that a gene that evolved by random mutations confers a benefit to the organism, but that it confers two benefits, completely randomly!\n14. “Toxin resistance in snakes and clams” # Explanation: Snakes and clams can develop resistance to some toxins by a single genetic mutation.\nRebuttal: One of evolutionary theory’s requirements is that genetic mutations be completely random. The genetic changes that snakes and clams go through to develop resistance to toxins occur far too frequently to be random. This is yet another example of already existing genes expressing themselves based on changes in their environment. I’d also like to point out that #14 gives no examples of evolution. The snake is still a snake, and the clam is still a clam.\n15. “Variation versus stability” # Explanation: When fruit flies are put under stress, they undergo genetic changes, all of which are harmful.\nRebuttal: Despite all the genetic changes fruit flies endure when placed under stress, they never cease to be fruit flies. And the genetic changes are harmful and result in an overall decrease in information. By the way, evolutionary scientists have been experimenting on fruit flies for years trying to force them to evolve in controlled conditions. They have failed over and over again.\nConclusion # You may have noticed that these 15 so-called gems of evolution really boil down to two ugly rocks: Genetic responses and mistaken identities. All of the evidence given for evolution (that the Darwinists have not yet themselves rebutted) makes much more sense when explained as a pre-programmed genetic response rather than a mutation. There is no other evidence given.\nPlease let this sink in. What you have just read is the evangelism tract for Darwinian evolution, and it is pathetic and embarrassing all by itself. Had I left out the rebuttals, you might have picked out most of the shortcomings in these “gems” yourself.\nOne final word: Pre-programmed genetic responses aren’t accidental. They are information based, and information is never random. The genetic responses were designed by the Creator Himself, Jesus Christ, and they are far too incredible, complex, and amazing to be explained away as a series of random events.\n","date":"13 December 2010","externalUrl":null,"permalink":"/2010/12/15-evolutionary-embarrassments/","section":"Posts","summary":"","title":"15 Evolutionary Embarrassments","type":"post"},{"content":"Tonight I watched a documentary on the life of Dietrich Bonhoeffer, a German theologian who encouraged the Lutheran church to stand against the Nazi persecution of the Jews and later joined a conspiracy to assassinate Hitler. The account of Bonhoeffer’s life led me to some of his writings on the role of Christians and the Body of Christ in fighting evil in the world. Bonhoeffer’s approach was much less academic than it was practical. One of the things that really stood out to me was his coining of the term “cheap grace.” He eloquently articulated the modern Christian church in this way:\n“[It] is the preaching of forgiveness without requiring repentance, baptism without church discipline, Communion without confession, absolution without personal confession. Cheap grace is grace without discipleship, grace without the cross, grace without Jesus Christ, living and incarnate.” [Citation]\nAt first read, it sounds almost as if he is proclaiming salvation by works. But I don’t believe this to be the case. Rather, he is contrasting salvation by grace with the universal salvation that so many Christian churches preach– wittingly or unwittingly. If you visit a lot of different Christian churches, you will find no shortage of this “cheap grace” being preached. Such churches typically focus on “doing good” and “judging not.” They piously and with false humility focus on their own imperfections while ignoring the festering sin of everyone else. The “cheap grace” they preach is grace without cost, grace that comes without sacrifice or punishment because the sin wasn\u0026rsquo;t that bad to begin with. “Cheap grace” is salvation by right, instead of salvation undeserved.\nOne does not have to “work out [his] salvation with fear and trembling” (Philippians 2:12) in order to keep that salvation. But in not doing so one will remain in a state of inner turmoil and conflict, “know[ing] the good he ought to do and not doing it, to him it is sin” (James 4:17). This raises the question of what good ought the Christian to do, and to what extent? Bonhoeffer saw his neighbors, the Jews, being persecuted and killed unjustly. The Lutheran church condoned and even participated in the atrocities, for they did not “obey God rather than men” (Acts 5:29). Bonhoeffer believed it was right to join a plot to assassinate the Chancellor of Germany in order to put a stop to the merciless brutality. Oddly, Bonhoeffer stated that man cannot know right from wrong because man’s sinful nature precludes him from having perfect knowledge of morality. This, of course, rides dangerously close to the rim surrounding the pit of moral relativism, which is not at all what Bonhoeffer taught. Rather, I think it’s safe to say he was terribly conflicted about whether his decision to try to assassinate Hitler was right or wrong. And rather than addressing the issue head-on, he dismissed his obligation to “judge with righteous judgment” (John 7:24).\nIt is easy to see why Bonhoeffer believed that sometimes the Christian will feel disappointment and frustration over his righteous actions rather than experiencing feelings of relief and peace. I have found this to be frequently true in my own life. Making a righteous judgment in a fallen world is seldom easy.\nIn his own life, Bonhoeffer participated in multiple assassination attempts on Hitler, one of which resulted in several casualties. He risked his own life by acting as a double-agent and plotting to stop the atrocities of the godless left-wing Nazis. He ran an illegal seminary in Germany which also served as the base of operations for his conspiracy against the Nazis. Bonhoeffer was eventually found out, brought before a court marshal, and sentenced to death. He was murdered by the Nazis on April 9, 1945. 21 days later, Adolf Hitler murdered himself.\n","date":"7 November 2010","externalUrl":null,"permalink":"/2010/11/cheap-grace/","section":"Posts","summary":"","title":"Cheap Grace","type":"post"},{"content":"","date":"30 October 2010","externalUrl":null,"permalink":"/tags/microsoft/","section":"Tags","summary":"","title":"Microsoft","type":"tags"},{"content":"The one theme that I keep hearing from those who attended Citrix’s yearly conference (Synergy) is that they weren’t sure if they were at a Citrix conference or a Microsoft conference. Citrix’s ties to Microsoft run deep and have for a long time. But just within the past couple years the Citrix-MS relationship has started to look less like a partnership and more like a full-fledged integration. Microsoft has its own application virtualization product called App-V, which at first glance looks curiously like a competitor to Citrix’s XenApp application virtualization solution. Of course, since the technology is licensed from Citrix to begin with, Citrix profits regardless. Then there is the new group policy integration with XenApp policies that puts yet another nail in the coffin of the old Presentation Server console. All pretty innocuous changes.\nBut it’s not the technical changes that are really concerning. What has so many hardcore Citrix fans on edge is the appearance that Citrix is taking a backseat to Microsoft, and eventually will be swallowed up by them. Microsoft certainly has plenty of reason to merge with Citrix. Currently Microsoft pays licensing fees to Citrix for every terminal server license Microsoft sells. Now with App-V, Microsoft is paying even more. If you know anything about the history of MS-DOS, you know that this is not the Microsoft way. Sooner or later, Microsoft will seek to break free of its licensing obligations to Citrix, and the only way to do that is to buy them out.\nBut so what? This really didn’t concern me all that much at first, although I’d be very disappointed to see Citrix just become another division of Microsoft. The consequences of this didn’t really hit me until I was listening to the “Security Now” podcast with Steven Gibson and Leo Laporte on Laporte’s TWiT podcasting network. Citrix is a staple sponsor of the show, advertising their one-off remote access and collaboration services like GoToMeeting and GoToAssist. Gibson frequently (as in every episode) points out security vulnerabilities and poor security policies in Microsoft Windows, and his company’s website does not sugarcoat Microsoft’s past indiscretions. Putting myself in Microsoft’s shoes, I would imagine that they’d want to put the quash on Gibson’s comments. And if Microsoft buys out Citrix, they suddenly are in position to control the content of the show by threatening to pull sponsorship. And not just “Security Now” but other shows on the TWiT network as well. I believe TWiT could easily survive without sponsorship from Citrix, but it raises a difficult decision: Change the content to appease a sponsor, or sacrifice much-needed ad revenue for the integrity of the show?\n","date":"30 October 2010","externalUrl":null,"permalink":"/2010/10/the-coming-citrix-microsoft-merger/","section":"Posts","summary":"","title":"The Coming Citrix-Microsoft Merger?","type":"post"},{"content":"","externalUrl":null,"permalink":"/authors/","section":"Authors","summary":"","title":"Authors","type":"authors"},{"content":"","externalUrl":null,"permalink":"/drafts/","section":"Drafts","summary":"","title":"Drafts","type":"drafts"},{"content":"","externalUrl":null,"permalink":"/series/","section":"Series","summary":"","title":"Series","type":"series"},{"content":"Download the The Chinese Union Version (Simplified) of the Holy Bible. Backup link: https://anonfiles.com/58f8L74cy5/Chinese_Union_Version_Simplified_zip\nYou can also read it online.\n","externalUrl":null,"permalink":"/post/2022/chinese-bible/","section":"Posts","summary":"","title":"The Bible in Chinese","type":"post"}]