Showing posts with label Blogging. Show all posts
Showing posts with label Blogging. Show all posts

Seven

Well, I was half right in my Breaking Bad prediction; I'm fine with that.

Yesterday marked seven years since I started this blog. It's hard to believe that much time has passed. (We moved into this apartment and got our dog earlier that same year.) I still enjoy doing this, and I keep coming up with stuff to write about, though I will admit there are days when I feel pressure to say something clever, or anything at all.

As always, thanks to everyone who visits, reads, or comments.

(Car stuff will be back tomorrow.)

The CAPTCHA Insanity

Dear fellow bloggers, if you don't want comments on your blog, then just say so. I typed a fairly lengthy comment on one prominent Linux blog, only to be confounded by the blogger's spambot-trapping CAPTCHA. He's installed a virtual Fort Knox on his blog. I had to decipher not merely a distorted word, but also an out-of-focus picture with a three-digit number on it. In nine cases out of ten, I could not read either the word or the number. My vision is close to 20/20, but after a dozen failed attempts I conceded defeat. The blogger did not receive my comment and will never know that he turned away his reader. Contrast his policy with my own. I allow anonymous comments and have nothing more than the generic CAPTCHA. I'm not torturing people with cryptograms. Yeah, I receive a spam comment once in a blue moon, especially on that post I wrote about Namecheap (the worst web hosting company in existence today), but I delete them. If I notice an upsurge in spam, then I change my settings to hold new comments in the moderation queue, so that they are not published unless I approve them. That completely defeats spammers. And for the record, I do not censor people who disagree with me. I prefer to argue with them! I do censor profanity and vulgarity, because I don't think it's cute or clever, and that sort of thing can impact my search ranking on Google.

Please knock it off with the crypto CAPTCHA insanity!

Namecheap, the Worst Web Hosting Company

Namecheap, Inc. just sent me an invoice for--well, I don't know what. They expect me to pay a bunch of money because, I guess, they need money. I haven't hosted with them in years and my domain is no longer registered with them. I'm not surprised their morals are amiss. Namecheap is possibly the worst web host in existence. Their service was lousy, with unexplained bizarre errors, and their tech support, which I frequently had to use, was foreign, incompetent, unresponsive, and uncaring. I was never so happy as when I abandoned my Namecheap account and moved to a different host, even though it cost me financially to do so. Namecheat is more like it.

The host I recommend is Bluehost, a class act all around. They may be Mormon-owned for all I know, but they do web hosting right, and on the extremely rare occasion that I have needed their tech support, I have talked to real, live American techies on the telephone who know what they are doing. I've never been talking to a Bluehost representative without feeling like they are intelligent and, perhaps more importantly, care. I've used Bluehost for many years. I don't know of any other web host that is as good as they are, although it's true I haven't tried many. Bluehost is even recommended by Wordpress, which I think is very impressive in itself. Their founder runs the entire company on Mac or Linux, scorning Microsoft. I've followed his blog off and on through the years. I doubt we would agree on politics, but as far as computers go, I think we are in agreement.

For the past couple days, my site on Bluehost has become inaccessible around midnight every day without explanation and stays slow until the morning. So I can't recommend Bluehost without reservation. I need to become more cautious about my enthusiasm for things. It seems like the very moment that I praise something, that's when I discover its shortcoming. In the case of Bluehost, I discovered their nightly slowdown about the same time that I renewed for two years. However, I think that this may have been a temporary glitch, possibly due to Wordpress attackers.

If this is the only post any visitor to my blog ever reads, then so much the better. Namecheap caused me hardship with their unexplained errors and incompetent service.

7/30/2013 Update: This post against Namecheap has been attacked on over ten separate occasions by spam comments linking to malware sites that try to infect people's computers with viruses. My policy now is that whenever that happens, this post will be updated to be the front-page, very first post; or else I may post another message about Namecheap and its sleazy, unethical business practices. There's no way that Namecheap can get out of their well-deserved poor reputation. They are going to have to live with it, no matter how many spammers they hire.

Blog Status

I updated my public .htaccess blacklist, in case anyone's interested. I assume someone is, because that post has received 11,000 hits, and they can't all be bots. My guess is that people are using it as a resource to check up on an IP address. I can tell you that from using it, the number of bots getting through declines by about 99%. Some will still get through, but the list grows over time due to my efforts, and those that get through, don't get through for long.

My efforts to monetize this blog via AdSense have fallen flat due to a technical error on AdSense's side. I left a message in their help forum but haven't received any answers. They do not permit ordinary mortals to contact them via email. So I will leave a post on my front page into perpetuity that points the finger at AdSense, which is broken, dead as a doorknob, kaput, game over on my site due to an AdSense bug. I imagine their developers are too busy drinking coffee and eating donuts to work on boring stuff like code.

I like working on code and am pretty good at it, but I am not allowed to do so anymore, because all the programming jobs were given to foreigners. I believe that politicians in Washington, D.C. right now are working on ways to eliminate even more jobs so that they will make a bunch of money on the stock market. The politicians are bribed, bought and paid for by corporations and don't care about America or, much less, American workers.

Trying Ads Again

I decided to try adverts again, because I put a lot of effort into the blog over the years, with a big wonky zero in the way of return. Many people come here and find the information they need to solve the problem at hand and then leave without so much as a thank you. Even if I only make five bucks a year, in ten years time, I'll at least be able to buy some bananas. I like bananas.

Well, it looks like Google Adsense is programmed by morons. Adsense sent me an email saying they put my account on hold until I update my tax info. I'm not permitted to update my tax info because my account balance is below $10. Thus, my sites are on hold forever or until Google hires intelligent programmers. I'm on hold forever.

Blogger Fails in Firefox

I've been using Blogger since 2009. Starting around 2012, Google made ill-conceived changes to Blogger that have made me dread editing my template's html or css. I have given up on maintaining a custom template. The Template and Layout functions of Blogger are horrible. Blogger has crashed Firefox so many times that I've lost count. How does Blogspot set about crashing a computer? Constant and nonstop hits to web sites like twitter, facebook, and google's own. Continual processing for no apparent reason, endless loops just burning the cpu up until 100% of the processor is in use, accomplishing nothing whatsoever. Blogger crashes Firefox on both Linux and Windows systems, I might add. It doesn't matter what kind of computer I use or how much memory I have or how fast my Internet is or which operating system I choose. Blogger will crash Firefox in a heartbeat. It will also bring a computer system to a crawl and force a reboot.

Like most things, Blogger devolves rather than getting better. I suppose Windows doesn't set a good example in that regard. The only thing Google cares about is making money off AdSense, but I can't see running ads on a web site where I cannot even edit the html or css at all without the computer crashing. I certainly can't recommend Blogger to anyone who wants to start a blog, unless they like rebooting their computer every five minutes.

On the plus side, I do like the stock template. It's nice and dark and seems more pleasing to the eye, although I could ask for a bit more color. We have color monitors--shouldn't we use them? Black and white seems, well, a bit of a throwback to the 1970's, when I actually had a black and white television set. It's a sign of age if one can remember watching television in black and white.

I would have preferred the option of selecting and installing a new template rather than being pressured into doing so by a kludgey editor that crashed my computers. Nobody likes being forced to do things.

Confessions of a Blogger

The reality as I see it is that most blogs have no readers--or few, if any. The lion's share of traffic consists of bots. Bots with bad intentions, mostly--content scrapers and hackers angling for derivative traffic. ?!Buzzword?! What is "derivative traffic," igor? Well, pardon my jargon, but derivative traffic is traffic that derives from somebody else's labor--writing, photos, what-have-you. Capiche? There are sites on the Internet that have stolen my content, such as it is, despite what may be regarded as its uncertain value. There are many sites on the Internet that rate my site, analyze my site, give every manner of statistics, and give previews and archival history of my site. All of that comes from bot traffic, from unattended software programs hammering this site day after day collecting data.

On this blog, my best estimation is that 90% of the hits are non-human bots. Of the humans that do hit the blog, most are searching for answers to narrow technical questions, and most hit about a dozen different posts that are the most popular posts on my blog. That would include the Dungeon Crawl Cheat, although I don't know how many Dungeon Crawlers actually bother installing the batch file nowadays. Not many people know what batch files are anymore, and I reckon those that don't would be worried about a virus. The batch file is useful mainly for my own purposes. I can't imagine playing Dungeon Crawl without it. I like to have control over death. Isn't that a natural human desire?

Why so many bots? I get asked that question often, especially when I explain that ninety out of a hundred hits to any given web site are non-human. Well, hackers figured out a long time ago that they could exploit weaknesses in human nature and in search engine technology to drive traffic to their own web sites, where they make money off advertising, install malware, flog some worthless software, or just increase the value of an url that they plan to sell later.

Gee, igor, that sounds like an easy way to make money! How come you don't do it? Ha-ha, I've thought about that and a lot of other easy ways to make money. I won't say I'm above temptation. But even though our government sets such a poor example, I still find some value in ethics. I don't want my legacy to consist of crap web sites and increased distortion and confusion on the Internet. I've always been on the other side of that war and have invested too much effort in fighting bots to change hats now. I suspect the government is behind some of these bots, using them in an effort to monitor and exert some degree of control over the flow of information.

What Bing Means to Me

I detest Yahoo and Bing. The acronym "Bing" stands for Bastion of Incompetence, Negligence and Gross impairment. Yahoo and Bing are one and the same as far as search results are concerned.

My strong feeling against these two search engines is in reaction to their stubborn insistence to index every last page on a web site, even those pages that the site owner has specifically disallowed in robots.txt. I discovered tonight that #2 in the Yahoo and Bing results for a search term for one of my web sites was the very bot-trap that I had disallowed in my robots.txt. The bot-trap should never, ever, under any circumstances be indexed by any search engine. The reason that Bing and Yahoo index it is because they are stupid, stubborn and ignorant. There is no other conceivable reason. I understand how the rules work in robots.txt. Google understands. Yahoo and Bing do not understand. I do not have time enough in my day to teach those corporations how to code their search engine. They are just going to have to teach themselves.

However, the incompetence of Yahoo and Bing caused a problem for me. I don't want innocent humans clicking on a search result in Bing and getting banned from my site. My first thought was to disallow Bing and Yahoo altogether and get de-indexed from those seach engines, which send so little traffic they are scarcely worth worrying about. However, some people don't know any better and get suckered into installing a toolbar that connects them to Yahoo or Bing.

My solution was simple and elegant. First, I renamed my bot-trap. The new name will not be disclosed anywhere. Yahoo and Bing won't be able to find it unless they stoop to dirty tricks and get banned. They might just do that. If the new bot-trap name shows up, then I may resort to banning Yahoo and Bing altogether, which was my first plan of action.

However, for the time being, the #2 search result that formerly led to my bot-trap now leads to a page that simply informs the user that Yahoo or Bing has caused an error, and they should use Google instead. A link to Google.com is thoughtfully provided.

My problem has now become Yahoo and Bing's problem. They lose face, rather than the other way around, and that's the way it should be.

Wordpress Security Vs. Wordpress Search Ranking

Wordpress security is sometimes at loggerheads with a site's search ranking. There are many tricks and tips recommended by security wonks that will actually decrease a site search ranking, such as banning all hits to xmlrpc.php, or disallowing various paths in robots.txt. I've experimented over the last several days and learned what works and what is counter-productive. I do not believe it is wise to ban hits to xmlrpc.php, and I do not think web admins should second-guess Google when it comes to directing robots. Google knows what it is doing, for the most part, and additional rules make Google angry, in a manner of speaking. I watched my site plummet from #2 in search rankings for a particular term to #5 after adding a lot of rules to robots.txt. Needless to say, I yanked those rules right out!

There is such a thing as having enough or even too much security. With regular backups of the database and the files, I am not inclined to follow all of the recommendations set forth by Perishable Press, one of the few sites I regularly follow. I view Perishable's advice in the way of guidelines and educational material. The author has a knack for explaining technical issues without resorting to jargon, with a humorous style reminiscent of Stephen King--the American vernacular, gotta love it--and he offers excellent examples on .htaccess. He is my "go-to" site when I am confused about arcane .htaccess syntax, which is often, because .htaccess syntax is unintuitive. I use some of his security tips, but not all, because some cause problems. I am also concerned that perhaps other problems may be created that I cannot detect, problems that may become evident in the future after I add a new plug-in or there's a new update to Wordpress.

Perishable's .htaccess code is sometimes compressed in a way that makes it difficult to debug or understand what is being done. Perhaps that is a form of showing off or maybe the intention is for the code to execute faster, but I'd prefer to sacrifice efficiency for readability and ease of maintenance.

I am no stranger to compressing code. I won a little contest back in the '80s, getting my name and program published in a national magazine. The challenge was to code a BASIC program that did something cool in only one line. Each BASIC statement could be separated by a colon (:), and GOTO 0 was allowed. But was this a useful or helpful skill? Maybe. This sort of experience may have helped me become a better maintainer of other people's spaghetti-code programs, which comprised a large portion of my career. I rarely had difficulty finding and fixing bugs.

I think Apache wrote the language for .htaccess back when every byte mattered, and in order to save a couple bytes, they made the language cryptic and anti-human. I much prefer languages such as COBOL, batch/script, or BASIC for their sheer readability. I never was a fan of C++, even if it is twice as fast. In my opinion, buy a faster computer, if you need speed. When programming languages are easier to understand and to code, then greater deeds may be wrought by human minds and with far fewer bugs. That's my philosophy about programming. I have indeed worked with extremely cryptic computer programming languages--assembler, no less. I am merely stating my own preference as a programmer and user. It's nice to be able to look at source code and figure out what is going on in just a few moments. Maybe my opinion does not dovetail with job security for those programmers already entrenched in cryptic languages, but it seems rather obvious to me.

Jonesin' for Wordpress 3.6

I eagerly await the overdue release of Wordpress 3.6 and moreover the twentythirteen theme. I haven't updated my Wordpress theme in ages, and I feel like now's the time, especially since I have time on my hands. The twentythirteen theme is supposed to offer superior support for mobile devices. I don't use one, but so many people do that of course I want to keep those people happy.

Yet another part of me wonders whether it is wise to join the other lemmings leaping into 3.6. Perhaps it is better to remain with the tried and true 3.5.1 and wait to see how 3.6 pans out in terms of security and stability. Perhaps I should give the hacking community time to find all the weaknesses in the next release. I don't know. I think if I backup on a regular basis, then I can deal with whatever may arise.

Blexbot Content Scraper is Really Nielsen Media Research

I had great difficulty finding detailed information online about an IP address, 216.176.177.162, that appeared in my site log over ten thousand times. But now that IP address is cold busted. It belongs to Nielsen Media Research, a pack of content scrapers. They do not wish to be identified as such, and so they lie, and call themselves a random name like Blexbot. Tomorrow they will be clexbot, and the day after that, wmu-bot. What are Content Scrapers? They are greedy bots that attempt to grab every piece of data from a given site. Interesting bits of this data are then grouped together and sold to companies, governments, or individuals. In short, they grab content and try to profit from it. They do not send traffic. They should be banned by every site, no question about it.

Lookie what the scumbags are doing on a Wordpress site:
216.176.177.162 - - [29/May/2013:06:21:13 -0800] "GET /password HTTP/1.1" 404 2438 "-" "BLEXBot"

216.176.177.162 - - [29/May/2013:06:21:16 -0800] "GET /signup?context=webintent HTTP/1.1" 404 2438 "-" "BLEXBot"

216.176.177.162 - - [29/May/2013:06:21:18 -0800] "GET /reg/join HTTP/1.1" 404 2401 "-" "BLEXBot"

216.176.177.162 - - [29/May/2013:06:21:21 -0800] "GET /forgot_password HTTP/1.1" 404 2438 "-" "BLEXBot"

They're not just content scrapers, they're malicious hackers. Those 404's you see above? That code means they're making up links as they go along, running them up the flag pole to see if anybody salutes. Meanwhile, the web admin gets to have fun wondering what's wrong with his web site that all of these 404 errors are popping up. (There were many more than just the above examples.)

Bot-Net Attack? What Bot-Net Attack?

I read many articles today about the brute force attack targeting Wordpress sites. My site is secure, and I just laugh at the enormous waste of that stupid bot-net's bandwidth. Each hit taxes my site about 500 bytes, so those scumbags will have to hit my site 2,000,000 times in order to waste one of my gigabytes--but that calculation seems rather liberal to me. After all, my deflate instruction is near the top of my .htaccess file, so I would wager that instead of 500 bytes, the server actually transmits each bot closer to 300 bytes, maybe lower since old 403.html is, after all, mere text, which receives quite optimal compression rates from any compression algorithm worth its salt.

But igor's solution will never be the thing people click on in google. Packaging and appearance are the thing. That is all right, because it is enough for me that my client's site is perfectly impregnable. I want his site to be fast all the time, I want it to look right all the time, and I want black hat hackers and evil bots to fail in everything they attempt.

Upon reflection, I think the stupid brute force attack against wp-login is meant to promote the sales of some cybersecurity firm(s). Let us be clear, it is not a serious attack. It is a stupid and ineffectual waste of bandwidth. Some cunning CEO may have decided to hire a bot-net to launch a stupid, ineffectual attack against everybody, knowing that the ignorant and the easily frightened would shell out money to buy a quick fix, a little band-aid to put on their precious web site to lull them into a false sense of security. I just don't which company(ies) are behind the attack, which stand to gain. There are probably a thousand different suspects.

I Love Deleting Comments

Out there in Internet-land, SEO scumbags are paying a bunch of needy nerds about ten dollars an hour to leave comments on blogs like mine. I mark such comments as spam and delete them. Ha-ha, game over, wah-wah-wah.

Takes me all of five seconds to clock SEO shills. For the record, igor was not born yesterday.

I see these shady Internet jobs on E-lance all the time. E-lance was made for crap jobs like that. I may be a needy nerd myself, but there are certain jobs I don't deign to do for ethical reasons. The money is beside the point. I can't stomach the thought of ever being a spammer that promotes crap sites on the Internet. Now if the site were worth a damn, that might be another question, but I don't work for the unethical or the ignorant.

I wish more people had scruples about who they work for. The world would be a better place. Homo Sapiens 2.0 needs to have a faculty in the brain that refuses to behave like a slave--refuses to work for evil ends.