Not Upgrading for Stage Manager

Apple’s iPadOS 16 features a new multitasking mechanism called Stage Manager, but only on very new iPad models equipped with Apple’s M1 CPU. The ludicrous reason Apple gave for this limitation is that the recent M1 chip is the first iPad CPU capable of using swap space.

If you listen quietly, you can hear millions of computer science graduates rolling their eyes at that ridiculous excuse. Far less capable computers have supported swap space for decades, and I won’t bother going into details of how nervy Apple’s claim is. Admit it, gang: you want to give people a reason to buy new hardware to use the shiny new feature. I could respect an honest explanation that doesn’t insult my intelligence.

But because of this dishonesty, I’m holding onto my still-overpowered 2018 iPad Pro until it dies, or until Apple releases a feature I can’t live without. If there were a legitimate technical reason to hold back new features on older hardware, I might use that as a reason to upgrade. Now, though, I don’t trust Apple not to pull the same trick next year. If I bought a 2022 iPad Pro because of this, and next year they released a feature in iPadOS 17 that would only work on 2023 models for another contrived reason, I’d be livid.

Apple’s trick isn’t going to make me upgrade more often, but less often. I’m not risking my hard-earned money until I have to.

How to give compliments

It’s fun to receive compliments. It’s as much fun to give them! That can be intimidating, though. “What if I say the wrong thing? What if they take it wrong? What if they get angry?” Relax! Saying something nice can be easier than you’d think. First, the ground rules:

Don’t be a pest. If someone’s talking to someone, chatting on the phone, reading a book, or otherwise occupied doing something they probably don’t want want to be interrupted from, then don’t.

They don’t owe you a response. If you say something nice to someone, you haven’t obligated them to thank you, to smile, or even to acknowledge your presence. If they don’t, move on.

Examine your motives. Are you saying something nice to get a date? See the previous rule, and stop right there.

Don’t compliment their body. Unless you’re talking to your romantic partner, don’t comment on someone’s body. If they’re a stranger, or a co-worker, or anyone else who isn’t already voluntarily in a relationship with you, don’t say it.

Stick to complimenting choices they make. For extra safety, concentrate on matters of taste that they’re publicly displaying, like “those are great boots!” or “I love the band on your jacket!”

Don’t take forever to do it. If you’re standing there impatiently waiting for them to finishing their conversation, you’re going to come across as creepy.

With those said, here’s how to say something nice to someone:

  1. Turn to them and say, “wow, your hair color is so cool!”
  2. Smile quickly and sincerely.
  3. Go back to what you were doing.

That’s it. This communicates that you’re being sincere and not imposing an obligation on the listener. If they smile and thank you, right on! If they don’t, that’s fine!

It’s fun to compliment strangers, and people should do more of that. Make sure you’re doing it for the right reason — to make the world happier and more pleasant — then make it easy on the recipient. Good luck!

Don't buy a cheap Apple Watch Series 3

Don’t buy an Apple Watch Series 3. Many recent articles enthuse about its current wonderfully low prices, but it’s a trap. The Series 3 is slow, technologically obsolete, and unsupported by the upcoming watchOS 9. Anyone buying it as their first Apple Watch will be disappointed by the awful performance.

I could only recommend it for someone who broke their newer Apple Watch, wants something to tide them over until the new Series 8 is released, and can recycle it or donate it to someone who’d be OK with a dead-end device.

The dynamic range of emotions

“Dynamic range” describes the difference between the softest and loudest bits of a musical recording. If the sound was recorded poorly so that the soft and loud parts are similar, it stops being interesting. Imagine the 1812 Overture where the cannon fire was at the same volume as the brass, or Skrillex without the drop. Without softness to compare it to, you can’t have loudness.

I was thinking about a loved one who passed away, and about the ebb and flow of happy memories mixed with tragic moments. The difficult parts were devastating, but I don’t think I’d forget them if I could. Without the sadness to compare with, could the happiness be as wonderful? I wouldn’t risk foregoing the lows if it meant the highs were less joyous.

Internet Explorer is finally dead

I was working the night shift at a motel while going to school during the day, when my parents saw a help wanted ad for a local ISP. This was in the late 90s when public use of the Internet was starting to take off, and that sounded like a lot more fun than balancing books every night.

It was. Although I technically worked in tech support, at least at first, in a small shop everyone learns how to do everything. Soon I was learning networking, configuring routers, managing Linux systems, and doing full stack web development. At the time, that meant using Gimp to carve up images to shoehorn into HTML table layouts, and using Perl to write CGI scripts to process forms.

That meant having very strong opinions about web browsers, and the preferences tended to fall into two camps:

  • If you used Windows and were new to the Internet, you liked Internet Explorer.
  • Everyone else preferred Netscape Navigator.

Netscape was better in almost every way, except for the most crucial: Windows came with Internet Explorer. And from Microsoft’s point of view, that was just peachy. They were able to leverage their famous “embrace, extend, and extinguish” policy to push ever more Windows-specific functions onto the web. Why struggle with tricky HTML forms when you could embed ActiveX controls right there in the web page? Or why use the industry standard HTML, CSS, and JavaScript definitions when you could use Microsoft’s own proprietary versions that were very slightly more convenient to use (even though it meant the page wouldn’t load in Netscape on Windows or any other OS)?

For the next decade, Microsoft used every trick in their book to make Internet Explorer the standard web browser, even though it was very non-standard. And once they succeeded, they got bored and forgot to improve it further, at least until Google’s Chrome started getting popular.

And through it all, my colleagues and I continued to try to make web pages that looked good and worked well in all browsers. That process looked like:

  • Develop the web page, testing with Firefox or Chrome, until you got it working.
  • Test it on the other browser to make sure it still worked.
  • Find a creaky Windows box to test it with, see what broke because Internet Explorer didn’t process standard HTML correctly, and tweak it until it looked mostly correctly in all 3 browsers.
  • Go home and drink.

The Browser Wars were a real, serious struggle, and it wasn’t at all obvious whether open technologies or proprietary vendors were going to win.

The web’s in much better shape now, with several major desktop and mobile browsers that work more or less the same. Sure, there are still differences that have to be dealt with, but at least they all use basically the same DOM, and the same JavaScript runs on most browsers unless you’re pushing at the edges.

And now, all these years later, Internet Explorer is finally dead. After many long years of fighting against that abomination, I won’t miss it one bit.

Do not use Readdle's Spark email app

I’ve written before about Readdle’s Spark email client, which is popular, highly rated, and a beautifully powerful app. It’s also too dangerous to use. I recommend dropping it immediately.

Readdle is a good, reputable company. I respect and appreciate them. However, Spark’s design is fatally flawed: to use its advanced features, your email username and password (or token — same thing) have to be stored on their servers so that they can access your email account on your behalf. That’s bad under normal circumstances, but astoundingly risky today. Readdle was founded in Ukraine and still has many Ukrainian employees. Russia is currently invading Ukraine, a sovereign country. If Russia manages to do this, they could likely have access to the login credentials of every one of Spark’s users. This would be catastrophic. Imagine Russia’s security agencies having full access to your work account, being able to use your personal email to reset your banking website’s password, or reading every email you’ve ever sent or received.

Spark isn’t the only email app designed this way. I believe it’s the most popular, though, and that means its dangerous-by-design architecture is used by a lot of people. This isn’t acceptable and it can’t be fixed. If you use Spark, I strongly recommend following their instructions to delete all your data off their servers immediately, and then changing the password of every account you’d used it with.

And when you’re done, see if their other apps look interesting to you. Risks with Spark aside, Readdle makes delightful software and could use our support right now.

Microsoft's gotta Microsoft

A long time ago, back in the dark days of the Browser Wars, Microsoft hated Free Software, especially Linux and the GNU General Public License. We knew this was factually true when one of their employees leaked the Halloween documents and confirmed all our worst suspicions. The world has changed since then, with Linux systems powering most Internet services and Unix-powered phones dwarfing the number of traditional Windows computers. Microsoft seemed to learn humility in their new role as underdog, going to surprising lengths to win a reputation as a kinder, gentler giant.

I’m not buying it. Oh, I did for a while. Although I’d used Emacs for many years, Microsoft’s shiny, MIT-licensed Visual Studio Code lured me away. Shortly after, Microsoft bought GitHub, the world’s most popular website for hosting FOSS projects, saying:

When it comes to our commitment to open source, judge us by the actions we have taken in the recent past, our actions today, and in the future.

Now I read that as more of a threat than a promise. Microsoft has made a few telling missteps since then:

  • They replaced the default MIT-licensed Pyright “language server” in VSCode’s Python extension with Pylance, their proprietary fork.
  • GitHub released their controversial Copilot project which uses AI to insert other entities’ code into a programmer’s project.
  • They accidentally replaced the license of a Free Software project with their own.

Taken together, this strikes me as a pattern. Microsoft pioneered the technique of “embrace, extend, extinguish”: embracing a standard someone else made, extending it with Microsoft’s proprietary add-ons, then extinguishing the competitor by taking its market share. They were legendary in their successful use of fear, uncertainty, and doubt in making potential customers afraid of using competing products.

The Pylance bait-and-switch could be straight out of the old playbook: get everyone to switch to their new, friendly-seeming product, then start replacing it with their proprietary technologies. The GitHub shenanigans would be textbook FUD if it turned out to be purposeful: what better way to get potential customers to accidentally inject GPL-licensed code into their projects, causing them a bunch of legal grief and getting them to switch to Microsoft’s own “business-friendly” licensed products?

I don’t have evidence for this, of course. I doubt anyone does. And Hanlon’s razor says these missteps likely have perfectly benign explanations. However, a big part of my job is analyzing risks and finding problems before they become major issues. My internal alarms are sounding that maybe Microsoft hasn’t changed as much as they’d like us to believe. I hope I’m wrong, but in the meantime, I’m migrating my personal projects away from all Microsoft dependencies.

Dealing with Princeton's flawed privacy research

This has been an odd week. Last Friday I got an email from someone asking about my hobby website’s CCPA compliance, ending with

I look forward to your reply without undue delay and at most within 45 days of this email, as required by Section 1798.130 of the California Civil Code.

The message sounded more legitimate than the usual spam I get, as it was asking about a real law in the jurisdiction where I live, and because it referred to a real website that I operate. That last line looked to my not-a-lawyer eyes like something a professional litigant might send out when they’re trying to gather information before deciding whether to sue someone. Mass frivolous lawsuits are a thing, after all, and I dreaded the idea that I might have had to defend my personal project in court.

This Friday, a friend told me that a researcher at Princeton sent the emails as part of a study on CCPA compliance they’re conducting with Radboud University. That changed my whole outlook: the letter came from a fake person with a fake email domain, lying about their intentions, and lying that the CCPA required me to reply to it. The stress it caused me wasn’t fake, though.

I submitted a link to my story to Hacker News, which a few people saw. Then someone else submitted another story and it took on a life of its own. It turned out that a lot of people got these emails. The researchers stated that they used the Tranco database of “popular” websites, and my tiny little site was only ranked as high as about number 350,000 in that list. I wasn’t alone. Princeton sent similar emails to other personal projects, and stories abounded that companies had hired counsel and incurred legal expenses to reply to complete fabrications. People had been frightened and were becoming angry.

Based on advice from Hacker News readers, I contacted Princeton’s Research Integrity & Compliance department and Institutional Review Board, and Radboud’s Research Data Management and Ethics Committee with my concerns. Radboud responded quickly. Princeton hasn’t responded.

What especially bothers me is that I think this is an important subject to study. I’m a Californian and I support the CCPA protecting my privacy. I want to know if companies are complying with their legal obligations, and I think a large research university like Princeton is the right kind of entity to conduct an effective study. I also believe that the researchers had the right intentions and wanted to do a good job. My problem with it is that I think they made a grave error in misrepresenting their legitimate research questions as coming from a fictional person, and wrote it in a way that set off a lot of “oh no, I think I’m about to be sued” alarms.

I suspect the data collected from misled responses is corrupted beyond repair. For instance, many entities who replied are likely to have formulated a policy solely because they received the email. I think, then, that the appropriate next steps for Princeton and Radboud are to immediately send explanation and apology emails to all the recipients of the original emails, and to delete all responses they received from recipients of the misleading messages.

This was such an unnecessary mess. It’s a shame because this could have been crafted in a way that resulted in better data and without scaring the research subjects. Do better next time, Princeton.

Update 2021-12-2: The researches updated their website to read, in part:

Our top priority has been issuing a one-time follow-up message that identifies our study and that recommends disregarding prior email. We are sending those messages.

We have also received consistent feedback encouraging us to promptly discard responses to study email. We agree, and we will delete all response data on December 31, 2021.

...And Back to OmniFocus

I recently wrote about switching from OmniFocus to Reminders and gave a lot of reasons why I thought that was a good plan. I was wrong and I’ve since moved back.

Apple has made Reminders into a solid app with a lot of nice features, but I realized I’ve been taking OmniFocus for granted. First, I sorely missed its “defer dates”. That is, I don’t need to be reminded to buy Halloween candy when it’s nearly Christmas time. I don’t even want to see that on my action list because it clutters up both my list and my thinking. Second, you can set OmniFocus to repeat an action a certain amount of time after that action’s completion date, not only its due date. “Pay the electric bill” needs to happen at the same time each month, but “make a haircut appointment” should happen a few weeks after my last haircut, whenever that was. Finally, OmniFocus’s project options like “complete with last action” are unmatched. Mix in many less crucial but nice-to-have features like nested tags, and per-tag location reminders, and it’s too good to walk away from.

I started moving my actions back out of Reminders and into OmniFocus and switched to using the OF 4 beta on my iPhone and iPad. That beta is turning into what I’d hoped OmniFocus would become: a stunning app that’s a pleasure to use. If it follows this current path, and OmniFocus 4 for Mac follows soon after, I think it’ll be amazing.

I’m glad I tried this experiment, and if nothing else it forced me to deeply review all of my actions before copying them from one system into another. Apple should be proud of Reminders and I bet it does everything most people need. It’s not (yet) enough for me, though. Until then, OmniFocus, I’m back.

About the Manifesto for Ubiquitous Linking

I’ve written before about Hook, a nifty way of linking things you’re working on together so you can seamlessly bounce between them. I’ve thoroughly integrated it into my workflow now and adore how quickly I can jump from one document to another — in a different app, even — without ever looking away from my work. It helps me reach and maintain a state of flow.

Hook depends on an app’s ability to support deep linking to its contents. Many apps are helpful, like OmniFocus. It supports both a right-click “Copy as Link” action to all sorts of items, and allowing other apps to ask it for a link to its currently selected item. Consequently, Hook’s OmniFocus support is top-tier, and I can make links between a to-do item and the website that documents how to do it. Other apps are less helpful, like Apple’s own Reminders app which supports neither users nor other apps asking for a direct link to an item. It somewhat supports drag-and-drop linking to other apps, but that’s not nearly so convenient and powerful as OmniFocus’s methods.

Apps should be more like OmniFocus than Reminders. To that end, Hook’s author Luc P. Beaudoin collaborated with an all-star list of Apple software developers to write the Manifesto for Ubiquitous Linking, which says in part:

We affirm that the ability to copy a link to a resource is as important for cognitive productivity as the ability to copy other types of information. This applies to all persistent digital information.

We invite software developers to do their part, by

  1. ensuring their users can conveniently obtain a link to the currently open or selected resource via a user interface; and
  2. providing an application programming interface (API) to obtain or construct a link to that resource (i.e., to get its address and name).

I could not agree with this, or endorse it, more heartily. Anyone can write an app that locks away content behind its own twisty maze of navigation links. The best and most powerful applications open themselves to users. Today I can link from an OmniFocus action to a DEVONthink document, and from there to an Obsidian note, whether on my Mac or my phone or iPad. Tomorrow, I want to go directly into any of my apps. If you’re an Apple developer, please take the time to read and consider this manifesto.