Saturday, January 20, 2018

Don't be a knee-Jerk on the way to GDPR

Yesterday morning my inbox was littered with, essentially, spam. These were posts to a discussion thread in an online community which I had not subscribed to, that system sending me the messages anyway.

It seems, someone wanted to protect people like me from having personal data poached from group discussions and related pages they’re managing. We can understand that this is a valuable goal, and in fact is consistent with requirements under GDPR to protect Subject’s personal information. So in their system, they have redacted email addresses, replacing mine with gl…@gmail.com.  I’m thrilled my email address is not displayed in the clear on this site, and equally happy that a data breach or similar event won’t expose my personal details in the wild.

Or I would be thrilled, were my inbox not full.

Because somehow their system still sends notification to subscribers. In reality it looks like it is sending emails to everyone it knows whose email address matches the redacted pattern. Trying to send an email to a true subscriber, gl…@gmail.com, they seem to have sent an email to all gl…@gmail.coms. Including to me.

Many people got these emails, and putting it mildly, they’re not happy about it. My HR department won’t let me post many of their comments on the topic. Especially since, to unsubscribe from a thread they didn’t subscribe to, recipients were being asked to click through an acceptance of Terms of Service.  Bad form!

Were it in effect, and in absence of a less blunt instrument, I guess GDPR offers these subjects a recourse: Dear DPO, I’m gl…@gmail.com, please erase me.  How will that go?

Let’s see now, what’s 4% of gross revenue for any of the large developer community owners?

So yes, we need to protect Subject data, but unthoughtful knee-jerk redaction without concern for downstream impact isn’t the answer.

Wednesday, August 3, 2016

Another clever way to prevent opt-out

Here's another clever way for spammers to keep spamming you.  Legally they have to include a way to opt out, usually via a link at the bottom of the email.  As I wrote a few days ago, sometimes those links cleverly look like phish attempts, so anti-phish measures block them.

Today I got one I could actually click, and did so. It seems the unsubscribe page was (accidentally, I'm sure) so badly written as to crash the browser!  Outstanding!


Friday, July 15, 2016

How anti-phishing is giving me more spam

I hate to write this one, for fear the spammers will learn from it and send more. But really ...

I'm getting spam from a particular sender. Same old thing.  But this one looks sufficient like a phish ..  well, our corporate anti-phish technology is triggering on it and removing the URLs. Which means I can't use the legally-mandated URL to opt-out.  So I get more spam from them.

It kinda sucks.  Protection implemented for the best of reasons, to block phishing, is making spam more prevalent.

Damned if you do.

Saturday, June 11, 2016

Mai Tai chez Glen

I've been fiddling with my Mai Tai recipe off and on for a couple of years ... here's what I'm making now, gets good reviews from my favorite tasters (you know who you are).

This makes about 4 tall drinks.

7 oz spiced rum
3.5 oz coconut rum
7 oz pineapple juice
2 oz guava nectar
8 oz orange juice (homestyle - ie. with pulp)
6 or 8 solid shakes of Angostura Bitters
1 oz dark rum
6 or 8 chunks of fresh pineapple

Serve over ice.

If you're being fancy, save the dark rum to the end. Fill the glass 3/4 with drink and 3 to 5 ice cubes. Pour a little grenadine down the side of the glass to layer on the bottom, and float a little dark rum on top.  I can't be bothered, and just mix the dark rum in, skipping the grenadine 'cuz I don't like pink drinks.

Some people have crappy paper umbrellas, and stab the pineapple chunks with them. I don't. I just throw a couple of chunks of pineapple in the glass at the end.  My guests can eat the infused pineapple when they're ready for another. :)

Aloha.

Thursday, June 9, 2016

Rude android apps

I'm getting pretty annoyed at the self-indulgence of some Android apps.  Facebook, gmail, and others.

Here's the deal. When I leave my home, I often turn off WiFi ... I've found that if I leave it on, sometimes my phone connects automatically to networks that need a signin, and because I didn't plan to connect, I don't sign in, and for a while any transfers are blocked. Eventually I might notice, but in the meantime an important email hasn't been delivered to me, or something I've sent hasn't actually gone upstream. So I turn off WiFi when I leave the house.

Sometime later, I want to do something that will use a fair amount of traffic, and deliberately connect to the local wifi where I am. Usually at a bar. Just thought you might like to know. :)

However, after I connect, my phone basically stops working for a couple of minutes as every friggin little pissant app I have on my phone decides now is an awesome time to sync. I watch the little traffic icon thing, and the up and down signals are pegged. In both senses of that word. It's really annoying, and all because these crappy apps think their background transfers are the most important thing in my life right now. I couldn't care less about the 39 Facebook updates in my network. Not in the next few minutes anyway. I deliberately connected to a network because I wanted to get something done! And I can't.

I guess what I need to find is some app that doesn't completely disable background transfers .. but maybe delays some of them so they don't all go at once.

In the meantime, if the apps themselves would just wait a danged minute or two - you know, be polite - I'd be a lot happier. Catch the signal that the network is now present, and set a timer for yourself. Wake up in 1 to 3 minutes. Do your sync.

I'm frankly about 5 more episodes of this away from uninstalling Facebook from my phone.

Thursday, April 30, 2015

Detailed specifications

As a Product Manager, I frequently struggle with how many details I need to supply in an Epic. Say too much, the team doesn't read it. Too little, weird things happen.

Lest my current staff think I'm pointing at them, I'm not.  :)

Broken cookiesYears ago I wrote a requirement that spoke of an unique sequence number. The product delivered to me had randomly selected numbers that nonetheless were unique.  I couldn't believe it .. randomly choosing the numbers, then testing uniqueness, was harder than just allocating the number in sequence. Which was, in fact what I had asked for.

Today, another wonderful example, this time from my local bakery. Box up some cookies so we can sell by the package. Seems simple. What bake shop owner in their right mind would imagine some industrious packer breaking cookies to make the boxes as full as possible? Such as this box, straight from the market, over half the cookies are, well, halves. Who would ever think to write in the epic, "Box up some whole cookies, take broken ones home for your kids." Or, "Don't break my pieces of art to make them fit!"

It would be like writing in the manual for the pizza delivery driver, "Don't hit any fire hydrants with our delivery car!" Though come to think of it, when I was in high school another student did in fact wreck a pizza delivery car by driving it into a fire hydrant at full speed. Hmmm.

Wednesday, September 26, 2012

Caller ID; or, Wireless Caller my butt

I've got this telemarketer calling me and they won't stop. Different number each time, different name in the Caller ID, vague about their company name, and continuing to call despite being asked at least 3 times now to add me to their Do Not Call list.  For that matter, they are ignoring the National Do Not Call Registry.

And here's the rub: I pay for Caller ID precisely so I can not interrupt my work to deal with this crap.

Meanwhile, the Telco I pay is letting disreputable callers spoof the system I pay for. It hasn't, after all, escaped me that the caller ID is reporting pretty unlikely names. This morning is "Wireless Caller". Tell me, since when has a telemarketer clearly in a call center (lots of background voices) used cellphones for the calls?

And I'm starting to wonder why I pay, and why others pay.  Class action refund, anyone?

Thursday, September 6, 2012

Greece as a condo corporation

Is is possible to draw an analogy between an EU country and a condo corporation?

I read this morning that Greek treasury debt rates are in excess of 23%.  It seems obvious that they must somehow increase their revenue to service that debt. How?

A start is to increase their tax rates and/or get serious about collection. No more of this "Only a fool would pay taxes" attitude many Greek (non-)taxpayers are said to have.  That can lead to two things: one, property owners are forced to focus on revenue from their properties, leading many of them to move and rent their homes to comparatively rich Germans and Brits; or two, homeowners flee to a cheaper EU country and/or the government repossesses their property out from under them and turns it into vacation rentals.

The government becomes a vacation timeshare operator.

And if they don't, or otherwise don't make enough net to pay their debt obligations, the Greek government could and perhaps should be viewed more like a condo corporation and the taxpayers like homeowners. Government debt is held on behalf of the citizens (homeowners), and paid for in revenues derived from the citizens (condo fees). If the the condo corp goes bankrupt, it is repossessed for its assets, and the new owner can liquidate or operate to recoup their investment.

Who can repossess Greece?

Sunday, February 5, 2012

Facebook captcha extortion

I started using Facebook recently, and quite frankly, they are annoying me.Here's one way.

I press the Like button on something, and am presented with the common captcha dialog whose usual purpose is to verify that I am human and not some sort of robot or screen scraping program. I pressed Like on several items yesterday, from the same browser window each time, and had to figure out an unreadable string like this one more times that I cared to.  It seems strange to me that Facebook believes a robot had taken over the connection I had already verified as having a human operator.

Whatever. Facebook seems to understand that this gets really old really fast, and the first text in the captcha dialog is "Sick of these?" Clicking that link opens this window where one is encouraged to supply a mobile phone number so they can text a confirmation code.

I have two complaints with this.  First is, I don't text, and don't have a text plan on my phone. I'm suppose I'll get a text if they send it. Probably. And my provider will be happy to charge me for that.

More interesting, though, is that any one-time text to my phone will do nothing to meet the useful goal of the captcha - which is to very that I am not a robot that pressed Like. For this to have that value, they would need to text me a confirmation every time I press Like, just as they are presenting the captcha every single time. I hope they're not planning to text me that often - as I mentioned above, I don't have a text plan.

I've confirmed with another Facebook user that she doesn't get confirmation texts with every post, so FB clearly don't feel the need to verify a human every time.  Why, then, do they present a captcha every time, other than to maximize pain and further incent me to give up my cell#?


Extortion.

Friday, December 16, 2011

Death, taxes and UPS

There's nothing more constant that death and taxes (well, that they are unavoidable at least).

I've felt the same way that UPS (the shipping company, that is, not the thing plugged into my power outlet) was kinda this black box, never really changing, despite being at least mildly shoddy.  We've all got stories about packages that didn't arrive the day planned, or my personal favorite, the "Fragile" sticker with a boot print on it.

But recently it seems they've got clever. They have increased their service level, for a fee. And the services are useful ones, such as being able to call them to redirect a package to another address (perhaps your office or a neighbour who will be home). Check it out.

If I have a gripe with this it is that it seems a little bogus to charge for some of these services. The least defensible is probably them redirecting your package to a UPS store for you to collect .. that service is saving them money, for exactly the same reason that super-mailboxes (multiple customers with a single drop-off point) are more efficient than delivery mail door to door.

Clever positioning to make it seem as if this is a valuable service that you want to pay for.

Though it could backfire ... it could be viewed as a protection racket - you know, where you pay the Piranha Brothers to make sure something bad doesn't happen. Picking up your package at the UPS office reduces the service they deliver, and gives them fewer opportunities to make another figurative boot print.  I might very well pay for that.

Friday, October 7, 2011

Failed at "Getting it done right"

Rob Bonta uses SafeUnsubscribe® which reliably removes one's email address from mailing lists.  Pity it doesn't work.

Back in July, I started getting political spam from the campaign of Rob Bonta, who seems to be mayor of another city in my general region. I don't live in that city, and don't know anything about him. He seems to be running for a state seat, and possibly could become my representative, but I am ineligible to participate in politics in this country so I frankly don't pay much attention to his or other campaigns or that level of political boundary.

Except when they are spamming me, in email or robot phone calls. Then I notice.

On July 23 2011, in response to an unsolicited campaign email from Bonta, I used the unsubscribe link to request my email address not be included in any future mailings. I continued to receive emails on Sept 5 and Sept 22.  The most recent email attempted to justify itself: "You're receiving this email because of your relationship with Alameda Vice Mayor Rob Bonta." I neither live, work, vote, nor even visit Alameda. My only relationship with him is that his campaign has started sending me emails, and has so far failed to respect my request to stop.

Beyond the immediate annoyance, the bait-and-switch of the ignored unsubscribe is frustrating. If you are going to publish an unsubscribe link, at least respect it. Sadly, political spam seems to be exempt from the California anti-spam laws.

My annoyance aside, this has also been an amusing example of Bonta's apparent (in)ability to "get it done right".  That seems, after all, to be his tagline. The unsubscribe link said:

"Getting it done right. Alameda Vice Mayor Rob Bonta uses SafeUnsubscribe® which reliably removes your email address from our lists."

I have since sent a note to the complaints address listed. I haven't heard back, but also haven't (yet) received any further emails.  Here's hoping. Kudos to the folks at SafeUnsubscribe for publishing this additional communications channel so they can hear about their clients who may be behaving unreasonably.

Thursday, October 6, 2011

Google and Third Party Cookies

A few web pages I've tried to visit are refusing to load these days. One such is Google's account settings page. The others also seem to touch Google account-related services, eg viewing someone else's public calendar. When I hit such pages, Google courteously offers to help me correct my browser config by enabling 3rd party cookies.

How ... helpful.

Here's the thing: I disable third party cookies quite deliberately, and want them disabled.

Third party cookies are, to me, an invasion of privacy.  With a third party cookie, some schmuck who buys an ad placement in a site I visit can set a cookie in my browser tagged with the advertisers domain.  Then when they buy another ad presented in another site I visit, they can set another cookie. Since both cookies are 'owned' by the advertiser, they can then track my browsing history, at least to the extent of the subset of my browsing where their ads are presented.

I don't want third parties, especially any schmuck who can buy a few ads, to know my browsing history. For an example why, check out the ACLU Pizza Dramatization.

So now I'm kinda stuck if I want to tweak any of my Google account settings. I can't just clear my last hour of browsing history, because my work style means I currently have about 10 browser windows and 40 or 50 tabs open right now, some half of which I've touched in the past 20 minutes. I suppose I could keep a secondary browser on my machine just for pages such as these, set that browser with a relaxed security profile, and clear its cookies after each use.  Seems a pain.

And I can't figure why Google would want third party cookies on their account settings page anyway. I suppose they may have some number of internal domains, but it seems to me as if they are not being careful of their cross-domain cookies.

Tuesday, May 31, 2011

The expurgated version

Congratulations, you're enjoying the new expurgated version of my blog.

My previous blog service provider is leaving the business, so I needed to find a new provider and migrate my old posts.

By the way, my thanks to Alan and Ceri at Blog-City, which has been a great home for the last 8 years.

It didn't take long in my evaluation of new blogging services to discover two glaring issues with migration:
  • Permalinks aren't permalinks.  More precisely, the new providers I was looking at wouldn't let me duplicate the old permalinks as-is because they seem to insist on a specific format.  So it seems that if anyone has saved a link to one of my posts, that link will now break. I'm guessing that will include Google Search, so what, I lose my accumulated pagerank because my service provider closes their doors?
  • There was no easy way to migrate my posts.  All the services provide some kind of export, and re-import back into their service.  Some also support migration from certain other large players - for example, it seems as if one can switch between Blogger and Wordpress in either direction.  However, no-one seems willing to import the lingua franca of blog content, RSS. Probably some deliberate decision to discourage blog theft or something.
Which is where the expurgated version of my new blog comes from.  I spent a bunch of time over the past few days migrating old posts by hand, and fixing broken 'permalinks' between some of my posts.  I won't be migrating everything ... there were a bunch that aren't very interesting any more, like those advertising a Spikesource event. Hmmm. I guess I was pouring free beer, that makes it interesting. :)

Anyway, enjoy the ramblings of a marketing oddity and legal (well, frequently) alien. Mark II.

Wednesday, February 2, 2011

Google, Bing and copyright

There has been a bit of controversy over the apparent copying of Google search results by Microsoft's Bing search engine.

For me, the interesting question about this issue is: who owns the search result after it has been displayed to the user? The San Jose Mercury News said :
Microsoft countered that it was only using data voluntarily supplied by its customers to improve Bing's search quality.
That's fine, if the customers own the results and so have the right to voluntarily supply the data. If not, then I suppose these customers are at fault for copyright violation, and Microsoft for building in a nondiscriminating feature that causes its customers to violate copyright law.

I visited the Google search page, and a Google result page, and neither showed any link to determine how the results were licensed.So I'm not sure how the Google result is licensed to users.

To me, this is reminiscent of the music piracy cases a few years ago, and similar cases since about other copyright content. The web site can claim that it doesn't make any decision to infringe, only the site user can choose what to upload. Nonetheless, folks like Napster were held liable for building a product for which there was a reasonable expectation of it being used for piracy.

Similarly, Microsoft can claim all they want that this controversy is based in a misunderstanding of how their opt-in program works ... but if the customers have no legal right to browser-displayed content, this is a pretty reckless feature for Microsoft to argue. I know for many (paid) sites, there is a clearly worded copyright license - is Microsoft indexing from those sites as well?

That said, I suspect Microsoft has more and better lawyers than Napster did.

I wonder if the Bing search page has a link for copyright owners to complain of violations, as required under the DMCA?


I am not a lawyer, nor do I play one on TV. My employer neither knows of nor avows this post.

Tuesday, May 11, 2010

Ironic Spam

I blogged a few days ago about inane password reset questions, and now another amusement from the LA Times ...

I can't remember now why I ever went there - no doubt I was following a link to an article - but in that I don't remember and never go there, I ignored a recent flurry of emails requesting that I visit or my 'subscription' would be canceled. Well, I didn't mind them canceling it, and they said the cancellation would be on a date within a few week, so I gritted my teeth and ignored the (frequent) requests. The problem would solve itself.

My subscription is canceled now, so what do I get? Another email:

"Why have we stopped sending you e-mails?"

As if. I could only wish.

Between the password questions and now this, I'm not sure I'll follow a link to them if I ever get one again.

Monday, May 10, 2010

Lemonade for teachers

Remember lemonade stands? When I was a kid, if someone wanted to earn a few bucks on a hot day, they could make some lemonade and sell glasses to passing pedestrians or motorists. Maybe go a little further, and sell cookies or brownies or something. It was something of a cultural icon, featured in comic strips and so forth. Lucy even went so far as to sell psychotherapy.

Roll forward to these days of education funding cutbacks and I'm seeing lemonade stands with a difference: kids are selling lemonade and cookies just as before, but the money is being donated to a school PTA or Education Foundation (as the case may be) to help cover teacher salaries that can't be funded out of payments from the State. Sure, some of these 'stands' are bigger productions, organized by the PTA or school principal. But not all. Some of those little kids selling on streetcorners (now there is an image I didn't need) are donating their quarters to keep their favorite teachers in the school.

And it isn't surprising, seeing as they know exactly who is being cut. One morning last week when dropping my kid off at school, I saw a display of empty chairs with a teacher's name on the sidewalk of the drop-off circle. Some kind of post-economic performance art or something, apparently organized by some parents.

Even Brownies aren't safe. Brownies and Girl Guides have been selling cookies for ages to support their programs, but I saw an email yesterday afternoon saying the Brownies are going to donate part of the proceeds.

Please, support your local schools.

Saturday, May 8, 2010

Thunderbird with IMAP hangs during new message scan

For a while now I've been annoyed when Mozilla Thunderbird hangs while I'm typing an email, during its periodic check for new messages. I'll be merrily typing along (hunt-peck-hunt-pause-peck-backspace), and the composition window will just freeze for upwards of 10 seconds, and come live again when the new message alert pops up to say I have some new messages.

Like I said, I've been annoyed for a while, and today I finally decided to do some digging. Lo and behold, I found this thread from 4 years ago describing exactly this problem.

That thread may have petered out, but the problem is still alive and (?) well. Sadly.

It definitely seems a locking problem and not just the desktop being busy. My client is a fast quad-core, and I can't imagine that an IMAP check and pop-up alert could consume all that ... it seems that a critical resouce must be locked during folder scan or perhaps the related local cache update or update of message counts in the main Thunderbird window.

No doubt the delay is related to how much stuff it has to scan. Admittedly, I have two email accounts configured, to IMAP servers on the same host, and some have some pretty large folders. And that host isn't all that speedy ... But still, it shouldn't block at all.

For the record, I'm using Mozilla/5.0 Gecko/20100429 Thunderbird/3.0.4 under Gentoo x86_64. The thread above mentions this problem in Thunderbird 1.5, so it has been a very long time.

For the record 2: This is still vastly superior to how Outlook handles IMAP.

PS. I tried to first post this as a comment in the other blog, but comments there seem to be busted. So I'll post here and trackback.

Wednesday, April 28, 2010

Flush with alacrity

One from the archives ... I wrote this in August 2009, lost it, and found it again this morning.

I very much enjoy reading the weekly Economist news-magazine - every issue invariably contains at least a few very interesting and informative articles on finance or politics, less dumbed down than any of the local media choices I enjoy living in The Land of the Free (Though Uninformed).

Every year I try to get away for a couple of weeks to my family's vacation property, a tiny log cabin on a remote lake in British Columbia, Canada. It is completely rustic - the nearest cell tower is some 30 miles away, nearest utility of any kind is 10 miles away, running water happens when the guy with the bucket is wearing sneakers, and those who like to think of their country as the "Home of the Brave" have never braved our outhouse.

It was therefore with interest and a certain bemusement that I, sitting on my throne in the woods, was reading "Face value - Flush with ambition" - Economist, July 25 2009, page 66 - about the Neorest, a high-tech Japanese toilet from Toto, which "... hides odours and plays sounds like running water or birdsong to drown out embarrassing noises," for a mere $5000.

Wow.

And I got to thinking: if Toto, an industrial powerhouse in Japan, could get their collective heads out of their, um, homeland long enough to see the opportunity provided by wilderness vacations, what could they offer the remote camping crowd? Birdsong I already have: a flock of loons, whiskey jack, chickadee, woodpecker, and hawk so far this morning. In fact, if the Japanese and Whoopi Goldberg are willing to plonk down $5K for these things, perhaps I can just rent out my facility with real, not artificial, birdsong.

Though I'd have a little more trouble with hiding odours and a heated seat. Maybe Toto's engineers could solve those problems together: somehow capture the various gases and run them through a small efficient burner to heat the seat? If they could do that without singeing something important, I'd pay for it.

Monday, April 26, 2010

Eyestrain and desktop colours

Maybe I'm getting old.  Ok, I know am getting old, proven by my kids insistence on having a birthday celebration for me today.  Also proven by that non-topical digression, I suppose.

As I get older, I'm having a little more trouble with eyestrain when using my computer. I've been in front of my monitor rather a lot over the past few weeks, and my eyes hurt. At least part of the problem is large white windows, so I've been fiddling with trying to invert my desktop colours ... white text on black gives me a lot less strain than black text on white.

But it is hard. Easy enough on the surface, but the Devil is, as they say, in the details. 

Desktop background, menu background and text, popups, text frames (like terminal windows) ... a lot of stuff is easy, just requires some attention to detail.

Even web browser colours were solvable, albeit non-optimally. In Firefox I could choose white text on black, but the pages still displayed white. I had to go the extra step of overriding the page's colour choices. Now I have white on black, but I've lost any shading the page author may have wanted to apply to a section.

And that hasn't helped HTML display in Thunderbird ... there I am currently getting white text on white background for HTML messages, which is a little rough for reading. Thunderbird doesn't present the same option to override a page's colour choices, perhaps because it isn't a web browser. Still, it gets plenty of HTML. and that HTML apparently has colours.

Even this editor I am working in now, writing this blog ... I'm in a lovely white-on-black screen, typing merrily away, but most the buttons at the top of the editing window are pure black, the little images don't show up. Most ... the "Media Browser" image shows up, and the pulldowns for Styles etc, but all the rest of the little boxes, all black.

Somehow I think this entry will be published without any special formatting or links.

What we need is some way for the user to specify colours for the broad range of situations that come up in all the content he views. Letting me override background and text colour isn't sufficient ... I also need a way to specify alternate background colours for sidebars, and for computer code boxes, and for table row highlighting, and ...

In fact, that's the problem - there are as many kinds of background as there are pages. Maybe not quite, but there are lots.

In part because there is no standardization. If I author a page with a table, and want to shade alternate rows of the table for separation, is there any standard name for that span? Will such a row on my page have the same style as a similar row on your page?

So me the poor user would need to separately override two styles for the same basic concept.  That sucks.

Where is the pretty UI that lists the styles I'm viewing or have viewed, lets me group them, and override portions, for example, override the colours while leaving font and size alone? Rules-based partial style overrides, similar to .mailfilter rules? Hmmm.


Or maybe something exceedingly clever that would let me click one checkbox to remap colours (for everything except images) to the opposite side of the colour wheel (0xFFFFFF- value).

Saturday, April 24, 2010

My pet's name is too short

Sure, passwords are a necessary evil. And given passwords and fallible human memory, password reminders are also necessary.

What bugs me are predefined challenge questions for recovering forgotten passwords.

You've seen them. "Please supply answers to the following questions: 1) What is your mother's maiden name? 2) What was your first school? 3) What was your first pet's name?" etc.

So there I was, creating a profile at a newspaper's site, and got this response to one of my challenge answers:
Please correct the following error(s) before proceeding: Password must contain at least one character that is not a letter.
Enter name of your favourite pet. Response must be between 6 and 9 characters long.
Come on, folks. My first pet's name is only 5 letters long. My bad, I know, but when I was 5 I wasn't thinking about password strength as I chose my pet's name. All I was looking for at the time was a name short enough that I could finish calling him before bed time.

It is your predefined challenge list that is forcing me to use my pet's name, and now you won't accept my pet's actual name .. what do you want me to do, make one up? And then forget what I made up?

What if my mother's maiden name is 'Wall', is that ok? Or would I have to get her to legally change her maiden name?

Please, let me make up my own challenge questions, and let me put off explaining password strength to my kids for another few years. Maybe once they're walking.

Ok, in the interest of accuracy, my kids are in fact walking. But this was funny, and I hope it made my point.