Lift off

I had a colonoscopy scheduled for today (everyone at the clinic asked me why I was getting one, and I’d answer, “I’m 50”).  My mom had suggested getting some lemon drops as chasers to the 4 liters of colonoscopy juice I had to drink last night and this morning, but I was having a dickens of a time finding any.  Venture Foods in Divide carries some, but they taste like chalk. All City Market had was some Lifesavers, so I got some of those.  7 Eleven didn’t have any.  Then I tried the Farm Crest store in Old Colorado City.

I usually only go to the Farm Crest store once a year to get eggnog.  I really like their eggnog, and they have other things in their convenience store that other stores might not have.  (There is usually some homeless person counting out change on the counter to buy cigarettes too). But no dice.  Nothing but sour gummies, and I’m not a fan of gummies. 

I was about to exit the store suspiciously empty-handed and was thinking of what I’d remark to the cashier, but she was walking out the open front doors (Tuesday was a lovely day).  She was tall and thin, traits her high pumps and tight jeans accentuated. Suddenly, she stopped and lifted her left hand up into the air and stood as still as the Statue of Liberty.  She was staring at her hand, held perpendicular to the ground, and I followed her gaze to the tip of her index finger.

Just then a dirt-brown moth stretched out its wings and took off from her outstretched hand, which she held completely still until it was clear of her fingers.  A plague of miller moths are the bane of Colorado Springs every spring, but this clerk had taken the time to capture the lost creature and returned it to the outdoors so it could continue its journey up into the mountains to mate. 

(Today’s colonoscopy went well, and I shouldn’t be dying of colon cancer anytime soon.)

Internet Passwords

This is a boring post about a mostly boring thing that I feel compelled to write. It’s aimed at those of you who haven’t thought much about Internet security, find websites’ increasing security demands obnoxious and just want to go about your life with minimal hassle. Like my Mom. Or Jonah. I find that I’m often giving this advice to people after it’s too late and individually, but now I can just link to this.

I know you’ve probably seen articles that are like “use a password manager,” and those are well-intentioned and have reasonable advice. And you know it’s a thing you should do, but it’s hard and you’ve got better things to do. And really, you probably figure that someone accessing your email account isn’t the worst thing the world.

So I’d like to start by explaining the way actual attacks work and why you don’t want it to happen to you. Hopefully coming from me in my own words means something more to you than some rando journalist.

A common thing that happens now is that someone (maybe you!) uses the same password everywhere. There are a ton of websites that require you to come up with a username and password for no good reason (like online shopping). So you buy some widget online from some little online outfit that runs a store with poor security. Someone targets their website and steals their entire customer database. This means that now they have your email address and your password for that store.

At first, maybe you think this is no big deal. But if the password to your email account is the same password that you used at this store–you’re probably screwed. One of the first things someone is going to do is try to log in to your email account with your password. They’re also probably on to the fact that you think you’re clever by using “secur3passw0rdWidget” for the widget store and “secur3passw0rdGmail” for your gmail. So now they have access to your email, and once they get in, you’re going to have a really bad time.

First, they’re going log into your gmail account and change your gmail password so you can’t access it anymore, but they can. Then they’ll read your email to see what banks you use. They’ll do “forgot my password” at your bank/paypal/whatever, which will send “you” an email to make sure you are who say you are.

The bank might ask for some other identifying information about you. Like your phone number, maybe your date of birth. Which, probably, can be found trivially by searching through your email. Once they get in, they’ll then change the phone number and contact information that your bank has on you to make it even harder for you to get your accounts back.

Chances are good that by the time you figure out what’s going on, they’ve stolen your account information, possibly your money. Maybe they’ve had one of your credit cards reported as lost and shipped directly to them. Possibly they’ve logged onto your Facebook and sent messages to some of your friends to explain that you’re stuck in a city far away from home, lost your wallet, and really need them to send some money to help you out of a jam.

So, here’s the things you should do to keep this from happening, and I’ll list them in the likelihood that you’ll actually do them:

(1) Make sure your email password is truly unique. I don’t care if you write it down on a sticky note and put it on your monitor or carry it with you. It’s not ideal, but this attack vector is unlikely compared to someone stealing it from another site.

(2) Pick an actually secure password for your email. Do what works for you, but it should not be a dictionary word, and doing common letter substitutions doesn’t count. It doesn’t need to be random to be secure. Correct battery horse staple passwords are pretty good as long as you avoid the 5,000ish most common words. (Munroe’s math in the comic involves cracking character-by-character, but a sophisticated attack will build rainbow tables with common words. If someone knows you’re using a battery horse staple password, they’re actually easy to crack if you use common words. Weird, uncommon but memorable words are best.)

(3) Go to Have I Been Pwned and see if the common password you’re using everywhere is in their database. It probably is. Stop using it for anything important, but seriously don’t use it for your email.

(4) Use a password manager! I know you don’t want to. It seems hard. It’s really not. The hassle is just in setting it up, but the good ones have browser extensions and apps for all browsers and phones. Once you go through the hassle of setting it up, it’s going to make your life much easier! You just click “generate random password” in your browser, it’ll generate it and remember it goes with that site. Your random, secure password will be auto-filled way faster than you can type your common password. It’ll then be synced to all your devices magically.

(5) Turn on two factor authentication for your email. There are 3 basic options now:

  • SMS – you get a text message with a code
  • Authenticator App – You use an app (like Google Authenticator) to generate a code
  • Hardware Key – a thumb-drive like device that you stick in a USB port and push a button when you want to log in.

The SIM card in your phone can be trivially cloned by any teenager who works for your wireless phone provider. Then they’ll stick the SIM in their own phone and get your code texted directly to them. SMS-based two factor is way better than not having two-factor, but it’s the worst choice and you should pick one of the others if you can.

Authenticator apps are a better choice, but they leave you vulnerable to phishing attacks where you think you’re logging into your email account, but you’re not. While you type in your password and your authenticator code, an attacker is logging into your account for you.

Hardware keys are the best answer, but can be a bit of a pain. If you want to go this route, Yubikey is the standard choice. You actually need to buy at least 2 of them because you won’t be able to access your account if you lose/break it. The way it works is that you log in to your email with your password, but then it’ll ask you to tap your hardware key. You don’t have to type They are awesome because when used correctly, they cannot be phished or stolen remotely.

The hassle is somewhat mitigated by the fact that you can check “remember this device” so you effectively only have to use the key to log in from a new device.

(6) Ideally you’ll turn on Google’s Advanced Protection! It looks like you can now do this with a modern phone, and you don’t even need to buy a security key to do it.

If you could change

We were lying in bed one lazy Saturday morning, and my husband asked me, “Would you change anything about your body?”

I know he’s a sucker for my blue (useless) eyes and my long (thin, plain brown) hair. I could stand to lose a few pounds… well, maybe more than a few.

“Yes!” I answered. “I’d like to have an exoskeleton.”

“A… what?”

“An exoskeleton, preferably bulletproof. And I’d like to have really strong legs so I could jump a hundred feet into the air like a grasshopper. But when I landed I’d be safe because of my exoskeleton.”

“An… exoskeleton?”

“And compound eyes.”

“What?”

“Wouldn’t it be great to see in 360 degrees?”

“But would they still be blue?”

“Disco, probably.”

“So,” he said, “you’d like to be an insect?”

“I’d also like to be able to eat rocks.”

“Eat… rocks?”

“Yeah, because I’d never go hungry. Rocks are everywhere! But to eat rocks, I’d need to have a funnel type mouth with rotating sets of diamond teeth. You know, to crush the rocks.”

“Rotating… what? How would you talk?”

“Telepathy.” I turned to him, “How about you? Would you change anything about your body?”

He cleared his throat. “I’d like to be shorter.”

Checkers

I dreamed last night that a Checkers hamburger joint opened up in Divide on Cedar Mountain road. This is, of course, preposterous, because we’re too far north for it to be a Checkers; it would have to be a Rally Burger. I ordered a Checker burger, seasoned fries, and a banana shake, and then Berck started cursing because the total was $18, and I was dismayed because there were children in the restaurant.

The closest retail establishment to our house is in reality a Pepsi vending machine, which is at the campground that is full all summer of people who are trying to get away from it all, that we pass on our drive to our house.

But now I want some fries the way Checkers batters them. Berck tried to make them in his deep fryer once, but the breading all came off and made a huge mess in the fryer.

Novavax shot four (for real this time)

It was about time to get a new COVID shot, and Novavax just came out with their updated vaccine (for Omicron, I think). So I looked to see where I could get it. The options in Colorado Springs were CVS and Costco. There’s a CVS a couple blocks from my office, so I went on their website to make an appointment. The questionnaire got as far as which vaccine I wanted, and when I selected Novavax, it said no appointment was necessary and to just walk in and talk to someone in the pharmacy.

So on Tuesday I clocked out for lunch and drove over to the Target that houses the CVS, the same one where we got Paxlovid. Even though it was the middle of the day, there was unfortunately, a line. I wasn’t sure if I was picking up or dropping off, so I just stood behind everyone else. It was finally the elderly woman in front of me’s turn, and it was taking the pharmacy employee at the pick up desk a long time to figure out the least expensive way to fill the woman’s prescription, running it through her insurance, with her coupon but without her insurance, and with both. The other pharmacy employee manning the drop off desk became available. I said I’d like to get a COVID Novavax shot.

“Uh,” she said, glancing at her coworker, still holding the elderly woman’s coupon, “You’ll have to talk to Nancy.” So I backed up to indicating that I was waiting in the pick up line again.

When Nancy had finally sorted the elderly woman’s issues, 20 minutes later, I finally had the opportunity to ask her for the COVID Novavax shot. “Have you made an appointment?” she asked. No, I explained that the website said for Novavax to just walk in and talk to a pharmacy personnel. “Just make an appointment for any time this afternoon, and we’ll go ahead and give it to you.” I checked the website on my phone, but it still said I couldn’t make an appointment for Novavax, but Nancy had rushed off to do something else. So I filled out all of the information on the website, and it told me I had an appointment for 3:30 for Pfizer. By the time Nancy had finished administering a shot to someone else, she came back and said, “Were you able to make an appointment?”

“Yes, I said, “But it would only let me make one for Pfizer.”

“That’s right,” she answered, “We only have Pfizer.”

“But it said you had Novavax?”

“You want Novavax?”

Turns out they did have Novavax, and I’m guessing this is the first one Nancy had administered, because it took her a while to find the information she needed on the packaging to input it in her computer system. I finally got my jab (I elected to go for the left arm to keep up the right, left, right, ones I’d gotten previously. It stung right away.

CVS gives you fancy bandaids

I was pretty happy the next day that I did not feel lousy at all, though my neck and lower back started aching. The next day my neck and back were really hurting, and the injection site had turned into a very itchy goose egg.

Five days later though, everything went mostly back to normal, with the swelling at the injection site going down and my neck and back stopping hurting.