Daredevil Brings Great New Villain(s)

Media

From Gene Hackman’s Lex Luthor to Phillip Blake’s The Governor (The Walking Dead), great casting and charismatic actors have frightened, enraged, and intrigued us with super villains from the comics universe. If you’re hankering for a new Big Bad, definitely turn on the Netflix series Daredevil. Vincent D’Onofrio strikes all the right notes of charming-sociopath evil in his surprisingly vulnerable Wilson Fisk (aka, Kingpin, in the original Frank Miller comic).

Daredevil Wilson Fisk

As many have noted, there’s an obvious historical reference in Wilson Fisk’s uber-developer “activities.” It’s a nod to mid-century NYC villain Robert Moses. Moses is the infamous urban planning autocrat and destroyer of blue-collar neighborhoods from the 1950’s and ’60’s.

But that’s overlooking the more salient two-headed juggernaut-of-gentrification: Mayor Giuliani/Bloomberg. Wilson Fisk “cleans up crime” by sending Chinese immigrant suicide bombers to Russian mobster hideouts; Giuliani/Bloomberg blows up minority neighborhoods with the now roundly repudiated policing tactic of stop-and-frisk.

Wilson Fisk wants to make the city safer and more beautiful. The question of course is, safer for whom? Beautiful in the eyes of whom? Giuliani and Bloomberg say the same thing during their tenures as mayor. Gentrification may bring safety and (a very particular kind of) beauty. But at what cost? By its nature gentrification shreds the existing social fabric — demolishing the historic character of the street and displacing existing residents. Consider the following.

  • In central Harlem the white population grew 405% between 2000 and 2010.
  • Average house prices in Harlem increased 86%.
  • 37% of the city was re-zoned.
  • Eight of the city’s tallest buildings have been built since 2001.

My brother lived on Manhattan’s Lower East Side (aka, LES) from 1993 to 2007. During the ’90’s, when I would visit him we’d walk through the blacktop city park around the corner, and I would worry about the kids on the seesaws and doing Double Dutch on the sidewalk; scattered on the asphalt were spent syringes and used condoms from people in the park the night before.

Since the time of Giuliani/Bloomberg, the grit and grime of the LES has been completely erased. Crime has been rendered moot. But that park is gone, too. So are the children. Now the LES is high-rise condos and the well-to-do. The Salvation Army Residence is now the Bowery Boutique Hotel. CBGB, the iconic, hellhole live music venue, is now a John Varvatos shop.

Sounds great. But what about history? What of people and character displaced? No more Indian curry walk-up windows. No more mudflap, by-the-slice pizza counters. The writers and academics? The Asian produce vendors and union film-production workers (like my brother)? They’re all gone.

And it hasn’t stopped with Manhattan. As new skyscrapers push lower-income and middle class Manhattanites out, the displaced are pushing into the outer boroughs. A telling New York Post headline reads, “New Hipsters Fight Old Hipsters in Bushwick.” Another headline puts it less ironically: “Gentrification as ‘Benign Ethnic Cleansing.'”

Here’s an amazing image from an article in Gothamist :

gentrification Google Street view - Daredevil blog post

Image credit: Justin Blinder, via Gothamist

 

New York Magazine says of Bloomberg’s development efforts:

[Bloomberg] bullied and cajoled developers, steered Liberty Bonds their way, and pushed through rezoning as they wanted. Today, each new Skyland Summit gets superseded by another. The race to the clouds is reminiscent of 1930, when the Chrysler Building and 40 Wall Street tried to bound past each other for the title of world’s tallest — only to have their rivalry mooted a year later by the Empire State building.

Sound like someone we know? (Less the immigrant suicide bombers, of course.)

VINCENT D'ONOFRIO as WILSON FISK in the Netflix Original Series “Marvel’s Daredevil” Photo: Barry Wetcher © 2014 Netflix, Inc. All rights reserved.

Photo: Barry Wetcher
© 2014 Netflix

Password Managers, or Doing Passwords Right

Entrepreneurship, Media

Part II in a three-part series on personal online security. Parts I and III can be found here and here.

please don't steal this

Still Using Scraps of Paper?

Back when I was “storing” passwords via pen and paper, I had, what, twelve pages worth? Fifteen? Of course it’s impossible to memorize more than just a few passwords, which is why people duplicate, or reuse, passwords on multiple sites. Reusing passwords is the primary no-no of personal Internet security. Yet we all do it, we who keep passwords on paper.

The trouble is, when a reused password gets stolen, the thief has access to any site associated with it. This is the principal danger for most when caught up when a big company gets hacked.

Then there’s the problem of using easily remembered passwords for our most frequented sites. Your dog’s name, your child’s birthday. Now that’s secure! Use it for online banking or your most-used email account!

Our third most common failing is not changing passwords regularly. Really? All fifteen pages worth?

If your password-tracking system is stack of dog-eared, greasy pages in disintegrating manila folder, you’re essentially dangling your business checking account in front of cyber criminals and taunting them to take its contents.

The Best of the Best:  LastPass vs. 1Password

Enter: the password manager.

Here are the two password managers I have direct experience with: 1Password and LastPass. These two, along with KeePass, represent the best of the best.

Ten years ago I started out with 1Password. 1Password is one of the few top password managers that does not store your data in the cloud. 1Password is essentially an encryption program, but one dedicated to password management. It generates and organizes strong, unique passwords, all encrypted and stored locally on your hard drive.

What soured me on 1Password is its lack of cloud-sync. It’s greatest strength was also it’s biggest weakness.

Like a lot of entrepreneurs, I have a raft of devices float through my life every few years. Without cloud syncing, 1Password  limited my password “vault” to my main laptop, only. After a few months I bit the bullet and manually re-created a second password vault on my second laptop. That chore took hours.

1Password did offer syncing via Dropbox. Convenient, yes. But then you have to rely on Dropbox’s security, as well.

At that point I switched to LastPass. Yes, this switch was guided, admittedly, by convenience. How great it was to have all my passwords on all my devices! But LastPass also offers topflight security.

I was queasy at first about LastPass storing my data in the cloud. It took some time to get comfortable with their basic concept: LastPass servers don’t actually store passwords. They only store encryptions of passwords. That’s how they thwart any potential inside job (a.k.a., a LastPass employee stealing customer data).

How Long Is a Billion Billion Years?

The encryption also discourages cyber attacks from outsiders. With AES 256 bit technology, a hacker who cracks the LastPass servers would need at least a billion billion years to decrypt even a single password. That’s not a typo. A billion billion. (Here’s a discussion of these numbers.) Hear that? That’s the sound of hackers crossing LastPass off their hit list. (1Password also uses AES 256.)

Finally, decryption of the LastPass ciphers happens locally, on your device. In other words, your naked passwords never travel outside of your device. Plus, you are the only one who holds the key to the decryption. That key is what LastPass calls your Master Password. Hence, the name–your Master Password is the last password you ever have to memorize.

So, I remember one, and LastPass handles the other 179.

No matter which program you choose, you should make your Master Password long and strong. And change it three to five times each year. Rather than a pass-word, I use a pass-phrase.

Two Factor Authentication

We should also all be using 2 Factor Authentication (2FA) with our password manager. Even if my Master Password were stolen, say, by keylogger malware, the thief still couldn’t access my LastPass vault without my 2FA security key. I love having my USB security key on my keychain, which I can use to access LastPass on any laptop or desktop. For my Android needs, I use the Google Authenticator app (always on a separate device).

It’s heartening to learn that LastPass is popular at MIT.

Next Post: Data Breaches in the News

Time: “Why You Should Change Your Amazon Password Now”

Entrepreneurship, Media

Part I in a series on personal online security. Parts II and III can be found here and here.

keep-calm-and-change-your-password- 400x467

“Why You Should Change Your Amazon Password Now”

So says the headline of a recent Time magazine article. The word “now” sure makes for provocative news. The article begins, “Hackers said Friday that they leaked data associated with 13,000 accounts on Amazon, XBox Live and other sites.” The writer concludes, “[This] news should underscore how important it is to change your passwords frequently.”

But is this just alarmist rhetoric? Should we really worry about such a small number of victims?

Online retailers say we have nothing to fear. Not only was the number of victims small, the 13,000 were spread out amongst 14 different retailers, not just Amazon. Some might point to the much larger 2014 Home Depot hack as cause for concern (56 million credit card numbers stolen). But the online retailers say the Home Depot crime wasn’t actually a “hack,” per se. In that attack, credit card info was stolen from Home Depot’s self-checkout machines in physical stores, not from the company’s computer database.

In other words, according to the spin doctors, cyber security is sound. They might admit the 2013 hack of Target was large (40 million credit card numbers stolen), or that the Sony hack of 2011 came with high costs for the company. But Sony, Target, Home Depot, and any big company watching the fallout of their hacks, have cried, Never again! They’ve elevated their cyber security. They declare online retailing to be safe–or even safer than–shopping in a physical store.

That’s plain wrong.

In a recent segment of CBS 60 Minutes, cyber security expert Dave DeWalt says “97 percent–literally 97 percent of all companies–are getting breached.”

What a mind-blowing figure. And DeWalt should know. Target has hired his security firm, FireEye, to prevent future breaches. “Even the strongest banks in the world . . . can’t spend enough money or hire enough people to solve this problem,” he says.

Perhaps the real takeaway from the 60 Minutes piece was that “80 percent of security breaches involve weak passwords. One of the most common is: 123456.” In other words, 80 percent of the passwords now in the hands of criminals were absurdly weak to begin with. Or, rather, 80 percent of us are still using passwords the way we did in the 1990s: simplistic, easily remembered (aka, easily guessed by strangers).

DeWalt says, “The days when we our username and password is our son or daughter’s name, or our cat or our dog, is not enough security to thwart today’s hackers.”

So, don’t just “change your passwords now.” Make them stronger.

My next post: Password managers, or Doing Passwords Right

The Heartbleed Bug: How to Keep Your Passwords Safe

Entrepreneurship

lastpass logo

As an entrepreneur, one of your most important tasks is securing your financial information.  In the wake of the Heartbleed Bug, I’ve been fine-tuning my digital security. I’ve especially been fortifying my passwords.  I already use a password manager called LastPass, which I highly recommend.

Though I’ve used LastPass for several years, until Heartbleed, I wasn’t utilizing LastPass to its full potential. The latent Luddite in me was on the fence about fully entrusting my most sensitive accounts to any password manager. But this past couple of weeks has shown me how important it is (and that it truly is safe) to use LastPass for even my bank accounts, PayPal, and other highly sensitive sites.

I’d been using LastPass for dozens of less sensitive sites, while continuing to use easy to remember, “secret” passwords for my bank accounts and Paypal. Not smart. By “easy to remember,” I mean actual words whose significance I believed to be too personal to be deduced by strangers.

How foolish.  Today’s password-cracking software can test out tens or even hundreds of millions of possible passwords per second. Against such brute-force juggernauts, my poor, easy to remember passwords would last mere minutes, if that.

Enter LastPass. LastPass is widely considered the best password manager out there.  You have one master password to log in to the LastPass browser plug-in. Whenever you visit a web service, the plug-in logs you in securely.  As long as your master password is chosen well (i.e., long and complex), LastPass offers excellent security. There’s even a multi-factor authentication feature to make remote hacking virtually impossible.  (Multi-factor authentication is like Google Two-step Authentication, which, if you aren’t using yet, I also highly recommend.)

LastPass generates a different, completely random, character-string password for each of your online logins. Randomness is the key. Randomness actually resists brute-force attacks, unlike actual words. This is how to leverage a single master password while never using the same password for more than one site.

LastPass stores only 256-bit encrypted versions of passwords on its servers. That way, if their servers are ever hacked, the thief would have a monumental task of decrypting just one password, not to mention any others after that one.

Also, LastPass doesn’t store your master password.  Only you know your master password.  That’s how they thwart the potential “inside job” by an unscrupulous Lastpass employee. (Inside jobs are actually the most common form of security breach involving passwords.)

Plus, the LastPass plug-in only decrypts your passwords on your local machine; it never sends an unencrypted password across the Internet. All individual passwords remain encrypted until the moment you use them.

And even then when LastPass decrypts a password to log you in to a site, the password fill-in remains masked (just asterisks), in case a hacker is mirroring your screen. (By the way, your master password is masked when you use it to log into the LastPass plug-in.)

 

Commuter Bikes and the Trek Soho Deluxe

Health

trek soho deluxe

My friend Tony asked if I’d have a look at this bike.  Tony lives in DC and commutes by bike, escorting his wonderful daughter to school every morning, all by DC bike share.  He’s become a bike-share-system savant — the hackles on his neck rise the closer he gets to the thirty-minute bike-share quota.  But his daughter is graduating to middle school this year, where there isn’t a convenient bike-share station to switch bikes.

So Tony needs to buy a new bike.  His commuting needs neatly mark out the boundaries of the no-maintenance bicycle market — namely, internal gear hubs (IGH) and carbon belt-drives.  So it’s no surprise he’s put his finger on the Trek Soho Deluxe.

In researching this bike, I’ve done my usual eval, all the while not realizing the model has been discontinued.  So I’ve also done a quick and dirty search for “city bike,” “belt drive,” and “disc brakes.”  That’s turned up a decent list of some drool-worthy machines for 2014-15.

My evaluation of the discontinued Soho Deluxe is still relevant, though.  Not only are the components of bikes in this narrow market segment very similar.  There are probably a number of Soho Deluxe’s still in showrooms in every major city, and at closeout prices, to boot.  So I’ll just include that here, while adding the list of current-model bikes at the end.

MISC. NOTES Re. the TREK SOHO DELUXE

1) If you find a “new” model, it’ll likely be a great deal, with “closeout” pricing.  (The model was discontinued for 2014.)  But what year is the specimen you’ve found, 2012 or 2013?

Consider the following:

a) Normally a year or two sitting in a showroom makes no difference.  But with internal gearing, lubrication can leak out or settle in ways detrimental to the parts.  So if you find a 2012 Soho Deluxe, ask if the bike shop will re-lube the hub upon purchase.  Sheldon Brown discusses lubrication issues, here:  http://sheldonbrown.com/nexus-mech.html

b) Internal gearing has come a long way in recent years, and the different iterations of the Nexus 8-spd. hub are no exception.  I don’t have the specifics on whether or not the 2013 is significantly better than the 2012.  Might be something to research further.

c) Similarly, the newer Gates belt drives are reported to be much better than older versions.  I’m not sure what the timeline is, so that’s something to look into, as well.

2) No quick release rear wheel.

a) Much more difficult to change a flat on the fly.  Here’s a somewhat daunting tutorial.   https://www.youtube.com/watch?v=HCREx_q55mw

b) I’d recommend upgrading to a flat-resistant tire, at least on the rear.  (May as well do both.)  Ask dealer for if you can trade out the tires for some credit towards the purchase.  Kevlar is good (though more expensive).   I haven’t had a flat on Kevlar tires in 4 years, riding 300 days/year.

3) Test drive it:  how’s the lowest gear on your local terrain?

a) Find a decently steep hill.  My wife rides internal gearing, the Shimano Alfine 8-speed hub, and here on the modest yet significant hills of Madison, Wisconsin, her lowest gear is perfectly doable.

b) Note:  one mustn’t shift internal gearing under load.  That’s something the LBS might forget to tell you.  This is certainly not a deal-breaker.  It just takes some dexterity to let up the force when shifting.  Definitely don’t want to stand up pedaling when shifting an IGH.  Some user reviews claim the NuVinci N360 hub is the exception to this rule.  (See the Novara Gotham, below.)

4) Misc. questions:  Rack mounts, front and rear?

One reviewer called the Soho Deluxe a “thief magnet” because it has a “flashy appearance.”  I think it’s the opposite.  It’s got a low-key, even stealthy, paint job.  Plus, theoretically, it may be even less likely to be stolen, for the fact of the belt-drive.  Rational bike thieves avoid specialty bikes because pawn shops may balk at buying such easily identifiable items.

COMMUTER-BIKE ALTERNATIVES for 2014-15

The market for low-maintenance commuter bikes (belt drive, internal gearing) seems to be shrinking in the middle ($1000 – $1400), while growing at the lower end ($600-900) and higher end ($1500 – $2500).  Back in 2012-13 there were many more models in the middle price range.  I had to really hunt for these:

Raleigh Misceo 4.0 2013

Great closeout deals

— Alfine hub (an upgrade over the Nexus hub of the Soho Deluxe)

$1100 closeout

http://www.rei.com/product/848626/raleigh-misceo-trail-i11-bike-2013

Raleigh City Sport DLX

$1100

http://www.bicycling.com/gearfinderProductDetail?gfid=78254

Breezer Beltway 8

$1500

http://www.bicycling.com/bikes-gear/bikes-and-gear-features/best-urban-bike-breezer-beltway-infinity

Novara Gotham

$1400

http://www.rei.com/product/857590/novara-gotham-bike-2014

— NuVinci N360 hub

Scott SUB 10

$1300

http://www.rei.com/product/865741/scott-sub-speed-10-bike-2014

Focus Planet 2.0

$1400 (not widely avail. in US)

http://www.paragonsports.com/shop/en/Paragon/focus-bicycles-usa–inc-belt-drive