WordPress 2.6.1 is out

After the difficulty I had with the WordPress 2.6 upgrade, I was both hopeful that 2.6.1 would fix some of the bugs, and a little hesitant about the upgrade. Apparently both my anticipations were incorrect. WordPress 2.6.1 was released yesterday, and while there’s no explicit mention of the admin cookie bug that I hit on the 2.6 upgrade, my own upgrade to 2.6.1 was pretty easy.

The full fixed bug list is on the WordPress Trac, so you may want to see if there’s any fixes you need. As another commenter pointed out, there are few security fixes, but that doesn’t mean there aren’t any–the thing about a plugin without headers not appearing on the plugins page raises concerns about hidden malware that might be worth upgrading to avoid. Just remember to clear your cookies before you try to log back into the admin console after the upgrade.

Family vacation time

I’m heading south this afternoon. We’ll stay a day or two with Lisa’s parents, then head to Lancaster on Sunday for the family reunion.

This will be the first Brackbill reunion since my grandfather and aunt passed away. It feels odd to be heading back to Lancaster, a little like one of my feet has come unglued from gravity and I might float away.

At least the weather is going to be nice. It poured last year, which was a little bit of a bummer. And being down on the family farm, where my grandfather grew up and where his grandnephew still lives, is going to be nice in the August heat. I miss that honest humidity of the mid-Atlantic from time to time. I tried to capture it in photos back in 2006, but I think I didn’t succeed in doing it justice.

Grab bag: McCain, solar, Julia, make, code

Grab bag: Cyberwar, MBTA are morons, free licenses upheld

The return of Shannon Worrell

Shannon Worrell, an artist whom I developed a serious musical crush on in Charlottesville in the early ’90s, is recording again after an eight year hiatus and has a new album, The Honey Guide, coming out later this year. This is big news; her last album, released after the breakup of her band September 67, came out in 2000 into a critical vacuum. I liked The Moviegoer but it was too polished for my taste, and her new song (“Driving in the Dark”) has an edge to it that brings back what I liked best about Shannon, the honeyed whiskey voice and sharp eye and lyrical left hook that combined for an unsettlingly brilliant listen.

I had a perpetual cold and perpetual insomnia during my third and fourth year, the spring and summer and fall of 1993, and so used to hang out in a long-forgotten Charlottesville restaurant called the Corner Grill Main Street Grill. It didn’t do nearly the sort of business it needed to pay the rent on its fairly large footprint, which included a spacious upstairs room with a small stage, and it folded in late 1993. But my insomnia loved the coffee there, and my cold was nourished by the grilled cheese sandwiches and chicken soup. And the joint drew the kind of musicians that Charlottesville seemed to create out of the mud: Greg Howard and Tim Reynolds (playing as Sticks and Stones), Boyd Tinsley one memorable night (I dragged my fellow physics interns in the REU program there; he was guesting with Sticks and Stones, and it was a wild improvised set. I ended up peeing next to him in the tiny bathroom, shrinking from his immense height), and Shannon.

The first time I ever saw her, she played a solo set, her and an acoustic, then called up Kristin Asbury to do harmonies. I knew of Kristin from her work in one of the UVA a cappella groups (she was a Sil’hooette, I think) and somehow I felt that I was on stage with them. It was a weird out of body sort of moment that was reinforced by the wonderful Southern gothic strangeness of the songs.

Zalm and I saw her later that summer in another mostly solo show (I think that both Fred Boyce and the cellist who played on Three Wishes were there). There were quite a few funny notes about the songs on the first album, including one about an elderly couple who misheard the lyrics to “Witness” and thanked her very solemnly for her willingness to share personal details. It was a pretty incredible show. The CD came out the next spring; I embedded its tracks in mix tapes and spent the summer singing along to it, stretching out my high range for the first time. (I think that’s a big part of the reason that Reilly Lewis of the Cathedral Choral Society thought I was a first tenor.)

I next ran across her in Tower Records in 1997, when I found the September 67 release. We were both going places: I was doing well professionally, and she had signed a deal with the Enclave and was on the Lilith Fair tour. I played the crap out of Lucky Shoe, again putting it in mixes and sending it to friends. But not all good things last, and September 67 was dropped when EMI/Virgin merger went down. Her last record, The Moviegoer, crossed my path when I was just starting business school and it didn’t make as deep an impression. Then… silence for eight years.

So I’m pretty excited, obviously, about the new record, which is due in October. Along the way I noticed that Shannon didn’t have a Wikipedia entry, so I wrote one.

Real artists: ship, rip 78s, slow-cook beans. Pick one.

VMWare critical licensing bug

According to Matthew Marlowe’s Blog, VMWare instances running ESX 3.5U2 in enterprise configurations have a license management bug that will prevent them from starting, beginning tomorrow.

The post has turned into a list of pretty helpful tips, including:

While the licensing bug does not appear to be related to security issues, this is a pretty good reminder of how mission critical hypervisor software is. It should be held to the same standards as operating systems.

Security: information, MBTA, geopolitical

Isaac Hayes, RIP

I was two or three years out of college when I first listened to Isaac Hayes seriously. I had picked up Shaft in college but, aside from the title track, it didn’t speak to me. I mean, flutes? Really? I just couldn’t get past the instrumentation. I knew there was something funky there but it wasn’t finding me.

And then I picked up, for some unknown reason, the soundtrack to Stealing Beauty, which leads off with Hoover’s (later Hooverphonic’s) “2 Wicky.” I was never a big Hooverphonic fan, but “2 Wicky” set off all kinds of bells in my head, primarily because of the opening, which I knew had to be sampled from somewhere. I did some digging and found it had come from the lead off track on Isaac Hayes’s Hot Buttered Soul, an album I had always assumed was a goof like Shaft. But I was hooked on that opening guitar + backing vox riff, so I picked up Hot Buttered Soul.

And I couldn’t put it down.

That weekend I was driving around Raleigh, North Carolina, with some college friends–we were there for a wedding–and I couldn’t pull the disc out of my car player. I must have played “Walk On By” and “Hyperbolicsyllabicsesquedalymistic” about a hundred times that weekend. The album was so over the top, so drenched in drama and sound, but somehow it touched the same funky center, breathed the same groove, as the Parliament and James Brown that I had been marinating in for the previous four or five years. And it reached deeper than those cuts in some ways–Hayes projected a pain and vulnerability that you’d never hear from the Godfather of Soul.

I was smacked sideways when I heard yesterday about Isaac Hayes’s death. It seems like someone who touched the human condition so deeply shouldn’t be allowed to go so quickly.

Security, privacy, fatuity, and parody

Attack of the Living Dead Friday Random 10

It’s been a good long while–over a year? really??? where did time go?–since I posted one of these. In that time I finished my “listen through” of my music library, so I don’t have a large pool of unlistened to songs on my iPod. Instead, a good many of these are likely to be songs that are already on my playlists, and therefore a little less revelatory. Let’s see what happens.

  1. U2, “11 O’Clock Tick Tock.” 11 O’Clock Tick Tock (Single)
  2. Howard Jones, “No One Is to Blame,” Dream Into Action
  3. Sun Kil Moon, “Si Paloma,” Ghosts of the Great Highway
  4. PJ Harvey, “The Letter,” Uh Huh Her
  5. Maddy Prior, “Singing the Travels,” Silly Sisters
  6. Jamie Lidell, “What’s the Use”
  7. Sarah Blasko, “Don’t U Eva”
  8. Peter Gabriel, “In Your Eyes (special remix)”
  9. M.I.A., “Bamboo Banga,” Kala
  10. Big Star, “Give Me Another Chance,” #1 Record

New mix: “Blasphemous rumors”

I haven’t posted a new mix for a while, and there are a few reasons for that. So I’m jumpstarting by posting a largely unedited theme mix, based on Estaminet’s Sacrilicious mix of a while back. It’s called “Blasphemous Rumors,” and it hits songs with Old and New Testament themes as well as good old fashioned breaking of the third (or second, depending) commandment.

This will also be the last mix I post on Art of the Mix unless a few things change. The site has had some problems with SQL injection vulnerabilities, and the developer chose to fix the vulnerabilities by filtering input–which is fine, but it means that you can’t create a mix with the word “drop” in it, even in a song title (e.g. “Dropkick Me Jesus”). Tip to the developer: the best way to avoid SQL injection is by whitelisting input and parametrizing your queries, not by blacklisting.

So does anyone have a recommendation for a replacement for Art of the Mix? It should ideally support uploading playlists from iTunes.

Money, money, and security

Comprehensive security guide for Windows Communication Foundation

The developer challenge in developing secure code is two-pronged: first, understanding the threat landscape; second, coding defensively and following best practices to avoid creating security vulnerabilities in code. The WCF Security Guide, now available for download from Microsoft, is a pretty impressive document (600+ pages) that combines aspects of both threat landscape definition and specific coding practices, leveraging Microsoft’s Windows Communication Foundation (part of the .NET Framework in version 3 and later).

WCF is an impressive framework that allows the creation of applications that do everything from turnkey SOAP web services to custom communications channels, with tons of flexible configuration options. The downside of the flexibility of the framework is that a lot of the choices it offers have serious security considerations, and the tradeoffs aren’t necessarily clear at development time. For instance, WCF allows the definition of the security mechanism used to protect a communication stream–transport level, message level, or none; encryption, message signing, or both–and using some of the options can make deploying services more complex (must run the service as a user who belongs to a domain, for instance). The guide walks you through a lot of these decisions, as well as basic secure coding practices ranging from input and output sanitization to developing to survive a DoS attack.

Onegin reviews and other musings