A site devoted to discussing techniques that promote quality and ethical practices in software development.

Showing posts with label Internet. Show all posts
Showing posts with label Internet. Show all posts

Thursday, May 14, 2015

My experience in using one2free prepaid Mobile Broadband SIM in Hong Kong

I am a regular visitor to Hong Kong and in every visit, I purchase a prepaid mobile broadband data SIM for my Huawei pocket modem to provide Internet service to me. I am no stranger to this kind of SIM as I have used in the past various types of 3HK Data SIM. So after reading so many glowing remarks about the one2free's prepaid mobile broadband SIM, I have decided to give it a test ride this time.

I did some preliminary investigation prior to the visit via their e-mail customer service which I may say is rather responsive by comparison. It would be nicer if they have 3HK's online chat service.

On the whole, I am rather pleased with the performance, the cost, the responsiveness of the customer service which I had to use quite a lot, as you will see, during my stay. Unfortunately, their responsiveness is tarnished somewhat by their answers which clearly indicate that they are let down by their organisation.

Now, with the good bits out of the way, let's go through the bad bits.

Foremost is their web site which is devoid of any useful and helpful information. It would be more helpful if their web site provides some form of instructions in using their services. Such as what happen if you buy the $100 starter kit, what rate will you be charged at. What about the steps to buy the 30-Day Pass with 3GB quota for someone what has not used your product before? What happen when one uses up the quota but still within the 30 days? Will the connection speed be shaped?

In my case, I want to use the 3GB 30-day pass, which according to the published information will cost me HK$148.00. To subscribe to that, one needs to load the prepaid SIM with at least (preferably more) that that amount. At the shop where I purchased the kit, they did not have $50 top up voucher instead they only had $100 voucher which means my SIM card is loaded with $200 and after paying for the 30-Day pass, it has a balance of $52.00.

No where in their web site explaining this and what happens to that balance. For those wanting to go down this path, here is the treatment of the balance.

The 30-Day pass expires after 30 days from the day of subscription. CSL will immediately deduced that amount from your card on subscription. Hence you must load your card up with sufficient amount before you can punch in the code to select the day pass. The amount remaining can be use for other purposes such as making calls or to contribute towards next day pass purchase. It does not expire until 6 months after the activation or from your last top up. In other words, your prepaid SIM card is valid for 6 months as long as there is sufficient fund to pay for the monthly government charges, which is HK$2.

Unless you do not have other SIM to make voice call, this SIM charges (HK$0.3/min) 3 times as much as other CSL SIM ($0.1/min).

The next area of great disappointment is how to monitor the data usage. Their web site for the prepaid starter kit contains wrong and misleading information.

While that site is for the Prepaid Mobile Broadband SIM, the login button is not intended for Prepaid mobile and I only found this out after the event.

This web site expects the user to possess certain degree of psychic to realise that. I was misled by this page and unsuccessfully to get a password or to reset it by following the online link. Out of desperation, I inserted the data SIM into a mobile phone and used the *777 code to successfully reset the 6-digit password for my SIM. The system acknowledges the request and echoes back the password (very security conscious).

Next, armed with my SIM's mobile number and the password, I pressed the login button on that web page. Rather than telling me that my SIM cannot use 'My Account' to manage my usage, it throws a Java Exception message:
type Exception report

message

description The server encountered an internal error () that prevented it from fulfilling this request.

exception

java.lang.IllegalStateException
 org.apache.coyote.tomcat5.CoyoteResponseFacade.sendRedirect(CoyoteResponseFacade.java:418)
 LoginRedirect.doPost(Unknown Source)
 javax.servlet.http.HttpServlet.service(HttpServlet.java:767)
 javax.servlet.http.HttpServlet.service(HttpServlet.java:860)
 sun.reflect.GeneratedMethodAccessor57.invoke(Unknown Source)
 sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:25)
 java.lang.reflect.Method.invoke(Method.java:585)
 org.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:249)
 java.security.AccessController.doPrivileged(Native Method)
 javax.security.auth.Subject.doAsPrivileged(Subject.java:517)
 org.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:282)
 org.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:165)

note The full stack trace of the root cause is available in the Sun-Java-System/Application-Server logs.

Nice? Have they ever tested their program? Why doesn't the web page inform their user that the login page is not for Prepaid user? Surely, they have all the information to tell if the caller's SIM is a prepaid or not.

I raised this issue with the online support as well as visiting one of their customer service centres and was then told that that login button on the web page and "My Account" facility are not for Prepaid users. Surely their web designer can put that few words into their page to warn their user and even better, their program tests and traps that kind of exception and to inform their users in a more meaningful manner. It is not a big ask isn't it. More disturbingly, if that facility is not for prepaid user, why does *777 allows a number belonging to a prepaid SIM to reset password? So amateurish!

So after the visit, I discovered that as a NextG-Prepaid user, I should use this URL http://www.one2free.com/nextg-prepaid while connecting to the CSL using the one2free SIM. Using this URL, I have managed for the next 3 days to make a daily enquiry of my usage.


On the 4th day, when I used that URL, I was confronted with this web page:

Notice that the left hand pane tells me that this is a "My Account" facility, the very facility that I was told that it was not for me.

Not deterred and with a sense of adventure, I pressed the login link which sent me to https://prepaid.hkcsl.com/login with the following login page

The login page asks for the mobile number of the SIM and a password, which I duly use the one that I used the *777 code to reset. The system accepts my inputs and provides me access to my SIM's data. The data usage can be retrieved by pressing the "Promotional Bonus Details" link.


Notice this is a different web page as compared to the previous one via the NextG-Prepaid link.

I sought the customer service for an explanation of how I could access "My Account" when they told me that it is not for me to no avail. We ended up going around and around in circle. The customer service refuses to acknowledge that the URL https://prepaid.hkcsl.com/login is right for me despite being pointed out that the URL containing the word 'prepaid' to indicate that it is for prepaid users.

Even more interestingly is that I can access my prepaid SIM card detail using this URL without having to use a connection provided by CSL SIM while I need to use the one2free SIM in order to use the http://www.one2free.com/nextg-prepaid regardless successful or not. As an experiment, I have just connected to this https://prepaid.hkcsl.com/login some thousands miles away from Hong Kong.

After discovering that I can use this URL to monitor my data usage, I continue to use it ignoring any contradictory comments from the customer service. Incidentally this URL is not disclosed on any of the CSL web pages. It seems that there is a communication problem within the CSL on this issue.

Whatever it is, it is CSL's problem and they need to deal with it. I have supplied all the information, such as SIM card number, mobile number, and modem model. They need to improve their web site to make it more useful and helpful. Don't just throw figures and data on it. Test it with someone who is not a user of your system or product.

Teach your front line support personnel to slow down and take time to explain the various facets of your products. I know you know your products very well but your potential customers DON'T.

Test your web site with any non-sensible data and don't let your Java exception message leak out to the users. That is not an acceptable way to tell your user that they have entered something wrong.

To date, I still have not been offered a logical explanation why the link http://www.one2free.com/nextg-prepaid, I was instructed by the customer service to use, failed after 3 days. And that why I should not use https://prepaid.hkcsl.com/login which works but the customer service next acknowledges that I should use that.

Thankfully, I have a wonderful Internet service and despite all the above mentioned issues, it is still cheaper than 3HK's offering and I still will recommend it to other travelers. Just be prepared for some rough edges.

Wednesday, June 30, 2010

No joy being (mis)classified as a bogon!

About a week ago, I tried to access http://www.translink.com.au, the integrated public transport for South East Queensland, and my browser timed me out unable to reach the site and since then I cannot access that site. Over this period and preceding that, I have not changed any router settings.

A tractrt brought me this typical result:
Tracing route to www.translink.com.au [202.58.101.51]

over a maximum of 30 hops:
1 2 ms 1 ms 1 ms 192-168-1-1.tpgi.com.au [192.168.1.1]
2 24 ms 24 ms 24 ms 10.20.21.36
3 24 ms 24 ms 24 ms 202-7-165-1.tpgi.com.au [202.7.165.1]
4 25 ms 24 ms 24 ms bri-sot-wic-crt2-po1.tpgi.com.au [202.7.171.41]
5 41 ms 42 ms 41 ms syd-sot-ken-crt1-TG-7-0-0.tpgi.com.au [202.7.171.125]
6 42 ms 41 ms 41 ms 202-7-162-246.tpgi.com.au [202.7.162.246]
7 59 ms 59 ms 59 ms 149.59.194.203.static.comindico.com.au [203.194.59.149]
8 59 ms 59 ms 59 ms 149.59.194.203.static.comindico.com.au [203.194.59.149]
9 * * * Request timed out.
10 * * * Request timed out.
11 * * * Request timed out.
12 * * * Request timed out.
13 * * * Request timed out.
14 * * * Request timed out.
15 * * * Request timed out.
16 * * * Request timed out.
17 * * * Request timed out.
18 * * * Request timed out.
19 * * * Request timed out.
20 * * * Request timed out.
21 * * * Request timed out.
22 * * * Request timed out.
23 * * * Request timed out.
24 * * * Request timed out.
25 * * * Request timed out.
26 * * * Request timed out.
27 * * * Request timed out.
28 * * * Request timed out.
29 * * * Request timed out.
30 * * * Request timed out.

Trace complete.

Initially I thought the site might have been down but asking several friends to test reach this site told me the site was up and running. While some using the same ISP as mine, TPG, met with the same fate. A search on the Internet resulted in a thread in a broadband forum discussing this very issue for users on TPG, my ISP, meeting the same fate.

My fate apparently is the result of me, by virtue of my IP address, being a bogon. It is no joy because essentially I cannot do anything as I do not control the IP address allocation. Furthermore, when things like this happening, there is no one-stop shop where you can go to get help and no one authority having the power to arbitrate. The ISP giving me the IP address is not really responsible for my fate; I guess in some way they are responsible for allocating a bogon IP to me. The destination party may be slow to the bogon's classification update announcement to correct the filtering problem resulting my mis-classification. That party may not even understand or aware that they are doing bogon filter using outdated data. Have you ever tried to discuss this kind of technical details on a site's feedback page, if one exists?

This site is of great importance to me as I routinely perform legitimate e-commerce transactions on it to top up my transport stored value smart card. Failure to access this will mean that I have to top up by queuing up at top up stations denying me the convenience e-commerce brings.

Thankfully at the moment, I have two ways to reach this site beating the alleged bogon classification. One is to use a proxy server like http://freeproxyserver.net. The other technique is to use a Tor Browser, which is my preferred way to access this site.

Just to prove that there is nothing wrong with my internet connection and router settings, here is a screen shot showing the successful connection to Translink, showing on the left using Tor Browser, and the failure screen via direct connection using my ISP allocated IP address, shown on the right. The two browsers are running simultaneously.

When using IE8, the message return is that it cannot display the page like this:


Perhaps there is another explanation other than me being a bogon! Checking my IP address against a list of Blacklist Servers using whatismyipaddress.com tells me that I am not blacklisted. So is the reason?

At the moment I am in limbo with two lifelines at the mercy of the Internet magic! If you are contemplating of implementing bogon filtering, be prepared to do frequent update as IP ranges go in and out of the bogon range. Failure will cause unwittingly innocent victims, like me, great problem. Think hard before you use bogon filter.

Saturday, May 15, 2010

How is NBN pricing compared with other country?

I am presently holidaying in HK and has just visited a friend who has just installed Fibre-To-Home service. It is interesting to compare what people in HK pays and that will be charged by iiNet and Exetel using NBN service.

HK is charging HK$99 (which is about AUD14) per month. Australia is one of those few rare countries that still imposes download limit. The HK service does not have download limit.

With is low cost, I am surprised to find in a building with 28 apartments, only 2 have taken up this kind of service. The installation fee is only HK$300 or AUD43 with a contract period of 2 years.

Friday, November 20, 2009

Feeling a bit cloudy

Unless you have not touched the Internet in the past year or so, you would no doubt be bombarded by the latest hype called Cloud Computing while the poster boys of yesterday B2B, B2C, E-Commerce are conspicuously ignored. Surprisingly, those advocates seem to imply Cloud only applies to those modern often rehashed applications.

According to those definitions in here and here, no one can argument that the good IMAP, whose RFC was ratified before the word Cloud Computing was ever conned, does not fit the definition of a Cloud computing application.

Since GMail is now supporting both POP3, which I have been using ever since I used e-mail, and IMAP, I have decided to give this cloud application a try to see what kind of adjustment I had to made or what other problem I can see.

Of course, I am not quite ready to give up my Desktop e-mail client and I am using Thunderbird as the IMAP client. Here are the main issues:

How could I take my mail from GMail to another ISP

In the past, when I switch ISP, I simply change the e-mail client's POP3 servers addresses to my ISP and to tell my friends to switch addresses. Since I am using an e-mail redirection service, I did not have to bother my friends and associates. My e-mail storage is the central repository of all my e-mail correspondence from various ISPs over the years. As long as I have a sound back up policy to adhere to, I do not lose them.

However, with the IMAP, the messages are located on the IMAP server and I cannot take the collection from say the GMail IMAP and give that to XYZ's IMAP and from there to accumulate e-mail sent to XYZ's server. Perhaps it is peculiar to GMail, I don't even have the control on when a file is actually deleted.

I guess this is not uncommon to many person's concern with using Cloud Computing. How can I retrieve the data that ultimately belonging to the user of the Cloud application when that association is broken?

I cannot find anyway to pick up all my e-mail from GMail IMAP and transplant that to another ISP's IMAP. Or could that ever be possible with IMAP technology? The best I could do is to employ a offline e-mail archive program.

How do I read/compose/search my e-mail when I am disconnected

The next annoying issue with IMAP is like Web Mail and you may as well embedded the browser in a Desktop application and calling that a 'IMAP' client. No Internet means no ability to browse through your mails or prepare the responses.

Yes, you can set up your e-mail client to operate in offline mode and when that happens it will download the messages to your client program.

It is not a matter if it can be done but how well it works in practice.

If your WiFi is suddenly cut or you have flown across to the other side of the world without a Wireless Internet service, it is a bit discomforting to know that you should have pressed that button to download all your IMAP messages before losing connectivity. Perhaps Thunderbird cannot do that process automatically.

As said, you may as well work totally with Web Mail via your browser. I guess in all these Cloud Computing, it is all predicated on having connectivity. If that is lost, you may as well be tapping on a piece of slat. It is just a modern version of the good old dumb terminals with the same kind of problems that technology bring.

In the end, I opted to switch back to the trusted POP3. The IMAP was supposed to be more efficient but from my experiments, it seems a lot more wasteful; when I clicked on different folder, the client contacted the server for information.

Monday, August 10, 2009

WSJ trying to annoy readers the dumb way.

I have been collecting RSS feed from my WSJ subscription using the following location:
http://feeds.wsjonline.com/wsj/xml/rss/3_7013.xml

Randomly, WSJ returns articles that really annoy their readers. For example this article appears black over most of the text like this:
Don't dispair, WSJ is not all that smart. To read this, simply type Ctrl-A to select all the text and there you are:
If you do not want to do Ctrl-A, simply delete "public/b" from the URL and you can read it again.

I have no idea why WSJ is doing this kind of stupid thing just to annoy people, could it be Rupert Murdoch, owner of WSJ, is experimenting with different way to annoy people into paying for his online information?

Saturday, June 27, 2009

Is it eBay or eBait?

The online auction site, eBay, is becoming more like eBait to both buyers or sellers of goods. Despite eBay's best effort to stamp out frauds, the customers are still being fleeced and to fend for themselves. Shame.

Thursday, September 18, 2008

Why does software suck - WSJ's latest format

While WSJ's latest update of its web pages are a welcome sign, it adds one very damn annoying feature when showing the indices and the graph as shown here:

This represents the worse design I have ever seen, namely:
  • There is no obvious UI clue of which index that graph represents. If you peer hard enough you might see the first index is of different colour to the rest and that indicates the index that graph represents. What's wrong with a dot or a symbol next to it.
  • If you want to see the graph of another index, you have to hover the mouse over the index. If you are using a mouse that is fine but if you are using a Tablet PC, it is a pain in the neck as that often brings up Market Data Center. A terrible piece of design.

Tuesday, September 9, 2008

Who needs any other spyware?

With one big malware that's the browser, called Chrome, who needs any other one!

Thursday, February 28, 2008

No excuse for using misleading message.

There are two major share registrar companies in Australia, namely ComputerShare or LinkMarketServices. The former one is well built and its reports are comprehensive but I can't say too much of the latter, which is the theme of this topic.

If you want an example of a commercial enterprise hell-bend on misleading their customers, you need not go any further.

The Link updates its system during time when people in the Eastern Seaboard (about 11pm EST) are still up and definitely those on the Western Seaboard are just finishing off their dinner. During its updates, it has no visible sign to inform the user that it is doing an update and that the system is running with reduced capability. Perhaps the developers are too lazy to deal with error message properly. The update time is not published in their web site prominently.

Worse still as you will see, they are using totally misleading message to tell the user that he/she cannot access the data. Wouldn't a phrase like "System in Maintenance Mode. Features unavailable"? Instead this is what they throw up:

This is after they let you successfully logged into your account and when you click on one of the shares in your portfolio. This is a very dangerous messages. It could indicate system data corruption because you are being informed that the share you have selected has incorrect information. Who change this between now and several hours ago, where you could view the materials? What should the user do?

When I first encountered this message, I was about to delete the share and to re-enter.

You get the same message when you enter a new one. Hence you do not know if the details in the one that you've just entered are truly invalid or because the system developers too damn lazy to inform the users appropriately that the maintenance is in progress.

Perhaps the code in this system is in a mess and that exception handling is left to chance rather than methodologically dealt with.

Misleading users is just another form of bugs in the system. Link has updated its web site recently but apart from the sugar-lolly coating, it is still primitive and buggy underneath. The small consolation is that instead of misleading user with the session times out etc, it is now giving me a much shorter and equally misleading message.

Why software users have to put up with this kind of sloppiness and buggy rubbish. Is it trying to project a 24X7 operation but only skin deep?

As a comparison with ComputerShare, I have yet to be misled. This shows that a good share registrar web site without misleading the user is possible.

Sunday, August 19, 2007

CBA Netbank UI gone from bad to worse

Further to my previous blog on the need to test UI on a number of Desktop settings, Commonwealth Bank of Australia's Internet Bank has just rolled out a new UI.

Sad to say that it has gone from bad to worse. See this layout distortion on 120DPI in IE6:
This is bad. The placements of all the controls are all over the places. When the same page is rendered in Firefox 2, the page layout is good compared to this.

Wooden spoon prize for CBA's Web developer.

Wednesday, April 25, 2007

An unscientific way to resuscitate a Netcomm NB5 Modem/Router

Recently, I was helping a friend to sort out their internet problem when they were changing ISP and they wanted to see if they could reuse their modem/router, a Netcomm NB5. They actually suspected that it was slightly faulty.

Of course I needed to get into the modem to alter settings to work with different ISP. Unfortunately they had forgotten the password, which had been changed from the factory default.

To cut the story short, they also wanted to get a WiFi router if they could reuse this modem. So I decided to take it home to replace my NB1300 Plus4 with this one in my home network infrastructure.

After the factory reset I managed to fire up the modem/router connecting to my ISP. For some reason when I switched it over to operate as a bridge providing modem service to my NetGear router, I accidentally caused the NB5 to go into a state that I could no longer acquire an IP address from it. I could not ping it and obviously could not hook the web browser onto it. It was dead for all intents and purposes.

I had met this kind of situation - comatose modem/router - before but with a different brand of router. In that situation, since it was still in warranty, I sent it back.

Since I could not use this comatose modem anymore, I left this powered down for a day or two and tried again with the same result.

Suddenly I vaguely recalled people had tried to hack into or by-pass those PIN protected car stereo unit by putting the device into a freezer. Out of desperation and seeing it couldn't do any more harm, I gave this a try.

I stuck the NB5 into the freezer for about 10 to 15 minutes (I nearly forgotten about it) and then I took it out (nice and cold like a block of ice) to thaw, making sure that I wiped away the moisture as it thawed.

When it reached temperature still lower than room temperature (I did say not very scientific, didn't I?), I powered it up, did another factory reset, plugged in my PC and a minute or so, the PC managed to acquired an IP address and I managed to browse into the settings page.

That boosted my confidence allowing me to change the NB5 to a bridge and providing the connectivity to my NetGear router. This would be my modem for the next few days to determine if it is faulty.

Tuesday, February 6, 2007

Vista firewall - outbound traffic is unblocked by default

It makes one wonder why a company spending so much on their activation scheme on their brand new Operating System is so stupid in configuring their firewall, relying on marketing spin to do the real work.

Take the report on Vista firewall by Robert Vamosi which says:
In Windows Vista, Microsoft says its new Windows Firewall is now two-way, that it adds outbound protection, but a closer look reveals that this is more deceptive marketing spin. With Windows Vista what you get turns out to be a half-cocked firewall that's hardly worth the upgrade.
Moreover he finds the configuration confusing:
It's confusing ... But for outbound--that is, those connections starting within your computer and going out to the Internet-- connections are allowed except when excepted. Here Microsoft uses the good icon. This is not good.
His observation is further supported by correspondence from Symantec, which says:
"We have discovered that though Vista's outbound firewall is 'on' by default, all outbound connects that do not match a rule are allowed. In the default configuration, there are no outbound 'block' rules, only allow rules. In other words, even though [the Windows Firewall outbound protection is] on, it is not doing anything."
This is kind of dumb. I thought Vista is supposed to be much more secure OS. Perhaps they waste too much time on this activation and protection scheme instead of developing proper protection of their user's information. It seems Microsoft values their IP/Information more than the customers'.

Microsoft's defense says:
If we turned on outbound filtering by default for consumers, it forces the user to make a trust decision for every application they run which touches the network. ....The out of box experience would be poor, and they would soon be desensitized to the prompts.
They do not seem to be bothered by firewall like ZoneAlarm or Internet Security From Symantec.

Perhaps this attitude explains why Microsoft has not done anything since the release of Windows 2000 to promote the use of non-admin account leaving their users defenseless against attacks. They build these security model and then encouraging user to run with security turned off by running in admin account. They do not force those rogue programs to correct their security violation. If they do that in year 2000, they would not need this UAC in Vista to support rogue programs.

The confusing Vista firewall experience was further illustrated by David Berlind, who composes a photo gallery of the issue.

Linux, this is your chance to showcase your talent!

Sunday, January 7, 2007

One very good reason not to use Internet Explorer 7

The Microsoft Windows Updates tells me that the IE7 is available to download. So I dutifully allowed this to proceed. What a mistake that is. While it works as a competent browser, it has lost a very important key feature that I desperately need and use frequently.

I am an unwaivering supporter of using LUA (Least Privilege User Account) and I will not deviate from this highly secure modus operandi just to have tab browsing - I have already enjoyed tab browsing way before Microsoft has released IE7 by using Firefox.

After I have installed IE7, I have discovered that I cannot fire up iexplore.exe in the way advocated by Keith Brown to provide a "Windows Explorer" running in admin account. No matter how much I had tried to tweak the IE7, I could not get it to behave like a Windows Explorer. If anyone knows how to do this, please tell me and I will be willing to give the IE7 another try.

Until then I consider IE7 hostile to using LUA and therefore should not be used in machines that are setup using LUA.

Thankfully, there is an uninstallation option to revert the IE back to IE6. Credit must be given to Microsoft for making the reversion so smooth and painless. Now with IE6, I am happy again.

Saturday, December 30, 2006

Asia Internet Disruption - still no messenger

On the 4th day after the earthquake off the southern coast of Taiwan, the Internet service is still not working properly.

Still can't get MSN Messenger going and naturally the Hotmail is down. Thankfully GMail is back.

According to the officials
, the damages are worse than first thought of.

WSJ and NY Times are still working.

Blog Archive