Mar 28, 2009

MyID.is Now In Public Beta, Aims To Become The Digital Certification Standard

A potential solution to Identity Squatting?


Digital certification platform MyID.is is taking a crack at offering a way for people to claim their real identity online, in order to be able to prevent ID theft and to verify content they publish on their blogs, social networking accounts, photo & video sharing sites, and so on.


As the article points out, it's an ambitious plan and would require not only users signing up and trusting the service but also tools providers offering identity verification. It's a nascent field but worth a shot. Reminds me of when thawte started out.

MyID.is Now In Public Beta, Aims To Become The Digital Certification Standard

Mar 27, 2009

Cloud Computing: Understand the Risks - BusinessWeek

Business Week chimes in the risks to consider when evaluating cloud services:

There are two kinds of risks in putting your data online. One is that you can never be quite sure who has access to your information once it has migrated beyond the hard drives and backup storage devices in your home. The other risk is that the information, and sometimes the applications you need to make use of it, may be available only when you are connected to the Internet and the service is up and running.


Cloud Computing: Understand the Risks - BusinessWeek

Mar 26, 2009

The iPhone Excuse - Gadgetwise Blog - NYTimes.com

Hear, hear!

For all its abilities and powers, the iPhone is a tremendous pocket computer, but a lousy phone.


I also converted to the iPhone from Verizon last Christmas. I'm in the 213/323/818/310 zone, and although CDMA isn't the same juggernaut here as in the Northeast, the AT&T network has plenty of bad moments. Of course we also have canyons for an excuse.

The iPhone Excuse - Gadgetwise Blog - NYTimes.com

The Fog of Cloud Services

I spent a good part of the last hour following links to stories about security and privacy lapses in Google Docs. I started out with a TechCrunch article detailing additional security loopholes that a security expert had recently uncovered including:

* Embedded images in protected documents that never go away and that get saved to an open server
* The new diagram feature of Google Docs saves all previous versions of the diagram and makes them available to anyone who can read the doc, even if you've set the diagram to view only mode
* Sometimes users still can access documents after their permissions have been revoked

These are pretty serious issues for customers who use Google Docs in a true collaborative fashion; where internal contributors create content, collaborate on it, and produce a final version that is shared with a new audience that is only intended to see the final product.

As I followed links in the post I found that earlier in March a Google Docs user uncovered a bug that was overzealous when setting document permissions on collections of documents. I can actually envision the flawed logic of the code behind that button. Burr. Google reacted and took steps to remedy the problem ultimately notifying customers that they created an automated fix that removed all permissions (except the authors) from the affected documents. Pretty dramatic, and having been through things like this before, not without its own risks of corruption and locking people out of documents for good; what would happen if the author is no longer available?

According to the account of the person who reported the bug, the two weeks that Google took to respond and remedy the problem was admirable, despite the fact that "ultra-secret" information was shared with people who should not have seen the information. Not only does this raise the question of how enterprise-ready Google Docs development is but also what customers come to expect of cloud service providers. I wonder if two weeks would have been admirable if this were Microsoft instead of Google. Not to harp on the customer. He was satisfied and the problem was remedied in part due to his own pro activeness.

Bottom line is the stakes are high when it comes to offering enterprise services in the cloud. Not only for the provider but also for the customer. I had considered using Google Docs for a recent project but decided against it because I did not know where the information was going to be stored. Since it was client information I was working with, and not my own, I opted for the much more cumbersome email approach to sharing files. I’m glad I did. The problems caused by posting embedded images to a separate, unprotected store that subsequently does not remove images when the document is deleted is a reminder that users of cloud services have no control over the architecture or infrastructure of the system (unlike an in-house system) and that they are trusting Google is doing the right thing. In this case Google isn't doing the right thing; at least not right now.

To me this begs the question of whether or not Google's developers really understand developing for enterprise requirements. Sharing and collaborating enterprise content is not new (I keep saying that around cloud services) and there are many developers who brought us products like Lotus Notes and Groove that understand the issues in creating systems to share and secure content. What is new, however, are vendors building sharing platforms in the cloud as if they were enterprise-deployed solutions. They are doomed to make the same mistakes that were made in the early days of collaborative systems if they do not tap into the knowledge that enterprise solution developers already know. And customers will fall into those traps if they aren’t careful. I recall a customer account of how an unprotected HR file that listed salaries of all employees made it into the company’s shared store only to be accidentally displayed in a searching demo to executives. Scary as it was, the problem was contained within the intranet. Imagine if that had been in the cloud?

Google Docs is a 2.5-year-old beta product, which should tip customers off to the fact that it’s all one big experiment still. It is one development model to continue to stumble along, make the same mistakes that companies like Lotus and Microsoft spent years learning, and to use its customers as guinea pigs. If the price point (free) is worth it, then customers of Google Docs can have little recourse when something goes terribly wrong. Customers need to consider all cloud services as carefully as they would consider in-house solutions. Checking out the technical facts as well as their risk tolerance before “buying” is likely to mitigate buyer’s remorse. Don’t count on users to be cautious once you bless the service. Users will not be concerned about how a system is implemented to ensure that the information they post is secure. If the tool makes their work easier you can be assured it will be used heavily. Therefore, it’s up to the people who understand IT to make sure that the cloud services that the company uses are satisfactorily implemented and is secure.

Mar 25, 2009

Redux: "Freedom is just another word for nothing left to lose"

- Kris Kristofferson (made famous by Janis Joplin)

UPDATE 3/25/2009: After several conversations with colleagues about how putting your life on public record can come back to haunt you and the recent identity squatting incident my friend is suffering, I decided to re-post this entry I made in February of 2007. I think the issues this article covers continue to become more important than ever. The idea of broadcasting your activities in social networks may raise the risk hackles of the X-Gens but will it be tolerable when Millenials are doing the hiring? This article explores these and other issues with social software, privacy, and changing attitudes. My entire post from February 24, 2007 is below.

The current generation gap is predicated on the expectation of privacy, or rather the lack thereof, according Emily Nussbaum in her New York Magazine article: Kids, the Internet, and the End of Privacy: The Greatest Generation Gap Since Rock and Roll.

Kids today. They have no sense of shame. They have no sense of privacy. They are show-offs, fame whores, pornographic little loons who post their diaries, their phone numbers, their stupid poetry—for God’s sake, their dirty photos!—online.

She's got a good point, if you approach the social software world with the idea that you can't hide anything (no matter how hard you try) then you might as well hide nothing. That attitude allows a greater sense of freedom when posting blog entries and joining social networks.

So imagine today's teens becoming 30-somethings and the impact their attitude will have on business and how people work together. Today's "collaboration enthusiasts" will no longer be reminding users to "link rather than attach". And, gasp, e-mail may eventually become passe? It'll be the old-time "e-mailers" clutching to their PIM devices and personalized tools that will be the ones calling the help desk and recreating the Medieval Tech Support scenario circa 2015.

Still, I suspect that I'm going to be one of those privacy nuts holding out to the end ("compared to the scroll, it takes longer to turn the pages of a book"). I know that as much as I like to share, I also like to hoard. Something I learned as a descendant of the cold war and most likely can only be explained in Jungian terms. The pack rats of the future will store their "stuff" in accessible places (public and corporate networks) and on someone elses dime. Free comes with a price, less privacy. But if you have no expectation of privacy in the first place then the price isn't so high. And if the users are OK with it, then social software and collaboration are just a matter of habit.

Source: Kids, the Internet, and the End of Privacy: The Greatest Generation Gap Since Rock and Roll -- New York Magazine