Those of us that grew up in the Big Apple remember those obnoxious ads for 1-800-Mattress where the announcer told us to "leave off the last s for savings." The company is still selling bedding and still preying on the general public for its lack of spelling prowess. (They actually purchased the 800 numbers with the misspelled names because so many customers dialed them, but that is a story for another time.)
My point today is about that ending 's' but in another place that might have you losing sleep. I am reminded of their little ditty with an email from a reader who asks if there are many eCommerce sites that still don't use secure Web pages (where they use https: instead of just plain http:) for their shopping carts.
Sadly, they do still exist. I ask you all if you come across examples, to email them to me and I will add them to my strominator.com blog post and publicly shun them. It is time we put a stop to this shoddy practice. Come on people, this is the new millennium, we have better things to worry about, and this is not new technology or hard to do. Why just this week I purchased an SSL certificate – what you need to turn your Web server from http into https -- and it took all of about 10 minutes and less than $50. Godaddy makes it relatively easy to get one and get it setup, and if you don't want to use theirs, there are dozens of others who will take even more of your money for one.
Even Google's Gmail has gotten on board the https cluetrain: last week they turned on a very nice option that forces your browser to open a secure session when you are reading your Gmail account (go to Settings and scroll down to the "browser connection" choice and click the button to "always use https" and then click on save, it is that easy. If you use Gmail, go and do this now and you can thank me later.
Why is this important? Because someone can hijack your browser session and obtain personal information if you leave off the last 's'. This is especially the case when you are using a shared public computer, such as at an airport or library. But it can happen even if you are at work, if your work network has a wireless segment that anyone can see your traffic on just by sitting outside your building, or if someone brought an infected laptop into the office that is recording your sessions.
My correspondent wrote to the eCommerce vendor (in this case, it was the photo printing and sharing site Fotki.com) and asked why they did leave off the last 's.' This is what he got in a reply:
Please don't worry about missing padlock, we no longer use HTTPS on our payment page, because web browsers tend to send warning messages about web page security and some users get confused with that. All credit card transactions are going through the secure network and properly encrypted by means of Java Scripting.
Yeah, and some users are still misspelling "mattress" too and dialing the wrong numbers. Steer clear of these Web sites that are trying to make it easier for others to steal your personal information. And don't leave off that last 's' unless you plan on spending some sleepless nights when your identity is compromised.
Wednesday, August 20, 2008
Wednesday, August 13, 2008
Managing contacts
Last week's thoughts about the past ten years of email have got me thinking about how we collect, maintain, and use our digital contacts. And really, when you think about what and how you use email, it is all about staying in touch with people that we have met, and answering and asking their questions.
To do this right, you need a decent contact manager. And over the years I have used dozens of products, starting with a venerable rolodex card file back in the pre-computer days. There was a great and simple program called Dynodex that ran on Macs that I used for many years: it was fast, it didn't take up tons of screen or computer real estate, and it didn't have a lot of fields to mess with. Right now I use Gmail's contact manager, and while it is cumbersome to have all my contacts online, it isn't fatal, even when (as what happened earlier this week) when Gmail goes down.
I tell you up front that I am not a big fan of Microsoft Outlook. Outlook standalone, without Exchange, is overkill for me, and besides, it ties me too closely to Windows. But there are some people that swear by it (and sometimes swear at it). My sister's company uses Outlook in standalone mode, which is probably the worst choice for any enterprise contact system.
Some people love ACT for keeping track of contacts: I think it is also overkill, and the latest versions have suffered from feature bloat. Really, all I need besides a person's name and email address is a phone number and maybe a short description or job title. I can search through my Gmail archive and see all of my correspondence with that individual, so I don't need to replicate that in ACT. I realize that many people want a lot more out of their contact managers, and that is why ACT and Outlook are so popular.
There are several things that I look for in a contact manager. One is the ability to put a single contact in multiple groups: for example, I could have a client who is a CIO that also is someone that lives in Boston. This person would be in three different contact groups: clients, CIOs, and Bostonians. I have about 50 different groups in Gmail, and one of the reasons I like the service is because I can have this kind of structure – and also for my emails too. Outlook and other desktop emailers only allow messages to be placed in a single "folder." Gmail uses labels, and you can have an almost unlimited number of them, but more importantly, each message can have multiple labels attached. Why is this important? You want to be able to sort through similar collections of people, or find out who on your list meets particular criteria, just to name two actions. Once you start using labels and groups, you wonder how you ever got along without them.
Another test is what happens when the contacts aren't personal, and need to be shared around your enterprise. Then you might want to consider one of several hosted contact management services. I actually wrote something about this for the New York Times last year:
http://www.nytimes.com/2007/11/14/business/smallbusiness/14contact.html
And then there is the issue of what happens when you want to migrate from one contact manager to another, and that is usually hard to do. While most products support some kind of import and export feature, the devil is in the details: for example, Gmail doesn't allow you to export your group memberships of each contact, so you have to re-create that even if you export from one account and import to another Gmail account. Others don't fare well with the free-form text fields: if you have commas or other punctuation inside them, they will mess up the particular contact record.
There are other online services that are somewhat useful for managing contacts, such as Plaxo's Pulse and LinkedIn. Neither works well enough for me to use them exclusively, but are helpful to keep track of when someone has moved to a new job (or in the case of LinkedIn, about to consider such a change). There are also other synchronizing services, such as Glide, but it didn't like to deal with 9,000 addresses and took a while to catch up.
Stepping into this space are the various social networks that try to enumerate all your "friends" but again they are flawed: not everyone you know is a member of one particular social network, and not everyone wants to use the social network as a means to keep up with their business contacts (seeing people's sexual or religious preferences for my business contacts comes under the heading of Too Much Information, for example).
Ideally, I would like one system to use for maintaining my contacts that could also be used as a publishing platform for this newsletter, so you could subscribe to various other editorial products of mine for example, or change the way you hear from me. Most of you like these weekly emails, but not everyone – some people want RSS feeds, for example, which is why I cross post the Web Informant on my Strominator blog too. (I know, brand confusion: I probably should fix this sometime soon.) The social network that understands that will get my immediate attention, for sure.
To do this right, you need a decent contact manager. And over the years I have used dozens of products, starting with a venerable rolodex card file back in the pre-computer days. There was a great and simple program called Dynodex that ran on Macs that I used for many years: it was fast, it didn't take up tons of screen or computer real estate, and it didn't have a lot of fields to mess with. Right now I use Gmail's contact manager, and while it is cumbersome to have all my contacts online, it isn't fatal, even when (as what happened earlier this week) when Gmail goes down.
I tell you up front that I am not a big fan of Microsoft Outlook. Outlook standalone, without Exchange, is overkill for me, and besides, it ties me too closely to Windows. But there are some people that swear by it (and sometimes swear at it). My sister's company uses Outlook in standalone mode, which is probably the worst choice for any enterprise contact system.
Some people love ACT for keeping track of contacts: I think it is also overkill, and the latest versions have suffered from feature bloat. Really, all I need besides a person's name and email address is a phone number and maybe a short description or job title. I can search through my Gmail archive and see all of my correspondence with that individual, so I don't need to replicate that in ACT. I realize that many people want a lot more out of their contact managers, and that is why ACT and Outlook are so popular.
There are several things that I look for in a contact manager. One is the ability to put a single contact in multiple groups: for example, I could have a client who is a CIO that also is someone that lives in Boston. This person would be in three different contact groups: clients, CIOs, and Bostonians. I have about 50 different groups in Gmail, and one of the reasons I like the service is because I can have this kind of structure – and also for my emails too. Outlook and other desktop emailers only allow messages to be placed in a single "folder." Gmail uses labels, and you can have an almost unlimited number of them, but more importantly, each message can have multiple labels attached. Why is this important? You want to be able to sort through similar collections of people, or find out who on your list meets particular criteria, just to name two actions. Once you start using labels and groups, you wonder how you ever got along without them.
Another test is what happens when the contacts aren't personal, and need to be shared around your enterprise. Then you might want to consider one of several hosted contact management services. I actually wrote something about this for the New York Times last year:
http://www.nytimes.com/2007/11/14/business/smallbusiness/14contact.html
And then there is the issue of what happens when you want to migrate from one contact manager to another, and that is usually hard to do. While most products support some kind of import and export feature, the devil is in the details: for example, Gmail doesn't allow you to export your group memberships of each contact, so you have to re-create that even if you export from one account and import to another Gmail account. Others don't fare well with the free-form text fields: if you have commas or other punctuation inside them, they will mess up the particular contact record.
There are other online services that are somewhat useful for managing contacts, such as Plaxo's Pulse and LinkedIn. Neither works well enough for me to use them exclusively, but are helpful to keep track of when someone has moved to a new job (or in the case of LinkedIn, about to consider such a change). There are also other synchronizing services, such as Glide, but it didn't like to deal with 9,000 addresses and took a while to catch up.
Stepping into this space are the various social networks that try to enumerate all your "friends" but again they are flawed: not everyone you know is a member of one particular social network, and not everyone wants to use the social network as a means to keep up with their business contacts (seeing people's sexual or religious preferences for my business contacts comes under the heading of Too Much Information, for example).
Ideally, I would like one system to use for maintaining my contacts that could also be used as a publishing platform for this newsletter, so you could subscribe to various other editorial products of mine for example, or change the way you hear from me. Most of you like these weekly emails, but not everyone – some people want RSS feeds, for example, which is why I cross post the Web Informant on my Strominator blog too. (I know, brand confusion: I probably should fix this sometime soon.) The social network that understands that will get my immediate attention, for sure.
Thursday, August 7, 2008
Ten years of email
This week Google's Gmail crossed the 7 GB storage threshold – meaning
that anyone can get a mailbox with at least that much storage, and for
free, too. (The size continues to increase slightly each day, wonder
of wonders.) It made me stop and think about how much my email habits
have changed in the past ten years, when Marshall Rose and I sat down
to write a book about Internet emails. Back then, 7 GB was a lot of
room for your mailbox, and I don't think anyone imagined that we would
have it free of charge, either.
Of course, one thing that is very odd is that Gmail has been in beta
like, forever it seems. (We are coming up on close to 5 years.) I
wonder when Google will consider it good enough for a release
candidate? If this had been Microsoft, we would be on v 3.1 or
something by now, for sure. One wag suggested that the real product
name is "Gmail Beta." Har har.
Ten years ago, I was using desktop email software to store my
messages. If memory serves me, I used a succession of products,
including Eudora, Thunderbird, and Lotus Notes. When I had problems
with T-bird corrupting my messages about two and a half years ago, I
switched to Gmail, and have been a pretty happy camper for the most
part. What is interesting is that Google hosts the email for my
strom.com domain, again, completely free of charge and with a very
capable user interface as well. I don't need to store my emails on any
desktop, because it lives in the cloud.
So ten years ago, we had the following email programs popular enough
that we included them in our book: Lotus cc:Mail (extinct), Netscape
Messenger (extinct but replaced by Thunderbird you could say), Eudora
Pro (still very much alive, although no longer under the thumb of a
phone handset maker thankfully), Compuserve (not extinct but should
be), AOL (ditto and back then it was on v3), and Microsoft's Outlook
Express (v4 that came with IE v4, and replaced with the Mail app in
Vista).
Curiously, CS and cc:Mail were proprietary software that didn't start
out using Internet protocols and standards, and had their basis in
local area networks (cc:Mail) and closed online systems (Compuserve).
The ones that are still among us are Internet-savvy. Indeed, you could
say that AOL had one of the first popular gateways to Internet emails
(although MCIMail beat it by several years, it wasn't very popular).
Compuserve was also very popular in its day, despite having email
addresses that only a geek could love like 73234,5869. Trying saying
that string often to your friends.
Back ten years ago, we didn't have Web-based emailers that were worth
much of anything. They had few features, couldn't really interoperate
with all that many browsers, and had lots of other quirks. Outlook's
Web interface was dog slow and required all sorts of tricks to work
across a public Internet connection. We wrote in our book: "Either the
market will enforce adult supervision … whereby IMAP technology is …
standardized or a huge opportunity will open up for Web-based email
readers." Gmail has tried to play both ends here, with its support of
the IMAP protocols as part of its service.
In our book, we introduced the concept of having 100% pure Internet
for your email – having products that faithfully implement Internet
standards natively if possible. And yes, Notes/Domino, Groupwise, and
Exchange are all far from 100% pure, which is why they are in decline.
Back ten years ago, email was still a relatively new concept for
corporate communications. You could still find pockets of people who
weren't accessible via a "dot com" email address, and not that many
people put their email address on their business card. It was rare to
find a corporation that would be diligent about answering their emails
from their customers in a timely fashion. Well, some things don't ever
change.
Back then we didn't have the broadband penetration that we do now, and
certainly not the Wifi penetration that we have now. It is perhaps
harder to resist the urge to check your email because it is so
available. With Blackberries, iPhones, and Internet kiosks everywhere
you don't even need a laptop to stay connected. And the US is even far
behind other countries now, sad to say. Ten years ago we still had
dial up modems that we used to get connected. I haven't touched a
modem in so long that I can't remember when, but it was probably
around ten years ago when I started tossing them and not carrying them
on business trips anymore.
One thing that hasn't changed much in ten years is secure email usage:
almost no one does this, despite some major advances in encryption
ease of use. In our book, we called the state of secure email
standards "a sucking chest wound" saying that no one has a solution
that is multivendor, interoperable, and Internet standards based. That
is mostly true today, although there are some solutions that do a
better job at hiding the certificate management and automatically
decrypt and encrypt message traffic. And several multivendor attempts
in the past decade to standardize on approaches have mostly met with
failure. Still, despite the many well-publicized breaches, secure
email remains out of reach of ordinary humans.
I hope you enjoyed my trip down email memory lane. Certainly, email
has become the glue that binds together so much of our communications.
that anyone can get a mailbox with at least that much storage, and for
free, too. (The size continues to increase slightly each day, wonder
of wonders.) It made me stop and think about how much my email habits
have changed in the past ten years, when Marshall Rose and I sat down
to write a book about Internet emails. Back then, 7 GB was a lot of
room for your mailbox, and I don't think anyone imagined that we would
have it free of charge, either.
Of course, one thing that is very odd is that Gmail has been in beta
like, forever it seems. (We are coming up on close to 5 years.) I
wonder when Google will consider it good enough for a release
candidate? If this had been Microsoft, we would be on v 3.1 or
something by now, for sure. One wag suggested that the real product
name is "Gmail Beta." Har har.
Ten years ago, I was using desktop email software to store my
messages. If memory serves me, I used a succession of products,
including Eudora, Thunderbird, and Lotus Notes. When I had problems
with T-bird corrupting my messages about two and a half years ago, I
switched to Gmail, and have been a pretty happy camper for the most
part. What is interesting is that Google hosts the email for my
strom.com domain, again, completely free of charge and with a very
capable user interface as well. I don't need to store my emails on any
desktop, because it lives in the cloud.
So ten years ago, we had the following email programs popular enough
that we included them in our book: Lotus cc:Mail (extinct), Netscape
Messenger (extinct but replaced by Thunderbird you could say), Eudora
Pro (still very much alive, although no longer under the thumb of a
phone handset maker thankfully), Compuserve (not extinct but should
be), AOL (ditto and back then it was on v3), and Microsoft's Outlook
Express (v4 that came with IE v4, and replaced with the Mail app in
Vista).
Curiously, CS and cc:Mail were proprietary software that didn't start
out using Internet protocols and standards, and had their basis in
local area networks (cc:Mail) and closed online systems (Compuserve).
The ones that are still among us are Internet-savvy. Indeed, you could
say that AOL had one of the first popular gateways to Internet emails
(although MCIMail beat it by several years, it wasn't very popular).
Compuserve was also very popular in its day, despite having email
addresses that only a geek could love like 73234,5869. Trying saying
that string often to your friends.
Back ten years ago, we didn't have Web-based emailers that were worth
much of anything. They had few features, couldn't really interoperate
with all that many browsers, and had lots of other quirks. Outlook's
Web interface was dog slow and required all sorts of tricks to work
across a public Internet connection. We wrote in our book: "Either the
market will enforce adult supervision … whereby IMAP technology is …
standardized or a huge opportunity will open up for Web-based email
readers." Gmail has tried to play both ends here, with its support of
the IMAP protocols as part of its service.
In our book, we introduced the concept of having 100% pure Internet
for your email – having products that faithfully implement Internet
standards natively if possible. And yes, Notes/Domino, Groupwise, and
Exchange are all far from 100% pure, which is why they are in decline.
Back ten years ago, email was still a relatively new concept for
corporate communications. You could still find pockets of people who
weren't accessible via a "dot com" email address, and not that many
people put their email address on their business card. It was rare to
find a corporation that would be diligent about answering their emails
from their customers in a timely fashion. Well, some things don't ever
change.
Back then we didn't have the broadband penetration that we do now, and
certainly not the Wifi penetration that we have now. It is perhaps
harder to resist the urge to check your email because it is so
available. With Blackberries, iPhones, and Internet kiosks everywhere
you don't even need a laptop to stay connected. And the US is even far
behind other countries now, sad to say. Ten years ago we still had
dial up modems that we used to get connected. I haven't touched a
modem in so long that I can't remember when, but it was probably
around ten years ago when I started tossing them and not carrying them
on business trips anymore.
One thing that hasn't changed much in ten years is secure email usage:
almost no one does this, despite some major advances in encryption
ease of use. In our book, we called the state of secure email
standards "a sucking chest wound" saying that no one has a solution
that is multivendor, interoperable, and Internet standards based. That
is mostly true today, although there are some solutions that do a
better job at hiding the certificate management and automatically
decrypt and encrypt message traffic. And several multivendor attempts
in the past decade to standardize on approaches have mostly met with
failure. Still, despite the many well-publicized breaches, secure
email remains out of reach of ordinary humans.
I hope you enjoyed my trip down email memory lane. Certainly, email
has become the glue that binds together so much of our communications.
Tuesday, July 29, 2008
When good companies make bad products
What do Zimbra, Knol and MobileMe have in common? All three have come out in the past month, all from companies that have loyal customers and solid revenues, and all three are dogs. Yahoo, Google, and Apple should know better: don't push something out the door before it is baked. I've tried them all, and while I haven't spent tons of time to review them, I have seen enough to know that none of them are ready for real customers.
Zimbra is Yahoo's answer to a desktop email client, like Thunderbird, Microsoft Outlook, or something similar. It allows you to combine a variety of Web-based emailers like Yahoo Mail, Gmail, and AOL (remember them? I know, there are still a few people in my life that insist on using AOL, try to be kind to them and not sneer) into one unified inbox. The trouble is, it is a product that would have been innovative say back in 1997 or 1998. But today? Nope. Gmail does a terrific job organizing my email, and can collect emails from other systems, too.
Yahoo's email software has always been a day late and a dollar short, sorry guys. Icahn doesn't love you for your email – indeed, if he ever did use a computer, that would probably be the last email product he would pick up. It is clunky, the user interface (both the classic one and the current one) are used in classes on bad design principles, and when you have to manage multiple accounts it bogs down like quicksand. Into this environment we have a solution: let's develop a client emailer! Well, at least give them points for diversity training: it comes in Mac, Windows, and Linux flavors. But a dressed up pig still stinks.
I also don't want to go back to a desktop email client for several reasons: First, because I use several computers during the course of my average day, and when I am on the road I don't want to have to bring my laptop and fight through the TSA screening lines and cart it up and down concourses and escalators ad infinitum. Second, because I have forgotten how to set up POP and IMAP mail servers and don't want to have to dig out my book (which I wrote with Marshall Rose back in 1998) to remember how to do it. Finally, I don't want to have to backup my desktop email archive: having it sorted out by Google's Gmail means I don't have to deal with this chore. Scratch Zimbra.
MobileMe is Apple's latest incarnation to its dot Mac service. It's failures have been well documented, and it has been amusing to watch Apple stumble on this one. Again, give them some points for having both a Windows and Mac versions, but they didn't quite get it right: the Windows version doesn't run on Internet Explorer. Hunh? What reality distortion field were you living in, Steve baby? I mean, what do you expect all those Windows users to do, move over to Safari or Firefox just to run your nifty software? I even said Apple's choice of nomenclature was prophetic: remember Windows Me, the version that lasted all of a few months before Microsoft realized what a dog it was? MobileMe is the Apple version for the rest of us.
And now we have Google's attempt at creating another Wikipedia with Knol. Isn't one Wiki-tiki-web site enough for our universe? And I mean the good folks over there all due respect. I like Wikipedia, it is responsible for endless hours of amusement and resolving pivotal factual arguments in my life. Granted, Knol has some nifty name verification features, so that you can at least have some clue who is writing all that free content and whether you want to trust them when you have to cut and paste it into your next term paper. But I couldn't verify my name using either with a credit card or phone number, probably because I have just moved and the addresses aren't on file. Oh well.
But more importantly, why oh why would Google get into the content creation business just to piss off every one of their advertising partners? It doesn't make any AdSense. Some have already claimed that Google IS in the content business already, we just haven't been paying attention. I will leave that argument for another day.
Knol, MobileMe, and Zimbra are all cases of bad products coming from otherwise good companies. Notice I didn't draw any parallels to any number of past Microsoft products, like Bob, Vista, DOS 4, or even MSN for that matter. Remember those?
If you have your favorite bad-product-from-good-company story, please share.
Zimbra is Yahoo's answer to a desktop email client, like Thunderbird, Microsoft Outlook, or something similar. It allows you to combine a variety of Web-based emailers like Yahoo Mail, Gmail, and AOL (remember them? I know, there are still a few people in my life that insist on using AOL, try to be kind to them and not sneer) into one unified inbox. The trouble is, it is a product that would have been innovative say back in 1997 or 1998. But today? Nope. Gmail does a terrific job organizing my email, and can collect emails from other systems, too.
Yahoo's email software has always been a day late and a dollar short, sorry guys. Icahn doesn't love you for your email – indeed, if he ever did use a computer, that would probably be the last email product he would pick up. It is clunky, the user interface (both the classic one and the current one) are used in classes on bad design principles, and when you have to manage multiple accounts it bogs down like quicksand. Into this environment we have a solution: let's develop a client emailer! Well, at least give them points for diversity training: it comes in Mac, Windows, and Linux flavors. But a dressed up pig still stinks.
I also don't want to go back to a desktop email client for several reasons: First, because I use several computers during the course of my average day, and when I am on the road I don't want to have to bring my laptop and fight through the TSA screening lines and cart it up and down concourses and escalators ad infinitum. Second, because I have forgotten how to set up POP and IMAP mail servers and don't want to have to dig out my book (which I wrote with Marshall Rose back in 1998) to remember how to do it. Finally, I don't want to have to backup my desktop email archive: having it sorted out by Google's Gmail means I don't have to deal with this chore. Scratch Zimbra.
MobileMe is Apple's latest incarnation to its dot Mac service. It's failures have been well documented, and it has been amusing to watch Apple stumble on this one. Again, give them some points for having both a Windows and Mac versions, but they didn't quite get it right: the Windows version doesn't run on Internet Explorer. Hunh? What reality distortion field were you living in, Steve baby? I mean, what do you expect all those Windows users to do, move over to Safari or Firefox just to run your nifty software? I even said Apple's choice of nomenclature was prophetic: remember Windows Me, the version that lasted all of a few months before Microsoft realized what a dog it was? MobileMe is the Apple version for the rest of us.
And now we have Google's attempt at creating another Wikipedia with Knol. Isn't one Wiki-tiki-web site enough for our universe? And I mean the good folks over there all due respect. I like Wikipedia, it is responsible for endless hours of amusement and resolving pivotal factual arguments in my life. Granted, Knol has some nifty name verification features, so that you can at least have some clue who is writing all that free content and whether you want to trust them when you have to cut and paste it into your next term paper. But I couldn't verify my name using either with a credit card or phone number, probably because I have just moved and the addresses aren't on file. Oh well.
But more importantly, why oh why would Google get into the content creation business just to piss off every one of their advertising partners? It doesn't make any AdSense. Some have already claimed that Google IS in the content business already, we just haven't been paying attention. I will leave that argument for another day.
Knol, MobileMe, and Zimbra are all cases of bad products coming from otherwise good companies. Notice I didn't draw any parallels to any number of past Microsoft products, like Bob, Vista, DOS 4, or even MSN for that matter. Remember those?
If you have your favorite bad-product-from-good-company story, please share.
Wednesday, July 23, 2008
Using OpenDNS to protect your network
This week we had another Internet security exploit revealed. And while I don't want to get into the details, let's just say that if you aren't using OpenDNS.com for your home network, now is the time to take the five minutes and get it done. It is simple (well, as these things go), it is free, and it will protect you from any number of issues in the future. And you might get better browsing performance as a result.
Before I tell you how to do this, let's have a brief explanation of what the Domain Name System is for those of you that really want to know. Think of what a phone book (remember them, before we used online searches to look up a friend's number, seems so quaint now) does – it allows you if you know someone's name to look up their phone number. The names are in alphabetical order, so if you know the alphabet, you can quickly page through and find the person, if they are listed.
The DNS does something similar, except for computers: if you type in "google.com" it translates that name into a sequence of four numbers, called an IP address, which in this case for google.com is 72.14.207.99. Paul Mockapetris, a gentleman I have spent some time with and one of the Internet bright lights, put the thing together in the early 1980s, which is enshrined in RFC 882, even before Al Gore had invented the Internet itself.
http://tools.ietf.org/html/rfc882
The overall Internet infrastructure has a series of master phone books, or DNS root servers, located at strategic places around the world and maintained by a collection of public, semi-public, and private providers. They talk to each other on a regular basis, to make sure that as we add new domains they are in synch. As you can imagine, if someone wants to "poison" one of the entries, or misdirect Internet traffic to a phony domain, it can be done with the right amount of subterfuge.
Here is where OpenDNS comes into play. When you set up your home network, typically you don't give your DNS settings any further thought. If you have a cable or DSL modem, you hook it up and it automatically gets its DNS settings from the cable or phone company's DNS servers.
What I am suggesting is that you change these settings, to reflect the DNS servers at OpenDNS. There are instructions on their Web site, but basically you specify the two (one is used for backup) DNS IP addresses for your router or DSL/cable modem. If you have a wireless gateway from Netgear or someone similar, you make the entries there. You need to know the router's IP address, and how to access it via its Web interface.
There are a few nice things about using OpenDNS. First, you can set it up to block objectionable domains, so that you might be able to get around your kids seeing something that you would rather they didn't. They also spend time to block known exploit domains, so you have a better chance of not getting trapped by some hacker. You also get better DNS service, because they have servers that will return the domains supposedly faster than the ones for the general Internet. They also catch common typos, so if you are like me and make mistakes typing in names in your browser, they can usually direct you to the place you intended.
How do they make money? If you type in an unknown domain name, you are directed to their search page where they show ads, just like the Google search pages.
OpenDNS is not the answer for everyone, and businesses should go a step further and protect their DNS servers on their networks. While I don't want to get into that here, you can find out more about the explot from the experts, start with this blog post here:
http://www.circleid.com/posts/87143_dns_not_a_guessing_game/
It is sad that the Internet is at risk: this exploit is serious, and goes at the core protocol that everyone uses all day long. Hopefully, the engineers will find a fix soon.
Before I tell you how to do this, let's have a brief explanation of what the Domain Name System is for those of you that really want to know. Think of what a phone book (remember them, before we used online searches to look up a friend's number, seems so quaint now) does – it allows you if you know someone's name to look up their phone number. The names are in alphabetical order, so if you know the alphabet, you can quickly page through and find the person, if they are listed.
The DNS does something similar, except for computers: if you type in "google.com" it translates that name into a sequence of four numbers, called an IP address, which in this case for google.com is 72.14.207.99. Paul Mockapetris, a gentleman I have spent some time with and one of the Internet bright lights, put the thing together in the early 1980s, which is enshrined in RFC 882, even before Al Gore had invented the Internet itself.
http://tools.ietf.org/html/rfc882
The overall Internet infrastructure has a series of master phone books, or DNS root servers, located at strategic places around the world and maintained by a collection of public, semi-public, and private providers. They talk to each other on a regular basis, to make sure that as we add new domains they are in synch. As you can imagine, if someone wants to "poison" one of the entries, or misdirect Internet traffic to a phony domain, it can be done with the right amount of subterfuge.
Here is where OpenDNS comes into play. When you set up your home network, typically you don't give your DNS settings any further thought. If you have a cable or DSL modem, you hook it up and it automatically gets its DNS settings from the cable or phone company's DNS servers.
What I am suggesting is that you change these settings, to reflect the DNS servers at OpenDNS. There are instructions on their Web site, but basically you specify the two (one is used for backup) DNS IP addresses for your router or DSL/cable modem. If you have a wireless gateway from Netgear or someone similar, you make the entries there. You need to know the router's IP address, and how to access it via its Web interface.
There are a few nice things about using OpenDNS. First, you can set it up to block objectionable domains, so that you might be able to get around your kids seeing something that you would rather they didn't. They also spend time to block known exploit domains, so you have a better chance of not getting trapped by some hacker. You also get better DNS service, because they have servers that will return the domains supposedly faster than the ones for the general Internet. They also catch common typos, so if you are like me and make mistakes typing in names in your browser, they can usually direct you to the place you intended.
How do they make money? If you type in an unknown domain name, you are directed to their search page where they show ads, just like the Google search pages.
OpenDNS is not the answer for everyone, and businesses should go a step further and protect their DNS servers on their networks. While I don't want to get into that here, you can find out more about the explot from the experts, start with this blog post here:
http://www.circleid.com/posts/87143_dns_not_a_guessing_game/
It is sad that the Internet is at risk: this exploit is serious, and goes at the core protocol that everyone uses all day long. Hopefully, the engineers will find a fix soon.
Monday, July 7, 2008
A grown-up's guide to legal music downloads
The reason for the title is simple: we all know that a world of music is available for the stealing from any number of sites. But if you want to download music legally – and if you are going to pay for it you might as well get it without any DRM copy protection restrictions -- what are your choices?
Before embarking on this project, I asked my kids if they have ever heard of any of these services. Other than iTunes, I got blank stares. Of course, none of them pay for their digital music, and don't care. Here are the five sites that I spent time with:
eMusic.com offers several different monthly subscription plans for what they claim are from two million DRM-free songs. The cheapest is for 30 song downloads at $12 per month, up to the most expensive at $20 for 75 songs a month. No matter which plan, you get 50 free downloads and you can cancel your subscription at any time. If you want to be really mercenary about the whole deal, you can sign up, take your 50 songs, and cancel within the same day, without spending a dime. You have to sign up before you can browse their store, however.
Rhapsody.com from Real Networks claims more than four million songs, and you can just listen to the full length of up to 25 tracks a month for free, provided you sign up and give them the right to send you unlimited email solicitations. (They are a bix obnoxious in that regard.) If you want to download them, you pay 99 cents per most songs or $10 per most albums. You can only download a song once, and if you use their Windows software, it will automatically add the songs to iTunes (but not Windows Media, they are still a bit huffy after the lawsuits). Mac or Linux users can download a zip file with multiple songs included, and then you have to manually import them into your music library.
Amazon.com has "millions" of songs, but unlike Rhapsody you can only listen to a 30 second sample and not the entire song. They have optional downloading software for Windows, Linux and Mac that will add them automatically to iTunes (or Windows Media) and makes buying multiple tracks simple. If you don't use the downloader, you have to download one track at a time. Each song is 89 or 99 cents, albums range from $6 to $10. The ones I purchased had fairly high encoding rates of 256 kbps. You can only download them once like Rhapsody.
iTunes Music Store (who claims a catalog of five million songs) is beginning to experiment with DRM-free music from some of its publishers. The songs are 256 kbps encoded and cost the same as the copy protected songs. If you have bought a DRM'ed version previously you can upgrade for an additional 30 cents a track or a third of the price of the original album purchase. To do this (not that you want to give Apple any more dough), you go to the iTunes Store within the latest version of the software, click on the link for "iTunes Plus," and then click on the upgrade button. It will show you which of your tracks can be upgraded and what it will cost. Unlike the other services, you are buying an AAC file rather than an MP3, but most portable and PC-based players will be okay with this format.
Finally, there is SpiralFrog.com, an interesting site run by a friend of mine that doesn't charge for its downloads, but only gives you music that contains DRM. They claim 800,000 tracks and have a large music video selection as well. You need to be running a recent version of Windows, Windows Media Player and dot Net Framework. Unlike eMusic, you don't need to register and Install their download manager to browse the site, so you can get an Idea of what they have to offer. But once you install their software, you can download whatever you desire. And one other limitation: you can't copy their tracks to more than two portable players, and you can't play them of course on iPods. You also can't play them on Zunes, which shows you how messed up Microsoft's DRM Is.
So there you have it. There are some choices, other than stealing your music. If you want to do a lot of downloads, I would go with eMusic, especially if you go beyond 15 or so songs a month, but it is a subscription service and right now you might feel as I do that you are paying enough between monthly charges for premium cable, premium DSL, and premium unleaded gas.
If you are the occasional downloader, as I am, then Amazon makes the most sense, especially as I have my music on my Mac and it has a nice client for that OS. You can turn on the one-click ordering and it is effortless. I don't like Rhapsody's corporate culture, and if you use the iTunes player the imports into your library is cumbersome. And while the iTunes Plus Music Store is trying to get more DRM-free tunes, most of its music is still copy-protected, so best to steer clear until that changes. Finally, SpiralFrog has an Interesting twist on the music download, but since I am Mac and iPod-based it Isn't for me.
Before embarking on this project, I asked my kids if they have ever heard of any of these services. Other than iTunes, I got blank stares. Of course, none of them pay for their digital music, and don't care. Here are the five sites that I spent time with:
eMusic.com offers several different monthly subscription plans for what they claim are from two million DRM-free songs. The cheapest is for 30 song downloads at $12 per month, up to the most expensive at $20 for 75 songs a month. No matter which plan, you get 50 free downloads and you can cancel your subscription at any time. If you want to be really mercenary about the whole deal, you can sign up, take your 50 songs, and cancel within the same day, without spending a dime. You have to sign up before you can browse their store, however.
Rhapsody.com from Real Networks claims more than four million songs, and you can just listen to the full length of up to 25 tracks a month for free, provided you sign up and give them the right to send you unlimited email solicitations. (They are a bix obnoxious in that regard.) If you want to download them, you pay 99 cents per most songs or $10 per most albums. You can only download a song once, and if you use their Windows software, it will automatically add the songs to iTunes (but not Windows Media, they are still a bit huffy after the lawsuits). Mac or Linux users can download a zip file with multiple songs included, and then you have to manually import them into your music library.
Amazon.com has "millions" of songs, but unlike Rhapsody you can only listen to a 30 second sample and not the entire song. They have optional downloading software for Windows, Linux and Mac that will add them automatically to iTunes (or Windows Media) and makes buying multiple tracks simple. If you don't use the downloader, you have to download one track at a time. Each song is 89 or 99 cents, albums range from $6 to $10. The ones I purchased had fairly high encoding rates of 256 kbps. You can only download them once like Rhapsody.
iTunes Music Store (who claims a catalog of five million songs) is beginning to experiment with DRM-free music from some of its publishers. The songs are 256 kbps encoded and cost the same as the copy protected songs. If you have bought a DRM'ed version previously you can upgrade for an additional 30 cents a track or a third of the price of the original album purchase. To do this (not that you want to give Apple any more dough), you go to the iTunes Store within the latest version of the software, click on the link for "iTunes Plus," and then click on the upgrade button. It will show you which of your tracks can be upgraded and what it will cost. Unlike the other services, you are buying an AAC file rather than an MP3, but most portable and PC-based players will be okay with this format.
Finally, there is SpiralFrog.com, an interesting site run by a friend of mine that doesn't charge for its downloads, but only gives you music that contains DRM. They claim 800,000 tracks and have a large music video selection as well. You need to be running a recent version of Windows, Windows Media Player and dot Net Framework. Unlike eMusic, you don't need to register and Install their download manager to browse the site, so you can get an Idea of what they have to offer. But once you install their software, you can download whatever you desire. And one other limitation: you can't copy their tracks to more than two portable players, and you can't play them of course on iPods. You also can't play them on Zunes, which shows you how messed up Microsoft's DRM Is.
So there you have it. There are some choices, other than stealing your music. If you want to do a lot of downloads, I would go with eMusic, especially if you go beyond 15 or so songs a month, but it is a subscription service and right now you might feel as I do that you are paying enough between monthly charges for premium cable, premium DSL, and premium unleaded gas.
If you are the occasional downloader, as I am, then Amazon makes the most sense, especially as I have my music on my Mac and it has a nice client for that OS. You can turn on the one-click ordering and it is effortless. I don't like Rhapsody's corporate culture, and if you use the iTunes player the imports into your library is cumbersome. And while the iTunes Plus Music Store is trying to get more DRM-free tunes, most of its music is still copy-protected, so best to steer clear until that changes. Finally, SpiralFrog has an Interesting twist on the music download, but since I am Mac and iPod-based it Isn't for me.
Tuesday, July 1, 2008
The changing nature of pop culture distribution
My wife and I watched the movie Juno last night, and I highly recommend it for your own viewing. But this isn't a review of the movie, what sparked today's essay is how (depressingly) little of its dialogue I didn't understand. This was because of the quick cultural references spoken by the teenagers portrayed in the movie. I guess I am getting to that generation where words like cool and hep cat are no longer part of the lexicon. I know, this isn't a news flash.
It occurred to me that years from now we will watch this movie and need on-screen annotations to explain what they are talking about.
But the movie is a static, finished entity. What is more interesting to watch is how pop culture references are being incorporated into various online media, and how they are passed around, consumed, and transformed as part of the media itself. As the online world becomes more a fixture in our lives, we are seeing a much more complex evolution. It isn't just the insertion of a bunch of slang words, but an almost complete encoding or translation of pop culture itself. Witness leet-speak, the gamer lingo that results from substituting numbers for letters that luckily (for me, at least) peaked a few years ago. The more cynical of us could look upon leet as just a substitution cipher, but it really is more than that, embodying a way of life and world view. (The best example is the Pure Pwnage videos available here:
http://www.purepwnage.com)
The most recent evidence of pop culture is this music video by Weezer (for those of you that don't know, they are a pop music group):
http://www.youtube.com/user/weezer?ob=1
The video contains visual references to a wide variety of topics. The difference is that these are mostly other Internet videos and online personality references. It is a very clever collection too, and like the Juno dialogue I doubt that I got more than a few of them even after repeated viewings.
Back in my misspent youth, we didn't have online videos. (Well, duh!) We were lucky to have black and white TV, and we had to contend with decoding rebus puzzles, and playing Sgt. Pepper backwards on our turntables to hear "Paul is dead" and figuring out Mad magazine's parodies. When we did get computers, we thought the ultimate in geek coolness (sorry, I will try to think of another word that doesn't date me) were Easter Eggs, bits of hidden code that required you to hit five different keys to bring them up.
Now we have fake news that contains some truth and is broadcast every night on the comedy channel, serious news that contains some fake information that is broadcast on the news channels, and music videos that contain sly references to other videos. The mind boggles at the whole interconnectedness of it all. We have invented words used by the fake anchors like "truthiness" that are included in dictionaries, and script writers for reality shows.
Yes, we are at new levels of how pop culture is being incorporated, parodied, and encoded by teens, and others too cool for school, even some noobs (maybe). It will be interesting to look back on this moment in time and see if anyone in the future can figure any of it out, or maybe they'll say, "Wassup with that?"
It occurred to me that years from now we will watch this movie and need on-screen annotations to explain what they are talking about.
But the movie is a static, finished entity. What is more interesting to watch is how pop culture references are being incorporated into various online media, and how they are passed around, consumed, and transformed as part of the media itself. As the online world becomes more a fixture in our lives, we are seeing a much more complex evolution. It isn't just the insertion of a bunch of slang words, but an almost complete encoding or translation of pop culture itself. Witness leet-speak, the gamer lingo that results from substituting numbers for letters that luckily (for me, at least) peaked a few years ago. The more cynical of us could look upon leet as just a substitution cipher, but it really is more than that, embodying a way of life and world view. (The best example is the Pure Pwnage videos available here:
http://www.purepwnage.com)
The most recent evidence of pop culture is this music video by Weezer (for those of you that don't know, they are a pop music group):
http://www.youtube.com/user/weezer?ob=1
The video contains visual references to a wide variety of topics. The difference is that these are mostly other Internet videos and online personality references. It is a very clever collection too, and like the Juno dialogue I doubt that I got more than a few of them even after repeated viewings.
Back in my misspent youth, we didn't have online videos. (Well, duh!) We were lucky to have black and white TV, and we had to contend with decoding rebus puzzles, and playing Sgt. Pepper backwards on our turntables to hear "Paul is dead" and figuring out Mad magazine's parodies. When we did get computers, we thought the ultimate in geek coolness (sorry, I will try to think of another word that doesn't date me) were Easter Eggs, bits of hidden code that required you to hit five different keys to bring them up.
Now we have fake news that contains some truth and is broadcast every night on the comedy channel, serious news that contains some fake information that is broadcast on the news channels, and music videos that contain sly references to other videos. The mind boggles at the whole interconnectedness of it all. We have invented words used by the fake anchors like "truthiness" that are included in dictionaries, and script writers for reality shows.
Yes, we are at new levels of how pop culture is being incorporated, parodied, and encoded by teens, and others too cool for school, even some noobs (maybe). It will be interesting to look back on this moment in time and see if anyone in the future can figure any of it out, or maybe they'll say, "Wassup with that?"
Subscribe to:
Posts (Atom)
About Me
- David Strom
- David Strom has looked at hundreds of computer products over a more than 20 year career in IT and computer journalism. He was the founding editor-in-chief of Network Computing magazine, and now writes for Baseline, Information Security, Tom's Hardware, and the New York Times.