Tuesday, June 16, 2009

Learning about proxies in the news, see post on http://strominator.com

The Power of the Proxy

Proxy servers have been in the news as of late, both as a result of the Iran putative election and a new legal case where Microsoft is suing purveyors of advertising click fraud. I thought I would take you through what proxies are, how they can be used for both good and evil, and what all the fuss is about.

First, here is a little background. When you bring up your Web browser, you are asked how you want it to connect to the Internet. Most of us that have home PCs don't use any proxy, and go out to the raw Internet without any fuss or bother. But enterprises that want to cut down on their bandwidth usage, improve performance and security, and have control over what their users see use them all the time. Each browser first checks and sees if the Web page that is being requested is on the proxy's cache, or memory, and if so, it saves a few milliseconds or more by grabbing the page directly, without having to traverse the Internet at all. So proxies are often combined with caching servers to deliver the best combination of features and management. As far as the browsing user is concerned, all this happens without any notification, other than the pages seem to load quicker on their PCs. About the only configuration option is the IP address of the server, which is placed inside the browser options or network settings. And proxies are available for more than just Web protocols, although that is their most popular use case.

That is the good side of proxies. What about the evil side? Proxies are supposed to be for internal users of an enterprise, but if a hacker can find out the IP address of an internal proxy, they can gain access to lots of network resources. This was a common MO for the hacker Adrian Lamo, among others, and you still find corporations that haven't locked their proxies down with the appropriate security. It is also possible for proxies to operate on a user's PC without their knowledge, which is a common way botnets are created.

There are also proxies that are used to make your browsing history anonymous, which can be used for both good and evil; depending on what information you are trying to hide.

Now to the news. Microsoft filed suit in federal court yesterday against three people it claims were defrauding Internet advertisers by having automated programs mimic users clickstreams. They found the fraudulent activities by tracing the actions to two proxy servers. And once they blocked the particular IP addresses of the proxies, the fraudsters would simply alter them in a continual game of cat and mouse. The fraud involved is significant, and ClickForensics estimates that 14% of the total ad clickstream is faked.
http://www.nytimes.com/2009/06/16/business/media/16adco.html

When the Iranian government wanted to block Internet access, several private individuals from around the globe took it upon themselves to set up the open source proxy Squid (squid-cache.org) and other tools on their own networks to get around these blocks. They then publicized (via Twitter) the IP address of their Squid PCs so that anyone could connect to the open Internet, rather than be blocked. Of course, as the government learns of these addresses, they add them to their block list, so another cat and mouse game ensues.

(small self-promotion here) The news is very timely, indeed. I am off next week to work with Blue Coat on producing another of my screencast product review videos on their proxy and caching server line for my WebInformant.tv site. Let me know if you'd like me to do one of these for your product, they are a unique way to promote and explain a product.

Tuesday, June 9, 2009

Faster response times and Google's Wave

For those of you that feel good about yourselves because you are IM'ing and Tweeting, your online life is about to get a whole more complicated thanks to Google. More on that in a moment, first let me set the stage.

I remember back in the day when many of us first got on email and we tried to do everything in it. When we tried to completely replace real-time phone calls and in-person meetings, it was an abject failure: you still needed that give-and-take. And many corporations that put up email support or customer response inboxes quickly found out that they needed to do more than just assign the inbound messages to a staffer: they actually had to respond with a meaningful answer. I remember an article that I wrote back in 2000 where I sent out a test email inquiry to 13 financial services firms and timed how long it took before I got a response. Some sent out automated responses quickly and followed with a more meaningful reply within an hour, some did worse. Ironically, one site where it was hard to find an email address now has one of the currently best self-service Web sites, USAA.com.
http://strom.com/pubwork/fintech2.html

Then came the era of Instant Messaging, and suddenly we didn't have to worry about email response times because we could connect with someone in real time. Some firms got into IM in a big way, particularly to connect remote work teams. And parents found out that IM was another tool in their arsenal of trying to track down their teens' whereabouts in those dicey after-school hours.

Lately everyone is talking Twitter, and that makes IM seem slow. Twitter and I are still getting used to each other, and I am still not sure that it will be tremendously useful to me in the long run. But it is sure fun to experiment with, and thanks to Bank of America being on it, I managed to save myself a bundle in overdraft fees about a month ago. But that is a story for another time. What I have found is that I am sending and receiving fewer IMs these days.

Some of the more interesting experiments in the Twittersphere have to do with aggregating Tweets from a variety of different sources. Take a look at scienceinthetriangle.org, a news site that reports on tech events in the Raleigh-Durham area that is the labor of love of a bunch of volunteers but is probably the best place to go to get up-to-the-minute news and blog posts in the area.

And then there is a new protocol and product coming from Google by way of Sydney Australia called Wave. It was announced a few weeks ago, and while I am still analyzing it, I can tell you that the near-instant response times that we get from our IMs isn't going to be fast enough. What Wave does is similar to a product called Etherpad.com that allows for real-time collaborative composition of documents, but oh so much more. You can thread your conversations, add wiki-like tools to do joint editing, and add email notification and Twitter-like status streams all in a neat bundle. The 80-minute demo video is definitely worth watching, at least the first third, here:
http://wave.google.com/

But before you abandon all hope of every staying current with the latest Internet fad, let's just go back to first principles for a moment and think about what your expectations of customer response times should be these days, and whether your company is coming anywhere close to fulfilling these expectations. With some people (such as my condo board), I have no expectations that I will get a timely response – that is just the type of folks that they are or they just aren't that service-oriented. With others, such as my Tweets to Bank of America, a few hours to reply was better than anything that I have gotten from them. Previously, I had to wait on hold or in line down at my very busy local branch for at least 30 minutes. For other businesses, overnight is still a reasonable expectation.

What I am saying here is that before you scrap yet another response system, take a few days to conduct a census of your customer-facing staff and see exactly what they are delivering now. And maybe try to improve the human side of your response systems that have nothing to do with any underlying technology.

I have no doubt that Wave represents a new way of thinking about how to interact with each other and work together. And while it might be a while before we can actually touch the technology, in the meantime let's not lose sight of how we work with our customers and give them the best possible service.

Thursday, May 28, 2009

Keeping track of your Web site passwords

I have a dirty secret to share with you all today: until recently, I didn't have a very good strategy for keeping track of my various Web site passwords and logins. Near my desk is a worn set of stapled sheets of paper with various notations about which username, email address, and password I have used to authenticate to its services. Luckily, I work alone, but still it bothers me that if someone were to break into my office, those special pieces of paper would probably be the most important thing to find. I know some of you use PostIt notes for this purpose, and keep them where no one would look, such as under your keyboards.

There is a better way, and I will get to it in a moment, but first I want to take you through what some of the other solutions that I have tried and rejected. Since I do most of my work on my laptop, why not just automate the credentials inside my browser? That is good for some of the sites that I use most frequently, but it isn't very secure should someone get a hold of my laptop.

Another idea is OpenID.net, which is an open-source collection of Web sites that federates your identity, including Yahoo, MySpace, Facebook, and others. OpenID sounds really good, until you start to peek under the covers, and realize that if a phisher ever got ahold of just one authentication of yours at one site, they could pretty much gain access to the rest of your OpenID sites. This is more 'phederated ID' and a hacker's paradise. The problem is that once you authenticate properly on one Web site, you can use your OpenID URL to gain access to anything else.

I have mentioned in previous missives Ping.fm and Quub.com that attempt to consolidate all of your social networking logins in one place, and be able to update your status messages across the board. But it is troubling when I get emails from Quub mentioning that they have upgraded their system and "had to clear everyone's existing credentials that were encrypted with the old algorithm. Please re-enter your credentials under Settings …"

RoboForm is another solution, which basically automates the credentials and saves it in an encrypted spot on your hard drive. That is great, but what happens if you are using a different PC?

Another way is to use some form of two-factor authentication, so called because it uses something that you – and only you – have on your possession, such as a special and unique SecurID token. I have one for my PayPal account, it cost $5 and is well worth the added protection that it offers. Basically, no one else can use my account unless they use the token to sign in.
http://tinyurl.com/paypalkey

But the issue with these tokens is that you need one for each of your accounts. There are some vendors who are trying to get around this issue by using one's cell phone as a second factor authentication tool including Phonefactor.com and FireID.com. Both require some integration of their tools into your applications, which isn't very good if you want to apply them universally to all of your Web authentications. FireID's solution involves using a special server that sits on my network, while PhoneFactor requires software agents to download to your desktop or to integrate into your Web applications.

So what else can you do? The service that I am trying out now is from Tricipher and called MyOneLogin.com. It costs $30 a year per user, and everything is done via their hosted service so there is nothing to download, other than an optional Firefox or IE browser plug-in to handle some tasks. You set up a special Web portal for your company, and then add your credentials to the various sites. It comes with hundreds of pre-set applications and works with either special knowledge questions (what was the name of your third-grade teacher) or with your cell phone. The good thing about MyOneLogin is that you can set it up and forget your passwords, because no matter where you are you can login to the portal and then to your applications. You can mix and match Web and internal apps, such as your VPN login, too, without any programming or installing any servers. And it is also a great solution if a company wants to keep control of these credentials to these sites, so when you leave you can't take your logins with you.

Look for one of my WebInformant.tv screencast video demos in the near future that will show you more about the service. And you can try it out for 30 days for free if you are interested. Maybe now I can finally toss those special pieces of paper – but first I will have to make sure to shred them!

Wednesday, May 20, 2009

When to defriend and defollow

When I was growing up as a nerdy teen on Long Island, needless to say I wasn't one of the Popular Kids. Back then we called it Junior High rather than the current appellation Middle School and now nerds are now the new cool kids. In my youth, we didn't have reality shows where beauties met their geeks, Bill Gates hadn't yet gone to, let alone dropped out of college, and the Steves were still eating fruits rather than making Macs. We didn't even have computers, phones still had dials on them, and we all watched one of three network TV channels and read newspapers that came in the afternoon. And all of our parents bought American-made cars.

Ok, enough nostalgia. I give this as background, to explain my own behavior when I started getting involved in social networks. My first thought was to collect as many "friends" as I could, to grow my network quickly and add just about everyone that I had an email address for. Now that I have accumulated a bunch of people on Facebook, LinkedIn, Twitter and Plaxo, I have a different strategy.

I want quality rather than quantity. As my networks have grown – and they still aren't as large as my college-age daughter (see, it is that underdog feeling again) – I have seen the "feed" streams that are produced from all these people just burying me in the details and status updates of their lives. I try to dip into this vast, deep flow of information on a daily basis, but it quickly overwhelms me. I run back to the relative comfort of my email inbox, where at least I can hit the delete key and pare things down to a reasonable single screen of to-do and action items and people that I have to return messages to.

Burger King ran a promotion not too long ago where they asked people to defriend 10 Facebook friends in order to get a coupon for a free burger. They were swamped with thousands of requests, thereby establishing the value of a friend at somewhere around a quarter. That is pretty depressing. I always thought a friend was worth at least a couple of bucks, if not more.

I also want to grow my networks slower, because like anything else on the Internet, I am concerned about customer retention and my networks are my customers. You are the people that will (hopefully soon, puh-lease) pay me money to speak at a conference, write an article or white paper, produce a screencast video, or do some custom product consulting. So I don't want to just spam you with needless updates about what I had for breakfast or insights about my pets or family vacations, although I did get some interesting feedback when I mention the books that I read in my last missive.

So I have gotten pickier about who I add to my various networks. And while I don't want to be as snobby as that Jr. High clique of popular kids, I do think we all need to take a step back and consider what our friending – and more importantly defriending –policies will be going forward.

Over at Twitter (where my network is still "just" a few hundred followers), there is a lot of activity around third-party apps that will automatically increase your network with all sorts of tricks. This is a bad thing, because those networks become less valuable as their feeds become larger. You will be adding more noise to the signal, and as a result, miss out on the important stuff.

I am still figuring out Twitter, to say the least. But I can tell you that my Twitter activities have saved me a grand total of $140, which is the overdraft fee that Bank of America initially charged me when I deposited a check to the wrong account. Through the miracle of social networks, I was able to tweet my bank, email them the information and get them to call me and correct the problem, and probably keep me as a customer.

Now, I don't have all the answers here. Or even some of them. And I am glad that I don't have to deal with the hyper social strata that are Middle School today. But I can take some small comfort that none of my 20-something children have Twitter accounts, at least not yet.

Monday, May 4, 2009

The new breed of eReaders

The New York Times has a story today about progress that is expected on the next generation of eBook readers, but I have already seen this future thanks to a long-time correspondent and independent software developer Hank Mishkoff. The Times story can be found here:
http://www.nytimes.com/2009/05/04/technology/companies/04reader.html

The Times piece talks about the main supplier to the Amazon Kindle and Sony reader, E Ink, and a new entry to the scene PlasticLogic.com who is also mentioned in last month's Technology Review here:
http://www.technologyreview.com/computing/22490/

I don't have a Kindle, but have borrowed a couple of friends' units for a few minutes. It has its own broadband modem that does the selecting and downloading of content and that is why the initial price of the device is so high (around $350). Instead, I have read several books on my iPhone using the Kindle app. You need to go to Amazon's Website using a standard browser and select and pay for which books you want to receive on your phone, and then the download happens relatively quickly once you bring up the app on your phone. I found the iPhone app to be very satisfying for the pulp fiction trash novels that I like to read on planes and other fill-in time when I don't want to drag around my laptop. It is nice to have a book to read "automatically" – without having to carry something else.

But the Kindle and its ilk only do monochrome and static text. They aren't well suited to the hyperlinked world of the Web, and they require specially formatted books for each device – the version that you download for the Kindle will work on both the device itself and the iPhone, but that is about as cross-platform as you get. These books won't work on the Sony reader. And the books aren't free, although Amazon at any specific time has a lot of sales going on, and indeed I found a new series of thrillers by Lee Childs that I have quickly become a fan of, since one of them was available free on Amazon's store. (Great marketing idea, by the way, and yet another way for authors to seed their content to early adoperts.)

So what about Mishkoff's idea? He calls it the "xBook" and incorporates video, full color pictures, and hyperlinks into his reader. The idea being that an inquisitive reader would want to do the same sorts of explorations and Web surfing expeditions that someone who is used to a browser would perform. He has cobbled together a video that demonstrates his idea here:
http://www.WebFeats.com/xBook/

Note that the xBook is still very much a concept and far from an actual product. Mishkoff wants to try to get someone to help fund a project to build a device, or at least some software that will work with existing platforms.

As many of you know, I am a pretty voracious reader and I welcome these experiments. I still buy lots of books and don't think that will change, even with the Kindle et al. coming of age. And do contact Mishkoff (his information is on his Web site) if you are interested in following up with him further.

About Me

My photo
David Strom has looked at hundreds of computer products over a more than 20 year career in IT and computer journalism. He was the founding editor-in-chief of Network Computing magazine, and now writes for Baseline, Information Security, Tom's Hardware, and the New York Times.