Showing posts with label eBusiness. Show all posts
Showing posts with label eBusiness. Show all posts

Tuesday, September 30, 2008

Google trading goes nuts at the end o' the day


Checking my portfolio this afternoon, I noticed Google (NASDAQ:GOOG) had dropped 80 points in the last few minutes of trading! MarketWatch reports that NASDAQ is canceling certain bizarre Google trades:

Nasdaq said Tuesday afternoon that it has cancelled certain trades made on shares of Google Inc. (320.50-60.50-15.88% 5:39pm 09/30/2008 minutes before the closing bell Tuesday. In a statement, the exchange said it will cancel all trades on the stock at or above $425.29 and at or below $400.52 that were executed between 3:57 and 4:02 Eastern. The exchange also said it will be adjusting the Nasdaq Official Closing Cross (NOCP) and all trades executed in the cross to $400.52. The decision came after data late in the trading session seemed to indicate that shares of Google - which were trading up about 8% for most of the session - fell between 10-16% in the final minutes before the closing bell. The statement from Nasdaq did not gie [sic] a reason for the other trades.

Only three letters suffice: WTF? Here's the latest chart from Yahoo.

It shows after-hours trading occurring at $411, which seems a bit more like it.

Of course: what the heck really happened?
Continue Reading »

Sunday, September 14, 2008

New Sitemeter: textbook example of a poorly planned project


Many bloggers use Sitemeter, a service that offered simple, useful traffic reports. Even the free service, which I used, was pretty good. I'm using the past tense because the site is down after a project debacle worthy of a systems development case study.

I suppose Sitemeter thought they were competing with a high-end reporting service like Google Analytics. In doing so, they created a new version of the site. It's a montrosity and a usability nightmare: heavy on Flash and nearly devoid of plain old HTML. Using the new version, I could never even find referrals (how users got to my sites) other than through a bulk download of a CSV file into Excel.

The old site made the reports simple and, more importantly, accessible. You could get the last 100 referrals without even logging in, if so configured. I could easily see who was hitting my site from my BlackBerry using a bookmarked URL.

The new site requires a login and, worse, to get any reporting requires the user to download a massive Flash file. On a broadband connection, it took five or ten seconds, depending upon the load on the server, I suppose. Once the Flash application has loaded, the user's presented with a well nigh inscrutable interface that makes psychoanalyzing Michael Moore look like child's play by comparison.

Quickly scanning bloggers' reactions finds us mining terms like "stinko", "bye-bye", "they've ruined [it]", "I hate hate hate hate [it]", "sux", "out of site[meter]", and "goodbye".

The only positive news for bloggers is that the feedback to Sitemeter has been so overwhelmingly negative, they've decided to rollback to the previous version.

Put simply, this is a textbook example of a poorly planned project. You could look at every aspect of the project, from early mockups, to requirements, design, testing, and even migration strategy and find San Andreas-sized faults. I'm not sure which users they vetted the new design with, but my guess it was one guy named Sal who owns an Auto Body shop next door to Sitemeter's office.

Prediction: the rollback will also fail miserably and take at least a day or two. I'll be pleasantly surprised it the old reports are back up by tomorrow morning.

Update: Ann Althouse, Jammie, Say Anything and the Anchoress all have similar reax.
Continue Reading »

Tuesday, September 9, 2008

Google News Archive includes scanned newspapers from yore!


Understatement must be the Official Google Blog's forte. Its announcement that the Google News Archive now includes some scanned newspapers -- reaching back decades -- is, for a researcher, earth-shattering.


Here's an example. I searched the archive for early 20th century references to two different terms: Hitler and Atom:

Time Magazine - Dec. 21 1931:

Adolf Hitler sat in Berlin giving press interviews as though he were already Chief of State. In Leipzig a congress of pharmacists and physicians turned into a typical Fascist rally. Hitlerite orators, drunk with the sound of their own voices, shouted their program to maintain the superiority of "the Nordic race, the finest flower on the tree of humanity." They mentioned the hanging of Marxists, abolition of trade unions, compulsory sterilization of Jews.

But don't worry, little progressives. Mahmoud Ahmadinejad's probably just joking about nuking Israel.

Time Magazine May. 27, 1940:

Atomic Power in Ten Years? Early last year news came from Germany, Denmark and France that hit physicists like a punch in the solar plexus. The massive atom of uranium, heaviest of the 92 elements, had been cracked by neutrons (electrically neutral subatomic particles), yielding some 200,000,000 electron-volts of energy per cracked atom (TIME, Feb. 6, 1939). These uranium explosions or "fissions" were most effectively touched off by slow moving neutrons of only one-thirtieth of one electron-volt energy, so that the energy profit was 6,000,000,000 to 1. Prospect of using atomic power-the old dream of sending a ship around the world on the energy in a pint of atoms-seemed much closer than before. Question: how close?

I'm telling you, this is a freaking treasure trove of information.

We're lucky to be alive in this day and age.
Continue Reading »

Thursday, August 28, 2008

Rub yourself in bacon and throw yourself in the wolf-pen


I thought the use of ActiveX had been banned in most civilized countries.

[This] Novell story is sad bad tale of You Can't Teach Some Dogs Anything At All. I quote:

Secunia, which reported the bugs to Novell, counted at least eight vulnerabilities in the ActiveX control included with the Windows Vista version of the iPrint client, as well as several other flaws in another Windows Vista iPrint component...iPrint is Novell's implementation of the Internet Printing Protocol (IPP), and lets users use, install and manage printers through the browser.

First of all, iPrint sounds like Apple, but it is some kind of Frankensteinian CUPS mutation. But that's a minor nit compared to using ActiveX in a printer client. Do these people feed and dress themselves competently? Is there anyone on the planet who doesn't know that ActiveX is a finely-engineered pestilence that cannot be trusted under any circumstances? ActiveX has one purpose in life: allowing the installation and execution of remote code on a Windows system via Internet Explorer.

ActiveX controls have unfettered access to the entire operating system. Using ActiveX is like rubbing yourself with bacon and flinging yourself into a hyena pack. There is no safe way to use ActiveX. Why it is even necessary for a printer client? The CUPS Web interface for Linux doesn't need ActiveX and it's worked fine for years. There is one for Mac too, which also doesn't need ActiveX, and both of them work in pretty much any Web browser. You don't need the match+flame duo of ActiveX and IE. In fact smart people avoid them like the toxins that they are.

Lest anyone think I am being too mean to poor old defenseless Novell and Microsoft, I recall ActiveX security advisories almost from its inception back in 1996 or so. What has changed since then, twelve years later? Nothing, as this random recent security bulletin shows:

Microsoft has released Security Advisory (955179) to describe attacks on a vulnerability in the Microsoft Office Snapshot Viewer ActiveX control. Because no fix is currently available for this vulnerability, please see the Security Advisory and US-CERT Vulnerability Note VU#837785 for workarounds.

So we need to revise the popular "fool me once" saying:

Fool me once, shame on you
Fool me twice, shame on me
Fool me thousands of times over many years...let's get married!"

Now why is it again that corporate participation is important to FOSS?
Continue Reading »

Sunday, August 17, 2008

Most pathetic phishing attempt of all time



Misspellings in the subject line? Check.

Sender is an anonymous Yahoo account, not the financial institution? Check.

Link you're supposed to click is an IP address? Check.

Odd phrasing, as if authored by a non-English speaker? Check.

Anyone falling for this phish needs their own chapter in Guinness.
Continue Reading »

Saturday, August 16, 2008

BBC introduces new video advertising medium


The Beeb's created a new mechanism for Internet video advertising (first spotted at Powerline).

Not bad!
Continue Reading »

Sunday, August 10, 2008

That ain't a captcha, baby, that's just text!


Check out the "captcha" on the Broadcasting & Cable Online website:

Doesn't it look a bit... well... simplistic? It doesn't even look like a JPG or GIF. And since I was able to highlight the individual characters... harrumph! A View Source revealed:

</style><script type="text/javascript">
document.write('<div id="kphgathsyfwf">');
document.write('<span class="nmphehxddlno">K</span>');
document.write('<span class="sepbxvbjrcva">C</span>');
document.write('<span class="brtdrtazqxkk">I</span>');
document.write('</div>');
</script>
<p><b><span class="ihtfw">Before submitting this form, please type the characters displayed above:</span></b></p>

Heh. I'm sure the spammers will never figure that one out.
Continue Reading »

Saturday, August 9, 2008

An introduction to Security Enhanced Linux (SELinux)


If you've ever wondered what Security Enhanced Linux (SELinux) is all about, RedHat has an excellent webcast featuring Daniel Walsh, one of the lead developers. The webcast provides the history, rationale and current state of the proejct.

The FedoraProject's Wiki also offers some excellent resources.
Continue Reading »

Monday, August 4, 2008

EFF's new tools lets users test for ISP interference


You may have heard about Comcast's denial-of-service attack against BitTorrent users. After initially denying that they'd done anything wrong, they finally came clean only to have their hand slapped by the FCC.

One positive coming out of the case: it no longer takes an investigation by our crack mainstream media to determine whether your ISP is picking and choosing which applications get to make it to your desktop.

In light of today's FCC ruling against Comcast, Electronic Frontier Foundation (EFF) has released a software tool dubbed, "Switzerland," for internet users to check ISP interference of their connections.

Fred von Lohmann, EFF Senior Intellectual Property Attorney says: "The sad truth is that the FCC is ill-equipped to detect ISPs interfering with your Internet connection. It's up to concerned Internet users to investigate possible network neutrality violations, and EFF's Switzerland software is designed to help with that effort. Comcast isn't the first, and certainly won't be the last, ISP to meddle surreptitiously with its subscribers' Internet communications for its own benefit."
Continue Reading »

Sunday, July 27, 2008

How big is the web?


Google software engineers Jesse Alpert and Nissan Hajaj:

Even after removing... exact duplicates, we saw a trillion unique URLs, and the number of individual web pages out there is growing by several billion pages per day.

...This graph of one trillion URLs is similar to a map made up of one trillion intersections. So multiple times every day, we do the computational equivalent of fully exploring every intersection of every road in the United States. Except it'd be a map about 50,000 times as big as the U.S., with 50,000 times as many roads and intersections...

Whoa. One trillion? To give that number a little perspective, one trillion dollars is more than The Anchoress makes off of her blog ads in a month!
Continue Reading »

Wednesday, July 23, 2008

Microsoft kicks off the $300 million Vista salvage operation


Gizmodo:

Microsoft's $300 million campaign to return fire after Apple's "Mac vs. PC" ads with our buddy John Hodgman—which, like it or not, were a wildly successful campaign and definitely helped shape the public's perception of Vista—has begun with this image from microsoft.com

...It makes sense that Microsoft is going for a more conceptual ad here, rather than tick off a list of everything that people should perceive Vista is good at (they already do that on the page the ad points to). I can think of a lot of other future installments, like "At one point, everyone thought witches walked among us" or "At one point, people thought they could turn lead into gold," or "At one point, people thought that it was a good idea to s*** into ditches alongside the city streets."

A few of the choice comments:

Goes to show just how "uncool" MSFT is. Even their ads to say they don't suck, suck.

You mean it's not a good idea to s*** in a ditch? So wait, because the world isn't flat - Vista doesn't suck? That was a perception, that the world was flat. Is Microsoft saying that Vista sucking is just a perception? No, it's a fact. Vista sucks b***s, it's got gaping holes and bugs and so on. I'm a PC guy, but I can still smell crap in the ditch when it's present.

Do I have to install Silverlight to view it? And what the hell is up with microsoft.com?! My first time on the site but WOW it blows and is impossible to navigate!

I haven't used Vista extensively in a long time, but the bugs I had on it were so minor yet so frequent that they frustrated me to no end and I've lost a lot of reason to go back to it...

Completing the tone-deaf quality of the whole campaign is the ship in the illustration -- a design in use about 400 years AFTER Columbus, when round-the-world voyages were routine...

At one point people thought Vista would be good... Then it shipped.

At one point, people thought XP sucked.

At one point, everyone bought our products because there was no other choice.

So i go to microsoft.com and it tells me i should install Silverlight. ok. i download and try to install it. installer tells me i already have a 'newer' version installed. original page still says i should install plugin to 'experience' silverlight. microsoft fails on all fronts all the time. why cant they get it right? why is that? why?

If these are the things that are supposed to be the reason to switch, then Vista is even more dead in the water than i thought. Every single one of those can be done better with non MS software.

At one point Microsoft made passably decent products.

I hope MS aren't spending much on the advert, 'cos I can't think how it could be worse. Is that supposed to be a drawing of the Nina, the Pinta or the Santa Maria, or a frigate from Nelson's navy, circa 1800?

I don't much care for Vista. I don't really feel like UAC is an elegant solution-- it works, but it's the computer equivalent of having a ruler slapped across your fingers whenever you do something ill-advised on your PC. Couldn't they have come up with a less intrusive-- or at least, less annoying-- answer? I hate DWM-- it's such a neat concept, but the implementation is just wonktacular-- and I wish they'd figured out a way to do that kind of seamlessly, instead of making it a giant resource suck-hole. It's not even about having the RAM to run Vista properly-- I do-- but it's about not wasting what you've got. I appreciate that Vista's more secure than XP, by and large, and decidedly so when comparing XP at this point in its lifetime to Vista now-- but give me a copy of XP and a copy of nLite and I'd be much happier. I don't want my OS to be a big drain on my system resources-- I want something snappy and really, really lightweight. It's a consideration I also make when I'm weighing any comparable softwares. I don't really care for bloat. And Vista-- at least, for the foreseeable future until even every cheap Dell box is running a quad-core, 8GB RAM setup-- is just using too much of the system resources for my tastes.
Continue Reading »

Sunday, July 6, 2008

Google releases its open-source RatProxy web app scanner


Last week, Google open-sourced one of its web development tools -- RatProxy. The company describes it as:

A semi-automated, largely passive web application security audit tool, optimized for an accurate and sensitive detection, and automatic annotation, of potential problems and security-relevant design patterns based on the observation of existing, user-initiated traffic in complex web 2.0 environments.

Detects and prioritizes broad classes of security problems, such as dynamic cross-site trust model considerations, script inclusion issues, content serving problems, insufficient XSRF and XSS ([Ed: cross-site request forgery and cross-site scripting, respectively]) defenses, and much more.

But what's it really do?

At heart, it's designed specifically for web 2.0 applications (as opposed to full-blown security proxies like WebScarab and ProxMon, which are more general purpose in nature). WebScarab, for instance, supports automated parameter fuzzing in order to detect SQL injection and XSS, but also supports a zillion other features.

Conversely, RatProxy is designed specifically for assessment of cross-site vulnerabilities with little effort. As opposed to more active scanning tools, it also can run against production systems without fear of DOSsing (denial-of-service) them. RatProxy hones in on five specific types of weaknesses:

• MIME type mismatches: does the reported MIME type match the actual content?
• How do apps behave when cookie-based authentication data is removed from requests?
• Are security tokens sufficiently strong (e.g., can they be guessed) and will they resist replay attacks?
• Are parameters of a request echoed back in the response such that XSS is possible?
• MIME type mismatches: does the reported MIME type match the actual content?
• Can boundary conditions be exploited such that trust mechanisms are spoofable or information disclosure is possible?

The doc is pretty good reading and covers more of the details.

RatProxy should run under most Linux, FreeBSD, MacOS X, and Windows (via Cygwin) configurations.
Continue Reading »

Friday, July 4, 2008

How Google Maps determines your location


These guys at Google are S-M-A-R-T-T.

Wireless phones can make and receive calls because they are connected over the air to a nearby cell tower. The phone knows the ID of the cell tower that it's currently using...

...If the phone has GPS, the Maps application on the phone sends the GPS coordinates along with the cell ID to the Google location server...

...Over millions of such updates, across multiple phones, carriers, and times, the server clusters the GPS updates corresponding to a particular cell ID to find their rough center. So when a phone without GPS needs its own location, the application on the phone queries the Google location server with the cell tower ID to translate that into a geographic location, i.e., lat/long coordinates. Nifty, huh? We think so.

Very, very slick. GPS-equipped phones send a data pair (GPS location as well as cell tower ID) to Google. That data is saved in a database. When non-GPS-equipped phones send their cell tower ID, Google then utilizes the database to compute GPS location.

Consider it crowd-sourcing for location.

The reconstituted Ma Bell (let's just call them AT&V and wave a thanks to the FCC) isn't real pleased.

The telephone carriers' monthly charge for GPS services -- yes, a monthly charge for receiving signals from government-owned satellites! -- isn't nearly as compelling these days.

So, give thanks to Google. They even modified their logo to celebrate Independence Day.
Continue Reading »

People who need to stop writing software


From Camen Design. My favorites:

ISPs - I pay you to put a cable in my house, and let me send things up and down it; no more. I don’t want your useless Anti-Virus products. I don’t want your “Desktop Help” applications. I don’t want your tray icons. I don’t want your proprietary browsers. I don’t want an email address with you. I don’t want your website as my home page (including a Google Search that only shows adverts).

Norton - Somewhere along the line, you decided to protect people from their own computer, rather than protect the computer itself. You have never once written a piece of software that didn't slow a machine down to a painful crawl. Every machine I have come across that has had Norton on it, has had a virus and multiple spywares still there. Your product is so bad, its own uninstaller does not work. You sell a false sense of security, nothing more.

Nokia, and other phone manufacturers - You seem to be under the impression that you are the only piece of software on the computer. You’re happy to rear your ugly face at every boot. You make a simple thing like syncing seem like surgery.Your software is so unweildy, it’d be easier to take up oragami.

nVidia and ATI - A graphics card driver drives the screen. It does not include a tray icon, that handily reminds you that you don’t have a SLI configuration everytime you boot. Your configuration options shouldn’t be so complex that I have to choose between a Basic and Advanced mode, both of which are as equally useless as each other.

Apple's Quicktime didn't make the list, but deserves to. Apple: I just want to play a video on a webpage somewhere. It happens to require Quicktime. I do not want a system tray icon (what in the name of Jerry Wozniak would I do with it anyhow?). I do not want free Quicktime offers. I do not want all of my preferences overwritten. I do not want a desktop icon. I just want to watch the freaking video!

Whew. That was cathartic.
Continue Reading »

Thursday, June 19, 2008

In-flight Internet access: because we're not connected enough


Crotchety old Walter Mossberg (and I mean that in a good way) got to try out the new in-flight Internet access offered on some airlines.

The Gogo service will cost a flat fee of $12.95 for flights of three hours or longer, and $9.95 for shorter trips... The service operates at respectable, if not blazing, speeds -- similar to what you'd get on a cellular broadband service or a slow home DSL line. On my test flight, download speeds varied from 266 kilobits per second to about 1.4 megabits per second, with the most typical speeds hovering between 500 and 600 kbps. Upload speeds were between 250 and 300 kbps. I found that most of the tasks I tested, except for streaming video, felt smooth and normal.

Speeds could degrade on a large plane with scores of people online simultaneously. But Aircell claims it has the technology to make my experience representative for anyone doing common tasks, such as Web surfing and email. During my test flight, eight laptops and six Wi-Fi-enabled smart phones were using the system simultaneously. All registered decent speeds, except for a couple of minutes when the plane was crossing between the zones controlled by the company's ground-based towers.

Aircell gets Internet access to the planes through a network of 92 towers scattered across North America. These essentially are cellphone towers, carrying a high-speed cellphone data signal, except that the Aircell antennas point up, into the sky. A receiver on the underside of the aircraft picks up the signal, which is then distributed through the plane via Wi-Fi.

It's only available in the U.S. (for the time being).

And as for using Skype or otherwise bypassing the brutally expensive Airphones? Gogo reportedly blocks all voice services, so you'll have to stick with IM and email.

Hat tip: Gretawire
Continue Reading »