Friday, October 15, 2010

Stalking a criminal

The Internet has obviously changed many things. One thing it has changed is crime. Criminals are known to use sites like Craigslist and eBay to sell stolen goods.

It's interesting how people have also used this in the investigation of crimes. For example, a woman recently had a GPS stolen, and used Craigslist to get in touch with someone who was selling a GPS of the same brand the next day. She contacted the guy, got his email address, used that to find his profile on an online dating site, used that information to find him on Myspace....

The police were able to get video footage from a McDonald's where he used her card, and the Myspace profile matched the face of the person on the video.

It's a lesson that (as she says) you never know who you are robbing.

Link to story

Thursday, October 07, 2010

Charging for Web design work

One of my former students emailed me to ask about freelance Web design work, and how much to charge. This is always a very difficult question, and I don't know many people who are comfortable setting rates coming out of college.

Keep in mind that companies will pay what sounds like a really high hourly rate because they are not subject to the overhead that their regular employees have, such as health benefits, office supplies, and other such items.

The difficult part in freelancing early on is figuring out how long things will take. I found as a programmer I had no sense for how long projects would take me to do. People would ask me how long things would take, and I would think it should be a 2 hour project, and I would spend 25 hours on it. I developed that sense over time. Classes like Systems Analysis and Design were great in theory, but when it came to applying the lessons, I fell a little short.

Customers don't really want to pay based on how good you are, so generally, customers should not see your hourly rate. I would suggest creating some base packages. For example, a 5 page Web site should cost X, a 10 page Web site costs Y, etc. You want to be clear with a customer what they are paying for. I found a company that does something like that here, for reference.

You can see they have a base package for $600. For a basic 5-page site, $500-$750 seems to be the going rate. This would generally include the basics of meeting with them, gathering content, designing it, having the user test it, fixing the errors they find, and making the site live. In reality, the technical end of the work will probably take less time than the other components of the project.

Other stuff that is extra, and this is where I would run in to issues. If the customer wants e-commerce stuff, or they want Flash animations, that would be stuff that would cost extra. When they describe the requirements, that is when you have to determine the cost of it. If they describe a Flash animation, keep in mind that is rarely a two-hour gig. Flash animations, Web programming, and e-Commerce projects should include testing and bug fixing time. There have been times where I wrote a program in an hour and then spent 5 hours trying to hunt down a bug. Flash programmers can charge rates of $50-$75 an hour, so a site that is heavy on customization like that will be more costly.

What is very clever is that there is a maintenance package is $50 a month for two hours worth of work, and additional hours are extra. You may want to offer options like "10 hours of updates over the next year for $250, or updates at an hourly rate of $40" rather than constraining someone to a number of hours in a month. By offering a package deal, you may have someone pay for the 10 hours even if they don't need them, just because it looks like a better deal. Also figure most updates will be small changes, so a lower hourly rate is fine.

You can of course work with people on price. There are people I've been eager to work with, and made allowances for them.

You also have to decide if you are going in to the hosting business, or if you are going to arrange for the customers to host things elsewhere. I generally would not want to get in the middle of a transaction between a customer and a Web hosting service. If this is the case, make sure you provide them the username and password for the site. Even if they don't use it, it's professional to make sure they have access to this. I've dealt with people who have no clue about this, and if they ever need to change hosting sites, it's a pain for them. Same idea goes for the domain name purchase. You can direct them, but you probably don't want to be the person in the middle since domain names do need to be renewed.

If you are not doing the hosting yourself, you have to assume some customers may have a URL purchased and a hosting agreement, and others will not. If the customer does not have the infrastructure in place, there is some startup work you have to do to get them up and running, and that may be something you want to charge for. This may be something you want to charge $100 for.

I would recommend the customer set up a billing arrangement directly with the hosting service (like godaddy). If you end up in the middle, your credit card is the one the hosting service has on file. If, however, you are planning on hosting sites yourself, that is something different.

You should always have some sort of portfolio available. For my PCCC students, your capstone project can be a start, but you may want to expand on it and upload it to a server somewhere.

The main problem I think most customers have is that they don't understand that you don't provide content. When they pay for a site, you are taking their existing information and turning it in to a Web site. You will need to meet with someone in their organization, and they should be providing you electronic copies of the information they want on the site. Some customers think you are going to actually write the text for the site, and (unless you want to do this) it needs to be made clear that this is their responsibility, and that you don't provide proofreading services.

As you get better at doing basic Web sites, you can probably get things done quicker and therefore make your business more profitable. You can also change prices as you go along. Notice the site I linked above also includes a year (2010 rate card). You can always change rates yearly (or project to project).

Wednesday, September 29, 2010

Census and computing

The US census brings to mind one of the reasons computers advanced.

The 1880 census took 8 years to tabulate. Of course, the census is done every 10 years, so a long wait for results makes this data almost useless. The fear was that the 1890 census would take more than 10 years to tabulate, which of course makes no sense.

Enter Herman Hollerith and his fabulous mustache. He invented a tabulating machine that helped with this purpose. This tabulating machine allowed them to count survey results in one year. Of course, many early computers used punch cards, so this was one of the forefathers of those computers. I did not know (until I read a little bit of the Wikipedia article) that his company was one of the companies that would merge to form IBM in 1924. Thanks, Wikipedia!

Anyway, the 2010 census results are being tabulated, and you can already see the response rates posted for all towns. Making things more interesting is the use of data mining. We can now use the computers to not only count results, but to do projections, spot trends, and all sorts of stuff that would have been impossible 100 years ago. It looks like President Obama will get the first report by December 31, 2010. Considering surveys were sent out in March and data collection ended in July, that's really amazing turn around time. Now, if everyone just did the data entry on the computer, imagine how quickly it would go!

Anyway, here's the site with the response rates:
http://2010.census.gov/2010census/take10map/

Tuesday, September 21, 2010

Using Google Earth to make $75,000

Just another case of learning from my students...

In class today, we were discussing Google services, including the advanced Google search options, image search, and Google Maps. It came out during class that the town of Riverhead, NY used Google Earth in a very interesting way. People started getting summonses for having illegal pools, and it came out that they were using Google Earth to find this out. Really! Turns out they wrote about $75,000 worth of summonses before people caught on and complained.

NPR did an interview with the chief building inspector of the town, and he said they did it for the protection of the neighborhoods, saying "I use it strictly for safety." Of course, there is some validity there, because as he states, there are requirements to make sure children don't drown, and I agree with that. I also think that, well $75,000 had something to do with it. I'm a little cynical when someone won't admit to that. Of course money making is part of it. It's not just about safety.

In the "DUH" statement of the year, he stated "Most of the people that complained were the ones that didn't have the permits." Of course those are the people that complained, because they were the ones who were directly affected and may or may not have had their right to privacy violated.

The town is no longer doing this, so I think that tells us how they feel about whether it was a good decision. If they thought it was, they would have kept on doing it. My opinion? As someone who worked for a company doing government contracting, we were told that the government could not spy on its own citizens. The government tried to implement domestic spy-satellite imaging through the innocuous-sounding National Applications Office, but this idea was withdrawn over privacy concerns. If the government can't do it using our own satellites, why can they do it using Google's? Again, my opinion, they shouldn't be doing that, but that's me.

The other interesting part is Google. This sort of use of Google Earth is not prohibited, either in the main terms of service or the government agency terms of service addendum. Yes, I checked. In theory, this is fine per Google's viewpoint. Then again, they haven't updated the terms of service in a while.

Thursday, September 16, 2010

Dead Online

Had an interesting discussion during class the other day. We were talking about online gaming and I mentioned the case of Shawn Wooley, the 21-year old who killed himself over Everquest back in 2002.

It always made me wonder how word would get out about things like this. If you are part of online communities (aside from Facebook, where people can post information to the "wall"), how do people find out? When my aunt Judy died in 2000, I remember the hassle of having to get copies of a death certificate to places like banks, retirement companies, health insurance providers, and other places, and with the advent of the Web, this becomes even more complicated. How do you get access to Web sites and other accounts if someone dies? Are things like World of Warcraft, Amazon Associates, Paperback Swap, and other sites things you would want people to have access to after you died? At this point, a World of Warcraft (or Starcraft, or whatever) account might actually be something people would put in their will...a site like Amazon Associates or Google AdWords might have unclaimed income (and continue to generate income). No one is going to change their will every time they change their passwords, so there has to be some other solution.

This is one of those areas where no one has *the* solution yet, so here are a few sites that I have read about.

First of all, there is Death Switch. Death Switch will send you a message at various times and if you do not click on the link and enter a password, they will assume you are dead. At that point, you can have the site email out your usernames, passwords, etc. that you might want your wife, children, friends, etc. to have. Of course, if you take a really long vacation, or if you die and forget to change the email address of the recipient, there are problems!

Another way to do this is to use Legacy Locker. This is a site that is similar in concept, without the replying to emails. The person would assign two verifiers to verify that they weredead, and if so, the information stored on the site would then be released. Of course, there are security issues there as well, if the two verifiers are people who conspire against you!

A little morbid, to be certain, but it's interesting that companies have found ways to make money off of this.

They both have very limited free versions. For the paid versions, Legacy Locker costs $29.99 a year at this point (or a one-time, $299.99 fee), and Death Switch is $19.95 a year.

Thursday, September 09, 2010

Zero-Day exploits

I have pretty tight security on my home system. I have my anti-virus, my anti-spyware, and router with built in firewall. I keep my operating system and anti-virus up-to-date. I feel pretty safe on a day-to-day basis. I sometimes forget that this is not true. We are all vulnerable to "zero-day exploits". These are basically newly discovered ways for you to get a virus (or get hacked, etc) even if your virus scanner and operating system are 100% up-to-date. This is the part of computer security that people don't always understand. Anti-virus programs, anti-spyware programs, the operating system, and things like that all get updated AFTER problems happen, so someone needs to be the first group of people to get this virus. Unfortunately, fixes are often reactive (oh, no, we didn't think of that!) rather than proactive (hmm, how would I exploit this system if I were a hacker?).

Yesterday, Adobe (the company that makes Acrobat and Flash, among other tools) released a statement saying there was a vulnerability in even the latest version of Adobe Reader. This is a free tool most people have installed that reads read-only versions of documents. Sounds pretty innocuous, right? Well, there is an exploit that allows this to beat security. If I were to download a file, my firewall, anti-virus, anti-spyware, and operating system would all be beaten by this exploit.

What helps is avoiding high-risk activities online. File sharing networks and torrents obviously present advantages in the form of free stuff, but even if you have all the protection I mentioned before, you are subject to zero-day exploits. This one is an exploit with Adobe Reader, but it could happen in iTunes, or in Windows Media Player, or Internet Explorer, or Firefox, or any other software package. It can also happen when people download software through these networks and actually run a program on their machine. Just remember that despite the updated anti-virus, you are vulnerable. This doesn't even take in to account the folks who have anti-virus software that they don't subscribe to and don't receive updates to.

(For those of you who understand digital signatures, this is a very clever exploit that seems to take advantage of stolen certificates. Who knows, maybe the hackers used a zero-day exploit to steal the certificates!)

Wednesday, September 08, 2010

Back to School (Fall 2010 Edition)

Today starts a new semester...as I mentioned at some point, I will be teaching two classes at Bergen.

I think in my case I have become very comfortable in Passaic. As a full time faculty member, I have a lot of freedom as to what I do in my classes. As I am a creature of habit, when I found something that worked, I stuck with it.

I have been teaching since 2001, and I hope I have improved each year, but the only place I have taught a formal class is at PCCC. I am impressed with the amount of work the department chair does at Bergen to provide support for the faculty teaching the intro course. I know some faculty resist things like standard tests, etc. However, I generally do not find this offensive. I may be in the minority, but I feel like if we as a community college want four-year colleges to accept our courses, there needs to be some standardization. I have heard it argued that the four-year schools do not standardize, but all we can do is keep our side of the street clean.

My prep time is less because the full time folks have done work setting up tests, assignments, etc. I generally spend a lot of time on assignments, so they have freed up my time. As such, I am going to try new things that I would not have had the time to do at PCCC. There is no doubt that this will make me a better educator.

So today I have INF 101 004, an Intro to IT course similar to PCCC's CIS 107, and INF 163 001, similar to PCCC's CIS 152. My experience at Bergen will certainly serve me well, and I am excited to get started.

Wednesday, August 25, 2010

The Weakest Link: Password Reminders

Security vs. Ease of Use...always is a tradeoff.

I always use an example of a car security system in class. If I could GUARANTEE that no one could steal your car, and it wouldn't be expensive to install, you'd probably go for it, right?

What if I then told you it would take 90 minutes to get in to the car? At that point, the security isn't worth it.

Generally, when you sign up for accounts, you are given very few choices for password hints. For example, what is your mother's maiden name? Or, where were you born?

The problem is that some of these things can be found out from social networking sites or even from personal knowledge. For example, if you friend your mother, everyone who is a friend of yours now knows the answer to that security question, especially if you use the Facebook "related to" option to show she is your mother. Where were you born can be guessed many times as well, even without Facebook. Where I went to high school, I would guess that most of the students were born in the same hospital. In more rural areas, that isn't as tough of a question as you might think. A good private investigator might chat you up in a bar to find out the answer to the question "what was the name of your first pet", if the answer to that question is valuable enough. In divorce cases, this sort of information can be a gold mine. If you are going through a divorce, remember that things like birthdays and anniversaries are things your future ex may know, and they can circumvent your password that way. Even things like "what is your blood type" aren't great, because how many possible choices are there? (A, B, AB, and O, I think). Even questions like "who is your favorite actor/actress" is tough, because answers change.

On the other hand, no one wants the question to be "pick your favorite number between 122 and 488".

Some sites will let you create your own questions, which present their own problems. People may tend to make even easier questions ("what is your middle name"), or really poor questions ("what color shirt are you wearing"). Yes, I've seen questions like this when helping people.

One of the better questions I have seen is "what is your father's middle name". I couldn't tell you the middle name of my friend's fathers, so this would require a little more work. Other good questions might be "what was the first bone you ever broke" - certainly something you would remember, but still vague.

Another clever idea that hasn't taken off is "Passfaces", where people use visual reminders as a password. Clever idea either as a replacement for a password or as something to augment password reminder security, but not mainsteam yet.

The best defense is to pair sets of questions together, asking people to answer multiple questions to get access. Another way would be to give people a checklist, for example, ask "which of the following statements are true about you", give a list of 15 things, and have the person check off which they have done. For example, give statements like:
I have shoplifted something worth more than $10.
I have been to Cincinnati.
My first car was white, yellow, brown, or green.

Have the person check off yes or no for each, and they are only granted access if all 15 questions are correct. Even if someone tries to guess their way through that, that is hundreds of possible responses. The problem here is that the best questions are the deeply personal ones that no one else knows the answer to. These are also the questions people might be shy about answering honestly. For example, the "shoplifted" question is good, but would I really check off "Yes" if this were a password reminder for a company I work for?

Or, you can do what I do, and give fake answers to the questions in a way that you will still remember it. Or, just use your mother's maiden name everywhere and wonder how all your accounts got hacked on the same day.

Tuesday, August 17, 2010

A Vision of Students Today

Students learn differently today than they did even 10 years ago when I was in college. I've been at a number of meetings at PCCC where they emphasize this. It's never easy to change teaching habits.

A few years ago, a professor at Kansas State University put together a video that describes some of these things. Writing on the blackboard should be replaced by more entertaining ways of learning. I grew up on Nintendo, and I personally was bored in college by straight lecture. I think that education is changing, and I think a lot of professors feel like if they are paid to lecture for three hours, they should be lecturing for three hours. I saw this video for the first time last week at an adjunct orientation at Bergen.

I feel like online classes has helped create some momentum in education reform. Professors have had to find ways to redesign education, and this is a good thing.

This video definitely gave me something to think about.

http://www.youtube.com/watch?v=dGCJ46vyR9o

Friday, August 13, 2010

My Fall Plans

As I mentioned earlier, I am taking a leave from PCCC in the Fall semester. I mentioned earlier that I wanted to recharge. However, that doesn't mean I am going to do nothing with my time.

One thing students do not always get to see is how active some professors are outside the classroom. I know it took me three years at Montclair State to figure out that my professors actually had other obligations besides teaching and office hours and course development. I guess it just never crossed my mind that all sorts of things need attending to.

For example, who approves changes to courses and programs? There should be some sort of process where other people in the college can discuss proposed changes. One of my duties has been to prepare some of our curriculum changes, filling out the appropriate paperwork, and getting my department on board. This also involved presenting the changes to our Curriculum Committee (ably chaired by another member of my department, Professor Bamkole). If there were changes suggested by that committee, I would then incorporate them. I would need to present them again at the Academic Council - this is the entire College community. Again, people could make suggestions and I would need to incorporate them. Any small change to a course required at least three meetings and a number of possible revisions. In other words, rewriting a course description might take 30 minutes to rewrite and then 5 hours to document, present, revise, re-present, and revise.

Point being, there are a lot of responsibilities of being a full-time faculty member that are not necessarily obvious. I wanted to update you on my fall plans.

First of all, I will be teaching two classes at Bergen Community College. I am scheduled to teach INF-101-004 (similar to PCCC's CIS 101) and INF-163-001 (similar to PCCC's CIS 152 class, but with more technology and less business. The courses both meet in the late afternoon, which is interesting, since we generally have problems filling classes in those time slots at PCCC. Bergen does things a little differently, so I am working on getting fluent in their WebCT/Blackboard system, as well as learning the INF-101 textbook. It's a book that is taking a really interesting approach to things, and I look forward to trying it out.

I am also working on a few side projects.

I am working on doing some of the supplements for a new edition of the Exploring Access 2010 textbook (test bank questions, etc). I am also working on a manuscript for an Office textbook.

I also will be doing some work with teachers and possibly students through the PRISM program at Montclair.

Should be an interesting semester, to say the least.

Wednesday, August 04, 2010

Microsoft Digital Literacy

Microsoft has a new program available called Digital Literacy. This is part of their efforts to help educate America.

As part of it, they have a set of free trainings available on their Web site. One is a basic computer literacy training, and the other is a slightly more advanced Microsoft Office and Windows training.

For free, why not right?

Link to Site

Wednesday, July 28, 2010

Workshops, and the role of computer training

I just finished a series of workshops with the group I work with at Montclair (PRISM) in conjunction with PCCC. It was very interesting to be working on a joint effort with these groups. I have been working for the PRISM project (and it's previous incarnation, CETERMS) since the summer after my sophomore year. They are a grant funded project that provides teachers with training in the math/science areas. It is actually the place I got my start teaching. Someone was scheduled to do a technology workshop and called out sick. I had been assisting the workshop coordinator, so I knew the workshop, and I gave the workshop that day. I've been doing technology training for them ever since. I've done Internet concepts (and for 1999, that was pretty forward thinking!), PowerPoint, data analysis with Excel...and a few more workshops. I also used to do their Web site (coding the Web pages by hand, instead of with a tool like Dreamweaver). Who knew I would turn out to be good at teaching and would turn it in to my career? I certainly did not, and I don't think the woman who runs the program foresaw this either.

Anyway, this summer presented a very interesting challenge. The theme that was chosen for PCCC and PRISM to work together was Forensic Science. I didn't really see any way I fit in to this, but eventually as I worked to liaise between the two groups, I noticed they had fingerprinting database software. Basically, it would be able to look up people's fingerprints and match them to a local criminal database that you create. It's not FBI, but it's good enough for training and small police forces. When I suggested including that, I was told that they did not have anyone qualified to teach it, and that people were waiting to go to training for the software.

The beauty of studying computers is that once you have a feel for computer interfaces, new technologies are easier to learn. I sat down in front of this program (by a company named Sirchie called ComparaPrint- though oddly enough, I can't find it on their Web site so I can link) and picked it up very quickly, and I have never seen a program quite like this one. I managed to learn how to use the software very quickly because I understand the concepts of databases. This software is basically a big database package, and since I understand databases, all the natural operations (adding a record, performing a query, generating a report) came pretty naturally. Likewise, back in my undergraduate days, I remember teaching myself a programming language called Perl by doing what we called "hacking around". I just sat down, played with the language, and learned the key things in one night. That was easy for me since I learned programming concepts at Montclair (as opposed to receiving training in a specific programming language). Montclair did an excellent job of using the programming language as a vehicle to teach programming concepts.

In most college programs, there is a mix of theoretical concepts and facts, and the general feeling I get is that if you teach students how to learn about their field, it will treat them well going forward. It reminds me of the old saying "give a man a fish, and you will satisfy his hunger...but teach a man to fish, they will eat for a lifetime". Most careers require evolution, and computers perhaps more so, so this is why I do not think it is critical if my students remember what tab the spell check button is on. My personal opinion is that Information Technology should not be a degree where you simply learn where to click around, but a career where you learn how to learn new technologies. This is why, even though I teach software in my application software training classes, I do tend to ask some short answer questions about how the tool can be used.

I had a lot of fun, and I do not think that many people (some of whom may be reading this now, since I did give out this blog address) realized exactly how short of a time I was using that tool.

Saturday, July 17, 2010

How Old Spice just changed social networking

I was watching the baseball All-Star game the other night and there was an Old Spice commercial that came on. This commercial featured a good looking guy basically telling women that their man doesn't look like him, but they could smell like him. It was really over the top and goofy.








So yeah...amusing enough, I chuckled. Were this the end of it, that would have been enough, but the commercial producers arranged for their Facebook, Twitter, and Reddit sites to allow people to tweet/post questions. The actor, a former NFL hopeful named Isaiah Mustafa, then posted an incredible amount of responses...all of which were done in a towel in his bathroom as if he had just left the shower. Some of them were to famous people, and some to random people. Some of the celebrities he tweeted videos to include Demi Moore, George Stephanopoulis, Ellen Degeneres, Rose McGowan, Ashton Kutcher, Ryan Seacrest, Starbucks, and perhaps most famously, Alyssa Milano. Alyssa Milano went back and forth, with the actor posting four videos flirting with her, and even sending her flowers in real life, and prompting Alyssa Milano to post a video response in a towel of her own (view the entire set of videos here).

Apparently, he responded with over 180 videos over a few days, and had 5.9 million video views in the first day, according to this article. The amazing part is that this is getting news coverage, and celebrities are basically giving Old Spice free advertising. This is just one of the most amazing Internet buzzes I have seen. Sadly, the videos seem to be done for now according to the Twitter feed, but I wouldn't be shocked if Old Spice brought them back based on the popularity.

The question for Old Spice is always "will this improve sales" and the answer isn't clear at this point. If nothing else, they generated buzz!

The actor, based on this, was signed to a deal with NBC, who hope to capitalize on his buzz and create a sitcom.

Check out the tweeted video responses here:
http://twitter.com/oldspice

Wednesday, July 14, 2010

Amazon Free Shipping For College Students

Let's say you wanted to purchase one of Kevin Mitnick's books on Amazon. At the moment, "The Art of Intrusion" costs $11.53. If you were to purchase this, you would need to get to $25 worth of purchase to get free Super Saver shipping (5-9 days), or you could pay $3.99 for shipping for this item and get it in 3-5 days.

Amazon also has available a program called Amazon Prime. This will let you get free shipping on most orders, but most of the time to sign up for Amazon Prime costs money ($79 a year).

At the moment, it is free to students. Sadly, for PCCC students, it requires a .edu email address, which our College does not provide. However, for readers who are at other colleges, you may be able to take advantage of this. Amazon does reserve the right to ask you to provide "proof" that you are a college student.

www.amazon.com/student

Thursday, July 01, 2010

Bill Gates joke

I was reading an article by one on my favorite writers, Joe Posnanski, about Lebron Jame and where he will end up.  As a Knicks fan, I am hoping the answer is New York, but we shall see. The article had a joke that was similar to one I had heard about Bill Gates.  It went something like this:

Bill Gates dies and meets with St. Peter in purgatory.  St. Peter says to him "Bill, you did a lot of good in this world, but you are also responsible for Windows ME and Windows Vista.  I'm going to let you decide whether you want to go to heaven or hell, we will take a tour of each."

St. Peter takes Bill on a tour of heaven, and there are angels playing harps, things like that.  Bill thinks this is nice, but is curious as to what hell looks like.  St. Peter takes Bill to hell, and the devil himself takes Bill on the tour.  There are warm, sandy beaches with beautiful women on the beaches, people drinking and playing volleyball, warm sunshine and laughter. 


The devil returned Bill to St. Peter and gave Bill the choice between heaven and hell, and Bill chose hell. 


A week later St. Peter decided to check in on Bill and see how he was doing.  When he got there Bill was chained to a wall, being burned and tortured by demons.  St. Peter asked "How's everything going?". 

Bill said "This is nothing like the hell I visited last week!  What happened to the hell I visited with the beaches and sunshine??"

"That was a demo," replied St. Peter. 

(I've also seen the ending "that was just the screen saver")