Back in the stone ages of the mid-1990's, I developed Web pages by hand. Some of my students seem pretty impressed that I can still code a page by hand, and seem to want to do things that way as well. My advice at this point is to not do it that way. A good working knowledge of HTML can be useful in order to tweak a page, or if you are writing a script to generate a dynamic Web page. However, for static Web sites, it generally makes a lot more sense to just use a Web development tool such as Adobe Dreamweaver.
As someone who is not a graphic designer, I would have problems making attractive Web sites. If I were really planning on doing Web development, I would either find a graphic designer to work with, or plan on purchasing some sort of package. Many times, designers or design companies will sell templates to Web developers for this purchase. For example, a site like Project Seven sells some really nice designs that I would never be able to create for $60. The nice part is they are designed for use with Dreamweaver, and should cleanly plug right in to your interface.
I look back on some of my early Web work, and it was clumsy, but by purchasing the rights to something like that, I'd be able to make some really professional sites with very little effort.
Computing is such a large topic, that no matter how good you are, there is always something to learn. I personally feel like I learn something new every day. Knowledge is power, and knowledge should be free.
Wednesday, December 29, 2010
Friday, December 24, 2010
NORAD Santa tracker
It always amazes me how people use technology.
As a child, I remember writing a letter to Santa. Now, you can email Santa.
Just to one-up that, NORAD (North American Aerospace Defense Command - a joint Canadian/American effort) has launched a Santa tracker, complete with Google map and computer graphic video. Pretty cool stuff! If I had a small child to show this to, I would certainly do so.
noradsanta.com
Hope everyone has a nice holiday break. Looking forward to doing some recharging myself.
As a child, I remember writing a letter to Santa. Now, you can email Santa.
Just to one-up that, NORAD (North American Aerospace Defense Command - a joint Canadian/American effort) has launched a Santa tracker, complete with Google map and computer graphic video. Pretty cool stuff! If I had a small child to show this to, I would certainly do so.
noradsanta.com
Hope everyone has a nice holiday break. Looking forward to doing some recharging myself.
Friday, December 17, 2010
Java up, Adobe down
...in terms of exploits, anyway. Looks like Java exploits are gaining favor with hackers again lately, according to this CNN article.
One of the problems with the Internet and specifically the World Wide Web is there are so many moving parts. Many novice users do not seem to realize the complexity of it all. Any application software (including Web browsers) present security risks, and when you add in the various plug-ins (such as Adobe Flash Player, Javascript, Microsoft Silverlight, etc.), you have a hacker's paradise. In the typical interaction, you have three points where security breaches can happen:
1) The browser
2) The plug-in
3) When the browser and plug-in interact
A perfect secure world would have no plug-ins at all, but that is not realistic. We are left as end users to hope the developers of the plug-ins secure their products.
Adobe has come under fire a bit for some of their exploits, but it seems as if they have done a good job (albeit, a reactive job) of plugging up some of their security holes. The report linked above shows that the number of Adobe exploits recorded has gone down, while Java exploits have gone up. Does that mean that Adobe has fixed their problems, or does it mean that Java problems are easier to exploit? That I can not tell you.
One of the problems with the Internet and specifically the World Wide Web is there are so many moving parts. Many novice users do not seem to realize the complexity of it all. Any application software (including Web browsers) present security risks, and when you add in the various plug-ins (such as Adobe Flash Player, Javascript, Microsoft Silverlight, etc.), you have a hacker's paradise. In the typical interaction, you have three points where security breaches can happen:
1) The browser
2) The plug-in
3) When the browser and plug-in interact
A perfect secure world would have no plug-ins at all, but that is not realistic. We are left as end users to hope the developers of the plug-ins secure their products.
Adobe has come under fire a bit for some of their exploits, but it seems as if they have done a good job (albeit, a reactive job) of plugging up some of their security holes. The report linked above shows that the number of Adobe exploits recorded has gone down, while Java exploits have gone up. Does that mean that Adobe has fixed their problems, or does it mean that Java problems are easier to exploit? That I can not tell you.
Saturday, December 11, 2010
There's an option for that
One thing many computer users don't seem to intuitively understand is the idea of customization for the programs and apps they are using.
My approach to using software is to try to use the software, and when I find something I don't like, to try to find some way to change it. For example, inside of Microsoft Internet Explorer, you can change the start page. Most computer savvy users know this, but one of my friends just called this morning saying he changed his somehow and couldn't figure out how to switch it back.
This applies to Web sites as well. For example, Facebook allows you to turn off certain notification emails, change privacy settings, and change many other options. Most free email providers allow you to set up "filters", which would basically let you screen your mail (for example, you could have all email from people at a certain college go in to a special folder so it does not fill up your Inbox, but does not get deleted). If you use a site such as Yahoo! Calendar, you can set it up so it will send email reminders for events to a certain email address or phone number by default, instead of having to set that up every time you create a new event. Even games like World of Warcraft are customizable. You can switch things on or off using some of the menus in a game.
Chances are, if you are annoyed by something, there is an option to change it. Don't like Excel starting every file with three worksheets? You can change that. Do you hate it when you open a bunch of windows, and things compress on your taskbar? That can be changed. Would you prefer your Word to always space in one inch when you hit tab instead of a half inch? That can be done. Does your Blackberry give you annoying little "message sent successfully" messages every time you send an email? That can be removed.
The key is knowing that things can probably be changed, and finding the answer on the Internet.
My approach to using software is to try to use the software, and when I find something I don't like, to try to find some way to change it. For example, inside of Microsoft Internet Explorer, you can change the start page. Most computer savvy users know this, but one of my friends just called this morning saying he changed his somehow and couldn't figure out how to switch it back.
This applies to Web sites as well. For example, Facebook allows you to turn off certain notification emails, change privacy settings, and change many other options. Most free email providers allow you to set up "filters", which would basically let you screen your mail (for example, you could have all email from people at a certain college go in to a special folder so it does not fill up your Inbox, but does not get deleted). If you use a site such as Yahoo! Calendar, you can set it up so it will send email reminders for events to a certain email address or phone number by default, instead of having to set that up every time you create a new event. Even games like World of Warcraft are customizable. You can switch things on or off using some of the menus in a game.
Chances are, if you are annoyed by something, there is an option to change it. Don't like Excel starting every file with three worksheets? You can change that. Do you hate it when you open a bunch of windows, and things compress on your taskbar? That can be changed. Would you prefer your Word to always space in one inch when you hit tab instead of a half inch? That can be done. Does your Blackberry give you annoying little "message sent successfully" messages every time you send an email? That can be removed.
The key is knowing that things can probably be changed, and finding the answer on the Internet.
Friday, December 03, 2010
Bring out the Dancing Pigs!
"Given a choice between dancing pigs and security, users will pick dancing pigs every time."
Once someone explained that line to me, I loved it. Basically, Bruce Schneier (a US computer security consultant and cryptographer) explained, "If the computer prompts him with a warning screen like: "The applet DANCING PIGS could contain malicious code that might do permanent damage to your computer, steal your life's savings, and impair your ability to have children," he'll click OK without even reading it. Thirty seconds later he won't even remember that the warning screen even existed."
That basically seems to summarize computer security these days. Users often get taken in by phishing schemes, download viruses, give out personal information, and do other things that compromise security...for the promise of dancing pigs. Smart hackers do this and create attractive links that people will click on.
As you can see, there are tutorials taking potential phishers through the process of stealing information. Stopping sites posting information like that is like playing Whac-A-Mole.

Congrats, you shut down a phishing site! Put down the hammer, I don't think others will pop up!
I do not know that most Americans are adequately prepared to figure out what sites are legitimate and which ones are not (and to read warnings). Sadly, people seem to learn by making mistakes and losing their personal information or getting hacked.
Once someone explained that line to me, I loved it. Basically, Bruce Schneier (a US computer security consultant and cryptographer) explained, "If the computer prompts him with a warning screen like: "The applet DANCING PIGS could contain malicious code that might do permanent damage to your computer, steal your life's savings, and impair your ability to have children," he'll click OK without even reading it. Thirty seconds later he won't even remember that the warning screen even existed."
That basically seems to summarize computer security these days. Users often get taken in by phishing schemes, download viruses, give out personal information, and do other things that compromise security...for the promise of dancing pigs. Smart hackers do this and create attractive links that people will click on.
As you can see, there are tutorials taking potential phishers through the process of stealing information. Stopping sites posting information like that is like playing Whac-A-Mole.
Congrats, you shut down a phishing site! Put down the hammer, I don't think others will pop up!
I do not know that most Americans are adequately prepared to figure out what sites are legitimate and which ones are not (and to read warnings). Sadly, people seem to learn by making mistakes and losing their personal information or getting hacked.
Tuesday, November 30, 2010
Proper Hardware Disposal
In one of my classes last week, we discussed the proper way to get rid of old computer hardware, to avoid privacy issues.
I've gotten rid of old computers, but I generally either keep the hard drives (to destroy) or use software to do a thorough wipe of the drive's data When I say "thorough wipe", I am not talking about deleting files, because data can easily be recovered from a hard drive, EVEN AFTER YOU DELETE IT. Really. As a matter of fact, Microsoft's pre-Windows operating system, DOS, used to include an undelete tool which could recover deleted files easily.
eBay is one place people can purchase used hard drives, and they even provide information on why you need to thoroughly wipe a hard drive before you sell it. You can see that the site shows that social security numbers, credit card numbers, and all sorts of stuff can be found on these hard drives. This means your identity can be stolen even if you do nothing wrong, if a company you have purchased from does not follow good procedures for hard drive disposal. Aside from eBay, there are sites like Craigslist where people get rid of old hardware, and there are always garage sales. In the corporate environment, many colleges and companies pay companies to dispose of old hardware (such as eRevival locally). If you go with a cut-rate company, you may find that though they promise to clean hard drives, they may not do so thoroughly. Any of these are ways that data can be leaked if the hard drives are not wiped.
One way you can provide a level of security is to physically destroy the hard drive, though someone could pick it out of the trash and recover something. The best way is to do a full wipe of the hard drive, or what we used to call a "zeroize" at the company I used to work for. We were putting defense systems in military crafts, and one of the requirements was that the pilot needed to have a button to wipe all the data in the system, to prevent classified data from falling in to the enemy's hands. (Yes, that information is public.)
The Department of Defense has pretty high standards for data wiping, and there are a number of tools that meet their standards. The problem is most of these tools cost money. The one that I recommend is a free tool called Darik's Boot and Nuke (available for download at www.dban.org). Despite the informal name, it is a legitimate program (referenced by CNN and the BBC). There are commercial tools that do this sort of thing as well, but the major difference is not function, it is speed (DBAN has a reputation for being slow - the BBC article says it took two hours for an 80GB drive). DBAN is cool because it gives you a CD to boot off of, and you select the depth of the wipe you want. The more depth you want, the longer it will take to run. If you are going to do this, I would recommend choosing the most in-depth wipe, doing it before you go to bed (as a home user) or before you leave work in the evening (at work), and just letting it run overnight. That way, there is no time wasted waiting for wipe to be completed. In a professional environment, having a DBAN CD around is not a bad thing, especially so your company does not end up in violation with the standards that govern your industry (Sarbanes-Oxley, HIPAA, FACTA, etc.).
A larger company may want to invest in faster, packaged software for this, or a hard drive sanitizer (such as this one - though I am certain their claim of 7 minutes per drive is for the simple wipe and not the seven-pass version).
Any of these options are better than the ol' sledgehammer method, because who wants to clean up that mess?
I've gotten rid of old computers, but I generally either keep the hard drives (to destroy) or use software to do a thorough wipe of the drive's data When I say "thorough wipe", I am not talking about deleting files, because data can easily be recovered from a hard drive, EVEN AFTER YOU DELETE IT. Really. As a matter of fact, Microsoft's pre-Windows operating system, DOS, used to include an undelete tool which could recover deleted files easily.
eBay is one place people can purchase used hard drives, and they even provide information on why you need to thoroughly wipe a hard drive before you sell it. You can see that the site shows that social security numbers, credit card numbers, and all sorts of stuff can be found on these hard drives. This means your identity can be stolen even if you do nothing wrong, if a company you have purchased from does not follow good procedures for hard drive disposal. Aside from eBay, there are sites like Craigslist where people get rid of old hardware, and there are always garage sales. In the corporate environment, many colleges and companies pay companies to dispose of old hardware (such as eRevival locally). If you go with a cut-rate company, you may find that though they promise to clean hard drives, they may not do so thoroughly. Any of these are ways that data can be leaked if the hard drives are not wiped.
One way you can provide a level of security is to physically destroy the hard drive, though someone could pick it out of the trash and recover something. The best way is to do a full wipe of the hard drive, or what we used to call a "zeroize" at the company I used to work for. We were putting defense systems in military crafts, and one of the requirements was that the pilot needed to have a button to wipe all the data in the system, to prevent classified data from falling in to the enemy's hands. (Yes, that information is public.)
The Department of Defense has pretty high standards for data wiping, and there are a number of tools that meet their standards. The problem is most of these tools cost money. The one that I recommend is a free tool called Darik's Boot and Nuke (available for download at www.dban.org). Despite the informal name, it is a legitimate program (referenced by CNN and the BBC). There are commercial tools that do this sort of thing as well, but the major difference is not function, it is speed (DBAN has a reputation for being slow - the BBC article says it took two hours for an 80GB drive). DBAN is cool because it gives you a CD to boot off of, and you select the depth of the wipe you want. The more depth you want, the longer it will take to run. If you are going to do this, I would recommend choosing the most in-depth wipe, doing it before you go to bed (as a home user) or before you leave work in the evening (at work), and just letting it run overnight. That way, there is no time wasted waiting for wipe to be completed. In a professional environment, having a DBAN CD around is not a bad thing, especially so your company does not end up in violation with the standards that govern your industry (Sarbanes-Oxley, HIPAA, FACTA, etc.).
A larger company may want to invest in faster, packaged software for this, or a hard drive sanitizer (such as this one - though I am certain their claim of 7 minutes per drive is for the simple wipe and not the seven-pass version).
Any of these options are better than the ol' sledgehammer method, because who wants to clean up that mess?
Spring 2011 Schedule
I just wanted to post my tentative Spring 2011 schedule at Bergen.
I am scheduled to teach:
INF 163 001 (Monday/Wednesday 3:55 PM to 5:50 PM)
INF 101 009 (Tuesday/Thursday 3:55 PM to 5:50 PM)
I may also be teaching a Summer I 2011 course, if that information is solidified, I shall announce it here.
I am scheduled to teach:
INF 163 001 (Monday/Wednesday 3:55 PM to 5:50 PM)
INF 101 009 (Tuesday/Thursday 3:55 PM to 5:50 PM)
I may also be teaching a Summer I 2011 course, if that information is solidified, I shall announce it here.
Sunday, November 21, 2010
The Gmail Killer
Facebook is preparing to come out with a new email service, where users can get email sent to an email address @facebook.com. There were a number of headlines that advertised this as "the Gmail killer", though it could just as easily be "the Hotmail killer" or "the Yahoo! Mail killer".
First, Facebook started to try to be your "one true login". They seem to be succeeding in this, because a number of sites have started to give you the option to sign in using Facebook instead of creating an account. For example, here are some random sites that came up when I Googled "Facebook Connect":
Evony
Joost
SurveyMonkey
TravelPod
Facebook even has taken so much of Myspace's market that they are introducing a "connect with Facebook" option. That's the ultimate admission on Myspace's part that Facebook has won the war.
Facebook has succeeded there, so they are looking to expand. The next horizon seems to be Facebook email, which they've announced plans to implement. Facebook's CEO says that this email will be even better because they know who your friends are. No, really.
"Because we know who your friends are," said Facebook CEO Mark Zuckerberg, "we can do some really good filtering for you."
There is something a little creepy about that, but I do think this idea will take off. The interesting part is this: back in the early 2000's, sites like AOL had email and chat services, and tried to expand in to profiles...same with Yahoo! and MSN. None of those transitions worked well. However, Facebook starting with profiles and expanding to chat and then email might actually work.
So, Facebook vs. Google...who wins? Time will tell.
Link to story
First, Facebook started to try to be your "one true login". They seem to be succeeding in this, because a number of sites have started to give you the option to sign in using Facebook instead of creating an account. For example, here are some random sites that came up when I Googled "Facebook Connect":
Evony
Joost
SurveyMonkey
TravelPod
Facebook even has taken so much of Myspace's market that they are introducing a "connect with Facebook" option. That's the ultimate admission on Myspace's part that Facebook has won the war.
Facebook has succeeded there, so they are looking to expand. The next horizon seems to be Facebook email, which they've announced plans to implement. Facebook's CEO says that this email will be even better because they know who your friends are. No, really.
"Because we know who your friends are," said Facebook CEO Mark Zuckerberg, "we can do some really good filtering for you."
There is something a little creepy about that, but I do think this idea will take off. The interesting part is this: back in the early 2000's, sites like AOL had email and chat services, and tried to expand in to profiles...same with Yahoo! and MSN. None of those transitions worked well. However, Facebook starting with profiles and expanding to chat and then email might actually work.
So, Facebook vs. Google...who wins? Time will tell.
Link to story
Saturday, November 13, 2010
Keeping up with the Jobses
There's a saying "Keeping up with the Joneses" which goes back to the early 1900's (thanks Wikipedia). It basically has to do with people needing to keep up with the neighbors (in this case, the generic Joneses). I feel like Microsoft has this same symptom at points.
According to recent numbers, Microsoft Windows Mobile was only on 2.8% of cell phones, according to Gartner Research. Compare this with 36.6% for the open-source Symbian OS, 25.5% for the Android OS, 16.7% for iPhone OS, and 14.8% for the Blackberry OS. In other words, Microsoft Windows Mobile just is not cutting it.
Since Microsoft needs to keep up with the Jobses (Steve Jobs is often considered the Face of Apple), Microsoft released Windows Phone 7 last month. Microsoft basically redesigned the operating system, because as we see it wasn't working. According to USA Today, the first phone to run this OS is the Samsung Focus through AT&T, which was released on November 8.
According to cNet reviews, Microsoft does seem to have done a nice job on the operating system, but as they point out, it is an uphill battle to overtake some of the companies above them on the list. One interesting feature that jumped out from the review (since I haven't used it myself yet) was the integration with Xbox Live. That could be something that sets this phone apart, if it gives people access to their games and accounts in a mobile fashion.
We'll see how it shakes out, but Microsoft does have a long way to go.
Thanks to Kevin for the heads-up!
According to recent numbers, Microsoft Windows Mobile was only on 2.8% of cell phones, according to Gartner Research. Compare this with 36.6% for the open-source Symbian OS, 25.5% for the Android OS, 16.7% for iPhone OS, and 14.8% for the Blackberry OS. In other words, Microsoft Windows Mobile just is not cutting it.
Since Microsoft needs to keep up with the Jobses (Steve Jobs is often considered the Face of Apple), Microsoft released Windows Phone 7 last month. Microsoft basically redesigned the operating system, because as we see it wasn't working. According to USA Today, the first phone to run this OS is the Samsung Focus through AT&T, which was released on November 8.
According to cNet reviews, Microsoft does seem to have done a nice job on the operating system, but as they point out, it is an uphill battle to overtake some of the companies above them on the list. One interesting feature that jumped out from the review (since I haven't used it myself yet) was the integration with Xbox Live. That could be something that sets this phone apart, if it gives people access to their games and accounts in a mobile fashion.
We'll see how it shakes out, but Microsoft does have a long way to go.
Thanks to Kevin for the heads-up!
Friday, November 05, 2010
Twitter and Poor NBA Etiquette v2.0
Charlie Villanueva, an NBA player, recently played against Kevin Garnett. During the game, Villanueva claims Garnett called him a cancer patient. Garnett, for what it is worth, said he called Villanueva "a cancer", which isn't as far fetched as it sounds. According to urbandictionary, the term cancer "[is] often used as an insult when referring to someone who is a pathelogical [sic] source of trouble and discord within a group."
Now, who knows what happened and what did not, but I can see someone exaggerating because they are annoyed. Either way, the point is he came out and put it out there, and as we know about Twitter, there is no undo button.
If this guy's name sounds familiar, it is because he is the same guy who was benched for tweeting during halftime of a game in 2009. I blogged about that here. I would think the guy would have learned his lesson about Twitter, but nope. If it is getting in the way of your professional life, perhaps it is time to let someone else serve as your filter.
Now, who knows what happened and what did not, but I can see someone exaggerating because they are annoyed. Either way, the point is he came out and put it out there, and as we know about Twitter, there is no undo button.
If this guy's name sounds familiar, it is because he is the same guy who was benched for tweeting during halftime of a game in 2009. I blogged about that here. I would think the guy would have learned his lesson about Twitter, but nope. If it is getting in the way of your professional life, perhaps it is time to let someone else serve as your filter.
Friday, October 29, 2010
Death by Farmville
Wow.
We've seen this story on the news before...a parent shakes a child and it dies. Sad, unfortunate, but also not uncommon. This happened down in Jacksonville, Florida. What makes this sensational is the fact that the mother got upset with the child over it interrupting her playing Farmville.
Facebook's role is being overblown in the media. Notice it is not "Mother Shakes Baby to Death". Headlines seem to be more "Child Dies due to Facebook Game". The focus is put on Facebook. News articles do report she was playing it through Facebook, but Facebook did not create Farmville. You don't have to be on Facebook to use Farmville (Myspace and Twitter also work, as I understand). Putting Facebook in the headlines is sexier than putting Farmville in the headline.
Of course, this is also going to be something people cite when they say Facebook is bad for society. I have a friend who hates Facebook, and I am sure this friend will see this headline and just tie it to Facebook.
Let's be honest. If this woman would shake a baby to death over a Facebook game, she probably have done it over a TV show, or cooking, or a phone call, or any of another thousand reasons.
Link to CBSNews Article
We've seen this story on the news before...a parent shakes a child and it dies. Sad, unfortunate, but also not uncommon. This happened down in Jacksonville, Florida. What makes this sensational is the fact that the mother got upset with the child over it interrupting her playing Farmville.
Facebook's role is being overblown in the media. Notice it is not "Mother Shakes Baby to Death". Headlines seem to be more "Child Dies due to Facebook Game". The focus is put on Facebook. News articles do report she was playing it through Facebook, but Facebook did not create Farmville. You don't have to be on Facebook to use Farmville (Myspace and Twitter also work, as I understand). Putting Facebook in the headlines is sexier than putting Farmville in the headline.
Of course, this is also going to be something people cite when they say Facebook is bad for society. I have a friend who hates Facebook, and I am sure this friend will see this headline and just tie it to Facebook.
Let's be honest. If this woman would shake a baby to death over a Facebook game, she probably have done it over a TV show, or cooking, or a phone call, or any of another thousand reasons.
Link to CBSNews Article
Friday, October 22, 2010
Time Machine: Everything Old is New Again
Some topics of interest from this week's classes.
We discussed the Do Not Call Registry, which was a way to prevent telemarketers from calling you. Someday, we may see a Do Not Email Registry, but I wouldn't expect that for a while. I remember telemarketing being annoying in the 80's, and it took them until 2003 to do anything about it. Here's my original post about how to get on the registry and save yourself from telemarketers.

Of course, for people majoring in the IT area, it's always a struggle to find a balance between security and ease of use. If you require difficult passwords, your users may end up writing them on a sticky note, or putting them in a passwords document.
We discussed the Do Not Call Registry, which was a way to prevent telemarketers from calling you. Someday, we may see a Do Not Email Registry, but I wouldn't expect that for a while. I remember telemarketing being annoying in the 80's, and it took them until 2003 to do anything about it. Here's my original post about how to get on the registry and save yourself from telemarketers.
Second of all, passwords came up in one class this week. Microsoft has a free password strength checker on their Web site, where you can see how strong or weak your password is. Here's the link. We also discussed passwords, and how you can make a better password. I discussed the mnemonic device method for creating and remembering a password in class, and here is my original post on that.

Friday, October 15, 2010
Stalking a criminal
The Internet has obviously changed many things. One thing it has changed is crime. Criminals are known to use sites like Craigslist and eBay to sell stolen goods.
It's interesting how people have also used this in the investigation of crimes. For example, a woman recently had a GPS stolen, and used Craigslist to get in touch with someone who was selling a GPS of the same brand the next day. She contacted the guy, got his email address, used that to find his profile on an online dating site, used that information to find him on Myspace....
The police were able to get video footage from a McDonald's where he used her card, and the Myspace profile matched the face of the person on the video.
It's a lesson that (as she says) you never know who you are robbing.
Link to story
It's interesting how people have also used this in the investigation of crimes. For example, a woman recently had a GPS stolen, and used Craigslist to get in touch with someone who was selling a GPS of the same brand the next day. She contacted the guy, got his email address, used that to find his profile on an online dating site, used that information to find him on Myspace....
The police were able to get video footage from a McDonald's where he used her card, and the Myspace profile matched the face of the person on the video.
It's a lesson that (as she says) you never know who you are robbing.
Link to story
Thursday, October 07, 2010
Charging for Web design work
One of my former students emailed me to ask about freelance Web design work, and how much to charge. This is always a very difficult question, and I don't know many people who are comfortable setting rates coming out of college.
Keep in mind that companies will pay what sounds like a really high hourly rate because they are not subject to the overhead that their regular employees have, such as health benefits, office supplies, and other such items.
The difficult part in freelancing early on is figuring out how long things will take. I found as a programmer I had no sense for how long projects would take me to do. People would ask me how long things would take, and I would think it should be a 2 hour project, and I would spend 25 hours on it. I developed that sense over time. Classes like Systems Analysis and Design were great in theory, but when it came to applying the lessons, I fell a little short.
Customers don't really want to pay based on how good you are, so generally, customers should not see your hourly rate. I would suggest creating some base packages. For example, a 5 page Web site should cost X, a 10 page Web site costs Y, etc. You want to be clear with a customer what they are paying for. I found a company that does something like that here, for reference.
You can see they have a base package for $600. For a basic 5-page site, $500-$750 seems to be the going rate. This would generally include the basics of meeting with them, gathering content, designing it, having the user test it, fixing the errors they find, and making the site live. In reality, the technical end of the work will probably take less time than the other components of the project.
Other stuff that is extra, and this is where I would run in to issues. If the customer wants e-commerce stuff, or they want Flash animations, that would be stuff that would cost extra. When they describe the requirements, that is when you have to determine the cost of it. If they describe a Flash animation, keep in mind that is rarely a two-hour gig. Flash animations, Web programming, and e-Commerce projects should include testing and bug fixing time. There have been times where I wrote a program in an hour and then spent 5 hours trying to hunt down a bug. Flash programmers can charge rates of $50-$75 an hour, so a site that is heavy on customization like that will be more costly.
What is very clever is that there is a maintenance package is $50 a month for two hours worth of work, and additional hours are extra. You may want to offer options like "10 hours of updates over the next year for $250, or updates at an hourly rate of $40" rather than constraining someone to a number of hours in a month. By offering a package deal, you may have someone pay for the 10 hours even if they don't need them, just because it looks like a better deal. Also figure most updates will be small changes, so a lower hourly rate is fine.
You can of course work with people on price. There are people I've been eager to work with, and made allowances for them.
You also have to decide if you are going in to the hosting business, or if you are going to arrange for the customers to host things elsewhere. I generally would not want to get in the middle of a transaction between a customer and a Web hosting service. If this is the case, make sure you provide them the username and password for the site. Even if they don't use it, it's professional to make sure they have access to this. I've dealt with people who have no clue about this, and if they ever need to change hosting sites, it's a pain for them. Same idea goes for the domain name purchase. You can direct them, but you probably don't want to be the person in the middle since domain names do need to be renewed.
If you are not doing the hosting yourself, you have to assume some customers may have a URL purchased and a hosting agreement, and others will not. If the customer does not have the infrastructure in place, there is some startup work you have to do to get them up and running, and that may be something you want to charge for. This may be something you want to charge $100 for.
I would recommend the customer set up a billing arrangement directly with the hosting service (like godaddy). If you end up in the middle, your credit card is the one the hosting service has on file. If, however, you are planning on hosting sites yourself, that is something different.
You should always have some sort of portfolio available. For my PCCC students, your capstone project can be a start, but you may want to expand on it and upload it to a server somewhere.
The main problem I think most customers have is that they don't understand that you don't provide content. When they pay for a site, you are taking their existing information and turning it in to a Web site. You will need to meet with someone in their organization, and they should be providing you electronic copies of the information they want on the site. Some customers think you are going to actually write the text for the site, and (unless you want to do this) it needs to be made clear that this is their responsibility, and that you don't provide proofreading services.
As you get better at doing basic Web sites, you can probably get things done quicker and therefore make your business more profitable. You can also change prices as you go along. Notice the site I linked above also includes a year (2010 rate card). You can always change rates yearly (or project to project).
Keep in mind that companies will pay what sounds like a really high hourly rate because they are not subject to the overhead that their regular employees have, such as health benefits, office supplies, and other such items.
The difficult part in freelancing early on is figuring out how long things will take. I found as a programmer I had no sense for how long projects would take me to do. People would ask me how long things would take, and I would think it should be a 2 hour project, and I would spend 25 hours on it. I developed that sense over time. Classes like Systems Analysis and Design were great in theory, but when it came to applying the lessons, I fell a little short.
Customers don't really want to pay based on how good you are, so generally, customers should not see your hourly rate. I would suggest creating some base packages. For example, a 5 page Web site should cost X, a 10 page Web site costs Y, etc. You want to be clear with a customer what they are paying for. I found a company that does something like that here, for reference.
You can see they have a base package for $600. For a basic 5-page site, $500-$750 seems to be the going rate. This would generally include the basics of meeting with them, gathering content, designing it, having the user test it, fixing the errors they find, and making the site live. In reality, the technical end of the work will probably take less time than the other components of the project.
Other stuff that is extra, and this is where I would run in to issues. If the customer wants e-commerce stuff, or they want Flash animations, that would be stuff that would cost extra. When they describe the requirements, that is when you have to determine the cost of it. If they describe a Flash animation, keep in mind that is rarely a two-hour gig. Flash animations, Web programming, and e-Commerce projects should include testing and bug fixing time. There have been times where I wrote a program in an hour and then spent 5 hours trying to hunt down a bug. Flash programmers can charge rates of $50-$75 an hour, so a site that is heavy on customization like that will be more costly.
What is very clever is that there is a maintenance package is $50 a month for two hours worth of work, and additional hours are extra. You may want to offer options like "10 hours of updates over the next year for $250, or updates at an hourly rate of $40" rather than constraining someone to a number of hours in a month. By offering a package deal, you may have someone pay for the 10 hours even if they don't need them, just because it looks like a better deal. Also figure most updates will be small changes, so a lower hourly rate is fine.
You can of course work with people on price. There are people I've been eager to work with, and made allowances for them.
You also have to decide if you are going in to the hosting business, or if you are going to arrange for the customers to host things elsewhere. I generally would not want to get in the middle of a transaction between a customer and a Web hosting service. If this is the case, make sure you provide them the username and password for the site. Even if they don't use it, it's professional to make sure they have access to this. I've dealt with people who have no clue about this, and if they ever need to change hosting sites, it's a pain for them. Same idea goes for the domain name purchase. You can direct them, but you probably don't want to be the person in the middle since domain names do need to be renewed.
If you are not doing the hosting yourself, you have to assume some customers may have a URL purchased and a hosting agreement, and others will not. If the customer does not have the infrastructure in place, there is some startup work you have to do to get them up and running, and that may be something you want to charge for. This may be something you want to charge $100 for.
I would recommend the customer set up a billing arrangement directly with the hosting service (like godaddy). If you end up in the middle, your credit card is the one the hosting service has on file. If, however, you are planning on hosting sites yourself, that is something different.
You should always have some sort of portfolio available. For my PCCC students, your capstone project can be a start, but you may want to expand on it and upload it to a server somewhere.
The main problem I think most customers have is that they don't understand that you don't provide content. When they pay for a site, you are taking their existing information and turning it in to a Web site. You will need to meet with someone in their organization, and they should be providing you electronic copies of the information they want on the site. Some customers think you are going to actually write the text for the site, and (unless you want to do this) it needs to be made clear that this is their responsibility, and that you don't provide proofreading services.
As you get better at doing basic Web sites, you can probably get things done quicker and therefore make your business more profitable. You can also change prices as you go along. Notice the site I linked above also includes a year (2010 rate card). You can always change rates yearly (or project to project).
Wednesday, September 29, 2010
Census and computing
The US census brings to mind one of the reasons computers advanced.
The 1880 census took 8 years to tabulate. Of course, the census is done every 10 years, so a long wait for results makes this data almost useless. The fear was that the 1890 census would take more than 10 years to tabulate, which of course makes no sense.
Enter Herman Hollerith and his fabulous mustache. He invented a tabulating machine that helped with this purpose. This tabulating machine allowed them to count survey results in one year. Of course, many early computers used punch cards, so this was one of the forefathers of those computers. I did not know (until I read a little bit of the Wikipedia article) that his company was one of the companies that would merge to form IBM in 1924. Thanks, Wikipedia!
Anyway, the 2010 census results are being tabulated, and you can already see the response rates posted for all towns. Making things more interesting is the use of data mining. We can now use the computers to not only count results, but to do projections, spot trends, and all sorts of stuff that would have been impossible 100 years ago. It looks like President Obama will get the first report by December 31, 2010. Considering surveys were sent out in March and data collection ended in July, that's really amazing turn around time. Now, if everyone just did the data entry on the computer, imagine how quickly it would go!
Anyway, here's the site with the response rates:
http://2010.census.gov/2010census/take10map/
The 1880 census took 8 years to tabulate. Of course, the census is done every 10 years, so a long wait for results makes this data almost useless. The fear was that the 1890 census would take more than 10 years to tabulate, which of course makes no sense.
Enter Herman Hollerith and his fabulous mustache. He invented a tabulating machine that helped with this purpose. This tabulating machine allowed them to count survey results in one year. Of course, many early computers used punch cards, so this was one of the forefathers of those computers. I did not know (until I read a little bit of the Wikipedia article) that his company was one of the companies that would merge to form IBM in 1924. Thanks, Wikipedia!
Anyway, the 2010 census results are being tabulated, and you can already see the response rates posted for all towns. Making things more interesting is the use of data mining. We can now use the computers to not only count results, but to do projections, spot trends, and all sorts of stuff that would have been impossible 100 years ago. It looks like President Obama will get the first report by December 31, 2010. Considering surveys were sent out in March and data collection ended in July, that's really amazing turn around time. Now, if everyone just did the data entry on the computer, imagine how quickly it would go!
Anyway, here's the site with the response rates:
http://2010.census.gov/2010census/take10map/
Subscribe to:
Posts (Atom)