Friday, December 7, 2007

Thursday, October 18, 2007

Progress

We now how a rough indicator of how much progress people have made in 23 Things. There is a chart here; those of you playing along at home will need a staff wiki log-in to see it.

Today I wanted to acknowledge that there is a huge variation in how easy people have found the tasks and the effort that they have had to put in. For some, setting up a blog has taken hours of work, and that's before making a single post. For others - well, some people had already done most of the things in the program anyway. Setting up a blog on Blogger could take as little as a couple of minutes if you already knew what you were doing.

I think the program is aimed at that former group - those who haven't used a blog before, or feeds, or other online tools. I don't want anybody doing 23 Things to feel 'left behind' because they haven't figured out how to do something in an hour, when it took their colleague five minutes. Hopefully, people can get help from each other, rather than wondering where to get started. If anyone has other suggestions for encouraging those have more difficulty, please do comment.

I have read everyone's blog and commented on a few, and some of them are very interesting. It's also good to see we have some Doctor Who fans!

A word of encouragement

Before 23 Things started I hadn't used an image generator at all, but it has been one of the most popular tasks in the program, probably because it's something very visual that we could demonstrate when we were showing people 23 Things.



For this image I used the excellent and very classy ICanHasCheezBurger Factory. I used a photo I found on Flickr by Lazy Lightning, who kindly licensed their photo to allow adapted works.

Friday, September 28, 2007

Using flickr

I am already quite familiar with flickr; I do some photography as a hobby and I have an account there with a large number of my photos already. I pay flickr's yearly fee so people can see more than 200 of my photos.

Of all the 'social' web applications, flickr was the first one I ever joined, so I wasn't used to its 'contacts', 'groups' etc. I was a big skeptic when it came to social web applications. Since using other social applications, I find that I wish flickr had more privacy control. I'd love it if I could prevent certain parts of my profile or certain photos from being viewed externally (such as by Google's indexer), or set viewing rights for my photos on a per-contact basis (so I can show a picture to a certain person).

As a result of having photos on flickr I occasionally get comments from other people who are into photography. This is encouraging. I have also had 3 photos which were published in magazines - one in print, the other two online. The publishers found my photos by searching flickr based on the tags I had used and, in one case, the Creative Commons license I had given the photo.

If you want your photos to be found, I would recommend adding relevant tags to them. That way, someone who is doing a search for a particular Melbourne landmark is likely to find your photo of that landmark. I'd also recommend submitting them to relevant groups, so Melbourne photos can go to the Melbourne group, and so on.

Picture Australia (from the National Library) has created 2 flickr groups which encourage people to upload photos of people, places and events, and their town. The idea is that selected photos from these groups will become a part of Picture Australia's image collection. I haven't contributed anything yet, though there's no reason I shouldn't - I have plenty of photos of 'my town'. If you feel like contributing photos to Picture Australia would give you a warm fuzzy feeling then do have a look at the information on their site. I think I might get involved.

Tuesday, September 25, 2007

Managing passwords

I have so many different accounts with online services that I cannot possibly use a different, easy to remember yet hard to guess, password on every one. Or at least that's my excuse.

For security it's a good idea to choose a password that contains both letters and numbers, is at least 8 characters long, and doesn't contain a dictionary word. This rules out passwords such as 'ringwood' or 'happy123', or anything with your user name in it, because machines could guess them quite quickly. It's also good practice to use a separate password for each organisation where you have an account, and to make sure that you remember them without needing to write them down. Here's some more about password security. While I have a decent understanding of online security, in various ways I fail each of those requirements.

One could argue that the importance of a given password is relative to the sensitivity of the information it protects, and hence the damage it could do if someone else were to gain access. For my online banking, for example, I use a string of otherwise meaningless numbers that are very hard to guess, and I've never written them down anywhere. If I did that everywhere that I have an online account, however, I wouldn't be able to remember them all.

Some people use a software package such as KeePass to remember their passwords for them. This stores and encrypts all of your different passwords, and reveals them to you only after entering a master password of your choosing. I'm skeptical about this, because it allows a single point of failure; if someone manages to get that one single password they can now access anything you own. At the same time, if I forget that master password or my hard drive crashes, I have a frustrating time ahead of me.

Another concern is social engineering attacks including phishing, which have the potential to render all technological security measures useless, as they work by simply deceiving the password holder into revealing the password to someone who appears genuine. A rule of thumb here: if it looks like your bank, it may not be your bank.

From my perspective, though you should always be careful about security online, you should exercise the greatest caution with any organisation that has access to sensitive information such as your credit card numbers, where you live, your real name, or anything that could be used to defraud you or pose as you.

If there is a better way to remember many passwords yet at the same time ensure they are unique and hard to break, I'd be interested in finding out more about it.