I don't even remember exactly how it happened, except that I happened to follow a link from Wikipedia, but I managed to end up entangled in TV Tropes. Apparently I'm not alone.
If you haven't visited it already, be warned: This is one of the more potent timesinks out there. Thinly masquerading as a collection of motifs and plot devices from television, it's really a compendium of archetypes from all sorts of fiction, clearly and wittily explicated and extensively cross-linked. The piece on William Shatner alone is worth the price of admission, as is the Evil Overlord List. Think Joseph Campbell meets Wikipedia meets Remote Control.
Somewhere around the Space Whale Aesop, the obvious occurred to me: It's the extensive cross-linking, that is, the webbiness of the site, that makes it so addictive (that, and there dependably being something worth reading at the other end of the link). A little bit later (Fridge Logic?) it occurred to me that really webby sites like TV tropes are relatively rare. Yes, most blogs include links, but mostly external links. Even Wikipedia isn't as densely linked as TV Tropes (or at least it doesn't feel like it).
In fact, I find a large part of my web experience consists either of directly visiting a favorite site, or doing a search and then following a small number of links to what I'm looking for. Most of the time, I'm using the web to find some particular piece of information, not to browse at random. Nothing wrong with browsing at random -- it's just not my main mode.
As essential as links are to the web, they may not be its most essential feature. If links went away tomorrow and individual sites were flattened into giant, unwieldy documents, it would still be possible to find useful information via your favorite search engine. If search engines went away instead, no one would be able to find much of anything. Furthermore, if search engines had never existed, sites would be much less richly linked than they are now, because authors would have been less able to find good links. Searchability supports links at least as much as the other way round.
In short, search engines may well be more important than links, except when it comes to a particular digressive mode of chasing links to see where they go [But then, I would say that after a few months at Google, wouldn't I? -- D.H. Dec 2015].
Wednesday, October 27, 2010
Monday, October 18, 2010
NEW TECHNOLOGY LOOKS ODDLY FAMILIAR STOP
My phone is not particularly well suited to texting, but for various reasons I've found myself doing more of it lately. Even beyond the basic problem of typing on a chiclet keyboard with fingers that did some of their first typing on an Underwood manual, there are a couple of challenges.
For one, I'm used to writing complete sentences, so I find myself compulsively and pointlessly going back and fixing spelling mistakes, checking punctuation and so forth. Mind, I don't have anything against the usual abbreviations and casual spellings. I doubt it's a sign that the language has gone to pot or that Kids These Days don't learn anything. More likely it's a sign that full and careful spelling is just not worth the effort if you can get your message across more quickly without it.
The upshot is that I text much, much more slowly than I write. I'd guess at least four times as slowly and very likely closer to eight or ten [re-reading in 2015, I note that I'm able to text much faster now, with a smartphone and keyboard app, and the character limit is much less visible. I think my texting is somewhat less terse now, but the overall point of texting technology influencing texting style still stands, I think -- D.H.]. An order of magnitude in quantity generally means a change in quality and this is no different. Working at such a slow speed, I find every word counts, as typing another is just too much bother.
Side note: Once I was at a conference where computer graphics legend Jim Blinn presented his first ray-traced picture. Ray-tracing is a technique that carefully follows rays of light through every pixel of the picture, as opposed to the classic "polygon pushing" technique, which Blinn helped pioneer and which is still in wide use today because of its speed. Polygon pushing determines which surfaces are visible and draws them (more or less directly), saving a bunch of time. Blinn claimed that one of the nice aspects of ray-tracing was that since it was so slow, around eight hours per frame in that case, as I recall, you had plenty of time to think about what was going to be in the image.
Just so, slowing down to text gives much more time to think about a short message. I'm sure the situation is different for experienced texters, but even then another factor comes into play: SMS's draconianly (and more or less artificially) short message length. If you're tweeting, it doesn't matter if you're sitting at your desk typing full steam ahead, or picking out words while squinting at a cell phone, or rattling away with thumbs of lightning. 140 bytes is 140 bytes.
Way back in the early days of electronic communication networks, people sending messages faced a similar problem. I'm not aware of any particular length restriction on telegraph messages, but for decades telegraph messages had to be transmitted, by hand, in morse code. As a result every word was expensive -- and punctuation was conveyed in words, notably STOP for a period. To cope with this, customers developed a concise "telegraphic" style in order to make every word count.
Technology doesn't just enable. It also constrains, and the effects of such constraint can be just as interesting.
For one, I'm used to writing complete sentences, so I find myself compulsively and pointlessly going back and fixing spelling mistakes, checking punctuation and so forth. Mind, I don't have anything against the usual abbreviations and casual spellings. I doubt it's a sign that the language has gone to pot or that Kids These Days don't learn anything. More likely it's a sign that full and careful spelling is just not worth the effort if you can get your message across more quickly without it.
The upshot is that I text much, much more slowly than I write. I'd guess at least four times as slowly and very likely closer to eight or ten [re-reading in 2015, I note that I'm able to text much faster now, with a smartphone and keyboard app, and the character limit is much less visible. I think my texting is somewhat less terse now, but the overall point of texting technology influencing texting style still stands, I think -- D.H.]. An order of magnitude in quantity generally means a change in quality and this is no different. Working at such a slow speed, I find every word counts, as typing another is just too much bother.
Side note: Once I was at a conference where computer graphics legend Jim Blinn presented his first ray-traced picture. Ray-tracing is a technique that carefully follows rays of light through every pixel of the picture, as opposed to the classic "polygon pushing" technique, which Blinn helped pioneer and which is still in wide use today because of its speed. Polygon pushing determines which surfaces are visible and draws them (more or less directly), saving a bunch of time. Blinn claimed that one of the nice aspects of ray-tracing was that since it was so slow, around eight hours per frame in that case, as I recall, you had plenty of time to think about what was going to be in the image.
Just so, slowing down to text gives much more time to think about a short message. I'm sure the situation is different for experienced texters, but even then another factor comes into play: SMS's draconianly (and more or less artificially) short message length. If you're tweeting, it doesn't matter if you're sitting at your desk typing full steam ahead, or picking out words while squinting at a cell phone, or rattling away with thumbs of lightning. 140 bytes is 140 bytes.
Way back in the early days of electronic communication networks, people sending messages faced a similar problem. I'm not aware of any particular length restriction on telegraph messages, but for decades telegraph messages had to be transmitted, by hand, in morse code. As a result every word was expensive -- and punctuation was conveyed in words, notably STOP for a period. To cope with this, customers developed a concise "telegraphic" style in order to make every word count.
Technology doesn't just enable. It also constrains, and the effects of such constraint can be just as interesting.
Labels:
computing history,
history of technology,
telegraph,
text,
Twitter
Sunday, October 17, 2010
Defending your reputation (for a small fee)
Some time back, when I had a somewhat different vision of this blog, I ruminated about how one might model reputation. Whether or not the model is any good, taking some time to think about what reputation might be was a useful exercise. Re-reading the posts in that thread, one of the more useful observations was:
Nonetheless, there are companies in the business of helping people control access to information, and thereby their reputations. A fool's errand? Probably not. There are several services that reputation protection services can and do provide:
We try to control our reputations (at least)Of those, we have the most control over the first, though perhaps more effort is devoted to the third. The second has its own special quirk: It's possible for information to disappear from the web, if all permanent copies can be removed, but the safe assumption is that information only accumulates.
- through our actions
- by controlling access to information about us
- by influencing people's interpretation of the information (we think) we know
Nonetheless, there are companies in the business of helping people control access to information, and thereby their reputations. A fool's errand? Probably not. There are several services that reputation protection services can and do provide:
- Monitoring what you look like on the web. If someone posts something slanderous about you, you may not find out until it's too late, unless you're constantly monitoring the web -- or have someone doing it for you.
- There are various online lists and databases that you can sometimes have your personal details purged from, but who has the time?
- You can't erase information from the web, particularly if it's a rumor that's already spread far and wide, but you can respond and try to counter it. In this sense, protecting a reputation is just old-fashioned PR.
- If you choose to, say, put all your purchases and reading selections and reading up for your friends to peruse, you might want to use a different identity to mention that you're reading World Domination in Six Easy Evil Steps or to purchase that 1.21 gigawatt laser. But if you don't already know that, a service may not be of much help.
What's less clear to me is how much any of this is worth to private individuals. If your ex has just posted those embarrassing videos of you from the last christmas party, it's not going to help much to learn about it in a report form your reputation service. It would seem it's the PR function that's most useful in such cases, but unless you're directly in the public eye you probably don't have call for that. If you do need it, you're not going to get it online for a small monthly fee.
I'd liken it to search engine optimization. If you're doing serious business online, you definitely want it, along with real marketing expertise. If you're blogging in a web.backwater, probably not so much.
Or so I hope.
Tuesday, October 12, 2010
"The computer knows"
The other day someone asked me whether it was supposed to be cold out that week. I didn't know offhand. "That's OK," they said, "I'll check the computer. The computer knows."
It occurred to me that if someone were trying to convince a skeptical public back in the 80s that this whole "personal computer" thing was really going places, and that person were allowed just one ten-second glimpse into the faraway world of 2010 to show the audience, they would probably give their eyeteeth for that particular glimpse. Ditto for a budding AI researcher.
Except ... the viewer from thirty years ago would naturally take "the computer knows" at face value. Computers in the 21st century would be so fast and so smart that the personal computer in the kitchen could predict the weather.
Today, by contrast, we don't generally assume that computers "know" much of anything, but we do assume that they can easily direct us to someone who does, in this case the people at a weather service. Granted, said forecasters are making use of computers that, as far as computing power, could swallow an 80s-era supercomputer whole without a hiccup. Nonetheless, we don't assume that our own computers could do any such thing, or even that a supercomputer is so omnipotent as to make weather forecasters redundant.
That's the difference between having a PC and being on the web. The primary function of most computing devices -- personal computers, phones, netbooks, routers, etc. -- is communication. That's not to say that computers aren't essential in producing and cataloging data, but data is only useful if you can get to it.
It occurred to me that if someone were trying to convince a skeptical public back in the 80s that this whole "personal computer" thing was really going places, and that person were allowed just one ten-second glimpse into the faraway world of 2010 to show the audience, they would probably give their eyeteeth for that particular glimpse. Ditto for a budding AI researcher.
Except ... the viewer from thirty years ago would naturally take "the computer knows" at face value. Computers in the 21st century would be so fast and so smart that the personal computer in the kitchen could predict the weather.
Today, by contrast, we don't generally assume that computers "know" much of anything, but we do assume that they can easily direct us to someone who does, in this case the people at a weather service. Granted, said forecasters are making use of computers that, as far as computing power, could swallow an 80s-era supercomputer whole without a hiccup. Nonetheless, we don't assume that our own computers could do any such thing, or even that a supercomputer is so omnipotent as to make weather forecasters redundant.
That's the difference between having a PC and being on the web. The primary function of most computing devices -- personal computers, phones, netbooks, routers, etc. -- is communication. That's not to say that computers aren't essential in producing and cataloging data, but data is only useful if you can get to it.
Saturday, October 2, 2010
What did I mean, "web before the web"?
I badly mis-titled my previous post.
The point I was trying to make was that the ability to sit down at a computer and do many of the things we now associate with the web, and the idea that there was good money to be made in providing that ability, both predate the Web As We Know It. Fair enough, but calling that "the web before the web" is just wrong. There was very little webby about it.
What makes the web the web? The ability to link from one site to another, that is, the good old http:// link we all know and love. In the 80s you could connect to a remote site. With some applications (for example HyperCard, though it wasn't the first) you could chase links between and within documents on the same computer. UUCP and Usenet also predate the web, allowing email and news to flow between systems (including some BBSs). And, of course, the internet itself was around, so some people at least could connect to more than one system without signing off and dialing in again.
Nonetheless, the essential feature of the web, the idea that you could seamlessly follow a link in one online document to an online document hosted by a different system, had not yet arrived. Without that, no web.
The point I was trying to make was that the ability to sit down at a computer and do many of the things we now associate with the web, and the idea that there was good money to be made in providing that ability, both predate the Web As We Know It. Fair enough, but calling that "the web before the web" is just wrong. There was very little webby about it.
What makes the web the web? The ability to link from one site to another, that is, the good old http:// link we all know and love. In the 80s you could connect to a remote site. With some applications (for example HyperCard, though it wasn't the first) you could chase links between and within documents on the same computer. UUCP and Usenet also predate the web, allowing email and news to flow between systems (including some BBSs). And, of course, the internet itself was around, so some people at least could connect to more than one system without signing off and dialing in again.
Nonetheless, the essential feature of the web, the idea that you could seamlessly follow a link in one online document to an online document hosted by a different system, had not yet arrived. Without that, no web.
Memory lane and the web before the web
Unpacking some boxes of books, I ran across The MC6809 Cookbook. The '09 was a very nicely-designed Motorola CPU with a clean and well-regarded instruction set. In the event, the Motorola family, including the 680x0 family of 16-bit processors, ended up playing Betamax, with Intel's 8080 and 80x86 family playing the role of VHS.
Actually, that's not fair to Motorola, given that the 68K architecture is still in production and use. It's not necessarily fair to Intel either, as one can certainly argue that the x86 architecture, for all its quirks, actually makes the right trade-offs. Being a software guy, I'm not going to dive much deeper than that. I'm probably already in over my head.
The book is a typical technical book of the time (1981), talking about about pinouts, voltage levels and evaluation boards along with the basics of twos-complement and the details of the instruction set. It includes a description of the language VTL (Very Tiny Language), whose runtime fits in 768 bytes -- considerably less than this post -- complete with code listings. The one for Conway's game of life "takes at least 2K of memory to operate satisfactorily," so be sure you've got that RAM upgrade installed.
Towards the beginning of the book, during the obligatory drumming-up of how great the processor is, is the boast that the '09 "was recently incorporated into what will more than likely become the small computer system of the decade ..."
Any guesses?
"... the Radio Shack TRS-80 Videotex."
No, that's not the classic (Z80-based) TRS-80 that I first learned to hack on. It's not (exactly) the TRS-80 Color Computer (the "CoCo"), though that did use the '09. It's basically a dedicated box for dialing in to servers run by news sources and such, and it basically fell quietly off the face of the earth (Videotex did well in France, but they had their own box).
So why make such a fuss -- and the major players at the time did make a fuss -- over such a thing? Well, while seeing how many Google hits I could get for TRS-80 Videotex (about 8000), I ran across this page on trs-80.org, which in turn quotes an article in TRS-80 Microcomputer News. The author of the quoted article describes the rush of using his CoCo to dial in and get late-breaking sports, news and all manner of interesting information, and even send "electronic mail" to other Compu$erve users.
I remember spending inordinate amounts of time in the early 80s on a local BBS (Hi, Keith!) chatting, emailing and playing games, nearly a decade before TimBL put up the first web server. Clearly there was something to the whole concept.
So, right idea, nearly the right time, but not quite. It's one thing to say "this whole online thing could get big," quite another to work out how it will happen, and another thing entirely to place a winning bet on a particular product. As Warren Buffett said in the 2009 Berkshire Hathaway shareholder's letter (before he said "come and shop at all our businesses"):
Actually, that's not fair to Motorola, given that the 68K architecture is still in production and use. It's not necessarily fair to Intel either, as one can certainly argue that the x86 architecture, for all its quirks, actually makes the right trade-offs. Being a software guy, I'm not going to dive much deeper than that. I'm probably already in over my head.
The book is a typical technical book of the time (1981), talking about about pinouts, voltage levels and evaluation boards along with the basics of twos-complement and the details of the instruction set. It includes a description of the language VTL (Very Tiny Language), whose runtime fits in 768 bytes -- considerably less than this post -- complete with code listings. The one for Conway's game of life "takes at least 2K of memory to operate satisfactorily," so be sure you've got that RAM upgrade installed.
Towards the beginning of the book, during the obligatory drumming-up of how great the processor is, is the boast that the '09 "was recently incorporated into what will more than likely become the small computer system of the decade ..."
Any guesses?
"... the Radio Shack TRS-80 Videotex."
No, that's not the classic (Z80-based) TRS-80 that I first learned to hack on. It's not (exactly) the TRS-80 Color Computer (the "CoCo"), though that did use the '09. It's basically a dedicated box for dialing in to servers run by news sources and such, and it basically fell quietly off the face of the earth (Videotex did well in France, but they had their own box).
So why make such a fuss -- and the major players at the time did make a fuss -- over such a thing? Well, while seeing how many Google hits I could get for TRS-80 Videotex (about 8000), I ran across this page on trs-80.org, which in turn quotes an article in TRS-80 Microcomputer News. The author of the quoted article describes the rush of using his CoCo to dial in and get late-breaking sports, news and all manner of interesting information, and even send "electronic mail" to other Compu$erve users.
I remember spending inordinate amounts of time in the early 80s on a local BBS (Hi, Keith!) chatting, emailing and playing games, nearly a decade before TimBL put up the first web server. Clearly there was something to the whole concept.
So, right idea, nearly the right time, but not quite. It's one thing to say "this whole online thing could get big," quite another to work out how it will happen, and another thing entirely to place a winning bet on a particular product. As Warren Buffett said in the 2009 Berkshire Hathaway shareholder's letter (before he said "come and shop at all our businesses"):
In the past, it required no brilliance for people to foresee the fabulous growth that awaited such industries as autos (in 1910), aircraft (in 1930) and television sets (in 1950). But the future then also included competitive dynamics that would decimate almost all of the companies entering those industries. Even the survivors tended to come away bleeding.
Friday, September 24, 2010
Blockbuster, RIP
Back during the Madness, a neighbor happened to mention a new service that would let you rent DVDs online. This was around the same time as eToys and WebVan, back when one could look at a preposterous business plan and think "Well, maybe I'm missing something." Nonetheless it seemed a bit unlikely that people would want to wait for DVDs to arrive in the mail when they could just hop over to the local Blockbuster. I didn't give the idea much of a chance.
About a decade later, Netflix is still going strong and Blockbuster has just filed for bankruptcy, sending its stock from about $0.06 to around $0.04. That's a typical "oh look, you can too fall through the floor" dot-bomb performance and, sadly, not too much of a surprise. I literally don't remember the last time I set foot in a Blockbuster or heard someone say "Oh, I'll rent it at Blockbuster". For that matter, I'm still not sure when I last bought a DVD. The only reason even to rent a DVD is that it's not available online cheaply enough. My Netflix subscription, however, is still going, albeit at the minimum rate [and it's still alive and well ... the new "smart TV" in the bedroom has Netflix built in with a button for it on the remote control, and Netflix seems to be doing pretty well following the HBO playbook in moving from supplying movies to producing original content --D.H. Dec 2015].
The winner here, of course, is online video (provided you include video on demand). The loser is physical video (tape and DVD, but with movie theaters in a separate category). Netflix would likely be in the same boat as Blockbuster had it stuck to mailing DVDs and conversely Blockbuster might have survived had Netflix not beat it to the punch online.
So there you have it: Convergence and the web winning decisively over the old bricks-and-mortar model. It really did happen. Just years later and only in an industry that's essentially been selling bits all along.
About a decade later, Netflix is still going strong and Blockbuster has just filed for bankruptcy, sending its stock from about $0.06 to around $0.04. That's a typical "oh look, you can too fall through the floor" dot-bomb performance and, sadly, not too much of a surprise. I literally don't remember the last time I set foot in a Blockbuster or heard someone say "Oh, I'll rent it at Blockbuster". For that matter, I'm still not sure when I last bought a DVD. The only reason even to rent a DVD is that it's not available online cheaply enough. My Netflix subscription, however, is still going, albeit at the minimum rate [and it's still alive and well ... the new "smart TV" in the bedroom has Netflix built in with a button for it on the remote control, and Netflix seems to be doing pretty well following the HBO playbook in moving from supplying movies to producing original content --D.H. Dec 2015].
The winner here, of course, is online video (provided you include video on demand). The loser is physical video (tape and DVD, but with movie theaters in a separate category). Netflix would likely be in the same boat as Blockbuster had it stuck to mailing DVDs and conversely Blockbuster might have survived had Netflix not beat it to the punch online.
So there you have it: Convergence and the web winning decisively over the old bricks-and-mortar model. It really did happen. Just years later and only in an industry that's essentially been selling bits all along.
Labels:
Blockbuster,
convergence,
dot-com bubble,
Netflix
Monday, September 6, 2010
More reading on identity
As a companion to the previous post, Joe Andrieu's blog, apart from its own merits, is also a fine jumping off point into a whole community of people thinking long and deeply about such things as what identity means on the web and how to empower* people to take charge of data. The immediately relevant post is Self-managed Identity, itself part of a series Introducing User Driven Services.
* I generally cringe when I hear words like "empower," but I use it here because I believe it's appropriate and they really mean it.
* I generally cringe when I hear words like "empower," but I use it here because I believe it's appropriate and they really mean it.
The cry of the squeamish ossifrage
I think I got rid of the old Scientific American issue years ago, but I still remember reading about the RSA public key cipher in Martin Gardiner's Mathematical Games in 1977 (August, to be precise). Thirty-three years later, RSA is still in use, providing a secure means of encrypting and signing digital data (unless someone has figured out a way to crack it and is sitting very, very tightly on the secret).
In particular, it can be used to verify that only someone in possession of a particular secret key, generally a several-hundred digit number, could have produced a particular block of bytes. If you visited a site whose URL started with "https://", for example your bank, your browser most likely used RSA in the process of satisfying itself that it really was talking to the right server.
So why is authentication such a mess? Why does resetting a password require anything from coming up with the name of a cat to providing a working email address to providing several pieces of information and then getting a phone call? Why do some sites want the three-digit code on the back of your card and some not, and how is adding three more digits that you end up handing out to all and sundry helping the situation? Why hasn't OpenID or some other knight in shining armor been able to rescue us? Why do we still use passwords for anything besides locally decrypting the key to a real authentication system? How do you even know I wrote this?
I don't really know, but if I didn't have some guesses I probably wouldn't be writing this, now would I?
First, what would a really seamless authentication system look like?
In particular, it can be used to verify that only someone in possession of a particular secret key, generally a several-hundred digit number, could have produced a particular block of bytes. If you visited a site whose URL started with "https://", for example your bank, your browser most likely used RSA in the process of satisfying itself that it really was talking to the right server.
So why is authentication such a mess? Why does resetting a password require anything from coming up with the name of a cat to providing a working email address to providing several pieces of information and then getting a phone call? Why do some sites want the three-digit code on the back of your card and some not, and how is adding three more digits that you end up handing out to all and sundry helping the situation? Why hasn't OpenID or some other knight in shining armor been able to rescue us? Why do we still use passwords for anything besides locally decrypting the key to a real authentication system? How do you even know I wrote this?
I don't really know, but if I didn't have some guesses I probably wouldn't be writing this, now would I?
First, what would a really seamless authentication system look like?
- It would allow for multiple identities. Maybe I just haven't caught on to the whole every-waking-moment-of-your-life-available-online thing, but I would rather keep my work identity separate from my blogging identity separate from my personal email separate from my bank accounts. Not to mention my identity as an international man of mystery.
- It would allow the same identity to work multiple places. This is not the same as giving N different sites the same username and password. Your username doesn't belong to you, whereas a real identity does. Anybody can choose your favorite username if they happen to get there first. It's also not the same as letting your browser keep track of a bunch of username-password pairs and putting a master password on all of them.
- It would minimize the number of tokens needed for an identity, and each token would be there for a clear reason. If the token is a password, fine, but it should be a password, not a password and two or three "security questions."
- It would use current best practices. It's risky to use anything too new when it comes to security technology, and unless you're No Such Agency or the like it's madness to try to create your own, but there are plenty of well-established road-tested security techniques available.
- It should be portable, both physically (like the "pocket-thing") and across sites. Ideally, registering with a new site means registering the token(s) for the appropriate identity.
- It should be as completely under the identified individual's control as possible.
What actually happens? Something along these lines, I think:
Suppose I have some sort of digital certificate that I can use to identify myself. Properly used, this could satisfy the requirements above, perhaps together with some sort of physical token, like a smartcard. Any really secure authentication system, including a smartcard, is going to have some such certificate in it somewhere.
Suppose I have some sort of digital certificate that I can use to identify myself. Properly used, this could satisfy the requirements above, perhaps together with some sort of physical token, like a smartcard. Any really secure authentication system, including a smartcard, is going to have some such certificate in it somewhere.
Since it costs money to have a major certificate authority (CA) vouch for a certificate (by signing it), certificates used by individuals in practice tend to be "self-signed", or signed by members of a "web of trust" instead. That's fine for some purposes, but not for doing business with a bank. If it's not good enough for the banks, it's probably not good enough for your utility company either.
In theory, you could establish your identity with a bank and then get them to sign a certificate to that effect, which your utility company might choose to trust, but that basically puts your bank into the CA business, not one they're necessarily keen to get into. In practice, each company would rather control the process, typically asking for an account number off a paper statement to get the ball rolling. Each entity has its own customer ID system for the account number, and usernames are potluck, so you end up with (at least) one semi-identity for each company you do business with.
In the wild-and-woolly world of pure web sites, where you don't already have a customer id when you sign up, there doesn't seem to be any strong push to move beyond the usual username-password system. Everyone's used to it. Switching would mean re-doing the login screen, at the least, with new and less-familiar technology, then convincing your users to go along with it. If it ain't broke don't fix it.
Since an authentication scheme is only as strong as its reset mechanism, there are basically two schemes in wide use:
- An identity is a working email address
- An identity is a couple of "security questions" and answers
If I had to choose, I'd take the former, but it's not much of a choice.
Thursday, September 2, 2010
Online customer service, only without the service
I don't generally like to criticize customer service reps. It's a thankless job. However, this particular one might have been a little more careful with those boilerplate macro keys. It would be helpful, also, if SomeCompany's system would allow a password reset* given:
It's sort of a division of labor anti-pattern. A human an a computer working together end up more obtuse than either alone. Offering the customer the service the customer can't log into and the chat support that didn't help is a nice parting touch.
What follows is an anonymized and lightly edited transcript of an actual customer chat sent by one of my "army of stringers, researchers, fact-checkers and miscellaneous hangers-on."
Problem: Trying to sign in; need password
Hello Customer, Thank you for contacting SomeCompany Live Chat Support. My name is Service Rep. Please give me one moment to review your information. I'm ready to assist you today. How are you doing by the way?
Fine, thanks .
Nice to know that you are doing good.
I was trying to log in to your service
As what I have understood, you would like to have your password for you to sign in right?
Yes. I thought I'd already set up an account and your website found a user name from looking at my IP address, but I can't reset the password . Also, I'd rather choose my own user name rather than use the assigned one (wemadethisup@somecompany.com), if possible.
Oh, I see. I understand that it is very important for you to know the password of your here. I also know that you would like to have your email address personalized and change it. There is no need to worry since as your service representative today, I want you to know I am more than willing to help you today with your issue. I can assure you that we can have a positive resolution since we will be working on this together.
Here’s what I can do, Since your password is not allowing you to log in, and since we do not store our customers’ passwords, I can give you a randomly system generated password would that be okay?
That would be fine, thanks
Alright. Please allow me to pull up your account information so that we can resolve it in the most efficient way possible. I will be verifying security information to protect your account privacy. May I please have the account number, account holder's full name, home address, and the last 4 digits of your SSN?
<Customer gives the information>
Thank you. May you also verify your phone number and the Email address that you are using?
<Customer gives phone number and personal email address>
Thank you. I am referring to the SomeCompany email address that you would like to reset the password.
I don't use SomeCompany for email, so that address is only useful to me as the login ID. I'm not set up to check that account and I would rather not have to be. But I think you mean wemadethisup@somecompany.com.
Thank you. While waiting, I will share with you a feature of SomeCompany that you can truly benefit. Are you aware of the customer self-help on SomeCompany.com? SomeCompany.com has an extensive series of Frequently Asked Questions (FAQs) that cover all of our products. Customers do not have to sign in to access the FAQs. Quick steps to do it...Open a web browser window and go to http://www.somecompany.com/. On the home page, the navigation menus are on the left side of the window and click on Customers then Help and Support.
I have already pulled up your account.
I don't think the FAQ will help. Please just reset the password.
Okay. Now, for the password, since we do not keep it for security reasons, I can reset it and provide you with a randomly generated one. Do not worry about changing it because you would be able to change it to your preferred password once you are able to log in. Would that be okay with you?
Yes, please.
Sure, now for me to push through the process and reset your password, may you please give me your security pin?
I don't remember setting a security PIN.
A security pin is like a password to your account. This will be sent via a postal mail to you, a few weeks after your service is started. It is a 4 digit number. May you please try to check your postal mails?
OK. I might have the mail somewhere. I have no idea where. [time passes] Sorry, I can't seem to find anything.
Since you have not provided the Security pin, in order to push through with this process, I would have to call you right now on your phone number to authenticate. Would that be okay with you?
Unfortunately, no. My kids are sleeping. Perhaps I should try again during the day?
Yes, you may always contact us. We are available 24/7, Customer.
So there's nothing else you can do?
Customer I really know how important it is to have your password. I would like to apologize however, we need to call you to authenticate so that we can reset your password.
OK. I'll try again during daytime hours.
Thank you so much for your time, Customer.
[time passes]
Customer, here’s what we have done on this chat today, I have assisted you with your SomeCompany inquiry on resetting your password however we need to call you to authenticate. Customer, it has been my pleasure serving you today and I truly appreciate your understanding and cooperation. Do you have other concerns for me today? I will be glad to assist you further.
No, that will be all, thank you.
We strive to exceed your expectations and hope that you will take a moment to complete the 3 question survey that will follow our interaction, your feedback will help us to continue improving how we serve you. Do you want to use our service? Go to http://www.somecompany.com. Thank you for choosing SomeCompany as your service provider and have a great day! SomeCompany appreciates your business and values you as a customer. Our goal is to provide you with excellent service. If you need further assistance, you can chat with one of our Customer Support Specialists 24 hour a day, 7 days a week at http://www.SomeCompanySupport.com
* Actually, SomeCompany is probably right to want better authentication. It's quite possible that someone, say, found their neighbor's bill, with the account number, and leeched onto their non-secured WiFi or used other chicanery so as to connect from the right IP address and thence obtain the user name. It's conceivable that such a person also somehow happened to know the customer's personal email address and last four digits of the SSN.
Calling the phone number of record (which the customer was challenged to give and the service rep is able to verify) would raise the bar significantly. Likewise, assuming the snail mail with the PIN didn't also have the account number, the would-be thief would have had to steal two separate pieces of mail, typically delivered on different days.
The annoyance here is that the stronger authentication is strong on its own. That is, "Tell me the PIN we mailed you" is about as secure as "Tell me the PIN we mailed you and several pieces of not-too-hard-to-find information." and "So you want a password reset? Let me call you at the phone number listed on the account." is at about as secure as "Tell me several pieces of not-too-hard-to-find-information and I'll call you on the phone number listed on the account." Unfortunately, Service Reps are generally required to go through the whole account verification cha-cha-cha before doing anything meaningful.
One wonders, though, why this bundle of not-too-hard-to-find information is good enough the let the customer access the account information, but not good enough to let the customer use the service itself.
- Account number
- Username, being the service provider's home-grown email address for the customer
- Customer's personal email address
- Customer's full name and home address
- Last four digits of customer's SSN
- Customer's home phone number
- IP address associated with the account (from which the system was already able to find the username)
It's sort of a division of labor anti-pattern. A human an a computer working together end up more obtuse than either alone. Offering the customer the service the customer can't log into and the chat support that didn't help is a nice parting touch.
What follows is an anonymized and lightly edited transcript of an actual customer chat sent by one of my "army of stringers, researchers, fact-checkers and miscellaneous hangers-on."
Problem: Trying to sign in; need password
Hello Customer, Thank you for contacting SomeCompany Live Chat Support. My name is Service Rep. Please give me one moment to review your information. I'm ready to assist you today. How are you doing by the way?
Fine, thanks .
Nice to know that you are doing good.
I was trying to log in to your service
As what I have understood, you would like to have your password for you to sign in right?
Yes. I thought I'd already set up an account and your website found a user name from looking at my IP address, but I can't reset the password . Also, I'd rather choose my own user name rather than use the assigned one (wemadethisup@somecompany.com), if possible.
Oh, I see. I understand that it is very important for you to know the password of your here. I also know that you would like to have your email address personalized and change it. There is no need to worry since as your service representative today, I want you to know I am more than willing to help you today with your issue. I can assure you that we can have a positive resolution since we will be working on this together.
Here’s what I can do, Since your password is not allowing you to log in, and since we do not store our customers’ passwords, I can give you a randomly system generated password would that be okay?
That would be fine, thanks
Alright. Please allow me to pull up your account information so that we can resolve it in the most efficient way possible. I will be verifying security information to protect your account privacy. May I please have the account number, account holder's full name, home address, and the last 4 digits of your SSN?
<Customer gives the information>
Thank you. May you also verify your phone number and the Email address that you are using?
<Customer gives phone number and personal email address>
Thank you. I am referring to the SomeCompany email address that you would like to reset the password.
I don't use SomeCompany for email, so that address is only useful to me as the login ID. I'm not set up to check that account and I would rather not have to be. But I think you mean wemadethisup@somecompany.com.
Thank you. While waiting, I will share with you a feature of SomeCompany that you can truly benefit. Are you aware of the customer self-help on SomeCompany.com? SomeCompany.com has an extensive series of Frequently Asked Questions (FAQs) that cover all of our products. Customers do not have to sign in to access the FAQs. Quick steps to do it...Open a web browser window and go to http://www.somecompany.com/. On the home page, the navigation menus are on the left side of the window and click on Customers then Help and Support.
I have already pulled up your account.
I don't think the FAQ will help. Please just reset the password.
Okay. Now, for the password, since we do not keep it for security reasons, I can reset it and provide you with a randomly generated one. Do not worry about changing it because you would be able to change it to your preferred password once you are able to log in. Would that be okay with you?
Yes, please.
Sure, now for me to push through the process and reset your password, may you please give me your security pin?
I don't remember setting a security PIN.
A security pin is like a password to your account. This will be sent via a postal mail to you, a few weeks after your service is started. It is a 4 digit number. May you please try to check your postal mails?
OK. I might have the mail somewhere. I have no idea where. [time passes] Sorry, I can't seem to find anything.
Since you have not provided the Security pin, in order to push through with this process, I would have to call you right now on your phone number to authenticate. Would that be okay with you?
Unfortunately, no. My kids are sleeping. Perhaps I should try again during the day?
Yes, you may always contact us. We are available 24/7, Customer.
So there's nothing else you can do?
Customer I really know how important it is to have your password. I would like to apologize however, we need to call you to authenticate so that we can reset your password.
OK. I'll try again during daytime hours.
Thank you so much for your time, Customer.
[time passes]
Customer, here’s what we have done on this chat today, I have assisted you with your SomeCompany inquiry on resetting your password however we need to call you to authenticate. Customer, it has been my pleasure serving you today and I truly appreciate your understanding and cooperation. Do you have other concerns for me today? I will be glad to assist you further.
No, that will be all, thank you.
We strive to exceed your expectations and hope that you will take a moment to complete the 3 question survey that will follow our interaction, your feedback will help us to continue improving how we serve you. Do you want to use our service? Go to http://www.somecompany.com. Thank you for choosing SomeCompany as your service provider and have a great day! SomeCompany appreciates your business and values you as a customer. Our goal is to provide you with excellent service. If you need further assistance, you can chat with one of our Customer Support Specialists 24 hour a day, 7 days a week at http://www.SomeCompanySupport.com
* Actually, SomeCompany is probably right to want better authentication. It's quite possible that someone, say, found their neighbor's bill, with the account number, and leeched onto their non-secured WiFi or used other chicanery so as to connect from the right IP address and thence obtain the user name. It's conceivable that such a person also somehow happened to know the customer's personal email address and last four digits of the SSN.
Calling the phone number of record (which the customer was challenged to give and the service rep is able to verify) would raise the bar significantly. Likewise, assuming the snail mail with the PIN didn't also have the account number, the would-be thief would have had to steal two separate pieces of mail, typically delivered on different days.
The annoyance here is that the stronger authentication is strong on its own. That is, "Tell me the PIN we mailed you" is about as secure as "Tell me the PIN we mailed you and several pieces of not-too-hard-to-find information." and "So you want a password reset? Let me call you at the phone number listed on the account." is at about as secure as "Tell me several pieces of not-too-hard-to-find-information and I'll call you on the phone number listed on the account." Unfortunately, Service Reps are generally required to go through the whole account verification cha-cha-cha before doing anything meaningful.
One wonders, though, why this bundle of not-too-hard-to-find information is good enough the let the customer access the account information, but not good enough to let the customer use the service itself.
Wednesday, September 1, 2010
A belated Happy Birthday
Yikes, this is a bit casual even for the new, even-more-casual Field Notes [Heh ... I think the current record is now 27 Aug to 14 Dec 2015, which would include a Field Notes birthday -- D.H. Dec 2015]. For months I'd realized that post 500 and the third anniversary of the first Note would come close together, but I got so caught up in spinning up the new blog after post 500 that I forgot all about the date, even though I posted just one day afterwards.
In the new spirit of apathy, I won't hold forth as I did in years past, but I would at least like to note the occasion, if only a bit after the fact.
In the new spirit of apathy, I won't hold forth as I did in years past, but I would at least like to note the occasion, if only a bit after the fact.
Subscribe to:
Posts (Atom)
