Showing posts with label site. Show all posts
Showing posts with label site. Show all posts

Friday, April 4, 2008

Computers and Privacy part 3

RSA Public Key Cryptography

Several algorithms are used today for public-key asymmetric encryption. The most widely known is called the RSA algorithm, named after its inventors, Ronald Rivest, Adi Shamir, and Len Adleman. This method is based on multiplying two prime numbers to come up with the key pair. Further mathematical functions are performed after the multiplication to create the actual key pair. It's a simple matter to use a computer to come up with a rather large prime number, but it's a difficult computation task to take the result of this multiplication and the subsequent operations performed and determine which two prime numbers were used to generate it.

If you want to learn more about RSA, visit the Web site for the company founded to market this technology: www.rsasecurity . com. The RSA Security Web site is an excellent resource for encryption techniques overall, but also has a lot of information pertaining to the RSA algorithm, which has been licensed to a large number of software and hardware security providers.

Because of the difficulty in cracking RSA-encrypted data, it has been adopted by a large number of vendors, including Sun, Microsoft, and Novell, and is the most widely used cryptosystem today.

Digital Certificates

Digital certificates are used to bind a person's name (or an identity) to a public key. Certificates, then, must come from a trusted authority. The certificate itself is determined to be valid (that is, it was issued by the certificate authority [CA] it claims to represent) by a digital signature. Because the public key of a CA can be known to anyone, it is a simple computational matter to use the CA's public key to determine that the digital signature is valid. After this is done, the certificate itself can be assumed to contain a valid identity (a user, a corporation, or another entity) associated with a public key. Using a digital certificate, you then can obtain the public key for a person and use it to encrypt data to be sent to that person, who then can use his own private key to read your message.

Internet 2010

CAs can be trusted companies on the Internet, or you can act as your own CA in your company. Included with Windows 2000 Advanced Server and the family of Windows 2003 servers, for example, is Microsoft's Certificate Services, which can be used within a company that wants to manage its own digital certificates. If you have branch offices and want to use digital certificates to certify public keys used for communicating over the Internet, you can set up your own certificate servers in your enterprise. Or you can use a commercial company (such as VeriSign) and obtain certificates from a third party.

In practice, it also is possible for a hierarchy of certificate servers to be set up, with a single root server being the most trusted certificate server in your enterprise. Then, child certificate servers are created, which can be validated by the end user because the child certificate server itself has a Certificate from the root server (or another server in the hierarchy leading back to the root server) that validates its certificate. It's all a game of trust, however. If the secret key of the root server's key pair becomes compromised, it's possible to impersonate the certificate server and all security is lost. Most certificates also are issued with an expiration date, which can be used to ensure that new certificates, created using a new key pair, are in use.

For this reason, should you choose to operate your own certificate server(s) in your network, you need to take extreme security precautions to safeguard the private key. Likewise, if you use a third- party commercial certificate service, you need to read the policy of that company to determine how it verifies the identity of the end users that it issues certificates to. For example, a CA might simply verify the email address of the requestor and issue a certificate. For a software publisher, the CA might conduct some kind of background check and require further evidence before it issues certificates to the company. Before you decide to use a commercial service for issuing digital certificates, be sure you investigate the company's policies for both issuing and revoking certificates.

Pretty Good Privacy (PGP)

One of the most popular encryption programs on the Internet for a number of years now has been PGP, originally developed by Phillip Zimmerman. PGP uses public-key cryptography and has been ported to many computer platforms, including Unix, Linux, and, of course, all versions of Windows from Windows NT and Windows 95 onward.

PGP Corporation currently markets the commercial version of PGP. PGP is available in a Universal Series version for network gateways, Whole Disk Encryption for desktop and enterprise systems, command-line for servers and mainframes, and home and professional desktop versions. PGP also maintains a Global Directory of PGP keys, replacing the PGP Keyserver service. A 30-day trial of the home desktop version is available.

PGP has been established as an Internet proposed standard through the Request for Comments (RFC) process. RFC 2440, "OpenPGP Message Format," was written in 1998 and details the specification.

An international site devoted to PGP also can be used to download PGP. Visit the PGPi Project International PGP home page at www pgpi. org/ to learn more about PGP International. The downloads available from this site include support for the following platforms:

Amiga

Atari

BeOS

EPOC (Psion, and so on)

MacOS

Newton

OS/2

PalmOS

Unix

MS-DOS

Windows 3.x

Windows 95/98/NT

Windows Me

Windows 2000

Windows XP

As you can see, various operating systems are supported by the International PGP site, which is working to establish PGP as a standard for encryption on the Internet. In addition to the standard PGP package, which provides for a number of applications, such as document encryption and email, a number of other products also are available, such as PGPdisk (for encrypting disks) and PGPphone (for making secure phone calls on the Internet).

The PGPi Project also is making PGP available in various languages, and also is currently translating the documentation. PGPi is a nonprofit organization dedicated to further developing and distributing PGP technology throughout the world. In addition, for some platforms, the source code is available so that you can examine it before compiling it on your system.

Wednesday, February 27, 2008

Outline marketing plan for Asuk Creative Limited a B2B provider of Internet services continue...

Objectives

The objectives are each built around the SMART criteria (specific, measurable, actionable, realistic and timed).

  • Increase market share. ASUK Creative Limited currently holds 2 per cent (200 servers) of the UK dedicated server market (approx immediately 10,000 dedicated servers). ASUK should plan to increase this steadily to 16.7 per cent after four years. Since the market share has risen from 0 to 2 per cent in one year without increased marketing, this is a realistic target.
  • Streamline ordering processes. The new web site called DediPower.com should incorporate online facilities for order processing, upgrades and support. The development of these features can continue over time but a fully featured site should be ready for launch.
  • Increase brand awareness/brand building. By launching a new site, ASUK can take advantage of a fresh start but still use all the advantages of an established company. A brand image of power and quality, yet competitive prices should be established through intensive marketing and excellent CRM. The company plans to have a powerful brand name within six months of launching the site.
  • Internet 2010
  • Create self-contained entity for possible initial public offering (IPO) or trade sale.
  • ASUK can aim for an IPO within three years, being sold either to a competitor or to a diversifying larger company. The sell value is currently £300,000. A target should be set to have this at £1 5 million within three years.
  • Expansion into international markets. The launch of DediPower means that foreign clients will become more accessible. The improved site will have support for international sales.
  • Improve CRM and customer support. By improving these fundamentals, ASUK aims to sell additional products to its current clients. Currently, 25 per cent of clients have bought additional services, and the aim is to increase this to 55 per cent within a year.

Strategies by target markets

  • Current customers. By rebranding, enforce customer loyalty and improve service level. Also provide an easier product upgrade path. Better support and customer self-service should also be provided.
  • Domestic. Build brand as a high-quality service with lower-value pricing. Offer three core incentives to show confidence in the product: thirty-day money back guarantee, UK price matching initiative, no minimumcontract. ASUK will be the first company in the UK industry to offer all these incentives together in a genuine fashion.
  • International. Key strengths to marketing include sustainability and experience. The product will be positioned in the market as a high-end service, offering good performance for companies that have interests across Europe.

The marketing mix

  • Price. Although prices should be offered on a price match guarantee within the UK, they should be based around a product-line pricing strategy; that is, each customer can start with a basic product and build layers on top to create their custom product.
  • Product. The product is to be sold individually, but a discount should be offered for multiple sales and/or prepayment packages. Customer loyalty could be rewarded with additional free services.
  • Promotion. ASUK should base the promotion around an online marketing strategy, using online targeted banners and search engines, complemented by increased exposure on the major Web hosting guides. Publication to online and offline trade magazines of press releases and adverts will reinforce the respectability of the brand.

Evaluation and control

  • Monitor market share and company growth rate. Frequently obtain market share statistics. An estimate can be made by obtaining the total number of dedicated in the market segment and calculating the percentage of them that ASUK holds.
  • Occasional customer surveys to ensure support satisfaction is increasing. ASUK already has the facility to conduct customer surveys online. These should be conducted half-yearly to ensure that satisfaction objectives are met.
  • Demographic analysis of buyers and potential buyers. To determine whether ASUK is penetrating all potential markets sufficiently, customer account details should be collated and analysed to produce maps of customer distribution.

Thursday, February 21, 2008

E-NEWSLETTERS - DEFINING AND REFINING Part 10

3. Some content in e-mail, full content on web site (multiple pages). This is similar to approach (1), but here the e-mail newsletter is longer since it contains a short extract from each article. Typically a more >> option link will be available to take the user through to the web site. This makes it easier for the reader to decide whether the content is relevant to them. This is a common approach; Figure 5.14 is an example.

4. Some content in e-mail, full content on web site (single pages). This is similar to option (2), but again has the advantage that an idea of the relevance of the content is given in the e-mail, and also it is easier to find other content from the same newsletter on the web site.

5. All content in e-mail. This approach is being used by Freepint (www.freepint.com) at the time of writing. A lot of detailed content about web searching is provided in two detailed text e-mails, sent each month. Here, a clickthrough is not required to the site at all(although some longer articles may require this). It is typically used by professional or technical plain-text newsletters. This approach is arguably the best method of communicating information to the recipient. However, for the marketer, calls-to-action encouraging further participation are more difficult to achieve from the newsletter than from the web site.

Internet 2010

This decision is difficult, since the preference on length varies according to the individual. For many, including this author, part of the power of e-mail newsletters is to be able to get a rapid briefing on developments about a particular topic. If you have to clickthrough to a web site and then understand the structure of the web site, as is the case with the What's New in Marketing web site (www.wnim.com), this slows down the experience.

A related question is, should we archive? For a B2B newsletter, the question is perhaps not should we archive, but how? Archiving a B2B newsletter, provided it has quality content, provides an excellent resource for your customers. They will return to the resource as they face particular issues. As mentioned above, this can also assist in generating new subscribers, since specialist articles indexed by search engines will gain new visitors who may look to tap into your expertise. For a B2C newsletter, the issue is not that clear cut. If the e-newsletter is providing news or interesting content, then similar arguments apply — it is a resource that will encourage repeat visits and can also, via search engines, act as an acquisitions tool. For B2C newsletters from an e-tail site it is inappropriate to archive the content, since product information and offers will quickly date.

When an archive is content-rich, which is typically the case with a media or news site, the utility for the user can be improved by developing 'related article' features. ClickZ (www.clickz.com) has a good related-articles feature. This lists items related to the current article according to which category they fall into, or according to similarity in key words in title or body.

Decision 18 how do we gain subscribers?

There are two aspects to gaining subscribers: first, there are various sources where e-mail addresses can be collected; secondly, there is selling the benefits of the newsletter so that potential subscribers are happy to give up their e-mail address. You may want to refer back to Chapter 4, where approaches to gain customer e-mail addresses were covered in more detail. This explains maximizing our use of online and offline touchpoints with our audiences to explain the proposition, and offer the opportunity to opt-in without building too many barriers.

On the web site, we need to ask these three questions to maximize sign-up:

1. Is our opt-in given enough prominence? Is it on the home page? Is it 'above the fold'? Is there enough screen real-estate devoted to it? Is our archive and proposition indexed by search engines? Is it prominent throughout the site?

2. Is our proposition clear? Does the messaging say more than 'opt-in to our e-newsletter'? Does the sign-up page highlight the benefits? Are the benefits for different audiences clearly described? Is the quality of content demonstrated through an archive or example newsletter?

3. Can we overcome barriers to subscription? Reassure potential subscribers that you will not be overloading them with e-mail. Show how the newsletter will be relevant and targeted. Reassure them that details will not be passtd on to third parties by using those six magic words: 'we will not share your information'.

E-NEWSLETTERS - DEFINING AND REFINING Part 9

Decision 15 marketing communications integration

There is a tendency to plan our e-mail newsletters with blinkers on. If this happens, we lose opportunities to leverage the strengths of different media for different purposes. Here are some ideas on how to avoid this:

  • Use the e-newsletter to preview future offers and product developments before other media. Highlight unique web offers — this will be an incentive for audiences to open the e-newsletter.
  • Use the e-newsletters to reinvigorate recent or current campaigns or promotions that were first highlighted in other media.
  • Use the e-newsletter to give more detail than the offline newsletter or house magazine provides — refer visitors to the online version and reduce the size and cost of the offline communication. Alternatively, put the whole magazine online, as with http:// www.easyjetinflight.com.
  • Rather than referring the media or other audiences to press releases or a media centre, refer them first to an e-newsletter item. This will give them a more complete picture of what the company stands for, and your current news.

Decision 16 e-mail integration

Alongside the e-mail newsletter, there will be many other e-mail communications from an organization. This leads to decisions about what is the best way to break major news such as a product launch or upgrade.

Internet 2010

I have seen newsletters where a major initiative such as a product launch or an event invitation becomes lost in all the other news items. Many newsletter templates could be improved by avoiding the newsletter being a list of items with similar weightings. This danger can be reduced through themed subject lines, or an e-mail newsletter design that gives precedence to certain items and is not too long. However, the danger of diluting the message still occurs. In the case of the product launch, it is best to use a separate e-mail to give this message. The opt-in form should give this option, so that the e-mail received is in keeping with the subscriber's expectations.

Decision 17 web-site integration

One of the benefits of e-newsletters, compared with their paper-based equivalents, is the ability to deliver a large amount of valuable information at a low cost. Of course, this is a double-edged sword. Too much information will make the e-newsletter unwieldy, and your message will not get across or the recipients will not be able to locate the information relevant to them. So when you want to convey a lot of information, as is the case with many newsletters, you have to decide on the split of content between the e-mail newsletter and the web site, where more detailed content may be hosted.

To simplify an example, let's say this newsletter contains just three different content areas, or three different articles. The options are:

1. Minimal content in e-mail, full content on web site in multiple pages. Here, the e-newsletter contains the links and a very short summary of the article, linking through to the full article on the web site. This has the benefit that the newsletter can be scanned very rapidly by the recipient for articles of interest. However, there is no indication of the quality or relevance of the content, which is possible with approaches (3) to (5). It also less easy for the other articles to be read than in the next option, (2).

2. Minimal content in e-mail, full content on web site in a single page. As in the previous case, the e-mail has limited information, but on clicking through to the web site a single page newsletter is presented that contains all the articles. This has the benefit that the interested reader can rapidly find the information in all articles.

Monday, February 11, 2008

Early Problems: Whose Mental Model Is It, Anyway?

In the case of Rural Net problems arose early on with the development of the original interface to the web-site. This was based on user actions, with a button bar whose topic heading represented verbs rather than nouns.

Consequently, the interface was centred around a number of actions - enquire, submit, pay, notify and monitor. These actions could have a number of interpretations that were entirely subjective and dependent on the users' interpretation of the actions that they wished to perform. For instance: in the case of a user checking their local Council tax bill, would this be an enquiry, monitoring a payment, submitting a payment or paying? It assumed a particular mental model for users which was in practice impossible to predict. This problem was further exacerbated by the fact that none of the content providers were in a position to provide the specific functions promised by the action style topic headings.

Internet 2010

The content providers were not happy with the original action-based interface. They anticipated that their end users would be put off by the use of language such as: "Citizen's View" and "Technical Annex". Structuring the site in this way also made the assumption that people would not visit Rural Net out of idle curiosity but with a clear goal of what they wished to achieve.

The original interface also included a personalization process, which gave the impression that new users must go through a registration procedure to access the site. Given that the site was sponsored by local government and the police, asking visitors for personal details could be seen as intrusive, although in fact, registration was optional and the intention was to help people viewing the site from public access terminals to save their favourite options.

The site also included a map style interface which gave access to geographical information in the region. This application had to be downloaded - a slow and tedious process which most users would give up on. The application itself was idiosyncratic and difficult to use.

Finally, there was no adequate help or site map and the search facility did not work. Given the obliqueness of the site's content headings this made Rural Net extremely difficult for the average user to navigate.

Sunday, February 10, 2008

Identifying and Getting Access to Users

Successful intranet projects require access to users. In situations where this is discouraged, information may have to be gathered covertly. In situations where this is strictly forbidden, it is important to understand the limits and to find creative ways to work within them.

Identifying users of an intranet is as difficult as it is crucial. Getting access to them is more so. This proved to be a real challenge in Example A for several reasons. As is often the case, the project owners were concerned that employees would come to expect too much of the new portal. As a result, the usability engineers were told not to show associates prototypes or concepts that might "get their hopes up." Attempts at gathering information through field studies were repeatedly denied. The usability engineers were not to create any expectations at all, but to generate excitement whenever possible.

Internet 2010

What to do? The project leaders repeatedly described themselves and the developers as typical users, suggesting that the team observe them instead of going out to the stores. The usability engineers accepted the offer and treated the observations as sales opportunities. In one example, the usability engineers observed a project leader retrieving information from the newly designed intranet site. After conducting the observation, the usability engineers described the type of information that could be provided by actual (rather than representative) users, and how a fresh set of eyes might be useful. Eventually, the project leaders referred the usability engineers to customers who could be relied on to provide less biased feedback.

We took every possible opportunity to educate the business and technology sides of the project on the types of information that we could gather through field studies. One of the most difficult concepts for us to land was that users could provide us with useful information about their use of the intranet even if they had never used it. For example, users could have let us observe their current work areas, showing us their offices, allowing us to understand what systems they used and how an intranet site could make their lives easier. These educational opportunities challenged our ability to remain positive and resilient At times we spent more time complaining about our limited role than working to make the best of it. We should have visited the retail environment and gathered the information we needed any way we could.

In Example B, the usability engineer had access to the current site's webmaster and the supervisor of the employees who were most likely to use the site. Both of these people were invaluable resources. Although the client's Project Manager had forbidden the usability engineer from asking these experts what the site would be used for, the usability engineer was able to gather this information by asking good, carefully framed questions about the underlying technology. The usability engineer initially asked what type of files were being accessed on the site and then followed up with a questions about how the users would use the files and what the userstneeds were for the files. The subject matter experts didn't share the project managers' ideas that all the analysis was already complete and were therefore willing to discuss the users' need with the usability engineer. This data, covertly gathered and analysed, was used to build a solid information architecture, which was critical to the success of the site.

Saturday, February 9, 2008

The Beginning of Progress: Common Sense and Consistency

The catalyst for change occurred when the project missed some deadlines which put its funding in jeopardy. At this stage one of the industrial sponsors, Telco, assigned a small team to work on Rural Net and helped to pull it around. This team provided project management and development skills. Their work involved liasing with all the project partners and making some common sense improvements to a site prototype.

Internet 2010

The Telco team (especially the project manager) understood that people expect Web conventions to be fairly standard and become resentful and confused when this is not the case. So actions (verbs) on the original button bar were replaced with categories (nouns) — education, tourism, business, community, transport, training.This meant that users could search for information using hypertext links in a way that was familiar to them from its use in other web-sites. More importantly for naïve users it provides an analogy that is similar to the categorisation used in printed material, such as magazines, books and newspapers.

This version of the interface made great improvements to the navigation of site, providing a use of language which was more in tune with prospective users. It illustrated that usable web-sites can be created by following some very basic rules. For example: making sure that users can access all the functions of the site all of the time. The layout of horizontal content topics button bar (underneath the header) and vertical functions button bar (to the left side of the screen) ensured that users could navigate their way around the site without needing to scroll and that the options available to them were always visible. These comments may seem obvious, but the briefest of excursions on to the web will show that too few designers show consistency in their use of navigational constructs. They do not consider the needs people have for visual metaphors, for example, the web page as an electronic version of the magazine or catalogue.

The Politics of Rural Net: One Web-Site, Many Owners

Rural Net is a pan-European project (partly funded by the European Union) which involved participants from rural regions in four countries. Web-sites were produced for each of the four regions and although not identical, the original aim was that they should share some commonality in approach, delivery and use of technology. With the passage of time and the imperative of local needs this requirement gradually became less significant.

The focus on the use of web technologies in rural areas was to improve the social and economic well being of local residents and businesses. The principal application areas were:

  • support for small and medium sized business;
  • local and public services;
  • Internet 2010
  • lifelong learning;
  • community networking and information.

The idea was that the Rural Net web-site should give the local community seamless access to various types of information offered by regional content providers, who in this case consisted of the local council, the Enterprise Board, the tourist board and police force. The aim of the content providers was to use the Web to provide a better service to the public.

Each region was committed to installing a number of regional access terminals to allow the public to use the site, for example, libraries, tourist information and enterprise board offices. This decision ensured that a high percentage of people accessing the site would be naive users, whose experience of using web technology was limited.

Rural Net had a range of parties involved in its production:

  • A technical lead, a small software house responsible for day-to-day development of the site.
  • The regional content providers, who were also in essence the clients.
  • Industrial sponsors, two large IT services companies who provided practical consultancy as their contribution to the project.

The author's involvement with Rural Net came about as part of this industrial sponsorship. In addition to usability consultancy, the industrial sponsors provided project management and development skills. There were a number of key themes that were considered important in the planning of the web-site, these were:

  1. The integration of information, both at a technical level (Integrate these two databases") and an organizational level ("get these two organizations to work together for the good of the local area").
  2. Personalization: users could register on the site. Registered members would have the ability to request specific types of news, to save search results and to bookmark links. It was anticipated that this feature would be particularly useful at the regional access points where a number of different users would use the same machine.
  3. The use of a map style interface to present geographical information to the user.

The nature of the project and its funding meant that there was a wide range of people involved, whose interests and goals did not always match. The technical lead (a small software company) and a research group at a local university were both reliant on funding from the project. They regarded it primarily as a research opportunity. The content providers wanted a site that supported the local community and local businesses, they were keen to have a practical easy to use site which would have a life beyond EU funding.

Internet Blogosphere