Tuesday, September 19, 2006

Please excuse our appearance - mashups gone wrong!


It seems that I prematurely blamed Blogger for display problems - a holdover of being a software consultant maybe! It seems that my recent addition of a Technorati tag cloud consumed all of my hosting bandwidth in the background, preventing access to stylesheets, images and all of the other fancy stuff that makes my blog so slow to load! The tag cloud has been disabled from updating automatically for now, while I try and work out how to get some more bandwidth from my hosting account and fix an underlying problem with the code.

This has been a demonstration of abuse of the Web 2.0 approach - despite the simplicity of being able to add new features and components to a web app, it is essential that the underlying components are well tested, trusted and generally likely to play well with others. I made the inexcusable mistake of taking a piece of code that appeared to work and trusting that it would be fine in my environment. Web 2.0 still depends on a strong software discipline for components, even if they can be mashed-up into web pages with relative simplicity and little effort.

Hopefully this blog will return to regular service soon. Blogger is down for schedule maintenance at 4pm this afternoon (presumably PST, but they don't make that very clear), presumably to fix some problems they had a couple of days ago with their templates. So expect that there will be some problems that I can actually blaim them for later today, so they can hold my premature doubting of their quality of service in credit.

The presentation components of Blogger (blogblog.com) are down - again. If you are coming in directly to the website rather than a feed reader, I apologize if the default style is hard to read. Hopefully Blogger will quickly sort out its recent extremely poor reliability so that everything can return to its normal state of unreliability.

Monday, September 18, 2006

Building the Organization of the future

James Taylor has been looking at Using decisioning to build the bank of the future. In it he picks up on several key themes that I agree are important. I would summarize them as:
  • Customer identification
    • Always identify the customer
    • Make the interaction experience more personal and appropriate
    • Not request the customer to re-identify themselves for every activity requested
  • Cross-channel consistency
    • Ensure that a customer's interactions follow the same preferences and approach across all the contact points they have with the bank
    • Enable services and transactions selected in one channel to be used across others
  • Personalization
    • Ability for a customer to select preferences for the way interactions work
    • Provide themes that drive how the activities are presented and run (e.g. fast, step-by-step, most used options, etc) - personalization isn't just about choosing the color of your website
    • Ensure preferences are remembered and used across all channels
  • Individualization
    • Offer the customer options in the way they interact based on observed behavior
  • Cross/up-sell of services
    • Predictive selection of offers that are most appropriate to the customer and not likely to be an annoyance
    • Target offers to the channel - a customer making a fast cash withdrawal from an ATM probably does not want to be hassled with other offers

In his post, James lists the key channels as being:
  • ATM
  • Call center/Interactive Voice Response (IVR)
  • Website
  • Branch
  • Monthly statement

I hadn't thought about the last one (as I only get my statement online), but it is an important point of customer interaction. In addition, I would like to extend the channels to include 'mass marketing' - the postal and phone based marketing that is pushed to customers and can be an annoyance alongside an otherwise acceptable service. Especially the use of postal mass-mailings when a customer has selected to have all other statements and communications delivered online (personal rant complete!).

The rules that James has highlighted are not really bank specific, and could be easily applied to the "Wireless or Mobile Phone Service of the Future", the "Government of the Future", and the "Utility Company of the Future". Achieving the goal of "Organization of the Future" requires a combination of technologies, processes, identity management, integration and analytics, all of which exist today. What is needed are some smart people to push the business drivers, building teams to perform the process design, the technology implementations and the systems integrations. The Organization of the Future is a possibility, it just needs the Organization to realize the value.

Technorati tags:

Friday, September 15, 2006

DRM hacked again - is it useless for protecting corporate documents?

The speed with which hackers broke the Digital Rights Management (DRM) from Microsoft and Apple last week, was commented on by David Berlind on ZDNet - 24 hours: The time it takes to crack the newest DRM from Microsoft or Apple.

This article was timely for me, as I was reading it just after coming off a conference call with Brad Beutlich, Director of Business Development for Safenet, a provider of encryption applications and devices for software and media. His comment around the announcement that was something along these lines:
Perfect DRM protection is like a waterproof watch - it doesn't exist

He wasn't surprised that either Microsoft or Apple had their protection systems hacked, citing a host of technical reasons why this is possible. A significant one is that the OS and the hardware it runs on must both provide facilities to secure the encryption keys used to unlock protected media - standard OS and hardware makes it too easy for a determined hacker to read the required information and incorporate it into a separate unlock utility. It seems unlikely that in the near future the PC hardware will provide this capability as standard, so DRM protection is likely to continue to be a feature of hacker's attention.

Now I'm not so worried about the DRM schemes that protect Windows media and iTunes (at least not when wearing my business hat). My previous posts, DRM gets lardy and Web technology for electronic records worry about the use of DRM for protection of vital business documents, both inside and outside of the corporate firewall. Both Stellent and EMC claim that they have coupled their recently acquired DRM technology with Records Management:
EMC recently announced that it was pairing its Records Manager with DRM technology aquired from Authentica, enabling records managers to enforce their policies for all records, independent of custody. In principle this seems like a great pairing, but there are some issues to be addressed[...]

It is in the corporate world that DRM could offer significant value, though there are issues related to use and lock-in with proprietary DRM solutions as I mention in my previous posts. Documents that need encryption are likely to be most valuable to a malicious hacker with the aim of damaging a corporate reputation. Given the recent news that DRM can be hacked easily, it seems it can only really protect against misuse of documents by casual users. A determined hacker that had acquired corporate documents through fraudulent means could probably hack a utility to unencrypt them (or find one on the Internet) in a short amount of time. The DRM protection of the documents would be worthless for the most valuable use case.

Safenet claims a strong security background, going far beyond that of consumer targeted DRM. Amongst other things, they can provide hardware devices and tokens that hold encryption keys, preventing a major hacking loophole in consumer systems. Although this may limit flexibility of document usage, targeting the deployment of the technology to appropriate users in an organization may be considered worthwhile in highly sensitive environments.

When identifying a need for DRM for corporate assets, ensure that a vendor that provides it is not just repackaging a consumer solution - Windows Media Player and iTunes are not the gold-standard! Stronger hardware reliant technologies such as Safenet come at a price - both flexibility and dollars. The question is whether IT managers and legal cousel can balance the risks of document misuse against the issues and costs of corporate DRM.

Technorati tags:

Thursday, September 14, 2006

Offering third-party content & services may save traditional businesses

Recently I have been immersed in the world of telco, media and entertainment; all related industries for communicating different stuff. At the same time I've been digging more deeply into the telecommunication companies: wireless/mobile, wireline/landline, and VoIP. It is prime-time for new technology driving new consumer capabilities, and new market requirements driving new technology. Despite this, telcos struggle to keep up with the new possibilities and opportunities that technology offers, partly due to their traditional philosophies and business models. They, like other traditional service providers risk losing long-term customers to new innovative companies if they don't adapt.

Telecommunication carriers have traditionally been highly conservative in the way they develop and adopt new technology, driven by an underlying philosophy requiring measurable and controllable Grade of Service (GOS) and Quality of Service (QoS). Grade of Service roughly equates to how likely you will be unable to place a call because of network congestion. Quality of Service is more about the actual quality and reliability of individual calls. As the technology for the telephony system was growing, significant engineering rigor was applied to ensure every component of the system operated effectively to ensure service levels. To ensure service levels, stringent control is taken to what is plugged in to the system, and all that can pass across the wire is voice, fax and dial-up modems.

Mobile/wireless carriers adopted the trusted approaches of their landline parents, to build telco networks on top of far less controllable infrastructure, while still offering a level of service generally acceptable to their customers. The network and all that plugs into it is still stringently controlled. Despite rapid increases in capabilities of mobile devices, the ability of mobile carriers to adapt and provide new services and content has lagged due to stringent requirements for quality and control over what is plugged into the network.

Based on initial network philosophy and subsequent rapid growth, the Internet is built on the concept of being an interconnected system of unreliable and largely uncontrolled networks and components. After adding the World Wide Web on top of this network infrastructure, the result is a highly organic, often disorganized mass of media, information, services and devices. All of this leads to a level of service that is largely unknown. It is only the efforts of the best datacenters and network infrastructure that enable any control of the level of service experienced by users. But it is the ability for services of low quality and reliability to be accessible to users at all that makes the Internet a breeding ground for rapid advances and disruptive technology.

Internet users love the speed of change they experience. Telcos, both wireless and wireline are slow to respond due to their traditional business models and perceived need to control everything that is attached and everything that is put on the wire.

As telcos start to offer themselves up as an entry to a range of mobile media, services and entertainment, tech-savvy users will demand far more rapid development of new offerings. The networks have the opportunity to capitalize, by meeting this demand and being the simplest identifiable means for customers to get at new stuff. The high walls around everything that is offered by today's mobile networks will start to erode if they don't manage to keep up with the expectations of their customers, but they can't do it alone.

Ringtones, wallpapers and basic games offered by some of the networks have satisfied basic customers for a while. But fast 3G networks and off-deck (third-party) websites like Jamster make access to new content, services and applications far easier. If the networks don't keep up by making their own portals better while opening them up to more third-party services, they will start to lose an important revenue stream as customers start to identify more closely with third-party mobile content providers.

Customers start to switch their allegiances fast when they see the opportunities offered by a renegade third party service provider, threatening traditional business models and revenue streams. Wireline telcos are seeing the threat from VoIP. Mobile telcos are at the point of losing lucrative content services to easier to use third-party portals. Maybe other traditional services will start to experience that soon. The question is, how much do banks have to feel the pressure of services like PayPal and Zopa before they start producing innovative new offerings for customers?

Technorati tags:

Wednesday, September 13, 2006

ATMs for buying services on the move

My trip back to the UK was a useful reminder of the different services offered by banks to their customers, compared to the US. Some banks seem to be playing with their vast network of ATMs as a channel for selling services alongside simple cash withdrawals. Given that many UK banks do not charge for withdrawals from ATMs within their broader partner networks, this may be considered an important way of improving the returns from cash machines.

The most common service I noticed was the ability to buy 'mobile phone top-ups' (Natwest provides a decent flash demo of how it works). Given the penetration of mobile phones in the UK (greater than one subscription per capita), offering services to cell phone users may make sense. Prepaid phones make up a significant percentage of the total, and buying top-up credit is something that users do regularly, so making top-ups easily available and fast to buy makes sense to the mobile networks.

From a bank point of view, ATMs do not need to be physically modified to dispense credits - a back end integration is purely required to talk to the common mobile networks. Compare this with Bank of America that insists on offering me the useful, but barely utilized service where you can by stamps. This type of service carries a cost in keeping the 'stamp dispenser' filled and presumably needed the ATM to be modified to operate this.

ATMs are suited to providing services to customers who are 'out and about', rather than performing transactions that they could perform in the comfort of the own home in front of the PC. What other services do (or could) banks provide through their pervasive ATM channel? The University of Pennsylvania has some thoughts that don't seem to extend much beyond the obvious mini-statement and check cashing. I expect that we will continue to see big differences between the offerings in the US and Europe, where electronic / online payments, direct debits and prepaid mobiles are common and paper checks/cheques are less so.

As payment mechanisms converge across online, mobile phone, debit cards and contactless payments (see Bankwatch for many examples), the ATM and mobile phone are likely to become a central point of contact for buying services on the move. As I focus more on mobile technologies, expect some new blogs on this soon.

Technorati tags:

Tuesday, September 12, 2006

DIY rather than IBM

Andy Mulholland blogged on CTO Blog Unavailable Soon or no two are ever the same! about the evolution of differentiating products. It made me think about examples in the enterprise software market.

In Andy's mind, the standard tool for differentiation as we head to a level of blandness in all of our products (IT, financial, consumer, etc) ends up being price. He believes that customization is a factor that can more effectively provide differentiation.
[...]In amongst the differentiation possibilities are some factors that were quoted in the first age of the Internet, the one that really didn’t work when some basic business rules were ignored. The one that really interests me is ‘customisation’, the idea that by a fully connected and interoperable business world it would be possible to deliver exactly what was wanted by connecting the consumer directly through the manufacturing or services ecosystem.

In the current age of the Internet; Web Services, SOA and Web 2.0, [...]

I agree with Andy that Web 2.0, with its focus on simplicity in aggregating web services into a single application has enabled application designers to differentiate. My blog is for example different from the CTO Blog not just because of its focus or content, but because of the components we have alongside the basic text, differentiating our approach and the way that readers interact with us. Our product is different, not just because Andy writes better stuff than me.

Looking at this from a slightly different angle, some enterprise software companies have been successful at differentiation before, by being the focus of a strong ecosystem of partners that customize their products. FileNet with its community of Value Added Resellers (VARs) had a powerful base product (that was otherwise just another bland repository/workflow offering) that was tailored by the VARs according to the needs of their market segments to provide vertically focused offerings. These were further customized by the VARs to provide the eventual 'bespoke' solution for each customer. FileNet was highly differentiated by the fact that its VARs knew their own market segment better than almost anyone out there, making the end product different than that offered by IBM for example.

To my mind, this mirrors Toyota's approach with Scion, as described by Andy. The problem now is that FileNet has been acquired by IBM. And Big Blue aren't renowned for wanting to hand over potential services engagements to other companies, despite the 'toolkit' nature of some of their enterprise software that would suit this model.

I haven't seen how FileNet's VAR network is holding up, but I would be interested to hear of any feedback from anyone 'in the know'. VAR customization was an essential part of FileNet. Can IBM stomach that reality? If not, maybe in the world of enterprise software acquisitions Web 2.0 is the only sustainable customization model - it offers DIY rather than IBM.

Technorati tags:

Travel, processes and back to blogging

After a nice little trip to London to visit friends and family I have made it back to Boston. I avoided reading too much work-related email while I was away, so now I'm playing that big catch-up game. Feeling tied to blogging during this time (both mine and my regular reads) was also a new experience, so I'm trying to skim some of the more interesting blogs I missed while I was away.

As ever, airport security, immigration and customs formalities were interesting to watch and judge from a 'process' standpoint. Heathrow always strikes me to be a reflection of London as a city - the airport manages to cram a large number of impatient people into a small space and half a dozen chain pubs, while formalities try to be effective and efficient but somehow just fail to get it completely right. Logan airport similarly models Boston, with constant construction work, ineffective directions, and security and customs formalities that seem to require an ever increasing number of people and paperwork, but at least seem to work OK.

I would also love to meet the bloke that originally designed the baggage claim conveyor. Another idea in industrial efficiency, badly executed in most airports. I don't claim any abilities in handling big, physical processes like baggage handling, but I do wonder if anyone with a process or manufacturing background has really looked at our largest airports to see how this most visible process could be improved so that people will actually check in their luggage.

Similarly, I'm sure that many business process experts could look at the paper handling around customs and immigration and really improve the processes. To my untrained eye there appears to be many things that could be done, including reducing paperwork, improving forms, making effective use of available technology that could make the traveler's experience (and waiting times) far better.

As ever, travel is a great experience, with even the most familiar places and processes becoming open to new interpretation when you've been away from them for a while!

Technorati tags:

Thursday, September 07, 2006

DRM gets lardy

Vacation / holiday is great! The weather is great, and the travel through Heathrow is always a nightmare, but its still great to be 'home' for a bit. I could say the guilt of not blogging hit me. Its more that I'm staying with my folks, so escaping to the PC for an hour is a good thing now and again, so here is an item I felt I should comment on.

I almost missed a nice post at the end of last week by James Governor on MonkChips, titled: digital lard for the enterprise: DRM meets document formats. I certainly couldn't have named it better myself, as it probes some of the fatty issues around Digital Rights Management clogging up documents repositories. Stellent was named as one offender with their most recent acquisition of SealedMedia. As I talked about in a little detail last week:
EMC recently announced that it was pairing its Records Manager with DRM technology aquired from Authentica, enabling records managers to enforce their policies for all records, independent of custody. In principle this seems like a great pairing, but there are some issues to be addressed[...]

Then I go on to talk about some of these issues, finishing with the most important: "Proprietary encryption and DRM typically ties an organization to that vendor for life". James puts it a little more bluntly (and effectively):

You see, if the vendor in question decides you have broken the terms of the software license, they could, in theory simply turn your documents off. The vendor , not the customer, holds DRM keys.

Of course you could argue the great majority of current documents usually require Microsoft anyway, to read them. But those documents are readable. DRM on the other hand adds a whole new level of difficulty.


And so it seems that we agree that DRM has its issues. It also has its place, so to reinforce the message James finished up:
But not all documents need that protection.

Now I have to go back to wrestling why it is that I am looking at DRM at all, and why companies believe they need it. I'm going to be doing a little work with wireless / mobile telcos and their sale and distribution of content. A space well removed from the records repositories I am most familiar and closer to the 'end of the (consumer digital) world is nigh'.

Technorati tags:

Friday, September 01, 2006

Blog hiatus and mashup

Those of you who click through from your feedreaders into these blog pages may notice that there have been a few changes.

First, I have added Trackback using Haloscan - you should be able to ping a post's trackback URL found by clicking the link (a popup) at the end of the post. The standard Blogspot links remain as well for the Blogger users.

Second, I hacked a script by Matt on the Random Thoughts blog to retrieve this blog's Technorati tag cloud (see right menu). Sort of in lieu of categories really. Since I don't have control of Blogger, I'm running the PHP for this on a hosted server, hidden away somewhere, and plugging it into Blogger as a chunk of javascript. Let me know if its useful, or if it just fails to work - I'll save the bandwidth!. Matt, nice work on the script!

Finally, you'll notice a little break in my blogging - I'm heading back to the UK for a vacation and a friend's wedding. Should be back full force in just over a week (assuming my precarious visa situation let's me back into the US). So don't run away. And if you want to make sure you catch up with my writing as soon as I return, subscribe now by clicking this icon and selecting your preferred feed reader:

Alternatively, subscribe by email

Enter your email address:

Delivered by FeedBurner




Technorati tags:

Who takes responsibility for security?

Neil Maechiter put out an interesting post about biometrics and the use of multi factor authentication. He references a post by Jerry Fishenden, Microsoft's National Technology Officer for the UK, describing how extremely secure systems should use 3 factor authentication:
something you know (such as a PIN), something you have (such as a smart card) and something you are (which is, of course, where biometrics typically come in).

A couple of weeks ago I talked about how US and UK banks are approaching multi-factor authentication for access to online services and secure banking sites. In the US the FFIEC has mandated two factor authentication, although the way that some banks are approaching this seems to require only software tricks to support two types of 'something you know'. In the UK, card readers and key fob tokens are being rolled out now to supplement the first factor of username/password, following hot on the heels of mainland European banks.

The third factor, "something you are", has not been applied by banks (to my knowledge), but with the accelerating pace of biometric passports and identity cards this could soon be an option. The question is, does your online banking really need a third factor of identity to be secure? The third factor (biometrics) purely adds extra protection to ensure it really is 'me' at the computer keyboard - not someone who found my stolen key fob and attached Post-It with my username and password written on it.

It seems to me that the bigger risk to my accounts are through personal information being compromised internally by company and agency IT staff or insecure systems. Maybe with 2 factor security providing authentication protection, the banks will start to take some responsibility for their part in the security of our accounts and information -- deflecting the blame to hackers and customers outside the organization will no longer provide enough aircover.

Technorati tags: