<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Think Vitamin &#187; Peter Nixey</title>
	<atom:link href="http://thinkvitamin.com/author/peter-nixey/feed/" rel="self" type="application/rss+xml" />
	<link>http://thinkvitamin.com</link>
	<description>The Web Practitioner&#039;s Blog</description>
	<lastBuildDate>Thu, 09 Feb 2012 16:41:31 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>The Thrill of the Launch</title>
		<link>http://thinkvitamin.com/uncategorized/the-thrill-of-launch/</link>
		<comments>http://thinkvitamin.com/uncategorized/the-thrill-of-launch/#comments</comments>
		<pubDate>Thu, 27 Mar 2008 09:00:13 +0000</pubDate>
		<dc:creator>Peter Nixey</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.thinkvitamin.com/features/webapps/the-thrill-of-launch</guid>
		<description><![CDATA[It&#8217;s 7pm in Austin Texas and I&#8217;m in a deserted lobby at South by Southwest with Nick Gonzalez from TechCrunch. Tomorrow is the day we&#8217;ve been building up to for ten months, the day we launch our product, Clickpass. I&#8217;m now demoing Clickpass to Nick who wants to review it for TechCrunch. Almost everyone has [...]]]></description>
			<content:encoded><![CDATA[<p>It&rsquo;s 7pm in Austin Texas and I&rsquo;m in a deserted lobby at South by Southwest with Nick Gonzalez from <a href="http://techcrunch.com">TechCrunch</a>. Tomorrow is the day we&rsquo;ve been building up to for ten months, the day we launch our product, Clickpass. I&rsquo;m now demoing Clickpass to Nick who wants to review it for TechCrunch.</p>
<p>Almost everyone has left the building and are either back in their hotels or at the Facebook party, but for some reason the wireless is still saturated and has almost slowed to a halt.</p>
<p><img src="http://thinkvitamin.com/images/articles/clickpass/austin-is-the-killer-app.jpg" /></p>
<p>On this grindingly slow network, our homepage hardly loads. When it finally does &mdash; in an irony not lost on either of us &mdash; Nick can&rsquo;t remember the password he created six months ago when he last tried Clickpass and has to try several times to get back in.</p>
<p>Clickpass was designed to make single-sign-on easy. Before someone starts using it, though, they need to connect it to their sites.</p>
<p>The connection process is not going well. It&rsquo;s been a while since Nick&rsquo;s used any of the sites we support and we cycle through yet more password attempts as we try to hook into them. We ï¬nally manage to connect up to one of them but, for no apparent reason, <a href="http://news.ycombinator.com">Hacker News</a> keeps failing. The demo part of the interview winds up and we get stuck into talking about the business instead. I&rsquo;m starting to feel decidedly nervous.</p>
<h3>Storm clouds gather</h3>
<p>Ten months earlier we left London, moved to Boston to join YCombinator and started work on Clickpass &mdash; which was back then called Remember Me. We ï¬rmly believed that OpenID was one of the most important things to happen to the web and that the core issue standing between a brilliant protocol and widespread adoption was its unintuitive usability.</p>
<p>At the time we started the work of evangelists like <a href="http://simonwillison.net/">Simon Willison</a>, <a href="http://www.davidrecordon.com/">David Recordon</a>, <a href="http://factoryjoe.com/blog/">Chris Messina</a> and <a href="http://kveton.com/blog/">Scott Kveton</a> have succeeded in making most of the technology community aware of the protocol, but there was still a lot of cynicism and doubt.</p>
<p>As 2008 began and Yahoo and Google both announced their support for OpenID, something began to change.</p>
<p>Earlier that day, the SXSW OpenID session had been standing room only. Despite being in a sizeable room, every seat was taken and people were being turned away at the door as others stood around the walls and down the aisle.</p>
<p><img src="http://thinkvitamin.com/images/articles/clickpass/data-portability-panel.jpg"  style="float:right;" />That afternoon in a panel-session on distributed social networks, someone in the audience stood up and asked how OpenID was going to become easier to use. Following a mention from <a href="http://adactio.com/">Jeremy Keith</a> (moderating) almost the entire panel complemented our about-to-launch product.</p>
<p>It was a huge room, with hundreds of people and I could hardly believe it as Leslie Chicoine from <a href="http://getsatisfaction.com/">GetSatisfaction</a> described Clickpass as the &ldquo;ï¬rst time that OpenID&rsquo;s actually made sense&rdquo;.</p>
<p>Back at the demo now with Nick, in the middle of what seemed to be brewing into a perfect tech-storm, but with our ship still side-on to the wind. We ï¬nish up the interview and Nick heads back to his hotel room to write up while I hop next door to use the wireless in the Hilton.</p>
<h3>Final tweaks</h3>
<p>As the night wore on, many of the problems started to fall away. It turned out that the fact we couldn&rsquo;t connect to Hacker News was indirectly because the site had, by complete coincidence, been TechCrunched that day.</p>
<p>The massive trafï¬c had revealed a registration bug that was slowing the login system to a standstill. Had it it not been TechCrunched, the same bug would have killed the Clickpass experience the day after. By 10pm though Paul Graham had posted that it was ï¬xed and the site was back to normal. Sometimes you just get lucky.</p>
<h3>March 11th &mdash; day of launch</h3>
<p>1am: Immad has crushed every bug we can ï¬nd, our four servers are all idling happily and I&rsquo;m about to head back to my hotel when I get an email from Nick saying that he&rsquo;s sent the piece to Mike Arrington, but that Mike wants to ask us some questions. Can I hang on to take a call?</p>
<p>2am: I&rsquo;ve just uploaded the company details to CrunchBase as requested when Mike Arrington calls. We talk for almost two hours about Clickpass, about the pains it&rsquo;s solving, about how it takes the confusion out of OpenID.</p>
<p><img src="http://thinkvitamin.com/images/articles/clickpass/vc-wear.gif" style="float:right;" />As an entrepreneur you spend a lot of your time explaining things to people who aren&rsquo;t always paying a lot of attention. However, Mike is 100% engaged throughout the full two hours and totally focused on understanding the product. I&rsquo;m impressed.</p>
<p>Mike hasn&rsquo;t used OpenID that much though and at the end of the interview he&rsquo;s still keen to publish the story but feels we need something more to explain our unique selling point.</p>
<p>He advises me to produce a screencast and hold back from the prescribed 9am embargo for a couple of hours until it&rsquo;s ready. We ï¬nish up and I leave him with an article from Marshall Kirkpatrick highlighting the difï¬culties around OpenID.</p>
<p>4:10am: I email Chris Messina and arrange to do a screencast with him the next morning. Chris is great at explaining these things and drawing out their signiï¬cance in a way that people get.</p>
<p>4:20am: Take a taxi back to the hotel.</p>
<p>5am: Bed.</p>
<h3>Launch morning</h3>
<p>8am: Get up and promptly ï¬eld a call from Joseph Smarr at Plaxo. With tens of millions of users, Plaxo are by far our biggest launch partner and the integration is yet to go live. Joseph&rsquo;s hit a couple of small bugs at our end and and works with Immad back in SF to iron them out. SF is two hours behind Austin so it&rsquo;s 6:30am over there and we&rsquo;ve still got a bit of time before the 9am PST publication embargo.</p>
<p>At this stage I&rsquo;m still expecting TechCrunch to hold the article until 11, when they get the screencast, and assume we&rsquo;ve probably got a couple of extra hours more on top.</p>
<p><img src="http://thinkvitamin.com/images/articles/clickpass/techcrunch-twitter.png" style="float:right;" />Joseph tells me that Techcrunch is twittering our imminent launch. After 10 months of designing, documenting and building it&rsquo;s hard to believe it&rsquo;s all really happening.</p>
<p>9:30am: <em>SXSW convention center</em> &mdash; I ï¬nd a table and start testing all of the partner sites making sure everything is doing what it should be doing. Immad is doing the same back in San Francisco. David our designer is producing a &ldquo;We&rsquo;ll be back soon&rdquo; page in case anything goes wrong.</p>
<p>Plaxo has pushed their code live and our little button is now on the bottom of their site. Nobody can see it until we drop our beta-cookie, but it&rsquo;s there, and ready to switch on for their 40M users.</p>
<p><a href="http://disqus.com/">Disqus.com</a> is looking good. Simon Willison&rsquo;s Django OpenID libraries are blazing fast and Hacker News is now back to normal loading time. Plaxo is as fast as ever.</p>
<p>10:30am: With everything looking good I start getting to grips with the screencast software and mail Chris to ï¬x up a place to meet.</p>
<p>11:25am: As I shut my Mac and go to do the screencast I happen to glance at TechCrunch. We&rsquo;re on. Top story. No comments. It seems Marshall&rsquo;s OpenID critique hit the spot. It&rsquo;s an incredible review &mdash; everything we could have hoped for. Fantastic, except that we didn&rsquo;t expect this for another two hours and the site&rsquo;s still behind a password!</p>
<p><img src="http://thinkvitamin.com/images/articles/clickpass/techcrunch-headline.png" /></p>
<p>11:25am 10s: I call San Francisco: &ldquo;Immad, we&rsquo;re live, TechCrunch just published the story &mdash; let&rsquo;s push!&rdquo;</p>
<p>11:25am and 30s: &lt;ping&gt; Aral Balkan twitters that he can&rsquo;t see the site &mdash; how do people ï¬nd these things out so quickly?!</p>
<p>11:26am: Immad, as fast as ever, IM&rsquo;s to say that everything&rsquo;s live. Clickpass is go.</p>
<p>11:37am: An email arrives kindly offering to sell me Clickpass.cn. Un. Believable. I start buying other countries.</p>
<p><img src="http://thinkvitamin.com/images/articles/clickpass/china-email.png" /></p>
<p>11:40am: Joseph publishes a <a href="http://blog.plaxo.com/archives/2008/03/plaxo_now_suppo.html">great post about us on the Plaxo blog</a>. I can&rsquo;t help feeling a ï¬‚ush of pride.</p>
<p>11:50am: 50 new registrations on the site. Congratulatory emails and twitters start coming in. We&rsquo;re the top story on Hacker News.</p>
<p><img src="http://thinkvitamin.com/images/articles/clickpass/site-traffic.png" style="float:right;" />2pm: 300 registrations. The trafï¬c is ramping up but thanks to Martin, our sys-admin, the servers don&rsquo;t even blink at the extra load.</p>
<p>2:40pm: I call Immad and David back in the ofï¬ce. Everyone is excited and so far, everything&rsquo;s holding strong. I tell the guys that there&rsquo;s a bottle of champagne waiting for them in the bottom of the fridge.</p>
<p>3pm: &lt;ping&gt; &mdash; twitters keep coming in. I didn&rsquo;t use Twitter much before SXSW but am amazed at what an incredible realtime snapshot it gives of the early-adopter web. Most are positive but a couple of people don&rsquo;t really get what we&rsquo;re doing. There&rsquo;s clearly still work to be done. </p>
<p><img src="http://thinkvitamin.com/images/articles/clickpass/bwana-clickpass.png" style="float:right;" /></p>
<p>3:30pm: An email comes in from one of our new users asking if they can join the company.</p>
<p>3:40pm: And another.</p>
<p>4pm: We make it onto Techmeme and one of our new users has already written a brilliant blog post about us.</p>
<p><img src="http://thinkvitamin.com/images/articles/clickpass/techmeme.jpg" style="float:right;" /></p>
<p>5pm: 600 registrations. The adrenaline is starting to wear off and I suddenly feel exhausted. Draft an email to investors to bring them up to speed and realise that we haven&rsquo;t even emailed our pre-launch list to tell them we&rsquo;re live yet.</p>
<h3>Lock-down</h3>
<p>5:30pm: We haven&rsquo;t set up our email marketing software yet so after writing up an email of the day&rsquo;s events, I check, double-check and check again that I&rsquo;ve put 1000 email addresses into the BCC and not the CC ï¬eld on GMail.</p>
<p>GMail won&rsquo;t take 1,000 emails at a time so I split them down into chunks. First chunk &mdash; okay. Second chunk &mdash; okay.</p>
<p>Write an email to another friend thanking them for their support. Send.</p>
<p>&ldquo;GMail has detected an unusually high volume of mails being sent from this account. Access to your account will be frozen for the next 24 hours&rdquo;. Bugger.</p>
<p>5:40pm: Phone a friend at Google. Fingers crossed.</p>
<p>6:10:pm: Hurrah &mdash; email back on. Silicon Valley is crazy-connected.</p>
<p>6:30pm: All of my electronics are about to die. MacBook is ï¬‚at and hard-disk is starting to make strange, not-good, marble-on-a-stone-ï¬‚oor sounds and won&rsquo;t sleep. iPhone has enough juice left to take a call from Joseph suggesting dinner. I catch up with him and John McCrea and we dissect the day&rsquo;s events over Guinness and burgers. It&rsquo;s a great evening and when they head back to their hotels I peal off to join the obscenely long queue for the Digg party.</p>
<p>10pm: Immad calls and we review everything. We&rsquo;ve got a couple of glitches in some of the ancillary features but the whole core has been as solid as a rock. He&rsquo;s an incredible developer and together with David&rsquo;s design skills the product hasn&rsquo;t just pleased us but also, it seems, our users too. We&rsquo;re on track to hit 1,000 registrations in the ï¬rst 24 hours and loads of people are installing the WordPress plugin. We agree it was a good day.</p>
<h3>The next fortnight</h3>
<p>The ï¬rst couple of weeks have been a bit of a blur of emails, investor meetings and bug ï¬xes. They&rsquo;ve also revealed a ton of work still to do. The concept of password-less single sign-on is totally alien to most people and Clickpass doesn&rsquo;t yet do enough to explain things.</p>
<p>We did a lot of work to make sure we didn&rsquo;t contradict the decentralised ideals of OpenID and that people can still use their existing OpenID&rsquo;s with us. Even so, feedback and reviews have highlighted that there are still things left we can to do to make it easier still for those who want to use pure OpenID.</p>
<p>Making OpenID easier is our raison d&rsquo;etre. I&rsquo;m pleased with just how much we&rsquo;ve done for users but we&rsquo;ve now got to turn our efforts to developers. Installing OpenID isn&rsquo;t too difï¬cult but it&rsquo;s intimidating and we need to change that. Over the coming weeks and months we&rsquo;re going to be releasing both libraries and plugins that should start to help a lot.</p>
<h3>Live on new sites &mdash; Ma.gnolia</h3>
<p><a href="http://ma.gnolia.com/"><img src="http://thinkvitamin.com/images/articles/clickpass/magnolia.gif" style="float:right;" /></a>We&rsquo;ve also got more sites coming online and at the same time as this article is published, so is our integration with <a href="http://ma.gnolia.com/">Ma.gnolia</a>.</p>
<p>If you&rsquo;ve not tried Ma.gnolia before it&rsquo;s a beautifully designed social-bookmarking site which, like Plaxo, has also always been on the cutting edge of OpenID.</p>
<p>We&rsquo;re really pleased that people are going to be able to use their Clickpass with it.</p>
<h3>Celebrating the victories</h3>
<p>There&rsquo;s an undeniable cult around internet startups and a generous helping of hype. As with any other project, 99.8% of the time is spent coding, designing, documenting, answering support and making sure the ï¬nances stay sound.</p>
<p>When the exciting times do come though, they come thick and fast and are exhilarating and nerve-racking all at the same time. Launch was exactly like that for us and a day I won&rsquo;t be forgetting anytime soon.</p>
<p><strong>Image credits:</strong></p>
<p>Austin is the killer app: Scott Beale/Laughing Squid: <a href="http://www.laughingsquid.com">laughingsquid.com</a> <br />
Data Portabilty Panel: Ian Kennedy: <a href="http://everwas.com/">everwas.com/</a> <br />
Blackberry:1  Entrepreneur: 0 : <a href="http://vcwear.com">VCWear.com</a></p>
<p><script src="http://digg.com/tools/diggthis.js" type="text/javascript"></script></p>
]]></content:encoded>
			<wfw:commentRss>http://thinkvitamin.com/uncategorized/the-thrill-of-launch/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>How will OpenID change your site?</title>
		<link>http://thinkvitamin.com/code/how-will-openid-change-your-site/</link>
		<comments>http://thinkvitamin.com/code/how-will-openid-change-your-site/#comments</comments>
		<pubDate>Tue, 06 Nov 2007 09:00:08 +0000</pubDate>
		<dc:creator>Peter Nixey</dc:creator>
				<category><![CDATA[Code]]></category>

		<guid isPermaLink="false">http://www.thinkvitamin.com/features/webapps/how-will-openid-change-your-site</guid>
		<description><![CDATA[After three months away in San Francisco I was recently back in London visiting friends and family. With a couple of weeks to spare I got stuck into booking dinners with old friends. I&#8217;m a big fan of the offers on Top Table and with my eye on a nice little brasserie in Hampstead I [...]]]></description>
			<content:encoded><![CDATA[<p>After three months away in San Francisco I was recently back in London visiting friends and family. With a couple of weeks to spare I got stuck into booking dinners with old friends. I&#8217;m a big fan of the offers on <a href="http://www.toptable.co.uk">Top Table</a> and with my eye on a nice little brasserie in Hampstead I knew I had enough points to get one of my meals on the trip for free.</p>
<p>Or at least I thought I did, only after so many months away, I&#8217;d forgotten my password to get back in. Not only that but I&#8217;d registered with an old email address and couldn&#8217;t even get the password reminder. For the want of a password, me, my page views and my commission were lost.</p>
<p>Usernames and passwords are everywhere. In a web that&#8217;s becoming more and more specialized and mashed, where storage comes en-masse from Amazon, video from YouTube, maps from Google, presence from MyBlogLog and sharing from <a href="http://del.icio.us">del.icio.us</a>, one last feature remains awkward and local: login.</p>
<h3>The cost of sign-up</h3>
<p>Sign-up: one simple and ubiquitous feature that costs websites users, lots of users. France Telecom recently did extensive research on the subject and found that at every new screen presented during sign up, 50% of users give up and go elsewhere.</p>
<p>That makes sign-up screens a very expensive part of your website. So you&#8217;ve built an incredible new service and spent a fortune advertising it on Google to get maybe a thousand clickthroughs. Of those, perhaps a hundred will be impressed enough with your service to reach that critical sign up screen. Ask the user for a username and password, confirm their email and you&#8217;ve just lost 75 of them.</p>
<p>The simple act of sign-up just multiplied your customer acquisition cost by a factor of four. Getting rid of the process would make your advertising a staggering four times more effective.</p>
<p>Even once the user has finally signed-up the login screen will continue to haunt both them and you. Up to 80% of calls to help desks are from users requesting password resets and every one costs an average of $30 to process.</p>
<p>The pain of sign up and login is both extensive and expensive. In the last two years though, a protocol has emerged to address it, a protocol which shows the early glimmers of even being able to solve it: OpenID.</p>
<h3>OpenID, the HTML of identity</h3>
<p>In 1990, Tim Berners Lee made the enormous simplification that most information people needed to access could be encoded into plain old HTML. “Information” is as broad a category of data as you can get though and can be encoded in lots of different formats: xml, pdf, jpg and plaintext being just some of them. In making that one extreme simplification though, Tim Berners Lee nailed the core of the problem and laid the foundations for the depth and complexity of the web that exists today.</p>
<p>Two years ago, Brad Fitzpatrick of Six Apart made the same simplification for identity. Identity is a complex and amorphous beast. Who are you, what qualifications do you have, who can verify them and how can I trust them? What&#8217;s your reputation, who are your friends and are you really my second cousin once removed?</p>
<p>These are very difficult questions to structure and answer programatically and, like document encoding, too difficult to solve in one fell swoop. Brad proposed a solution to a different and far simpler question — are you the same user who was at my site last week?</p>
<h3>Remember me … forever</h3>
<p>At its core, all OpenID cares about is telling a website that you&#8217;re the same person, the same user you were last time you visited them. It&#8217;s a bit like a cookie you carry around with you and drop into any machine you&#8217;re using — “remember me forever”. OpenID gives you, the website owner, the opportunity to personalize and customize your content to more users more of the time.</p>
<h3>How it works</h3>
<p>In essence, OpenID allows one website to piggy-back off an authenticated session from another website. I log into my OpenID provider (e.g. <a href="http://www.clickpass.com">Clickpass.com</a>, the startup I founded), pick up my OpenID URL and create a session there. When I want to use another site (e.g. 37 Signals&#8217; <a href="http://www.basecamphq.com/">Basecamp</a>), instead of giving them my username and password, I give them my OpenID URL.</p>
<p>Basecamp then has a quick word with Clickpass and asks whether I&#8217;ve got an authenticated session already set up. If I have, it logs me in to Basecamp and creates a new authenticated session for itself and if not, it sends me back to Clickpass to log in.</p>
<h3>The WWW cloakroom attendant</h3>
<p>You can imagine OpenID to be a little like the tickets a cloakroom attendant uses. When you leave your coat in the cloakroom of a nightclub they tear a ticket out of their book, pin one half to the coat and give the other half to you. When you want your coat back you give them your half of the ticket, they find the coat that matches it and give it back to you.</p>
<p>OpenID does exactly the same thing with a website. You go to a website, and give them a copy of your OpenID URL which they then pin to your account. Next time you come back, you flash them your OpenID, they look up the account that corresponds to it, do a quick check to make sure you really are the owner and then let you in.</p>
<h3>Your user or mine?</h3>
<p>So if OpenID is logging the user into your site then who exactly owns them? Is that user ultimately a user of the OpenID provider or the website itself.</p>
<p>A good place to look for the answer to this is <a href="http://evite.com">Evite.com</a>. One of the reasons Evite became so successful is that it didn&#8217;t require people to create accounts in order to see their invitations. Clicking on a personalized link sent to you in an Evite email is proof that you own the email address and logs you directly into Evite.</p>
<p>Evite piggy-backs off the authentication from your email account. Nonetheless, it&#8217;s clear that it is Evite, rather than Hotmail or GMail, that owns the user. In the same way as Evite piggy backs off email, OpenID lets you to piggy back off the OpenID provider&#8217;s session and at the same time retain ownership of your user. The data that they enter at your site is something that is between you and them and nothing to do with the OpenID provider.</p>
<h3>The possibilities</h3>
<p>The consequences of reducing the barrier to account creation and login at websites are hard to understate. Users&#8217; resistance to signing up to your service falls, the number of users returning to it increases and the amount of time you have to spend reminding them how to do so plummets.</p>
<p>With one account logging them into so many places, the user can also now afford to bring more than just a new username and password to your site and you can afford to demand more. At the same time as lowering the barrier to legitimate users, OpenID raises the barrier to your unwanted visitors.</p>
<p>People are exhausted by having to prove themselves again and again to every new site they visit. OpenID opens the door to portable identity and to them accumulating reputation and credibility which can then be reused elsewhere just as they reuse their EBay reputation on auctions. Portable identity and credibility is, in turn, the key to demanding more proof from your visitors that they are who they say they are and in turn reducing chargebacks, fraud and spam.</p>
<h3>One ring to bind them all … and lose them?</h3>
<p>With one account to store everything in, many people&#8217;s first reaction is that they now have one place from which to lose everything. Crack your OpenID provider and you crack every other site. Being able to get into all sites using one password is undeniably attractive but is it worth it if it lets someone else in too?</p>
<h3>Today&#8217;s access-all-areas: email</h3>
<p>The irony is that we already face the threat of the latter without any of the convenience of the former. Ever forgotten your password? How did you get it back? Did you perhaps click the password reminder button?</p>
<p>Almost every account you have across the web can be accessed using your email account. As soon as someone has your email account they have the key to your other accounts.</p>
<p>Since over a third of users use the same username and password everywhere, the problem is actually far worse than this as they inadvertently grant access to their email account to each new service they sign up to. I ask for your username, password and email address when you sign up to WinAnotherIPod.com and you give me the same one you use for your email provider and Paypal.</p>
<p>Today&#8217;s user has all of the risks associated with a centralized login and none of the benefits.</p>
<h3>OpenID and phishing</h3>
<p>Just like Paypal and Google Checkout, OpenID is a protocol vulnerable to phishing attacks. Click on a subversive Google Checkout link, enter your Google login details onto a phisher&#8217;s website and you&#8217;ve given away your Google account and payment details. Click on a Paypal button that connects to a bogus storefront and you accidentally give away your Paypal username and password.</p>
<p>OpenID can be attacked in exactly the same way. Arrive at an OpenID enabled website without being logged in and you&#8217;ll be redirected to your OpenID provider to do so. Don&#8217;t look too carefully at the URL of that login page and you might accidentally find you&#8217;ve given your details to someone you didn&#8217;t mean to.</p>
<p>There are various ways of making it far more difficult for this to happen and some that make it almost impossible. At their best, OpenID services like Clickpass.com make a user far more secure than they are using conventional logins and do so across all the sites the user visits.</p>
<h3>Make yourself small</h3>
<p>The last point is very important because when it comes to being attacked, it&#8217;s always easier to defend a smaller area than a larger one. If spiders and aliens are descending on you in a computer game (or indeed in real life) you get your back against the wall. Leave the keys to your house under every pot in the garden and they&#8217;re more likely to be found than if you leave them under just one.</p>
<p>Web users today defend their security and their privacy on lots of fronts simultaneously. For people who use the same password everywhere, every new account is a new place for it to be compromised, every new place you enter your details is another place they can be stolen from.</p>
<p>With only one account to log themselves into, user can afford to be more careful about how they do it They can use email authentication, SMS confirmations and even RSA key-fobs to secure that OpenID account and, by association, every other account that it links to. The power of single sign on means that the heightened level of authentication can now be re-used and re-demanded across the user&#8217;s entire network of sites.</p>
<h3>So where is it?</h3>
<p>It would seem like OpenID is the the wonder-drug of the internet. With the power to decrease password reset requests, spam and fraud and the ability to increase conversion rates, user loyalty and security it seems almost too good to be true. Today unfortunately it still is.</p>
<p>OpenID is fully functional but still raw and too tricky for the average internet user to be able to understand. Even as I write though there is change afoot. Various startups and initiatives, including the OpenID specs themselves, are filling in the gaps and rounding off the corners.</p>
<p>The user experience isn&#8217;t yet finally complete but with people like <a href="https://pip.verisignlabs.com/">Verisign</a> and our team at <a href="http://www.clickpass.com">Clickpass</a> working on solving the remaining parts of the puzzle, the future for OpenID looks very, very promising.</p>
<p><script src="http://digg.com/tools/diggthis.js" type="text/javascript"></script></p>
]]></content:encoded>
			<wfw:commentRss>http://thinkvitamin.com/code/how-will-openid-change-your-site/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Review: Fluxiom</title>
		<link>http://thinkvitamin.com/uncategorized/fluxiom/</link>
		<comments>http://thinkvitamin.com/uncategorized/fluxiom/#comments</comments>
		<pubDate>Wed, 12 Apr 2006 05:15:00 +0000</pubDate>
		<dc:creator>Peter Nixey</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.thinkvitamin.com/reviews/webapps/fluxiom/</guid>
		<description><![CDATA[<a href="http://www.fluxiom.com">Fluxiom</a> is a next generation digital asset manager. We put it through it's paces to see if it's worthy of all the pre-launch press.]]></description>
			<content:encoded><![CDATA[<p>Fluxiom is one of those web apps you seem to keep bumping into. It was first glimpsed back in November when the demo trailer was released and put up on <a href="http://www.digg.com">Digg</a>. Humming with a slinky jazz soundtrack and oozing shiny surfaces and fade effects, the two-minute teaser did everything to get our juices flowing so, when the possibility of an account dropped through our door we were happy to test it out.</p>
<p><img alt="Screenshot of Fluxiom interface" title="Screenshot of Fluxiom interface" src="http://www.thinkvitamin.com/images/articles/reviews/fluxiom/fluxiom-interface.jpg" /></p>
<h3>What is it used for?</h3>
<p>Fluxiom is a digital asset manager. So if you&#8217;re working from home, from the office, or in collaboration with a team, you&#8217;ll probably find a use for it. If you find yourself emailing documents here there and everywhere in a bid to stay up-to-date, then you&#8217;re sure to find Fluxiom useful.  Simply upload the files, fire up your web-browser and they&#8217;ll follow you from machine to machine like a lovesick puppy.</p>
<h3>The User Interface</h3>
<p>The user interface is mouth-wateringly pretty. Once logged on, it&#8217;s hard to pay attention to anything other than just how utterly gorgeous the UI is. It&#8217;s universally adored wherever it goes too. At a sneak preview  back in December there were actually gasps when it first went up on screen.</p>
<p>Tagging, uploading, downloading and sharing are only a slide-out-panel away and both fast and easy to use. Users and permissions are managed on a separate screen and asset previews are displayed in a scalable popup window.</p>
<p><img alt="Screenshot of Fluxiom's User Management screen" title="Screenshot of Fluxiom's User Management screen" src="http://www.thinkvitamin.com/images/articles/reviews/fluxiom/fluxiom-user-screen.jpg" /></p>
<h3>Technical analysis</h3>
<p>Cross-browser performance is very impressive. Much of Fluxiom is built on <a href="http://script.aculo.us">Script.aculo.us</a> which itself is built on <a href="http://www.prototypejs.org/">Prototype</a> and the different frameworks really deliver.</p>
<p>We tested Fluxiom on IE6, Firefox 1.07 &#8211; Windows/Mac and on Safari and found no perceivable difference in look or performance across any of them. Anyone worrying about a Mac-bias has nothing to fear.</p>
<p>Download times are quick and initial startup takes about 5-10 seconds across a 500k connection. Memory usage is pretty much the same as other web apps. On our XP machine, Firefox 1.07 ticks over on about 21Mb of RAM and goes up to 35Mb after loading Fluxiom. GMail by comparison works at 32Mb.</p>
<p>The layout is clear and uncluttered although  the fonts seem  too small, making it difficult to read the text. Increasing the text size in Firefox didn&#8217;t seem to do much to rectify this.</p>
<p>The app will unpack a zip file upload although you can burn quite a lot of server time during the process. Full text search through Word documents, Excel files and PDF&#8217;s is also very impressive and worked quickly on the few files tested.</p>
<h3>The Features</h3>
<h4>Uploading and Downloading</h4>
<p><img alt="Screenshot of Fluxiom's upload window" title="Screenshot of Fluxiom's upload window" src="http://www.thinkvitamin.com/images/articles/reviews/fluxiom/fluxiom-upload-screen.jpg" /></p>
<p>It&#8217;s a bit frustrating that you can only upload one file at a time. In order for Fluxiom to really fly, it&#8217;ll need some sort of drag-and-drop uploader tool. Also, we couldn&#8217;t figure out how to use the Tags functionality. This is either because it&#8217;s in Beta (and not finished), or because it&#8217;s not intuitive &#8211; it&#8217;s hard to tell at this stage. However, once you start your upload, the progress bar is quite handy.</p>
<p><img alt="Screenshot of Fluxiom's uploader bar" title="Screenshot of Fluxiom's uploader bar" src="http://www.thinkvitamin.com/images/articles/reviews/fluxiom/fluxiom-upload-screen2.jpg" /></p>
<p>Downloading is very simple. All you have to do is select the files you&#8217;d like to download, and click &#8220;Download&#8221;. If you select more than one file, it zips them up into one file for download.</p>
<h4>Drag Selection</h4>
<p>This is by far one of the most amazing usability features that Fluxiom has to offer. If you want to select multiple files, you simple click and drag, as you would on your desktop. We&#8217;ve never seen this on a web app before, and it is quite an achievement.</p>
<p><img alt="Screengrab of Fluxiom's drag-and-select feature" title="Screengrab of Fluxiom's drag-and-select feature" src="http://www.thinkvitamin.com/images/articles/reviews/fluxiom/fluxiom-drag-select.jpg" /></p>
<h4>Sharing</h4>
<p>Fluxiom makes it really easy to share your digital assets with others. All you have to do is select the files you want to share, click &#8220;Share&#8221;, type in an email address and choose from three options:</p>
<ol>
<li>Send link &#8211; Send a password and a link to download a .zip archive of the assets</li>
<li>Send attachments &#8211; Send an email with the assets as file attachments</li>
<li>Use my email client &#8211; Open a new email in my local email app with a password and a download link</li>
</ol>
<p><img alt="Screenshot of Fluxiom's sharing capability" title="Screenshot of Fluxiom's sharing capability" src="http://www.thinkvitamin.com/images/articles/reviews/fluxiom/fluxiom-share.jpg" /></p>
<h4>RSS Feed</h4>
<p>Fluxiom allows you to subscribe to a global RSS feed for your digital assets. Whenever someone adds a file, your RSS feed gets updated. This is super useful, but we think this feature would be much better if the RSS posts included a URL to download the file.</p>
<p><img alt="Screenshot of Fluxiom RSS feed" title="Screenshot of Fluxiom RSS feed" src="http://www.thinkvitamin.com/images/articles/reviews/fluxiom/fluxiom-rss.jpg" /></p>
<h4>Previewing Assets</h4>
<p>Fluxiom has a nice feature for looking at your image files. Simply select the file, and click &#8220;Preview&#8221;. It opens up a new window with the file displayed, and some brief file info. The coolest thing about this feature is that you can resize the window and it dynamically resizes the image, to fit inside the window &#8211; nice touch.</p>
<p><img alt="Screenshot of Fluxiom's Preview function" title="Screenshot of Fluxiom's Preview function" src="http://www.thinkvitamin.com/images/articles/reviews/fluxiom/fluxiom-preview.jpg" /></p>
<h3>The Highlights</h3>
<p>Judged against traditional web-applications, Fluxiom is very fast.. There is almost never any page refreshing and despite actions feeling occasionally sluggish, they are nonetheless lightning fast compared to a page refresh.</p>
<p>The use of AJAX in Fluxiom is a real bonus &#8211; not so much because it makes it quicker  (which it does) but because it makes the experience much more pleasant. With critical functionality only a slide-out away it is far easier to get things done than in traditional cluttered web pages.</p>
<p>Traditional apps often cram so much into a page that it&#8217;s  hard to think, let alone work. Fluxiom uses AJAX brilliantly to keep such tools discretely stowed until the moment they&#8217;re required.</p>
<h3>The Lowlights</h3>
<p>Although the UI is always intuitive, it can be a little confusing on the  functionality side of things.  The filtering buttons are unhelpful and often	make you unsure of exactly what you&#8217;ve done at any given time.</p>
<p>The steps required to tag an asset are easy but not obvious and  the drag and drop addition of editing privileges to users is unintuitive and somewhat gratuitous.</p>
<p>The asset window  needs occasional refreshing, however,  it&#8217;s not clear when you should do this. This is something that you&#8217;d  expect to be automatic rather than user-driven.</p>
<h3>Conclusions</h3>
<p>The true test of any application is how well  it does the job. How much easier does it make your work? Someone using the software long term can only really give the answers and on a day-to-day basis as this is where Fluxiom will come into its own.</p>
<p>As a web application in its own right though, Fluxiom is a knockout. It works across all the major browsers, is responsive, incredibly pretty and leagues ahead of traditional form-driven interfaces.</p>
<p>Pitted against other web apps, Fluxiom is a real winner. It occasionally suffers from being slightly difficult to use, in some respects, but far less so than any other web app. At the end of the day, its speed and beauty far outweigh any of the niggles.</p>
<h3>Rating</h3>
<ul class="item vcard">
<li>Software name: <a href="http://www.fluxiom.com" class="url fn">Fluxiom</a></li>
<li>Maker: <a href="http://www.wollzelle.com" class="org">Wollzelle</a></li>
<li>Price: Starts at 9 Euros per month</li>
<li>Rating: <span class="rating">4</span> out of 5</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://thinkvitamin.com/uncategorized/fluxiom/feed/</wfw:commentRss>
		<slash:comments>45</slash:comments>
		</item>
	</channel>
</rss>

<!-- Dynamic page generated in 0.503 seconds. -->
<!-- Cached page generated by WP-Super-Cache on 2012-02-11 16:32:18 -->

