Security and priorities!

I was visiting a web page of some invoicing / time tracking web-app and saw this text in their FAQ:

“In the very unlikely event of a security incident, we’d be in more peril of someone duplicating our application and attempting to resell it than you losing your data or someone stealing your identity.”

Eeeee… wrong answer!! Totally!!!

Well, the service seems very solid otherwise so maybe it’s just a case of not well thought out PR.

Security is a very complex subject..
You can never simply cover all the corners and go to sleep. There are no absolutes. Linear/feed forward thinking of do/pay more/better to get more in not very effective. It’s about being smart, creating a system that will by design minimize certain problems (better than other problems).

So although you really want none of security issues to happen, you must get a very clear priority of things you want to prevent.

At cebelca.biz which is a local small business application the priorities are (from most important to least, number is the level of importance from 100 to 0):

    100
    A hacker gets to data of our users.
    95
    A hacker destroys the data of our users.
    35
    A hacker for noticeable period disables our service.
    20
    A hacker gets the source code of our application.

To me, our users data is of top priority, they trusted us with their data. And our source code… meh… capable developers want to code and design their solutions according to their ideas, not copy someone else’s stuff and get a outdated copy of something that already exists.

Reblog this post [with Zemanta]
Posted in cebelca.biz, security | Tagged , , , | 1 Comment

Usability 101: Give ME MY data!

Few months ago I saw the tweet from @gandalfar

Gandalfar on Magnolia

My understanding was that Ma.gnolia is a bookmarking service (like del.icio.us), they lost all the data and so Gandalfar lost all the bookmarks he was saving into it for years(?). The whole thing is extremely absurd because the only functionality of bookmarking services is to remember what you save to them, and they lost it all…

When I saw that, I got an simple idea. I liked it and was determined to try it at the first chance I get:

The whole fiasco with Magnolia would not happen, if the service would send emails with attachment to all their users weekly. Attachment would hold a gzipped file with all user’s data in some general format. So even if service goes to hell the users still have their data.

In such case user could re-import data into the original service or simple tools could be made that would import data into other similar services or transform it to general file with format of their liking.

The important thing being: User would have his data and a choice to do with it whatever he wants!

With this you effectively create another backup system for your service. The one that is not in any way centralized and works on the level of peers / users.

I will use this technique with cebelca.biz , a very lightweight business web-application that we are finishing. The data dumps will also be encrypted with user’s passwords in this case.

Reblog this post [with Zemanta]
Posted in Uncategorized | 12 Comments

Kratek prikaz Čebelce.biz

To je surov, neobdelan zaslonski video (screencast), ki prikazuje delovanje našega spletnega programa Čebelca.biz. Čebelca.biz je še popolnoma v delu. Zvok je nekoliko pretih zato si povečajte glasnost, če želite kaj slišati.

Cebelca.biz

Kliknite za ogled videa »

Zelo hvaležni smo 5 “beta” preizkuševalcem in 1 preizkuševalcu za uporabniško izkušnjo, ki so nas zasipali s povratnimi informacijami. Naša naslednja naloga je sprocesirati vse vaše povratne informacije in iz njih narediti naslednjo verzijo. Hvala!

Posted in Company, cebelca.biz, our products | Tagged , | 1 Comment

Site Assistant updated to 0.42

Another bigger update was posted online yesterday. Changes are:

Composable detailed view
There is and will be more and more information in details so “all at once” model can’t work well any more. I really like select/compose functionality of menu we came up with.
Hide the rest function:
We show all information on one page so you can compare things without switching, but after you extend few details the rest of domains might stand in your way, Hide the rest solves this.
A touch of history :
Core for historic view and changes of site parameter is in it’s place now. It shows only on external data details now but this is just a start.
Filters:
Besides views that show certain group of data of currently selected websites we have filters now. Filters determine which websites to show and in what order. Example is Expiring domains. More filters will be added.
Screen captures:
A new capture bot was added to the system. Currently it captures the website screen shots. We figured this will be to beneficial to give general overview of the situation on the websites for users that have man of them.

site assistant

All changes were core changes. We implemented them carefully and lightly, only doing the minimal partial representation of them. We want them to sink into our minds with usage and give us more complete idea how to do the whole interface without screwing it all up.

Reblog this post [with Zemanta]
Posted in our products, site-assistant | Tagged , , | Leave a comment

Introducing QwikiTXT

QwikiTXT is a mini project we released lately. You can read about the “why” here. It’s an online notepad, which you can use immediately, without the need to sign up or anything.

You can use it to collaborate with others on a text or note something down for yourself. Besides that QwikiTXT has two special features, it remembers 10 previous versions of the text and it can visually show the changes between the versions. Both of these features are generally nice to have, but come specially handy when collaboration on text with others.

Here is a simple screen cast to quickly show the QwikiTXT work flow:

Posted in Uncategorized | Leave a comment

Site Assistant Update to 0.4

We finalized an update that prepares more information about your websites at Site Assistant. Here are the changes:

Whois info

  • Added support for .si .fr .eu domains to the .com .net .org .biz .info .us that were there before

External sources info

  • Added number of links to your website in DMOZ directory (and link for details)
  • Added number of links to your website in Yahoo directory (and link for details)
  • Added information if your website is flagged as suspicious by Google Safe Browsing diagnostics

Front page info

  • Added detection of ads from Toboads/Httpool and ADPartner

Front page security and functionality warnings
This group of information is more technical and is just at it’s infancy. Remember, this is the Beta.

  • Added listing of external links (href-s). This can also be helpful at checking if your website got hacked
  • Added listing of external inclusions (src-s). This can also be helpful at checking if your website got hacked
  • Added so far called “Hacking hotspots”. A listing of html/javascript code that could mean that your website got hacked. And can also mean perfectly normal code, as long as you know who put it there and what it’s doing. We detect common patterns of hacking here, javascript keywords often used at hacking attacks, suspicious words, extensions…
  • Added so far called “Error hotspots”. Detection if your website is possible throwing an error.

Smaller incremental updates

There was also a lot of smaller incremental updates and improvements that I won’t list here (and happen all the time).

We want to know what you think

We are very grateful to our beta testers for all the feedback they are giving us. If something is itching you about Site Assistant, let us know! That’s what beta stage is all about.

Reblog this post [with Zemanta]
Posted in Company | Tagged , , | Leave a comment

Introducing Site Assistant

Site Assistant is a website management service for web-masters, web-studios and website owners that need to manage multiple websites. It saves your time by continuously checking, collecting and processing information that will help you do your job better, and save your time.

www.site-assistant.com

Few examples of what site assistant does:

- It checks your web-site’s front page and displays most important information to you (like Title, Meta tags, Pageload time, Advertisements on the page, Statistics you use)

- It checks your domains who-is record and show systematic information about it like (Date of expiration, Last update, Registrar, Age of domain…)

- It checks external sources (like Google, Yahoo, DMOZ, Alexa..) and reports you number summary of relevant information (like indexed pages, back-links, page rank, Alexa position, google safe-browsing warnings…) and links to pages with detailed view

- It lists external links and external sources on your website front page, it warns about known patterns of hacking attempts, spam related words, errors…

- A simple to use notebook to write down tasks, ideas or messages for others on per website basis.

Site Assistant Screenshot

Public beta offer

Site Assistant is currently in public beta and if you sign up you get to manage up to 30 websites for 1 year for free of charge.

Posted in Uncategorized | Tagged , , | Leave a comment

A bit of history

It’s not my intention to bore you with any “once in a faraway land..” stories, but I thought that explaining a bit of the past and our current situation, will give us all some ground, from which we can better push forward.

We as a company exist for four years now. All this time was devoted to programming. We worked on various contract jobs ranging from desktop applications, games to web applications.  Our own products that you see on the front page are mostly smaller side-projects that we did in this time. To test some ideas and scratch few creative itches.

In the middle of last year we slowly started moving from contract programming to seriously building our own products — which was our goal from the start. We focused on 3 different projects and all 3 are now gradually reaching state of first public releases.

Already in testing stage by real users is Site Assistant, which is an online service of tools for webmasters, web-studios and anyone who needs to manage bigger number of websites/domains.

The second, currently named BizyBee is also reaching that stage. It is a lightweight business application, more about it soon.

The third is a search engine for slovene classifieds  Oglasko.com . Because ad revenues are a little bleak in our country, especially at this time — Oglasko has a little lower priority than the first two.

Posted in Company | Tagged , , | Leave a comment

Hello world!

Hi, and welcome to our blog.

I hope you will find our posts interesting.  Let’s get started and see what happens.

Janko

Posted in Uncategorized | Tagged | Leave a comment