Monday, March 14, 2011

Privacy and Security: if it’s your app, then it’s your @$$

This is the first of a continuing series to help smartphone app developers make more informed design, development, and policy decisions. The objective is to raise material issues, options, and risks specific to mobile app development (but not to give legal advice).

Specific topics to come include;

  • PII: what definitions are out there and which ones can you not afford to ignore?
  • Opt-in Opt-out: what should your defaults be? How often must you ask? Do you need separate opt-ins per app? Per app version? For regular use AND exception reporting?
  • Data retention and reuse: do you own your own data? Do you need to care about partner data policies or only your own?
  • App hardening: what risks stem from app reverse engineering and/or tampering? How do you know if you should care?
This first entry will delve into the broader motivations behind this series and call out aspects of the mobile app development experience that set it apart from other platforms and markets.

It’s impossible to guarantee that an app will never do harm

Evolving technologies, emerging and divergent regulations, and evolving social and ethical mores have made it is simply impossible to define a concise, bullet-proof set of policies and development patterns that are guaranteed to do no harm to either user or developer. Effective risk management must, by necessity, be a practice governed, to a significant degree, by subjective guidelines.

When god wants to punish you, He answers your prayers

It’s no secret; the convergence of technical, social, economic, and market forces that we call “the smartphone” is a mega-opportunity for those who “get it right.” And what’s greasing the skids speeding this disruptive force of change? Apps of course. Apps are on the front-line hooking consumers and driving the smartphone revolution – pretty cool right? Most definitely.

Swimming in deep waters is always cool, but sometimes it can be deadly too.

The most powerful corporations, the smartest entrepreneurs, and the crème de la crème of investors are racing to meet exploding smartphone demand. And when that much money, information, and power are on the move, criminals (of all kinds), lawyers, regulators, law enforcement, and all genus of government will be right there with us.

These are deep waters indeed.

To serve an app: Is it a cookbook?
Do app developers need to care about this stuff? Consider that when a developer ships their first phone app, they will most likely have already entered into as many as five different (and almost certainly contradictory) binding legal agreements that include assignments of personal liability tied to the developer’s privacy policy and their app’s security. Each tool supplier, marketplace owner, platform provider, ad-server provider, and (last but not least) user demands this assurance.

As an app moves across platforms and international borders, the developer’s legal obligations multiply and, as such, so does their material risk.

To be clear, there is nothing inherently wrong or unreasonable here; but it IS unprecedented.


The list of potential concerns grows considerably when one stops to consider ethical considerations (what’s the right thing to do versus the legal thing) on one hand, and the technical/development security requirements on the other.

In order for a developer to ensure that both their users’ and their own interests are being addressed, application design and development priorities must account for operational and contractual requirements (in addition to market-driven feature functionality of course.)

What level of due diligence and development investment is appropriate?

The diversity of the interested parties and the number of governing agreements all covering essentially the same act (running a single app on a phone) make it especially important that the developer understand:
  • Definitions: For example, do all parties use the same definition for PII (personally identifiable information) and do they use it consistently (when defining the developer’s obligations versus their own)?
  • Obligations: For example, are you agreeing (and indemnifying the other party) to adhere to multi-national regulations – many of which you will have no knowledge of?
  • Rights and privileges: For example, what usage and commercial rights to application usage, user behavior, and other data are conveyed? Are these subject to change?
  • Notifications: Under what conditions, through what channels, and in what timeframes must which information be communicated? Does the developer have different special obligations?
Knowledge management versus risk management
Most people divide the world into things they know and things they don’t and then try to manage their risk within that “circle of knowledge.”



Knowledge management is not risk management and often misses a danger-zone where risk most often hides; in “the things we don’t know that we don’t know” and “the things we think we know, but we don’t.”


If you “don’t know you don’t know”, then you miss the chance to educate yourself or ask for expert advice.

Similarly, if you think you know something, but you’re wrong, you may find yourself exposed or missing an opportunity.

The single-minded objective of this series will be to shrink the “danger zone” for mobile app developers; to make sure that you don’t get bitten by security, regulatory, or social gotcha’s that you didn’t even know were out there.

The take away from today’s installment is a very simple one; if it’s your app that gets jammed up – rest assured; it’s going to be your @$$ on the line.

Wednesday, February 16, 2011

Survey sez!

We are deep into two WP7 dev surveys, but I just love this stuff and so I'm going to leak some preliminary data out now – if you want me to send you a link to the final results, send me an email at sebastian at preemptive dot com.

The first survey we are doing goes back to the earliest group of WP7 developers, “first 300,” and asks how they have made out over the past two months.

The second survey targets roughly another 1,500 active wp7 devs who are using analytics and/or obfuscation but who began their work after the initial survey.

Here are a few tidbits that we see so far…

Analytics improves mobile development practices and app value

Going back to the original 300 and asking those who had deployed apps with analytics, we have found that:

  • 82% of the devs say that using Runtime Intelligence (RI) has “helped them to establish for themselves the value of analytics for app development overall”

With regards to their specific WP7 app in the marketplace, the devs directly credited their use of RI as:

  • Increasing the value of their app (45%)
  • Improving their app’s user experience (36%)
  • Improving their app's quality (27%)

Mobile app devs migrating to WP7 4X’s faster than .NET devs

In the first 300, only 4% of the registered developers targeted two or more additional mobile platforms. This indicated to me at least that the very first developers to develop for WP7 were already MSFT devotees versus serious mobile app developers exploring WP7 as an alternative/incremental mobile platform.

However, in the latest wave of developers, that stat has more than quadrupled. There is no question that developers who identify themselves as mobile app developers first rather than iOS, .NET, or Android developers are building for WP7.

Platform share for those developers targeting multiple mobile platforms are (in addition to WP7):

  • iOS 69%
  • Android 67%
  • RIM 23%
  • Symbian 5%

There’s a lot more to come – so stay tuned (or shoot me an email). Cheers!

Tuesday, February 1, 2011

Riddle me this! Where can French, Italians, and Germans all agree?

Well, apparently, its in their tendency to pair wine with spicy Chinese food.

How did I come up with such a farfetched notion? The answer to “how” is “easily” when I started with a WP7 app like VinoMatch’s Mobile Sommelier that was instrumented with Runtime Intelligence for Windows Phone. But let me back-up a little.

On Nov 4, 2010 MSFT and LG announced that LG Owners Get Free Access to Popular Windows Phone 7 Applications. You can read more about the 10 premium apps and another 10 LG-specific apps on LG’s Facebook page here. They call the program “hAPPiness!”

Anyhow, it turns out that all 10 of the premium apps were instrumented with Runtime Intelligence and have been sending analytics since the January launch of the program.

Last week, Microsoft invited lead developers from all ten development teams on campus for three days to gather feedback as well as to hold some specialized training on a variety of technical topics – and I was fortunate enough to be invited to lead a discussion on best practices for incorporating mobile analytics into the development process. In support of this presentation, I was given permission to look into the runtime data that these 10 apps had been collecting to see what I could see.

The 10 premium apps that are free from LG through March 10th are:

1. Cocktail Flow by Gergely Orosz
2. Color Sprouts by Jarek Kowalski
3. Colorize by Kitron Software
4. Doodle God by JoyBits Ltd. (a Top 100 Paid App)
5. Envision by Dotnetfactory
6. Krashlander by Farseer Games (a Top 100 Paid App)
7. Mobile Sommelier by VinoMatch
8. Mr. Hat and the Magic Cube by BRAVO game studios
9. Talking Ragdoll by Spritehand LLC (a Top 100 Paid App)
10. Weave by Seles Games (a Top 100 Paid App)

While I can’t share the entire presentation here, VinoMatch and Gergely Orosz were kind enough to give me permission to include some of their mobile analytics in this discussion. I want to highlight two powerful analytical techniques using their real-world data.

Conversion feature analysis

Embedded within most apps are a few keystone features that drive conversion (from eval to paid, prospect to customer, fan to fanatic) and Cocktail Flow has one under development, Shopping Assistant. It does not yet connect directly to a store and, as a nascent feature, is not yet a centerpiece in their UX design. Here is what I was able to deduce from the Runtime Intelligence data:
  • Only 5.5% of all user sessions used the shopping assistant feature.
  • Of those, 49% used shopping assistant only once inside their session, and 51% used shopping assistant multiple times. Of those 51%, they used it for an average of 2.9 times per session. What were they doing?

With Runtime Intelligence, I am able to map out the full usage trail, feature-by-feature, session-by-session, and so I am also able to visualize:

  • Where in the sequence of features of each user session shopping assistance was being called.
  • And when it was used, was it a part of a “one use” session or one of those sessions where the user called the shopping assistant multiple times in a single session.

I can also see that the overwhelming number of Cocktail Flow users using this feature rarely used more than 10 features in their session and that virtually all lengthy sessions (taking more than 14 actions) were always churning (going back to the shopping assistant feature multiple times).

When this feature is functionally complete to the developer’s satisfaction, they will now have benchmarks to measure feature adoption (increase it over 5.5%) and session behaviors (when, how often, and under what circumstances the feature is used) all relating to what may ultimately be their most lucrative app feature.


Mutli-variable AB testing and cross-domain user profiling


In the Cocktail Flow example, we focused on a single feature. With Mobile Sommelier, we are going to add a few more dimensions.

The following graphic shows, as a relative percentage, how often ten selected features inside the Mobile Sommelier application were used over a 6 day period.

What we can see immediately is that there is very little variability over time. The population of users generally uses the application in the same way over time.

What can we do with this perspective?

If we were to release a new version of this App, we could immediately see any meta shift in behavior across the two versions (Runtime Intelligence will automatically roll-up multiple versions and then break them out when asked).

What CAN’T we do?

While we can see how often the “ShowTasteCard” feature has been used, we CAN’T readily determine which wine/food pairing users are most (or least) interested in. We can’t analyze custom, application specific data.

Luckily, Runtime Intelligence CAN grab this data – with no programming – all post-compile. For example, this (very busy) chart shows the how often (by percentage) users want to pair wine with specific foods (like BBQ or spicy Chinese) AND it is further broken out by country.

Of course, this is too busy to read in its current form, but the trend lines do immediately show that while all users may use the “ShowTasteCard” with generally the same frequency (as indicated in the last graphic), it is clear that they use the feature DIFFERENTLY, e.g. they care about different topics. Culture counts!

Let’s drill down.

Focusing in on just three countries (France, Germany, and Italy) and focusing on just a few of the food options (from AntiPasto through Chocolate Cake), we can see genuine differences in user behavior and preferences.

Perhaps it is not surprising that French are more interested in Caviar, Germans in apple pie, and the Italians in antipasto.

On the other hand, maybe we were not expecting Italians to show such a strong interest/preference for BBQ. Could this data point to a way to sell Zinfandel (a US export based on a grape that originated in Italy) into the Italian market? – as the US wine for US food (BBQ).

Some general best practices

At the end of the session, the developers generally agreed on the following developer patterns:
  • Instrument key usage and application milestones (Not just clicks and page views)
  • Capture user selections and preferences (Not just selection and preference setting events)

Other conventions and best practices

  • Implement exception reporting
  • Integrate runtime intelligence into your CRM, ALM, and Marketplace repositories

Application Analytics are not your older brother’s web clone for the phone!

These have been just a few small examples of the rich set of analytics that are now available (both on and off of the phone). So, if you think Runtime Intelligence is just another web analytic clone for the phone, think again – Runtime Intelligence provides application analytics – not web analytics (see my earlier blog Application analytics: a new game brings new rules).

In a nutshell, this means that these analytics include:

  • Custom data (including complex objects)
  • Session, feature, event, and method-level precision (not just event)
  • Exception reporting (unhandled, handled, and thrown)
  • Support for both Silverlight and XNA
  • Opt-in policy enforcement, SSL transmission, and caching
  • And were implemented using post-compile injection eliminating the requirement to change (or even recompile) source code.

Anyhow, I am ALWAYS eager to hear from developers who have employed analytics in cool and innovative ways – PLEASE reach out and share the wealth! Thanks

Thursday, December 2, 2010

Pacquiao, Lebron, and ... Microsoft

Is Microsoft more like Pacquiao or Lebron – and why should we care?

As a longtime Cavaliers season ticketholder, I have spent more time than I should have trying to divine what could possibly have been going through Lebron’s mind when he decided to “take his talents to South Beach.” Popular wisdom tells us that he wanted a ring – he was simply pursuing his longstanding professional goal. Recently though, I have come to believe that Wade did not attract Lebron with the promise of achieving his professional ambition– he actually gave Lebron an excuse to run away from something bigger still – an opportunity to transcend his sport and become a true leader.

For those of you who don’t know Manny (Pacman) Pacquiao, he is arguably the best professional boxer of all time. He is an eight-division world champion and the first boxer in history to win ten world titles in eight different weight divisions. …And, most notably, he has emerged as a national hero inside his native Philippines. In fact, he has parlayed his singular athletic success into a burgeoning political career – and was recently elected to congress in a landslide victory. Police report that there is a measurable drop in crime when Pacquiao fights; everyone watches. He has embraced his larger role as a transformational leader – in fact, in the lead up to his latest title bout, he confounded his trainers by jumping on a plane to campaign for Harry Reid’s reelection campaign – he wants it all and he is willing to take on the multitude of pressures of maintaining his world champion boxing status and serving as a societal role model, a cultural icon, and a political leader.

Consider this – if Pacquiao were to leave his homeland, his influence in the Philippines would be erased and could never be replicated (even if he returned). If “the Pacman,” in his secret inner heart, was afraid or unwilling to take on the mantle of true leadership that comes with transcending his sport; he could find a safe way out by manufacturing an excuse to immigrate from the Philippines – perhaps to focus on his boxing or some other myopic rationale.

Let’s go back to the one time “Chosen One,” Lebron James. He was born and raised in Northeast Ohio, went right from high school into the NBA, and had played (until “The Decision”) his entire career in Cleveland. The pride, the energy, and admiration that Lebron garnered in this part of the country was off the charts – not to mention the hundreds of millions of $$ he brought to this hard hit economy.

Now consider this – if Lebron’s decision had been to stay in Cleveland and commit to building both the Cavs and the region, he would have committed himself to Parcquiao’s journey – the expectation that he be more than an athlete would have been unavoidable (and inescapable). I think this young man could not hack it – he did not want to walk away – he wanted to run as fast as he could from this burden – a burden that he never wanted in the first place.

What’s this have to do with Microsoft? (stick with me here)

Microsoft is the world champion of business and desktop software. Their unparalleled success has fostered a large, dependent community of partners, developers, and consumers (a community that is in some ways analogous to Northeast Ohio or the Philippines). This community looks to Microsoft as more than just a software supplier – their personal and professional skills are highly dependent on their MSFT-centric skills – that means both revenue and self-worth are also tied up (dependent upon) MSFT. MSFT has transcended the role of software supplier (somewhat awkwardly in many cases one has to admit) to become a social/societal leader.

Now, it’s no secret that MSFT took a shellacking in the mobile phone market – but rather than cede this brave new world, they have come back hard with Windows Phone 7 and a strategy that includes a laser focus on the developer experience. With a steep hill to climb and their reputation on the line, Microsoft is not abandoning the faithful or the strengths that made them what they are.

No excuses – and no Lebron. Microsoft is the Pacman of the Smartphone.

Friday, November 19, 2010

300: Survey results from Runtime Intelligence for Windows Phone first movers


I have been pouring over a just completed survey that targeted the first 300 developers who downloaded the new Runtime Intelligence for Windows Phone SKU (RI4WP) and I have to say that I am extremely jazzed by the results.

First, we had a 20% response rate which shows right away how engaged these developers already are with the software. I am not going to go into the entire survey here, but I do want to share a few nuggets.

Developers were 3 times more likely to want both analytics and protection versus wanting either one as a standalone function. This is great to see because it says 2 things; first that when you care about what you build – you will want to BOTH know how it’s doing in the wild AND protect your work; second, is shows that developers are getting how efficient it is when you can integrate and combine post-build functions into a single build step (even when those functions appear otherwise to be distinct).

9 out of 10 developers indicated that RI4WP materially improved their overall development experience – now, you might say that this is biased because we only surveyed developers who had downloaded our software – but every developer had been using our software for at least one week – most for the first time – and so there was no guarantee whatsoever that we would be getting such positive marks so soon after installation.

It was not all love and rainbows – we asked developers to share both what they were most excited about and what their greatest concerns were – and the developers certainly did not hold back.

We saw a lot of enthusiasm for analytics but also some genuine frustration that can only be attributed to a legitimate need for better training and/or support and/or product maturity. For those of you that gave us feedback, rest assured: we are working hard to further simplify, harden, and expand this exciting technology – and be sure to register for our upcoming Master Classes on 12/8 and 12/9.

I will end with a small sampling of the survey write-in comments (unedited).

I (respondent) am most excited because:
“The detailed feature reporting (and the ease at which it can be implemented) is extremely useful for gaining insight into how an application is used in the wild. Early results for my current marketplace application have been surprising - enough so that I will be added more detailed telemetry reporting to my next application.”
“I will have more insight into application usage trends”
“I can actually see how people are using the app”
“It gives me insight into what is happening with my apps and which ones are more popular so I can focus my efforts there”
“I am figuring out how my users use my app in the real world. Incredibly valuable.”
“Dotfuscator's obfuscation is better than any other product on the market today.”

Friday, November 12, 2010

Biting the hand in the gift horse's mouth

I have been watching the growing “outrage” around the WP7 app reverse engineering controversy; outrage wrapped with an unmistakable implication that Microsoft has somehow dropped a ball and is trying to cover-up by recommending obfuscation to mitigate any risks.

I know that I have written that good developers should act like babies, but let’s take a reality check here.

First, let me say that reverse engineering managed code (and the risks that can stem from that) is not unique to .NET – it is common to all managed code platforms including Java (and Mono). For a solid overview on this topic, please see my 2009 article from the ISSA Journal: Assessing and Managing Security Risks Unique to Java and .NET (pdf).

The question is really how a WP7 developer’s experience compares to (for example) an Android developer’s (Google’s Android is Java and subject to all of the same issues and risks).

How many years has Android been out? Let’s compare Android's policy and recommendation to Microsoft's shall we? (click on image to enlarge)


Sources: Android policy and Windows Phone policy

This gets us to the real question that developers should be asking – how does Google’s ProGuard recommendation serve its developers as compared to Dotfuscator for Windows Phone? (again, click to enlarge)


Now call me crazy – but as far as I can tell, Microsoft has, in a few short weeks, served up a premier mobile development platform that is not only far more productive than any other, but includes dramatically superior monitoring, measurement, and protection technologies and services – this is not some defensive move to overcome some flaw or hole – it’s designed to further extend the unfair advantage Microsoft offers developers who target Windows Phone 7 first.

What am I missing here?

A phone by any other ‘nym is just as slick

(…or, are smartphones also people too?)

One of my favorite words is retronym. A retronym is a new name for an existing (old) thing that becomes necessary because of progress. (what!?) Examples help – the term “acoustic guitar” was only necessary when electric guitars hit the scene. The term black and white TV was not born with the invention of TV – it was born with the invention of color TV.

But we don’t have color phones, we have SMARTphones!

And here is the twist – a smartphone is more than a new class of phone, its also an anthropomorphism (ascribing human attributes to a thing that is not human). Phones can't really be smart – people are smart (at least in theory).

As I've already written in some of my more verbose entries below, smartphones are important because they combine the best of computing, communication, content, and social forces – to become something entirely new.

And as one more piece of supporting evidence that the smartphone hype is real – not only do smartphones promise to disrupt markets, business operations, and social norms ... they have given us our very first anthropomorphic retronym – the dumbphone.

I didn't make this up – see Dumbphone. Its the first of its kind - and i think that's worth noting.

Can you hear me now?

Sunday, February 21, 2010

old school social networking

The intimate connection between form and function is nothing new. Lately, I have been reading my father’s stories out loud to my daughter (as they were always intended) and I am struck by how a form of writing unique to him seems purpose built for the Twitter/facebook world of tweets and status updates. I am referring to his – “Beginnings" or “Pleasures of the Imagination.”

Beginnings are first lines of works left unwritten. Long before the Internet emerged as a household appliance spawning today’s socially networked ADD community, my father actually used the term “virtual stories" to describe these tiny works.

But do not fall into to a revisionist trap. His work always strove for a higher standard – not just to be read – but to be read aloud – and that’s what we call old school social networking!

To see what I mean – follow me on Twitter… http://twitter.com/ssholst

Monday, September 7, 2009

Walter Cronkite for CIO!

I keep six honest serving-men
(They taught me all I knew);
Their names are What and Why and When
And How and Where and Who.

Rudyard Kipling, Just So Stories

The "5 W’s" serves as one of the most basic formulas in journalism (police investigation and research too). The power of “Who? What? When? Where? Why? (And How?)" stems from the fact that each question requires a factual answer that cannot be answered with a simple “yes” or “no”.

How many botched projects, misinformed acquisitions, and over hyped technologies could have been nipped in the bud had the original proposals been subjected to this most basic journalistic benchmark?

Who specifically are the stakeholders? (people who care) Whose job responsibilities will change? (not at all the same as stakeholders)

What exactly will change for each of the stakeholders and those who will see their day-to-day tasks change?

When will these changes occur (as steps within a process flow and/or in what sequence)?

Why will any of the participants “opt-in” or cooperate? What’s in it for them?

How exactly will proposed changes be implemented? How will the proposed technology set all of this in motion?

New technology promises all kinds of life-changing opportunities – but the distance between technology and adoption is much more than “the last mile” of a vision – it’s the difference between vision and victory.

A case in point – we have been focusing on bringing “runtime intelligence” to market – a genuinely unique approach to application monitoring. What makes our approach unique is that it is designed to “serve the selfish interests” of two communities that have historically had very different priorities and worldviews. By serving a much larger constituency, we are able to drive higher adoption, increase collaboration, and solve “unsolvable” problems for the very first time.

Typically, applications are monitored by EITHER developers OR operations. Developers are mostly concerned with debugging and general usability issues. IT operations will often focus on performance, security, and licensing. In fact, BOTH groups of stakeholders suffer from their respective isolation from one another. For example, a software vendor wants to build features that are of value to the widest possible set of users – a single company (operations) only cares about their own parochial needs (and they don’t want to pay for “over engineering”). The software vendor worries about piracy and IP theft – operations worries about sensitive information loss and operational risk. This (and many other) inherent conflicts between developers and operations management undermine both groups' agendas and impede their success.

Runtime Intelligence may be the first solution that addresses application developer demand for near real-time visibility into adoption and usage in the field while simultaneously helping operations automate their IT policies and reconcile application investments with business performance.

Our breakthrough is, in large part, due to a our focus on making sure we have solid answers for the 5W’s (and 1 H).

"And that's the way it is."

Tuesday, September 1, 2009

Are developers just big babies? The good ones are!

In her latest book, The Philosophical Baby, Alison Gopnik points out that babies are far from self-centered, myopic beings. In fact, they exhibit all of the characteristics (both good and bad) of adults. In fact, they are in some ways superior. Babies, Gopnik would assert, have malleable, complex minds and a drive for discovery, and are enthralled by every subtlety that surrounds them.

Gopnik compares babies to the research and development department of the human species, while adults take care of production and marketing. Like little computer scientists, babies draw accurate conclusions from data and statistical analysis, conduct experiments, and are even capable of counterfactual thinking (the ability to imagine different outcomes that might happen in the future or might have happened in the past).

In short, babies can
· Observe their environment and absorb salient facts,
· Connect consequences that stem from the events they have observed,
· Predict future outcomes based upon the previous observations and their consequences,
· Develop a vision for the future – develop predictions based upon “what if” scenarios based upon hypothetical (versus observed) events and consequences.

(The fact that babies have these innate characteristics is consistent with the evolutionary perspective on creativity that I already discussed in my earlier entry Software as Fiction)

So why are good developers just big babies?

Good developers move beyond the strict functionality of the code that they write – they move beyond higher order concepts of system quality – they even move beyond caring about and optimizing their work to maximize the value of the code they write. They have the ability to imagine wholly different worlds where the underlying assumptions, constraints and, by extension, their criteria for success may be completely different. This is what we call a “market disruption” like the Internet, cell phones, etc…

In short, good developers can
• Unit test (observe)
• Profile applications (consequences)
• Calculate business impact and mitigate security risk (predict)
Develop a vision for the future – develop predictions based upon “what if” scenarios based upon hypothetical (versus observed) events and consequences.

This is why its always good to let developers have some play time (and some milk and cookies too)

Thursday, August 20, 2009

How do I love thee? Let me count the ways.

- Sonnet 43, Elizabeth Barrett Browning

What’s love got to do with people and software? (apologies to Tina Turner’s Private Dancer)

Hint: if people live for love, then (software) businesses live for money.

When all is as it should be – love is at the heart of our life and value drives our business. Both are vital – and both are very very hard to measure. Its figuring out WHAT to measure that is so difficult. What really matters? How many poems someone writes? How heavily software is being used? Measuring is easy – measuring the right stuff is what is so very very hard.

At PreEmptive, we have been focusing on Microsoft’s Azure. For those that are non-technical (or who think you are but live in a cave and can’t see the horizon), Azure is a massive Microsoft entry into “cloud computing” – an approach that takes all the worry, hassle and expense of managing computers away (into a cloud) making software very much like a phone service – all (or most) equipment is shared by massive numbers of people and managed for you. Cloud users simply pay to use the service.

Unlike phones, however, software builders and buyers are not all that used to this business model – technically – it’s not that big a deal – but from a business perspective – figuring out what you pay for, how its measured, and what the costs will actually be – this is all new! Ms Browning measures her love in "depth, breadth, and height" - could software value be harder to measure than love?

If wireless phone companies did not charge by the minute, no one would count minutes – we would just talk. Well, developers have just been “talking” for their entire professional careers – and now they have to start structuring their work around these new rules to avoid waste and expense. Azure (and other competitive cloud platforms) is not really a technology innovation as much as it is a major shift in business model.

So, whether you are a romantic (like Ms Browning “I love thee to the depth and breadth and height”) or perhaps more hardened like Papillon Soo in Stanley Kubrick’s Full Metal Jacket, one thing is for sure - Microsoft’s Azure wants to “love you long time.”

How deep, wide, high or long is the question.

Check out a this article in SD Times - PreEmptive's Dotfuscator instruments Azure applications By David Worthington – where Dave makes many of the very same points in a much more professional manner.

For a more commercially-centered view on all of this, read my preemptive blog entry.

Spread the love!

Thursday, July 9, 2009

Update to last post... I hate to say i told you so...

Right from the NY Times headlines - Cyberattacks Jam Government and Commercial Web Sites in U.S. and South Korea. The article in part reads "SEOUL, South Korea — A wave of cyberattacks aimed at 27 American and South Korean government agencies and commercial Web sites temporarily jammed more than a third of them over the past five days, and several sites in South Korea came under renewed attack on Thursday."

I have seen the list - it's more than 27 sites and it is more of a probe than a serious attack. The attackers are learning from our response and refining their strategy. The fact that these attacks are being characterized as primitive should not make us feel any more secure - sorry - i promise not to turn this blog into a paranoid rant... (unless it's already too late;) - the next few postings will be cheery and sunny (even if it kills me).

Tuesday, June 30, 2009

A daker side of application and human behavior

In DC today at a security conference (Gartner) – and this has prompted the following - I use this blog explore the symmetry between applications and their human progenitors – today’s posting focuses on a darker side – the military, terrorism and war.

I have just left a presentation led by David Sanger, Chief Washington Correspondent for The New York Times. He focuses more broadly on foreign policy, globalization, nuclear proliferation, and the presidency – today’s discussion was on Cyber threats rather than nuclear or trade.

Applications are now soldiers, terrorists, saboteurs and secret agents.

Did you know that denial of service attacks (techniques for bringing down phone, power, broadcast and financial networks) are now a standard tactic in every army’s war book?

Just as air bombing is standard before a land battle begins, so are denial of service attacks.
  • Estonia experienced a devastating cyberattack in 2007 following a decision to move a statue memorializing Russian soldiers who fought during World War II. Pro-Russian hackers took down bank and school websites on Estonian networks.
  • Russia used denial of service attacks before attacking Georgia last year.
  • And earlier this week, Iranian news websites and those belonging to political organizations were hit following the contested re-election of President Mahmoud Ahmadinejad.
Did you know that the US power grids and financial markets are continuously probed searching for weaknesses to be exploited at some future date?

…and guess what? Unlike human terrorists, you cannot easily determine their origin. We have no borders to protect. And even when you find the source (computers) that are launching these attacks – they are rarely in the country of origin (Russia’s attack against Georgia emanated from Turkey). How do you think Turkey would feel if Georgia bombed Turkey to defend itself?

If you haven’t already heard, Obama will soon be appointing a “Cyber Czar” – and before you buy in to some hack (the media equivalent of a computer hacker) complaining that we should be focusing on “the real threats” overseas, our economy, etc. remember your history – think of The Maginot Line – and be grateful that we have a president that actually uses computers and understands their role as the literal “work horse” of the 21st century and, now, the emergence of an entirely new “military front.”

Friday, June 12, 2009

Stuff i took the time to post on LinkedIn that may be worth repeating

I got caught up in a LinkedIn discussion thread on the influence of analysts on application vendors and software categories - i think it bears repeating... the original question was in part ...
Do industry analysts have too much influence on software vendors, who call their products GRC or CCM/T - terms used by analysts?

There were a few comments before i wrote...

I probably read way too much into this question – but it hit a nerve and so here is a rather lengthy reply (for a linkedin comment anyhow).

At the most abstract level – the etymology of terms like GRC are no different than any other phrase or term in natural language – like heat off of an engine, meanings are generated through usage (which often diverges substantially over time from first use). This means that even though careful and deep thinkers take the time to carefully craft a coherent and fully realized definition of GRC – this is not, at the end of the day, the actual meaning of GRC. There are two scenarios here – a) people using the term with a shallower or incomplete understanding and b) people intentionally reusing the term to mean something slightly (or entirely) different. In either case, whoever gets the most air time generally wins.

Looking at the second use case – intentional misuse – this is extremely common in the commercial world (not just hi-tech). What does “natural” mean? How about “fat free”? Hi-tech examples are numerous too – enterprise content management (ECM) is another good example. In fact, I wrote a short column on this way back in 2002 (before blogs were big) entitled “Enterprise: how long is a piece of string?” http://gilbane.com/columns.pl?view=5 …here I offer my own musings on the tension between vendors, consumers and analysts at length– but the topic was not GRC – it was ECM. Is it surprising that vendors like IBM, Oracle, EMC and others are players in both?

To be clear, motivations are not always malicious or deceptive – as long as analysts need to produce a body of work that is organized, integrated and expandable (and commercially valuable) – they will develop (and insist upon controlling) their own taxonomies.

As long as suppliers are most interested in solving problems competitively and profitably, they will emphasize and focus only on problem domains where they are effective (no vendor paints a worldview with a hole in the middle).

And as long as enterprise consumers are focusing their scarce resources on the most material/pressing challenges and opportunities in front of them, they will ignore skills, technologies and opportunities that do not address their selfish interests. Each group works to influence the other two – but the tension is natural – and I believe healthy.

In my view, all three players are correct to do this (in fact, this is more of an ideal than a common practice). So, I guess the short answer from my perspective is that mapping capabilities to features or categories is, by design, an imprecise means of communicating priorities and intentions – and should never be relied upon to replace detailed and deliberate assessments/evaluations/recommendations.

Buyer beware – or – he who controls the language, controls everything – or – meaningful ambiguity is a good thing…

A few complimentary notes were posted on the above :) and then an interesting post came from Michael Rasmussen - a very effective analyst and thought leader in his domain of governance, risk and compliance management....

Michael wrote "Yes, industry analysts do have too much influence on defining and categorizing software. Particularly in markets such as GRC. I left Forrester after seven years because I was continually frustrated - my definition and approach to GRC was broader than Forrester's audience. Forrester, Gartner, and their peers are good at reaching the IT audience - so GRC (as a software category) often gets trapped within IT. Occasionally it breaks out into other areas such as finance where they have some traction. They fail to understand GRC's role in EH&S, Quality, CSR, and many other areas. "

...and that's when i went a little overboard for a linkedin discussion (it took two posts to fit it in - here it is)

POST 1

Perhaps because I too have spent many years in this business (over 20 as an ISV and even 2 as an analyst), I cannot resist the temptation to connect Michael’s point of view with my earlier post. Sadly for all of you, because the post was too long, you will have to read this post AND THEN THE NEXT POST for the punchline...

The ISV-enterprise-analyst knot If you deconstruct the influence of analysts on software categories, you will see that ISVs are keenly focused on their customer needs (this is the ISVs primary focus). In the same fashion, the ISV customers’ primary focus stems from their target customers requirements (whoever they are). Since assessing IT options (or HR policy or tax law or…) is NOT the ISV customers’ primary focus, they look to outside support that is, ideally, expert and independent. With regard to IT, they look to IT analysts. IT analyst firms in this particular scenario have enterprise IT as their primary customers (focus) too. So – ISV sells to Enterprise who is then sold to by Analyst firms who provide “independent” guidance. The result is a tightly woven financial, professional and organizational knot. Leading to the following good, bad and twisted consequences

1) This dynamic discourages innovation and transformational solutions: The enterprise IT group is generally not incented to modernize or re-engineer their IT strategy on their own initiative – and so, typically, do not look to analysts for this kind of advice – they want guidance with minimal risk, a proven (therefore established) approach, using equally stable technologies and suppliers.

2) IT analyst firms deliver what their customer-base wants – That means a topology and best practices that emphasizes a “rear-view mirror” perspective. This is especially true for companies like Gartner and Forrester because of their enterprise client base. (Note that Michael appears to validate this when he writes that analyst firms are “good at reaching the IT audience.” That’s no accident or even handicap from a business perspective – that is their North Star to hitting their revenue goals. This is the high-order bit, the organizing principle, their raison d'etre. )

3) ISVs must “set the table” to win sales. ISV’s try to influence (or appease) analysts as a tactic to influence their shared customer-base. The influence on ISVs (who ultimately must label their software as “grc” or “ecm” or whatever) is, therefore, indirect. If the enterprise IT customer was willing to pay analysts to produce transformational business and operational re-engineering recommendations – then that’s what analyst firms would immediately start to focus on. But, to date, market forces rarely lean in that direction.

4) Sometime the market does demand transformation. Disruptive technologies like the Internet, regulations like Sarbanes-Oxley or economic forces like the rise of India and China may force businesses to place new demands on IT that get passed to analyst firms which then generate short bursts of transformational analyst output. NOTE - This is the exception and lasts just long enough to address the threat and never long enough to reap all of the potential value. This is why so many companies will stop GRC investments once individual regulatory obligations appear to be met but well before an integrated and effective GRC transformation is even in view. It is organizational and professional entropy.

5) In order to transform businesses, you must cut the knot – If the success of a new business practice or technology requires organizational change and/or a re-education of professionals (inside any of these three organizational threads) – the interlocking dependencies of the ISV-enterprise-analyst knot must be severed.

Is this inherently bad? Read my next post please.... (its WAY shorter)

POST 2

Is this inherently bad? Of course, if you’re a spirit who thrives on transformational change – this will be extremely frustrating (and I count myself among that number). But I have to say that this is not the only view.

As our founding fathers recognized – perhaps the greatest threat to our liberty stems not from dictatorship, but from “a tyranny of the masses.” Like the executive, legislative and judicial branches of government, our “knot” of enterprise IT, ISV and analyst may slow things down to a maddening degree – but it also protects us from swinging corporate strategy and operations too often or too far in any one direction. (hey, let’s throw out our computers and just use iphones!).

Now, I would never presume to speak for or represent Michael’s views – but I did have the good fortune to be one of Michael’s clients when he was at Forrester and have had some experience with him in his subsequent “expanded” and independent role as well. My experience of Michael is that he is a man who is not readily satisfied with the status quo and is energized when he sees a way to materially transform the way people work – and by extension – the way they live.

Ironically, as Michael succeeds in his almost evangelical mission to raise our collective consciousness as to what GRC SHOULD mean, organizational changes within enterprises to better align with good GRC practices will be one sure result. This will in turn lead to a spike in demand for more sophisticated/expansive analyst services around “true GRC” and this will in turn bring “the new GRC” into the analyst firm mainstream. …and in a decade or so, someone will rail against these firms for stifling the next dimension of business/social/operational/financial management. Who knows, perhaps it will still be Michael.

Remember – an “end-to-end solution” is just a silo seen from the inside. (…and apologies in advance to Michael if I have in any way misrepresented or dumb'ed down his outlook beyond recognition)…

Sunday, May 31, 2009

Software as Fiction

I caught an installment of The Bob Edwards Weekend on PRI this week where he was interviewing Denis Dutton, a philosopher and author of The Art Instinct – Beauty, Pleasure, and Human Evolution. Dutton is also the founder and editor of the website Arts & Letters Daily which was named by the Guardian as the “best Web site in the world.”

Anyhow, and to oversimplify, his premise is that art is much more than heat thrown off of a cultural engine – rather, art sits at the heart of our evolutionary advantage. Art provides a safe, effective means to learn life’s tough lessons without actually having to suffer the scars or take the risks inherent in the real world. As a species, fiction gave us the ability to adapt and survive better than our less creative Neanderthal competitors.

My first thought was of one of my father’s stories – “The Zebra Story Teller” –Checkout the following analysis from The Norton Introduction to Literature: “’The Zebra Storyteller’ suggests that the purpose of stories is to prepare us for the unexpected. Though the storyteller (a zebra in the story) thinks he is just spinning stories out of his own imagination in order to amuse, his stories prove to be practical. When the extraordinary occurs—like a Siamese cat speaking Zebraic—the storyteller is prepared because he has already imagined it, and he alone is able to protect his tribe against the unheard‐of.”

In the context of Dutton’s thesis, the Zebra Storyteller describes how fiction emulates the science that establishes fiction as an emulator!

The Zebra Storyteller is included here at the end of this post.

What’s this have to do with software? If fiction is a safe way to explore and grow – what are computer games? Simulators for airplanes or war games? Test cases that are a part of every application development cycle? We typically think of software as a means of automation that increases productivity, improves quality, etc. – but if Dutton is right, software plays an equally important (or even more important) role as a "low-cost, low-risk surrogate experience."

…and for me – this leaves room (establishes the permanent need) for the truly creative developer who is not chained to a formal spec…

Programmers as poets writing software sonnets - diggit!

The Zebra Storyteller
by Spencer Holst

Once upon a time there was a Siamese cat who pretended to be a lion and spoke inappropriate Zebraic.

That language is whinnied by the race of striped horses in Africa.

Here now: An innocent zebra is walking in a jungle, and approaching from another direction is the little cat; they meet.

“Hello there!” says the Siamese cat in perfectly pronounced Zebraic. “It certainly is a pleasant day, isn’t it? The sun is shining, the birds are singing, isn’t the world a lovely place to live today!”

The zebra is so astonished at hearing a Siamese cat speaking like a zebra, why, he’s just fit to be tied.

So the little cat quickly ties him up, kills him, and drags the better parts of the carcass back to his den.

The cat successfully hunted zebras many months in this manner, dining on filet mignon of zebra every night, and from the better hides he made bow neckties and wide belts after the fashion of the decadent princes of the Old Siamese court.

He began boasting to his friends he was a lion, and he gave them as proof the fact that he hunted zebras.

The delicate noses of the zebras told them there was really no lion in the neighborhood. The zebra deaths caused many to avoid the region. Superstitious, they decided the woods were haunted by the ghost of a lion.

One day the storyteller of the zebras was ambling, and through his mind ran plots for stories to amuse the other zebras, when suddenly his eyes brightened, and he said, “That’s it! I’ll tell a story about a Siamese cat who learns to speak our language! What an idea! That’ll make ’em laugh!”

Just then the Siamese cat appeared before him, and said, “Hello there! Pleasant day today, isn’t it!”

The zebra storyteller wasn’t fit to be tied at hearing a cat speaking his language, because he’d been thinking about that very thing.

He took a good look at the cat, and he didn’t know why, but there was something about his looks he didn’t like, so he kicked him with a hoof and killed him.

That is the function of the storyteller.
--------------------------------------------------------------------------------

©Spencer Holst. From THE ZEBRA STORYTELLER, Station Hill Press