Thursday, June 28, 2007

Wanted: A VIP (VPN?) Room for Web 2.0 Apps

I am working on a project with a team in New York, San Francisco, and Noosa, Australia. It's a bunch of really smart folks and we have a good time ... but collaboration and communication could always be better.

I would love to cook up a little social networking site for our project work using, say, Ning. In addition to the basic stuff like messaging and chat, we could embed this box filesharing widget, put up videos and photos (ok, our photos are mostly of whiteboards, but we count that as fun), audio recordings of meetings, maybe a gizmo or skype or grandcentral widget for click-to-call. Maybe plug in some WYSIWYG wiki editing.

But we can't do that because of security and nondisclosure concerns. IndustryNext doesn't harbor a lot of secrets, but our clients may -- especially when it concerns upcoming and unannounced products that we're building with them. And our confidentiality with clients means that we won't put their project data into a shared SaaS environment.

So what can we do? The other extreme (from fully shared Saas) is to acquire the apps to host in-house. But that's not an option with many of these services, for good reason.

I propose that a third party build a business hosting secured and partitioned areas where instances of these apps could live. Of course going down this road starts to break the business model that makes many web 2.0 services viable. Without shared hosting infrastructure, and with the added hassle of supporting a "customer" deployment (even if the hosting service is a very sophisticated customer), advertising won't pay all the bills anymore.

But that's ok: I'm willing to pay some money for secure, semi-private access to these apps. It's way cheaper than any alternative I'm aware of, and would have a positive impact on our productivity. Moreover, since the apps are already built and deployed, it's all gravy -- a new revenue line -- beyond the actual hosting and the maintenance (from the app provider to the host).

Does something like this exist? If not, any takers?

Tuesday, June 26, 2007

Free ActionScript3 Code Generation from Violet UML

At IndustryNext, we are in the interesting position of building cutting-edge projects, with cutting-edge tech for somewhat more established companies than your typical web 2.0 startup.

Part of keeping the speed and quality high is leveraging tools for code analysis and code generation to help keep a handle on dynamic language development. (E.g. I wouldn't ban the use of eval in Ruby, but I'd sure as heck want a tool that can tell me where in the codebase it's being used, and why.) In some cases, we're pioneering these methods.

Generating consistent code from models is a step in this direction. (In JavaScript, just guaranteeing consistent variable names can save no small amount of debugging.)

In order to make it easier to play with object models in ActionScript 3, I spent a little time integrating Cay Horstmann's lightweight Violet UML modeling tool with David Holroyd's metaas library for manipulating ActionScript.

The result is VASGen (Violet UML ActionScript 3 Generator) 0.1, an initial release of a free code generation tool that supports generating classes, interfaces, field, properties, methods, and various types of relationships from Violet's Class Diagram editor.

The project page includes details on what works and what doesn't in this release. If you build applications in AS3 and you like UML models, please give it a try and let me know what you think.

Friday, June 22, 2007

Jeans and a Minority Report Moment

I was putting on a pair of jeans and noticed a nylon tag stitched in them, marked "Remove Before Washing or Wearing." The fabric was conveniently marked with a line saying "cut here."

Wondering what that was all about (a desiccant? inventory control?) I grabbed a knife, cut out the tag, and held it up to the light:


Ok, it's an inventory control RFID tag (the rings are the antenna). Not a huge surprise...

But something about cutting the fabric out with a knife, holding it up to the light, and seeing this inside reminded me of the sequence in Minority Report when John goes to a back-alley surgeon to get his eyes cut out and replaced (tracking and identification is accomplished through retinal scanning in the film). After the operation, he's forced to hide, delirious and blindfolded, in a tub of icewater, as the police flood the building with robotic eye-scanning spiders. This description makes it sound a touch hokey, but it's a brilliant terrifying sequence in the film, and an allusion to role of eyes in Bladerunner.

Having worked hands-on with RFID quite a bit, I'm sure someone imagined how easy and "useful" it would be to not print "Remove Before Washing or Wearing" on the tag at all.

Wednesday, June 20, 2007

More Khakis: Build a Market for Near-Future Consumer Dealmaking

Here's an idea I've had for a while... if you're good with strategy (see Hey, Guys in Khakis) you might be able to fit the pieces together well enough to make a buck. I thought about building something like this at one point but I'm just not enough of a strategist or a consumer to have a real passion for it.

The premise is that most everyone always has some purchases they're planning, say two weeks to six months out in the future. The buyer has some characteristics in mind, a general idea of price, and is definitely going to buy in that time frame. But he or she doesn't have a specific item chosen nor a specific date when it's time to search out a deal and buy.

As just one example, if you like or need shiny gadgets, you might have thought
  • I'm going to get a X-megapixel camera sometime this summer, I'm just too lazy to read all the reviews and sort it out right now.

  • I'm want to buy my wife a bigger flat panel, but the prices are always bouncing around. I think I'll wait a while and see how much LCD real estate I can get for my money.

  • I'm sick of encoding all these DVDs. When I see a deal on TigerDirect or techbargains I'll grab one of those DivX-capable DVD players and be done with it.
There's a market here: a lot of people are not actively searching today (using one of the many comparison shopping sites), but they are definitely buyers. Whether $150 is a good pricepoint or $1500, it's something they are comfortable with and have essentially already decided to spend.

Today, this is an inefficient process on both sides.

The customer waits around until eventually he or she happens to hear the Fry's ad on the radio, drives by a store, or sees a chipmunk on the way to work and figures it's time to get a camera and start posting lolmunks.

The seller has limited visibility into who is interested in what products, when they plan to buy, and how much they'll spend. If a site has an extensive profile on you (say, amazon) then maybe they could develop an algorithm to predict when you'll upgrade your camera, what you're likely to spend, and how you comparison shop. They could then communicate directly with you to try and close a sale. But most vendors have a fleeting relationship with the customer, so they spend lots on ads, make sure their products are listed on sites like pricewatch, and hope the customer comes.

The opportunity is to create a market that lets vendors go look for buyers who want certain kinds of products, and make them an offer. For example, Fuji revs their cameras constantly, so maybe I have a bunch of a particular model, and I know the next line is coming out soon. If I want to move the inventory, I put it "on sale" and pay to advertise.

What if I could go and find a bunch of buyers who have said they're looking for this kind of camera at a price point I can stand and they're buying soon? My goal is to (1) offer them a price they'll buy at and (2) make enough on the sale that I'm still ahead of where I would have been in the "put in on sale and advertise" scenario.

This system would be a win-win. But several pitfalls must be overcome. Principally: How can you tell a "true buyer" from someone who just wants to window shop some really great deals? It makes a big difference to the seller, because publishing these kind of targeted deals out into the ether (offering them to arbitrary unverified people) is essentially the same thing as just publishing a lower price. It's asking the vendor to show his cards without the buyer committing anything.

So, to make this work, one needs at least a way of limiting the pool of "true buyers" to those who are plausibly legitimate. At the same time, it cannot be a closed system of fully committed participants since a "true buyer" may sign up, see some great deals, and legitimately decide to just forget it and buys something else that catches his eye. The buyer is not likely willing to be obligated to buy through this system.

The whole mechanism needs some sophistication, and probably a few small but key innovations that will keep people (mostly) playing fair on both sides. These might include unique valid credit cards, online reputation mechanisms, social networks, and some things that haven't been invented yet.

I believe such a market can and will be built. I expect to see someone clever or lucky make a bunch of cash building this and then selling it to eBay. And although I don't love shopping nearly enough to want to build this product, I'd gladly be its first customer.

Tuesday, June 19, 2007

Design and Implementation for Longevity: Two 20th-Century Machines

Here are two twentieth-century machines that are beautiful, functional, and still have it after several decades of radical technology evolution "should have" passed them by.

This C2 Corvette is as edgy, clean, and exciting as any vehicle built since. It probably always will be:

This original (1978) Cessna 152 performs at original spec after 30 years and looks great doing it:

So what does it take to come up with a design and an implementation that can hold up like these two?

Certainly sportscars and airplanes are not trivial problem domains with few constraints. And they're not domains lacking innovation and evolution. Yet neither of these machines take it on the chin for lacking digital gauges or GPS navigation.

There's some luck, some genius ... what else? It's more than a design question. If it were only about design, we might get bogged down in aesthetics and cultural theory, which is fun but sort of a sui generis sport. (Why does art deco seem futuristic? because "the futuristic" has irremediably incorporated art deco? what about directly undermining this? or does that form a stucturalist framework that reinforces the duality? ... )

One key piece is the absence of over-engineering. The 'vette and the 152 are fabulous implementations of their times, but never strove to be "ahead of their time" in terms of showy engineering.

Contrast a recent BMW or a Mercedes, which always comes off rather less slick a few years on, because at design time it had been packed with every blinking gewgaw money could buy, and those rarely age well. These cars do ok, though, because the first buyer gets a space shuttle experience during her 39-month lease. And since the drivetrain and suspension tend to be solid on these cars, the cars hold up for the next 25 years -- they just look increasingly tired doing it.

Friday, June 15, 2007

Scamalicious, Bubblicious, or the Next Transistor?

It's a multiple choice test for this venture investment in Stirling engines as solar power collectors. Stirling engines are of course very real. But so is fusion.

Is this brilliant risk-taking and the green investment that'll lead to breakthroughs? or another dangerous sign of too much money chasing too few ideas?

Wednesday, June 13, 2007

Pac-Man on your Smartphone? Ghosts are Chasing Your Game Download

Remember Bad Idea Jeans? That's what came to mind after TechCrunch told me Namco is releasing classic arcade games for AT&T smartphones, and I checked it out.

Pac-Man on my Blackjack is not a bad idea at all. But here's the ordering page:


Notice you can choose how many copies you want to but, but not whether you want "Download Protection" ... Interesting .. My downloads have never been injured before. I wonder why I need protection? If you click the protection link, you get this popup:



This is obnoxious on so many levels. And no, I'm not complaining about the money. The problems are these:

First, the market for off-deck software for mobile devices is in its infancy. While the general population is slowly realizing that the phone is a computer and can run programs (if the iPhone does nothing else, its TV spots will help communicate this fact), most folks have still never installed an off-deck app, let alone paid for one.

The smartphone users are at the vanguard, the evangelists that get their friends and companies onto mobile apps. So why even suggest that the software downloads are any different from a PC software download? Why suggest there's some special problem with mobile software, so you'd better pay $3 for "insurance" in case your stuff gets screwed up?

At this market's stage of maturity, users need to be told that if they're ready to start buying mobile apps, there is no risk, and the vendor will do 100% whatever it takes to make sure the software is available in case a device gets broken, hard reset, etc. Compare the early days of e-commerce: a number of companies promised extraordinary customer service to overcome anxieties about returns, using credit cards online, etc.

The second problem is that it undermines the whole idea of software sales as IP licenses. If I've bought a permanent license to Pac-Man for my device, why does it cost $3 to make sure I can download it again later? Is the $14.99 for a conditional license, that only gives me the right to use the app until such time as my device gets reset? Then $3 buys me a permanent license? Of course this is absurd.

Bottom line: if Namco want another $3, just call it a handling fee, or a one-time provisioning fee, or just toss it into the price. My downloads don't need protection.

Tuesday, June 12, 2007

Hey! Guys in Dockers! Over Here!

Geeks love to hassle the guys with the MBAs and the "strategy" resumes. And plenty of geek entrepreneurs have showed the MBAs a thing or two making a fortune with code-first-ask-questions-later software and websites. But sometimes the technology isn't the problem and some strategy would be helpful.

In particular, I was chatting with a co-worker last week about how to set up a mass system for buying and selling used software licenses. In most countries and most U.S. jurisdictions, the "right of first sale" says that if you have a software license, you can resell your rights under that license to someone else. That's the legalese behind buying an old game from a bored gamer on craigslist. As an IP sale, it's not about the disks or even the activation key, but about the license. The seller has to relinquish the right to use the software (usually) and anything that comes with that (like support). The buyer gets it.

For big expensive licenses, like that 16-CPU perpetual Oracle license you no doubt have lying around, there are companies ready to help broker a deal. Actually there are a handful of companies ready to wheel and deal. At the consumer or low-value, low-volume level, there are some funkier ones. But there is no ebay for buying my aunt a "used" but legit copy of Word 2003.

Clearly there's a market here, and a look at the current players suggests it's not efficient or transparent. How can we get a web-based open market to work?

In this arena, it's reasonable to suppose most buyers are "legit" because most or all of these software packages could be acquired illegally for free if the consumer were not inclined to pay. It's trickier on the sell side since, in the extreme case, a seller can offer to sell a license for anything at all without possessing it in the first place. Most software licenses have no physical redemption token like a bearer bond, stock certificate, or paper money. So a buyer pays up, and the seller says, "You've got a deal, you're now the owner of a Foobar 2.0 license."

So we need some kind of clearinghouse ... but a clearinghouse for what? And how to keep it digital so we don't need a Netflix-grade DVD sorting facility to bag Microsoft Bob disks?

We're going to need digital tokens and a tracking scheme that software vendors want to participate in. Why would they want to do that? One argument asserts that a product is more valuable if a buyer knows it can be resold (think cars). And a uniform, open key registration and verification scheme could help fight software piracy without requiring each vendor to pay to maintain their own system.

The point is, I need a strategy guy (or gal) to line all the pieces up. The tech is trivial -- we have auction systems and reputation systems and crypto and tokens and all that. What we need is a scheme that arranges interests, incentives, and rewards in such a way that enough players get in to bootstrap the market.

Sunday, June 10, 2007

Alrighty Then...

This blog gets a lot of hits via Google... from Windows Live Search, not so much.

Recently a visitor arrived via this referring URL:

search.live.com/result.aspx?q=viagra&mrt=en-us&FORM=LVSP

I'm unsure whether this says something about my blog or about Microsoft's search engine. Probably the latter. But if it's the former, I'm not sure if it's a compliment or not.

Saturday, June 09, 2007

A Workforce That's Never Seen Mac OS 9

I spent some time yesterday with a recent grad who is interviewing for a design position with IndustryNext. For some reason, I got the idea to ask him if he'd ever used a Mac before OS X. "Nope," he said, "I've been OS X all the way."

Damn, man. I'll resist the temptation to get melodramatic about feeling old or to reminisce about walking uphill both ways, hacking Think C and Think Pascal code for the old MacOS, with Inside Macintosh open on my lap 'cause there was no "line" for online docs to be "on."

Actually, the emergence into the workforce of a generation that knows only OS X means that Steve Jobs, for all his quirks, has pulled off something pretty amazing. Namely, making OS X successful enough for long enough that students are graduating who don't know anything about Apple's troubled bad ol' days.

I'm still ambivalent about Apple and Mac OS X, though. Great accomplishments include the design (both software and industrial), the first POSIX compatible BSD OS that your mom wants to use, and the first mass-market OS with a native OO API...

At the same time, Apple is still a high-maintenance partner with serious control issues.

Things have improved since the "authorized repair" racket in the 80s, where Apple required personnel to confiscate hardware if there were signs you had tried to install it yourself or put in something that hadn't been blessed by Cupertino (creating ethical dilemmas aplenty for the geeks with the case crackers and screwdrivers, at least where I lived). But vestiges of the program were still in force for factory repairs, at least up to the point just before OS X was released. And after that, there has been an unending series of minor scandals.

To be fair, selling high-end product in a Wal-Mart world is a tough gig. More power to 'em for trying. And nostalgia aside, if a new generation of designers doesn't know or care about the Mac legacy, good for them. Let's hope that their ignorance of the past opens their minds to new possibilities for the next generation of products.

Friday, June 08, 2007

Notebarn: Launching URLs and International Phone Numbers (Includes Crash Couse in Numeric Regular Expressions)

A lot of visitors to this blog and the Notebarn project page (where you can download the app) are from outside North America, and all of those folks got a raw deal from my last update.

I added the ability to dial numbers from a note, but the phone number recognition was based on a hard-coded pattern that looks like a North American phone number (basically, 10 digits with some optional delimiters).

So I've got an update that moves the phone number recognition out to a configuration file, where you can put in a localized phone number pattern.

I also found it really frustrating to put a URL in a note and then have to key it in later to browse. So this update recognizes URLs in notes and lets you launch them just like dialing a phone number from a note.

URLs / web browsing works straight out of the box. For localized phone numbers there's, um, a small catch.

The Catch

I did not set up a list of international phone number patterns. So, in this release, if you're outside North America, you'll need to add your own phone number pattern to the config file. Here's how it works:

  1. Install the new Notebarn with the latest OTA installer. The install will place a config file called notebarn.config.txt in the Program Files/Notebarn directory on your device, right alongside the executable.
  2. If you have a regular text editor on your device you can edit the file in place and skip to step 3. Otherwise, use ActiveSync to grab the file, pull it over to your PC, and edit it there (with an editor like Notepad). When you're done you can push it back to the device with the changes.
  3. In the config file you will see two lines like this:

    #Add a RegEx for your localized phone number format here:

    PHONE=\d{3}\D{0,2}\d{3}\D?\d{4}\D

The beast on the right is called a regular expression, and your .net-enabled Smartphone has a great engine for processing them. Microsoft has docs on the format. But you don't need to read all that. The cheatsheet for phone number patterns works like this: \d means a digit. \d{3} means exactly 3 digits in a row. \D means a non-digit. Specifying non-digits is how you look for delimiters used between groups of numbers, like a period, space, dash, parens, etc. And \D{0,2} means anywhere from 0 to 2 non-digits in a row. The \D? is shorthand for \D{0,1}, or "zero or one non-digit."

So all together, the North American pattern above means 3 digits (the "area code") followed by 0, 1, or 2 non digits (think of 415-555-1212 or (415) 555-1212), then 3 digits, optionally a nondigit, 4 more digits, and a non-digit to mark the end. How does the phone dial if we've recognized an extra non-digit at the end? Well, the phone app in Windows Mobile is smart enough to drop the non-digit parts of the phone number when it dials.

If you put together an expression for your locale (or borrow one from another program), feel free to email me or post it in the comments. In the next release I'll include all of them in the config file to make it easier to set up.

Monday, June 04, 2007

Foleo is Foolish ... But Here's a Better Idea

I know, the Foleo is spelled with an "e" ... Either way, it's such a silly proposition only Steve Jobs could hype this thing enough that people might buy it. And if he did, the only benefit would be keeping the computer gene pool diverse by preventing people from buying a decently spec'd Windows laptop, for about the same price.

The interesting bit is that we do need optional larger displays for small computing devices so that we can get the most out of them as they continue to increase in power and connectivity. So what would work better than this non-laptop?

I worked with Tim Andrews at Viant in "Web 1.0" and one time he took us out of our way to look at the latest video goggles from Sony Japan. Ok, personal movies ... huh? I didn't get it. The goggles are going to be the video output for this, Tim explained, pointing at his Palm. Tim has spent much of his career thinking ahead, and this time was no exception. The 1999-era Palm would've taken 30 seconds to BlT a frame for these goggles. But now?

Let's see... Modern smartphone hardware can drive a VGA display or larger. And here are the visor displays: VGA for about $400, and SVGA for $1600. Like most hardware, the price is inverse-exponential with volume. That's a fancy way of saying these are expensive gadgets 'cause no one makes a lot of them. The price will drop drastically as they are produced in higher volume.

On the input side, there are old fashioned Bluetooth or more futuristic solutions and bear in mind: you don't always need big input and big output at the same time. Web browsing and document review can benefit from a big screen, but hardly need a full-sized keyboard. So there's no reason to fill your lap with another battery-chewing, airport-security-antagonizing monstrosity just to follow up on some links.

Small computing devices are about mobility and convenience. They are hardly "enhanced" by chaining them to a big dumb anchor. But the tech is here to take a smartphone-grade device and get a ton more productivity and value out of it by widening its human I/O bandwidth with these virtual keyboards and virtual big screens.

Saturday, June 02, 2007

"Offline is Here" ... and Credible (!)

I spent a few minutes chatting with Brad Neuberg yesterday, following up on his presentation at Google Developer Day on Thursday. We spoke about offline data persistence for web apps, and the rapid crystallization of industry players around a particular approach.

"Offline is here," he said. Two weeks ago, that would have been just one opinion of one prominent person working in the space. Fast forward to June 1, and half the industry seems to have decided that now is the time, and that a specific SQL flavor of offline storage is the right one.

Why two weeks ago, not one week ago? Because when I asked about Firefox 3 (which has been promising an offline facility), Brad pointed me toward this change to the XHTML5 spec at the WHATWG, submitted on May 23. Here's a more readable and faster-loading spec draft section on local SQL storage (but content might change, as the doc develops). Firefox 3 aims toward this spec, and the spec API looks remarkably similar to what Google Gears offers.

So we have Dojo, Apollo, and Firefox essentially promising the same relational, origin-domain-partitioned storage metaphor along with similar APIs. Google brings plugin implementation code targeting all major browsers. For someone like me, who gets paid to make bets on the (near-term) future in order to architect applications, that's awfully persuasive.

In some ways, this is another iteration of the "dumb terminal + remote computing" vs. "smart terminal + dumb network services" oscillation... but it seems like we're maybe getting critical damping now.

Microsoft articulated a sensible "Smart Client" architecture around eight years ago: deliver apps that leverage services in the cloud but can also run offline. They should sync when online, while leveraging local hardware for performance and to maintain state. I'm using a quintessential smart client right now as I type.

The only easy way to implement that architecture and get the full benefit of local resources though was to build a .net application. Then Win XP shipped without .net; zero-click install had issues, one-click install was too late, and the rest is history.

We got AJAX and Web 2.0 instead of a lot of smart clients, which wasn't a bad trade.

I'm pretty psyched now though, because it looks we're going to get to have both.

Thursday, May 31, 2007

dojo.offline = apollo.db = google.gears

You know those scenes in political thrillers when a character starts spilling the beans about what's really going on? And as the real plot takes shape in your mind you start thinking about the consequences: "That means the old guy is working for them ... and the girl is going to get killed if ... wait, she must've done all that stuff on purpose, which means..." You get the idea.

Well I had one of those experiences tonight at the final Google Developer Day session, where it turns out dojo has elected to scrap their own infrastructure for offline AJAX app operation, which had been in development a long time and had just reached beta. In the runup to Dev Day, Brad was treading lightly. But what he just told us is that the dojo plugin is dead. The dojo offline high-level Javascript library will run on top of the Google Gears offline app plugin. Incidentally, Google helped pay for porting the dojo offline library.

Early in the day, when Gears was introduced at the keynote, we learned that Gears would interoperate with Adobe Apollo. This post has details.

Ok, who's left standing here?

True, "interoperation with Apollo" isn't the same as "being Apollo" (Apollo has access to the filesystem, up to the perms that the current user has). But dojo was clearly the frontrunner in offline AJAX, and has held a hegemony in vector graphics and other wicked scripty stuff.

So to keep the metaphor, I see a surprise coup d'etat. And not necessarily a bad one, either. I want to see how this one ends.

Wednesday, May 30, 2007

Rejected for Individual Health Insurance Coverage in CA? Meet the MRMIP

I keep this blog to tech commentary (and to areas I have expertise in), or software I've cooked up. But I'm writing today about a California-specific health insurance program that guarantees coverage for, among others, self-employed geeks who seek individual health coverage and get rejected.

This is a common phenomenon for those who stray outside the white-picket-fence world of employer-sponsored group coverage. Last weekend I came across another smart, savvy tech pro who got rejected for individual coverage and didn't immediately find info about this critical program. I'm not a big SEO guy, no doubt to the detriment of my traffic volume, but this information really needs to make its way up the Google rankings: for the heck of it I ran a number of searches myself, and info is just as obscure today as it was four years ago when I went looking for help on this issue.

So here's the executive summary:

  • California's "Major Risk Medical Insurance Program" or MRMIP is a state-administered program that guarantees certain groups of individuals can buy a health insurance plan from a specific set of private-sector plans

  • This program is mainly valuable to folks who need to obtain individual coverage (i.e. are not eligible for group coverage through an employer, union, etc.)

  • You are eligible if you have been formally rejected for coverage in the last year or if you have been offered coverage at a more expensive rate than the current MRMIP program rates

  • The program addresses accessibility of coverage, not affordability. I.e., it will help you get insured; it will not help you pay for it. Sadly, that means you more or less need some flavor of middle-class income to get your HMO on.

Considering this program lives at the unholy intersection of (a) government bureaucracy and (b) health insurance bureaucracy, it is well documented, easy to apply for, and easy to work with. YMMV, but I am speaking from personal experience, having struggled with the "I have no group coverage" problem and being happy with the solution MRMIP provided.

Ironically, once you know the magic keyword (MRMIP) it's easy to Google the rest of the data. But here are some direct links anyway:

2007 program brochure, which includes details on eligibility, carriers, coverage, prices, and the application form. The original is on the state's web site. Here's the program home page.

The program is administered under the auspices of the "Managed Risk Medical Insurance Board." If you're interested in the politics, policy, and future of this program, these notes are interesting.

Two last things worth noting:

First, there is an annual coverage cap of $75,000 on these plans. That seems like a lot of money, but in the US's insane healthcare economy it is very possible to run through that amount if something bad happens. For that reason it is still worth looking at which program offers the most potential care for $75k. I have a hunch that would be Kaiser, though I don't have all the data to back that claim up.

Second, although insurance companies seem to be getting more diligent about investigating your medical history, there may be the temptation to falsify or conceal various bits in order to get coverage, or to get a better rate. Doing so is hazardous.

If you get away with it in the short term, you may get some cheap doctor visits. But if you have a serious illness or injury, where the insurance company is looking at paying big bills, you can bet they'll put a fraud investigator on the case. If they can turn up evidence that you lied on your application, they'll deny your claims and probably try to terminate your coverage altogether. You could fight, but it would be a long uphill battle and not the kind you want to take on when you're already sick or hurt.

Bite the bullet, tell the truth, and if they tell you to get lost, programs like MRMIP can help.

Monday, May 28, 2007

Notebarn Update: Dial Phone Numbers from Notes

Once I gut a bunch of phone numbers in my Notebarn notepad, I started getting frustrated that I couldn't dial a phone number in a note just by viewing the note and clicking on the number. So I've updated the app to include this capability.

If you want this feature, and don't want to read any more geek ramblings, you can go right to the project page and download the app.

I missed this feature acutely because I used to use a Blackberry. On the Blackberry, whenever you come across an email address, URL, or phone number, the device recognizes the format of the text and creates a sort of smart tag. The trackwheel menu gets new tasks related to the data. If you move the cursor over a phone number, the wheel menu will include Call, Send SMS, and, if the number is recognized as matching someone in your address book, clever things like "Send an email to [name]", "Invite to meeting", etc.

It's not accidental that most Blackberry apps support this functionality: the folks at RIM supply classes in their platform API (net.rim.device.api.ui.component.ActiveRichTextField and net.rim.device.api.ui.component.ActiveAutoTextEditField to be specific) that do pretty much all the work for you. Use these classes, and you get this functionality for free.

Despite many strengths relative to the Blackberry platform, the .Net Compact Framework on Windows does not include such a class (at least as of 2.0).

Making this kind of an implementation harder, the Smartphone version of a multiline textbox has a "clever feature": In order to allow multiline textboxes to fit nicely onto a small screen, play nice with directional tabbing, and still accept a lot of text, they have two states. The base state shows one line of text and a little "expand" triangle. You can edit the text, the control responds to events, etc. If you click "Enter", triggering the expansion, the textbox switches into a fullscreen state where you can put in all the text you like.

The problem is that in fullscreen mode the component does not respond to all of its events (it doesn't even fire an event when switching modes), making it very hard to do context-sensitive stuff, such as "look at where the cursor is, extract the nearby phone number, and allow the user to dial it." Which is what I really wanted to do.

I implemented two workarounds instead. When notebarn finds one phone number in the note (using a RegEx that looks like a U.S. number), it adds a "Dial 415-555-1212" command to the main app menu. If there are multiple numbers, it opens a new window with a list showing each number and some of the context around it (so you can tell which number is which). Pick the one you want, and click to dial.

Happy calling!

Tuesday, May 22, 2007

TechCrunch vs. The Maker Faire

Mike Arrington wrote one of those shot-heard-round-the-world posts today. It wasn't news, but Mike Arrington writing it on TechCrunch was the news. The Valley in a troubling state? Indeed.

It would bum me out a lot more if I hadn't spent this weekend at the Maker Faire. The fair was a beautiful thing. The people and projects looked great; the companies mostly silly. The bigger they tried to look (Yahoo!) the sillier they looked. The more they focused on doing cool stuff (Microsoft... sorta kinda) the better they looked. But really it was DIY anything and everything. The essence of the geek thought process was there, the thought process that makes Silicon Valley work decade after decade: one part science, one part "I bet if I monkeyed with this a little more, it would be really damn cool," and one part "that is really damn cool -- you need a hand with that?"

Robert Scoble already made this connection. But I want to hammer on it a little more. Spend 15 minutes browsing this flickr stream and you'll feel right as rain. It's meatspace stuff, mostly, some fire and robots and yarn along with the software. But the idea is the same, and the membrane between online and offline has never been thinner.

On Saturday, we spent 20 minutes looking for parking and ended up in the far reaches of a dirt lot where some cargo trailers were parked. The event was well attended.

The peninsula has its own cash-driven strain of lycanthropy, never more than a full moon away, but a lot of people here always want to sit down with a soldering iron or scissors or a blank text editor window and put something new and cool into the world.

Monday, May 21, 2007

No Signature Required: It's the New Cash

Banks, credit card companies, startups, mobile phone companies, and whole bunch of other folks have jumped onto "future payment systems" in recent years -- focusing mostly on how to make small day-to-day payments more frictionless. So we've seen a dozen wireless phone wallets that, in the U.S. anyway, aren't very useful. RFID payment experiments at Mobile or McDonalds, and credit cards with chips of dubious value embedded in them.

When I recently found myself hoarding cash because it made certain purchases easier than using a credit card, I thought a little bit about the ease-of-payment problem. I came up with the following equation:

Ease(CreditCardPaymentNoSignatureOrPIN)
>= Ease(LoyaltyCard)
>= Ease(CashWithNoChange)
>= Ease(CreditCardWithSignatureOrPIN)
>= Ease(CashWithChange)

In English? The easiest game in town is swiping your card (or handing it over) and walking away (well hopefully you get it back). No signature, no PIN, no touchpad. Where does this happen? Starbucks and 7-Eleven are among the merchants supporting the Visa No Signature Required program for amounts under $25. It's a beautiful thing -- I can't imagine any easier way to pay, and I used to work on some of those RFID systems. At best they match this experience, but they can be much worse. The credit card gives me near perfect fraud protection, an itemized bill, and a short-term zero-interest loan.

A lot of businesses (Peets, Subway, etc.) haven't hopped on the bandwagon though, I suspect because the fine print is higher pricing on the back end. They'd love to avoid and card fees if they can, and they're happiest when they carry your cash for you. So they sell you a stored-value card and in exchange for letting them keep your interest and unspent funds, you get a swipe-and-run experience. This approach also has the drawback of requiring an extra card for each vendor, more of a hassle than pulling out a single Visa card.

After this, a cash transaction where no change is involved is fast and painless. You can pay and run, and cashiers love not having to count or give out change. Pricing in round numbers (think parking garages or ballparks) eliminates most change. Much is made of the supposed "anonymity" of cash. But that argument applies only to illicit transactions. Any transaction you do in person with an established business is bound to be on camera and timestamped these days, so you can be tracked even if you pay in cash.

Then you have credit card purchases with a signature or PIN -- my principal method of payment. This sounds easy until you're handed a card and a receipt to sign and return at a parking garage on a windy day. Aaaargh.

Lastly there's old fashioned cash with change: pain for all involved.

The big opportunity here is for banks and other credit-card issuers to cement their lead in the payment industry by pushing hard to expand the No Signature program. As it is, there is vastly improved data transmission infrastructure compared with what existed when credit card protocols were designed. The Obopays and Speedpasses, not to mention alternative credit card entrepreneurs are all over it. But the same data infrastructure could let Visa vastly extend No Signature without the fraud risk this would once have entailed.

Thursday, May 17, 2007

Flight Data Button 0.5 for Outlook

I've spent a little time working on an Outlook add-in for putting flights in my calendar. A few weeks back, I took a trip and wanted to be able to pull up flight status on my phone, without keying in an address and surfing, or installing an app like Skip. (Skip is great, but was never fully implemented for Smartphone.)

 So I put my flight into Outlook as a calendar item, and put a link in it to FlightStats Mobile, for my specific flight. FlightStats is the premier flight data provider in the U.S. -- many airport flight boards actually get their data feeds from FlightStats. Now, when my phone syncs with Exchange, the flight item comes onto my phone along with a quick-click link for status.

I decided this is a useful thing to automate, since any system that syncs Exchange to a device (DirectPush, Blackberry Enterprise Server, Moto/Good) would carry the link. But I was frustrated that I needed to key in the flight times, and I realized that should be automated too. To top it off, I foolishly ended up booking an appointment during time I needed to be driving (but which showed "free" in my calendar) -- so I figured my "automation" widget ought to add the travel time to and from the airport, and the time waiting at the airport before departure.

Using OpenKapow, I built a web service that scrapes flight schedule data. Assembling a FlightStats link is almost straightforward (getting to the individual segment within a flight number turned out to be tricky). And integrating to Office is delightfully simple thanks to great templates that take all the work out of it so a lazy sod like me can just write business logic.

I've called the addin "Flightify" since, to use it, you select an appointment in your Outlook calendar (where you've previously stuck some basic flight info), click the button, and the plug-in "flightifies" the appointment.

Here's an example: you start with basic info like this:



Click the button, and select the additional calendar items you'd like:



And a few seconds later your calendar shows the sad reality of your travel day:



You can't see them, but the mobile links to realtime flight status are embedded in the body of the flight item, so it's ready-to-click on your phone.

Here's the project page with the download/install if you want to try it. Full source code is there too.

I wanted to make this more of a learning experience and use the Outlook Addin templates that ship as part of Visual Studio Orcas Beta 1. I could try out more of Orcas and easily produce both an Office 2003 and Office 2007 version of my button.

Unfortunately, the Orcas Beta includes project templates, but not all of the Interop Assemblies you need to build the project (Office COM libs are required as well). So to get it building I would have needed to install Office on the Orcas test machine (in my case a VM with limited resources, meant for testing VS CTPs). My recommendation to Visual Studio team? Ship stub DLLs that implement the relevant COM classes (perhaps they just log calls to a file) and all of the Interop Assemblies. That way, the machine where Orcas is running doesn't need to have Office installed and can still successfully build these Office project types.

A few final thoughts on the plug-in:

  • Since the web service calls run in the main thread, Outlook will freeze for a second or two while they're being made. Considering that Outlook freezes the UI thread all the time while doing its own built-in tasks, I didn't put a lot of time into a proper workaround.

  • I don't write a lot of Windows Forms apps, so I was pleasantly surprised that the snap-band positioning logic in the form designer allowed my dialog box to appear the same on both a standard and high-DPI display without my having to do anything special.

  • The automagical "Setup Project" builder was also great. I didn't really have to do anything, and it produced a nice exe/msi install, that includes registering my addin with COM via RegAsm.

Tuesday, May 08, 2007

OpenKapow Fun: Scraping an AJAX Site

I'm interested in web services which represent operations that make a persistent change in the non-web world. Like buying a ordering food or checking in for a flight. These capabilities exist as human-powered web workflows today, but rarely as remixable web services. Sooner or later, that's going to change.

Many of these services resist initial attempts at scraping and remixing because they contain AJAX elements such as scripts that rewrite the DOM. Scraping such a site is more than a little challenging, since you either need to analyze exactly what the scripts do and try to grab and run just the scripts you want, or else you need to emulate a Javascript enabled browser and then scrape the screen when the script is finished and the DOM is in the "right" state.

One tool that seems promising in the quest to tame these sites is the openkapow service host and its Robomaker IDE, which both work by hosting a Javascript-enabled browsing engine. The IDE combines this engine with a set of tag-finding and flow-control tools so that you can point-and-click your way to a script that automates the target site.

I've been looking for an excuse to build something transactional with Robomaker, and I hacked up REST services that execute a checkin or an offload ("un-checkin") for a passenger on a United Airlines flight. It worked for me on a couple of flights. But without having a large sample of itineraries that I could abuse in the testing process, I was a little uncomfortable with how the robot might handle some multisegment flights. The source (".robot" XML files) are available here though if you want to try it out or tinker. Seat selection would be an interesting and nontrivial feature to add...

So I reined in my ambitions a little and created a service to get flight schedules, in order to add automation to a small Office 2007 tool I'm working on.

The Airwise flight schedule page seems simple enough at first glance, but turns out to be one of those pages that uses script to write the DOM data that the user ultimately sees. That makes it a perfect candidate for ... RoboMaker!

It was straightforward to configure my robot to enter travel dates and airports into the form, click "go," and find the table with the results. What I wanted to do was look through the table rows, create XML snippets for the data, and package them up into a response.

But here's where my inexperience with RoboMaker and impatience got the best of me: once I got beyond the point-and-click part of automating the web page, I wanted to just write some imperative code to pack up my XML. Since RoboMaker is a Java app, I wished I could just write a micro-plugin for this stage of my robot in Java. I found the deep spelunking in dialog boxes, squirrelly regular expressions, and mediocre help docs to be frustrating.

Maybe the idea is to give me a taste of Kapow so I'll license their enterprise technology, which isn't free. Not sure about that. But I did know that I could dump the entire flight schedule table as the service response and deal with it on the client. So I selected to return the whole table content as "advanced structured text" (which basically translates into plaintext with newlines in between every table cell).

Although on the client it's trivial to parse the resulting data set and find what I want, I feel a little guilty about the ugliness of the XML response. You can view/use/download/edit the REST robot on the openkapow portal, and if you run it with the defaults you can see the mildly embarrassing chunk of XML produced (in the browser, the newlines in XML are ignored, so it looks even worse). A REST call looks like this.

I got over my issues with the service, though, and moved on to using the data for my Office plugin, which I'll post about soon.

Friday, May 04, 2007

Interaction Sequence Diagram for Google Web Toolkit

I've been doing some work with Google Web Toolkit. GWT is based on a cool model where the client-side and server-side code are both written in Java. The client-side code follows certain API guidelines which allow it to be compiled to optimized Javascript by GWT. Among the APIs that can be used is a pattern for asynchronous remoting, so that AJAX calls can be made and received in Java, with Java objects as arguments and return values (a bit like RMI). The marshaling and unmarshling, JSONizing and the like is done automagically. Nikhil Kothari has a similar technology on the .net side that lets you code client-side Javascript via C#. It is called Script#.

This model has a number of major strengths. But one weakness is that is not common, so it is not immediately familiar to developers. The interaction pattern can seem a little mysterious even with Google's doc set, debugging tools, etc. It gets more interesting when you consider that you might also be generating the original pages (the ones with AJAX interactions on them) via Java. (GWT does not require a dynamic page generation scheme at all, and can use static HTML.) In order to make this clearer, I wrote a sequence diagram which I'm posting because it may be valuable to other developers getting their heads around GWT.

The diagram shows three interactions. First, I'm generating my initial pages using the FreeMarker templating system. There are lots of other ways (like JSP for example). But here I'm using FreeMarker. This all takes place before GWT gets involved in the pages.

Next, I show how the GWT scripting gets running and loads the page specific code which will rewrite the DOM. At the end of this, the page is rendered the way the user will see it in the browser.

Last, I show how an AJAX interaction flows, including a call to an external web service on the back end -- e.g., if there is a "Load My Favorites" button on the page that results in a call to an external service and asynchronously returns with data to bind into the DOM.

I hope it's helpful. If I've left anything key out, let me know.

Click to enlarge / view:




Tuesday, May 01, 2007

Lunchrtime on Mobilecrunch

I was psyched to fire up the newsreader tonight, pull the latest mobilecrunch stories and see my own "mobile 2.0" food ordering site, lunchrtime, as the top story.

Photoshop notwithstanding, I can't resist including a screenshot while this is still the latest mobilecrunch post.



What? Why? ... check out the about page. Is this going to be the next twitter? Probably not, but if the AdWords revenue covers the cost of the web services, I'll be pretty happy. If you like it, have fun, and maybe add in some restaurants near you.

Meantime, if you're up for some geekery, one of the things I loved about building the site was leveraging so many pieces of the asp.net platform to make it a little less code, a little more action with a very small amount of effort.

The entire app includes only around 300 lines of code and some markup. The total time to build, including the user-facing functionality, some quick admin bits, and the micro cms that I use to upload and serve pages with scanned menus like this? something like 70 hours. Total. It doesn't look as slick as it might, but if you've read this far you know I'm a developer and not a designer.

Here are the (mostly) asp.net pieces I used so I could be lazy, do my day job, and get this running:


It's a blast -- I really don't feel like I need to do much besides wave the baton, and all this stuff just comes together and starts playing in Visual Studio.

There are a bunch of solid web platforms out there today aside from asp.net. But anyone who thinks .net is somehow cumbersome, un-agile, un-fun, or not suitable for rapidly building and modifying a modern web app should really log out of the groupthink.

Saturday, April 28, 2007

Minor Update to Notebarn

Sorry for the hassle, but I have a slightly new version of Notebarn up on the project page now, which you may want to download if you have the original.

There was small focus-related bug that would manifest when the user returns to Notebarn after an Exchange sync. I thought it had passed a test earlier in the week (before the initial release) but I must have gotten distracted and messed up the test, because the bug was back. It passes the test now, and focus works the way it's supposed to. Honest.

It allows over-the-air update-in-place ... that is, you just run the new CAB file from the project page on your device, and Windows Mobile replaces the old version with the new one.

Tuesday, April 24, 2007

Free Smartphone "Notes" with ActiveSync/DirectPush Support

A former Blackberry user, I'm now running Windows Mobile Smartphone on a Blackjack. I love most things about Smartphone. But I miss the Blackberry "notes" integration with Exchange and Outlook. I used the notes feature constantly, managing all sorts of unstructured lists, and I liked being able to work on them on the desktop and know the changes would be propagated to the Blackberry and vice versa.

So I decided to write a little notes application that would sync with Exchange. If you like this idea and want to try the app, but don't want to hear any more geekspeak, you can get the app and instructions straightaway from here.

If you're still reading, here's what I did... The Pocket Outlook Object Model, which is the first stop for manipulating Outlook/Exchange data on the Smartphone, does not support note items. I wasn't sure if the Windows Mobile MAPI APIs covered notes, and I didn't really want to go that route as a MAPI novice, having heard many MAPI integration tales, none of the pleasant.

The Outlook Web Client accesses notes via AJAX, hence there is a web service endpoint of some flavor that can manipulate notes (Outlook can obviously get this data via HTTP too, since it can be instructed to operate in that mode). I could have sniffed/scraped that interaction ... but I wouldn't the get DirectPush I was jonesing for.

I took an easier route, and chose to store my notes as delimited strings in the body of a Task called "My Notes"

Since Exchange, Outlook, ActiveSync, and DirectPush take care of syncing my Tasks folder, I don't have to worry about that. And Tasks are first-class entities in the Pocket Outlook Object Model, so reading or writing one in C# is about 3 lines of code.

This approach worked well. I built a UI for the Smartphone using TextBoxes, put in the parsing logic, and I was set. On the Outlook side (or Outlook Web), I just open up the task called "My Notes" and there are all my notes, delimited by the same string. I can edit them, save, and the changes are propagated.

Only two wrinkles showed up.

The first is that Outlook 2007 is lazy about syncing the Tasks folder with Exchange, at least when it's set up to connect over HTTP. I cut my app out of the loop completely when testing this, by running Outlook 2007 in one window, and Outlook Web Client in another window. Web client read and committed changes to tasks immediately, while in order to refresh tasks in Outlook, even restarting Outlook did not always work. So, bummer... for now, it's an FYI.

The other interesting bit was the syncing logic in the phone client. The goal was to have the data saved and restored (when updated from the Exchange side) as automagically as possible. I've commented the relevant code, most of which lives in the Notebarn_Activated event handler, so you can take a look at the source if you like.

Any time you switch away from the app, or edit a note in full screen mode, your notes are saved, and any time you switch back, if Exchange has updated the Task data but you haven't, your notes are reloaded from the Task. I've tested various approaches and this one has worked the best for me.

I hope it works for you too. The project page (with source) is here.

Thursday, April 19, 2007

When "All-You-Can-Eat" is the Wrong Plan: a Plea for Metered-Rate Software

Why can’t I license productivity software on a metered-rate basis?

I had a mini-project that required vector-art manipulation. The assets I was using were Illustrator files, and I felt Illustrator would be the best tool for the job. But I didn’t have a license for Illustrator. I’ve always wanted Illustrator, but not enough to lay out the big bucks … after all, I would only fire it up a couple of times a month. Ditto for things like Photoshop, QuarkXPress, Premier and lots of other neat tools. If only I could install them and license them on a usage basis!

Without this sort of licensing, the options include:

  • Use some substitute app which might not be as good, as useful, or industry standard
  • Obtain a cracked/pirated copy of Illustrator
  • Find someone with a licensed copy and go use his
  • Install a new trial copy into a virtual machine (kinda gray-market, and a bad option for heavyweight apps anyway)

With metered licensing, here are potential advantages:

  • I get to use Illustrator, becoming (hopefully) more productive
  • My company benefits from my productivity and from lower licensing costs than if I needed to buy a full license
  • Adobe benefits because I develop my skills on their app, strengthening its hold in the market, and I don’t go install my 90-day trial of this
  • Adobe receives revenue from me where otherwise they would not

The metered approach is a total no-brainer: I can have all the apps I want installed permanently (not 30-day trials) on all my computers. At a cost of few cents or a couple dollars, it’s easy to pay as I go… and if start using the app heavily, the bills add up to the point that it’s clearly cheaper to buy. Maybe the publisher is even nice enough to apply some rent-to-own logic, so once I’ve dropped a few hundred buck, I am offered a discount to buy a permanent license.

It makes no sense to charge the same amount for Premier or Final Cut Studio regardless of whether the customer only edits a couple of videos a year, or is a professional editor who makes a living with it. One approach is for a publisher to create lots of SKUs at different price points for different user levels (Visual Studio Express Editions, Standard, Professional, Team System, Tools for Office) but that puts a huge burden on the publisher. Just let the users install the Ferrari version, and charge ‘em for what they do with it!

The infrastructure is already there — most of these apps are available on some kind of trial basis, and the entire install can be downloaded from the publisher’s site.

The per-copy tracking infrastructure is there for many publishers — activation codes are commonplace for expensive software.

Micropayments? Aggregate the charges on my “Microsoft” or “Adobe” or cross-industry-pay-per-use account, and bill me every quarter or whenever the total is high enough to justify it.

Tracking my activity in the app? That’s easy enough (LexisNexis has done this for a long time). Don’t charge me per minute or session, that encourages me to shut down the app, and makes it really expensive for a newbie to learn. Charge by use case: if I do something that every freeware clone also does, it’s cheap… but if I’m hitting the killer differentiating feature, whatever that is, make me pay.

This is free money for software publishers. Folks who absolutely need the app will already have it (hopefully legally), while pirates just bittorrent a crack. The metered system works for all of us in between, and I think that’s orders of magnitude more people than the publishers even imagine.

Tuesday, April 17, 2007

O'Reilly Web 2.0 Expo: Thoroughly Unimpressive == Very Encouraging

I spent some time at the Web 2.0 Expo yesterday, and as tech shows go, it was pretty weak:
  • The show floor was obviously, painfully small, even for a one of the smallest rooms in Moscone
  • Some of the BigCo sponsors seemed detached and irrelevant
  • The "food and libations" where hard to find, hard to pry away from vendors, and generally in short supply
  • The genuine web 2.0 plays seemed like they weren't sure why they were here; they weren't adept at engaging those of us who wanted to learn stuff that's not obvious from 5 minutes on the website
  • The tooling companies got a ton of attention, and were not prepared to leverage the attention... I went back to one tooling booth no less than four times to try and get a demo and conversation, but they were in long one-on-ones and had no bandwidth and no "backup chatters" (the ones who typically try to engage you at a show, triage you, and then if you seem important go the extra mile to find you the Chief Architect or the VP of Foobar to talk to)
  • The companies trying to sell services (consultants) have not figured out how to get attention and relevance
Wow. That sounds real bad. But I was elated, actually, and not because I'm working on a secret new thing and I wanted to feel superior to some competitors.

Instead, I realized that web 2.0 and the traditional tech conference are at odds conceptually. They don't make sense together, and the fact that this was obvious so fast means the web 2.0 ecosystem has not in fact been corrupted by so much froth that it starts looking like 1999.

I was really thrilled to see that by this yardstick there's a whole lot more runway for web 2.0 innovation before this plane floats up and away.

Lemme run through that list another time and tell you exactly what I liked:
  • Small show floow? Who needs a show floor? Web 2.0 exists on the -- gasp -- web! It's good to talk to the humans at these companies, but booth square footage is unimportant.
  • Big corps seemed irrelevant? well, many of them are irrelevant ... a web 2.0 meme is they became irrelevant as this wave of innovation took hold: Pricey license to get started? Whatever. Enterprise web stack with more classes in it than my app has lines of code? (I'm not exaggerating, this is a true story!) Get real. Proprietary SDK with a restrictive license agreement? No thanks, buddy.
  • Not enough free food and drink? This means there isn't hot and cold running money just yet, and the folks who absolutely must have hors d'oevres aren't there. Web 2.0 is more about Promax bars and BevMo (or Costco) than about catering.
  • Real web 2.0 plays seem flatfooted in the "traditional conference setting" -- of course they do. The traditional tech conference is really a marketing-oriented event. These companies were on the cluetrain from the beginning -- their marketing is via their users, and their web forums and wikis (with employee participation) are the best part of a tradeshow everyday, without the nonsense. Their schwag is the free service you can use right off their website.
  • Tooling is going to be increasingly important, and the best tooling companies will get their stuff together as the market matures. I think these companies got caught a little by surprise, and still have to work out a way to charge enough to stay in business, without charging too much to... stay in business.
  • Lastly, the consultants. I believe there is a place for consulting in the new web world (after all, I work for a consulting firm) but the traditional pitch is going to have to change. There are a number of themes I think make real down-to-earth sense around web 2.0 consulting, but they'll have to wait for another post.
When JavaOne turned the corner (in a bad way) and started looking like this show, it was clear the excitement was overwith. Java is an enterprise-style ecosystem. (Not that you can't build small agile things in Java if you really want, but seriously, do you really want?) It thrived on enterprise-scale players making huge investments with money, hardware, teams, code. Tons of mid-size software shops flourished, selling apps that run $100 up to $800 a seat, and there was money in it because it helped build even bigger enterprise systems. Lots of money, lots of free beer.

When JavaOne went small, it was a symptom of a serious illness. But then the virus took up a home in web 2.0 like some kind of endosymbiont and here we are.

Monday, April 16, 2007

Out of the Naming Shadows

When I saw the link to Silverlight (the artist formerly known as WPF/e), I was thrilled that Microsoft is apparently starting to move toward more compelling product names. Remember the firestorm maybe 20 months ago (publicized by Scoble, though he was really just the messenger) over “Why can’t Microsoft products have cool names?” … Folks talked about the constant confusion over .net being followed by even more boring names like “Windows Presentation Foundation” and asked why “Sparkle” had to become “Expression Interactive Designer.”

At first it seemed that the Microsoft branding group got defensive, citing trademark issues, cultural sensitivity, etc. as reasons to steer away from stronger names. But now it looks like they’ve come around: first we found out that Expression Interactive Designer would be called “Blend” – this doesn’t redline my engine, but it’s definitely a step up.

Now “WPF/e = Windows Presentation Foundation Everywhere” has the much sexier name “Silverlight” which makes me want to go grab a wizard’s cloak and conjure something. That’s a pretty encouraging reaction for a technology like this one. Besides the fantasy association, there’s also the sound of “silver screen” cinematics or a spotlight, which works for this product as well.

Saturday, April 14, 2007

GrandCentral Heralds VoIP Apps (Fer Real This Time)

I've been using GrandCentral and Gizmo for about a month now, and I recommend everyone check them out. Why Gizmo and not Skype? mainly, because GrandCentral integrates directly to Gizmo without going out to a "PSTN call in number" and back.

GrandCentral is rockin'! OK, their "Beta" is a genuine beta -- I've had some calls drop, calls not go through, voicemail never pick up... they have some bugs in the software and some issues in ops. But it's still a fabulous service. And when something does go awry there's a real live human on the other end of a chat widget. She's helped me a couple of times and is a real pro. Not to mention the longer the beta goes on, the longer you can enjoy the full power of GrandCentral, including unlimited calling into the PSTN, for free!

The "one phone number to rule them all" concept has been around a long time. The question is when to stop being a skeptic and when to start believing. Photorealistic graphics, good color printing, network-based apps with rich interactivity... all were promised several times and several years before becoming everyday reality. I'm not perfect at figuring out just when "this time around" becomes the time it really works. If I were, I'd be a VC instead of a developer. But I believe the time is now for VoIP and advanced apps for VoIP. Why? Besides Skype, and corporate adoption of VoIP, I think when Verizon sues Vonage over questionable patents in order to put the brakes on, and people actually care, then the time has come. Just like mobile apps had clearly crossed the chasm when everyone worried about NTP shutting off their Blackberries.

I tried to go "all in" by making the GrandCentral number the only one on my business card (due to a clerical error it didn't completely work). With my desk and my cell phones both ringing for business calls a client or coworker would be guaranteed to find me whether I'm in a conference room, at my desk, or out for a coffee -- plus I wouldn't need to check my office voicemail remotely, or force a client to deal with "I got voicemail... I'd really love to get feedback on this issue now, but is this really important enough to call his cell?"

For me, the remaining question isn't whether these services can be hits. They can. The question is how to manage an enormous number of communications accounts each with its own fees. I have a landline (originally for DSL, now because it's still cheaper for local by nearly an order of magnitude than cell or VoIP calls); a cell phone with minutes and a seperate data high-end data plan; a Gizmo phone that offers some free calls, but mostly charges 1.9 cents per minute (if you're keeping score, that's lower than a cell phone but higher than a landline); and GrandCentral, which is free in beta but plans to charge for connections into the PSTN. And this doesn't even include the cable modem account that gets IP to my house.

Each of these services plays a specific role and they all dovetail together to keep me connected to pretty much whatever I want. But there has to be some way to simplify this picture for mass adoption. Unfortunately, the only players in a position to do this are large telcos or cable companies, and they aren't known for innovation or customer service. In the Bay Area, for example, Comcast -- which offers "bundles" of cable Internet, TV, and VoIP -- bought radio time to hawk photo sharing as their great new thing. This is San Francisco in 2007, for godsakes, gimme a break. I'm not taking sides with AT&T either, who would also probably be happy to take $200 a month from me to sell me around half of what I need.

The other question is how number portability applies to the new services, in case this time around turns out to be more like the last time around.

Wednesday, April 11, 2007

ASP.net DB-backed Micro CMS in 50 Lines and 5 Minutes

I was working on a small web app where one area was intended to allow users to publish their own content. This area was not going to be ready for a while. In the meantime, I thought, there should be some way for users to put pages up on the site if they are inspired to do so. Images, too.

There are great lightweight CMS apps just for this, such as wikis. But with asp.net and SubSonic, I put this micro-CMS up in about 5 minutes. If you need a little area with WYSIWYG editable web content and binary uploads (images, PDFs, etc.) you might find it useful. n.b.: for my site, the created pages are meant to be be publicly readable and writable. If you want to restrict access, you will need to make some adjustments for that purpose. So here's how to brew it up:

Step 1: Create a table in SQL Server 2005

CREATE TABLE DataObject (
[ID] [uniqueidentifier] NOT NULL CONSTRAINT [DF_DataObject_id] DEFAULT (newid()),
[TextContent] [ntext] NULL,
[ImageContent] [image] NULL,
[MimeType] [nvarchar](50) NULL,
[CreatedOn] [datetime] NULL,
[CreatedBy] [nvarchar](50) NULL,
[ModifiedOn] [datetime] NULL,
[ModifiedBy] [nvarchar](50) NULL,
[IsDeleted] [bit] NULL CONSTRAINT [DF_DataObject_IsDeleted] DEFAULT ((0)),
CONSTRAINT [PK_DataObject] PRIMARY KEY CLUSTERED ( [ID] ASC ) )

You'll notice a number of convention-over-configuration moves that let SubSonic do some of my work: Created/Modified On and By as well as IsDeleted.

The main data fields are TextContent as ntext (i18n clob), ImageContent (blob), and MimeType. The PK and ID is an autogenerated GUID.

Step 2: Create a web page for editing and uploading content. Grab FreeTextBox for WYSIWYG HTML editing. Then toss in controls:

<FTB:FreeTextBox ID="FreeTextBox1" runat="Server" Width="600px" />
<asp:Button id="SavePageButton" runat="server" Text="Save"
OnClick="SavePageButton_Click"/>
<asp:FileUpload ID="FileUpload1" runat="server" />
<asp:Button id="Upload" runat="server" Text="Upload"
OnClick="Upload_Click" />
<asp:Label ID="LabelForNewURL" runat="server">(none)</asp:Label>

Add line breaks and formatting to taste.

Step 3: Add some code-behind to save the page.

protected void SavePageButton_Click(object sender, EventArgs e)
{
object id = Session[Globals.PAGE_EDIT_ID_CONSTANT]; // add some code in
// Page_Load to grab this out of the request,
// and load it into the FreeTextBox instance
DataObject o;
if (id == null)
o = new DataObject();
else
o = new DataObject(id); // this is SubSonic foo...
//read all about SubSonic, which rocks!
o.MimeType = "text/html";
o.TextContent = MyHtmlUtilities.CleanUpHTML(FreeTextBox1.Xhtml);
// Remove anything we don't want, like scripts
o.Save(User.Identity.Name);
LabelForNewURL.Text = "URL is http://www.mysite.com/Object.ashx?id="
+ o.ID;
Session[Globals.PAGE_EDIT_ID_CONSTANT] = o.ID;
}

Add some more code-behind to save an uploaded file.

protected void Upload_Click(object sender, EventArgs e)
{
if (IsPostBack && FileUpload1.HasFile &&
FileUpload1.PostedFile.ContentLength < MAX_LENGTH)
{
String fileExtension = System.IO.Path.GetExtension
(FileUpload1.FileName).ToLower();
if (allowedFileTypes.ContainsKey(fileExtension))
{
DataObject o = new DataObject();
o.MimeType = allowedFileTypes[fileExtension];
o.ImageContent = FileUpload1.FileBytes;
o.Save(User.Identity.Name);
LabelForNewURL.Text
= "URL is http://www.mysite.com/Object.ashx?id=" + o.ID;
}
}
}

This code omits the definition of MAX_LENGTH, a limit to the length of uploaded files, and allowedFileTypes, a Dictionary<string, string> that maps allowed file extensions to MIME types, like so: allowedFileTypes[".png"] = "image/png";

Now you have file-upload, database storage, and WYSIWYG editing in around 20 lines of code and 5 markup tags!

Step 4: Create the Object.ashx handler that serves these pages and objects. Add a new asp.net request handler like so:

<%@ WebHandler Language="C#" Class="Object" %>

using System;
using System.Web;

public class Object : IHttpHandler {

public void ProcessRequest (HttpContext context) {
DataObject obj = new DataObject(context.Request["id"]);
if (string.IsNullOrEmpty(obj.MimeType))
context.Response.ContentType = "text/plain";
else
context.Response.ContentType = obj.MimeType;

if (!string.IsNullOrEmpty(obj.TextContent))
context.Response.Write(obj.TextContent);
else
context.Response.BinaryWrite(obj.ImageContent);
}
}

That's it! Of course if you wanted to build in more features here, it's easy to do all sorts of stuff, from adding an attribute for a document/file name, to sorting or searching the database table to generate product thumbnails, automagic menus or site maps, etc. Ok, including all the SQL, asp.net markup, and the C# (except braces) that's at least 51 lines.

Addendum: I had to monkey with line breaks to keep the code readable outside of RSS readers, so never mind the line counts, I think the code is fun and the point is made anyway.

Monday, April 09, 2007

Mobile RIAs with FlashLite - Evaluation

Flash Lite is a promising route to RIAs on mobile devices. Adobe has recently strengthened their commitment to reaching mobiles, including strong device support in CS3, and planning for 1 Billion Flash-Enabled Handsets. The chart in that post also suggests 2007 is the year when "Adobe addressable handsets" clearly cross the 50% mark. Commitment to move the mobile platform toward a Flex-capable and ActionScript-3-capable runtime has been announced as well.

Wow. That's great. So how well and how easily does it actually work? I set out to do a quick evaluation of getting an interactive network connected app up and running on Flash Lite.

For my target platform, I picked Flash Lite 2.1, 320x240, on Windows Mobile, for these reasons:

1. Since this spec lies toward the high end of the Flash Lite ecosystem, I knew that if major things failed on FL2.1 and a 200MHz+ processor, they would be very unlikely to work on downversion FL

2. Real HW-level emulators are freely available for Windows Mobile, something that's not true for many mobile phones

3. I own a compatible device, and when working with devices, at a certain point there's just no substitute for the real hardware

For my "application," I wanted to see if I could implement a couple of use cases for a mobile 2.0 site for ordering food. This seemed like a reasonable real-world use for a Flash Lite application outside of entertainment; the use cases involve retrieving an order list from the web site, letting the user choose one, and then retrieving relevant destination restaurants where the order could be sent.

First I sketched out a simple Flash app which used the MX components for the onscreen text boxes, lists, and buttons, as well as for the SOAP web service client. I targeted Flash 7 (FL 2.x is essentially Flash 7), and built. After debugging on the PC, I tried it in the
WM 5 Smartphone emulator
(best enjoyed splashed over this SDK).

No joy. The movie starts to play, but then seizes up and the standalone Flash Lite player gives this error message: "ActionScript stuck" in both the emulator and real device. The culprit seems to be the mx.controls.List class, which is either too complex for the runtime to handle, or else triggers some low-perf detection code meant to ensure movies stop running altogether before they run badly. My web service connection via mx.services.WebService and SOAP was causing a similar problem.

This wasn't looking good, since those components date back at least to Flash MX 2004, and the hope was that a FlashLite 2.x app could be authored more or less like an MX 2004 app. Googling around, I found that the MX UI components do not, in general, work on Flash Lite 2 (a few do, but the kit as a whole cannot be assumed to work). This leaves the old-school approach of custom writing the UI widgets as part of the movie (not a bad approach for something so small) or finding widgets that would work. Since I wanted to complete this evaluation quickly, I looked for a widget kit for FL, and found Jesse Warden's Shuriken Components (see also his presentation here). For my purposes, this was perfect. Easy to use, and ran without a hitch on FL 2.

Next I needed web service connectivity. By adding this
<webServices>
<protocols>
<add name="HttpGet"/>
</protocols>
</webServices>

to an ASP.net app's web.config, you can turn on (Lo)RESTful behavior in addition to SOAP. (This switch enables not just GET but a simplified XML response format.) Next I used XML.load in ActionScript and gave it the appropriate URL to GET. This worked great on the emulator and device.

Then I added a couple of lines of "business logic" in AS, to allow additional dynamic interactions, so that I could bang on it without worrying about caching in the Windows Mobile HTTP stack or in Cingular's WAP-gateway-proxied network.

So far, so good. These patterns (movie-based or Shuriken UI + XML.load for web services) should work well on the high end of FlashLite (Windows Mobile devices range from about 166 MHz to 520 MHz; I was using a 220MHz OMAP). The next step will be to find some more constrained implementations that still support a the FlashLite "application" content type (e.g. a Nokia S40 device with FL 2.0) and try it out.

Thursday, April 05, 2007

Samsung Brings Software Game?

I've started using a Samsung Blackjack recently, and it's a great device. I'm not gonna review it here, because there are tons of solid reviews out there, and whole blogs and fansites just on this product.

I want to talk about the interesting partnership to be observed among the companies bringing this product out.

Samsung brings fabulous hardware to the device, which is pretty much what we expect from Samsung. Cingular brings the marketing and enough data bands (GPRS/EDGE/UMTS/HSDPA) to allow limited simultaneous voice and data, which is a genuine differentiator and makes an impression the first time you receive and respond to an email while you're on a voice call. Microsoft brings WinMo 5 Smartphone AKU 3+.

Samsung, though, has gone beyond the usual OEM manufacturer role. In addition to the promotional web site and the basic drivers for the hardware, they've bundled a set of apps carefully chosen to complement the Windows Smartphone OS and improve the value and usability of the phone.

User feedback has identified a number of weaknesses in Smartphone, some of which are addressed now in WinMo 6, some not. For example, in the past, users have screamed that the core app set is missing some basic PIM apps like a notepad. Never mind that you can get notepads online -- that's a step beyond a lot of consumers. So Samsung hops in with a mini productivity suite to fill in the holes: an enhanced filesystem browser, a notepad, calculator, and bunch of other stuff.

The stock Smartphone home screen has taken a lot of heat, so Samsung codes up a handful of alternates with different information densities and usability features. Need to read PDFs or Office docs? Samsung has licensed and supplied a version of Picsel Viewer -- frankly the video quality and smooth experience on this product is better than the Smartphone shell; maybe Microsoft should buy those guys!

The partners seem to be bringing their A game to the overall ecosystem around this device too: according to CrunchGear, Cingular will unlock this GSM device for free; Microsoft is working with Cingular to release an OS upgrade to WinMo 6 this year; and Cingular jumped all over early battery complaints with a pretty straightforward process for snagging a free extended battery.

Without being overly optimistic and wondering if a major shift is happening in the smartphone world, why does everyone seem to be trying so much harder than usual in this particular collaboration?

Tuesday, April 03, 2007

Why Does Software Suck? Why Do You Think?

My friend Andy over at Security Retentive sent me this link to Cigital discussing a twist on the meme of "software does snazzy stuff but it's built like crap."

I want to add two words to the "software sucks" discussion: organizational dynamics. If you start every conversation about software quality, process, security, predictability, etc. with these two words, you'll be on the right track.

Look at technology as just one competency of an organization, then zoom out and look at the whole organization. Now ask "do I believe that in an effort demanding some amount of precision, control, and predictability, this organization can execute?" With many organizations it's immediately obvious that the answer is "no."

If that question seems too vague or unfair, then zoom back in and take a look at specific capabilities inside the company. Look at product management. Look at marketing. Look at HR. Can you keep a straight face while they talk their talk?

Put it this way: think of a company where you have observed "software is crap" in action, whether it's a software product they sell, some line-of-business software they rely on (managing their type of widget or service), or a horizontal product they use to deal with the world (CRM, accounting). Now think of their customer service, or marketing or another department. If you can't take their marketing seriously, or they preach "great customer service" while delivering something else (maybe of great value, but in any case accompanied by awful customer service), then as an organization they are fostering cognitive dissonance at a group level.

The ability to tolerate cognitive dissonance is necessary for most organizations in order to allow flexibility and to prevent entropy from creating constant crises. But more than the "magic amount" of such tolerance just translates to being too comfortable with corporate doublespeak and BS.

In any case, dissonance and software is a bad thing because the machines that run software are remarkably anal. Compilers are adamant about not tolerating dissonance in the scope of a specific application. You can slip some shenanigans in when you're working in a scripting environment, but eventually the gap will manifest somewhere. And when an "enterprise app" is made up of various subsystems and databases, organizational cognitive dissonance leads to "HAL Syndrome" -- the ailment of the computer in 2001 which eventually starts doing undesirable things because it has been secretly given two sets of logically incompatible inputs.

Basically, a necessary (not sufficient) condition for software not to suck is that the organization producing it must have the capability to know when it is being hypocritical or producing conflicting messages, to recognize there is a problem, and to set some priorities which can resolve organizational discontinuities. Without that self-reflective and real self-modifying capacity, the software output may sometimes work, but has no chance of being predictable, reliable, high quality.