Monday, 16 November 2009

How to learn to stop worrying and love the Internet

I didn't mention it on the blog at the time, but in October I spoke at the Future of Technology in Education conference organised by ULCC. In How to learn to stop worrying and love the Internet I spoke about how universities must adapt in a global networked world. I covered many of the themes I'm passionate about and try to explore here - network effects, digital literacy, open resources, and thinking outside organisational boundaries.

I've also just heard that my proposal to speak Networkshop 38 has been accepted, so I'll be revisiting these themes in Manchester at Easter, perhaps with a more technical bent to suit the audience. In the meantime the fote video and Slideshare slides are online.

Thursday, 12 November 2009

Cloud Computing, Security & Reputation

I read this piece by Bruce Schneier: IT Security in the Reputation Economy. It's a very interesting argument from one of the most respected IT security professionals around.

Bruce starts with the common position that computing is now a commodity. Price and trust as the two factors driving sales of a commodity. Many IT services are free (for consumers at least, and also in education) so that leaves trust. As IT commodiditizes further providers are incentivized to protect their reputation by improving security to greater levels than their customers would demand on their own. Why? An individual company can afford to lose their own data, but no service provider can afford to lose their customers data, as soon after they will lose their customers.

Thinking of universities as service providers, this makes me think we should give greater protection to personal data (eg student databases) than to confidential data (eg financial reports). More generally it is interesting to reflect on two recent cloud computing stories in this light.

First the disaster which befell Sidekick users. Sidekicks are (or were) a popular brand of smartphones in the US. Users had their contacts, photos, appointments etc stored on Sidekick servers, with only transitory cached copies of the device itself. In a spectacular database failure the data vanished. Originally it was announced that all data had been lost with no possibility of recovery, although some has now been found. It is a major embarrassment for T-Mobile and for Microsoft (who acquired Danger two years ago). Perhaps Microsoft will now redouble their efforts to ensure nothing like that can happen again.

Secondly, Google announced a 'government cloud' to attract US federal government customers. It will operate only from Google data centres in the US. They are aiming for accreditation under the Federal Information Security Management Act (FISMA). There are no customers signed up yet, but it is good that Google are trying to demonstrate their trustworthiness, and in particular are taking public sector concerns more seriously. How about an EU government cloud, Google?

Bruce highlights one problem with his argument - markets only work if customers have accurate information. Therefore service providers have a motivation to hide their security problems. Not good. My problem with the argument is that IT may be a commodity, but not to the same extent as electricity or water. Switching from one cloud provider to another is too difficult. Lock-in, as ever, bedevils the IT industry.

Getting back to universities again: my purely personal view is that the case for moving student email to the cloud is now almost overwhelming, but that the trust issues (are the US/Chinese/French governments reading my email??) are currently too great for us to do the same with staff email. If Bruce is right about the reputation economy expect Microsoft and Google to work hard improving our trust in them. In a couple of years time we may think differently - especially if other Russell Group universities decide to make the switch first.

Tuesday, 10 November 2009

Should I buy a laptop or a netbook?






































Criteria
Laptop
Netbook
Battery life2-3 hours6-8 hours
Screen sizelarge screen, 13" - 17"
(good for presentations, spreadsheets, multitasking, anything at all)
small screen, 9"-11"
(OK for email, web, word processing, one application at time)
WeightHeavy, 2.5- 3.5 kg
(heavy enough to notice, too heavy to carry every day)
Light, typically 1.1 - 1.3kg
(light enough to carry everywhere and even run for the train)
ProcessorHigh power processor. Few things need a powerful processor, but it is necessary if you want to edit photos, edit video, or play the latest gamesLow power processor (fine for everyday use such as word processing, web, Youtube)
KeyboardFull size laptop keyboardReduced size keyboard (90% of laptop keyboard size)
DVD DriveBuilt-in DVD drive (can watch DVDs)No built-in DVD Drive, have to connect an optional external USB drive
Price£350 - £900£200 - £350





In summary:

Get a netbook if you value convenience and mobility. The light weight and long battery life mean that you can have it available any time, anywhere. However the cramped screen and keyboard mean that you won't want to use it for long periods, and will turn to a desktop or laptop for prolonged use. My personal favourite netbook at the moment is the Asus eeePC Seashell 1008HA, which has a great combination of weight, battery life, size and slim design.

Get a laptop if you want a workhorse which is comfortable for extended use. It could be your main computer and will do almost anything. You'll use it mainly in a fixed location but it is too heavy to be really portable so you will carry it with you only occasionally. You can use it for long periods, as long as you can find a power socket. Good examples of laptops: The Toshiba Tecra range (for business) or Satellite Pro range (for consumers).

There is a third category: the ultraportable. These have larger screens than netbooks, but longer battery life than laptops. They are not as mobile as a netbook but are more powerful. Until now they've been expensive (upwards of £1000) and aimed at those few top executives who can afford them. Typical examples are the Toshiba Portege range or the Macbook Air. However prices are now coming down, with models based on Intel's new and cheaper CULV (Consumer Ultra-Low Voltage) chip design coming on sale.

Any portable computer will always be a compromise between mobility, functionality, and what you are prepared to pay. The important point is to decide what is important for you.

Monday, 2 November 2009

Unified Communications - a vision from the snake oil salesmen

I've been reading a report from one of the major IT market research firms on what they (and many others) call Unified Communications. They are refreshingly rude and realistic about the state of unified communications today (everyone is evaluating but nobody is deploying, standards are ill-defined, it is unclear which vendors will end up on top, benefits in hard financial terms are difficult to define). However they paint an overly rosy picture of Unified Communications by 2015.

There is overwhelming marketing hype over unified communications and it obscures how communications works. I prefer to think about Integrated Communications. Today for most people integrated communications means email, address books, and calendar. I might want to use all of those in one interface, but it doesn't mean I'll stop using all my other communications tools.

New communications methods arise rapidly, seemingly out of nowhere - think of SMS, Facebook & Twitter. People adopt a new communications method because other people they want to talk to are already using it, not because it has come bundled with something else. Gradually more communication methods will be integrated into a single interface or available on the same device (a web portal or smartphone). This will happen slowly, as the vendors can't keep up with the pace. We should take a tactical, progressive approach. We will never reach the nirvana of Unified Communications that the industry would like to sell us.

There is remarkably little pushback against the unified communications marketing spiel, but there is some. Nick Jones of Gartner (not the research firm I mention earlier) is as ever insightful and refreshing: see his blog post I hate Unified Communications.

Monday, 12 October 2009

Should universities be OpenID providers, consumers, both or neither?

JISC commisioned a report on OpenID which was published last December. There were comments at the time, in particular thinking about the differences between Shibboleth and OpenID. Since then many more providers have announced support for OpenID in some form, but I'm not aware of much activity within UK HE.

One criticism is that OpenID providers typically give no guarantee that a user is who they say they are, so we wouldn't want to use it to authenticate resources of real value. However a university could use it as a mechanism for public resources - for example external users could log in with OpenID to comment on a public university wiki.

I think there is more benefit right now in us becoming an OpenID provider. This is a way to "internalise external web services". When experimenting with Web 2.0 services I often find that colleagues are reluctant to try something. An important reason given is that remembering another username and password is a hassle. It's a fair point. We've worked hard to combine internal university services into one single sign on, and expecting different logons for external services is a large step backwards.

Notable services which allow you to log in via OpenID include:
  • 37signals.com - several web services including HighRise simple CRM
  • Zoho Office - web-based office software
  • comment on blogs at Blogger (but you still need a Blogger/GoogleID to create a blog)
  • Log in to Facebook via OpenID (but you need to have created a Facebook account without OpenID first)
Unfortunately that's almost it, out of what I would call notable services. Other organisations make the same judgment as us - there is more value in being an OpenID provider than an OpenID consumer. They don't want to lose the direct customer relationship. It tends to be the less established companies that fully support OpenID. 37Signals produce excellent webapps but are quite a small player. Zoho is also excellent but plays second fiddle to Google Apps. Those are two of the better companies who are OpenID customers. If we integrated their webapps into our portal I'd be happy that they aren't going to disappear overnight, but I would worry about a lot of the others. I worry when looking at the OpenID directory that I've never heard of most of the sites on the list.

None of these popular web services allow you to log in with OpenID:
  • YouTube
  • Flickr
  • Slideshare
  • Evernote
  • Eventbrite
Due to the importance of network effects I firmly believe you are better off using the market leading Web 2.0 services. I wouldn't encourage staff or students to use a Flickr clone just because it does OpenID. Building university services that tie in with Flickr itself is more likely to be successful, as that is where the content and users are already.

So what should we do? I think there is benefit for individual universities in becoming OpenID providers.
A mechanism for staff and students to comment on externally hosted blogs under their university ID sounds useful. We could even let students log on to Facebook through their university portal - or would that horrify them?

We could become providers at a national level by creating a gateway between OpenID and UK Access Federation, but which acts the opposite way round to the existing gateway. Should we start to think about reconstructing UK Access Federation on top of OpenID?

Or is all this just too soon - should we sit on our hands a little longer and hope more OpenID consumers emerge?

Tuesday, 25 August 2009

How to make your social software succeed

A colleague recently pointed me at Microsoft's Community Clips. It is a community-driven website where users share training videos about Microsoft Office. Why, he wondered, would anyone want to freely document Microsoft's profit-making software?

I was intrigued, so I had a poke around. It didn't look like a vibrant healthy community to me. The most popular featured videos had all been added over a year ago and there was nothing at all within the last 30 days. I then played a few clips. Each video started with a banner "Attention! The Soapbox service will be discontinued as of 31st August 2009!".

No surprise then that Community Clips has the aura of a ghost town. Soapbox launched in 2006 as Microsoft's equivalent to YouTube, and it powered Community Clips. On July 21 2009, MS announced the demise of Soapbox, and on 31st August it will vanish.

A sad story, but despite many such examples I'm sure that collaborative, social Web 2.0 services are here to stay. I expect the audience for this blog will agree with me, but many people within HE remain unconvinced by Web 2.0. If asked I point them at Facebook. Some thought (still think?) it is a passing fad. The hype may have peaked, but at Bristol our student IT survey 2009 shows that more students are using it than in 2007.

Ah, they say, but we did that once. Our organisation tried a project with this social software thing, and it flopped. So it's all a bit pointless isn't it? Well no. Most social software experiments don't work out. I've launched one or two of them myself (so long ResNet Chat!). Suw Charman-Anderson has a great piece explaining why most social software doesn't work out, why this is the normal state of affairs, and not necessarily a problem.

For every success like Facebook, Flickr or Youtube there are another dozen similar ventures that flopped. Why do some fail and others succeed? If you can understand why then you have the best chance of stopping your service becoming another Soapbox.

This fell into place for me through reading Here Comes Everybody by Clay Shirkey. Two examples Clay gives are Linux and Wikipedia, and he draws out three rules for social software: the plausible promise, the effective tool, and the acceptable bargain.

Linux and Wikipedia were both announced to a relevant mailing list of like-minded people who might well contribute. They were intruigued by what the project offered, it gave them a plausible promise - something they wanted, but wasn't too ambitious.

Here is Linus' original Linux announcement from 1991:
I'm doing a (free) operating system (just a hobby, won't be big and
professional like gnu) for 386(486) AT clones. This has been brewing
since april, and is starting to get ready. I'd like any feedback on
things people like/dislike in minix, as my OS resembles it somewhat
(same physical layout of the file-system (due to practical reasons)
among other things).

I've currently ported bash(1.08) and gcc(1.40), and things seem to work.
This implies that I'll get something practical within a few months, and
I'd like to know what features most people would want. Any suggestions
are welcome, but I won't promise I'll implement them :-)
Linus says "this is just a hobby"! People liked this approach. If it had been a big commercial project people wouldn't have been attracted to join. I give you my labour for free and you exploit it, giving nothing back isn't an acceptable bargain. Group of hobbyists together, sharing under a free software licence, is.

Wikipedia illustrates another point - make it as easy as possible to get started and to use it. This is completely crucial - even a low barrier is too high. Anybody can edit wikipedia, you don't even need to sign up for an account. You must provide effective tools - lightweight, simple, that encourage, not discourage collaboration.

Inspired by Clay Shirkey and others, here are my suggestions for successful social software within a university:
  1. Seed your site with useful, relevant content, so it isn't starting from a blank slate. Content you can't get anywhere else is great if you can manage it. This helps make it obvious why the service is useful.
  2. Announce it simultaneously to a large, relevant group. Promise something useful but not undeliverable.
  3. Make your tool extremely easy and effective to use, so your users can get results quickly.
  4. Use single sign on with an ID most people will already have. Your University ID is great, or perhaps something else from a huge common provider like Microsoft or Google. Use no sign in process at all if you can possibly manage it.
  5. Don't make it too official/corporate/commercial - people need to share ownership of the tool. They won't contribute if they feel they are being exploited and there is nothing in it for them. Students may trust the Students Union more than the university. Consider getting the support of your union and putting the service out under their branding.
  6. Nurture your first few users. The founders of Flickr commented personally on the photos of their first few thousand photographers, to make sure they'd come back.
  7. Build your social software on top of a larger network, in order to benefit from the larger network's beneficial network effects.
I'll expand on this - especially on how you can pick the winners and avoid the losers amongst third-party services - in a subsequent post.

Wednesday, 5 August 2009

A domain driven design for the University Web

I wasn't at IWMW2009 last week, but I've been reviewing the conference thanks to a colleagues writeup and slideshare. The highlight for me was How the BBC makes websites (also in a more accessible text version BBC Radio Labs - how we make websites).

In the words of Michael Smethurst, "there's very little original thinking in here. For those familiar with the concept of one web, the importance of persistent URIs, REST, Domain Driven Design and Linked Open Data it'll probably be old news."

Michael is being modest. Personally I was familiar with some but not all of those. Even the most basic concept - having a single, unchangeable URI for an item - is rarely implemented. Bringing them all together makes the BBC Programmes site a powerful demonstration of how to do the web properly. More importantly it is a pleasure to use.

We are currently rethinking the University's web strategy and CMS requirements. To do this step back and think not about the web but about the activities the university undertakes.

What do universities do? They teach and they research. I'll use real-world data in two examples to show what I mean.

First teaching. Here's a course hierarchy:
(this would be clearer as a table or diagram but I'm limited by the tools in this blog)
  • Course Family: LLB Law
  • LLB Courses: LLB Law (UCAS course code M100), LLB Law with Study Abroad, LLB Law with Chemistry, LLB Law and French, LLB Law & German
  • year started the course: 95, 96, 97, 98, etc
  • Programmes of Study: 1st year, 2nd year, 3rd year
  • Year One Units: Law of Contract (Unit Code LAWD10008), Law of Tort, Law and State, Constitutional Rights, Criminal Law, Law of Property
  • Law of Contract Lectures: lectures 1 though 6
  • Lecture 1: introduction to contract law
The URI for that lecture would be http://www.bristol.ac.uk/courses/law/m100/1999/year1/lawd10008/lecture1

Every level in the hierarchy has a web page with a permanent URI. So every course family, course, year, unit, and lecture has a webpage with a single, permanent URI. Ideally we would have a recording of the lecture but as a minimum each lecture must have a presence, at least a placeholder.

Now look at research. Think about web pages for each of the following (again real world examples)

Department of Computer Science
Computer Science Research Groups: Computer Vision, Cryptography, HARE, Intelligent Systems, Interaction & Graphics
Research Group: Cryptography
Cryptography Staff: Elisabeth Oswald, Dan Page, Nigel Smart, Bogdan Warinschi
Person: Dan Page
Dan Page: list of all publications
Publication: Manuel Barbosa, Andrew Moss, Dan Page, Constructive and Destructive Use of Compilers in Elliptic Curve Cryptography . Journal of Cryptology, 22(2), pp. 259?281. April 2009

URIs for the above would be

http://www.bristol.ac.uk/compsci
http://www.bristol.ac.uk/compsci/groups
http://www.bristol.ac.uk/groups/cryptography
http://www.bristol.ac.uk/groups/cryptography/people
http://www.bristol.ac.uk/people/dan_page
http://www.bristol.ac.uk/publications/dan_page
http://www.bristol.ac.uk/publications/2009/constructive-and-destructive-use-of-compliers

So every department, research group, person, and published paper has a webpage with a single, permanent URL. Even if the paper itself isn't available electronically it must still have a presence.

Note that in this case the urls do not follow a strict hierarchy as they did in the teaching context. Why? Hierarchies change. Right now the faculty of engineering is merging its departments into larger schools. The URIs for the research groups, people and papers should not change. Our internal organisational structure is completely unimportant in the web context. Breaking a web link pushes us lower in search engines, hides our research and damages our reputation. It should be avoided at all costs!

Each webpage should be about an obvious, real-world thing. If it isn't about an obvious thing, split the page up into smaller pages, until the subject of the page is now clearly one thing. Then give each thing a single URI, and make sure it never changes.

Simple really. Now how do we do it?