Showing posts with label daily life. Show all posts
Showing posts with label daily life. Show all posts

Jan 28, 2011

The importance of the end-user experience: internationalization

A friend of mine always says: "I don't want more features. I want working features." This friend is also a big fan of Apple and the simple, clean, pleasant, intuitive user interfaces. In principle I agree with him (although I'm not an Apple fan boy), but I'd also like to add that software should work not only in its own little environment, but also in the user's environment.

I've ranted time and time again about the importance of localization and internationalization privately that I think it's time I express my opinion in the public. I'd like to pick on the Apple iTunes Store as an example and point out some of the reasons for my rants.

Here it goes...

Different country means different store.
Be it due to legal issues or some business strategy, Apple has decided separate entities to operate each store at the country level. So for instance, an Inc. operates the U.S. store, a B.V. operates the Dutch store, and so on. One thing worth of noting is that the content in each store differs. While the U.S. store offers games, music, movies, and so on, the Bulgarian store, for example, offers only a limited subset of the iOS apps that are available to U.S. customers.

Transferring from one store to another you ask? Not so easy. Buying a product in the Dutch store does not guarantee that you will receive your updates if you change to the Bulgarian or U.S. stores. Sure, you will get notified that your apps are out of date and a determined attacker may use them to compromise your email and private messaging... but in reality, the app you've installed has been purchased from a separate entity and is not available at the store which you are using. This brings me to the next point...

Your billing address determines your locale.
This is the fun bit in Apple's model. Everything is tied to the customer's payment card. Here is a trivial question: you're an expat living in the U.K., having just moved from Germany (thus having a credit card from a German bank), and are receiving your monthly statements in the Netherlands. Which locale of the Apple Store would you say you are using? The Dutch of course, your billing address is in the Netherlands.

Your locale determines your language.
Here's even the better question: what are the supported languages for your locale? English? German? Actually... Dutch is the only supported language in the Dutch locale. It's sad to see big companies like Apple deciding for their users that if a user receives his/her bank statements in a given country, then he/she surely speaks the local language.


So why am I sharing all this? Well... I for once experienced it as a user. It is not pleasant and it turns users away. Users deserve the right to use software at their own comfort level without being victims of engineering mistakes. Let's learn from this.

May 28, 2010

Last days in Amsterdam

These are my last days as a resident of Amsterdam. This morning I submitted my petition to deregister to Gemente Amsterdam. Starting in June, I will reside near the beautiful Swiss Alps.

Tot ziens Amsterdam und grüezi Zurich!

May 13, 2010

Jan 9, 2010

The Flying Dutchman

Some recent stats about my whereabouts during the past 3 months:
6 countries
7 cities
3 timezones
2 economic areas
5 currencies
21 flights
27 hours of flight time

Yep.

Jul 22, 2009

Phish me a Safari

Recently I decided to install Safari 4. The experience is quite nice, except I'm paranoid about phishing. Yes, I check the certificates of sites where I'm about to provide my user credentials. I check the validity of links before I click on them. I even use different browsers when browsing trusted and not so trusted sites (some might point me to this surf jacking article, but oh well).

In general, phishing is a concept that's been around for a while. It revolves around the idea to trick a user into performing an action while thinking he/she was performing another action. One of the mechanisms to do so is through obfuscating links inside a Web page. More on this can be found here.

Typically, Windows based browsers have been pretty good about revealing the URL of a link before clicking on it as this was a valid concern a few years ago (circa 2004/5). However, after switching to Mac I could say that I'm quite disappointed of not seeing any notification about the links I'm about to click on a page. In a way that goes against the secure by default concept that OS makers started adopting in 2003. Or maybe I'm just assuming too much from Apple?

P.S. - Of course, I can turn on the Safari status bar and everything will be fine; but then, would all users do the same?

Jun 22, 2009

Defining a leader

Recently I've found the following quote from this page:
The team of more than 600 professionally trained consultants is three times larger than that of any other competitor, and makes the company a leader in the constantly developing Bulgarian market.

So from a pure economic/business perspective, how do you define a leader? Is it in terms of sales? Is in terms of customers? Is it in terms of capability/throughput? Or is it simply in terms of head count?

The thought that provoked this post are simply this: many companies these days present themselves as leaders in something. Whether it's technology, ability to handle big projects, or throughput, everyone these days claims the to be a leader. As D says, they could be leaders in one thing compared to their competitors, but lack in something else.

I think marketing is trying to get a competitive advantage once again. ;)

Jun 6, 2009

Secure Exception Handling

Exception handling is an important part of building a secure application. Developers are often asked to pay close attention to the security context in which the exception handler executes as to ensure maximum robustness, both from performance and security point of view, of the application. The reason I mention this is a little ATM incident yesterday where a friend's debit card was swallowed in the middle of a transaction by the ATM. As my buddy provided his bank card, PIN, and withdrawal request, the ATM decided to crash -- resulting in a big red screen stating that the machine was out of order. After 3-4 minutes, while my friend was in touch with the bank's customer service, the machine restarted and started working as expected.

So what happened?
Based on the above observations it seems that the generic exception handler used in the ATM machine tells the machine to void the transaction and keep the card. There's nothing wrong with that. In fact, this seems like the most secure way to fail an operation without knowing the exact causes of this failure. However, this is where the flaw in this ATM actually is -- the gap between the source of the exception and the exception handler is too big. It's so big that the handler that catches the exception doesn't know what to do with it. This is where robustness fails and legitimate customers get pissed off. :)

Apr 2, 2009

Marketing in the IT

Gabe has an awesome post on using buzz words in marketing security products and services (which I think can be applied to the IT as a whole). The quote that I find really amusing is:
John’s UltraSecure Platform and Super AntiHacker technologies are the time-proven critical-acclaimed fast-reliant just-in-time cutting-edge self-healing on-demand value-added preferred choice for industry leaders and security-minded managers of today, just like you.

This is just sick!

Mar 30, 2009

When the human factor is of importance...

Lately I've been reading Nick Leeson's Rogue Trader, which talks about his experience during the bankrupt of Barings Bank. Although the book has not impressed me that much, it led me to a few thoughts:

  • How can orgs be better at deciding who their key personnel is?

  • How can orgs be better at managing their key personnel?

  • What can orgs do to better protect their assets, brand, and most of all their org?

  • What would be the most efficient mechanism for keeping real-time checks on org critical operations?

  • What can orgs do to encourage their key personnel to stay focused on the orgs goals?
These thoughts will produce various responses depending on the circumstances during which they're asked. However, it is good to think about these things once in a while.

Mar 3, 2009

Skilled happiness

J.D. Meier has posted a very good article on skilled happiness. The list of key take aways is excellent; however, based on previous experiences, I might add that people need to have more patience with their environment and have more faith in themselves and their overall success.

Oct 27, 2008

A bit of housekeeping

Greetings.

I've taken the liberty to update the layout of this blog a bit. This is mainly reflected in the introduction of a new list on right side labeled "Projects". Through this list I would like to unveil a bit more about my work by linking to some of the projects and products where I have been actively involved.

Mar 12, 2008

Joining Technorati

It seems like the time for me join Technorati has come. Therefore, by posting this link to my profile there, I certify the ownership of this blog.

Cheesy, eh? :)

Mar 6, 2008

I have a dream...

Surrounded by a group of Bulgarian PhD students last week, I began to wonder what could help the quality of research and academia in Bulgaria. Moreover, I began to wonder what can I do to improve the academic environment there.

Realistically speaking there's quite a lot of research to be done within the computer security field, so establishing a research team in that area is not impossible. This said, there are 3 major factors to consider while planning this out:
  • Vision. The first few ideas in this area involve building (if possible) on the established research trends in the virus labs at the Bulgarian Academy of Sciences. This will primarily involve establishing mechanisms for better monitoring, analyzing, and preventing outbreaks of malware. Second, invest time into researching and developing methodologies and tools that will aid the security community in various aspects of the software development life cycle. Lastly, the works of this research group should be used for raising the security awareness throughout the Balkan region.

  • Human Resources. In a talk a few years ago, Larry Page from Google said that the most interesting research happens where people are eager to learn new things. As I was once an undergrad doing research work, I really believe that any such research should involve any student (grad or undergrad) eager to learn. Given the right motivation, I really think that student will excel in this area.

  • Funding. In my personal opinion, the best way to keep any such group moving forward is to use independent funding channels such as grants or corporate sponsors. At this point I'm under the opinion, that for the sake of science itself, it is better that funding is as independent as possible from any of the already established institutions.

Of course, this is just a dream that I have. :)

Feb 17, 2008

Tarhana ftw

Over the past 3 weeks I was able to see twice the famous Bulgarian musician Theodosii Spassov. Although both events were held at the Bimhuis in Amsterdam, the line-ups were quite different. For the first event, Theodosii was accompanied by Tarhana, a local group composed of several young musicians, most of whom were from the Balkan region. This last bit was the decisive factor in shaping the group's musical style. During the second event, Theodosii performed in the company of Van Merwijk's Music Machine, a line-up of seasoned Dutch musicians who seem to have a bit of a soft spot for Latin and Carribean music.

This is where the difference in both performances is. Although Theodosii has turned the kaval, his main musical instrument, into an unique jazz instrument, most of Theodosii's works are derived from the Bulgarian folklore, which entails melodic, easy to follow music that allows the listener to establish a rythm and keep with it. This said, it was Tarhana that provided the better musical support, which enabled Theodosii to show the strong sides of the kaval.

Dec 23, 2007

The Shady Side of the Bulgarian Police

The writing of this post is provoked by the impudence of 2 uniformed Bulgarian police officers to accept a "package" in the middle of a street full of busy Christmas shoppers. See the attached map for more information on the location of the drop.



In the past few months I've heard of many cases where crooks would team up with police officers to support their exit plan when "ops" turned sour. The majority of the stories followed the pattern where a couple of malicious individuals would attempt to shake a few (hundred, maybe thousand) bucks out of unsuspecting individuals by sending the victim into a psychological shock through fabricating a close relative's misfortune. Such scams are usually based on a tragic story that persuades the victim to help their "relative" financially in an urgent manner. Because the information has to be accurate, the thieves would need to do quite a bit of data mining to ensure their information on family tree, the location of family members, etc. is up-to-date. Once everything is checked for and the initial shock is initiated, the victim simply becomes a puppet for the crooks.

How can info on family relationships be obtained? In Bulgaria this is not all that hard:

  • for starting, all Bulgarian names are of the pattern <first name> <father's first name> <family name>.

  • despite the Law for the Protection of Personal Information, a lot of the personal identifiable information is widely available on publicly accessible documents (for instance, digital certificates issued by the government-owned certificate authority). :)

  • since 1977, Bulgaria is running ESGRAON, a system for collecting personal information on each individual living in Bulgaria. Information in the system includes the individual's personal identifiable number, full name, nickname, citizenship, birthplace, family status, records on his marriages, etc. Bribing the right person may grant an attacker the necessary access.


What is the role of men in uniform in these scams? It is simple, if an "op" is foiled by suspecting victims, the men in uniform are to a) stall a possible arrest if possible or b) ensure a release from jail within 48hrs of arrest (search bulgaria+corruption in google for specific cases).

Although I'm not sure whether the actions of those 2 officers are related to this popular as of late scam, I'm quite disappointed by their impudence. In my eyes, those 2 are a disgrace to society.

Nov 19, 2007

Lessons Learned: Train Travel

This past weekend Alis and I decided to take a trip to London. Because we made this decision a few days earlier, we decided to take the Eurostar instead of flying. Good choice... the train leaves from Bruxelles, so we have time to buy some Belgian chocolate. Because the Eurostar was departing at 12pm, we had to make sure to leave Amsterdam early enough so that we're at Bruxelles-Midi by 11.30am. We barely made it, but it's important that we made it (yep, tickets were non-refundable)! This produced the following lessons learned:

1. Never trust public transport. If you think you'll save time by taking the bus (especially at 6am on a Saturday morning), no you won't!
2. Run! :)
3. Don't trust the railways too much either. Give yourself enough time in case your connection train stops in the middle of the highway 3 minutes before your next train departs from the next station.
4. Pray that your next train has a 10-15 minute delay.
5. Double check the departure times for your connections. It might save you some nerve-wrecking situations. :)

P.S. - Schiphol is under construction for 3 of their platforms, so that's why points 3 and 4 occurred.

Oct 6, 2007

Weekend Project (part 4)

Although being busy over the last few weeks, I've decided to post a continuation to the "weekend project" series. This last clip encapsulates the majority of my trips throughout 2007. The images in this clip are taken in the Netherlands, Belgium, and Bulgaria.