Epeus' epigone

Edifying exquisite equine entrapments

Showing posts with label OpenSocial. Show all posts
Showing posts with label OpenSocial. Show all posts

Wednesday, 9 November 2011

Our brains make the social graph real

Brilliant web essayist Maciej Cegłowski of Two Steaks and Pinboard fame has focused his considerable insight on the area of web standards I've been involved with for the past few years. You should go and read his The Social Graph is Neither now.

Maciej is spot on in his criticisms:

This obsession with modeling has led us into a social version of the Uncanny Valley, that weird phenomenon from computer graphics where the more faithfully you try to represent something human, the creepier it becomes. As the model becomes more expressive, we really start to notice the places where it fails.

Personally, I think finding an adequate data model for the totality of interpersonal connections is an AI-hard problem. But even if you disagree, it's clear that a plain old graph is not going to cut it.

Clearly you can't model human relationships exactly in software. Keeping track of a few hundred of them in all their nuanced subtlety is why our brains are so huge compared to other animals. As Douglas Adams put it:

Of course you can’t ‘trust’ what people tell you on the web anymore than you can ‘trust’ what people tell you on megaphones, postcards or in restaurants. Working out the social politics of who you can trust and why is, quite literally, what a very large part of our brain has evolved to do.

It is an act of hubris to attempt to represent such vital things as human relationships in a database, and those who have done so often do resemble Maciej's Mormon bartender - Orkut Büyükkökten, Mark Zuckerberg and Jonathan Abrams do seem to have made what danah boyd has called Autistic Social Software.

The thing is, people seem to find these attempts helpful. As Maciej points out, we're good at forming subcultures and relationships even around the most primitive of tools. He pokes fun at opensocial.Enum.Drinker.HEAVILY, but when we were compiling the OpenSocial Person fields, we found a high degree of convergence between the 20 or so social network sites we reviewed. Despite their crudity, the billions of people using these sites do find something of interest in them.

People choose to model different relationships on different sites and applications, but being able to avoid re-entering them anew each time by importing some or all from another source makes this easier. The Social Graph API may return results that are a little frayed or out of date, but humans can cope with that and smart social sites will let them edit the lists and selectively connect the new account to the web. Having a common data representation doesn't mean that all data is revealed to all who ask; we have OAuth to reveal different subsets to different apps, if need be.

The real value comes from combining these imperfect, scrappy computerized representations of relationships with the rich, nuanced understandings we have stored away in our cerebella. With the face of your friend, acquaintance or crush next to what they are saying, your brain is instantly engaged and can decide whether they are joking, flirting or just being a grumpy poet again, and choose whether to signal that you have seen it or not.

As danah says:

While we want perfect reliability for our own needs, we also want there to be failures in the system so that we can blame technology when we don’t want to admit to our own weaknesses. In other words, we want plausible deniability. We want to be able to blame our spam filters when we failed to respond to an email that someone sent that we didn’t feel like answering. We want to blame cell phone reception when we’ve had enough of a conversation and “accidentally” hang up. The more reliable technology gets, the more we have to find new ways for blaming the technology so that we don’t have to do the socially rude thing.

So here's to approximate, incomplete social web standards.

Posted by Kevin Marks at 23:56 No comments:
Labels: Faces, open web, OpenSocial, Social Web

Saturday, 13 November 2010

Firesheep, enterprise software and other broken models

There has been a lot of fuss about FireSheep, a browser plugin that show how easy it is to intercept packets on the internet, and masquerade as someone else. The idea is nothing new: EtherPeg—which intercepts wifi traffic and shows the JPEGs and other images passing by—is over 10 years old. Annalee Newitz wrote a Wired story on people packet sniffing in coffee shops back in 2004.

The underlying design of the internet means that you don't know who will be able to see any packets you send. If you care about not being snooped on, you need an encrypted connection from your computer to the one serving you at the other end. The best way to do this on the web is to use HTTPS, which all browsers support, and most servers support with configuration changes. It's not perfect, but it's good enough.

However, much of the advice following on from FireSheep was misleading or outright wrong. I saw several articles saying:

  • Avoid Open WiFi
  • Turn on WPA encryption
  • Use a VPN to tunnel the traffic into a server elsewhere

These techniques may protect for a while against those nearby you in the Café, but by not securing the whole connection, they just change who is able to intercept your communications.

The security model here is the firewall one - the notion that there are trusted networks and untrusted networks, and as long as you're inside a trusted one, you'll be OK. This is an obsolete worldview. When computers were large fixed physical entities with software controlled by a specialist, and networks were wires under their control too, this had some correspondence with reality, but it was always tenuous - others within the firewall could be running compromised machines; outbound connections could still leak data.

If you VPN into a company or service to mask your outbound connections, that endpoint is an attractive point of attack, as it has collected a set of people who think their data needs securing. There's a clear example of this in this NYT article about a hacker who lured his friends to use an FBI VPN to track them down and arrest them.

This worldview connects with two other themes. The US Government is trying to pass a law requiring ISPs to enable your communications to be intercepted. The UK government is also working on legislation on retaining all email and web traffic. Similarly, many companies monitor internet traffic within and leaving their secure networks for legal compliance and employee monitoring. Such mandated backdoors, like the VPN tunnel, become attractive targets for other bad actors - remember the Greek government being spied on through a legally mandated interception backdoor in the phones they used?

This week, I spent a couple of days at the Enterprise 2.0 conference, hearing how open standards like Activity Streams and OpenSocial are being used to bridge separate business information systems both within and between companies, with OAuth used to enforce corporate policy.

This seems anathema to old-line IT managers who assume that they dictate who gets to see what, but the pragmatic realisation that many business people have more powerful and connected computing devices in their pockets as phones than on their desks from corporate IT was in evidence at E2.0 at least.

This brought to mind the great conversation we had with Josh Klein on TummelVision last week, discussing his book Hacking Work - breaking stupid rules for smart results:

one of the most common hacks we found: jumping IT’s firewall and working around their restrictions and tools in open computing environments, then bringing the work back over the firewall and presenting it to bosses as if the corporate tools had actually been used.

Ben Horowitz's article on enterprise sales in TechCrunch today tries to justify corporate practices, even as he recognizes the inversion of the innovation flow.

What this misses is the underlying economic justification for the existence of a corporation in the first place - the economic theories that build on Coase's work saying that firms exist because transaction costs are lower within them than external transactions mediated by the marketplaces. Pettifogging internal purchasing rules should be subject to this test: does the internal transaction cost of approving and purchasing something exceed the value of the thing being purchased?

Reading Ben's explanation of how corporate salespeople help institutions negotiate their own labyrinthine processes, I couldn't help but be reminded of John Hagel's Big Shift model, (also discussed on TummelVision), which continues to show a declining return on assets for corporations.

The challenge we have on the web is to maintain the kinds of open-to-all interoperable standards that empower us to work round these creaking bureaucracies. If we delegate our online identities to a few firms operating proprietary APIs, that they can revoke access to, or decide who can call them for reasons of corporate strategy, the lowered transaction costs suddenly get very high again.

Doc Searls's work on VRM (this week's TummelVision) is all about making sure that we can retain agency over our own information. I expect to discuss this in depth at Defrag next week.

Posted by Kevin Marks at 15:21 1 comment:
Labels: Activity Streams, enterprise, firewall, OpenSocial, Tummeling, TummelVision, VRM

Friday, 20 February 2009

OpenSocial WeekendApps

I spent the evening at the opening of the OpenSocial WeekendApps tonight, and gave the opening talk, a 15-minute summary of the State of OpenSocial. Here are my slides:

The event looks very full of energy, and I wish I could stay all weekend, but I'm off to BarCampMiami on Sunday.
Posted by Kevin Marks at 22:13 No comments:
Labels: hackathon, OpenSocial

Friday, 23 January 2009

Notes on Charlene Li's Future of Social Networks SF AMA talk

Last night I went to an interesting talk by Charlene Li at the SF American Marketing Association -here are my twittered notes. See also, Charlene's slides.

says @charleneli: Theme is "social networks will be like air" - her better phrasing of my "Social Cloud" idea
says @charleneli: in future we'll say "wasn't it quaint that we had to go someplace to be with our friends"
says @charleneli: "I want Amazon to have a 'friend's reviews button on there - or anywhere else they could be"
says @charleneli: we'll have a feed of the presedential debates with our friends tweets on - like I did in 2004: http://bit.ly/IRCdebate
says @charleneli: universal login with OpenID lets you tie your IDs together, and sites can import friends from your networks
says @charleneli: I had to friend my co-author Josh 35 different times on different sites - Portable Contacts should save us from this pain
says @charleneli: Profiles where they are useful - eg LinkedIn profiles showing up in Lotus Notes via email
says @charleneli: your friends activities in context with GetGlue.com's plugin - Iron Man wikipedia page and IMDB page shows friends reviews
says @charleneli: 2 sets of standards exist Facebook's own protocols and the OpenStack backed by Google, MySpace, Plaxo, Yahoo and more
says @charleneli: advertising has evolved - content targetting for demographics; Search marketing for intent; behavioural targetting
says @charleneli: how many of you have gone to a social network site and remember seeing an Ad? or clicked on one?
says @charleneli: Who wants to be a fan of FiberOne on Facebook?
says @charleneli: people want to tell each other about things they care about - need new ads for this
says @charleneli: examples of new Ad types - branded virtual gifts, shown to you as your friends gave or received them
says @charleneli: SocialVibe has profile sponsorships that donate to your favourite charity eg colgate ad to leukemia
says @charleneli: the Tipping Point argued that there are influencers that can make a product go viral [I disagree see http://bit.ly/watts ]
says @charleneli: social graphs and interests, culture of sharing and online and email behaviour can create context for ads
says @charleneli: vendors who identify influencers include 33across, lotame, media6 degrees, unbound technologies
says @charleneli: network neighbourhood modelling in interesting - homophily is a good predictor for clusters - you are like your friends
says @charleneli: Google tracks who I email most - very useful to me: "In Google I Trust" http://bit.ly/BtvV
says @charleneli: Media6 identifies you by profiles you view on SNSs - shows ads to your friends based on your purchases
says @charleneli: Media6 gets 3-7x increase in response rates on banner ads through this homophilic targetting - no PII involved
says @charleneli: Influencer strategies are a misnomer, btu clustering works
says @charleneli: People will demand greater contol over when, where, how profiles + friends are used. Detailed permissions - a UX nightmare
says @charleneli: remember when people didn't trust callerID? Now if you turn it off, people won't take your call
says @charleneli: setting up lists of who can see your pictures is a pain - have to categorize people - reclassifying is hard
says @charleneli: there's a need to better articulate and detect sub-groups of friends so this is less of a chore
I pointed out the power of asymmetric friending eg http://bit.ly/publics and @charleneli and audience agreed that it reduces awkwardness
says @charleneli: people will pay real money for virtual gifts
[ChrisSaad @kevinmarks asymmetic is good, the term friending is not great. I prefer follow or subscribe ]
@ChrisSaad agreed "following" is a better term for this
Audience: when will people profit from us using their profiles? @charleneli says we all have our own CPMs
[clynetic @kevinmarks What is CPM?]
@clynetic CPM is marketingspeak for 'cost per thousand' - I suppose CPA ( cost per action) is better
says @charleneli: don't give up your social capital for short term gain me: don't be the Amway guy at the party
says @charleneli: behavioural targetting is often faulty, as behaviours change
says @charleneli: social media advertising experiments are waiting for turnaround
says @charleneli: GYM (Hotmail for M) will test social media integration with webmail
says @charleneli: Facebook Connect and Open Stack gaining traction with media co's
says @charleneli: Social shopping experiments start - we want our friends recommendations
says @charleneli: identify where social network data and content shoudl be integrated in your sites
says @charleneli: leverage existing identity and social graphs where your audience is
says @charleneli: get your privacy and permission policies aligned with an open strategy
says @charleneli: find your trust agents - in google I trust? do you trust facebook?
says @charleneli: the media buyers are still trying to buy demographics or content, not better targetting
Posted by Kevin Marks at 16:18 1 comment:
Labels: Charlene Li, facebook, marketing, Open Stack, OpenSocial, Social Cloud, social networks

Wednesday, 10 December 2008

My twittered notes on the Leweb Social panel

Platform Love: Getting Along - Panel

Panelists:

  • David Glazer - Director of Engineering, Google
  • Jeff Hansen - General Manager, Services Strategy/Live Mesh, Microsoft Corporation
  • Dave Morin -Senior Platform Manager, Facebook

  • David Recordon - Open Platforms Tech Lead , SixApart
  • Max Engel, Head of Data Availability Initiative, MySpace

Moderator: Marc Canter - CEO, Broadband Mechanics

Watching the 3 Davids, Max, Marc and Jeff talk social at LeWeb
says Marc Canter 'open is the new black' - and asks about the Open Stack
says @daveman692 google, yahoo, microsoft all building on the open stack - won't FaceBook become the underdog when openness wins?
Canter suggets OpenID will be the brand that ties the Open stack together
max of MySpace "what we're doing with these standards is moving the web forward - when the web hits a roadblock it routes round it"
max of MySpace:"90% of our users think of themselves as URLs so OpenID is a natural fit for us"
Dave Glazer: the goal is to let users do anything they want to, with others, anywhere on the web. OpenID lets you log in anywhere
Dave Glazer: openSocial solves a different bit of the puzzle - JS APIs to run the same app in different social contexts REST APIs web to web
says @daveman692 the web is designed to be distributed, and the Open Stack fits this model
Jeff of Microsoft: live mesh is built on symmetric sync - supports Open Stack, OpenID shipping, OAuth looks good, support PortableContacts
Jeff of Microsfot: we're evaluating the OpenSocial gadget container
Marc canter "we're putting all our balls into ev williams vice"
Jeff: we offer lots of languages. Marc: lots of ways to put our balls in your vice
Max: we support OpenID, Oauth, OpenSocial but you can too
Marc: anything good for the Open Web is good for Google
Marc Canter wants a URL for each Gmail? DG: each one does have that, but only you can see it
Dave Glazer: there are 3 classes of information: Public, Private and Complicated - users should never be surprised by who can see what
says @davemorin facebook wants people to have a social context wherever they go
says @davemorin FaceBook had to create a Dynamic Privacy model for FB Connect @daveman692 calls shenanigans - LJ had those in 1999
asks @daveman692 of @davemorin why are you giving microsoft access to all our email addresses wihtout asking permission?
Max of MySpace - we've shown that security and openness work together by using OAuth, and can revoke them from in MySpace
Dave Glazer: need to separate the technical levers from the social customs. technology can't stop people putting your bizcard on the web
says @techcrunch "call bullshit on facebook" - broke integration with google. FB don't want an open stack, they may be forced into it
says @tommorris how can MS be on the panel after the debacle of Office OOXML which wasn't open or XML?
says @dave500hats could we get contacts with certain features eg tennis fans?
Dave Glazer: there's an open spec process to define new attributes in the spec - if you want to add one go and propose it
Posted by Kevin Marks at 01:51 2 comments:
Labels: facebook, leweb, leweb08, OAuth, Open Stack, OpenID, OpenSocial

Monday, 8 December 2008

Cycling to new layers of freedom

Dave Winer used the public beta of Google Friend Connect to reflect on tech industry cycles:
A new generation of young techies comes along, takes a look at the current stack, finds it too daunting (rightly so) and decides to start over from scratch. They find that they can make things happen that the previous generation couldn't cause they were so mired in the complexity of the systems they had built. The new systems become popular with "power users" -- people who yearn to overcome the limits of the previous generation. It's exhilirating! [...]
The trick in each cycle is to fight complexity, so the growth can keep going. But you can't keep it out, engineers like complexity, not just because it provides them job security, also because they really just like it. But once the stack gets too arcane, the next generation throws their hands up and says "We're not going to deal with that mess."

Now, I may be a few years behind Dave, but I think he is throwing the baby out with the bathwater, or the stack out with the cycle here. Back when I started out, to get my computer to generate sound, I had to make my own D to A converter to attach to the parallel port, and for non-character graphics, my hardware hacker friends swapped the character generator ROM for RAM, and I had to code in assembler to swap the display data in time.

Now my son thinks nothing of mixing 10 polyphonic Midi tracks in an afternoon or editing hi-def video (and yes, it's on an OS I helped to make capable of that).

Dave's revolutionary impulsiveness has a germ of truth, but what really happens is that successful technologies become invisible infrastructure for the next things that build on them.

I no longer need to write assembler, heck I no longer need to write C code. Dave's very URL - scripting.com - shows how we have built up layers of utility to work upon.

HTTP, HTML, JSON, Atom and Javascript are infrastructure now. Our deepest role as developers is to build the invisible infrastructure for the next generation to take for granted, so they imagine new abstractions atop that. Dave did it with feeds.

What we're doing with the Open Stack — OpenID, OAuth, PortableContacts and OpenSocial— is part of this evolutionary cycle too. We're combining building blocks into a simplified whole that makes sense to people who want their websites to become social.

It comes down to what you can take for granted as the baseline to build the next exciting cycle on.

Posted by Kevin Marks at 01:35 1 comment:
Labels: OAuth, Open Stack, OpenID, OpenSocial, Portable Contacts, Social Cloud

Thursday, 13 November 2008

OpenSocial’s birthday today


OpenSocial Reach chart
Originally uploaded by Kevin Marks
Just over a year ago, we launched OpenSocial to the web, with a few example applications and a lot of potential. Now, a year on, over 600 million social network users can use OpenSocial applications in their preferred social network sites.
Then, applications had to be embedded in sites as gadgets, which makes the social context clear for users, but means developers have to write some Javascript, and can only run code when the user is looking at the site.
With OpenSocial 0.8 rolling out, the REST APIs mean that developers can integrate with social sites using server-side code directly, potentially delegating user registration, profiles and friend relationships to an already-trusted social site, and feeding activity updates back into them.
To do this, we are building an Open Stack, based on OpenID, XRDS-Simple, OAuth, PortableContacts and OpenSocial. By composing open standards in this way, we can make each one more valuable. The advantages of OpenID over email login in itself are not that obvious to users, but if the OpenID can be used to bring in your profile and contacts data - with your permission via OAuth - suddenly the added value is clear to users and developers alike. This connection was one of the exciting discussions at the Internet Identity Workshop this week - here's a video of myself, Steve Gillmor, David Recordon and Cliff Gerrish talking about it.
Posted by Kevin Marks at 15:57 2 comments:
Labels: OAuth, Open Stack, OpenID, OpenSocial, Portable Contacts

Saturday, 8 November 2008

Missing the point of OpenID

I'm puzzled by Dare's post on OpenID, as he is wilfully misunderstanding its advantages at each stage, and I know he's smarter than that. He gets it right that OpenID is a way to confirm that a user owns a URL, without the rigmarole required to do so for an email address. 

However, the then uses his unmemorable Facebook URL http://www.facebook.com/p/Dare_Obasanjo/500050028 as an example, rather than any of the memorable ones he actually uses and people refer to, such as http://www.25hoursaday.com/weblog/ or http://carnage4life.spaces.live.com/ or http://twitter.com/Carnage4Life

DeWitt Clinton did an excellent job of clearing up some of Dare's other innaccuracies, but he then rhetorically exaggerated thus:
URLs make fantastic identifiers — for the 0.1% of the web population that understands that they “are” a URL. Fortunately, the other 99.9% of the world (our parents, for example) already understand that they have an email address.

This is missing the huge population of the online world (our children, for example) who consider email a messy noisy way to talk to old people, or to sign up to services when forced to, but are happy using their MySpace or Bebo or Hi5 or LiveJournal or Blogger or Twitter URLs to refer to themselves.
As I said in URLs are People Too:
The underlying thing that is wrong with an email address is that it's affordance is backwards - it enables people who have it to send things to you, but there's no reliable way to know that a message is from you. Conversely, URLs have the opposite default affordance- people can go look at them and see what you have said about yourself, and computers can go and visit them and discover other ways to interact with what you have published, or ask you permission for more.

Where I see OpenID providing a key advantage is in it's coupling with URL-based endpoints that provide more information and save the user time. The OpenID to PortableContacts connection as demonstrated by janrain can add your friends (with permission) from an OpenID login directly via OAuth.
This makes the OpenID login instantly more useful than an email one, and by connecting to an OpenSocial endpoint too, you can couple activities you take on the wider web with the site you trust to be a custodian of your profile and friends data, so your friends can discover what you are doing elsewhere, and come and join you.

I'm looking forward to talking through these issues at Internet Identity World next week in Mountain View.
Posted by Kevin Marks at 23:18 1 comment:
Labels: IIW, OpenID, OpenSocial, Portable Contacts

Thursday, 31 July 2008

Open Source and Social Cloud Computing

Tim O'Reilly has written an excellent review post on Open Source and Cloud Computing which says, among other things:

The interoperable internet should be the platform, not any one vendor's private preserve.

So here's my first piece of advice: if you care about open source for the cloud, build on services that are designed to be federated rather than centralized. Architecture trumps licensing any time.

But peer-to-peer architectures aren't as important as open standards and protocols. If services are required to interoperate, competition is preserved. Despite all Microsoft and Netscape's efforts to "own" the web during the browser wars, they failed because Apache held the line on open standards. This is why the Open Web Foundation, announced last week at OScon, is putting an important stake in the ground. It's not just open source software for the web that we need, but open standards that will ensure that dominant players still have to play nice.

The "internet operating system" that I'm hoping to see evolve over the next few years will require developers to move away from thinking of their applications as endpoints, and more as re-usable components. For example, why does every application have to try to recreate its own social network? Shouldn't social networking be a system service?

This isn't just a "moral" appeal, but strategic advice.[...]

A key test of whether an API is open is whether it is used to enable services that are not hosted by the API provider, and are distributed across the web.


I think this API openness test is not strong enough. As I wrote in An API is a bespoke suit, a standard is a t-shirt, for me the key test is that implementations can interoperate without knowing of each others' existence, let alone having to have a business relationship. That's when you have an open spec.

The other thing I resist in the idea of an internet operating system is that that the net is composable, not monolithic. You can swap in and implementations of different pieces, and combine different specs that solve one piece of the problem without having to be connected to everything else.

The original point of the cloud was a solved piece of the problem that means you don't have to worry about the internal implementation.

Thus, the answer to "shouldn't social networking be a system service?" is yes, it should be a Social Cloud. That's exactly what we are working on in OpenSocial.

Posted by Kevin Marks at 13:12 No comments:
Labels: open web, OpenSocial, Social Cloud, social networks

Monday, 26 May 2008

An API is a bespoke suit, a standard is a t-shirt

Brad is calling for APIs, and even the NYT is proposing one, but there is a problem with APIs that goes beyond Dave's concern about availability.

When a site designs an API, what they usually do is take their internal data model and expose every nook and cranny in it in great detail. Obviously, this fits their view of the world, or they wouldn't have built it that way, so they want to share this with everyone. In one way this is like the form-fitting lycra that weekend cyclists are so enamoured of, but working with such APIs is like being a bespoke tailor - you have to measure them carefully, and cut your code exactly right to fit in with their shapes, and the effort is the same for every site you have to deal with (you get more skilled at it over time, but it is a craft nonetheless).

Conversely, when a site adopts a standard format for expressing their data, or how to interact with it, you can put your code together once, try it out on some conformance tests, and be sure it will work across a wide range of different sites - it's like designing a t-shirt for threadless instead.

Putting together such standards, like HTML5, OpenID, OAuth or OpenSocial or, for Dave's example of reviews, hReview, takes more thought and reflection than just replicating your own internal data structures, but the payoff is that implementations can interoperate without knowing of each others' existence, let alone having to have a business relationship.

I had this experience at work recently, when the developers of the Korean Social network idtail visited. I was expecting to talk to them about implementing OpenSocial on their site, but they said they had already implemented an OpenSocial container and apps using OpenID login, and built their own developer site for Korean OpenSocial developers from reading the specification docs.

I'm looking forward to more 'aha' moments like that this week at I/O.

Posted by Kevin Marks at 17:51 1 comment:
Labels: APIs, HTML5, idtail, microformats, OAuth, OpenID, OpenSocial

Wednesday, 7 May 2008

Talking about OpenSocial all over the place

I've been travelling a lot to conferences in recent months, and been interviewed by a lot of different journalists too. Here are a few links to them.
  • Cloud computing with Joyent at Web 2.0(video)
  • Chris Vallance of BBC Pods and Blogs (audio)
  • Jemima Kiss of The Guardian (audio)
  • Data Portability podcast (audio)
  • Kimberley Dykeman of web2.0 TV (video)
  • Christina Warren of Download Squad (video)
  • Caroline McCarthy of CNET (text)

For more in-depth details on OpenSocial, come along to Google I/O on May 28th-29th in San Francisco
Posted by Kevin Marks at 12:26 1 comment:
Labels: google io, OpenSocial, public speaking

Tuesday, 6 May 2008

Portable Apps, not data?

Brad Templeton has a post on Data Hosting not Data Portability that fits in neatly with the VRM proposal I discussed yesterday. In fact, what he describes is a great fit for OpenSocial.

He says:

Your data host’s job is to perform actions on your data. Rather than giving copies of your data out to a thousand companies (the Facebook and Data Portability approach) you host the data and perform actions on it, programmed by those companies who are developing useful social applications.

Which is exactly what an OpenSocial container does - mediate access to personal and friend data for 3rd party applications.

This environment has complete access to the data, and can do anything with it that you want to authorize. The developers provide little applets which run on your data host and provide the functionality. Inside the virtual machine is a Capability-based security environment which precisely controls what the applets can see and do with it.

This maps exactly on to Caja, the capability-based Javascript security model that is being used in OpenSocial.

Your database would store your own personal data, and the data your connections have decided to reveal to you. In addition, you would subscribe to a feed of changes from all friends on their data. This allows applications that just run on your immediate social network to run entirely in the data hosting server.

Again, a good match for OpenSocial's Activity Streams (and don't forget persistent app data on the server).

Currently, everybody is copying your data, just as a matter of course. That’s the default. They would have to work very hard not to keep a copy. In the data hosting model, they would have to work extra hard, and maliciously, and in violation of contract, to make a copy of your data. Changing it from implicit to overt act can make all the difference.

The situation is worse than that; asking people for their logins to other sites is widespread and dangerous. I'd hope Brad would support OAuth as a step along the way to his more secure model - especially combined with the REST APIs that are part of OpenSocial 0.8

If you're interested in these aspects of OpenSocial, do join in the linked mailing lists, and come along to the OpenSocial Summit on May 14th (just down the road from IIW).

Posted by Kevin Marks at 02:30 1 comment:
Labels: Caja, Capability-based security, Data portability, Identity, IIW, OAuth, OpenSocial, VRM

Tuesday, 19 February 2008

Be Organic, not Viral

I just got back from the VLAB Multi-platform Social Networking event, which I thought was very interesting overall. Jeremiah Owyang did a great moderating job, and Jia Shen, Sourabh Niyogi, Ken Gullicksen and Steve Cohen brought lots of different viewpoints to the discussion. Growing and deriving value from Apps within Social Networks is still full of lots of unknowns, but it was good to hear some basic shared principles come through - my summary of one point was 'before you think about a Business Model, make sure you have a Pleasure Model'.

Another point well made by Steve Cohen of Bebo was something I've been thinking for a while too - the hunger for 'Viral' growth is a mistake - what you really need is 'Organic' growth. Just as we distinguish between Organic search results and bought or spammed ones, social network sites and their users are distinguishing between the viral apps that are essentially parasitic, using their hosts as a means to their propagation, and the ones that organically become part of the social ecology, making both the site and the users richer by their presence.
I spent the last weekend fighting off a flu virus, partly by eating lots of organic fruit. I expect social networks and their users will continue to do the same.

Posted by Kevin Marks at 22:44 3 comments:
Labels: OpenSocial, organic, social networks, viral, viral marketing, vlabfeb08

Monday, 11 February 2008

The Social Cloud

My talk from LIFT is here for you to watch below (20mins, needs flash):


The others are up at the LIFT Video site
Posted by Kevin Marks at 05:11 3 comments:
Labels: Kevin Marks, Lift, OpenSocial, Social Cloud, Social Graph, social networks

Wednesday, 9 January 2008

OpenSocial Hackathon next week in SF

OpenSocial Hackathon hosted by Six Apart


Wednesday, January 16, 2008 4:00 PM - 11:00 PM
Six Apart 548 4th St,San Francisco, California

Find out the latest news about OpenSocial's 0.6 release and what Shindig and Cajoling can do for your next web application
Work with developers of OpenSocial Social Networks to get your applications up and running.
What to bring:
  • Your laptop
  • Your web application code or your social networking idea

What we provide:
  • Wifi and power
  • Help getting into OpenSocial 0.6 sandboxe
  • Developers from at least Google, MySpace, Hi5, Plaxo, and Six Apart
  • and don't forget pizza!

Hosted at Six Apart's 4th street offices, it's a short walk from Caltrain and indeed the Macworld Expo.
Six Apart's post
RSVP at Upcoming
Posted by Kevin Marks at 00:59 No comments:
Labels: code, event, hackathon, OpenSocial

Friday, 2 November 2007

OpenSocial and Social Software history

In the Journal of Computer-Mediated Communication, danah boyd and Nicole Ellison have written a very thorough history of Social Network Sites.

Over at the OpenSocial API site we've written what we hope could be their future. Let me know what you think.

Posted by Kevin Marks at 01:25 No comments:
Labels: danah, OpenSocial, social networks
Older Posts Home
Subscribe to: Posts (Atom)

This is my personal blog. Any views you read here are mine, and not my employers'.

Atom Feed

Support the Open Rights Group
My photoKevin Marks Me on Twitter
Me on G+

People's thoughts I read:

Daily

Rosie
San Jose Young People's Theatre
Dave Weinberger
Doc Searls
Gonzo Engaged
AKMA
Cory & friends
Denise Howell
Charles Wiltgen
Shelley Powers
James Lileks
Suw Charman
Halley Suitt

Weekly

Andrew Marks
Blogsisters
Arts & Letters Daily
Bricklin, Frankston & Reed
Steve Yost
Jeneane Sessum
Brian Micklethwait et al
Tom Matrullo
Gary Turner

Sporadically

Small Pieces
Stuart Cheshire
RageBoy
Nonzero
Neil Gaiman
Thomas Vincent
Brad deLong
Andrew Odlyzko
ProSUA

No to Mickey Mouse Computers

powered by blogger

Blog Archive

  • ▼  2023 (1)
    • ▼  September (1)
      • Plus Theory
  • ►  2017 (2)
    • ►  May (1)
    • ►  April (1)
  • ►  2015 (7)
    • ►  November (2)
    • ►  May (3)
    • ►  April (1)
    • ►  January (1)
  • ►  2014 (3)
    • ►  October (1)
    • ►  April (2)
  • ►  2013 (5)
    • ►  June (1)
    • ►  May (1)
    • ►  April (2)
    • ►  March (1)
  • ►  2012 (8)
    • ►  December (1)
    • ►  May (1)
    • ►  April (1)
    • ►  March (1)
    • ►  January (4)
  • ►  2011 (11)
    • ►  December (1)
    • ►  November (1)
    • ►  September (2)
    • ►  August (2)
    • ►  July (1)
    • ►  April (2)
    • ►  January (2)
  • ►  2010 (16)
    • ►  November (1)
    • ►  October (1)
    • ►  September (3)
    • ►  June (1)
    • ►  May (2)
    • ►  April (2)
    • ►  March (2)
    • ►  February (2)
    • ►  January (2)
  • ►  2009 (22)
    • ►  November (2)
    • ►  October (2)
    • ►  September (2)
    • ►  August (3)
    • ►  July (2)
    • ►  June (2)
    • ►  May (2)
    • ►  April (1)
    • ►  February (2)
    • ►  January (4)
  • ►  2008 (29)
    • ►  December (2)
    • ►  November (3)
    • ►  August (1)
    • ►  July (3)
    • ►  June (3)
    • ►  May (5)
    • ►  April (2)
    • ►  February (3)
    • ►  January (7)
  • ►  2007 (45)
    • ►  November (3)
    • ►  October (4)
    • ►  September (4)
    • ►  August (10)
    • ►  July (3)
    • ►  June (8)
    • ►  April (2)
    • ►  March (6)
    • ►  February (3)
    • ►  January (2)
  • ►  2006 (119)
    • ►  December (13)
    • ►  November (8)
    • ►  October (16)
    • ►  September (10)
    • ►  August (3)
    • ►  July (6)
    • ►  June (24)
    • ►  May (3)
    • ►  April (10)
    • ►  March (7)
    • ►  February (8)
    • ►  January (11)
  • ►  2005 (101)
    • ►  December (10)
    • ►  November (13)
    • ►  October (9)
    • ►  September (8)
    • ►  August (7)
    • ►  July (7)
    • ►  June (8)
    • ►  May (12)
    • ►  April (7)
    • ►  March (6)
    • ►  February (1)
    • ►  January (13)
  • ►  2004 (53)
    • ►  December (8)
    • ►  November (5)
    • ►  October (6)
    • ►  September (7)
    • ►  July (5)
    • ►  June (3)
    • ►  May (2)
    • ►  March (3)
    • ►  February (7)
    • ►  January (7)
  • ►  2003 (196)
    • ►  December (12)
    • ►  November (14)
    • ►  October (21)
    • ►  September (23)
    • ►  August (19)
    • ►  July (11)
    • ►  June (14)
    • ►  May (9)
    • ►  April (22)
    • ►  March (20)
    • ►  February (16)
    • ►  January (15)
  • ►  2002 (224)
    • ►  December (15)
    • ►  November (21)
    • ►  October (22)
    • ►  September (12)
    • ►  August (11)
    • ►  July (28)
    • ►  June (19)
    • ►  May (29)
    • ►  April (18)
    • ►  March (19)
    • ►  February (16)
    • ►  January (14)
  • ►  2001 (13)
    • ►  December (2)
    • ►  November (11)

Contributors

  • Kevin Marks
  • Kevin marks