Enterprise 2.0
Bèr Kessels: Five serious security issues and configurations, I found in recent clients sites
Part of my job is to help existing Drupal-users with their projects and sites. Sometimes this means upgrading, fixing some bug, or helping them get some new feature implemented.
What strikes me, is the amount of security hazards I encounter. I am not saying that I am the Perfect Developer, but I have a good knowledge of what makes a secure site secure, about what configuration break that security and so on The amount, and criticalness of the issues I encounter make me often think that we should really get some ranking or rating done in the Consultants-pool. Most of my clients are clueless themselves, so the ones who deliver or install a Drupal site for them, should really spend more time on educating the client, good configurations and considerations and overall on quality and security in general.
Five of the worst things I found recently:
Lullabot: Lullabot's New Venture
Lullabot announced today the formation of a new company -- a joint venture between Lullabot, Bond Art + Science, and Ed Sussman, former president of Mansueto Digital. The new company will be launching an easy-to-use platform for groups, individuals and businesses to create powerful dynamic social websites. Historically, these sites required huge time commitments and expert developers; this platform will allow users to harness the power of Drupal and its wealth of add-ons with a streamlined point-and-click, drag-and-drop interface. With these tools, even newcomers will be able to build feature-rich multi-user websites that go beyond the boundaries of simple blog sites.
Lullabot will continue to provide all of the same consulting and educational services that they currently offer. The new company will be separate and distinct from Lullabot.
Nick Lewis: Overriding Menu Page Callbacks
Sometimes you need to override more than a theme function: the entire page needs to be overridden. Drupal 6 makes it rather easy to do this.
In the example below, we call hook_menu_alter(&$callback) to override the display of every single node page view.
Instead of returning a node page, we return "[author's username] is great... for me to poop on.".
2bits: How relying on connections to third party servers can be detrimental to performance
Plan Your Social Life on Facebook and Bebo Using SocialCalendar (The Startup Review)
People use SocialCalendar to get their social life together - birthdays, anniversaries, holidays, get-togethers, other social occasions and associated gift-giving.
CEO’s PitchSocialCalendar makes it easy to manage and remember important social occasions like birthdays, holidays, and other get-togethers through event reminders, and allows users to share these dates with friends and family. In association with Amazon, SocialCalendar also takes the guessing out of gift-giving, helping users give (and receive) the perfect gift for any occasion. Users can browse for millions of gift ideas and items can be one-click added to wish lists without ever leaving the SocialCalendar page. Friends and family who receive event reminders can select the gift they want to purchase directly from the included wish lists without having to navigate to a new site – or go to the mall.
Almost 3 million Facebook users have added the application, and tens of thousands more sign up every day.
Mashable’s TakeSocialCalendar is a Facebook and Bebo application that pretty much does what you think: manages your social activities, birthdays, parties and appointments. However, there are some nice unexpected features that pop up. For example, the app doesn’t just list scheduled dates of events, but actually allows you and the other people involved to collaborate on the best time and date that works for everyone’s schedule. This reduces the need for excessive emails and phone calls back and forth, as well as the risk of miscommunication, ensuring higher attendance for the activity.
There’s also a wish list feature (from Amazon) that lets you know what presents others want, which helps a lot when it comes to gift giving ideas. This eliminates guessing games and reduces the odds of giving bad gifts. It helps your chances of getting what you want too. There’s an option that lets you see which gifts your friends and family will get for you, but you can turn it off if you like surprises.
SocialCalendar does a lot more than I expected from a social networking application. The only complaint I have is that in order to make full use of its services you have to connect to Facebook or Bebo. While that isn’t a big deal for most apps and games, that isn’t the case when it comes to time management tasks. In these hectic times with crazy schedules we need to be able to access this information anytime, anywhere.
Being tethered to any social networking site isn’t convenient. However, maybe that will change thanks to mobile devices such as the iPhone that allow us to access services we couldn’t access previously. Ultimately, I would have liked SocialCalendar much more if it were a full-blown service outside of any particular social network.
Editor’s Note: This post is part of an ongoing series at Mashable - The Startup Review, Sponsored by Sun Microsystems Startup Essentials. If you would like to have your startup considered for inclusion, please see the details here.
Sponsored by Sun Startup Essentials
Raincity Studios: Ægir Beta1 released - Built for hosting and managing multiple Drupal sites
Today, Drupal rockstar and the Raincity Studios super-developer and South African Emissary, Adrian announced the release of Ægir 0.1 Beta1. Named for the Norse God of the Seas, this evolution of Hostmaster is a critical part of Bryght's hosting environment.
The hardwork of Raincity Studios and Koumbit software engineers, and other contributors, is helping take mass Drupal hosting to the next level and you can join the fun - start at the Ægir hosting system group.
Added this release:
- Drupal install profiles - can be localized to provision sites in various languages
- Improvements to the comprehensive inline documentation
- Installation wizard to modify and/or simplify the user interface
User-interface refinements, non-critical ancillary features, and a Drupal 6 version are on the immediate roadmap.
Is Social Advertising a Safe Haven for Marketing Budgets?
As we watch the economy do what economies do - have growing pains and adjust to challenges - it becomes ever more apparent that doing things the old way just won’t work anymore. That is true of many of the old ways, especially when it comes to how companies advertise and grow their business.
It is my opinion that the return on investment (ROI) for traditional advertising will continue to shrink, even as companies using traditional advertising methods continue to throw money at ads in hopes that their company will survive these choppy financial seas. Instead of panicking and clinging to the deflating lifeboat of old ideas, now is the time to stand firm and innovate.
Evaluating the Situation
Before a company can find success in branding and marketing through non-traditional means like social media, companies and entrepreneurs need to reevaluate how they define ROI. Sure, there is always investment, but instead of thinking of this investment solely as monetary, also consider the investment you can make in time, staff, creativity, participation, and other less tangible resources. In this economy “investment” could be replaced by innovation, inspiration, involvement, or interaction for a different and fresh form of ROI.
Social media is often accused of taking a “touchy feely” approach to advertising, marketing and brand management. In a sense this is true. The ways of measuring ROI in a social media campaign are much more indirect than a cost based traditional model. In part this is because the cost of social media to grow your company is relatively low and consists mainly of intangible things like proper use of your time.
If the company is large enough, it may entail the cost of hiring someone to manage your social media efforts. If the company is a small to medium business or an entrepreneur or sole proprietor, most will find that after an initial training session with a good social media guide they can use existing staff to manage social media campaigns. This is a huge cost saver that can be carried over into a reduction in traditional advertising expenses as well.
Measuring ROI
One of the most tangible ways to measure ROI is site analytics. If you have a site that is starting a social media campaign, make sure to get a good analytics program installed, like Google Analytics. As you start each campaign, make sure to associate it with tags and key words you can track in your analytics program.
You can do the same for on-site CPM advertising, like the ever popular Google Adsense. By associating each ad block with key words and campaigns, it makes it easier to measure where the money and visitors are coming in from. Coupled with a great stats program like Mint or similar, there is no reason you can’t develop your own in-house ROI study as you embark on your first social media campaign.
Enhancing ROI
One of the many ways to enhance your ROI from social media campaigns is to consider transparency. Since it is very hard to hide behind an image these days (go ahead and Google your company name plus the word “sucks” or “stinks” or other negative connotations and see if anything comes back), the more transparent a company and its top level staff can be without giving away company secrets, the better.
A fantastic example of transparency helping a company’s numbers is that of BuzzAgent. They were so invested in the idea of changing how they approached their brand they did a 90 day experiment that showed measurable gains (and other interesting data) through openness and interaction.
Additional Benefits
If you aren’t sold on the idea of fully embracing social advertising, consider the intangible benefits of a brand campaign as well, including how social media can save you money indirectly. By becoming more involved with your brand and embracing both the negative and the positive (realize you no longer control the conversation about your company) you can stop problems before they start.
By giving your customers access to you through social media and using it to channel everything from customer support to sales and hiring, you will find that you are gaining income and stopping some tradition areas of corporate monetary hemorrhaging. All without spending vast amounts of extra money on ads no one stops to watch, listen to or read anyway outside of Superbowl Sunday. I’d say that’s pretty good indirect ROI, wouldn’t you?
---
Related Articles at Mashable | All That's New on the Web:
appssavvy Releases New Tool to Link App Developers with Advertisers
Another Cautious Report – Global Social Networking Ad Spend Estimates Lowered
Australian Ad It Last Comes To America
Save $100 off SWAT Summit on July 17th in San Francisco
Social Media Marketing Summit is Almost Here
What’s Next in Online Advertising?
Drama 2.0 Predicts What Won’t Happen in 2008
YouTube Begins Streaming Full-Length Shows from CBS
In another move towards earning more revenue from its huge audience, YouTube has started streaming full-length TV shows that will include advertising. The content, which includes Star Trek, The Young & The Restless, and Beverley Hills 90210 comes through a deal with CBS. Advertising will include familiar formats like pre, mid, and post-roll.
For YouTube, the deal certainly marks further indication that the company is not having a great deal of success in monetizing the user-generated video that dominates the site. While the current lineup of content from CBS may not be especially impressive – no offense Y&R fans – it’s likely just the first of many deals that YouTube will make to bring more professionally produced content to its site that can be more easily monetized.
For CBS, the deal might be seen as yet another sign of a lack of confidence in Joost, the professional video content site where CBS is an investor. Meanwhile, CBS already offers full-length versions of many of its popular shows like CSI on its own website. Ultimately, it would look like YouTube is simply being viewed as another place to distribute content for the media company. CBS also recently did a deal with Slide to distribute video content through Facebook applications.
---
Related Articles at Mashable | All That's New on the Web:
CBS Launches New Online Video Initiative
comScore Releases Video Streaming Study
Fox Shows Coming To MySpace Profiles
YouTube Multi-File Upload is Here
Imeem Partners with Palm Pictures for Interactive Indie Film Access
“Lost” and Other ABC Shows Coming to Veoh
NBC Streamed Nearly 333 Million Videos Online
Raincity Studios: Take Back the Power with a Campaign Module
No matter which side of the USA/Canada border you live on, it's impossible to ignore the political campaigns in full swing. Regardless of your leanings, no doubt the campaigns with polished social media strategies are enjoying advantages. Indeed, this is the first election cycle which 'Web 2.0" tactics are mandatory rather than merely optional or an after-thought.
Because Google (and the other search engines) efficiently index mostly all the pages within a site, visitors can obviously enter a site via hundreds of different on ramps. While this means the visitor may easily find the information they seek, the organization's time-sensitive objectives might not receive enough attention.
To rise above the noise, the savvy campaigner needs to transmit their message in a method in which people will receive and react to it with a clear and easy call to action.
New Drupal toolA new module developed by Raincity Studios' Makara Wang will help the many politico sites using Drupal to harness their Google-juice and funnel their visitors to a desired actionable task.
The module is called "Roadblock" - a term which usually denotes a unwanted traffic snarl, but in this case, the roadblock is designed to focus the visitor's participation and funnel them towards a specific action.
Tom Geller: Notes for BADCamp presentations: "1st Drupal Steps" and "2nd Drupal Steps"
It's finally here! BADCamp 2008 will happen this weekend in Berkeley, California, with 27 informative sessions, BOFs, a job fair, networking and good times. I'm really looking forward to it.
As mentioned earlier, I'm presenting two sessions, and have posted the slides in PDF documents. They are:
- First Drupal Steps: From Download to Launch (description, slides)
- Second Drupal Steps: Improving Your New Site (description, slides)
See you there!
Neil Drumm: Speaking at Bay Area Drupal Camp
I am speaking both Saturday and Sunday at BADCamp. Saturday I will be talking about Drupal Development Tools and Resources with Matt Cheney. We will demo tools we help build, like Drupal’s API reference and Drupal for Firebug, and other great tools we use to help build sites smarter and faster.
Memorandum Colors: X-Ray Glasses for Political Bias in Blogs
Upcoming.org founder Andy Baio and Del.icio.us founder Joshua Schachter have released a project called Memeorandum Colors. It's an easy-to-install Greasemonkey plug-in that shows the political bias of past linking behavior on blogs aggregated by Memeorandum, the political sister-site of tech aggregator Techmeme.
In this heated election season, Memeorandum is a huge asset for following politics online, but it's hard for the casual observer to get the most out of the conversation by merely visiting the site. Memeorandum Colors adds a whole new layer of clarity and sophistication to the site by color-coding algorithmically categorized liberal and conservative blogs.
How It WorksMemeorandum, like Techmeme, tracks hot conversations in the blogosphere by seeing who is linking to whom. Every 5 minutes these sites check to see what the break out topics are and then organize them by link-hub and conversation links. See the screenshot I took a few minutes ago.
Memeorandum Colors takes the history of what 50,000 blogs indexed by Memeorandum have linked to and analyzes them for patterns. Schachter and Baio found that there were two clear groups of blogs that tended to link together. Presumably they looked at them and determined that one group was conservative and the other, liberal. Interestingly, the two ran the same algorithm on the blogs in Techmeme and found that the blogs there are split into two groups as well - business vs. technology.
The Greasemonkey script then color codes each blog in shades of red or blue, depending on how consistently they've linked with the conservative or liberal pack in the past. The end result is that when you load the Memeorandum site, you can see which kinds of blogs are clustering around a common node, which story nodes are of such general interest that they cross party lines and which brave conservative blogs step out of the norm and link to liberal sources and vice versa. This author was just complaining yesterday about how hard it is to find out what liberal blogs have to say about conservative conversations on Memeorandum without a lot of knowledge about who the leading blogs are in each camp. Problem solved!
This is an awesome example of the kinds of magic services that can be created by analyzing aggregate data around user generated content. We love this kind of stuff.
If you've never used Greasemonkey before, we assure you - it's much easier than it sounds! Just download the official Firefox plug-in and then click on any Greasemonkey script link to install it. Honestly, two or three mouse clicks and you're cooking with gas. If it helps you can watch our screencast How to Start Using Greasemonkey in Under 5 Minutes.
For an in depth technical discussion of how Memorandum Colors was created and to grab the Memeorandum Colors script, see Baio's fabulous blog Waxy.org. I'm off to see what moderate conservative blogs have to say about reports of extreme hostility at Republican political rallies!
DiscussJeff Eaton: Beginning to suspect I might be a Drupal nerd
Over the past couple of weeks, a few friends and colleagues asked me to give a run-down of what modules and projects I created or contribute to in the Drupal world. I started picking my way through them, and it was pretty sobering. (I think I'm going to need an intervention if I release even one more module...) This list leaves out the work that I do on Drupal Core, and doesn't include patches or enhancements to other modules, but it's a nice birds-eye view of what kind of stuff I'm doing in my copious free time. Ahem.
Real VC Might Be The Safest Asset Class Today
In downturns there is a "flight to safety". Typically you would put Venture Capital (VC) at the risky end, with something like a Money Market Fund at the safe end. Well today even the safest stuff is looking scary, thanks to the games that the financial engineers have been playing. So maybe investing in a real business that disrupts the old order with a fundamentally new value proposition is actually the safest thing to do. That is "Real Venture Capital (RVC)". But RVC is very, very different from "Momentum Venture Capital" (MVC). MVC is under a significant threat.
RVC Is A Different Asset Class From MVCReal Venture Capital (RVC) is anything that takes a risk and works hard to create something fundamentally new. Many classic VC funds fall into this category. So do many angels. But I would also put entrepreneurs who bootstrap their ventures into this category. I would also even put Private Equity and Hedge Funds that do turnarounds and transformations.
This is very different from Momentum Venture Capital (MVC). The old asset class categories make less sense in this context. You get all kinds of MVC that would traditionally be called VC, Angel, Entrepreneur, Private Equity or Hedge Fund. But they are fundamentally different from Real VC. MVC jump on trends and amplify them. If they are lucky and smart, they get out in time. They are the bubble inflators. Their core competency is timing trends. They ride momentum.
In a downturn such as this, MVC get crushed. MVC that timed it well and got to cash are sitting pretty, playing golf ready to jump in a gain when the cycle turns. But MVC left "holding the bag" at a time like this get crushed.
RVC is contrarian. They invest when most people are scared and sell when everybody is bullish. MVC is the opposite. Smart MVC invest when the trends are obvious and get out quick, the classic "flip artist". Dumb MVC invest when the trends are obvious and don't get out in time. But both smart and dumb MVC are primarily trend spotters.
Warren Buffet is the RVC HeroWarren Buffet ignores Mr. Market and buys companies that generate lots of free cash flow. RVC build the kind of companies that Mr. Buffet would want to buy (which mean that anybody would want to buy and that you don't need to sell until the right buyer comes along).
Sure, But Safe??? Look At AlternativesNo asset class looks safe now. Remember that the objective is some cash after inflation, and inflation has certainly reared its ugly head again. Here are some of the usual assets that people turn to in difficult times. (In brackets are the classic "Chicken Little" fear mongering questions that you hear today).
1. Cash (in what Bank? After Inflation? In what currency?)
2. Money Markets (frozen assets in panic, no inflation protection)
3. Muni Bonds (what did Schawzenegger say about California needing emergency funds?)
4. Property, "safe as houses, right?" ('nuff said).
5. Oil (will drop if global economy slows)
I could go on and on. The point is that when nothing is safe the risk/reward of investing in a new business that you really understand, with people you trust, suddenly looks less out there on the risk curve.
The Playing Field Just Tilted To The Little GuyThis is what we wrote about yesterday related to SaaS and traditional IT vendors.
That maybe part of a bigger historical shift of power from BigCo to SmallCo, reversing what happened in the last 50 years when the share of US GDP controlled by Fortune 500 went from 1/3 to 2/3. Coase's Law and the reduction in transaction friction created by the Internet are the theoretical underpinning of this shift.
This historic shift makes it safer to build disruptive innovation from scratch than defend an incumbent position. To put it more simply, today it is better to be a Barbarian than a Roman.
In short, it is time for Real VC to be bold. Some will be bold. Some won't. Enough will be bold for this to work out just fine.
Image credit: Thomas Hawk
DiscussZivTech: Community Building: Drupal Cons, Camps, Sprints and Meetups
As I write this I’m sitting on a plane flying between Philadelphia and San Francisco, on my way to participate in this year’s BADCamp. I’ve been asked on more than one occasion why I would travel up the Turnpike to New York, let alone across the entire United States, to attend a regional Drupal Camp, and while I am always looking for an excuse to get on a plane, and The Bay Area is my second favorite city, the real reason that I’m traveling thousands of miles from home is community (and of course my love for everything Drupal).
Dries Buytaert: Addison Berry new Drupal documentation team lead
For the past few years the Drupal Documentation Team has been led by Steven Peck (sepeck). Steven was the first person to take on this role, and he has done a great job. Not only has he grown the documentation team to include a lot of talented and hard-working volunteer writers, he has overseen the restructuring and reorganization of Drupal.org's documentation handbooks, greatly improving their structure and accessibility. Thank you Steven for the great work!
Like so many Drupal contributers, Steven works on Drupal completely as a volunteer. His day job has been demanding a lot of time lately, and he has decided to step down from being the Documentation Team Leader. That means it is time to pass the torch to the next person who can then sprint with it for a while.
The Financial Crisis in Pictures: 8 of the Best from Around the Web
With the stock market continuing to plunge, one thing remains constant: financial news sites like to tell part of the story with images of distressed Wall Street traders and executives that are experiencing some of the worst moments of their careers. While the news of the day is indeed troubling and makes us all nervous, the emotion captured in some of these images is better than that any story could tell. Here are 8 of the best pictures we’ve spotted on the homepages of various business news hubs during the current market meltdown:
from The Motley Fool
from TheStreet.com
from Reuters
from WSJ.com
from USA Today
from Fortune - the CEO of General Electric
from BusinessWeek - the CEO of General Motors
Feel free to post links to some of the best imagery you’ve seen from around the Web in the comments.
---
Related Articles at Mashable | All That's New on the Web:
The US Financial Crisis-Nigerian Email Scam Parody
BillShrink Wants to Help You Manage Your Credit Cards
Share Your Investment Portfolios on Facebook
Could the Weak US Housing Market Hurt Google?
Look Out NWS: Reuters Building a Financial MySpace
Cake Financial to Launch Free Investors Network
Startups, it’s Time to Stop Calling Yourselves That
Anello Consulting: Developer's Quick Tip - Working with Memcache and File Uploads
As a Drupal developer and recent memcache convert, I now know the joy of speedy caching.
Memcache actually comes with 2 modules: the main memcache code as well as "memcache admin" which, as far as I can tell, is really only necessary during devlopment and testing of the site (sort of the same way the Views UI module can be disabled after a site goes live).
When using Memcache with Drupal 5.x (it hasn't been ported to 6.x yet, but there is some ongoing work), there's a big "gotcha" that has gotten me on more than one occasion - the "show memcache statistics at the bottom of each page" option on admin/settings/memcache.
Ning Adds OpenSocial Support
Social networking platform Ning announced support for the OpenSocial standard today. Thanks to this, developers can now easily create applications for the Ning platform. At this time, Ning already features 30 applications that users can embed into their profile pages, including support for file sharing with Box.net and poll creation from Polldaddy. One of the highlights of Ning's implementation of OpenSocial is that the widgets automatically adapt themselves to the branding and design of the individual networks.
Ning is a social networking platform that allows its users to create their own, custom social networks. Some of its high-profile customers include celebrities like 50 Cent and Ellen DeGeneres.
For now, users can only add OpenSocial applications to their profiles, but not to their networks. This will change, however, once future versions of OpenSocial are developed, as Caroline McCarthy reports.
By adding support for OpenSocial, Ning is joining a growing number of social networks that support this standard, including MySpace, hi5, Orkut, and Bebo. For developers, supporting OpenSocial makes good sense, as they can reach a far larger audience with an OpenSocial application than if they just programmed for a given network's own APIs. The only hold-out with regards to supporting OpenSocial is Facebook, though Facebook is also considering the option of opening up its development platform to other social networks in the future.
Ning itself is growing nicely and just celebrated the creation of its 500,000th network. By supporting OpenSocial, Ning now gains the ability to offer its customers an even larger array of options, though it would have been nice if Ning already supported OpenSocial apps on network pages and not just on profiles.
DiscussSave 30% off on October 15th’s Conversational Marketing Summit
Federated Media’s third, semi-annual conference, the Conversational Marketing Summit, will be held October 15 and 16, 2008 in San Francisco, CA. This two-day event, hosted by John Battelle, will look at the rise and evolution of conversational media and marketing, with a special emphasis on the role of brands in online media. Speakers include senior executives from Twitter, ComScore, Google, Microsoft and more. Visit http://federatedmedia.net/events/cmsummit for more information on the program agenda and speaker line up. Also, Mashable readers can save 30% off the ticket price by registering with this link.
---
Related Articles at Mashable | All That's New on the Web:
Ticket Giveaway to Federated Media’s Conversational Marketing Summit
BlogTalk 2008 Discount For Mashable Readers
Blog World 2007 Approaches: 15% Off for Mashable Readers
Dow Jones Web Ventures 2008: Updates and Discount
BugLabs To Slash Prices at CES
Politics Online Conference 2008: Mashable Readers Save $50
Web 2.0 Conference & Expo: Exclusive Discount for Mashable Readers