PRODUCTIVITY: How do you manage your contacts and data?

Friday, January 26, 2007

I’m frustrated with the lack of the “killer application” comprehensive Contact Management.

Plaxo has a fragment of it (The great external pariticpation). LinkedIn has a fragment of it (The Bio and Connection). Corex Cardscan has a fragment of it (The rolodex metaphor). Outlook has a fragment of it (Speaks to Plaxo and Corex). Act has a fragment of it (the Sales Funnel). But no one has “it” (i.e., Like, in Lord of the Rings, One Ring to control them all).

I’ve even thought about writing my own app using MySQL. But, that’s a daunting task. Several have tried in Fat Client or Web-based, but they didn’t capture “it”. So I wonder if “it” is capture-able.

So does anyone else share my frustration? Sometimes I think I’d be better off with paper and pencil!

Fustratedly,
Fjohn


PRODUCTIVITY: Use TWO gmail accounts to protect an ISP email account

Saturday, December 16, 2006

Many people advocate using a gmail account to protect against spam.

In my normal blundering way, I’m using two gmails to protect my ISP account from spam, and giving me a fully authenticated email address using gmail’s plus sign feature.

So let me see if I can explain how to duplicate the Yahoo AddressGuard. You can create and manage disposable email addresses to defend your primary address against spam. In Yahoo’s offering, they assign you a base name, unrelated to your real email name. Then Yahoo allows you to create suffixes that are just a string of characters. A real email address is created by base name, a minus sign, a suffix, and @yahoo.com. The suffix gets appended to the base separated by a a minus sign. (Great minds think … differently!) So if your real name is ABCDEF and your base name is ZXCVBN, then you can create, for example, ZXCVBN-EBAY. Then the address ZXCVBN-EBAY@yahoo.com will forward to ABCDEF@yahoo.com and you can even send from ZXCVBN-EBAY! Should your ZXCVBN-EBAY get spammed, then you can turn it off! They are easy to create, but there is no reporting or database with it. AND, it ain’t free!!!

So I sought to recreate that capability with GMail.

To refresh your memory, GMAIL (to their credit) has innovated by adding the capability to allow a plus sign in the email address. So if your gmail email address is abcdef @ gmail dot com, then you can put anything you want after a plus sign. So if email comes addressed as abcdef + fedcba @ gmail dot com will get delivered to your email account and you can test on that stuff after the plus sign.

Web sites may choke on the plus sign. (Gripe at them and don’t use their site till they fix it!)

I wanted to keep the base name concept. And, you want to control & database those suffixes. So here’s my concept.

I have an ISP account I want to protect called NORMAL@isp.com. So I created a “front door” account called FRONT@gmail.com and a “back door” account called WEIRD@gmail.com.

To test it all out I set it up so that FRONT forwards to WEIRD and WEIRD forwards to NORMAL. When it all works, I break that forwarding.

So far no big deal, just moving a lot of messages around. Except that FRONT does get vacuumed for spam by Google.

Now lets start using suffixes.

I created a table of suffixes and record where I use it. I then create a filter in the FRONT gmail that forwards FRONT+suffix to WEIRD+suffix. Then over on WEIRD, I create a filter that forwards WEIRD+suffix to NORMAL.

NOW:

* NORMAL only gets authentic pre-approved email.

* WEIRD is the protected hidden yahoo BASENAME equivalent.

* FRONT messages without a suffix get stopped there.

* FRONT and WEIRD get Google’s vacuuming for SPAM.

* If WEIRD is guessed by an alpha spammer, doesn’t move to NORMAL without a filter.

* Should any suffix be compromised, it can be stopped quickly by deleting the equivalent WEIRD filter.

* A web site, or intruder, who drops the suffix, to spam you, doesn’t reach NORMAL.

I think you need WEIRD, the second hidden BASENAME equivalent, so that you can change FRONT from time to time as needed. You could also have multiple “front doors” (i.e., FRONT1; FRONT2; etc.) feeding one WEIRD.

This a free solution equivalent to Yahoo’s address guard. It’s a great spam preventive.

For example, I now give each use of my gmail address a unique unguessable random code. (You expected different from a fellow who uses long strange email addresses?) Any email that arrives without a “plus code” is suspected of being spam. Should I get spam, I can pinpoint where the breakdown occurred.

Your comments, please?


PRODUCTIVITY: Secret questions are not foolproof … but you can make them!

Thursday, December 14, 2006

Network World’s Identity Management Newsletter, 12/11/06
Secret questions are not foolproof
By Dave Kearns

***Begin Quote***

The problem, as many have pointed out, is that this so-called secret information is readily discoverable by anyone who wants to dig a bit. As security maven Bruce Schneier said in “The Curse of the Secret Question” : “I’ll bet the name of my family’s first pet is in some database somewhere.” Bruce’s suggestion? “My usual technique is to type a completely random answer – I madly slap at my keyboard for a few seconds – and then forget about it. This ensures that some attacker can’t bypass my password and try to guess the answer to my secret question, but is pretty unpleasant if I forget my password.” Well that actually defeats the one good purpose of the secret password as well as blocking the bad uses – an example of tossing out the baby with the bathwater. I’ve got a better suggestion.

***End Quote***

May I suggest our old friend ROBOFORM’s random string generator?

Yup, for each site that needs my Mom’s maiden name, they can have a unique one. F53FA849645C26 for Yahoo, EFA897CABA45D4 for Google, and DAD999B5244BA2 for AOL.

And, if they want my favorite pet’s name, it’s in turn C9AF, 7B2B, or 222459.

See spammers can go ahead and guess all they want!

And, my first car was a BAD753!


PRODUCTIVITY: Adding plus signs to email — It’s a great spam preventive

Sunday, December 3, 2006

Some website’s registration edits don’t support the gmail plus sign option.

We have to insist that they do or not use their sites.

To refresh your memory, GMAIL (to their credit) has innovated by adding the capability to allow a plus sign in the email address. So if your gmail email address is abcdef @ gmail dot com, then you can put anything you want after a plus sign. So if email comes addressed as abcdef + fedcba @ gmail dot com will get delivered to your email account and you can test on that stuff after the plus sign.

It’s a great spam preventive.

For example, I give each use of my gmail address a unique unguessable random code. (You expected different from a fellow who uses long strange email addresses?) Any email that arrives without a “plus code” is suspected of being spam. Should I get spam, I can pinpoint where the breakdown occurred.

So, if a website would will NOT accept a plus code, I don’t use it.

(Note correcting an instance where the fingers led a life of their own.)


PRODUCTIVITY: the book The Virtual Handshake is available

Friday, December 1, 2006

FROM THE LINKEDIN INNOVATORS

with a great tip on a pdf book!

Reintroduction and “The Virtual Handshake”
Posted by: “John-Patrick Skaar”
Mon Nov 27, 2006 2:47 pm (PST)

I think it is time to reintroduce myself again to my fellow Innovator’s. Since I haven’t been too active lately I see this as the best way to make
sure that you all know that I am still around.

I am John-Patrick Skaar, resident in Oslo, Norway. I have a small family and work as BD for IT security vendors (mainly Israeli and American) and do have several other projects hanging around that keep me busy.

I am a strong believer in networking, and arrange several “LinkedIn and virtual networking” workshops for sales organizations and recruiters. I
believe that nothing comes into a closed hand, and in order to take, you have to give.

Anyways, I just found out that the book “The Virtual Handshake” is available as a free download from http://www.thevirtualhandshake.com/home.html

I am open to expand my already very strong network, and mainly within the Nordic region, within the IT security industry or relevant recruiters.
Others are also welcome, but please use a non standard invitation.

My email address is <To prevent spam, get it from the group.>

Have a GREAT day around the world!

//patrick

Senior Business Developer – Nordic region

https://www.linkedin.com/in/jpskaar

__

§ “The best way to predict the future is to invent it”
[Alan Kay <http://en.wikipedia.org/wiki/Alan_Kay> ’71] §


PRODUCTIVITY: Plaxo nukes some of “my” data and I’m miffed!

Tuesday, November 28, 2006

An interesting thing happened today. I was doing my birthday greetings. And, one of my fellow alums record was basically null. It was missing an email address. That’s plaxo’s key. All other fields had NA in them. There may be as many as four other records in the same shape.

Now, the counter party can do what ever they want to their data. But not to mine. I know that there was contact information in those fields that I input. Plaxo has no right to nuke that data.

I usually keep a copy of the source record (i.e., web page, email. or whatever initiated or updated my interest). That was gone to.

LinkedIn does something similar when it “silently” disconnects a LinkedIn contact. Presumably that is at the counterparty’s request, but how do you know it’s not an error by some clerk.

This rattles my confidence in other people controlling my data or access to it. When I create a record, I don’t want it changed. Perhaps, it’s time for me to get out my quill pen and put everything in long hand.

At the very least, maybe my old system of text files wasn’t so bad.

Neither of these two services Plaxo or LinkedIn, nor Corex Cardscan, nor Outlook itself ages the contacts so I’m not happy with any of the technology solutions.


PRODUCTIVITY: Free firewalls

Thursday, November 23, 2006

In today’s insecure computing environment, one needs personal pc protection. I’ve always had a router between me and the inet. Even when my isp (internet service provider) said I couldn’t. (Yeah right!) I’ve never had any problems with virus infections or bots that I know of. Somewhere in my travels I picked up Zone Alarm, (the free version), and it’s has served well. There are some other free alternatives as well for you to consider:

Sygate http://soho.sygate.com

Agnitum http://www.agnitum.com

and, of course,

ZoneAlarm http://www.zonealarm.com

FWIW YMMV and FAWWYPFI!


PRODUCTIVITY: Protecting from spam

Wednesday, November 22, 2006

http://www.pcmech.com/newsletter/viewtip.php?tipid=748

***Begin Quote***

One for personal/business contacts, and the other for anything that requires registration or sign-up (forums, subscriber content, etc). This way, if your second account gets buried with spam, various advertisements, or nag emails, your personal account should be relatively untouched.

***End Quote***

Well, if you follow my previous tip, then you can use one gmail account and GUARANTEE no spam.

To refresh your memory, gmail with the plus sign gives you fully protected email. Create your gmail account and then a list of random codes. For each use of the email, assign one of your codes after the plus sign. Then, create that label and filter in GMail. Then, the only thing that will get into that FILTERED category will be valid email. Everything else can be nuked!

Neat!


PRODUCTIVITY: Using GMAIL to avoid phishing

Monday, November 20, 2006

GMAIL has an interesting plus feature. If you think of email address syntax as user@provider.xxx, then you can put anything you want after a plus sign. So it’s user+string@gmail.com. You can use that feature to protect yourself from phishing attacks.

For example, create a random string for your “Mammoth Big Bank” bank (e.g., D3BCA3846CB5). Assume your email id is user@gmail.com. Then you tell your bank that your email address is user+D3BCA3846CB5@gmail.com! Anything purportedly coming from Mammoth Big Bank has to come with your secret code or you’ll ignore it. You can trash anything coming from Mammoth Big Bank that does NOT have your secret code.

If you’re like me and have lots of dedicated email address, then you can actually set a GMAIL label and filter to discard email that doesn’t authenticate with the secret code.

It’s simple and easy to protect against phishing.

Just don’t forget the D3BCA3846CB5! ;-)


PRODUCTIVITY: Missed an opportunity

Sunday, November 19, 2006

Argh! I’m mad at myself. When attending an event with a camera, I should have had a strategy. Photo everyone. Not only do you not get a second chance, but it could have been a hoot. Went to a “dance” last night, but didn’t exploit the opportunities to learn, link, and innovate. Argh!