Your Ad Here Visit new version of this Blog

wow! How easy to Keep the CPU cool while coding






10 Principles Of Effective Web Design

Usability and the utility, not the visual design, determine the success or failure of a web-site. Since the visitor of the page is the only person who clicks the mouse and therefore decides everything, user-centric design has established as a standard approach for successful and profit-oriented web design. After all, if users can’t use a feature, it might as well not exist.

We aren’t going to discuss the implementation details (e.g. where the search box should be placed) as it has already been done in a number of articles; instead we focus on the main principles, heuristics and approaches for effective web design — approaches which, used properly, can lead to more sophisticated design decisions and simplify the process of perceiving presented information.

In order to use the principles properly we first need to understand how users interact with web-sites, how they think and what are the basic patterns of users’ behavior.

How do users think?

Basically, users’ habits on the Web aren’t that different from customers’ habits in a store. Visitors glance at each new page, scan some of the text, and click on the first link that catches their interest or vaguely resembles the thing they’re looking for. In fact, there are large parts of the page they don’t even look at.

Most users search for something interesting (or useful) and clickable; as soon as some promising candidates are found, users click. If the new page doesn’t meet users’ expectations, the Back button is clicked and the search process is continued.

  • Users appreciate quality and credibility. If a page provides users with high-quality content, they are willing to compromise the content with advertisements and the design of the site. This is the reason why not-that-well-designed web-sites with high-quality content gain a lot of traffic over years. Content is more important than the design which supports it.
  • Users don’t read, they scan. Analyzing a web-page, users search for some fixed points or anchors which would guide them through the content of the page.

    Screenshot
    Users don’t read, they scan. Notice how “hot” areas abrupt in the middle of sentences. This is typical for the scanning process.

  • Web users are inpatient and insist on instant gratification. Very simple principle: If a web-site isn’t able to meet users’ expectations, then designer failed to get his job done properly and the company loses money. The higher is the cognitive load and the less intuitive is the navigation, the more willing are users to leave the web-site and search for alternatives.
  • Users don’t make optimal choices. Users don’t search for the quickest way to find the information they’re looking for. Neither do they scan web-page in a linear fashion, going sequentially from one site section to another one. Instead users satisfy; they choose the first reasonable option. As soon as they find a link that seems like it might lead to the goal, there is a very good chance that it will be immediately clicked. Optimizing is hard, and it takes a long time. Satisfying is more efficient.

    Screenshot

    Screenshot
    Both pictures show: sequential reading flow doesn’t work in the Web. Right screenshot on the image at the bottom describes the scan path of a given page.

  • Users follow their intuition. In most cases users muddle through instead of reading the information a designer has provided. According to Steve Krug, the basic reason for that is that users don’t care. “If we find something that works, we stick to it. It doesn’t matter to us if we understand how things work, as long as we can use them. If your audience is going to act like you’re designing billboard, then design great billboards.”
  • Users want to have control. Users want to be able to control their browser and rely on the consistent data presentation throughout the site. E.g. they don’t want new windows popping up unexpectedly and they want to be able to get back with a “Back”-button to the site they’ve been before: therefore it’s a good practice to never open links in new browser windows.

1. Don’t make users think

According to Krug’s first law of usability, the web-page should be obvious and self-explanatory. When you’re creating a site, your job is to get rid of the question marks — the decisions users need to make consciously, considering pros, cons and alternatives.

If the navigation and site architecture aren’t intuitive, the number of question marks grows and makes it harder for users to comprehend how the system works and how to get from point A to point B. A clear structure, moderate visual clues and easily recognizable links can help users to find their path to their aim.

Screenshot

Let’s take a look at an example. Beyondis.co.uk claims to be “beyond channels, beyond products, beyond distribution”. What does it mean? Since users tend to explore web-sites according to the “F”-pattern, these three statements would be the first elements users will see on the page once it is loaded.

Although the design itself is simple and intuitive, to understand what the page is about the user needs to search for the answer. This is what an unnecessary question mark is. It’s designer’s task to make sure that the number of question marks is close to 0. The visual explanation is placed on the right hand side. Just exchanging both blocks would increase usability.

Screenshot

ExpressionEngine uses the very same structure like Beyondis, but avoids unnecessary question marks. Furthermore, the slogan becomes functional as users are provided with options to try the service and download the free version.

By reducing cognitive load you make it easier for visitors to grasp the idea behind the system. Once you’ve achieved this, you can communicate why the system is useful and how users can benefit from it. People won’t use your web site if they can’t find their way around it.

2. Don’t squander users’ patience

In every project when you are going to offer your visitors some service or tool, try to keep your user requirements minimal. The less action is required from users to test a service, the more likely a random visitor is to actually try it out. First-time visitors are willing to play with the service, not filling long web forms for an account they might never use in the future. Let users explore the site and discover your services without forcing them into sharing private data. It’s not reasonable to force users to enter an email address to test the feature.

As Ryan Singer — the developer of the 37Signals team — states, users would probably be eager to provide an email address if they were asked for it after they’d seen the feature work, so they had some idea of what they were going to get in return.

Screenshot

Stikkit is a perfect example for a user-friendly service which requires almost nothing from the visitor which is unobtrusive and comforting. And that’s what you want your users to feel on your web site.

Screenshot

Apparently, Mite requires more. However the registration can be done in less than 30 seconds — as the form has horizontal orientation, the user doesn’t even need to scroll the page.

Ideally remove all barriers, don’t require subscriptions or registrations first. A user registration alone is enough of an impediment to user navigation to cut down on incoming traffic.

3. Manage to focus users’ attention

As web-sites provide both static and dynamic content, some aspects of the user interface attract attention more than others do. Obviously, images are more eye-catching than the text — just as the sentences marked as bold are more attractive than plain text.

The human eye is a highly non-linear device, and web-users can instantly recognize edges, patterns and motions. This is why video-based advertisements are extremely annoying and distracting, but from the marketing perspective they perfectly do the job of capturing users’ attention.

Enso

Humanized.com perfectly uses the principle of focus. The only element which is directly visible to the users is the word “free” which works attractive and appealing, but still calm and purely informative. Subtle hints provide users with enough information of how to find more about the “free” product.

Focusing users’ attention to specific areas of the site with a moderate use of visual elements can help your visitors to get from point A to point B without thinking of how it actually is supposed to be done. The less question marks visitors have, the better sense of orientation they have and the more trust they can develop towards the company the site represents. In other words: the less thinking needs to happen behind the scenes, the better is the user experience which is the aim of usability in the first place.

4. Strive for feature exposure

Modern web designs are usually criticized due to their approach of guiding users with visually appealing 1-2-3-done-steps, large buttons with visual effects etc. But from the design perspective these elements actually aren’t a bad thing. On the contrary, such guidelines are extremely effective as they lead the visitors through the site content in a very simple and user-friendly way.

Screenshot

Dibusoft.com combines visual appeal with clear site structure. The site has 9 main navigation options which are visible at the first glance. The choice of colors might be too light, though.

Letting the user see clearly what functions are available is a fundamental principle of successful user interface design. It doesn’t really matter how this is achieved. What matters is that the content is well-understood and visitors feel comfortable with the way they interact with the system.

5. Make use of effective writing

As the Web is different from print, it’s necessary to adjust the writing style to users’ preferences and browsing habits. Promotional writing won’t be read. Long text blocks without images and keywords marked in bold or italics will be skipped. Exaggerated language will be ignored.

Talk business. Avoid cute or clever names, marketing-induced names, company-specific names, and unfamiliar technical names. For instance, if you describe a service and want users to create an account, “sign up” is better than “start now!” which is again better than “explore our services”.

Screenshot

Eleven2.com gets directly to the point. No cute words, no exaggerated statements. Instead a price: just what visitors are looking for.

An optimal solution for effective writing is to

  • use short and concise phrases (come to the point as quickly as possible),
  • use scannable layout (categorize the content, use multiple heading levels, use visual elements and bulleted lists which break the flow of uniform text blocks),
  • use plain and objective language (a promotion doesn’t need to sound like advertisement; give your users some reasonable and objective reason why they should use your service or stay on your web-site)

6. Strive for simplicity

The “keep it simple”-principle (KIS) should be the primary goal of site design. Users are rarely on a site to enjoy the design; furthermore, in most cases they are looking for the information despite the design. Strive for simplicity instead of complexity.

Screenshot

Crcbus provides visitors with a clean and simple design. You may have no idea what the site is about as it is in Italian, however you can directly recognize the navigation, header, content area and the footer. Notice how even icons manage to communicate the information clearly. Once the icons are hovered, additional information is provided.

From the visitors’ point of view, the best site design is a pure text, without any advertisements or further content blocks matching exactly the query visitors used or the content they’ve been looking for. This is one of the reasons why a user-friendly print-version of web pages is essential for good user experience.

Screenshot

Finch clearly presents the information about the site and gives visitors a choice of options without overcrowding them with unnecessary content.

7. Don’t be afraid of the white space

Actually it’s really hard to overestimate the importance of white space. Not only does it help to reduce the cognitive load for the visitors, but it makes it possible to perceive the information presented on the screen. When a new visitor approaches a design layout, the first thing he/she tries to do is to scan the page and divide the content area into digestible pieces of information.

Complex structures are harder to read, scan, analyze and work with. If you have the choice between separating two design segments by a visible line or by some whitespace, it’s usually better to use the whitespace solution. Hierarchical structures reduce complexity (Simon’s Law): the better you manage to provide users with a sense of visual hierarchy, the easier your content will be to perceive.

Screenshot

White space is good. Cameron.io uses white space as a primary design element. The result is a well-scannable layout which gives the content a dominating position it deserves.

8. Communicate effectively with a “visible language”

In his papers on effective visual communication, Aaron Marcus states three fundamental principles involved in the use of the so-called “visible language” — the content users see on a screen.

  • Organize: provide the user with a clear and consistent conceptual structure. Consistency, screen layout, relationships and navigability are important concepts of organization. The same conventions and rules should be applied to all elements.
  • Economize: do the most with the least amount of cues and visual elements. Four major points to be considered: simplicity, clarity, distinctiveness, and emphasis. Simplicity includes only the elements that are most important for communication. Clarity: all components should be designed so their meaning is not ambiguous. Distinctiveness: the important properties of the necessary elements should be distinguishable. Emphasis: the most important elements should be easily perceived.
  • Communicate: match the presentation to the capabilities of the user. The user interface must keep in balance legibility, readability, typography, symbolism, multiple views, and color or texture in order to communicate successfully. Use max. 3 typefaces in a maximum of 3 point sizes — a maximum of 18 words or 50-80 characters per line of text.

9. Conventions are our friends

Conventional design of site elements doesn’t result in a boring web site. In fact, conventions are very useful as they reduce the learning curve, the need to figure out how things work. For instance, it would be a usability nightmare if all web-sites had different visual presentation of RSS-feeds. That’s not that different from our regular life where we tend to get used to basic principles of how we organize data (folders) or do shopping (placement of products).

With conventions you can gain users’ confidence, trust, reliability and prove your credibility. Follow users’ expectations — understand what they’re expecting from a site navigation, text structure, search placement etc. (see Nielsen’s Usability Alertbox for more information)

Screenshot
BabelFish in use: Amazon.com in Russian.

A typical example from usability sessions is to translate the page in Japanese (assuming your web users don’t know Japanese, e.g. with Babelfish) and provide your usability testers with a task to find something in the page of different language. If conventions are well-applied, users will be able to achieve a not-too-specific objective, even if they can’t understand a word of it.

Steve Krug suggests that it’s better to innovate only when you know you really have a better idea, but take advantages of conventions when you don’t.

10. Test early, test often

This so-called TETO-principle should be applied to every web design project as usability tests often provide crucial insights into significant problems and issues related to a given layout.

Test not too late, not too little and not for the wrong reasons. In the latter case it’s necessary to understand that most design decisions are local; that means that you can’t universally answer whether some layout is better than the other one as you need to analyze it from a very specific point of view (considering requirements, stakeholders, budget etc.).

Some important points to keep in mind:

  • according to Steve Krug, testing one user is 100% better than testing none and testing one user early in the project is better than testing 50 near the end. Accoring to Boehm’s first law, errors are most frequent during requirements and design activities and are the more expensive the later they are removed.
  • testing is an iterative process. That means that you design something, test it, fix it and then test it again. There might be problems which haven’t been found during the first round as users were practically blocked by other problems.
  • usability tests always produce useful results. Either you’ll be pointed to the problems you have or you’ll be pointed to the absence of major design flaws which is in both cases a useful insight for your project.
  • according to Weinberg’s law, a developer is unsuited to test his or her code. This holds for designers as well. After you’ve worked on a site for few weeks, you can’t observe it from a fresh perspective anymore. You know how it is built and therefore you know exactly how it works — you have the wisdom independent testers and visitors of your site wouldn’t have.
Article by: SMASHING MAGAZINE

flv file is not playing in firefox

-flv file is not playing in Firefox
-Flash file is not playing in Firefox
-video is not streaming is Firefox
-I have uploaded a flash video player which plays flv file through streaming, when i run it in Internet Explorer works very fine but in Mozilla Firefox doesn't work....(that was my problem and then i found exact solution for that and my problem solved and you can also try it..)

Solution:- try it....
Please make sure that you have added a 'flashvars' element in both 'embed' and 'object' tags, Might be you missed it...

View more reference

Could not load file or assembly

Fix for ASP.NET "Could not load file or assembly App_Web..." Error

Delete all temporary ASP.NET files, by removing the folders under the following directory and then check it:

C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\

Read full Post

Computers will never take the place of books


An amazing passionate recipe for Developers......!

Developers take a passionate recipe daily before going to start their non-stop activities. Recipes like given below promote developers,praise developers that they are the most valuable like in a TEAM. see how MICROSOFT call its DEVELOPERS.......Amazing?

How to upload file to the ftp Server or Flash Media Server(Influxis) using c#

//First create FtpWebRequest object with the ftpURL

System.Net.FtpWebRequest ftpRequest = (System.Net.FtpWebRequest)System.Net.WebRequest.Create(CompleteFTPPath);

//Set the ftp Method, like 'UploadFile' for upload

ftpRequest.Method = System.Net.WebRequestMethods.Ftp.UploadFile;

//Give your user name & password of the ftp login

ftpRequest.Credentials = new System.Net.NetworkCredential(ConfigurationManager.AppSettings.Get("username"), ConfigurationManager.AppSettings.Get("password"));

ftpRequest.UsePassive = false;

// By default KeepAlive is true, where the control connection is not closed
// after a command is executed.

ftpRequest.KeepAlive = false;

// Specify the data transfer type.

ftpRequest.UseBinary = true;

// Opens a file stream (System.IO.FileStream) to read the file to be uploaded

System.IO.FileStream streamObj = System.IO.File.OpenRead(CompleteLocalPath);

// Notify the server about the size of the uploaded file

ftpRequest.ContentLength = streamObj.Length;

// The buffer size is set to 2kb

int buffLength = 2048;
byte[] buff = new byte[buffLength];
int contentLen;

// Stream to which the file to be upload is written

System.IO.Stream writeStream = ftpRequest.GetRequestStream();

// Read from the file stream 2kb at a time

contentLen = streamObj.Read(buff, 0, buffLength);

// Till Stream content ends

while (contentLen != 0)
{
// Write Content from the file stream to the FTP Upload Stream

writeStream.Write(buff, 0, contentLen);
contentLen = streamObj.Read(buff, 0, buffLength);
}
// Close the file stream and the Request Stream

streamObj.Close();
writeStream.Close();

Adobe Flash Media Player has stopped a potentially unsafe operation

When I run my flash application from my system and connect to the Remote Flash Media Server I get the following message.



That reminds us about the new Flash Player 8 security changes and how local content cannot access remote files. I clicked Settings…. to allow this application run. When you will click on Settings….you will be redirected to the Flash Player Security web page where you can allow your application to run properly by adding it in that.

You will have in front of you Adobe Flash Player Settings Manager like given below. You need to click on ‘Edit locations… ‘ to add your application locations.



As you click on add location will have a new window which will represent you the recently tried application path. To add your application path select application by clicking on the Browse for files… button and select application.



After that your application will be added in that so close that web browser and restart your application which should run successfully.



Life Cycle of Software Development

By Peter Slade



Do developers only work in a Teamwork Environment?

Killer place to work

Everyone desires to have a BEST place to work where he/she will have more fun, more facilities as well as Productivity, loyalty, regularity etc.

GOOGLE is awarded with No.1 BEST PLACE TO WORK FOR 2007

Life at google

100 Best Companies to Work For 2007



Fun with Computer’s Life

Fun with Programmer’s Life

Do you know the effects of exceedingly attachment to Computer or use of Mouse?

Results sometimes have fun and sometimes cannot be as pleasurable as in video... :-D

Life of a Programmer

Life of a Programmer

  • How an irritated Programmer behave to the System?
  • Do you also behave like that if you are unable to get away yourself from such a disturbed problem?


Please don’t do that to your home PC


A Day in the life of a Programmer

A Day in the life of a Programmer:

Programmers know their daily activities,

  • How to tackle problems
  • How to overcome the frustration of intricate problems that come in daily life programming

(-: See your day ever passed like the buddy in VIDEO :-)




IT greats: Top 10 greatest IT people

IT greats: Top 10 greatest IT people

Author: Computer Weekly reporter

Posted: 00:00 27 Oct 2006

For every world-famous name with a world famous fortune, such as Bill Gates, Steve Jobs and Michael Dell, there are hundreds of other individuals who have moved the IT industry and its technology inexorably forward.

Fame and fortune has rarely been their immediate spur. A passion for changing the world through technology is the hallmark of the IT Greats. Sometimes they have changed technology, sometimes they have transformed the way technology is marketed or radically altered the way IT is perceived by society.

Some have been involved in great leaps forward, some have made incremental changes that have stood the test of time.

Whatever the case, our industry is truly one where we all stand on the shoulders of giants, and we are proud to pay tribute to some of them in the results of our IT Greats poll.

Top 10 greatest IT people
1. Steve Jobs

2. Tim Berners-Lee

3. Bill Gates

4. James Gosling

5. Linus Torvalds

6. Richard Stallman

7. Arthur C Clark

8. Ted Codd

9. Steve Shirley

10. Martha Lane Fox

1. Steve Jobs: innovator who enjoyed a second bite of the apple

Steve Jobs, the co-founder and chief executive of Apple Computer, topped the Computer Weekly 40th anniversary poll due to the devoted following he has generated through his pioneering work in personal computing and product design.

Jobs was born in 1955 in San Francisco, and during his high school years he showed his early enthusiasm for computing by attending after-school lectures at the Hewlett-Packard Company in Palo Alto, California. He met fellow Apple founder Steve Wozniak during a summer job at HP.

In the autumn of 1974, Jobs, who had dropped out of university after one term, began attending meetings of the Homebrew Computer Club with Steve Wozniak. He took a job as a technician at Atari, a manufacturer of popular video games.

At the age of 21 Jobs saw a computer that Wozniak had designed for his own use and convinced his friend to market the product.

Apple Computer was founded as a partnership on 1 April 1976. Though the initial plan was to sell just printed circuit boards, Jobs and Wozniak ended up creating a batch of completely assembled computers, and entered the personal computer business.

Their second machine, the Apple II, was introduced the following year and became a huge success, turning Apple into an important player in the nascent personal computer industry.

In 1983 Apple launched the Lisa, the first PC with a graphical user interface – an essential element in making computing accessible to the masses. It flopped because of its prohibitive price, but the next year Apple launched the distinct, lower priced Macintosh and it became the first commercially successful GUI machine.

Despite his success in founding Apple, Jobs left following a boardroom row in 1985. But his influence on the computer industry did not end there.

Jobs moved on to found Next Computer, then in 1986 he bought little known The Graphics Group from Lucasfilm, which achieved global dominance in animated feature films during the 1990s, after being renamed Pixar.

Much of Next’s technology had limited commercial success, but it laid the foundation for future computing developments. The company pioneered the object-oriented software development system, Ethernet port connectivity and collaborative software. It was the Next interface builder that allowed Tim Berners-Lee to develop the original world-wide web system at Cern.

Without Jobs, Apple had stumbled. Market share fell while it struggled to release new operating systems. Its answer was to buy Jobs’ company Next, together with its innovative operating system, and welcome back its charismatic former CEO.

On returning to Apple, Jobs drove the company ever deeper into the consumer electronics and computing market, launching the iMac and iPod.

Whether Jobs’ next creation changes the world like the Apple II, or turns out to bomb like the Apple Lisa, his place in computing history is guaranteed.

2. Tim Berners-Lee: father of the web and champion of IT freedom

Dotcoms, bloggers and Google all have one man to thank for their place in the 21st century world. In 1990,
Tim Berners-Lee made the imaginative leap to combine the internet with the hypertext concept, and the worldwide web was born.

Born in 1955 in London, Berners-Lee’s parents were both mathematicians who were employed together on the team that built the Manchester Mark I, one of the earliest computers.

After attending school in London, Berners-Lee went on to study physics at Queen’s College, Oxford, where he built a computer with a soldering iron, TTL gates, an M6800 processor and an old television. While at Oxford, he was caught hacking with a friend and was subsequently banned from using the university computer.
He worked at Plessey Telecommunications from 1976 as a programmer and in 1980 began working as an independent contractor at the European nuclear research centre Cern.

In December 1980, Berners-Lee proposed a project based on the concept of hypertext, to facilitate sharing and updating information among researchers. While there, he built a prototype system called Enquire.

He joined Cern on a full-time basis in 1984 as a fellow. In 1989, Cern was the largest internet node in Europe, and Berners-Lee saw an opportunity. “I just had to take the hypertext idea and connect it to the TCP and DNS ideas,” he said, and the worldwide web was born.

He wrote his initial proposal in March of 1989, and in 1990, with the help of Robert Cailliau, produced a revision which was accepted by his manager, Mike Sendall.

He used similar ideas to those underlying the Enquire system to create the worldwide web, for which he designed and built the first web browser and editor (called World-wide Web and developed on Nextstep) and the first web server called Hypertext Transfer Protocol Daemon (HTTPD).

The first website built was at http://info.cern.ch/ and was put online on 6 August 1991. The URL is still in use today. It provided an explanation of the worldwide web, how one could own a browser and how to set up a web server. It was also the world’s first web directory, since Berners-Lee maintained a list of other websites.

In 1994, Berners-Lee founded the World Wide Web Consortium (W3C) at the Massachusetts Institute of Technology. It comprised various companies willing to create standards and recommendations to improve the quality of the web.

Berners-Lee made his ideas available freely, with no patent and no royalties due. He is now the director of W3C, a senior researcher at MIT’s CSail, and professor of computer science at Southampton University.

3. Bill Gates: mixing maths and money to build microsoft

As joint founder of the world’s biggest software company, Microsoft, Bill Gates’s approach to technology and business was instrumental in making technology available to the masses.

Gates was born in Seattle, Washington in 1955 to a wealthy family: his father was a prominent lawyer and his mother served on the board of directors for First Interstate Bank and The United Way.

At school Gates excelled in mathematics and the sciences and by the age of 13 he was deeply engrossed in software programming.

With other school mates he began programming and bug fixing for the Computer Center Corporation, and in 1970 Gates formed a venture with fellow school student and Microsoft co-founder, Paul Allen, called Traf-O-Data, to make traffic counters using the Intel 8008 processor.

In 1973, Gates enrolled at Harvard University, where he met future business partner Steve Ballmer. Their first venture was to develop a version of the Basic programming language for the Altair 8800, one of the first microcomputers.

Soon afterwards Gates left Harvard to found “Micro-Soft”, which later became Microsoft Corporation, with Allen. Microsoft took off when Gates began licensing his MS-Dos operating systems to manufacturers of IBM PC clones. Its drive to global dominance continued with the development of Windows, its version of the graphical user interface, as an addition to its Dos command line.

By the early 1990s, Windows had driven other Dos-based GUIs like Gem and Geos out of the market. It performed a similar feat with the Office productivity suite.

Gates fought hard to establish Micro­soft’s dominant position in the software industry and has fought even harder to defend it. His ability to get Microsoft software pre-installed on most PCs shipped in the world made Microsoft the world’s largest software house and Gates one of the world’s richest men. It also meant Microsoft found itself on the wrong end of anti-trust legislation in both the US and Europe.

Gates stood down as chief executive of Microsoft in 2000 to focus on software development and on 16 June 2006, he announced that he would move to a part-time role with Microsoft in 2008 to focus on his philanthropic work.

Since 2000, Gates has given away about £15.5bn, a third of his wealth, to charity. Such is his fame in the world outside computing,fictional Gates characters have appeared in cartoons including the Simpsons, South Park and Family Guy.

4. James Gosling

Of your choice of the most influential people in IT, James Gosling is the true geek. Unlike Bill Gates and Steve Jobs, neither of whom finished college, Gosling completed a PhD in computer science and contributed to software innovation at a technical level.

Born in 1955 near Calgary, Canada, Gosling is best known as the father of the Java programming language, the first programme language designed with the internet in mind and which could adapt to highly distributed applications.

Gosling received a BSc in computer science from the University of Calgary in 1977, and while working towards his doctorate he created the original version of the Emacs text editor for Unix (Gosmacs). He also built a multi-processor version of Unix, as well as several compilers and mail systems before starting work in the industry.

In 1984, Gosling joined Sun Microsystems, where he is currently chief technology officer in the developer product group.

In the early 1990s, Gosling initiated and led a project code-named Green that eventually became Java. Green aimed to develop software that would run on a variety of computing devices without having to be customised for each one.

Although much of the technology developed as part of Green never saw the light of day, Gosling realised that some of the underlying principles they had created would be very useful in the internet age.

Sun formally launched Java in 1995. Gosling did the original design of Java and implemented its original compiler and virtual machine. For this achievement he was elected to the US National Academy of Engineering. He has also made major contributions to several other software systems, such as Newa and Gosling Emacs.

Although some critics say Java has not lived up to its initial "write-once-run-anywhere" claim, Gosling's success in the Computer Weekly polls is precisely because Java has allowed the creation of robust, reusable code which runs on devices as diverse at mobile phones, PCs and mainframes.

5. Linus Torvalds

As the creator of the Linux operating system, Linus Torvalds has been a driving force behind the whole open source movement, which represents not only an ever increasing challenge to proprietary software, but is also the inspiration for the industry to move to open standards.

Torvalds remains the ultimate authority on what new code is incorporated into the Linux kernel.

6. Richard Stallman

Richard Stallman is the founder of the GNU Project, an initiative to develop a complete Unix-like operating system which is free software. Stallman has written several popular tools, created the GNU licence and campaigns against software patents.

7. Arthur C Clarke

2001: A Space Odyssey writer Arthur C Clarke has consistently been ahead of his time in predicting how technology will change the world. Most notably, in 1945 he suggested that geostationary satellites would make ideal telecoms relays.

8. Ted Codd

Ted Codd created 12 rules on which every relational database is built - an essential ingredient for building business computer systems.

9. Steve Shirley

Steve Shirley was an early champion of women in IT. She founded the company now known as Xansa, pioneered new work practices and in doing so created new opportunities for women in technology.

10. Martha Lane Fox

With Brent Hoberman, Martha Lane Fox created Lastminute.com in 1998, and as "the face" of Lastminute raised the profile of e-commerce ever higher in the public consciousness.

Readers hail Dilbert the guru of corporate culture

According to Computer Weekly readers, Dilbert, which features every week on the back pages of the magazine, has more insight into corporate life and organisation than any number of highly paid management consultants could ever achieve.

Written and drawn by Scott Adams, Dilbert portrays corporate culture as a world of bureaucracy for its own sake, where employees' skills and efforts are not rewarded. Much of the humour emerges from the characters wrestling with the obviously ridiculous decisions and behaviour of management.

1955: a good year for computing

The top four people in our poll were all born in 1955, making it a very beneficial year for the world of computing.

It may have been a good year for computing, but 1955 was a sad year for science, as Albert Einstein died on 18 April.

It was also the year that the first McDonald's fast food franchise was opened: we'll leave you to make up you own mind about that one.

Your big names

Outside the main choices for greatest hardware, the most popular readers' suggestions were:

1. Ken Olsen, founder of Dec, who invented the minicomputer

2. Clive Sinclair, home computer visionary

3. Vint Cerf, one of the internet's founding fathers

4. Bill Joy, co-founder of Sun Microsystems

5. Larry Ellison, founder of Oracle

6. Steve Wozniak, Apple co-founder

7. Dennis Ritchie, inventor of the C programming language

8. Donald Davies, co-inventor of packet switching

9. Ken Thompson, co-creator of Unix

10. Grace Hopper, Cobol pioneer

10 Warning Signs of Project Failure

10 Warning Signs of Project Failure
By
Allen Bernard
October 18, 2007

Unless you are in a mature industry such as banking or insurance, where information is the life-blood of what you do, chances are you will be familiar with at least some of these 10 project management failings put together by Robert Francis Group analyst Mimi Ho.

"One, they're right on the button and two, if you take a look at the large majority of them, it all has to do with project planning and early stages of analysis that companies like to jump over," said Jeff Monteforte, owner of Exential, an independent project management consultancy in Cleveland, Ohio.

In other words, when IT projects fail it rarely is a result of the technology. At its core, project management is all about people.

"Even in some of our clients, some of them are doing very well … and others are just starting where they don't even have executive support and they get the executives saying 'Just start the project I don't care what you do'," said Ms. Ho. "And projects fail … and they're like 'It's IT's fault.'"

The Top 3 problems Monteforte, a 20-year veteran of the project management business, encounters most often are: lack of executive support; changes to project scope and the lack of change management; and failure to establish user expectations which leads all too often to unrealistic deadlines.

The Top 3 project killers he encounters are: lack of executive support; lack of pre-project planning; and insufficient people (not monetary) resources allocated to get the project done.

Ms. Ho also sees the same problems—especially lack of executive support—as Monteforte but adds poorly defined project requirements to his lists.

"You need to speak with stakeholders directly because the bill changes or they visualize the project being a certain way but when it's communicated the project could be different," said Ms. Ho.

According to RFG and Ms. Ho, what follows, in no particular order, are the 10 most common pitfalls to successful project completion:

Undefined or poorly defined project requirements. - Project managers should collaborate directly with key project stakeholders to define specific detailed project requirements and deliverables. Defining specific project requirements is necessary to maintain alignment of project tasks to desired business outputs, as well as to ensure that projects have clear and specific project objectives established.

While this step may seem obvious, many companies will skip this stage and go right to solutions to jump start a project. Business and/or IT executives assume the requirements (such as controls, dashboards, data, dependencies, functionality, integration, metrics, outputs, and workflow) are met without performing any confirming analysis.

These projects tend to fail and the companies usually encounter over spending, project restarts, rework, and/or unmet expectations.

Lack of project planning. - Once the requirements are known, then conducting thorough, upfront project scope planning is an essential next step to help project managers and stakeholders accurately and clearly define project scope.

It is important for people to understand that there is more than one way to achieve the requirements and that scope and cost vary by approach. Project scope management is therefore necessary to develop reasonable project estimates, enhance the management of customer and stakeholder expectations, and mitigate project risks such as cost overruns and schedule delays.

Project managers should establish and standardize a scope management process to develop concise project scope statements and credible budget and schedule estimates.

Lack of or poorly developed budget forecast. - Thorough research and preparation is necessary to develop a reasonable budget estimate. Many companies will skip this step or just do a very rudimentary estimate due to the amount of work needed to complete the task.

Some companies that do not maintain internal archives of project costs turn to external consultancies to acquire external spending/budget information on companies that have completed similar projects in a similar market.

Using the estimated budget, project managers should collaborate with stakeholders to help further refine the project scope and final deliverables. Project managers should use their initial budget to base actual spending plans as well as to proactively track spending and respond quickly to potential issues to prevent shortfalls in the budget.

Lack of stakeholder involvement. - Project managers should ensure that primary project stakeholders are involved with the project from the beginning and throughout the entire project. This is crucial to ensure that visions are properly communicated, defined, and verified.

It is very common for project efforts to be delegated to staff that do not have sufficient knowledge or understanding of the desired effort. As a result, projects are defined incorrectly and the projects delivered do not meet the expectations of key stakeholders.

Lack of executive support. - An IT project can be highly political and may end up involving an excessive number of unnecessary or incorrect participants. IT executives should seek ongoing senior management endorsement and enforcement of the planning process to keep the effort on track and to minimize pushback from line of business (LOB) managers.

Support from senior management and staff involvement are both needed to drive and keep the effort focused and moving. Ownership of the project must be shared to satisfy the demands of user management. IT executives must convey this message to senior management to retain involvement and participation.

Frequent or large changes to project scope. - Scope changes can significantly impact the cost, schedule, risks and quality of the entire effort. Project managers should watch out for early and frequent changes to the project scope.

While scope is defined early in the planning and estimation phases, there are valid reasons for change. For example, a stakeholder may acquire additional insight into a problem during the course of the project or external market conditions and/or government regulations can drive requests that extend beyond the initial project scope. However, changes to project scope can also occur as a result of developing a poor initial scope document.

Project managers must ensure that adequate time is spent on defining and refining the work effort directly with key stakeholders.
Lack of change management process. - Project changes will occur. However, uncontrolled changes and insufficient change management processes will increase the probability of project failure. A formal and structured change management process is necessary to ensure effects of any changed requirements are properly analyzed, prioritized, and balanced according to the project's budget, schedule, and scope.

Project managers should consistently and publicly take a phased approach to projects, so that users understand that not all changes must be completed for the current release. This will help acceptance of trading off specific desired changes for faster availability of greater functionality. This will also help reduce the impact of change onto the project, and allow for cost and time containment.

Failure to establish appropriate client/user expectations. Disputes often occur as a result of mismatched expectations. Missed project targets will cause delays, rework, and additional project spending. Setting user expectations is necessary to establish a baseline of what and what not to expect from the final deliverable.

Project managers should work with key stakeholders in establishing and prioritizing project requirements as well as reviewing budgets and schedules. Additionally, all people involved in the project effort should have periodic joint sessions, to ensure the same communications on project expectations are received by everyone.

This process helps keep users involved and abreast of the project's status, as well as minimizing the potential for misunderstanding of project expectations between stakeholders.

Unrealistic deadlines. - Stakeholders want their projects completed now. In some harsh environments, they may question IT's commitment and effort. IT executives and project managers must work with stakeholders to help them understand what is possible with the level of incumbent IT resources.

Project managers should collaborate with key stakeholders in defining reasonable project schedules and deadlines to ensure that business conditions and requirements are met and better manage expectation levels.

Project managers will need to ensure that project cost, scope, and time are optimally balanced to achieve the desired deliverables and the desired time. Effective planning and monitoring are necessary to help develop a strong start for the project. However, project managers must remain aware and anticipate change as re-planning is necessary throughout the project.

Insufficient resources. - Required resources are often underestimated and scheduled inaccurately. Companies often encounter problems with resource allocation, as many companies to do not spend sufficient time on resource scheduling and proper management.

In fact, it is very common for companies to overestimate the on-boarding of staff to a project, which immediately causes the project to be late and in trouble, impairing IT's image with LOB managers and executives. In addition, resources are often utilized ineffectively, especially when individuals are required to support multiple projects concurrently. Insufficient resource supply will cause delays and impact overlapping projects.

Project managers should plan according to the established project schedule estimates and work with concurrent project schedules to help ensure that resources are properly scheduled.

Summary

All companies have experienced projects that have gone over budget, schedule, and scope. However, project managers can learn from past historical data, experiences of peer companies, and project management organizations.

Taking a proactive approach to preventing project failure is a necessary first step to overcoming repeated failure. Sufficient research and planning as well as patience in establishing necessary project processes are essential to developing a solid project management foundation.

Project managers must ensure that the initial project plan is strong enough to sustain the project throughout its life cycle. A project plan should be assessed on the project's alignment with business strategies, budget, the cost/benefit analysis, relevance, resource requirements, and scope to help determine its value contribution to the enterprise.


The top 10 reasons Web sites get hacked

Experts say the people who actually build Web applications aren't paying much attention to security; a non-profit group is trying to solve that

By Jon Brodkin, Network World
October 05, 2007

Web security is at the top of customers' minds after many well-publicized personal data breaches, but the people who actually build Web applications aren't paying much attention to security, experts say.

"They're totally ignoring it," says IT consultant Joel Snyder. "When you go to your Web site design team, what you're looking for is people who are creative and able to build these interesting Web sites... That's No. 1, and No. 9 on the list would be that it's a secure Web site."

The biggest problem is designers aren't building walls within Web applications to partition and validate data moving between parts of the system, he says.

Security is usually something that's considered after a site is built rather than before it is designed, agrees Khalid Kark, senior analyst at Forrester.

"I'd say the majority of Web sites are hackable," Kark says. "The crux of the problem is security isn't thought of at the time of creating the application."

That's a big problem, and it's one the nonprofit Open Web Application Security Project (OWASP) is trying to solve. An OWASP report called "The Ten Most Critical Web Application Security Vulnerabilities" was issued this year to raise awareness about the biggest security challenges facing Web developers.

The first version of the list was released in 2004, but OWASP Chairman Jeff Williams says Web security has barely improved. New technologies such as AJAX and Rich Internet Applications that make Web sites look better also create more attack surfaces, he says. Convincing businesses their Web sites are insecure is no easy task, though.

"It's frustrating to me, because these flaws are so easy to find and so easy to exploit," says Williams, who is also CEO and co-founder of Aspect Security. "It's like missing a wall on a house."

Here is a summary of OWASP's top 10 Web vulnerabilities, including a description of each problem, real-world examples and how to fix the flaws.

1. Cross site scripting (XSS)

The problem: The "most prevalent and pernicious" Web application security vulnerability, XSS flaws happen when an application sends user data to a Web browser without first validating or encoding the content. This lets hackers execute malicious scripts in a browser, letting them hijack user sessions, deface Web sites, insert hostile content and conduct phishing and malware attacks.

Attacks are usually executed with JavaScript, letting hackers manipulate any aspect of a page. In a worst-case scenario, a hacker could steal information and impersonate a user on a bank's Web site, according to Snyder.

Real-world example: PayPal was targeted last year when attackers redirected PayPal visitors to a page warning users their accounts had been compromised. Victims were redirected to a phishing site and prompted to enter PayPal login information, Social Security numbers and credit card details. PayPal said it closed the vulnerability in June 2006.

How to protect users: Use a whitelist to validate all incoming data, which rejects any data that's not specified on the whitelist as being good. This approach is the opposite of blacklisting, which rejects only inputs known to be bad.

Additionally, use appropriate encoding of all output data. "Validation allows the detection of attacks, and encoding prevents any successful script injection from running in the browser," OWASP says.

2. Injection flaws

The problem: When user-supplied data is sent to interpreters as part of a command or query, hackers trick the interpreter -- which interprets text-based commands -- into executing unintended commands. "Injection flaws allow attackers to create, read, update, or delete any arbitrary data available to the application," OWASP writes. "In the worst-case scenario, these flaws allow an attacker to completely compromise the application and the underlying systems, even bypassing deeply nested firewalled environments."

Real-world example: Russian hackers broke into a Rhode Island government Web site to steal credit card data in January 2006. Hackers claimed the SQL injection attack stole 53,000 credit card numbers, while the hosting service provider claims it was only 4,113.

How to protect users: Avoid using interpreters if possible. "If you must invoke an interpreter, the key method to avoid injections is the use of safe APIs, such as strongly typed parameterized queries and object relational mapping libraries," OWASP writes.

3. Malicious file execution

The problem: Hackers can perform remote code execution, remote installation of rootkits, or completely compromise a system. Any type of Web application is vulnerable if it accepts filenames or files from users. The vulnerability may be most common with PHP, a widely used scripting language for Web development.

Real-world example: A teenage programmer discovered in 2002 that Guess.com was vulnerable to attacks that could steal more than 200,000 customer records from the Guess database, including names, credit card numbers and expiration dates. Guess agreed to upgrade its information security the next year after being investigated by the Federal Trade Commission.

How to protect users: Don't use input supplied by users in any filename for server-based resources, such as images and script inclusions. Set firewall rules to prevent new connections to external Web sites and internal systems.

4. Insecure direct object reference

The problem: Attackers manipulate direct object references to gain unauthorized access to other objects. It happens when URLs or form parameters contain references to objects such as files, directories, database records or keys.

Banking Web sites commonly use a customer account number as the primary key, and may expose account numbers in the Web interface.

"References to database keys are frequently exposed," OWASP writes. "An attacker can attack these parameters simply by guessing or searching for another valid key. Often, these are sequential in nature."

Real-world example: An Australian Taxation Office site was hacked in 2000 by a user who changed a tax ID present in a URL to access details on 17,000 companies. The hacker e-mailed the 17,000 businesses to notify them of the security breach.

How to protect users: Use an index, indirect reference map or another indirect method to avoid exposure of direct object references. If you can't avoid direct references, authorize Web site visitors before using them.

5. Cross site request forgery

The problem: "Simple and devastating," this attack takes control of victim's browser when it is logged onto a Web site, and sends malicious requests to the Web application. Web sites are extremely vulnerable, partly because they tend to authorize requests based on session cookies or "remember me" functionality. Banks are potential targets.

"Ninety-nine percent of the applications on the Internet are susceptible to cross site request forgery," Williams says. "Has there been an actual exploit where someone's lost money? Probably the banks don't even know. To the bank, all it looks like is a legitimate transaction from a logged-in user."

Real-world example: A hacker known as Samy gained more than a million "friends" on MySpace.com with a worm in late 2005, automatically including the message "Samy is my hero" in thousands of MySpace pages. The attack itself may not have been that harmful, but it was said to demonstrate the power of combining cross site scripting with cross site request forgery. Another example that came to light one year ago exposed a Google vulnerability allowing outside sites to change a Google user's language preferences.

How to protect users: Don't rely on credentials or tokens automatically submitted by browsers. "The only solution is to use a custom token that the browser will not 'remember,'" OWASP writes.

6. Information leakage and improper error handling

The problem: Error messages that applications generate and display to users are useful to hackers when they violate privacy or unintentionally leak information about the program's configuration and internal workings.

"Web applications will often leak information about their internal state through detailed or debug error messages. Often, this information can be leveraged to launch or even automate more powerful attacks," OWASP says.

Real-world example: Information leakage goes well beyond error handling, applying also to breaches occurring when confidential data is left in plain sight. The ChoicePoint debacle in early 2005 thus falls somewhere in this category. The records of 163,000 consumers were compromised after criminals pretending to be legitimate ChoicePoint customers sought details about individuals listed in the company's database of personal information. ChoicePoint subsequently limited its sales of information products containing sensitive data.

How to protect users: Use a testing tool such as OWASP'S WebScarab Project to see what errors your application generates. "Applications that have not been tested in this way will almost certainly generate unexpected error output," OWASP writes.

Another tip: disable or limit detailed error handling, and don't display debug information to users.

7. Broken authentication and session management

The problem: User and administrative accounts can be hijacked when applications fail to protect credentials and session tokens from beginning to end. Watch out for privacy violations and the undermining of authorization and accountability controls.

"Flaws in the main authentication mechanism are not uncommon, but weaknesses are more often introduced through ancillary authentication functions such as logout, password management, timeouts, remember me, secret question and account update," OWASP writes.

Real-world example: Microsoft had to eliminate a vulnerability in Hotmail that could have let malicious JavaScript programmers steal user passwords in 2002. Revealed by a networking products reseller, the flaw was vulnerable to e-mails containing Trojans that altered the Hotmail user interface, forcing users to repeatedly reenter their passwords and unwittingly send them to hackers.

How to protect users: Communication and credential storage has to be secure. The SSL protocol for transmitting private documents should be the only option for authenticated parts of the application, and credentials should be stored in hashed or encrypted form.

Another tip: get rid of custom cookies used for authentication or session management.

8. Insecure cryptographic storage

The problem: Many Web developers fail to encrypt sensitive data in storage, even though cryptography is a key part of most Web applications. Even when encryption is present, it's often poorly designed, using inappropriate ciphers.

"These flaws can lead to disclosure of sensitive data and compliance violations," OWASP writes.

Real-world example: The TJX data breach that exposed 45.7 million credit and debit card numbers. A Canadian government investigation faulted TJX for failing to upgrade its data encryption system before it was targeted by electronic eavesdropping starting in July 2005.

Furthermore, generate keys offline, and never transmit private keys over insecure channels.

It's pretty common to store credit card numbers these days, but with a Payment Card Industry Data Security Standard https://www.pcisecuritystandards.org/ compliance deadline coming next year, OWASP says it's easier to stop storing the numbers altogether.

9. Insecure communications

The problem: Similar to No. 8, this is a failure to encrypt network traffic when it's necessary to protect sensitive communications. Attackers can access unprotected conversations, including transmissions of credentials and sensitive information. For this reason, PCI standards require encryption of credit card information transmitted over the Internet.

Real-world example: TJX again. Investigators believe hackers used a telescope-shaped antenna and laptop computer to steal data exchanged wirelessly between portable price-checking devices, cash registers and store computers, the Wall Street Journal reported.

"The $17.4-billion retailer's wireless network had less security than many people have on their home networks," the Journal wrote. TJX was using the WEP encoding system, rather than the more robust WPA.

How to protect users: Use SSL on any authenticated connection or during the transmission of sensitive data, such as user credentials, credit card details, health records and other private information. SSL or a similar encryption protocol should also be applied to client, partner, staff and administrative access to online systems. Use transport layer security or protocol level encryption to protect communications between parts of your infrastructure, such as Web servers and database systems.

10. Failure to restrict URL access

The problem: Some Web pages are supposed to be restricted to a small subset of privileged users, such as administrators. Yet often there's no real protection of these pages, and hackers can find the URLs by making educated guesses. Say a URL refers to an ID number such as "123456." A hacker might say 'I wonder what's in 123457?' Williams says.

The attacks targeting this vulnerability are called forced browsing, "which encompasses guessing links and brute force techniques to find unprotected pages," OWASP says.

Real-world example: A hole on the Macworld Conference & Expo Web site this year let users get "Platinum" passes worth nearly $1,700 and special access to a Steve Jobs keynote speech, all for free. The flaw was code that evaluated privileges on the client but not on the server, letting people grab free passes via JavaScript on the browser, rather than the server.

How to protect users: Don't assume users will be unaware of hidden URLs. All URLs and business functions should be protected by an effective access control mechanism that verifies the user's role and privileges. "Make sure this is done ... every step of the way, not just once towards the beginning of any multistep process,' OWASP advises.