Categories
Google? Doh! Web 0.1

Google: please hire a UX person for Gmail

Who at Google even thought this sounded like a good idea?

1994 phoned: they want their GeoCities school of web design back.

(I’ve had to switch to non-javascript Gmail because the latest “forced update” of Gmail has some JS bugs in it that make it run very slow, lose emails, and overheat my laptop. Triple whammy (all because of a bug in a javascript somewhere, so far as I can tell))

Categories
amusing

“dinosaurs basically farted themselves to death”

Because there’s just not enough funny in the news these days:

:O

Categories
MMOG development programming security

LinkedIn (maybe) just leaked your password, won’t tell you; change it now

I’ve posted a few times over the years the … disappointing … state of LinkedIn’s engineering. But this takes the biscuit: it appears they were storing deliberately insecure passwords, and someone leaked the list:

http://news.ycombinator.com/item?id=4073309

(that page has links + info on how to check if your own password is in the mega list)

How bad is this?

  1. Many people have checked their personal, unique, passwords, that they claim to have only ever used on LinkedIn.com – and they’ve hit matches in the file.
  2. LinkedIn hasn’t told its users about the possible leak, more than 24 hours after it happened
  3. Many users re-use their passwords on other sites; any hackers could easily have stolen many accounts on other sites by now

How unlucky is LinkedIn?

This file is unsalted. That’s about as smart as locking your front door and then leaving the key under the mat – on the outside.

  1. Every tutorial, book, “newbie guide”, etc about using databases and writing login pages tells you never ever to do what was done here
  2. For any tech team, it is easy to check if this is what you’re doing, and tell your boss “uh, we need to fix that”
  3. It only takes a few *minutes* to prevent this problem, permanently. It’s not difficult

If LinkedIn were a small site, with a few hundred thousands users, I’d accuse them of laziness. But with 165million users, and a public company, you’d be looking at stunning incompetence by the tech wing of the company (the CIO and CTO never bothered to audit their own security?), or wilful negligence (no-one knew? really?).

Here’s hoping it’s a hoax…

Categories
games design startup advice

MakieWorld raises $1.4m funding for digital-to-physical toys

http://gigaom.com/europe/makie-future-doll-toy-funding/

“We’re making toys using game data and 3D printing,” explains Alice Taylor, Makielab co-founder and CEO. “We call ourselves a smart toy company, and for us that means there’s a digital side to it by default.”

The company slogan is “the action doll you design”, and here’s the concept in a nutshell: you hit the Makie website and create your own avatar, choosing from a range of shapes, sizes, features and outfits — the kind of thing that’s recognizable from all kinds of MMOs, virtual worlds and kids’ games. But then comes the magic: press a button and you get your digital figure turned into the real thing, produced as a one-off in bone-white plastic using cutting edge manufacturing techniques.

Congrats!