Welcome!

Cloud Security Authors: Toddy Mladenov, Liz McMillan, Jim Hansen, Carmen Gonzalez, Peter Silva

Related Topics: Agile Computing, Cloud Security

Agile Computing: Blog Feed Post

Social Media: Change, Control and Security

Facebook’s scope and ambition is also the source of its security complexity

As I write, Facebook is in the process of executing the biggest IPO in US corporate history. Yet, its security model is so involved, and changes so frequently, that not only have people found it necessary to publish sets of guidelines on how to maintain and update Facebook’s security settings, (http://www.facebook.com/note.php?note_id=10150261846610766 ) but also found that they have their hands full keeping these guidelines up to date. At this point, I must admit I’ve never had an account on Facebook; when they launched here in the UK I was invited to sign up by a number of early-adopter friends, but after a good hard look at their security and privacy policy, I said “you have got to be [elided] joking”.

Facebook’s scope and ambition, is also the source of its security complexity. By trying to be “the aggregation point of everything”, for its users – photo albums, bio and status details, blog, IM, music player, games console, etc etc – as well as attempting to tie it all together into the much-discussed “social graph” and using this to attract an income stream from highly-targetable advertising, I believe it has become sufficiently encumbered by having to deal with such a number of diverse entities with different vested interests that the problem of constructing a security policy which will “please a working percentage of these entities, a working percentage of the time” has become effectively intractable.

This may also be why Google+ seems to be controlling its features carefully. Also, I think Google are taking a very interesting approach in unifying their security, privacy and use policies across their offerings; kudos to them for taking that challenge on.

So, I’ve taken to considering where social media will go, from here; as well as seeing what’s happening at Facebook, I’m also seeing a bunch of people writing about how social media is another tech bubble all set to burst. While I firmly believe social media is here to stay, it’s going to get more Darwinian; as with the earlier tech bubble there’lll be casualties, but the result will be a more business-focussed industry.

I think the pendulum of control over information and its sharing is going to swing back, and much more control is going to be placed in the users’ hands; and this has to happen via a mechanism much more straightforward than Facebook controls. Here’s how I think it’s going to work.

What users are going to do, rather than look to a Facebook to host and aggregate all content and present a unified view of it, is run content aggregators locally. I can see these looking something like the Flipboard app for iPad (of which I happen to be rather a fan). From a UI perspective, I’d have a virtual “book of stuff” per friend, which would have pages, articles and photos aggregated from all the data sources they’ve chosen to share with me. I’d need my address book to be extensible to take URLs (and where applicable, passwords) for all these sources, per friend, but that’s not exactly hard.

When I want to share something with a friend, I post it to the appropriate site, using the most appropriate account I’ve given them access to. There’s no more need for fiddling with access controls, people who want to “share stuff” can just create a new account for sharing with particular people or groups of people. It’s all a bit retro, but it means that the account is associated with the group of people involved, not uniquely and verifiably me as an individual; therefore, I get to dictate whatever identities I want to use, wherever I want to use them. There’ll be a bunch of account info to keep track of from the sharer’s end too, but this is a solved problem.

This will also work if the pendulum swings far enough that users start hosting content on their own servers and devices, as some have predicted.

Therefore, the sites I think will do well out of this are those which do one or two things only, and do them very well, by facilitating sharing of a particular kind of content, under various easily-created accounts which are not tied to a single “real” verifiable ID per user. So Blogspot, Flickr, Wayin et al can breathe easy.

However, the flipside of the idea of returning a bunch of control to the users in this way, is that it becomes more difficult for a site to construct a business model; unless all the sites set cookies and users have to accept them it ceases to be possible to construct a useful social graph (which from a user privacy perspective, is A Good Thing), and as users would be consuming something like an RSS feed, it becomes difficult to insert revenue-generating advertising except at the point where users get to add content to their feeds.

So, the outstanding question for a more user-controllable social media, becomes how to monetise it. It could be that this halfway-house between social media-hosted content and local aggregation won’t wash, and the only  way in which people can make money involves letting the pendulum swing completely the other way by social media companies charging end users subscriptions to host their own individual micro-sites on a cloud infrastructure; whatever happens, it’s not going to be dull…

Read the original blog entry...

More Stories By Bob Gourley

Bob Gourley writes on enterprise IT. He is a founder and partner at Cognitio Corp and publsher of CTOvision.com

Comments (0)

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.


@ThingsExpo Stories
"There's a growing demand from users for things to be faster. When you think about all the transactions or interactions users will have with your product and everything that is between those transactions and interactions - what drives us at Catchpoint Systems is the idea to measure that and to analyze it," explained Leo Vasiliou, Director of Web Performance Engineering at Catchpoint Systems, in this SYS-CON.tv interview at 18th Cloud Expo, held June 7-9, 2016, at the Javits Center in New York Ci...
The 20th International Cloud Expo has announced that its Call for Papers is open. Cloud Expo, to be held June 6-8, 2017, at the Javits Center in New York City, brings together Cloud Computing, Big Data, Internet of Things, DevOps, Containers, Microservices and WebRTC to one location. With cloud computing driving a higher percentage of enterprise IT budgets every year, it becomes increasingly important to plant your flag in this fast-expanding business opportunity. Submit your speaking proposal ...
WebRTC is the future of browser-to-browser communications, and continues to make inroads into the traditional, difficult, plug-in web communications world. The 6th WebRTC Summit continues our tradition of delivering the latest and greatest presentations within the world of WebRTC. Topics include voice calling, video chat, P2P file sharing, and use cases that have already leveraged the power and convenience of WebRTC.
DevOps is being widely accepted (if not fully adopted) as essential in enterprise IT. But as Enterprise DevOps gains maturity, expands scope, and increases velocity, the need for data-driven decisions across teams becomes more acute. DevOps teams in any modern business must wrangle the ‘digital exhaust’ from the delivery toolchain, "pervasive" and "cognitive" computing, APIs and services, mobile devices and applications, the Internet of Things, and now even blockchain. In this power panel at @...
20th Cloud Expo, taking place June 6-8, 2017, at the Javits Center in New York City, NY, will feature technical sessions from a rock star conference faculty and the leading industry players in the world. Cloud computing is now being embraced by a majority of enterprises of all sizes. Yesterday's debate about public vs. private has transformed into the reality of hybrid cloud: a recent survey shows that 74% of enterprises have a hybrid cloud strategy.
Discover top technologies and tools all under one roof at April 24–28, 2017, at the Westin San Diego in San Diego, CA. Explore the Mobile Dev + Test and IoT Dev + Test Expo and enjoy all of these unique opportunities: The latest solutions, technologies, and tools in mobile or IoT software development and testing. Meet one-on-one with representatives from some of today's most innovative organizations
SYS-CON Events announced today that Super Micro Computer, Inc., a global leader in Embedded and IoT solutions, will exhibit at SYS-CON's 20th International Cloud Expo®, which will take place on June 7-9, 2017, at the Javits Center in New York City, NY. Supermicro (NASDAQ: SMCI), the leading innovator in high-performance, high-efficiency server technology, is a premier provider of advanced server Building Block Solutions® for Data Center, Cloud Computing, Enterprise IT, Hadoop/Big Data, HPC and E...
More and more brands have jumped on the IoT bandwagon. We have an excess of wearables – activity trackers, smartwatches, smart glasses and sneakers, and more that track seemingly endless datapoints. However, most consumers have no idea what “IoT” means. Creating more wearables that track data shouldn't be the aim of brands; delivering meaningful, tangible relevance to their users should be. We're in a period in which the IoT pendulum is still swinging. Initially, it swung toward "smart for smart...
The WebRTC Summit New York, to be held June 6-8, 2017, at the Javits Center in New York City, NY, announces that its Call for Papers is now open. Topics include all aspects of improving IT delivery by eliminating waste through automated business models leveraging cloud technologies. WebRTC Summit is co-located with 20th International Cloud Expo and @ThingsExpo. WebRTC is the future of browser-to-browser communications, and continues to make inroads into the traditional, difficult, plug-in web co...
"A lot of times people will come to us and have a very diverse set of requirements or very customized need and we'll help them to implement it in a fashion that you can't just buy off of the shelf," explained Nick Rose, CTO of Enzu, in this SYS-CON.tv interview at 18th Cloud Expo, held June 7-9, 2016, at the Javits Center in New York City, NY.
Buzzword alert: Microservices and IoT at a DevOps conference? What could possibly go wrong? In this Power Panel at DevOps Summit, moderated by Jason Bloomberg, the leading expert on architecting agility for the enterprise and president of Intellyx, panelists peeled away the buzz and discuss the important architectural principles behind implementing IoT solutions for the enterprise. As remote IoT devices and sensors become increasingly intelligent, they become part of our distributed cloud enviro...
SYS-CON Events announced today that MobiDev, a client-oriented software development company, will exhibit at SYS-CON's 20th International Cloud Expo®, which will take place June 6-8, 2017, at the Javits Center in New York City, NY, and the 21st International Cloud Expo®, which will take place October 31-November 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. MobiDev is a software company that develops and delivers turn-key mobile apps, websites, web services, and complex softw...
With major technology companies and startups seriously embracing IoT strategies, now is the perfect time to attend @ThingsExpo 2016 in New York. Learn what is going on, contribute to the discussions, and ensure that your enterprise is as "IoT-Ready" as it can be! Internet of @ThingsExpo, taking place June 6-8, 2017, at the Javits Center in New York City, New York, is co-located with 20th Cloud Expo and will feature technical sessions from a rock star conference faculty and the leading industry p...
The security needs of IoT environments require a strong, proven approach to maintain security, trust and privacy in their ecosystem. Assurance and protection of device identity, secure data encryption and authentication are the key security challenges organizations are trying to address when integrating IoT devices. This holds true for IoT applications in a wide range of industries, for example, healthcare, consumer devices, and manufacturing. In his session at @ThingsExpo, Lancen LaChance, vic...
Who are you? How do you introduce yourself? Do you use a name, or do you greet a friend by the last four digits of his social security number? Assuming you don’t, why are we content to associate our identity with 10 random digits assigned by our phone company? Identity is an issue that affects everyone, but as individuals we don’t spend a lot of time thinking about it. In his session at @ThingsExpo, Ben Klang, Founder & President of Mojo Lingo, discussed the impact of technology on identity. Sho...
Manufacturers are embracing the Industrial Internet the same way consumers are leveraging Fitbits – to improve overall health and wellness. Both can provide consistent measurement, visibility, and suggest performance improvements customized to help reach goals. Fitbit users can view real-time data and make adjustments to increase their activity. In his session at @ThingsExpo, Mark Bernardo Professional Services Leader, Americas, at GE Digital, discussed how leveraging the Industrial Internet and...
IoT generates lots of temporal data. But how do you unlock its value? You need to discover patterns that are repeatable in vast quantities of data, understand their meaning, and implement scalable monitoring across multiple data streams in order to monetize the discoveries and insights. Motif discovery and deep learning platforms are emerging to visualize sensor data, to search for patterns and to build application that can monitor real time streams efficiently. In his session at @ThingsExpo, ...
What are the new priorities for the connected business? First: businesses need to think differently about the types of connections they will need to make – these span well beyond the traditional app to app into more modern forms of integration including SaaS integrations, mobile integrations, APIs, device integration and Big Data integration. It’s important these are unified together vs. doing them all piecemeal. Second, these types of connections need to be simple to design, adapt and configure...
"ReadyTalk is an audio and web video conferencing provider. We've really come to embrace WebRTC as the platform for our future of technology," explained Dan Cunningham, CTO of ReadyTalk, in this SYS-CON.tv interview at WebRTC Summit at 19th Cloud Expo, held November 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA.
A critical component of any IoT project is what to do with all the data being generated. This data needs to be captured, processed, structured, and stored in a way to facilitate different kinds of queries. Traditional data warehouse and analytical systems are mature technologies that can be used to handle certain kinds of queries, but they are not always well suited to many problems, particularly when there is a need for real-time insights.