You may have read this headline about the “very sophisticated hack” in a letter sent to you when a company or other data collector gets caught with lax security that they only then, after the (latest) hack, start to patch.
Thus, by all outward appearances, most companies seem to be reactionary: – IF a data breach occurs – THEN, a company take some kind of action. Then, the company often makes the data breach “sound” like there was absolutely nothing they could have done about it — had they *been* proactive in the first place, of course.
Getting your personal data takes at least two steps:
1. Breaching a company’s server and firewall safeguards — Most of the efforts to keep your data safe are usually here.
2. Accessing and then downloading data — Encryption needed to protect data if server breached.
You are probably now wondering if companies encrypt (scramble) your most personal data, like health data, on their servers. We can’t know for sure, but it appears that in most cases, based on all the disclosures from the companies themselves, they don’t.
What we do know is that break-ins and theft of your personal data is happening at higher and higher rates. Companies are not accountable to us and seem to suffer no penalties for what we, as customers and citizens, must go through to deal with personal data being compromised.
A rare exception is that Target has proposed a settlement from the 2013 hack for up to $10,000 for each customer for damages. From the Target hack, hackers stole information from 40 Million credit cards. (This settlement is pending approval at this time.)
The evidence that our data was not secured (encrypted) on a company’s server comes when we’re warned, via a “it was a sophisticated hack” letter from the company to us that … “hackers have obtained personal information”. If the hackers have obtained information, then it was not encrypted or the letter would indicate this fact and we could breathe a small sigh of relief. Furthermore, this one letter is usually the last thing we hear from the company since the hackers are rarely, if ever, caught.
It’s interesting that most of us use encryption every day without usually even thinking about it. We encrypt our hard drives, we encrypt our iPhones (standard in iOS 8 with password) or other devices, we encrypt our credit card purchases over the Internet, etc.
Although you might feel secure with the little lock icon on your browser, it is not enough to use HTTPS to secure your Internet traffic during transit if your data is then stored unencrypted on an insecure server. This HTTPS-only expectation is like taking a armored truck (in this example, the secure HTTPS “transit” piece) with cash to a (non-secured) table at a restaurant (in this example, the possibly insecure server where your data lives) and leaving the cash there (and hoping the cash would still be there the next day).
————
While no company can promise total protection and security of online data, at Hurricane, our private clouds are encrypted using AES 256 bit encryption. To connect to your cloud data, you must additionally use HTTPS. Thus, your cloud data is strongly encrypted on the server itself and in transit.
Furthermore, we use industry Enterprise Linux with advanced firewall filtering for your additional security and piece of mind.
Please contact us for more information on setting up a private cloud for you with your domain account already hosted by us.
——–
Please read our disclaimer available from our home page
Personalized or data-driven marketing to your customers, “smart marketing”, is something few, if any companies actually do. Most companies still just send the “blast-a-gram” to everybody with zero personalization or forethought. These types of marketing “messages” typically get thrown into the trash without the recipient (home owner, or other recipient) even glancing at the (wasted) mailing.
By following a few simple steps, you can improve your odds of getting a positive customer marketing response. And, at the same time, not waste time and money trying to sell your services to people who don’t want them or perhaps couldn’t even use them. There are no guarantees in marketing, of course, smart marketing or otherwise, but with some filtering, you can weed out the least likely to use your product or services.
Below is a simple example of how just using simple customer data and a database could save you lots of money — even on the first mailing. The amount of money saved on this first example could buy database software for several employees!
This example assumes you have a database (of some type), a label printer, and a way to print labels for a 5×7 mailer.
————
Let’s say you’ve been in business for 10 or 20 years and you have 1,000 customers. Now, some of these customers may have only used your service once, moved away, don’t use the particular service your marketing flier covers, or are the best customers ever. But, how do you know? You could go through each of the 1,000 customers one at a time by paper, but this exercise would take days if not weeks every time.
We need a better way: a real computer database of our customers — which is usually very easy to set up.
Now, using “traditional” (non-smart) marketing, if you had just ordered 2,000 5×7 color mailers, which for our example, cost $2.00 apiece after postage, you would spend $2,000 to send a mailer to each of the 1,000 customers in your database.
Is this “smart” marketing? Nope. Just because you used a cool computer to print out the 1,000 labels on a cool new label printer could mean you’re wasting money faster using technology. Instead, doing an even relatively shallow analysis on your customer data could narrow this list extensively (save your marketing dollars) and improve your odds of getting a response.
For this example, to narrow the list, let’s just assume we apply a “filter” to our database to our data so we only include “active customers” for the mailing who:
1. Have done business with us in the last three years. 2. Have done at least $500 business with us. 3. Actually use our product or service in the mailer.
Now, after applying this simple filter to our customer data, instead of all 1,000 customers, we now have 250 that meet the selection criteria, the “filter”, above.
So, using our simple filter, we’ve…
1. Saved $1,500 from the mailing cost (we already paid for the fliers, but we can still use the unsent ones later) and 2. We are sending fliers to “active customers” who have the product or service we’re promoting.
And, because this filter is part our our database, we can use it over and over. Note too that since part of the filter above is “date-based”, the rule/filter will potentially show you different customers on each filtered list over time. That’s cool since you don’t need to do additional work to show the current list each time you run the marketing report, label printing, or whatever.
Note that this example’s definition of what an “active customer” is a “business rule” and it’s never guaranteed to be correct. Each business would need to define and test out their own business rules and modify as necessary. Hurricane could help you define business rules for your business.
The idea with a business rule is to define rules which describe aspects of your business that you can use in the database software for decisions. For example, what does it mean to be an active customer? Or, another business rule might define “what is a problem vendor”?. Perhaps you track issues with delivery, quality control, or other metrics. This rule might be as easy as how many times you need to have issues with a vendor before you need to take corrective action.
In this example, we didn’t discuss if you had a customer’s email address and you used that instead of snail-mail in your marketing to save even more money. For example, your database software could “loop through” all the selected filtered customers. Then, if a customer record had an email address, and that customer was OK with marketing emails (you track that contact preference too), you email the marketing information to that customer instead of printing a label and snail-mailing an expensive flier. Or perhaps you do both: print a mailer and email. A nice flier in the mail, personalized in some way for a customer, might have a better impact than an email message. That’s another possible business rule — Always print a mailer and email if possible.
Finally, to further personalize your mailer, perhaps you use a larger label so you can include the name or brand of product the customer has.
—-
How do you get started with smart marketing? Some questions for thought below.
1. Do you use customer data? 2. How do you use it? Database? Excel? 3. Can you search it? 4. Do you support your customers using that information when they call you? 5. Can you take your database software “with you” to the customer site? 6. How do you enter new information and keep your database up to date? 7. Do you personalize your customer marketing? 8. Do you track marketing responses? 9. Do you track each date a customer event occurred? 10. Do you know what types of products you offer each customer uses? 11. Do you collect email addresses for customers and also track which customers are OK with email marketing contacts?
Many companies can’t answer at least some of these basic questions.
At Hurricane, we can help you set up a customer database, import existing data, and get you started with smart marketing. We can help you set up your own database in your office or in the cloud. We can also get your database system mobile and connected to your home office. You can start with a small system and grow that system as your needs grow.
Many companies will try to sell you you an expensive “CRM” system to market to your customers. However, for many small- to medium-sized businesses (< 250 employees), a CRM system could be much more than you need, is expansive, may require lots of other “supporting” software, and often, is difficult to learn and use.
We can start you on an inexpensive database platform and even teach you how to use it if you want to maintain it. If and when your needs grow beyond that initial database, we could transition your data to another database.
Let’s get started!
Please contact us today for more information!!!
——–
Please read our disclaimer available from our home page
Have you ever gotten a dialog message similar to the one below when trying to use a program?
If so, what is the point of this dialog?
Basically, this dialog, the program, is telling you that:
(1) it has a serious internal bug or has found an actual file system problem that it is not handling at all (2) it has given up (3) it has dumped the problem in your lap (4) it wants you to click “OK” — that it’s … “OK” (it’s NOT OK)
Unhelpful dialogs like these are often from lazy programming, poor technical reviews, or other problems. These programs, instead of focusing on “user goals”, only follow their internal structure – making that implementation painfully aware and exposed to you, the user.
What was the user’s goal in this case, anyway? Clearly, the user just wanted to check the activity log and the program should do everything it can to make that possible. Elegantly-designed programs do not give you these types of ridiculous error dialogs.
Instead, a well written program would instead possibly:
(1) fix the problem in code automatically so you would never see the dialog in the first place, OR (2) fix the problem in code and possibly warn you that the program created, in this case, a new “activity log”, OR (3) if all attempts failed, some suggestions, in the dialog about what you might need to try, OR (4) other stuff….
Since creating a new file, as with the case above, is so utterly simple for an application program, why wouldn’t the program do it? Good question!
Trying to figure out the problem yourself could be tricky since other programs, all sharing the same log folder as in this case, might correctly re-create the log file if it’s not found leaving you with too many variables to know for sure what’s happening (again, not that you should be the one trying to figure out why the program isn’t working correctly).
In Java, for example, creating a new file, assuming paths are correct, etc., is as simple as this:
// if the log file is not found, for some reason… File logFile = new File(“logs/error.log”); logFile.createNewFile();
Internally, (sadly) the program in question most likely caught the error but rather than the program dealing with it, it just dumped the problem in your lap. Programs with dialogs like the ones above may have not gotten much, if any, review by technical management. In many cases, management isn’t technical to begin with and is focusing on “shipping software on time”, or other non software quality goals, which can make oversights like these more likely.
——
Using a well-written program is a joy. Seeing the internal implementation bleed out of the program with unhelpful dialogs isn’t (a joy).
So, if you get a dialog like the above just remember that it was up to the program (the programmer) to do the work and make every attempt to fix any runtime issue found. Is that unhelpful dialog a sign it’s time to ditch the program and find a better one.
Good question.
Enjoy!
——–
Please read our disclaimer available from our home page
Absolute vs. Relative Values (Don’t be fooled) ———————————————————————————————————— It’s amazing just how misleading some claims being made are. OK, it’s advertising, but seriously?
When an ad claims that their product “improves ‘x’ by 50%”, does that mean it improves ‘x’ (or whatever ‘x’ is) by 50% relatively or absolutely, and what’s the difference?
Example 1 (using fictitious lightening data):
Say, the absolute risk of being struck by lightening is 0.00001% or 1 in 1,000,000 (made up number for illustration).
Then, let’s say the absolute risk of being struck by lightning while holding an umbrella under a tree in a thunderstorm is 0.00003%. So, in absolute risk terms, we’ve only increased our risk by 0.00002% or about 1 chance in 333,333. Not that much in absolute (real) terms, right?
What an advertisement might do to make their product more compelling would be to focus on the relative risk instead of the absolute risk (or benefit). That is, focus on the risk increase itself “relative to” the initial absolute risk of 0.000002.
Mathematically, that “relative” risk just a percent difference, or:
((Risk2-Risk1)/Risk1)*100
(0.0.00003 – 0.00001)/0.00001)*100 = 200%.
WOW. Looking at only the relative risk, it’s now a 200% (relative) increased risk! (or 200% “benefit”, depending on how they’re pitching the number.)
To summarize, our new (fictitious) absolute risk of being struck by lightening by holding an umbrella under a tree during a thunderstorm is: 0.00003% or about 1 in 333,333.
Our relative risk is 200% higher to not having an umbrella and not standing under a tree in a thunderstorm. That (fictitious) risk was 1 in 1,000,000.
So the next time you hear that something is x% more or x% greater than something, ask yourself x% of “what”? Since this % increase is often a relative and not absolute difference, that part is left out.
Below is a graph split into two sections (separated by the horizontal red line). The top portion has the relative risk pairs and the bottom portion (below the red line) is the absolute risk pairs. Note that the risk pairs below the red line are indistinguishable at even a tiny 2% scale.
The actual data for this graph are: —————————————————————————— x-axis (vert) y-axis (horizontal) —————————————————————————— 1 0.000001 2 0.000003 3 1 4 2
Caveat Emptor ——–
Please read our disclaimer available from our home page
If your city is growing at 5% per year, is this a good thing? What will the size of the city be in 10 years? Is that a linear or exponential growth? If your checking account has a 10% interest rate, how long until you double your money? All good questions.
It’s been said that no layperson understands exponential growth and unfortunately, if that’s true, then neither do the media or popular TV shows. Try to explain exponential growth to someone and you may be greeted by a blank stare. Why does any of this matter?
First things first…
What is an exponential function?
An initial explanation might be that exponential growth is when something is growing at a very fast (non-linear) rate though possibly not noticeable initially. In normal everyday life we tend to think of things linearly getting faster, slower, bigger or smaller, but at a constant rate. Exponential growth is different. It is not linear as it gets very large, or quick, at some point, and that point is sooner than you might think.
In high school, most students learned about functions like 2^x (or, “2 to the x”: 2 raised to the power of x). Here, we have an exponential function since the variable is in the exponent itself. Having a variable that increases while in the exponent is the basis of what an exponential function is. Of course, things can, and usually do, get more complicated, but understanding the variable in the exponent is a the first step.
Graph — Look at the data vs. the graph below to see how the graph changes exponentially vs linearly
Note that the linear portion (right side) of the graph has the variable “x” not in the exponent. The linear portion has a line with constant slope.
Why does it matter?
Exponential growth is everywhere. Understanding it is important not only for day to day activities, but to understand how things work. Something that may not seem to matter with a few trials may actually be extremely important once proper analysis is done.
Examples?
Example1: Your bank’s interest rate on your investments.
Simple Interest: Simple interest is when you get, say, 10% per year (or other fixed amount) interest on your account or investment. Not much going on there. With a $100 principal amount, that’s just $10 per year. Easy. So, if your initial amount, or P, was $100, you would have $10+$10+$10+$10+$10 more in five years. Simple interest, or $100 + $50 = $150. The interest is growing linearly. If you looked at the formula for simple interest, you’d see there is no variable in the exponent.
Compound Interest: Compound interest gets more interesting, since the interest, if compounded yearly (or otherwise), takes into account all the money you’ve earned (including the previous interest) to calculate your future amount. A quick example.
Using the formula: Balance = P * (1 + r) ^ n, where P is the principal amount, r is the interest rate, and n is the number of compounding periods. Here, exponential growth quickly outpaces simple linear growth. If we start with the same values and assume a 10% interest rate, we would have:
Balance = 100 * (1 + 0.1) ^ 5 = $161.
Not impressed yet? How about after 10 years?
Balance = 100* (1+0.1) ^ 10 = $259.
— The side question often comes up as to how long it would take to double your money (dust off your college algebra for this one…)
M = P (1+i)n
Say you start with $100 and a 10% interest rate compounded yearly. How long would it take to double your money? 200 = 100 (1+i)n 2 = (1 + 1)n or log(2) = n log(1.1) n = log(2)/log(1.1)
napprox = 7.28 years. (to double your money)
With compound interest, the money you earn is growing exponentially, not linearly.
Albert Einstein was supposedly quoted as saying the most powerful force in the universe is compound interest.
—————————
Example 2:
Doubling your money every day for thirty days starting with just one penny.
Say someone offered to give you (A) $500,000 or a (B) penny and double it every day for 30 days. Which would you take A, or B?
If you chose B, you’d be a lot better off since that daily penny doubling goes like this:
Day: Pennies ——————————————————— 1 1 2 2 3 4 4 8 5 16 . . . … 30 536870912 pennies, or dividing by 100, $5,368,709.12 (over 5 million dollars!)
—————————
Example 3:
Paper Folding until you reach the Sun
Assuming you could physically fold a piece of paper in half over and over, how many folds would it take you to reach the Sun? We can see that this is as 2^x exponential growth since each fold is doubling the paper thickness. We quickly realize that there is no way we could “physically” fold the paper in half more than a few times, but what if we could, at least theoretically? How many folds would it take to reach the Sun? You might (incorrectly) assume it would take too many folds since folding the paper once, then twice, then three times, doesn’t amount to much. Ah, but that’s the problem with exponential growth: the growth kicks in later.
Here are some possible answers to the question about how many folds, approximately, it would take to reach the Sun (which is closest).
What’s your guess?
A. 50
B. 500
C. 5,000
D. 5,000,000
Guesses?
Well, if you answered A or 50, you’d be right.
Here is the output of a computer program that actually computes this paper folding (you could get the same result manually).
We assumed the thickness of a piece of paper is 0.0001 feet and the distance to the Sun is 491,040,000,000 feet.
Let’s start folding…. (notice that nothing really happens on the first 10 to 12 folds, but then, with exponential growth, it gets interesting)
Let’s calculate this!
Number of Paper Folds so far: 1, distance traveled toward the Sun: 0.0002 feet Number of Paper Folds so far: 2, distance traveled toward the Sun: 0.0004 feet Number of Paper Folds so far: 3, distance traveled toward the Sun: 0.0008 feet Number of Paper Folds so far: 4, distance traveled toward the Sun: 0.0016 feet Number of Paper Folds so far: 5, distance traveled toward the Sun: 0.0032 feet Number of Paper Folds so far: 6, distance traveled toward the Sun: 0.0064 feet Number of Paper Folds so far: 7, distance traveled toward the Sun: 0.0128 feet Number of Paper Folds so far: 8, distance traveled toward the Sun: 0.0256 feet Number of Paper Folds so far: 9, distance traveled toward the Sun: 0.0512 feet Number of Paper Folds so far: 10, distance traveled toward the Sun: 0.1024 feet Number of Paper Folds so far: 11, distance traveled toward the Sun: 0.2048 feet Number of Paper Folds so far: 12, distance traveled toward the Sun: 0.4096 feet Number of Paper Folds so far: 13, distance traveled toward the Sun: 0.8192 feet Number of Paper Folds so far: 14, distance traveled toward the Sun: 2 feet Number of Paper Folds so far: 15, distance traveled toward the Sun: 3 feet Number of Paper Folds so far: 16, distance traveled toward the Sun: 7 feet Number of Paper Folds so far: 17, distance traveled toward the Sun: 13 feet Number of Paper Folds so far: 18, distance traveled toward the Sun: 26 feet Number of Paper Folds so far: 19, distance traveled toward the Sun: 52 feet Number of Paper Folds so far: 20, distance traveled toward the Sun: 105 feet Number of Paper Folds so far: 21, distance traveled toward the Sun: 210 feet Number of Paper Folds so far: 22, distance traveled toward the Sun: 419 feet Number of Paper Folds so far: 23, distance traveled toward the Sun: 839 feet Number of Paper Folds so far: 24, distance traveled toward the Sun: 1,678 feet Number of Paper Folds so far: 25, distance traveled toward the Sun: 3,355 feet Number of Paper Folds so far: 26, distance traveled toward the Sun: 6,711 feet Number of Paper Folds so far: 27, distance traveled toward the Sun: 13,422 feet Number of Paper Folds so far: 28, distance traveled toward the Sun: 26,844 feet Number of Paper Folds so far: 29, distance traveled toward the Sun: 53,687 feet Number of Paper Folds so far: 30, distance traveled toward the Sun: 107,374 feet Number of Paper Folds so far: 31, distance traveled toward the Sun: 214,748 feet Number of Paper Folds so far: 32, distance traveled toward the Sun: 429,497 feet Number of Paper Folds so far: 33, distance traveled toward the Sun: 858,993 feet Number of Paper Folds so far: 34, distance traveled toward the Sun: 1,717,987 feet Number of Paper Folds so far: 35, distance traveled toward the Sun: 3,435,974 feet Number of Paper Folds so far: 36, distance traveled toward the Sun: 6,871,948 feet Number of Paper Folds so far: 37, distance traveled toward the Sun: 13,743,895 feet Number of Paper Folds so far: 38, distance traveled toward the Sun: 27,487,791 feet Number of Paper Folds so far: 39, distance traveled toward the Sun: 54,975,581 feet Number of Paper Folds so far: 40, distance traveled toward the Sun: 109,951,163 feet Number of Paper Folds so far: 41, distance traveled toward the Sun: 219,902,326 feet Number of Paper Folds so far: 42, distance traveled toward the Sun: 439,804,651 feet Number of Paper Folds so far: 43, distance traveled toward the Sun: 879,609,302 feet Number of Paper Folds so far: 44, distance traveled toward the Sun: 1,759,218,604 feet Number of Paper Folds so far: 45, distance traveled toward the Sun: 3,518,437,209 feet Number of Paper Folds so far: 46, distance traveled toward the Sun: 7,036,874,418 feet Number of Paper Folds so far: 47, distance traveled toward the Sun: 14,073,748,836 feet Number of Paper Folds so far: 48, distance traveled toward the Sun: 28,147,497,671 feet Number of Paper Folds so far: 49, distance traveled toward the Sun: 56,294,995,342 feet Number of Paper Folds so far: 50, distance traveled toward the Sun: 112,589,990,684 feet Number of Paper Folds so far: 51, distance traveled toward the Sun: 225,179,981,369 feet Number of Paper Folds so far: 52, distance traveled toward the Sun: 450,359,962,737 feet
Total Number of Paper Folds without going past the sun was: 52
WOW.
Conclusion.
Exponential growth is all around you. We use it in so many things in everyday life we sometimes aren’t aware it’s there.
People say (typically on “the news”) that things are (loosely speaking) “exponentially” bigger worse or whatever. This loose terminology is, unfortunately, slang for “getting really bigger! (or worse, etc.)”. In many of the circumstances where you might hear exponential growth used (again, often, sadly, in the media), the growth is really not exponential. Note that a^x type function is also geometrically increasing since it’s a constant raised to a power.
We recently blogged another example of how exponential growth works when using a longer and longer key space with an iPhone passcode. With six characters and only numbers we had 6^10 permutations, but with letters and numbers (lower case) we had 6 ^ 32 permutations. Thus, the key space is getting larger exponentially (since the exponent has the number of letters possible) but it’s getting larger linearly with the passcode length itself.
Exponential growth is not difficult to understand and it’s everywhere!
Enjoy!
——–
Please read our disclaimer available from our home page
Most software developers work under tight deadlines so finding software that makes their jobs easier or helps getting the job done more quickly is always a good thing, right?
Well, maybe not.
Consider the case when the company that makes your cool Rapid Application Development (RAD) software tool decides to do something “it” considers important, but you don’t see the benefit for you or for your organization at all.
For example, maybe the company decides it’s time to jump onto the “Forced Subscription Model” (as opposed to the “perpetual license”, which has long been the norm). Maybe the company never tells you anything about future direction leading to more uncertainty.
Then, after multiple software versions, you find that company won’t support the current product version the instant the new product version ships. And, to make matters worse, that product may not function properly when there’s a new version of the OS. And, of course, the company’s only suggestion at this point is to “upgrade”. Yeah, right.
And you have work to do, but now the software isn’t working!
Assuming only constant costs increases, when costs go up, the money for those costs needs to come from somewhere. Either you eat those costs or you pass them along to your customers.
Say you decide to stick with the current version, but that version all of a sudden has bugs with a new OS release. You don’t want to upgrade since could mean you have to sign up for a new subscription model. But, best case, if the fixes are only in the new product, you’d at least have to upgrade for “bug fixes”.
How do companies get away with this behavior? (Hint: a basically good product in a niche market with little or no competition.) Look at ever-increasing cable company prices for another example.
In any case, you now decide it’s time to look for alternatives, but because you picked this unique (read: Proprietary) product, there really aren’t any readily available alternatives like one that could read your files natively and let you keep working.
You lack, for example, an alternative like OpenOffice, LibreOffice, or any of the other MS-compatible office suites if you wanted to, say, ditch MS Office. Or, say you use a Java IDE and the company starts to charge money for a subscription model. Now, in this software space, you have other alternatives, some free, so you can leave quickly if you want. Yes, you may lose some productivity, but you can keep working. It’s interesting to note that the Java IDEs that charge yearly fees don’t charge that much. Hmmm, maybe we’re on to something.
But without these alternatives available, you may be stuck for the time being.
It’s unlikely that anyone considers a vendor “lock-in” issue when they get that fancy software that lets them “be more productive” right away. And of course it’s always possible that you’ll still be able to stick with that company too, despite the lock-in, even if you can pass along the costs.
But what about future cost increases and uncertainty in general.
Thus, it’s a good idea to consider the cost of proprietary solutions up front as they’re not always the cost saver, due to productivity increases found, as hoped or even promised.
If the software you’re using was database software, as one example, a possible solution would be to come up with a migration plan to move to another vendor. That plan’s costs would need to be carefully considered up front and for the long term.
So, carefully consider that RAD software up front and possible migration alternatives to handle various (not only the ones mentioned here) scenarios!
Not too long ago, a community college might charge up to $100 for all the classes you might want to take after the “full load” of classes. Today, a single 3 credit class can cost over $500! Then, you have to buy books, parking, and possibly pay other fees previously not charged.
Various studies have shown that college tuition increases have outpaced other costs of living such as housing.
Without examining the causes of constant tuition increases, what are some of the effects these increases have?
1. Huge debt loads for students 2. Deciding if college is even worth it 3. Only taking classes that are absolutely required 4. Community colleges not offering some interesting classes (side effect of 3) 5. Difficult without a community college financial commitment to find instructors who can teach specialized classes for working professionals
Thus, unlike in the past where you could count on a community college to offer a class that could be helpful to you as a working professional, nowadays the offerings are much more vanilla. Given the huge cost of a single class, professionals have better options that take less time:
1. A one-week class for a given software product or framework (Expensive, but focused, and fast. Exactly the content you need.) 2. Harvard, MIT, and others have plenty of FREE online courses 3. A yearly subscription to Lynda.com or similar (Huge course offerings. No instructor support. Some plans include sample files.) 4. You-Tube Videos (Free) 5. Tutorials 6. User groups
So, why spend $500+ for a single community college class, assuming there even was a course that could help you improve your professional skills, when there are plentiful cheaper options that are more focused, have less hassle, and have more user interaction?
Several reasons to opt for the community college approach include the slower and methodical pace, evaluated assignments, and instructor feedback. The college environment is compelling for many students — especially those changing fields. Yet, this option is moot if the classes simply don’t exist for the working professional
Thus, except for being a better deal relative to four-year colleges for “required” courses, community colleges are indeed pricing themselves out of the market for working professionals looking to improve their skills. This market exclusion is from either by not having the financial commitment to hire specialized instructors for those classes or by continually raising prices on the vanilla classes that might help career changers.
Some people are thus now rethinking the value of college, in general, for reasons stated here and for other reasons.
The data you entrust to third parties like colleges, your credit card processor, or data you have no control over (OPM, IRS, or other “organizations”) has likely been compromised. In fact, there have been shocking data breaches reported in the last ten years. So many breaches that you may no longer really pay attention to the newest breach on the news.
The biggest breaches get the headlines, like the OPM breach that affected over 20 million federal workers. The numbers are staggering. From 2005 through 2016 (partial data), there have been 898,590,196 total records reported breached!
To make matters even worse, more than half (53%) of all breaches reported zero records breached — meaning an “unknown” number of records breached. Therefore, the total breached count is potentially much bigger than the nearly 900 breaches reported above.
These breaches happen in various ways. From hacking, unintended disclosure, fraud, insider threats, and other methods (see “Types of Breaches” below). Organizations affected run the gamut — from retail to government, financial, education, and other types.
The data in this article is from the publicly available information at https://www.privacyrights.org/data-breach. Using this publicly available information from the privacy rights clearinghouse, this article describes the breaches grouped and summarized in various ways. Below you will see breakouts of that data, many possibly surprising.
Conclusion:
Based on the data breakouts below, you should be concerned about the security and privacy of your information and the nearly total lack of security organizations (and, yes, the government) have.
What’s shocking about these results is that encryption for databases has been around for a long time, which would mitigate many of these breaches completely or at least to some extent. Yet, it seems few, if any organizations, actually bother to encrypt their data. Thus, when they’re hacked, and it’s clear from publicly available data that they are getting hacked, the hackers get the juicy raw (unencrypted) data.
Although there is little you can do about this remote data when businesses and government fail to protect your information due to outdated computers, computers not updated with security patches, insider threats, susceptibility to phishing attacks, lax security policies, or whatever, you can consider taking steps on your own to protect your local data and data in transit (a few possible ideas below):
(Note: You might need technical help or other support for some of these ideas below. Please see our disclaimer on our Web site.)
Encrypt your hard drive
Encrypt your emails
consider PGP or a third party email service like Protonmail.com
Use a strong password (different) for every Web site
(use a password manager)
Use an up-to-date anti-virus program and keep it updated
Use an up-to-date anti-spyware program and keep it updated
Avoid email systems that have the ability to run programs from emails or have been used as virus vectors
Avoid running as “root” or “Administrator” except in rare, controlled, circumstances
Do multiple backups and keep backups off site
Use an Ad blocker with your browser (for example Ad Block Plus)
Consider using Ghostery or similar to stop trackers
Avoid using tracking search engines like Google – (Note: Google appeared four times in the data results, all with “zero” records reported compromised.)
Get your own domain name and email hosting
Other strategies…
Thus, organizations need to be held accountable for data breaches with financial penalties and possibly legal action. Until this day arrives, and the laws catch up to the data breach threats, additionally consider credit watches, freezing your credit, regularly checking your credit report, and taking all the possible steps you feel comfortable with to protect your privacy.
1. Unintended disclosure (**DISC**) – Sensitive information posted publicly on a website, mishandled or sent to the wrong party via email, fax or mail. 2. Hacking or malware (**HACK**) – Electronic entry by an outside party, malware and spyware. 3. Payment Card Fraud (**CARD**) – Fraud involving debit and credit cards that is not accomplished via hacking. For example, skimming devices at point-of-service terminals. 4. Insider (**INSD**) – Someone with legitimate access intentionally breaches information – such as an employee or contractor. 5. Physical loss (**PHYS**) – Lost, discarded or stolen non-electronic records, such as paper documents 6. Portable device (**PORT**) – Lost, discarded or stolen laptop, PDA, smartphone, portable memory device, CD, hard drive, data tape, etc 7. Stationary device (**STAT**) – Lost, discarded or stolen stationary electronic device such as a computer or server not designed for mobility.
Organization Types: – Unknown or other (UNKN) – BSO – Businesses – Other – BSF – Businesses – Financial and Insurance Services – BSR – Businesses – Retail/Merchant – EDU – Educational Institutions – GOV – Government and Military – MED – Healthcare – Medical Providers – NGO – Nonprofit Organizations
Years of Data: Years of Data: 2005-2016 (partial) ========================================
High-level Results:
Of all the data brach types, “HACK” is the highest occurring, with 1,281 separate incidents. The Insider threat also was high with 555 separate incidents.
As stated above, there were 898,590,196 total records exposed
Below is a table showing the type of breach and the number of incidents:
(see “Organization Types” above for to decode the Type below)
TYPE NUMBER
NULL – 46
CARD – 66
UNKN – 149
STAT – 248
PHYS – 542
INSD – 555
DISC – 846
PORT – 1113
HACK – 1281
You might not think that from the numbers of separate incidents above, that not that much data was exposed, but the table below breaks down the number of records exposed per hack type:
Number of total records exposed by hack type:
UNKN — 6,306,078
CARD — 7,203,035
STAT — 11,568,743
DISC — 32,113,235
INSD — 36,268,831
PORT — 172,876,499
HACK — 629,035,293
Data breaches by Entity (government, financial, etc.):
NGO — 107
BSR — 552
BSF — 633
GOV — 722
BSO — 740
EDU — 772
MED — 1274
Note that medical is the highest breach type followed by education. Government is also high with 722 incidents.
Looking at the actual number of records exposed by Entity Type, we have:
NGO — 2,038,766
EDU — 14,790,624
BSO — 21,505,346
MED — 45,403,049
GOV — 178,534,105
BSR — 257,517,157
BSF — 378,801,149
Above, we see that the number of total exposed records was the highest in the business financial area (BSF), followed by businesses retail/merchant. Government brings up the third highest breach count. So, although education and medical had the highest breach counts by entity, the number of total exposed records is by businesses and then by government.
Below, due to space limitations, is very small representation of the organizations involved in these hacks. The list shows only the first 25 characters of the company name. And, since there are so many breaches by company name, we limited the list to only those breaches with 100,000 total records exposed or more. And, even then, there were too many organizations (229) to list them all!
Partial list of organizations with at least 100,000 data hacks:
Finally, if you think things are getting better over time, 2015 was the second worst year on record for total records compromised with 2009 being the reigning champion.
Records compromised by year (2016, partial):
2009 — 218,903,159
2015 — 160,162,774
2007 — 130,261,978
2014 — 71,138,652
2011 — 66,131,642
2013 — 57,651,691
2005 — 52,821,610
2008 — 49,734,455
2006 — 48,607,177
2012 — 27,777,064
2010 — 12,861,822
2016 — 2,538,172
One more thing…Some organizations have multiple data breaches over multiple years so they don’t seem to be fixing things or learning from their mistakes. The short list below shows the top 10 organizations with at least 1,000 records exposed but with at least two breaches in different years. The actual list is quite long and you would recognize many of the organizations.
Name Number Breaches Total Records Exposed
Name — Number of Breaches — Most Recent Breach —————————————————————————————
University of South Carolina – 5 – 2013-06-28 00:00:00
Texas A&M University – 4 – 2012-04-14 00:00:00
UC, San Francisco (UCSF) – 4 – 2013-11-25 00:00:00
Ohio State University – 4 – 2010-12-15 00:00:00
Columbia University – 4 – 2012-04-30 00:00:00
AT&T – 3 – 2015-04-08 00:00:00
Eastern Illinois University – 3 – 2009-12-04 00:00:00
Merlin Information Services – 3 – 2007-09-25 00:00:00
Purdue University – 3 – 2011-08-16 00:00:00
University of Florida – 3 – 2013-05-29 00:00:00
(IRS was number 11 in the list above.)
———
The publicly-available data file we used (see URL above) for this blog has other useful or interesting information. For example, there is a field that describes how the data were actually stolen. Another field that documents when the breach became public.
One of the questions we often get in our intro to databases (conceptual intro) course is…in what kinds of real world problems could we use a database? One answer is consider using a database to help track a lot of data or complicated data, or both.
We wrote a recent blog on stopping junk mail so we won’t duplicate that, but instead expand on it to explain how you might use a database to track contacting companies to opt out of mailings and other activities.
Although in our intro to databases class we go through several case studies explaining different types of applications for which students could use databases, this blog posting discusses an applicable example. As with blog postings, we won’t go into any implementation details (see our Programming Tips for coding!), but rather just pose certain questions. This blog is by no means assumed to be the best way or only way to stop junk mail; it’s just one idea.
The basic idea is to model the opt out workflow that captures the data and automates as much of the letter writing, label printing, reporting, and other activities.
Getting started…
So how exactly would you stop all junk mail? What would the database need to look like (table structure)? What types of responses from companies would you need to track? How long does it take to stop all junk mail?
All good questions.
Considering the OPT OUT portion of the database:
To set up a database, first consider that you need to capture the company information but also each response you get from the company. Should you have a separate address table? (Probably) In database terminology when you have a single table possibly related to multiple items in another table, this is a “one to (possibly) zero or many” relationship. In our intro to database course we talk about different types of relationships that you would model in most databases. We also discuss the cardinalities with these relationships (1:M, 1:1, M:M, M:1).
Document Your Assumptions for the System Up Front:
One initial “getting started” activity is to write down all your assumptions and then examine them later for refinement. It’s nearly impossible to get it all right the first time since what happens in the real world will sometimes defy logic. Your assumptions could be perfectly reasonable, yet the real world may challenge them.
One assumption you might reasonably make would be that you could just call the company one time and they’ll stop sending you junk mail, but this is rarely the case. Sadly, often, it will take two, three, four, or more attempts to get the company to stop sending you junk. Your contact attempt may include letters, phone calls, and in the worst case even submit a USPS prohibitory order so the USPS will contact that company on your behalf. Do you see this might be a “one to many” relationship somewhere in our database?
Determine if Your Application Is a “Workflow”.
Since all of these activities involve workflow (do step 1, then step 2, …) you want to have the the database’s data entry, and other activities, fit that model.
With a prohibitory order, for example, you can automate much of the data entry using the data you already entered on the OPT OUT form. You already have, for example, the company information from the OPT OUT form so you could copy it (or just “link it”, referentially, depending on your design). Also, since at least two prohibitory order dates depend on the date the order goes into effect, then the database should calculate these two dates automatically after you enter the initial date.
Create a workflow diagram
The diagram below is a (early, draft) starting point to model what we want using a workflow approach. Once you diagram the system, it’s easier to spot workflow problems or other things in the database that might still need attention. You’ll more easily see that the diagram may be missing some decisions or flows. Or, possibly the flows that are there need refinement. Don’t focus on trying to get everything perfect in version 1, but rather get the basic flows as close as possible to how you envision they would actually work.
Note that the diagram below uses a UML “State Diagram”, which is useful for modeling workflow models.
Automate Letter Writing
Your database could also have multiple form letters you pick when you write a company to “OPT OUT” of receiving junk mail from them. You could modify the form letter for each company, if needed. You could automate printing a label for the envelope, too. The database could then save each letter you sent into the multiple contacts (as many as needed) for that company. You could even track postage.
Reports
You’ll also probably want a report showing you which orders are still in effect on the date you run that report. Another key use for a database: reporting.
Graphs:
Maybe you want a graph showing the worst junk offenders or possibly junk mail by type of mailing. How about a report showing the list of companies and the number of contacts for each company ordered by date? Your database may offer graphics or you may need a plug-in for your existing database.
Scanned Images
You’ll have to decide how much to scan and keep as part of the database. In this actual working example database, we captured the prohibitory order application, and the USPS prohibitory order received as searchable PDFs. Back in the OPT OUT form, we had the ability to capture an image in any of the possibly many interactions with a particular company (remember that the company table is related to one or possibly many contact actions. You could conceivably have zero actions if you chose to enter a company in by itself with no junk mail from them.)
Surprises along the way.
One of the things you will probably notice, once you start calling and writing companies to stop sending you junk mail, is that many companies are not really in charge of their data. Either they “farm out junk mail sending” to some third party or they don’t have sophisticated database folks you can talk to on their toll free number(s). If the company farms out their junk mail sending to a third party, you may never be able to get the message to the right person. It’s also possible since these companies like to send junk mail, that their hearts are not in stopping it just because you called or wrote them.
USPS Prohibitory Order – When they just refuse to stop sending junk
Fortunately, the supreme court decided in the ‘70s that you can stop any mail you do not wish to receive. Simply fill out PS-1500 and send it to the USPS (note the instructions). As described above, the workflow would capture all that information as well.
Conclusion:
We’ve covered a lot. Specifically, in our database, we are:
Enforcing a workflow
Automating date calculations
Reporting so we know how we’re doing
Graphing for getting the big picture quickly
Supplying canned form letters
Automating other activities including data validation
Fixing user entry errors: if they enter “ca” for California, automatically change this to “CA”. Use Title Case fixes in other case, all automated!
Tracking stamp costs in OPT OUT and Prohibitory Order forms
Doing basic accounting for stamp payments
Tracking the average time between junk mail for both new junk mail and junk mail actions with existing companies. This display uses a nice bar graph on our OPT OUT form.
Tracking the average time it takes USPS to process a prohibitory order after we send it (about a month!)
Printing labels if desired
(More!)
Here is the nice graph that we show for 10 above:
————-
It’s probably clear that trying to do all these activities with complicated data, without a database, would be difficult if not impossible.
Even with automation, expect stopping junk mail to be, probably, a six month effort. (Companies don’t always make this easy.)
The database makes tracking and reporting straightforward, but for even low to moderate junk mail (a few pieces a day), stopping junk mail will take serious dedicated effort.
Finally, getting a “perfect” database application to model the real world is quite difficult. Consider all the bug fixes and updates for every piece of software you use. No other company, anywhere, can get any of their software defect free either. Perfect software does not exist so expect your database application to be a work in progress as you make it better and better over time.
Many computer users are too young to remember mainframes typified by large cooled rooms with raised floors, dumb terminals. and the data center overlords who “granted” you access to data, memory, and applications. Control was the key. And the computer overlords had it.
Fast forward to today.
You may have noticed that more and more software companies are going to the “Forced Subscription” (aka “Take It Or Leave It” — pay monthly) model often with their proprietary and required cloud access. This forced approach is similar in many ways to the mainframe model. And, perhaps unsurprisingly, this forced software model yields the best cash flow for the company. Shocking!
Control? As with mainframes (or other centralized control): you lose it.
This new forced subscription model, simply put, means you pay regularly – whether you use the software or not — or, usually, your software stops working. While this model is great for the company with regular cash flow (or else!), the model may not match how you use the software or want to pay for it.
Whether this software model bothers you is largely personal, but your choice to not pay until you are ready for a new version is currently being eroded with forced subscription software models. Also, as stated, loss of control of your data can go hand in hand with this subscription model, especially if the company forces their cloud solution on you.
The Case for Software Subscriptions
The case for software subscriptions includes always having the most up to date software, often not needing to configure, install, or maintain subscription software. No licenses to keep track of. For teams of people, a subscription often means making one regular payment for working software for the team. Whether these subscriptions should be forced on you as the only option available is the key point here.
The Case Against Software Subscriptions
The case against Forced Subscription software is compelling.
Number one among the various reasons against forced software subscriptions is that forced software subscriptions are, well, forced. Take it or leave it.
If the company then also forces their cloud “solution” on you to use their software, do you want these companies to have access to and even control your data? You should read the fine print in your Terms and Conditions before simply clicking “Accept”.
Moreover, do you want the drip…drip…drip of your money now regularly going to a third party for software you can, or used to, just update (and then pay for) when you wanted to?
Other Questions…
Who at the software company has access to your “Cloud” data (aka, simply your data they store on their servers) Programmers? Admins? Others?
What happens if you stop paying (credit card expires, for example)? Is your data access terminated, your data deleted, or what exactly? How soon is the data deleted if deleted?
What happens if your data is lost by the company?
Does the company have and guarantee backups?
Is your data encrypted on a cloud (Internet) servers?
Where exactly is your data stored?
How private is your data?
Do you need this software up to date all the time as a subscription might offer?
What happens when the company is hacked? Security in general?
Do you have control do permanently delete your account and your data?
Once you’re roped into Forced Subscriptions, will companies try as hard to come out with new exciting software?
Why pay a monthly free for software you might rarely use?
Unexpected Consequences—Where Did My Data Go?
The costs of forced software subscriptions can add up, both financially, and from unexpected consequences.
One of our readers had an issue, for example, with a well-known company she used for email. She paid a monthly fee for that email service and had used this company for over twenty years. Yet, one month, her credit card expired. And, in just 6 hours, before she could update her credit card information, the company had deleted all her server email going back 20 years! Multiple calls to the company, letters to the president, and other attempts went nowhere. Her email data was gone. Period.
We’ve Got You!
When using software that needs “The Cloud” (aka “a hard drive somewhere on the Internet” others control) to run, companies could use this dependency to implicitly force a software subscription model on you. Consider when, at some point, cloud access itself ceases to be free, or becomes more expensive over time (as you become more dependent on it), etc.
A Ray of Sunshine — Lots of Software Options
Fortunately, there are many companies that don’t force a software subscription model on you. Instead of Office 365 (subscription), consider OpenOffice or LibreOffice. Both these MS Office alternatives are free for personal and for commercial use. Instead of TextExpander (previously recommended, but now recently changed model to forced subscription and forced, currently un-encrypted, cloud storage of your data), consider aText (one time $4.95 fee). Programmers can use the free “Eclipse” instead of now-subscription IDE offerings. With IDEs as well as other software, there may be tradeoff between cost and productivity that you should consider.
Let Companies Know How You Feel:
Companies are really thinking about jumping on the bandwagon and moving to this model. When you contact companies with questions for support or other contacts, let them know how you feel about forced subscription models.
Conclusion
Harkening back to the mainframe computer days, “The Cloud” and Forced Subscription models put the control with a third party, not with you. And of course, that’s the point: keep you paying … or else (software stops working, data gone, …) While you may get convenience or slightly more up to date software, you are also giving up control and are now paying regularly just to use your software.
Forced software subscriptions are becoming more common, but many choices for avoiding forced software subscription exist and should continue to exist. Unless forced software subscriptions are right for you (they’re not bad in all cases), look around for alternatives and take back (or keep) control of your software!