I had blogged a lot before with my best advice for graduates and prospective successful MSc students at Strathclyde Uni on the Marketing 'post grad' masters.
Now I will radically alter my advice to much of my earlier pointers. First a historical perspective and how you may fit into this.
The MSc course full time is I hear still made up of many local students from the region previously known as "strathclyde" and Scotland as a whole. Most of you are lower middle class and have lost interest in the content of your first degree and the limited career options you had.
Now here is my take: When I did marketing way back when in the early 90s, we had seen a generation just before us do extremely well thank you very much from a career in marketing. Indeed in the 90s you could get on a career path into traditional brand management and so on, but the vast majority of us didn't and that is for two reasons- firstly we wanted to stay in Scotland, and secondly brand management was then and probably is now, a plumb job for Oxbridge graduates and those from the better BSc courses with first class honours, and those with MBAs.
As a marketing master candidate, you are actually not as competent a marketer as someone from Strathclyde with the four years under their belt, and you are up against the best from the oxbridge and ivy clad uni debating societies. Most of my course did continue with careers in sales and marketing loosely, most of those in the core worked in public sector marketing and some in SMEs, while me and others worked in Ad' Agency land.
Now here is the other historical point of view in Scotland in particular: I blogged on my "growing up on the firth of clyde" that the Middle class made scotland, the working class did a grand job of following their vision, their plans, quality management and their orders. The Middle Class also then saved Scotland in the recession of the late 70s and most of the entire 1980s also, by adapting and transferring their skills to the service economy, becoming consultants, going into offshore management and starting new SMEs. The working class by in large did not adapt so well and became in many areas, the unworking class, with chips on their shoulders about pit and steel closures, which although lamentable, have happened and cannot be reversed.
What has happened thereafter is that the middle class got all the good jobs and started businesses and the new "graduate class" of the 1990s, when education to degree level was vastly (and wastefully expanded) , these graduates became the new working class. Only this time they had no unions, they had no bargaining rights, they had no overtime payments and they had no job security. In computing, call-centres, finance, business-ananlysis, junior accounting, communications and marketing the workforce had become a commodity, just as workers had been in the 19th century.
What this means is that graduate salaries and the career ladder will not deliver what it proposed to in the 1980s and in that great killer of common sense "hope" took over. We all hoped that the qualifications we had would be an automatic ticket to a well paid job with a good career ladder, and that our first couple of positions were hard work and poorly paid, as they should be. We woke up thinking we were well enough paid, and that wee flat on the dodgey side of town was a good first property investment. We were deluding ourselves- we were shop floor workers. This came to a head in the early 2000s when it became apparent that train driver's basic pay was 26k before the extortionate overtime payments and antisocial hours allowances plumped up their above-our-wage earnings. This is the other thing that happened- the unionised and skilled working class in the UK and Europe became damn well paid! Off shore salaries for skivvies and painters into double that figure!
So my radical departure in career advice is this: make your goal twofold- a rapid rise into marketing management AND the potential for self employment and being an owner-director of a start up or growing SME.
In fact it is the reverse order: you should be looking at being entrepreneurial all the time and trying to meet people to whom your marketing skills are valuable and your personal drives or interest are in line with.
You may get a shot at marketing management and that means being in a large or fast growing company or department where you have very soon the chance to manage other people, such as internet programmers, writers and external marketing and PR agencies. You should have a clear career ladder in the company or you should be in an industry which is new and fast growing, like micro breweries or the like, where you can choose to cash in your two years initial experience for a better job. As an MSc or BSc Marketing graduate then you do not want to be in a grunt job at the bottom of the feeding chain for very long, six months max.
However as I blogged before the "shot at marketing management" in Scotland is extremely limited and highly competitive. So go south early.
The main reasons people do not get involved with new start ups or becoming self employed is the perceived risk, fear of hard work and uncertainty of income. These are both true, but the stupidly low perceived risk of having a good wee job and a mortgage and the lack of both security and a share in the capital and profits you build up over the years mean that please do consider being self employed or getting early into a start up with possibility to buy shares. Your income is actually not all that certain and also you have levered yourself to hell on the first-and-worst wrung on the property ladder.
Considering "hard work" avoidance -In agency land in particular you will work damn hard and not get any overtime- you will be expected to work at least 48 hours a week and probably do some 60 hour weeks if you are in London and the home counties. Plus in your first job in agency land or in marketing in the home counties or dearer parts of Englandshire, you will also no doubt go deeper into debt as your cost of living with your first car, a few frills and visits home, will be higher than your salary- for a long time.
If I had my time again I would go headlong into entrepreneurial studies, management accounting and networking to the technical leaders of new SMEs post MSc. That is with hindsight, and would have been a successful approach in the 1990s with the explosion of internet SMEs amongst others. Today there is even more focus on all this in terms of opportunities for young people to get on that bus!
Simply put, the long term rewards of going down this route for you as an MSc graduate are far better on average than continuing as a marketing employee in a medium Scottish organisation. Why? Well despite the risks and set backs you will encounter, you will be at some point able to :
1) determine your own salary or profit related income
2) share directly in profits from the business / businesses
3) build capital ownership and ability to sell and buy capital
4) To some extent, be able to choose who you like to work with
5) To a large extent by reaching your mid 40s, you will be able to determine your own working hours, and along the way you will have had the ability to choose "lifestyle" hours which to some extent allow you to indulge in hobbies, sports and personal development while also working many more evenings and weekends.
The latter cannot be played down, but the preceding economic arguments are enough given that you have to slave away in an office anyway. The latter two points are often taken as compensation for those long hours- you may start a business with a friend or evolve a fun working relationship, while on the other hand you may well like my pal who went into the Reserve SAS, be able to be flexible and put in training afternoons and clock off early to train some times.
As a case in hand in fact, this pal of mine started a cleaning business doing all from houses, windows, wheely bins to jet washing forecourts and oil spills. He did it with a guy he knew quite well, who only went in if he could get a 50:50 share (wise guy!!!) He took Tuesday nights for barracks training, Wednesday afternoon for training for SAS "selection" in the hills, and refused to work Saturdays, doing paper work if the weather was bad (as it is in W. Scotland) on Sundays. He is not rich yet, but at 42 he is much better positioned to be rich and still has all the private pension and so on you would get as an employee.
I am lucky and in a small band of my type, who have worked both in technology Start Ups, SMEs and large multinationals (Global Enterprises as they are now called, I show my 1990s business education vintage!) I would say that I never got the right job in a start up / SME and that was due to lack of self confidence and nervous communication skills, which is a personal thing I confronted and overcame in my early forties. The thing about getting into a small end or high growth SME, or a start up is that you need to get in at the right level EARLY - and that all with the right responsibilities and authority defined.
For me I found out that I had better judgment and could make better strategies and game plays for three small technology companies under 15 employees, but I was never in a position to have the authority to do this, and although this was a bit to do with me as a person, it is more to do with the type of attitude they had about my usefulness and position I would be offered in the company.
If a company won't play ball and you will be a grunting employee, then review their technology and use your position as a six month to one year learning tree if you think that there are competing companies you could move to at a higher level.
This brings me to another point: marketing is seen as a very soft skill and you should consider building on your hard skills, or specialist knowledge.Marketing and communications has a skill set which is often perceived as dependent more on personality than education per se by management who decide who gets on in marketing. In fact in larger corporates, I really on average did not like marketing types especially not the arrogant dog-eat-dog women managers I locked horns with inn most of my positions.
What I would say is that you may, like me, have a set of hard skills from your previous degree: you may be an excellent grammatical writer if you studied English and Literature: you may have a computer language or have used a particular database, CRM or ERP; you may have some other hard skill.
As I went on in the malaise of mid nineties graduate employment I went back to Uni and worked as a trainee in the data center, and did this to get hard skills in databases and the internet. This "apprenticeship" was going to be too heavy in programming and I did lack a bit of initiative in maybe picking up how to make decent looking web pages with database back ends, but these new hard skills on the one side gave me the edge on my CV and in interviews, and on the other hand, gave me management knowledge into the black box of what programmers and data admin' types actually do. I still use these skills today in various ways, be that getting new functions out of an ERP system by knowing what is possible, to hot-wiring around a supposedly pass word protected area on a web site for valuable information.
This actually doesn't help a lot in marketing - not as much as it should do. In the last start up I worked in, an Internet consumer opinion web crawler company, there was no real marketing dept, I worked as an analyst, and the function was referred to as "fluffy in marketing". The soft skills are more important than being able to understand the technology and often those "soft" skills involve native cunning, raw ambition, power hunger and control freak-ery!
Where hard skills are valuable is in start ups and SMEs where you are closer to the core and can be involved directly in the technical side of the company, or in extending what you can deliver by virtue of your hard skill. SMEs will be wanting people who can multitask as well as understand their technology. A hard skill on the table, may mean also that you can learn the technology or system to a high level, and maybe even develop it further or take your knowledge and implement it in another enterprise where you are valued higher.
There will however be set backs in going down an SME route: but believe you me there are set backs in corporates- office politics, down sizing and being overlooked for promotion in favour of annoying MBA graduates amongst the worst. SMEs go bust more often than bigger companies and often they do not pay employees very well. Both of the internet developer agencies I worked in went bust and I came out with a bitter taste in my mouth a little unnecessarily and went back to "client side" for a few years. Also some start ups just fall apart due to personality and ambition clashes, or because the feel of the company is lost when the investors, especially VC, come in hard with their own ways of wanting things done and their chosen managers.
Do not despair, a group of venture capitalists were given an anonymised business plan and CVs of the founders and they all rejected it: the company anonymised was in fact Apple. More than a skill set around the market and technology the start up or SME is in, you will also equip yourself with a thick skin and the ability to realise value and be "nimble" in moving quickly on to the next opportunity in a competitor or in your own new enterprise.
The key amount of funding you need is to give your company enough "cash" in the bank to be able to survive on the one side, a three to six months period of costs and R&D which then bridges the gap to being paid by customers, or as if often the case in technology start ups, reaching the next milestone in acheivements such that more investment follows to cover the next and bigger period before you get paid by customers - in a nut shell. So instead of maybe a year of job security and any money you invest in your pension being safe, you have 3 to 6 months and a very high risk on any monies you have placed into shares in the company!
I think that is about all I want to say in this little ditty about getting your head up as a 22- 24 year old as on average you will be, and maybe actually realising that the path to having a better life with a decent big old detached house, a boat, a chalet, early retirement and so on, is no longer by being a non owning employee and that you can use your marketing in a direction which will pay larger dividends long term.
Showing posts with label 'university of strathclyde' MSc Marketing. Show all posts
Showing posts with label 'university of strathclyde' MSc Marketing. Show all posts
Friday, January 17, 2014
Monday, January 17, 2011
Internet Security for Non IT Managers
Internet Security
In this lecture we will talk about the major issues in internet security for non IT managers involved in secure web projects or operations, and for us all as consumers using the internet for banking, shopping and social-media.
We will consider firstly the largest threats; look at some of the technical means of attacking and defending our security at the user level - also touching on server level diligence - ; visit a complete alternative to open internet traffic for encrypted communication ; look in more detail at some of the potential technical loopholes or hacker opportunities ; and then summarise what steps should be included in web site development; At the very end ,as not just an appendix, we will discuss the highest level of practical internet security used for consumer banking today, the digital token system.
Acknowledgements and further reading: In compiling this I am very much indebted to the Harvard University E75 course, as streamed on Academic Earth.com and conducted by Professor David Malan. Please regard this as the main reference material for building a less technical while well informed background to this lecture. The course has been excellent in extending my own knowledge as a largely non-technical project leader earlier within the industry. One thing which inspired me to write this is actually the verbose and often esoteric nature of many wikipedia entries relating to internet technologies, but for all acronyms I would refer the user there as I have at least followed them up and used some as information sources, all authors recognised and copyright not infringed.
The Major Threats in Internet Security
The biggest security threats to your use of web sites and related e-mails on the internet today are all from what we could summarise as euphemistically " human error " namely ** :
Threat #1: Identity Theft and Open Public Networks
Having someone hijack your facebook session ID and log into your facebook may seem trivial and just irritating, but in doing this they can get enough information to commence a very good identity theft. Also your session may be with a web shop who have lax security "around the edges" meaning that someone could control your account details, deny you access and use your credit card or balance on the site to make purchases or bogus payments.
Why are public WiFi networks not safe?
Public WiFi is one of the main threats to internet security, when you engage with a public network or do not suitably protect your home or office WiFi. Passwords sent over a public network , Starbucks, etc, are completely open to copying if there is no SSL or Javascript VPN encrypting communications.
On any non https (SSL) web site, or web page for that matter, your data communication is completely open on a public network: so you are exposed to potential identity theft and more sophisticated phishing scams which use other communications like SMS, e-mail and telephone calls to coerce you into giving out more information over a web URL address, leading to theft.
For example, Wireshark - formerly Etheral - sniffs wifi or other routers and can intercept any packet of http on an open network router like in a wifi hotspot.
Even with SSL you could be victim to an attack from a local computer on the Wifi /LAN running a copy-cat site which intercepts your internet traffic and makes you believe you are entering user name / password to the real world version of the site. ( A.k.a. "middle-man-attack")
The same is actually true for FTP: the password can be intercepted on a network which is not secure, and standard http where the http packets can be intercepted by third parties. SFTP makes FTP passwords encrypted.
A "Perfect" Secure Solution is Out There: VPN - But at What Cost?
The supposedly perfect means of connecting in a secure way over the "Internet", is actually to go against all the usual principles of free movement and negotiate a VPN: a virtual private network.
These are similar to WANs og GANs (wide or global area networks) but use a higher level security by encrypting everything using a private key, not communicated over the internet/WAN. Sometimes VPNs dispense with usual TCP-IP and have alternative connection protocol and technologies centred on encyrption.
The VPN relies on a defined route over the internet, sometimes between just two internet nodes / routers, and crucially it relies that both sides have the same private network key for encryption, or synchronise this key in a way which relies on the closed loop of the key never being transmitted. The VPN is yet more secure by being relatively private or closed off from the rest of the internet traffic at the router level, where interception of data by hackers could be possible.
However VPNs are largely impractical and overly expensive for most e-commerce applications where users, sorry consumers, are not readily able or willing to set up a secure encyrption key. It would mean that for simple shopping on the internet, people would just move away from the shop asking for VPN set up, going to a competitor. Consumers are used to simple steps using https, a password and for lower value transactions with the big brands or trusted sources, they are comfortable with the level of risk.
Also we would undoubtedly have to pay a lot more for our connection to the "internet" in using this kind of ring-fenced data route (a.k.a a tunnel).
On the other hand, with the use of token mediated security, the cost and time of establishing VPN between high value consumers and their banks and secure trading areas may outweigh the risks of using http and https at some point, or at least the percieved risk.
However, this could lead to a false sense of security, and hence if someone does take control of the remote computer or hack the server, then any delay in detecting this could lead to a higher relative financial or IPR loss because the stakes were probably high enough to pay for a VPN in outset.
Threat # 2: Sloppy Programming
There are several areas which are subject to security breaches caused by sloppy programming for want of a better word for lazyness or poor project resource- invesment.
Also not covering for a simple security breach in those auto-form fill requests, allowing an external site to phish out the log in name and even password,
It should be pointed out that the small JS programming routines (scripts) operating in the browser, which do things like allow for only 10 characters in a user name, or ensure the operators " <>&%?" etc in a field are invalidated or neutralised (escaping the data), also help increase security from unforseen attacks with new command lines.
We will cover most of these types of attacks in a little more detail below. Realistically they can all be managed-out with due diligence routines in the security section of a sweb project, long before launch.
Don't Take Your Internet Browser For Granted
What we actually rely on for much of our internet security at home, is not our ISP or national DNS authorities, but our humble internet browser.
Sometimes new techniques evolve within the possibilities offered by the internet, which mean that hackers can gain access to information being passed to-and-from, or held in our PCs. Or worse, they can take control of our own PCs over the internet, or actual entire web servers.
One example of this was when Javascripting allowed for pop ups and there was possibility for cross domain JS scripts running automatically before you could stop a cascade of new windows opening.
The pop up issue with JS (javascript) above, lead to a rapid introduction of new security measures in the browsers. This included the control of all pop ups which are cross domain, or those which automatically ran the scirpsts leading to this action, and involuntary start up of scripts running file management actions ie auto down load of files out of your control.
The latter versions of all main browsers, have closed down this type of activity so you have to opt in to opening such pop ups, third party scripts, file downloads and external links with a warning controlled by the browser, so clicking "cancel" does not take your vote for the Republicans. This has of course gone further with more restrictions within Hot- and G- mail interfaces for example, which block all html link and script content at source code level in e-mails.
Browser security is an arms race which has, by-in-large for now, been completely won by the leading makers of browsers. Hackers spend more of their energies trying to capture data in transit, steal identities from snail-mail, or catch out our sloppy programmers as mentioned, rather than programming work-arounds for browser security.
Internet Explorer, FireFox, Safari, Opera and Chrome hold the majority of the world's internet access in their hands, and do really an admirable job for what is freeware! These programmes contain the https (SSL) encryption and certification system, the controls of javascript and the security rules on what web sites can and cannot access: for example web sites should not be able to view other web sites cookies (as info references, stored user names or session IDs): and one web site may not use scripting from another source by the policing of this by the browser in the standard cross domain policy.
However, despite having just stated that the battle against browser mediated hacking is "won", microsoft/Apple/ Mozilla/Google all keep ahead of potential or emerging threats by updating their software, which is more or less automatic for you and me. Therefore you really should not impeed the progress of updates to IE, Firefox or Safari because despite this being free, it is of high value to you!
Threat # 3 : Server Hijacking
One of the nirvannas of hacking used to be gaining control of supposedly secure servers. Now as e-commerce and web serving perhaps becomes more widespread or under cost pressure to offer cheaper hosting, non IT managers should be aware that investment in resources and best practice in this area is essential.
Apache and other server secutiry issue: super user status: on default programmes running on linux Apache, the super user is "Root", and this means that some programmes running are actually at the level of super user, so if they crash or are manipulated then an external hacker can run the whole server by assuming that super user during and after the crash. This is avoided by having a different default super user on an internal machine, so that programmes crashing just crash or the server needs to be rebooted by the administrator with those permissions.
When web pages on a unix/linux system are served via Apache, then the permission to access is fully public, but the properly configured apache server will send your dot com or IP requests at top level domain just to index.php or -.html and send the request in dynamic web URLs to the file to be processed to give a result ( expects the result to be the reply to the URL request, say a GET$) and NOT the actual source code. Other users on the APACHE served network could see your source code though , but there are other security programmes which empose a layer of administration permission onto your own file area: eg suPHP, substitute user PHP.
Some web hosts will however, configure their linux environment so that the Apache has super user access, and allows for a public route to the served content and operations, while not allowing file admin to anyone but the owner of those web sitess, and the apache /linux super user administrator. If there is a php environement running anyway, then suPHP does this rather well according to Prof. David Malan at least, so the extra work is probably not worth the time. The permission can be applied to directory AND file, such that if abberant files or hacks can be stopped from working.
Threat # 4: Cookie and Session Hijack Issues
Cookies : storing user name and password in a cookie is a bad idea, because it is both open over any open network when you connect to the owning site and communicate these details over: and if your machine is compromised or you are on a shared machine, it is there as a visible text on the hard drive. Https only protects in transit, and quite a few web sites are sloppy, starting a user session and setting up initial user name cookies outside the https encryption, meaning the cookies can be read by interceptors.
Sesssion hijacking means the open account, after password is passed, has the cookie and session ID running and can just be copied and while you are logged in. The other hacking user can have a duplcate session running: this is why re-set password should include re-iterate current password so that they cannot just exclude you from your own account from such an interception and temporary hijack.
Sessions are useful because http is not a continuous connection, and also now you have quite a lot of JSON/XML/Ajax/API functionality in the background giving you useful data while you are logged into an area or otherwise in a "session".
Google analytic cookies: google gets around the cross domain policy because they are so often opted in on so many sites, becase they offer those sites free web stats in return. This means that they can link the information on where you have been because they are the same domain accessing and laying the cookie upon request. As we will see a phishing URL could mimmick google while actually sending cookie data to an third party site in an XSS conflict attack.
Browsers though can disable such third party cookies ( 'external site' in firefox), but at the moment is is not a default and in fact in FireFox's latest versions it is actually only specifically in add ons which must be installed seperately.
Session IDs can be completely random, because they are huge numbers in PHPs session ID engine for example. The chances of a hacker second guessing one is low, in relation to a user name, and the chances of two users on the same server and web site getting issued the same session ID are null if the random issuing is not reiterative through a pseudo random listing.
A cookie's sphere of influence or reading can also be limtied to certain file directories in the server URL / directory set up, in the little packet of info in the cookie which helps restrict GET URL theft of Session ID or use of it further.
The Major Cornerstone in Today's Internet Security: SSL and https
When you see the sign for https then you know you are utilising a line which encrypts form data and information coming back from the site, using a certified system integrated on servers and browsers called SSL ( secure socket layers).
Https is what you see at your end, as well as some dialogue pop out window warnings, usually about entering or leaving a secured area. Also you may be warned that the Security Certificate for a web site is expiring, which means its accreditation to most often microsoft, has run out.
These little warnings about entering and leaving a secure area may be annoying, but if you are using a public network it is very well worth noting that you may still be "logged in" and using some facilities private to you while the "http" has lost the little "s". Thus your communications are open again. It is worth deleting all cookies when you leave a public computer or making sure you log off from the web site you were on before you shut down the machine or window.
Using https helps the problem of potential router-interception or public Wifi network session hijacking, but it is still possible that any info or pages not in https reveal the cookie session ID on a public WIfi network for example or an insecure router. Such a hijacked session could then revert to the https area and abuse your account or credit card.
SSL/https is not supported by all serves ( if not all routers ?), and most sites which have https requires that bit extra time and processing means that after log in , facebook amongst others kicks you over to standard http and uses a session ID. So https is a performacne and server capacity issue, but under the UK dataprotection act at least, personal details linked to web registration, would be reasonably expected to be protected by SSL as a consideration for due diligence.
SSL: secure socket layers; SSL Certificates : What is all this About?
SSL certificates usually cover one domain name on one IP address, and they are issued/certified by your trusted domain name partner, like network solutions, Verisign, Go Daddy etc when you buy an https ready web domain.
The browser types themselves, like IE 6, have approved SSL partner lists from Microsoft, giving a certain level of confidence and meanign that you should have a host which is on the MS list for SSL certified source. Having one enables you to receive and send https on the network or internet routers. The >SSL certificate contains a code which denotes the vendor.
You can get a *.com 'wildcard' SSL for a single IP address running as a virtual web host, but this is expensive and the key will possibly be the same across all the web sites you have running there. However given good apache / linux file admin, this can be attractive for TLD names and sub domain level name security.
SSL's Public Key Encrytpion Practice and Theory
SSL's system is sometimes called assymetric encryption, because the users have a their own respective public key and this public encrytping key is different to the decrytpting key, the private key.
As a new customer / visitor we do not have a shared secret key in advance : the shared secret would be sent "In the clear" so it could be intercepted.
Public key and privat key are generated at browswer installment time, and at the SSL certified server side when say Apache is installed or upgraded to SSL at that unique IP address. There is actually a mathematical relationship between the public and private keys.
What happens is that you communicate the public encryption key to each other and send the data encrypted to this key, while it is actually decrypted by a local private key. Your SSL public key is open for any https connection to read, and that web site will then encrypt using that key, but only YOU can decode that encryption. The reverse is true for sending data, you get the servers public key code when you request an https transaction and only the server can then decrpyt that - in theory, using their private key.
Elegant!
Theory:
The two numbers as mentioned are related to each other, and the public is generated from the private : to overly simplyfy: the public is the private to the power n for example with the private being a prime positive integer for example. The public numbers are shared to perform a one way encryption of ASCII and other characters over to numbers. The public key can be accessed, but the computational power needed to decrypt any messages would be so huge that it renders it unpractical to do so.
Issue: is middle in the man attack or of course hijacking in either an internet cafe scenario: someone on that network intercepts your https initial request to say amazon, and presents themselves as amazon, sending a key they of course can decrypt. The same could be true if a mis-spell or an expired domain name is hijacked, and maybe you return there with your pass word and user name, and they then ask you to reissue your credit card details.
Other Security Risks Relating to Sloppy Programming :
SQL Injection Attacks
This means that a SQL coding is written into a form field/s and then submitted then becoming a query ie a valid SQL command. This is worked around by 'escaping' the syntax, like apostrophes which enclose a string to be submitted: the content of the field string then becomes like CDATA, and this can be done also at the javascript level to help users whose names contain "illegal" characters.
Same Origin Policy Breaches
JS code does not allow for direct republishing or integration of data in JS from cross-origin web sites. RSS and XML do allow for this, usually done server side through importing via PHP , but that is safer than allowing JS to roam the internet outside the origin who wrote it. So FB can update to itself in JSON/Ajax but not use this API
Third party javascript cannot look into your browser behaviour : so ad's cannot directly do this. Frames are the same, so you cannot manipulate a frame requested from another URL.
The data has to first be "imported" to your own or the common domain so that when served to you it is : the same is true of APIs: you have to copy google maps JS and then it is just looking for permitted flat data in their google maps repository.
CSRF ( Phishing email and bad web site links)
A commonly used web site which involves financial / buying can be embedded in a link in an email or a phishing site, which you click on and then it uses the session ID to then open a direct account: these can be hidden at the top of jpeg http requests, so you don't even click on them.
This can be worked around by good cookie management and requesting password for any buy or send sensitive data. Also this is related to URL GET$ so it is wise to use POST data for some key transactions.
Cross Site Scripting - XSS - Vulnerabiliy
This is similar to SQL injection: an HTML GET line or form submission is mimmicked in a link, which also may contain a script activation reference, overcoming cross domain policy. The first half of the URL is mimmicking the real web site and its form fill /submit page or GET $URL, but then also requesting a bit of javascript linking to the attacking site.
Once again, these URL links can be automatically run in http headers for jpegs etc, and hence hotmail and g-mail protect against content with links in HTML-mail.
The phishing URL will request a JS held on the Baddie URL which is embedded / referenced to the fake host URL. www.amazon.com/?....script js..document.location= filewhich will for example look at the cookie for amazon dot com and then refer it over to badguy such that they coud steel the user session ID.
Increasing Security
Top Ten Tips When Considering Implementation or LifeCycle Updates of a web site which should have a diligent level of security:
Another means of internet security for the highest levels of banking, software exchange (inc high value web services), film streaming and e-commerce itself is the use of "token" based password/ verification / encryption code. This adds an additional layer of security which is difficult to intercept and virtually impossible to guess. The token itself plus the log in and password would all need to be stolen from the user and used before they could alert the bank.
The most popular type of token is the stand alone, thumb sized medallion, which have a preprogrammed number generator which generate a password or encryption key number either synchronisously/sequentially done with the server or interpreted like an SSL key.
There are also dongle and cordless types which send the data when you allow connection, and latterly out-of-band tokens can be used which send an SMS or other datapacket through another type of telephony than the internet TCPIP.
In many banking web systems, the token key is a one time password and is requested both at log in and when movements or payments are to be made. Banks always use https and SSL certification, thus there is a very good extra layer of security requiring this token be to hand. If you had your token AND your identity stolen you would notice it, or be the victim of a "extortion with menaces" ie an off line mediated crime.
This further reduces the chances of Session Hijacking getting anywhere, but you could in theory still be open to middle-man scams if someone was really able to mimmick the bank site, and then pass the current synchronised token key on further in actioning fraud in your real web account.
Back End Security
The key issues of back end security arise beyond the SSL decryption on the server side. For example, log in passwords and credit card numbers are then fed back to the database server for verification, or initial data entry. This has in the past lead to employees stealing databases, or developers loosing laptops which included copies for WIP testing. Now even MySQL, the shareware, includes modules (eg AES) which allow for industry standard encryption of password: some use the ASCII coding in the password as the actual key, and this has some native appeal given the initial connection was SSL and the user keeps their password to themselves. The down side is that no one can know the original password, or even the legnth of it on better encryption, so if you forget it, then you have to register new or go through some other security checks and get it sent to you by e-mail or SMS.
ENDS--
In this lecture we will talk about the major issues in internet security for non IT managers involved in secure web projects or operations, and for us all as consumers using the internet for banking, shopping and social-media.
We will consider firstly the largest threats; look at some of the technical means of attacking and defending our security at the user level - also touching on server level diligence - ; visit a complete alternative to open internet traffic for encrypted communication ; look in more detail at some of the potential technical loopholes or hacker opportunities ; and then summarise what steps should be included in web site development; At the very end ,as not just an appendix, we will discuss the highest level of practical internet security used for consumer banking today, the digital token system.
Acknowledgements and further reading: In compiling this I am very much indebted to the Harvard University E75 course, as streamed on Academic Earth.com and conducted by Professor David Malan. Please regard this as the main reference material for building a less technical while well informed background to this lecture. The course has been excellent in extending my own knowledge as a largely non-technical project leader earlier within the industry. One thing which inspired me to write this is actually the verbose and often esoteric nature of many wikipedia entries relating to internet technologies, but for all acronyms I would refer the user there as I have at least followed them up and used some as information sources, all authors recognised and copyright not infringed.
The Major Threats in Internet Security
The biggest security threats to your use of web sites and related e-mails on the internet today are all from what we could summarise as euphemistically " human error " namely ** :
- Phishing scams and resulting identity theft, or temporary seizing of control of bank/shopping accounts- the human error in opening the links!
- Sloppy programming allowing for loopholes like SQL/script injection and session ID capture, as well as link mediated phishing scams or copy-cat web sites.
- Using your own laptop in an open network or public Wifi spot... and resulting identity theft or temporary seizing of control of bank/shopping accounts
Threat #1: Identity Theft and Open Public Networks
Having someone hijack your facebook session ID and log into your facebook may seem trivial and just irritating, but in doing this they can get enough information to commence a very good identity theft. Also your session may be with a web shop who have lax security "around the edges" meaning that someone could control your account details, deny you access and use your credit card or balance on the site to make purchases or bogus payments.
Why are public WiFi networks not safe?
Public WiFi is one of the main threats to internet security, when you engage with a public network or do not suitably protect your home or office WiFi. Passwords sent over a public network , Starbucks, etc, are completely open to copying if there is no SSL or Javascript VPN encrypting communications.
On any non https (SSL) web site, or web page for that matter, your data communication is completely open on a public network: so you are exposed to potential identity theft and more sophisticated phishing scams which use other communications like SMS, e-mail and telephone calls to coerce you into giving out more information over a web URL address, leading to theft.
For example, Wireshark - formerly Etheral - sniffs wifi or other routers and can intercept any packet of http on an open network router like in a wifi hotspot.
Even with SSL you could be victim to an attack from a local computer on the Wifi /LAN running a copy-cat site which intercepts your internet traffic and makes you believe you are entering user name / password to the real world version of the site. ( A.k.a. "middle-man-attack")
The same is actually true for FTP: the password can be intercepted on a network which is not secure, and standard http where the http packets can be intercepted by third parties. SFTP makes FTP passwords encrypted.
A "Perfect" Secure Solution is Out There: VPN - But at What Cost?
The supposedly perfect means of connecting in a secure way over the "Internet", is actually to go against all the usual principles of free movement and negotiate a VPN: a virtual private network.
These are similar to WANs og GANs (wide or global area networks) but use a higher level security by encrypting everything using a private key, not communicated over the internet/WAN. Sometimes VPNs dispense with usual TCP-IP and have alternative connection protocol and technologies centred on encyrption.
The VPN relies on a defined route over the internet, sometimes between just two internet nodes / routers, and crucially it relies that both sides have the same private network key for encryption, or synchronise this key in a way which relies on the closed loop of the key never being transmitted. The VPN is yet more secure by being relatively private or closed off from the rest of the internet traffic at the router level, where interception of data by hackers could be possible.
However VPNs are largely impractical and overly expensive for most e-commerce applications where users, sorry consumers, are not readily able or willing to set up a secure encyrption key. It would mean that for simple shopping on the internet, people would just move away from the shop asking for VPN set up, going to a competitor. Consumers are used to simple steps using https, a password and for lower value transactions with the big brands or trusted sources, they are comfortable with the level of risk.
Also we would undoubtedly have to pay a lot more for our connection to the "internet" in using this kind of ring-fenced data route (a.k.a a tunnel).
On the other hand, with the use of token mediated security, the cost and time of establishing VPN between high value consumers and their banks and secure trading areas may outweigh the risks of using http and https at some point, or at least the percieved risk.
However, this could lead to a false sense of security, and hence if someone does take control of the remote computer or hack the server, then any delay in detecting this could lead to a higher relative financial or IPR loss because the stakes were probably high enough to pay for a VPN in outset.
Threat # 2: Sloppy Programming
There are several areas which are subject to security breaches caused by sloppy programming for want of a better word for lazyness or poor project resource- invesment.
- Server Side issues: File Management, Security, Configuration and so on.
- Web site areas which go in and out of secure pages while the "session" is still continuing
- Making code easily copyable such that someone can fake your web site in a phishing or middle-man scam.
- Not programming out loopholes in how information from web sites enters the web server- allowing for SQL/PHP or JS scripts to control the server log in area or crash the server
- Not managing the session ID ( cookie) in a secure way which means making them expire and replacing the ID number next time with something which cannot be guessed from the previous one.
- Neglecting to use POST data for some important stages when a visible GET URL is shown instead, exposing a security risk.
It should be pointed out that the small JS programming routines (scripts) operating in the browser, which do things like allow for only 10 characters in a user name, or ensure the operators " <>&%?" etc in a field are invalidated or neutralised (escaping the data), also help increase security from unforseen attacks with new command lines.
We will cover most of these types of attacks in a little more detail below. Realistically they can all be managed-out with due diligence routines in the security section of a sweb project, long before launch.
Don't Take Your Internet Browser For Granted
What we actually rely on for much of our internet security at home, is not our ISP or national DNS authorities, but our humble internet browser.
Sometimes new techniques evolve within the possibilities offered by the internet, which mean that hackers can gain access to information being passed to-and-from, or held in our PCs. Or worse, they can take control of our own PCs over the internet, or actual entire web servers.
One example of this was when Javascripting allowed for pop ups and there was possibility for cross domain JS scripts running automatically before you could stop a cascade of new windows opening.
I myself lost control of a laptop once by wandering my cursor over a gambling banner-ad' or icon, clicking by accident: it opened many casino sites and some hard porn sites in Russia, dozens of them within a couple of seconds, which in turn opened a download dialogue and landed a trojan horse executable in the background which was active just before the antivirus found it and was therefore able to run several exe's essentially taking administration control of my machine and not allowing me to even use CTRL-ALT-DEL to find out what was running!
The pop up issue with JS (javascript) above, lead to a rapid introduction of new security measures in the browsers. This included the control of all pop ups which are cross domain, or those which automatically ran the scirpsts leading to this action, and involuntary start up of scripts running file management actions ie auto down load of files out of your control.
The latter versions of all main browsers, have closed down this type of activity so you have to opt in to opening such pop ups, third party scripts, file downloads and external links with a warning controlled by the browser, so clicking "cancel" does not take your vote for the Republicans. This has of course gone further with more restrictions within Hot- and G- mail interfaces for example, which block all html link and script content at source code level in e-mails.
Browser security is an arms race which has, by-in-large for now, been completely won by the leading makers of browsers. Hackers spend more of their energies trying to capture data in transit, steal identities from snail-mail, or catch out our sloppy programmers as mentioned, rather than programming work-arounds for browser security.
Internet Explorer, FireFox, Safari, Opera and Chrome hold the majority of the world's internet access in their hands, and do really an admirable job for what is freeware! These programmes contain the https (SSL) encryption and certification system, the controls of javascript and the security rules on what web sites can and cannot access: for example web sites should not be able to view other web sites cookies (as info references, stored user names or session IDs): and one web site may not use scripting from another source by the policing of this by the browser in the standard cross domain policy.
However, despite having just stated that the battle against browser mediated hacking is "won", microsoft/Apple/ Mozilla/Google all keep ahead of potential or emerging threats by updating their software, which is more or less automatic for you and me. Therefore you really should not impeed the progress of updates to IE, Firefox or Safari because despite this being free, it is of high value to you!
Threat # 3 : Server Hijacking
One of the nirvannas of hacking used to be gaining control of supposedly secure servers. Now as e-commerce and web serving perhaps becomes more widespread or under cost pressure to offer cheaper hosting, non IT managers should be aware that investment in resources and best practice in this area is essential.
Apache and other server secutiry issue: super user status: on default programmes running on linux Apache, the super user is "Root", and this means that some programmes running are actually at the level of super user, so if they crash or are manipulated then an external hacker can run the whole server by assuming that super user during and after the crash. This is avoided by having a different default super user on an internal machine, so that programmes crashing just crash or the server needs to be rebooted by the administrator with those permissions.
When web pages on a unix/linux system are served via Apache, then the permission to access is fully public, but the properly configured apache server will send your dot com or IP requests at top level domain just to index.php or -.html and send the request in dynamic web URLs to the file to be processed to give a result ( expects the result to be the reply to the URL request, say a GET$) and NOT the actual source code. Other users on the APACHE served network could see your source code though , but there are other security programmes which empose a layer of administration permission onto your own file area: eg suPHP, substitute user PHP.
Some web hosts will however, configure their linux environment so that the Apache has super user access, and allows for a public route to the served content and operations, while not allowing file admin to anyone but the owner of those web sitess, and the apache /linux super user administrator. If there is a php environement running anyway, then suPHP does this rather well according to Prof. David Malan at least, so the extra work is probably not worth the time. The permission can be applied to directory AND file, such that if abberant files or hacks can be stopped from working.
Threat # 4: Cookie and Session Hijack Issues
Cookies : storing user name and password in a cookie is a bad idea, because it is both open over any open network when you connect to the owning site and communicate these details over: and if your machine is compromised or you are on a shared machine, it is there as a visible text on the hard drive. Https only protects in transit, and quite a few web sites are sloppy, starting a user session and setting up initial user name cookies outside the https encryption, meaning the cookies can be read by interceptors.
Sesssion hijacking means the open account, after password is passed, has the cookie and session ID running and can just be copied and while you are logged in. The other hacking user can have a duplcate session running: this is why re-set password should include re-iterate current password so that they cannot just exclude you from your own account from such an interception and temporary hijack.
Sessions are useful because http is not a continuous connection, and also now you have quite a lot of JSON/XML/Ajax/API functionality in the background giving you useful data while you are logged into an area or otherwise in a "session".
Google analytic cookies: google gets around the cross domain policy because they are so often opted in on so many sites, becase they offer those sites free web stats in return. This means that they can link the information on where you have been because they are the same domain accessing and laying the cookie upon request. As we will see a phishing URL could mimmick google while actually sending cookie data to an third party site in an XSS conflict attack.
Browsers though can disable such third party cookies ( 'external site' in firefox), but at the moment is is not a default and in fact in FireFox's latest versions it is actually only specifically in add ons which must be installed seperately.
Session IDs can be completely random, because they are huge numbers in PHPs session ID engine for example. The chances of a hacker second guessing one is low, in relation to a user name, and the chances of two users on the same server and web site getting issued the same session ID are null if the random issuing is not reiterative through a pseudo random listing.
A cookie's sphere of influence or reading can also be limtied to certain file directories in the server URL / directory set up, in the little packet of info in the cookie which helps restrict GET URL theft of Session ID or use of it further.
The Major Cornerstone in Today's Internet Security: SSL and https
When you see the sign for https then you know you are utilising a line which encrypts form data and information coming back from the site, using a certified system integrated on servers and browsers called SSL ( secure socket layers).
Https is what you see at your end, as well as some dialogue pop out window warnings, usually about entering or leaving a secured area. Also you may be warned that the Security Certificate for a web site is expiring, which means its accreditation to most often microsoft, has run out.
These little warnings about entering and leaving a secure area may be annoying, but if you are using a public network it is very well worth noting that you may still be "logged in" and using some facilities private to you while the "http" has lost the little "s". Thus your communications are open again. It is worth deleting all cookies when you leave a public computer or making sure you log off from the web site you were on before you shut down the machine or window.
Using https helps the problem of potential router-interception or public Wifi network session hijacking, but it is still possible that any info or pages not in https reveal the cookie session ID on a public WIfi network for example or an insecure router. Such a hijacked session could then revert to the https area and abuse your account or credit card.
SSL/https is not supported by all serves ( if not all routers ?), and most sites which have https requires that bit extra time and processing means that after log in , facebook amongst others kicks you over to standard http and uses a session ID. So https is a performacne and server capacity issue, but under the UK dataprotection act at least, personal details linked to web registration, would be reasonably expected to be protected by SSL as a consideration for due diligence.
SSL: secure socket layers; SSL Certificates : What is all this About?
SSL certificates usually cover one domain name on one IP address, and they are issued/certified by your trusted domain name partner, like network solutions, Verisign, Go Daddy etc when you buy an https ready web domain.
The browser types themselves, like IE 6, have approved SSL partner lists from Microsoft, giving a certain level of confidence and meanign that you should have a host which is on the MS list for SSL certified source. Having one enables you to receive and send https on the network or internet routers. The >SSL certificate contains a code which denotes the vendor.
You can get a *.com 'wildcard' SSL for a single IP address running as a virtual web host, but this is expensive and the key will possibly be the same across all the web sites you have running there. However given good apache / linux file admin, this can be attractive for TLD names and sub domain level name security.
SSL's Public Key Encrytpion Practice and Theory
SSL's system is sometimes called assymetric encryption, because the users have a their own respective public key and this public encrytping key is different to the decrytpting key, the private key.
As a new customer / visitor we do not have a shared secret key in advance : the shared secret would be sent "In the clear" so it could be intercepted.
Public key and privat key are generated at browswer installment time, and at the SSL certified server side when say Apache is installed or upgraded to SSL at that unique IP address. There is actually a mathematical relationship between the public and private keys.
What happens is that you communicate the public encryption key to each other and send the data encrypted to this key, while it is actually decrypted by a local private key. Your SSL public key is open for any https connection to read, and that web site will then encrypt using that key, but only YOU can decode that encryption. The reverse is true for sending data, you get the servers public key code when you request an https transaction and only the server can then decrpyt that - in theory, using their private key.
Elegant!
Theory:
The two numbers as mentioned are related to each other, and the public is generated from the private : to overly simplyfy: the public is the private to the power n for example with the private being a prime positive integer for example. The public numbers are shared to perform a one way encryption of ASCII and other characters over to numbers. The public key can be accessed, but the computational power needed to decrypt any messages would be so huge that it renders it unpractical to do so.
Issue: is middle in the man attack or of course hijacking in either an internet cafe scenario: someone on that network intercepts your https initial request to say amazon, and presents themselves as amazon, sending a key they of course can decrypt. The same could be true if a mis-spell or an expired domain name is hijacked, and maybe you return there with your pass word and user name, and they then ask you to reissue your credit card details.
Other Security Risks Relating to Sloppy Programming :
SQL Injection Attacks
This means that a SQL coding is written into a form field/s and then submitted then becoming a query ie a valid SQL command. This is worked around by 'escaping' the syntax, like apostrophes which enclose a string to be submitted: the content of the field string then becomes like CDATA, and this can be done also at the javascript level to help users whose names contain "illegal" characters.
Same Origin Policy Breaches
JS code does not allow for direct republishing or integration of data in JS from cross-origin web sites. RSS and XML do allow for this, usually done server side through importing via PHP , but that is safer than allowing JS to roam the internet outside the origin who wrote it. So FB can update to itself in JSON/Ajax but not use this API
Third party javascript cannot look into your browser behaviour : so ad's cannot directly do this. Frames are the same, so you cannot manipulate a frame requested from another URL.
The data has to first be "imported" to your own or the common domain so that when served to you it is : the same is true of APIs: you have to copy google maps JS and then it is just looking for permitted flat data in their google maps repository.
CSRF ( Phishing email and bad web site links)
A commonly used web site which involves financial / buying can be embedded in a link in an email or a phishing site, which you click on and then it uses the session ID to then open a direct account: these can be hidden at the top of jpeg http requests, so you don't even click on them.
This can be worked around by good cookie management and requesting password for any buy or send sensitive data. Also this is related to URL GET$ so it is wise to use POST data for some key transactions.
Cross Site Scripting - XSS - Vulnerabiliy
This is similar to SQL injection: an HTML GET line or form submission is mimmicked in a link, which also may contain a script activation reference, overcoming cross domain policy. The first half of the URL is mimmicking the real web site and its form fill /submit page or GET $URL, but then also requesting a bit of javascript linking to the attacking site.
Once again, these URL links can be automatically run in http headers for jpegs etc, and hence hotmail and g-mail protect against content with links in HTML-mail.
The phishing URL will request a JS held on the Baddie URL which is embedded / referenced to the fake host URL. www.amazon.com/?....script js..document.location=
Increasing Security
Top Ten Tips When Considering Implementation or LifeCycle Updates of a web site which should have a diligent level of security:
- Block subversive commands in data submitted to your dynamic web sites ( "/&%" and so on) All GET$ and POST $ data being submitted should be "escaped" that is the string sent is like CDATA- the computer knows to ignore the content until it comes to the end of the escape
- You limit the legnth of the form $ to a known or reasonable number of characters in the POST/GET on server side, and you can do this with JS during form control.
- You also limit the characters possible to submit from the web form.
- You use POST data instead of GET$ in open URL, and call this POST command set up in a hidden file area from general web page code,
- Make sessions ID only temporary with an expiry inversely proportional to the potential personal financial loss from session hijack or reuse of a public computer.
- Request password ( or token key number, see below) at vulnerable points where payment is required, value is to be transfered or personal details and credit cards can be viewed.
- Re-set password should also include re-iterate current password so that a hacker cannot just exclude you from your own account from a session hijack. Ideally this should be accompanied by an e-mail or SMS action as in 8:
- To activate accounts or change e-mail addresses to accounts, you force an e-mail to be sent to the original email address on the original registration: you keep this field as a locked UID for the user and copy the e-mail address over to a field modifiable by the user. Consider using an SMS mediated activation code or temporary password from an original mobile phone number in this vain.
- Log suspicsious IP addresses which attempt the submission of SQL/Bolean or HTML coding in form fields. Refresh session ID underway to those which are suspicious and leave a permanent cookie with a special user ID on that side to see if they repeat an attack. If the IP address is common to a small ISP, a university or the like, contact their system administration or security manager. Exclude IP addresses from countries with which you have no business with or are noteworthy sources of criminal internet attacks.
- When the transactions, personal information or IPR exposed is of significant value and the traffic volume is acceptable in cost-benefit, then consider either using an SMS key or password system, a digital token system or setting up a VPN connection to users ( See below) . The same could be true if you are aware that there have been many attempts or several successful breaches of security from user identity theft or Session Hijacking.
Technical Approaches in the Highest Level of Consumer Internet Security In Practice Today
VPN is one solution: virtual private network. This relies on a defined route, sometimes between just two internet nodes / routers, and also that both sides have the same private network key. This is discussed in some detail already, and we have mentioned the use of tokens, which are in effect symmetrical or highly encrypted assymetrical encryption keys.Another means of internet security for the highest levels of banking, software exchange (inc high value web services), film streaming and e-commerce itself is the use of "token" based password/ verification / encryption code. This adds an additional layer of security which is difficult to intercept and virtually impossible to guess. The token itself plus the log in and password would all need to be stolen from the user and used before they could alert the bank.
The most popular type of token is the stand alone, thumb sized medallion, which have a preprogrammed number generator which generate a password or encryption key number either synchronisously/sequentially done with the server or interpreted like an SSL key.
There are also dongle and cordless types which send the data when you allow connection, and latterly out-of-band tokens can be used which send an SMS or other datapacket through another type of telephony than the internet TCPIP.
In many banking web systems, the token key is a one time password and is requested both at log in and when movements or payments are to be made. Banks always use https and SSL certification, thus there is a very good extra layer of security requiring this token be to hand. If you had your token AND your identity stolen you would notice it, or be the victim of a "extortion with menaces" ie an off line mediated crime.
This further reduces the chances of Session Hijacking getting anywhere, but you could in theory still be open to middle-man scams if someone was really able to mimmick the bank site, and then pass the current synchronised token key on further in actioning fraud in your real web account.
Back End Security
The key issues of back end security arise beyond the SSL decryption on the server side. For example, log in passwords and credit card numbers are then fed back to the database server for verification, or initial data entry. This has in the past lead to employees stealing databases, or developers loosing laptops which included copies for WIP testing. Now even MySQL, the shareware, includes modules (eg AES) which allow for industry standard encryption of password: some use the ASCII coding in the password as the actual key, and this has some native appeal given the initial connection was SSL and the user keeps their password to themselves. The down side is that no one can know the original password, or even the legnth of it on better encryption, so if you forget it, then you have to register new or go through some other security checks and get it sent to you by e-mail or SMS.
ENDS--
Monday, November 15, 2010
Keep Your Head Up! Get that Job!
I think this will be my last post on this topic for a while: I am very keen to help students and recent graduates to get onto a good career train, or as good as it gets in the recession. However the readership is not huge and social media blogs are of more interest to Freddie readers apparently
The American way we often here is "who is recruiting? " : this is a good, direct way of thinking about grabbing opportunities: for these companies, and think company, growth and not job titile, your USPs ? ( unique selling poits)
1. Cheap: think 5 pounds per hour as ok! You can also be relocated cheaply. As going direct and avoiding recruitment consutlatns / bemanners you save them money, especially on a average graduate start package in the recession. Do not, repeat do not, turn down a good opp' on cash, or any opp in marketing right now. In graduate flat pay or "staff" jobs you will work many 12 hour days without moaning! That averages out to about 35% extra work free for marketing departments and suppliers of marketing services.
2. Available: you can start yesterday! As a graduate of 2010. Also you are most likely young/free/single-ish ( lie!) and therefore can relocate. When head count is to be secured by a manager facing "use it or lose it" budgeting, this can get you a job, or when a spotty non marketing graduate with two years photocopying in a boring marketing department has to give 1 months notice, you can be in there!
3: Skilled: at Thinking and Communicating. this does not go without saying, but you should have good skills here otherwise get out of marketing asap
4. knowledgeable: The MSc is very useful for more strategic approaches to business, which is useful believe me, even if you are not steering any strategy yourself, you have to interpret it and place actions within the mission statement for the company and your department. Once again on balance you are of higher value to the company than all and sundry sales-reps and marketing assistents sans education in the very art, especially if your first degree or work experience from before is relevant.
The last is only any good when coupled to no.3, with numbers one and two being deal closers.
Once in a job you can use the other job jumping techniques to get onto a better career ladder if need be. See my last post on recruitment consutlants.
The American way we often here is "who is recruiting? " : this is a good, direct way of thinking about grabbing opportunities: for these companies, and think company, growth and not job titile, your USPs ? ( unique selling poits)
1. Cheap: think 5 pounds per hour as ok! You can also be relocated cheaply. As going direct and avoiding recruitment consutlatns / bemanners you save them money, especially on a average graduate start package in the recession. Do not, repeat do not, turn down a good opp' on cash, or any opp in marketing right now. In graduate flat pay or "staff" jobs you will work many 12 hour days without moaning! That averages out to about 35% extra work free for marketing departments and suppliers of marketing services.
2. Available: you can start yesterday! As a graduate of 2010. Also you are most likely young/free/single-ish ( lie!) and therefore can relocate. When head count is to be secured by a manager facing "use it or lose it" budgeting, this can get you a job, or when a spotty non marketing graduate with two years photocopying in a boring marketing department has to give 1 months notice, you can be in there!
3: Skilled: at Thinking and Communicating. this does not go without saying, but you should have good skills here otherwise get out of marketing asap
4. knowledgeable: The MSc is very useful for more strategic approaches to business, which is useful believe me, even if you are not steering any strategy yourself, you have to interpret it and place actions within the mission statement for the company and your department. Once again on balance you are of higher value to the company than all and sundry sales-reps and marketing assistents sans education in the very art, especially if your first degree or work experience from before is relevant.
The last is only any good when coupled to no.3, with numbers one and two being deal closers.
Once in a job you can use the other job jumping techniques to get onto a better career ladder if need be. See my last post on recruitment consutlants.
Dealing With the Recruitment "Industry"
Job Seeking for Strathclyde MSc Marketing Graduates
::::: How to Deal with Recruitment Consultants:::::
At the moment if we take the majority of you with no relevance work experience, then recrutiment consultants will be the last people on earth to hold an umbrella over you in the current rain weather. They have very, very few graduaet jobs that are a good career start fro you. This is made worse because now they have on their books, lots of people made redundant from marketing and related jobs with only a year- or two's experience.
However, "Who is hiring" is a good Americanism to think a look at it. Recruitment consultants are sources for information on who is expanding, or who maybe has a "chicken run" .Through their overt advertising and in revelaing the companies with marketing jobs on the phone, they point the spotlight on a company which is maybe expanding or replacing staff. These advertised jobs may not be relevant to your experience or directly in marketing, but you should use recruitment houses to get the names of the companies and send direct applications or get in the door from other job interviews when actually using the consultant.
Now these "shopping window" interviews may not be for jobs in marketing; it may be admin, customer service or the evil of sales : phone or field. Give them a call, find out who and where their client is. Apply direct to the firm with an open application, or if you feel up to it, go through the consultant to get in the door, make a good impression and leave a much more detailed marketing CV with the client. Also consider making business cards, these can be useful when the consultant sits in, and I have had jobs offered to me after the first position with thrhough consulant is filled.
As advised in a previous FredRant, be careful when using "shopping window" interviews in sales or other functions. A sales manager will be furious to have yet another " work a year or two in sales and then into marketing" if they have just had a string of reps do that. Humour them, get to a head office interview and meet the personnel, maybe agreeing (only with personnel!) in forehand to have a look round the marketing department while you are there to consider the range of opportunities relevant to you. Get your detailed marketing CV and business card to personnel and anyone you meet.
Sales has been discussed before as a route in to marketing: it is a very double edged sword. However a field sales job in the recession is better than nothing and can be a good brand name on the CV. ( Often when I go to interviews, I note that the interviewers put far too much importance onto the larger brand names I have worked at or on: I often had more responsibility or relevant experiences on the smaller ones, but the big ones stick in the mind!!)
Sales jobs in marketing services companies, selling the firm, not working on behalf of clients, are also really worth applying to now: in any given city or industry you will get your feet in the door at countless good contacts and be able to see who has spend immediately: spend= head count as much as ad's and websites.
Other shitty jobs at interesting firms are to be avoided: telesales, call centre etc ...do you really want to do this? Well you may well want to get your face inside the company and get some interview expereince so go along with it, leaving a copy of your own, pepped up marketing CV with personal acheivements and positions of responsibility etc on there. Some other crappy jobs in good firms, or on behlaf of good brands ( consumer or B2B), may be worth getting in to as a first stepping stone. the brand name is worth a lot when you want to move up.
Also, as discussed before, because you are cheap, available tmw and have marketing know-how, you are in fact up for jobs which recruitment consutlants will not send you forward to : one to two years experience. SO work around them on all occaisions: they are a barometer and a way for managers to save time and manage wage expectations on the way in at the lower levels of the copannyu
Through all this though, do not PISS on your chips: keep some recrutiment consultants sweet: or just leave the good ones alone until you have that precsious work experience under way. Recruitment consultants tend to have good memories for people, but they remember a very short-hand version of you: so you need good personal branding and being a "Pushy student who had no real work experience and tried to present himself as a marketer in a sales job interview" will stick with you in their minds or in some euphenistic notes on their database.
Don't feel guilty about using smaller consultants/agents to get leads and "shopping window" interviews. Many of them will go bust soon, or never be able to offer you quality interviews later on in your career. On the other side it may be worth leaving registration at the marketing specialists until later: either when they have a graduate job or when you have more experience.
In both cases Consultants like "fresh shelf wares" - there is a true recency effect, despite their databases: a recent, active job seeker is easier for them to motivate to agree to go to interview than an experienced marketeer sitting in a good job.
Small agencies will use you sometimes in a string of interviews they know you are an outsider for. Large agencies do the same, but you will be relevant to a larger extent than the small, struggling-for-numbers agencies. In both cases they both tire of you or develop guilt complexes and leave you alone.Don't be naive, this is easy to spot: they are doing the hard sell on you and the last point will be the actual crappyness of the job or unlikeliness of you to get the position. It is possible to cut deals with them on this front: Ask them to promise to put your CV speculatively to three companies or get an interview with a better job which is advertised before agreeing to go to some also ran, salesy interviews as a presentable filler.
Much better to hit the MPMs of the world later, long after you have abused other small consultancies with good clients to get in the door and on the ladder of a markeitng career.
Friday, November 05, 2010
Team Work and Job Hunting in the Credit Crunch
Why bother with team work, especially in the dog-eat-dog credit crunch, sorry, recession....
What will team work achieve for you?
The first necessary ambience for team work to happen, and the very crux of why more-minds-are-better-than-one, is the flow of information. As always, knowledge is power.
So this means getting your heads together to share job tips: where a company is hiring, who has a chicken run, what is new and hot , new agencies, and all the paraphenalia: business forum meetings, the gazelle awards, recruitment visits to glasgow...and so on.
It may seem very alien to be doing this...job hunting appears a jealously gaurded occupation. Capital is to a large extent these days dependent on labour not organising itself. ( which means that more labour become capital by starting their own businesses) Being organised means that you will feel the benefits of letting go this selfishness after a short deal of pain. In any case, after June the class will disintegrate into individuality so even the most egocentric has everythign to gain by cooperation.
Now another thing which is key to team work is dividing the tasks up: all these events are not going to be covered by everyone, so a small platoon can go and get the "gen" on each of these.
The final thing about team, for the purpose of this rant, is that a team presents a united front: I have written before that you should get the best CV style you can, and push yourselves forward as strong, leader potential personalities....But this done collectively will make a bigger impact...a strathclyde uni proffessional CV may start to build the class brand, but will also make immediate recognition for qaulity,,,,first step to brandiling
'
To your own well being too, you will feel better and on a bigger learning curve by being with other people on solving the problem of getting the first post MSc job.
What will team work achieve for you?
The first necessary ambience for team work to happen, and the very crux of why more-minds-are-better-than-one, is the flow of information. As always, knowledge is power.
So this means getting your heads together to share job tips: where a company is hiring, who has a chicken run, what is new and hot , new agencies, and all the paraphenalia: business forum meetings, the gazelle awards, recruitment visits to glasgow...and so on.
It may seem very alien to be doing this...job hunting appears a jealously gaurded occupation. Capital is to a large extent these days dependent on labour not organising itself. ( which means that more labour become capital by starting their own businesses) Being organised means that you will feel the benefits of letting go this selfishness after a short deal of pain. In any case, after June the class will disintegrate into individuality so even the most egocentric has everythign to gain by cooperation.
Now another thing which is key to team work is dividing the tasks up: all these events are not going to be covered by everyone, so a small platoon can go and get the "gen" on each of these.
The final thing about team, for the purpose of this rant, is that a team presents a united front: I have written before that you should get the best CV style you can, and push yourselves forward as strong, leader potential personalities....But this done collectively will make a bigger impact...a strathclyde uni proffessional CV may start to build the class brand, but will also make immediate recognition for qaulity,,,,first step to brandiling
'
To your own well being too, you will feel better and on a bigger learning curve by being with other people on solving the problem of getting the first post MSc job.
Tuesday, October 26, 2010
Facing the FaceBook
I look forward to seeing the film, "the social network" and I suppose it will be something to get clicky on Facebook about.
Not that I am a social network addict: okay I am a forum and blog addict which puts me in a minor league, with most likley just crawlers reading most of my hits. FB I can kind of take or leave and right now I am going through FB fatigue, although that is not as from any huge overdosing on it-. just boredom. I actually delete people from FB and keep my friends numbers to under 50. There are still a couple of people I would like to connect to, God excluded, and some I should maybe connect to, but I am pretty determined to keep to under 50, at least as my private profile goes. Maybe DF will develope his own profile, alter ego as he is.
(links to founders) The founders were, or have become, somewhat shy types who started the whole concept as a beauty rating project: very peri pubescent of them too. However, they soon saw the social value of a simple "face" on the internet with connections round Harvard and later of course, were lucky to ride the storm and catch the money wave.
As I wrote in my last ranting blogg, I am more interested in the beast than we fleas upon its' back. Or rather how we fleas feeding on the blood of the social network, organised to join up.
The beast itself holds some fascination for me, in its quintessential simplicity. It looks like any live content portal I would have worked on in y2000-2001: Conservative, text and thumbnail based. Simple, clear, familiar, and stable. The simplicity lies in "getting it" quickly,what it does for your wild social betworking imagination proposes to you, more on that soon. But the latter two are pretty important: it is familiar, like the php/cgi/cfm pages I'm thinking about. It has levels of permissions, like the extranets I designed a decade ago. You have to join to get in, and you have to be a good little boy once in.
So it is a familliar and therefore safe environment, and unlike many other predecessors, has no half-hidden agenda of fleecing you to make further progress in your sociableness. The stability is vital to this feeling of security. FB evolves very slowly and is currently no doubt have an internal security review after the spate of FB virus, spy-ware and spam "apps" which have plagued us like chain letters did in the 1970s.
Well, well. FB fatigue: I am a little bored, perhaps I got my personal branding wrong and don't have a little band of the cleveries with good reparte. I just find it a bit static, and fully expect a merger and take over YT-FB! Video with video replies, limited tweet wise to 4 Mb or the like.
So there it is, a totally unstructred, short rant for the evening. But what will become of FB, what is the next move? WIll there arise a new beast from the east or something else capture our imagination? What FB could do, in the mind of DF, will be the topic of a forthcoming rant.
Not that I am a social network addict: okay I am a forum and blog addict which puts me in a minor league, with most likley just crawlers reading most of my hits. FB I can kind of take or leave and right now I am going through FB fatigue, although that is not as from any huge overdosing on it-. just boredom. I actually delete people from FB and keep my friends numbers to under 50. There are still a couple of people I would like to connect to, God excluded, and some I should maybe connect to, but I am pretty determined to keep to under 50, at least as my private profile goes. Maybe DF will develope his own profile, alter ego as he is.
(links to founders) The founders were, or have become, somewhat shy types who started the whole concept as a beauty rating project: very peri pubescent of them too. However, they soon saw the social value of a simple "face" on the internet with connections round Harvard and later of course, were lucky to ride the storm and catch the money wave.
As I wrote in my last ranting blogg, I am more interested in the beast than we fleas upon its' back. Or rather how we fleas feeding on the blood of the social network, organised to join up.
The beast itself holds some fascination for me, in its quintessential simplicity. It looks like any live content portal I would have worked on in y2000-2001: Conservative, text and thumbnail based. Simple, clear, familiar, and stable. The simplicity lies in "getting it" quickly,what it does for your wild social betworking imagination proposes to you, more on that soon. But the latter two are pretty important: it is familiar, like the php/cgi/cfm pages I'm thinking about. It has levels of permissions, like the extranets I designed a decade ago. You have to join to get in, and you have to be a good little boy once in.
So it is a familliar and therefore safe environment, and unlike many other predecessors, has no half-hidden agenda of fleecing you to make further progress in your sociableness. The stability is vital to this feeling of security. FB evolves very slowly and is currently no doubt have an internal security review after the spate of FB virus, spy-ware and spam "apps" which have plagued us like chain letters did in the 1970s.
Well, well. FB fatigue: I am a little bored, perhaps I got my personal branding wrong and don't have a little band of the cleveries with good reparte. I just find it a bit static, and fully expect a merger and take over YT-FB! Video with video replies, limited tweet wise to 4 Mb or the like.
So there it is, a totally unstructred, short rant for the evening. But what will become of FB, what is the next move? WIll there arise a new beast from the east or something else capture our imagination? What FB could do, in the mind of DF, will be the topic of a forthcoming rant.
How to Howcast ?
Whatcasting?
This is a new take on YouTube: or rather a new look opportunity for commentators on the internet and marketing to look back at the Mp4 Mpeg explosion on the internet.
So what is the core offering of howcast..com to the consumer?
Basically web film makers (who are they?) put up MP4s video clips of "How To" do erm, "stuff" as the Yanks would say. So far, recipies and conversely, diets have been on the play list ticker-tape at the top of the page. ( Sorry, a side scrolling preview panel!) . Different to Youtube? yep, it is only for how to do stuff videos, and the etiquette for the format of content is to do things stepwise, both in the mpeg. Nothing really new ?
Perspective from The Ancient Archives of the Web
When we first heard about Mp4 a decade ago, what was exciting to me was the embedded database information, which meant that videos could be searched by keyword, and other data. This meant you could search a database of films or perhaps fast forward to the part you wanted, maybe the "money shot" eh?
A decade ago all the elements were well and truly in place for YouTube and there were various prototype social networking sites, recognisable as the blogs and Facebook of today. You could say the internet by-in-large is a social network. It would be interesting to see how much www traffic is free-time related: this would need a measure of Mb, page hits and interactions.
Why was there then such a lag until Facebook and YouTube came to the market?
Well they weren't first on the market by any means. More the market coincided with the two entities. People were bored with spam from googling and the sporadic special interest sites, or pay-for-connection social networks like "friends re-united". People wanted something trustworthy, simple, connected to both their friends and special interests and there with scalable. Most of all they wanted it to be free! When I say free, not only void of fees, but with advertising and spam at a low leve, and relevant to their interests.
In other words, people were looking for brands to match their percieved need for a social network, and a place with enough searchabel video content that they could rely on finding something interesting for their gnat like attention spans ( generation X and i- are not alone in this though- the old greys also have a pretty short patience for something playing on a 15" screen with bad sound and bumpy streaming!)
Now they have the two biggies in terms of bandwidth, consumer involvement and rich content.
Why Did FB and YT become so Big so Quick?
FB and YT were in the right place at the right time, and could grow by their very nature of connectivity, snowballing out as people first e-mailed links and invitations to each other and later tweeted, sms-ed or sent direct invites from FB in particular.
Also of course the two sites had the branding and the runway was clear for easy hits on Google and Yahoo ( hey where is Alta Vista these days? My favourite 1995-1998!)
Also an important perspective was that FB and YT came with their own ready baked early adopters and lead influencers: given FB started in Harvard, there was one social echelon which were both the early adpoters on insett, and also lead influencers. As "the face book" was released it spread through business student networks and into the parents of the Harvard crowd, the siblings, the non Ivy league pals and so on. Wider than the initial, and it must be said, established small social networks which were now connected, just about every company in the world had a little group of early adopters: IT and Web people. Then of course the media "luvvies" got into it and celebrities wanted to start getting scores on the doors. Big hit clips on YT and "n>400" friends on FB.
Now the only thing the two needed was enough banne-ad'-click -through revenue to support the server banks and international load balancing across their incoming land lines.
Why are there not More FBs and YTs?
Well that is answered in a self fulfilling spiral from the last point on economics. When consumer sites go big on the internet, they are massive. The nuclear chain reaction is fuelled by the social connectivity and user definable choice of content and sub channels ( groups, brands, likes, playlists and so on, the sub channels or internal clusters). The obvious snowballing in herent in FB meant that the chain-reaction was optimised once, as in the atom bomb, the material reached a critical mass. In fact, once started I think it would have been impossible to stop FB because if anyone had t4ied in say 2008, then someone else would have bought them out. It was just too good a concept and channel to stop. Being able to see friends-of-friends and either complete your current social circle on the net, grow it outwards or locate old friends, aquaintances or which ever celebrity you want to try ensured explosive growth once x% of internet users 14 to 40 years old were on. It would be interesting to know what x was! How much ure-cranium it too
The second of the two factors makes the brands "super sticky" for us: we find that we not only have immediate content we like or social contacts we know, but we can control what we see and explore areas we are interested in. It is not the channel which controls our viewingl. The channels are suprisingly passive, and well, that should not be so suprising.
Other sites like the temporary shooting star, "friends re-united", had annoying features and some lead to outright spamming as they sold out their members e-mail addresses and on site experience to the highest space bidder: either on the point of , or in fact the very cause of their implosion. Like a newspaper, we flick through things and choose what we browse for longer time, we do not appreciate restrictions on access or forced-view advertising content.
All the ingredients for FB were there from the very birth of the www, or even in the newsgroups of the older IP world on the internet. Groups, as discussed in an earlier blogs, by in large were absorbed into Google and Yahoo and became very stale: the problem was they remained special interest and not a portal to a wider yet also personal connectivity.
Portals and Channels
Twelve years ago in 1998, channels and portals were the next big thing on the internet, which did not get big , yet. Web rings were just dying out ( a little button which lead you to a "Jump station" indexing the sites on the ring, or to the next site on the chain, or to a random site within the ring) . Now everythign has come full circle: we go in social and interest rings and web sites want to connect us togetehr with a button to FB. Previously we sent links by e.mail and ICQd , now we micro blog in tweets and FB posts. Previously we toroturously sent round mpegs in e-posts, now we post links to YT on FB.
A decade ago "portals" started to go wrong because they were structure heavy and networking poor. Indexing was usually poor or actually not useable, even with good Atomz or google internal searches. The portals were push media devised by media owners from an earlier education and IT people from the six-levels-of-structural layers. They were push and not consumer-pull. The corporate, academic and quango portals in particular, grew navel-gazing side alleys and meaningless "intra.extranets" .
Channels became buttons which we soon grew bored of, because they were, ah-hem corporate portals. Stodgey and impersonal.
Everything was there for FB and YT and Twitter, but the WILL of those with cash to invest was not in tune with our WILL on the internet: a free and ever expanding source of knowledge, entertainment and social contact driven by our own curiousity and human wishes.
This is a new take on YouTube: or rather a new look opportunity for commentators on the internet and marketing to look back at the Mp4 Mpeg explosion on the internet.
So what is the core offering of howcast..com to the consumer?
Basically web film makers (who are they?) put up MP4s video clips of "How To" do erm, "stuff" as the Yanks would say. So far, recipies and conversely, diets have been on the play list ticker-tape at the top of the page. ( Sorry, a side scrolling preview panel!) . Different to Youtube? yep, it is only for how to do stuff videos, and the etiquette for the format of content is to do things stepwise, both in the mpeg. Nothing really new ?
Perspective from The Ancient Archives of the Web
When we first heard about Mp4 a decade ago, what was exciting to me was the embedded database information, which meant that videos could be searched by keyword, and other data. This meant you could search a database of films or perhaps fast forward to the part you wanted, maybe the "money shot" eh?
A decade ago all the elements were well and truly in place for YouTube and there were various prototype social networking sites, recognisable as the blogs and Facebook of today. You could say the internet by-in-large is a social network. It would be interesting to see how much www traffic is free-time related: this would need a measure of Mb, page hits and interactions.
Why was there then such a lag until Facebook and YouTube came to the market?
Well they weren't first on the market by any means. More the market coincided with the two entities. People were bored with spam from googling and the sporadic special interest sites, or pay-for-connection social networks like "friends re-united". People wanted something trustworthy, simple, connected to both their friends and special interests and there with scalable. Most of all they wanted it to be free! When I say free, not only void of fees, but with advertising and spam at a low leve, and relevant to their interests.
In other words, people were looking for brands to match their percieved need for a social network, and a place with enough searchabel video content that they could rely on finding something interesting for their gnat like attention spans ( generation X and i- are not alone in this though- the old greys also have a pretty short patience for something playing on a 15" screen with bad sound and bumpy streaming!)
Now they have the two biggies in terms of bandwidth, consumer involvement and rich content.
Why Did FB and YT become so Big so Quick?
FB and YT were in the right place at the right time, and could grow by their very nature of connectivity, snowballing out as people first e-mailed links and invitations to each other and later tweeted, sms-ed or sent direct invites from FB in particular.
Also of course the two sites had the branding and the runway was clear for easy hits on Google and Yahoo ( hey where is Alta Vista these days? My favourite 1995-1998!)
Also an important perspective was that FB and YT came with their own ready baked early adopters and lead influencers: given FB started in Harvard, there was one social echelon which were both the early adpoters on insett, and also lead influencers. As "the face book" was released it spread through business student networks and into the parents of the Harvard crowd, the siblings, the non Ivy league pals and so on. Wider than the initial, and it must be said, established small social networks which were now connected, just about every company in the world had a little group of early adopters: IT and Web people. Then of course the media "luvvies" got into it and celebrities wanted to start getting scores on the doors. Big hit clips on YT and "n>400" friends on FB.
Now the only thing the two needed was enough banne-ad'-click -through revenue to support the server banks and international load balancing across their incoming land lines.
Why are there not More FBs and YTs?
Well that is answered in a self fulfilling spiral from the last point on economics. When consumer sites go big on the internet, they are massive. The nuclear chain reaction is fuelled by the social connectivity and user definable choice of content and sub channels ( groups, brands, likes, playlists and so on, the sub channels or internal clusters). The obvious snowballing in herent in FB meant that the chain-reaction was optimised once, as in the atom bomb, the material reached a critical mass. In fact, once started I think it would have been impossible to stop FB because if anyone had t4ied in say 2008, then someone else would have bought them out. It was just too good a concept and channel to stop. Being able to see friends-of-friends and either complete your current social circle on the net, grow it outwards or locate old friends, aquaintances or which ever celebrity you want to try ensured explosive growth once x% of internet users 14 to 40 years old were on. It would be interesting to know what x was! How much ure-cranium it too
The second of the two factors makes the brands "super sticky" for us: we find that we not only have immediate content we like or social contacts we know, but we can control what we see and explore areas we are interested in. It is not the channel which controls our viewingl. The channels are suprisingly passive, and well, that should not be so suprising.
Other sites like the temporary shooting star, "friends re-united", had annoying features and some lead to outright spamming as they sold out their members e-mail addresses and on site experience to the highest space bidder: either on the point of , or in fact the very cause of their implosion. Like a newspaper, we flick through things and choose what we browse for longer time, we do not appreciate restrictions on access or forced-view advertising content.
All the ingredients for FB were there from the very birth of the www, or even in the newsgroups of the older IP world on the internet. Groups, as discussed in an earlier blogs, by in large were absorbed into Google and Yahoo and became very stale: the problem was they remained special interest and not a portal to a wider yet also personal connectivity.
Portals and Channels
Twelve years ago in 1998, channels and portals were the next big thing on the internet, which did not get big , yet. Web rings were just dying out ( a little button which lead you to a "Jump station" indexing the sites on the ring, or to the next site on the chain, or to a random site within the ring) . Now everythign has come full circle: we go in social and interest rings and web sites want to connect us togetehr with a button to FB. Previously we sent links by e.mail and ICQd , now we micro blog in tweets and FB posts. Previously we toroturously sent round mpegs in e-posts, now we post links to YT on FB.
A decade ago "portals" started to go wrong because they were structure heavy and networking poor. Indexing was usually poor or actually not useable, even with good Atomz or google internal searches. The portals were push media devised by media owners from an earlier education and IT people from the six-levels-of-structural layers. They were push and not consumer-pull. The corporate, academic and quango portals in particular, grew navel-gazing side alleys and meaningless "intra.extranets" .
Channels became buttons which we soon grew bored of, because they were, ah-hem corporate portals. Stodgey and impersonal.
Everything was there for FB and YT and Twitter, but the WILL of those with cash to invest was not in tune with our WILL on the internet: a free and ever expanding source of knowledge, entertainment and social contact driven by our own curiousity and human wishes.
Thursday, September 09, 2010
Hard Work! Repeat ! Work Hard"
Now I note that it is time for a new intake of masters students to the 2011 MSc Marketing course.
Firstly congratulations on landing a place on a course which will give you a head start in your career in marketing or business otherwise, in providing you with knowledge, skills and not the least attitudes to suceed.
In terms of your career, marketing is not for the faint hearted. It requires a lot of percieverance just to get a career started, even to get interviews or work experience to get half way up to the first rung on the ladder. You have to be very tough or very lucky to get on and in my experience all too many Msc graduates have vaguely wandered into marketing because it sounds interesting, without knowing that it is very, very hard to get into once you finish.
The freddy blog seems to have been read a lot by previous graduates and I will stress again upon the new students, that marketing is a very, very, propostorously competitive profession to get into and then progress within. Please read back over my previous blogs on job hunting and how to get on: your job hunt preparation begins now and will start in earnest in October if you want to make the best possible head way against the larger brand companies.
Marketing is so extremely tough to get into because so many people want to work in it, not just qualified marketeers. Many of those general business graduates want in, many sales people want to move in(degree or no degree) and then you also have all and sundry BA, BSc, for example many psychology graduates, wanting a piece of the action. Then of course, there is the whole oxbridge bunch of medieval historians or theoretical economics who seem to be able to slide into plumb jobs. They have a head start because so many previous brand managers came from the UK's own "ivy league" and follow the "model for success" by recruting back from Oxbridge, Durham and so on.
You will need your luck, but the harder you try in your studies, job hunt and network building, the luckier you will get.. My career languised until one day I took a call and it was the golden opportunity to get a real start. I seized it, although it was pretty mediocre pay, and worked darn hard to learn the practical aspects of marketing on the shop floor of a "through the line" ad agency. After two years, the world so to speak was actually my oyster because the big agencies had stopped training new graduates and prefered experienced people from even much smaller agencies. I moved on to a decent wage and company car and later had the option to move "client side" for fewer working hours.
Read back through my advice and take it as highly opinionated, personal stuff, but remember it is based on the realities of job hunting and building a career. I have worked for 15 years with internet marketing for example, so new technology does not take over from the human hum-drum of pressing flesh and getting yourself a job these days.
Firstly congratulations on landing a place on a course which will give you a head start in your career in marketing or business otherwise, in providing you with knowledge, skills and not the least attitudes to suceed.
In terms of your career, marketing is not for the faint hearted. It requires a lot of percieverance just to get a career started, even to get interviews or work experience to get half way up to the first rung on the ladder. You have to be very tough or very lucky to get on and in my experience all too many Msc graduates have vaguely wandered into marketing because it sounds interesting, without knowing that it is very, very hard to get into once you finish.
The freddy blog seems to have been read a lot by previous graduates and I will stress again upon the new students, that marketing is a very, very, propostorously competitive profession to get into and then progress within. Please read back over my previous blogs on job hunting and how to get on: your job hunt preparation begins now and will start in earnest in October if you want to make the best possible head way against the larger brand companies.
Marketing is so extremely tough to get into because so many people want to work in it, not just qualified marketeers. Many of those general business graduates want in, many sales people want to move in(degree or no degree) and then you also have all and sundry BA, BSc, for example many psychology graduates, wanting a piece of the action. Then of course, there is the whole oxbridge bunch of medieval historians or theoretical economics who seem to be able to slide into plumb jobs. They have a head start because so many previous brand managers came from the UK's own "ivy league" and follow the "model for success" by recruting back from Oxbridge, Durham and so on.
You will need your luck, but the harder you try in your studies, job hunt and network building, the luckier you will get.. My career languised until one day I took a call and it was the golden opportunity to get a real start. I seized it, although it was pretty mediocre pay, and worked darn hard to learn the practical aspects of marketing on the shop floor of a "through the line" ad agency. After two years, the world so to speak was actually my oyster because the big agencies had stopped training new graduates and prefered experienced people from even much smaller agencies. I moved on to a decent wage and company car and later had the option to move "client side" for fewer working hours.
Read back through my advice and take it as highly opinionated, personal stuff, but remember it is based on the realities of job hunting and building a career. I have worked for 15 years with internet marketing for example, so new technology does not take over from the human hum-drum of pressing flesh and getting yourself a job these days.
Monday, July 26, 2010
Social Media Monitoring Goes Bust
A Brief History
To start with a brief history of social media: from cloudy beginings in nerd talk and security services personal info boards, social media came to the public internet in the late eighties and early nineties as the newsgroup: a simple text based repository for messages and early blogs, with circulation by e-mail subscription or internet boards.....and these were indeed monitored then, mainly by police in connection with the pædo rings and other unsavoury comms.
Newsgroups quickly went HTML on the World Wide Web and evolved into the forum, which is still the best repository for accessible, high value and trackable information on the web. This is where most consumer involvement with products and brands takes place. Although the micro blogging / glue services like Twitter are rapidly becoming a larger, faster resource they are still less useful for examining consumer attittudes over months of time or in detail.
Little Brother is Watching You
Now there are a host of agencies offering "social media monitoring" and these currently run the risk of creating a bubble soft and venture capital will feel the implosion of. Currently the most advanced indexing tools are not much better than stringing together several specialist hot shop functions, a core data depository and crawler and monitor and "deck" resourcest which are free on the internet. The larger agencies, like Meltwater are able to attract the larger brands while the major players of Trad' market research are still testing the water and holding off on acquisitions.
Why is Social Media Monitoring Going Bust?
The whole market for social media analytics, is in peril of undervaluing it's core pricing. Put simply, the barriers to entry are rather low given that comp'sci' students are often given crawler-indexer or deck meta data projects in undergrad years. Most of the new emerging agencies are student shops: comp sci and MBAers slung together to play at business. Problem being that they want to set experience before value and are cutting each others throats by going into brand names on "loss leaders".
Another key issue is the propagation of free services: "amsterdam hooker windows" as one software engineer called them in another area. The problem here is that you can begin to string together enough free services to make a picture of your brands' position in SM and then just go into the key forums and twitter yourself with your short-suffering marketing interns. The initial "Brand X status in CGM" is devalued as are tha later tracker reports: the key value for agencies is in presenting the statistics and sentiment mapping, but this is so relative and subject to the media surface changing itself that you really have to question the value of it for brands with less than 2000 hits per month in SM.
Scalability ....lack of it.
Although a few of the new starts may have strong crawler-indexer technology, one major problem is that the technology has to monitor a diverse range of sources out there on the internet, and those sources are not always too keen on being crawled. Programmer time is used in not just attaining sources, but retaining them. Also indexing for relevance and speed takes programmer time,and unfortunetly a new arena for a new brand may not be as fast or inclusive/exhaustive as the last indexing which had been optmised.
Put on top of this the awful costs of account management and new business development in acquiring and maintaining brand name clients and the issue of scalability just in this one area, is the one which will kill off most of the new starts.
Lumpy Custard
This economics of SM monitor agencies is actually nothing new: most small 1970s-80s advertising agencies failed because they tried to scale and could not make the leap from the core owner-manager team to an expanding, system driven agency.
Most of all in marketing services, it is horrible risky business with huge over reliance on a small number of customers ( clients in agency land) . "lumpy custard" as I used to describe it. In the 1980s the expression "lose a client, lose your job" was the mantra of account directors, while today it is more likely to be "lose a client, lose your VC funding".
To give some detail on this, when a new project is taken on then it inevitably comes with new sources or indexing demands. Also it comes with a new set of expectatons and because Market Research is still cinderella to the communications side of on line marketing, then new demands of the clients are usually out of line with charging the baseline 85€ per man hour to even break even in business services.
Winners and Losers
The largest, most comprehensive indexers will probably win over and then get the third level funding or even IPO / alternative exchange floatations. I'd expect these technology and brand become acquisition hungry and buy up the hot shops with key expertise in delivering more from fewer man hours. They in turn will want to either exit from VC or the stock exchange, by being eaten by the MB/TNC or Frosts of the world.
This would be the current exit model for the numerous university spawned start ups in SMM.
However, another huge issue they have is in defending their IPR: outside the US very litte will be patentable and a copyright can either be worked around or be somewhat irrelevant in a David-Goliath situation. So rounds of acquisition will come down to " can we get there cheaper ourselves? Do we head hunt out the key techies? What value do they really add ? How will they integrate technically and cutlurally to us?" for the potential bigger fish.
Acquisitions rounds will become window shopping with all the above questions firmly in mind once they get a look behind the scenes. Small companies would be wise to limit their exposure in terms of their "black box" code and indeed the identities of their staff.
These days you are open to headhunting through facebook and linked-in, so Social Media monitors may be eaten up by their own poison.
To start with a brief history of social media: from cloudy beginings in nerd talk and security services personal info boards, social media came to the public internet in the late eighties and early nineties as the newsgroup: a simple text based repository for messages and early blogs, with circulation by e-mail subscription or internet boards.....and these were indeed monitored then, mainly by police in connection with the pædo rings and other unsavoury comms.
Newsgroups quickly went HTML on the World Wide Web and evolved into the forum, which is still the best repository for accessible, high value and trackable information on the web. This is where most consumer involvement with products and brands takes place. Although the micro blogging / glue services like Twitter are rapidly becoming a larger, faster resource they are still less useful for examining consumer attittudes over months of time or in detail.
Little Brother is Watching You
Now there are a host of agencies offering "social media monitoring" and these currently run the risk of creating a bubble soft and venture capital will feel the implosion of. Currently the most advanced indexing tools are not much better than stringing together several specialist hot shop functions, a core data depository and crawler and monitor and "deck" resourcest which are free on the internet. The larger agencies, like Meltwater are able to attract the larger brands while the major players of Trad' market research are still testing the water and holding off on acquisitions.
Why is Social Media Monitoring Going Bust?
The whole market for social media analytics, is in peril of undervaluing it's core pricing. Put simply, the barriers to entry are rather low given that comp'sci' students are often given crawler-indexer or deck meta data projects in undergrad years. Most of the new emerging agencies are student shops: comp sci and MBAers slung together to play at business. Problem being that they want to set experience before value and are cutting each others throats by going into brand names on "loss leaders".
Another key issue is the propagation of free services: "amsterdam hooker windows" as one software engineer called them in another area. The problem here is that you can begin to string together enough free services to make a picture of your brands' position in SM and then just go into the key forums and twitter yourself with your short-suffering marketing interns. The initial "Brand X status in CGM" is devalued as are tha later tracker reports: the key value for agencies is in presenting the statistics and sentiment mapping, but this is so relative and subject to the media surface changing itself that you really have to question the value of it for brands with less than 2000 hits per month in SM.
Scalability ....lack of it.
Although a few of the new starts may have strong crawler-indexer technology, one major problem is that the technology has to monitor a diverse range of sources out there on the internet, and those sources are not always too keen on being crawled. Programmer time is used in not just attaining sources, but retaining them. Also indexing for relevance and speed takes programmer time,and unfortunetly a new arena for a new brand may not be as fast or inclusive/exhaustive as the last indexing which had been optmised.
Put on top of this the awful costs of account management and new business development in acquiring and maintaining brand name clients and the issue of scalability just in this one area, is the one which will kill off most of the new starts.
Lumpy Custard
This economics of SM monitor agencies is actually nothing new: most small 1970s-80s advertising agencies failed because they tried to scale and could not make the leap from the core owner-manager team to an expanding, system driven agency.
Most of all in marketing services, it is horrible risky business with huge over reliance on a small number of customers ( clients in agency land) . "lumpy custard" as I used to describe it. In the 1980s the expression "lose a client, lose your job" was the mantra of account directors, while today it is more likely to be "lose a client, lose your VC funding".
To give some detail on this, when a new project is taken on then it inevitably comes with new sources or indexing demands. Also it comes with a new set of expectatons and because Market Research is still cinderella to the communications side of on line marketing, then new demands of the clients are usually out of line with charging the baseline 85€ per man hour to even break even in business services.
Winners and Losers
The largest, most comprehensive indexers will probably win over and then get the third level funding or even IPO / alternative exchange floatations. I'd expect these technology and brand become acquisition hungry and buy up the hot shops with key expertise in delivering more from fewer man hours. They in turn will want to either exit from VC or the stock exchange, by being eaten by the MB/TNC or Frosts of the world.
This would be the current exit model for the numerous university spawned start ups in SMM.
However, another huge issue they have is in defending their IPR: outside the US very litte will be patentable and a copyright can either be worked around or be somewhat irrelevant in a David-Goliath situation. So rounds of acquisition will come down to " can we get there cheaper ourselves? Do we head hunt out the key techies? What value do they really add ? How will they integrate technically and cutlurally to us?" for the potential bigger fish.
Acquisitions rounds will become window shopping with all the above questions firmly in mind once they get a look behind the scenes. Small companies would be wise to limit their exposure in terms of their "black box" code and indeed the identities of their staff.
These days you are open to headhunting through facebook and linked-in, so Social Media monitors may be eaten up by their own poison.
Saturday, April 17, 2010
Interviewing your Prospective employer
Now I have to come back to two points about careers and making the right choices, because I am painfully remined of how bad things can go with a company in the "patient capital" late start up ( F-up) phase. They are running out of cash and I am bailing out, having noted that they have actually a pretty inefficient core "technology" from which it wil be hard to compete while making any decent gross margin.
1) You are interviewing the firm as much and more than they are you!
People forget this: we are nervous and want to match our best abilities against the job decscription AND offer some more, often superfluous info to them. We then get given a standard corporate blurb back at us an in the end of the day, none of us is all that much wiser about the possible exchange of values. We both know it will happen though, and given you are the least bad candidate you will get the offer.
Now, you actually have learnt rather little about the job and they have learnt just enough to know you will be able to function at the hands of the politics and flagrant lack of trianing you will get.
When I was a self respecting masters graduate, I considered a two week work trial ( as supported by the dole office, BA or whatever they are called now) as being a total sell out of my skills and abilities. Now I see it, even at first job level, as a really powerful means to gather info, understand the job and lay down some assertions about what you actually want to do.
In a two week period you will get the core tasks of an entry level graduate job and get to work ( or maybe only fleetingly) with your manager. Thus you will get a real insight into the job and if it is at Aardvark Galactica selling widgets to nobody's then you get the chance to say no.
A MUCH BETTER situation than I have now: the company's technology takes too much manual time to produce results and is therefore destined to be over run by faster, leaner competitors who are more customer quick-win oriented. I knew this within two weeks and that my bosses were aresholes but I perciveered because CGM monitoring is pretty trendy and I need a lift. So I coulkd have spent two weeks with them, as I suggested actually come to think of it, and turned round and said the job was far too junior and played to only weaknesses in attention to detail and motivations. Instead I am six months in, they are going belly up and I am stressed to hell.
So a two week trial is pretty good actually.
2) You need to get the RIGHT first job or know you need to move to the next RIGHT job asap!
I have been in the wrong jobs for all the right reasons, and had maybe two trials or . contracts both of which lead to jobs. The trouble for MSc-ers is that you have no real networking route or trail blazed into the big FMCG brands and you must languish in 2nd rate public service and SME marketing in Scotland if you will not move. In this market it is very, very easy to get a marketing job which turns into a nightmare of doing either sales donkey work or having all the monkeys in the department put on your back: ie all the shit no one else wants to do gets queued for your desk from day 1!
The MSc is a double edged sword because really it prepares you for MBA graduate jobs, while people do not respect it as much. So while being qualified to do strategy work you are actually too sharp for the jobs often on offer and cannot compete with "full MBAers" for those jobs you should aim for. I mean I worked with some prick recently who kept on refering to "fluffy" in the marketing department, AS the marketing department actually: market strategy being too important for the likes of marketers to touch !
A work trial of two weeks can allow you to swing in, get a grip on the company's failures and possibilities and then present yourself as a more strategic analyst and planner than the original "marketing exec' " role was specified as.
More often though, you will be able to see if the job is really just a sales admin type job or if it has very little of interest. You may be able to then play anouther card, often played actually, taking a part time position to cover only those functions you feel are relevant to your qualifications. This is really cunning because it buys you the RIGHT experience to shine in AND TIME to look for other jobs, start your own consultancy or take a convenient second job in.
1) You are interviewing the firm as much and more than they are you!
People forget this: we are nervous and want to match our best abilities against the job decscription AND offer some more, often superfluous info to them. We then get given a standard corporate blurb back at us an in the end of the day, none of us is all that much wiser about the possible exchange of values. We both know it will happen though, and given you are the least bad candidate you will get the offer.
Now, you actually have learnt rather little about the job and they have learnt just enough to know you will be able to function at the hands of the politics and flagrant lack of trianing you will get.
When I was a self respecting masters graduate, I considered a two week work trial ( as supported by the dole office, BA or whatever they are called now) as being a total sell out of my skills and abilities. Now I see it, even at first job level, as a really powerful means to gather info, understand the job and lay down some assertions about what you actually want to do.
In a two week period you will get the core tasks of an entry level graduate job and get to work ( or maybe only fleetingly) with your manager. Thus you will get a real insight into the job and if it is at Aardvark Galactica selling widgets to nobody's then you get the chance to say no.
A MUCH BETTER situation than I have now: the company's technology takes too much manual time to produce results and is therefore destined to be over run by faster, leaner competitors who are more customer quick-win oriented. I knew this within two weeks and that my bosses were aresholes but I perciveered because CGM monitoring is pretty trendy and I need a lift. So I coulkd have spent two weeks with them, as I suggested actually come to think of it, and turned round and said the job was far too junior and played to only weaknesses in attention to detail and motivations. Instead I am six months in, they are going belly up and I am stressed to hell.
So a two week trial is pretty good actually.
2) You need to get the RIGHT first job or know you need to move to the next RIGHT job asap!
I have been in the wrong jobs for all the right reasons, and had maybe two trials or . contracts both of which lead to jobs. The trouble for MSc-ers is that you have no real networking route or trail blazed into the big FMCG brands and you must languish in 2nd rate public service and SME marketing in Scotland if you will not move. In this market it is very, very easy to get a marketing job which turns into a nightmare of doing either sales donkey work or having all the monkeys in the department put on your back: ie all the shit no one else wants to do gets queued for your desk from day 1!
The MSc is a double edged sword because really it prepares you for MBA graduate jobs, while people do not respect it as much. So while being qualified to do strategy work you are actually too sharp for the jobs often on offer and cannot compete with "full MBAers" for those jobs you should aim for. I mean I worked with some prick recently who kept on refering to "fluffy" in the marketing department, AS the marketing department actually: market strategy being too important for the likes of marketers to touch !
A work trial of two weeks can allow you to swing in, get a grip on the company's failures and possibilities and then present yourself as a more strategic analyst and planner than the original "marketing exec' " role was specified as.
More often though, you will be able to see if the job is really just a sales admin type job or if it has very little of interest. You may be able to then play anouther card, often played actually, taking a part time position to cover only those functions you feel are relevant to your qualifications. This is really cunning because it buys you the RIGHT experience to shine in AND TIME to look for other jobs, start your own consultancy or take a convenient second job in.
Friday, March 19, 2010
DIY Consumer Generated Media Survey
DIY Market Research in Consumer Generated Media
At this instant, many universities around the world are spawning out small start ups and VC are raising eyebrows as angel captial invests in a new type of market research and intelligence firm.
The new enterprise opportunities are based on the sheer volume of CGM and the vogue for the big brands on the web in this area: Twitter, Facebook, Digg, and the latest brave new entry, google-buzz. Statistics, as I discussed below, are a little hard to use in reality and the cold world of market-movements and quantitative , conclusive, inferential and the numerically indicative is somewhat removed from CGM at the moment. What the meat-of-the-dinner is in fact, remains qualitative research with some utilisable methods for stat's which help describe the parameters and prominent qualities within voice-of-public or "Buzz" in social media.
Now from the arena I have seen, there is quite a smidgen of the "emperors new clothes" around in social media-monitoring. Take for example what is all dressed up and being used and no doubt abused: In areas like sentiment with some pretty flimsy algorythms out there, or little if any statistical significance to confirm the relative changes over time or differences between brands.
Also hit count statistics: for reasons of the prevalence and magnetism of the big sticky threads I discussed earlier, these can in fact populate a large amount of your hits in a topic, and if a topic has become google-rooted ( search engine ranks are high for that forum on the given free search in the topic area) then these get alot of noise about nothing other than one place to look. You see where I am going? If you want to open a kosha sandwich deli, then you will soon realise that most of the current world market is in new york.
It is actually pretty easy to follow the path " he who hath shall have a cup which over floweth, and he who hath not shall go without for ever" : the sticky sites and the sticky threads suck in a lot of the numbers and within this lies some of the really good qaulitative insight. You don't need large indexing or meta crawling tools to get the same qualitative result: but you do need sound judgement and the "corner pieces" of your social media space and range of consumer expression.
The opposite is also true: very small postings or postings which are very similar over a range of web forums and other social media, can point to a lead indicator or early problem alert after NPI. New users posting in a period after product launch are worth picking up: they are often the tip of the iceberg of customer dissatisfaction!
Until a few years ago, search engines did not want to index "live content" for various reasons best known to them selves! So any php , asp or cfm pages where ignored as perishable and not to be indexed. This had me stuck on a few forums we ran for clients a decade and more ag- Iit became a bit tedious because back then the big-thread magnet phenomenon, and ettiquette (discussed two blogs ago). However the corporate bosses were hanging on every word written down in awe and fear of libel suites or some tumultuous disclosure ( which did happen actually)
So your start point should be to follow the well trodden path like a wolf amongst the sheep who go google, and then like the idea of CGM forum rather than reading the corporatised blurb or sanitised PR bloggs. The doors to the crime scene are all open and there are hundreds of footprints.
So your tools are the search engines. Beware being all google centric: some may be more prominent nationally or within a specialist niche of global or national citizens ( academics always used Alta Vista and then moved over to FAST all the web for example). Now you add google buzz, google blogg search, twitter search, youtube, tweet deck etc and you start to have a powerful set of doorways to be able to set out and build a report like "attitudes the the bumble bee brand amongst international english speaking consumers in Social Media"
A few weeks ago, Google announced they would be indexing public content on FaceBook which will make both some opportunity , and a big stick to beat yourself with. As with analysing tweets, it can be a torturous route of reading conversations or following links to actually make sense of hit results.
It is a little difficult to get meaningful statistics in DIY SMMing but some clever use of search string arithmetic will help. More on this , making your google etc advanced or multiple searches efficient and exhuastive in a later blog.
You can meta-track launches, from rumour mill to unboxing and consumer adoption. You can track political issues, viral news story discussion...anything that affects several hundred thousand people in a western country, and you can bet it will be posted on, blogged, tweeted or have it's own fan or hate club on FB.
On some topics you will find a fairly concise set of mega-threads, a smattering of blogs and a pitter-patter of small threads and comments around the various social media nodes. Other topics you choose to research will be huge, sprawling and broad in both their appeal and the spectrum of opinion which is expressed.
Larger topics are usually worth sub categorising by sub topic, geography or forum-colour. Alternatively you can try to see the amenability of searches which find a type of segmentation based around a more qualitative factor: like consumer intention to purchase ; polars of sentiment ; brand or feature comparative posts and pages.
When you find page hits ( times 10 for post hits on average!) which run into the hundreds then it is worth using a very simple, well validated sampling methodology. First ensure that the page listings are exhaustive and you know the total number. Then take this and take it as every tenth page to counts of 100 or 500, and every 25th page for over 500 and so on. This will mean opening everything in "new tab". Most pages on forums will have 10 posts, but some may list the entire thread or hundreds. Then you can apply the same rule of thumb: every nth post: 5 for 100 would be a more quality result. The point of this discipline being that you sample from the whole distribution, (population of posts as species if you like) and you don't follow "interesting routes". In other words, you are forced to take a wide angled shot so you understand the landscape before you can decide which features are actually representative, prominent or meangingful in light of the whole spectrum.
From this approach you can do some surprisingly quick five-bar gate counts of keywords, brands or even sentiment. Many forums have sentiment ratings, and if you include comments and reviews on places like Amazon as CGM then you can start to do sample based sentiment ratings - which in fact can be pretty much as accurate as the latest AI driven ratings- if you have enough time.
All is not equal, as discussed in the sticky threads blog below. Some threads which are large or have topical subject lines, receive many more hits than others. Also some medias are more prominent and perhaps carry more status: like the BBC web forums and comments boxes. Forums with high SE rankings tend to have the most traffic. Retweet rate /total is another meta-metric .
From a knowlegde of prominent forums for a product type, brand, band, author, lifestyle or political view point you can then consider the sub set of consumers who are most interesting to follow up: the innovators, the early adopters, the opinion shapers, the self-appointed authorities, brand champions ( fan boys / fanboi's) ..brand terrorists....and follow their posting to gain a high level view of the discussion: see if indeed they are influencing people or if generally people make their own minds up and buy that pink coloured laptop anyway!
So you start to get a feel for how a report may be structured, using simple hit counts as a top level introduction and then results from your measurements within the samples. Finally you get into the qualitative observation with the prominence of the media and the activity of the opinion leaders, and the sentiment tallies from the different samples to give some kind of summative opinion poll for the topic. The conclusions you may draw should therefore be based upon prominent information, a knowledge of why it is prominent and what else lies in the spectrum, a handle on the polarity of sentiment expressed and the average point for consumers, be it neutral or not! When you make a conclusion which points to a useful management insight, then go back and check the prominence: check the hit coutns relative to other topics or shades or opinions etc, check your sample is exhaustive and re-check your search strings ( a little more on this latter below and then another blog , coming soon to a soggy-spot near you!)
There are plenty of kid on numbers you can put around these things. For computer scientist graduates, metacrawling or re-indexing can be a way forward to producing statistics based aroung the single post as the "Unit of selection". Different sampling strategies based on random and temporal dips can be useful when confronted with 50 million tweets per day!
For the very numerate amongst you as marketers, sociologists or computer scientists, you should be aware than CGM is in such large numbers that a topic such as a fairly common brand name or product, will have a "normal distribution" of opinion if you like, and this can be captured in a correspondingly 2 SD centric list of keywords: the first six search strings capture the first two or even three standard deviations .
There is a bell curve : x axis rating versus Y axis volume. The majority of opinion/keywords etc, will be within the first two standard deviations. When you do a nth sampling you really get to check that the bell curve is covered. If you do manage to plot data, sentiment or keywords, and you find that there are more peaks and troughs than one bell curve then you have either too small a sample size, a poorly defined opinion-keyword-etc scale, or in fact you are measuring two different things: either from two destinct populations with some degree of polarity to each other on your scale ( OOPS! you sample tory and labour forums ( republican / democrat) and not general political discussion!) .
When you know you have a nice bell curve then you can be very safe in using nth sampling or random statistical sampling and that your comparisons can be shown to be statistically significant: FOR THIS DESCRIPTIVE DATA SET. You cannot use this as inferential statistics, primarily because you cannot accurately capture social demographics in CGM and there fore you cannot make any extrapolations to the population as a whole.
If you combine an offline survey which identifies people's demographics in relation to their interaction with CGM, it can be possible to make some tentative inferences based on the knowledge that your large sampling base is composed of a cross section of society idenitfied in this CGM interaction survey . Even then you have to tread very carefully, statistically speaking, because your "Hits" are by a decided number of authors, some using several handles over forums, some using multiple identities to stimulate discussion on the same forums ! In other words your actual "n" for the study group is too small. Is the post more important than the author? Hmmm well people tend to be consistent and only change opinion after some degree of cognitive dissonance so really your "n" is authors and not posts.
Inference to the general population soon evapourates when as you get into small number of authors per posts, and some of my "sticky, syrupy threads" are very much dominated by a gang of less than 10 key proponents. But then again a knowledge of what cross section are reading those forums and the thread rankings on the SE's means you can start to make a judgemental call on the importance of an issue or the opinions around a topic.
Sociologists and psychologists are very taken up with not interfering with the subjects:not introducing experimental method source errors, researcher interference or interpreter bias. If it is purely observational, then just a simple permission disclaimer is all that interfere, or in focus groups, skilled moderators stimulate debate and keep it on topic while being allegedly carful not to introduce biases (observers are usually in other rooms and should not confer on their notes themselves! )
But in the area of CGM you can be a little more anarchic. Having identified and qualified your CGM sources as "prominent" then you can set out to interact a little by starting threads, or tweets, yourself. This is a purely qualitative approach, but it can help you gain insight in an area where you found many tangenital conversations, unclear opinion or forum leader-or fanboy -bullying ( shutting out opinions, topics , alternative products/ solutions etc) previously skewing the area you are researching. Tread a little carefully and pick those forums or social networks where you have established that "noobs" ( newbies...first time or low count posters) receive a positive welcome and a range of replies and are not shut out when they post sensible . This means you can pose a question within a subject which is tenable : this could indeed include concept building around latent demand and unmet needs.
I hope this has stimulated some ideas for just going out and doing some DIY research from your desktop. This approach deals not only with qualitative observations, but you may also pick up some qualitive ideas on what would work with a crawling-indexing system, or a new type of social media platform!
=================
Perspective
=================
To show how long in the tooth I am, and just how jaded I am by the industry, market research is a be-whoared cinderella within marketing. Of course it should be the lead violin, the first on the dancefloor but instead it is the working girl who turns up in her best frock only to have a hand put up her skirt! They want her knickers off, just to get as quick as they can to what makes them happy: to drop the analogy, product managers have often made their own minds up about what makes a good campaign and where they are going and only want market research which will support that or their plan B. They have sales and national account managers to keep happy and they need to steal a bit of limelight by doing something unique.
This is true of research in social media, and it there is a danger for observer bias in generating keywords and search strings, and the in choosing themes or summarising the spectrum of opinion. Conversely, any-road-will-take-you-there-if-you-dont-know-where-you-are-going, so it is easy to follow seemingly prominent themes and paths of arguement which take you down blind alleys. Avoid the critical path approach, and keep it broad and objective.
In a later blog I will discuss how you create an objective set of search strings which are both exhaustive enough while being efficient in "containing" a topic, and as mentioned making sure you are within the first couple of standard deviations for a given distribution with the majority of your efforts.
Subscribe to:
Posts (Atom)