2
Padlocks

Livestream 300x221 Free Web Conferencing Service Comparisons

Chris Dunlap, ISA Boston Section Vice President, kicks off our October meeting on Livestream.

I hosted a Web 2.0 workshop at last month’s ISA Fall Leader Meetings that was an open discussion of social media and collaborative technologies. The overwhelming interest was clearly focused on using video conferencing for holding meetings and presenting information. Before, during and after that workshop I’ve promised at least a dozen people that I would put together a comparison of available services and some hints and tips for using them.

In this post, I’m going to compare four different free services for conducting online meetings and/or presentations; DimDimUstreamLivestream and Skype. None of them is a perfect solution and they all have trade-offs that need to be considered for their applicability to your specific needs.

The Big Picture

Meetings vs. Presentations

The first question to answer is whether the collaboration is primarily a meeting or a presentation. While all of these services support online chat, only two of them permit muli-party audio or video conferencing. For meetings that are primarily one-way, Livestream and Ustream will be the best option. If you require audio or video conferencing capability, you need to look at either DimDim or Skype.

Audience Size

This is another critical factor, and will frequently dictate whether or not one of these services will fit the bill. DimDim’s free service will limit the number of attendees to 10, while Livestream’s audience can reach 50 and Ustream is unlimited. Skype’s limitations depend on how you’re using it – it allows up to 9 video conference participants, 25 audio and 50 chat.

Cameras and Desktops

Each of these services (except for Ustream) supports simultaneous broadcasting of both a webcam and computer desktop in one form or another. In my opinion, Livestream does the best job at this by a wide margin while Skype’s is pretty poor. The quality of the webcam broadcasting is always limited by the bandwidth of your Internet connection, but they all offer decent to excellent quality as long as you have a high speed link. Skype’s video quality is hands-down the best, with Livestream and Ustream tied for a very close second.

Head to Head

Feature DimDim (free) Livestream Ustream Skype
Attendees 10 50 Unlimited see below
Cameras 1 1 1 9
Record meetings No Yes Yes No
Public meetings Yes Yes Yes No
Private meetings No No No Yes
Desktop sharing No Yes Yes Yes
Online chat Yes Yes Yes Yes (50)
Audio conferencing Yes No No Yes (25)
Change presenter No No No Yes

DimDim

DimDimWebmeetings 300x212 Free Web Conferencing Service ComparisonsDimDim has the most versatile of solution of these services, hands down. I’ve used it many times and have to admit that there have been significant reliability issues. I’ve never been able to conduct a meeting successfully with attendees from Australia – have no idea why not. Admittedly, I have only used DimDim once in that last nine months and it worked flawlessly so the service reliability may have improved recently. The bottom line is that when it works, it’s a great service! The downside is that their free option is limited to just 10 attendees.

Livestream

Livestream Studio 300x180 Free Web Conferencing Service ComparisonsLivestream is a really cool service and something I’ve been using more and more. The screen shot to the right is the online studio that lets you import video fromYoutube, Media RSS Feeds or simply upload a video file. The broadcasting tools are top shelf and the video quality is excellent. During broadcasts, you can easily switch between different camera/display modes which is very handy. The downside to Livestream is that they embed commercial advertisements into your broadcasts.

Ustream

Ustream 300x208 Free Web Conferencing Service ComparisonsI’ve only used Ustream a couple of times, so can’t speak from a tremendous amount of experience. One interesting difference is that Ustream offers pay-as-you-go pricing for $1 per viewe-hour via its Watershed product.

Skype

Skype Groups 300x171 Free Web Conferencing Service ComparisonsSkype is a very different option from the previous two but may be suitable in certain cases. The desktop sharing capabilities are not great; the quality is slightly poor. However, the audio and video quality are excellent. Unlike the previous three web-based solutions, attendees must download a desktop application in order to use Skype. If you are looking to video conference 9 or fewer or audio conference 25 or fewer then Skype may be a good solution.

Paid Alternatives

While this article was meant to cover some free options, it’s probably worth listing a few options that are available on a paid basis for comparison purposes.

Feature DimDim (Pro) GoToMeeting Webex
Monthly fee $25 $49 $49
Attendees 50 15 25
Cameras 4 0 6
Record meetings Yes Yes Yes
Public meetings Yes Yes Yes
Private meetings Yes Yes Yes
Desktop sharing Yes Yes Yes
Online chat Yes Yes Yes
Audio conferencing Yes Yes Yes
Change presenter Yes Yes Yes

A Word of Caution

1417422595 2415d348bf m Free Web Conferencing Service ComparisonsAnd that word is “firewall.” Many corporate firewalls block Skype and video streaming sites like Livestream and Ustream. It’s important to understand who your audience will be and take this into account.

Continue Reading

High Five for Week Ending 10-Jan

Published on January 10, 2010 by in High Five

4
High Five for Week Ending 10-Jan
HighFive 300x275 High Five for Week Ending 10 Jan

Weekly High Five lists the most interesting, compelling, and/or useful links of each week.

This week’s High Five is about all things Internet.  It includes some interesting uses, abuses and threats that are not only worthy of mention but long term monitoring.

#5: The Answer Factory: Demand Media and the Fast, Disposable, and Profitable as Hell Media Model

I don’t generally use this space just to list “cool stuff.”  However, in addition to having pizazz, it seems to me that this model has some serious potential to become a game-changer.

Link: Wired

#4: Optimize LinkedIn Profile for SEO

Mike Volpe from Hubspot provides some very simple yet important tips for optimizing your LinkedIn profile (it led me to immediately make a couple of quick tweaks).  I am constantly evangelizing how important your online presence is, and this short tutorial is great for maximizing its effectiveness.

#3: China Blocks Wired.com With ‘Great Firewall’ – Updated

The conclusion from this article is that China’s algorithms for censoring the Internet were messing around with Wired magazine’s availability, which seems to be intermittently available.  The interesting nuggets from this article are the notations that China tends to block any sites with RSS feeds and blogs.  Why RSS feeds?  Because they are a push mechanism instead of pull.  In other words, it’s easier to track people when they have to visit a site to read what’s on it.  I know none of this is particularly shocking, but it’s important to understand what governments can do to encumber the Internet.  And before you start feeling too comfortable in the U.S. or E.U., read on…

Link: Wired

#2: Court to FCC: You Don’t Have Power to Enforce Net Neutrality

Net neutrality is the principle that your ISP (Internet Service Provider) should not be able to deliberately throttle back bandwidth for particular sites or protocols or otherwise interfere with them.  This ruling is about Comcast’s efforts to hamper use of the file sharing site BitTorrent.  Since these “torrents” are frequently used to illegally share files, there may not be much sympathy.  However, consider that Comcast has also been accused of interfering with Vonage as well, who is a competitor to their voice over IP service.  The courts and government seem to be setting the stage for an Internet that is going to be patrolled, regulated, fettered, and not at all like the one we are used to right now.

Link: Wired

#1: Senator Demands IP Treaty Details

This is a follow from last week’s story about the possible efforts by U.S. and E.U. authorities to deputize ISPs (Internet Service Providers) to be the Copyright Gestapo.  This week, we see that a U.S. Senator is having to file a Freedom of Information Act request to see the details of this treaty.  That the government is trying to hide information is nothing new, but the fact that this Senator is from the same political party as the current administration makes you wonder what’s in this bill that they don’t want people to know.

Link: Wired

Feel free to provide your thoughts and/or contributions…

Continue Reading

The Fatal Flaw In IT Security

Published on December 10, 2009 by in Best Practices, Rants

2
Locks

“There is no such thing as 100% inspection.”

iStock 000005288325Small 300x219 The Fatal Flaw In IT SecurityAccording to Dr. Jim Stewart of Northern Illinois University in DeKalb, IL “While working on my dissertation, I was reviewing some trade magazines from the 50′s. There were a number of case studies showing 50-75% efficiency and a breakage rate (visual inspections of wire wraps with pics) of 10-15%. Giving an effectiveness of 40-65%.”

The problem is, many IT departments do not understand this concept and are deluding themselves into a false sense of security that they are in control.

Zero Defects

When you are manufacturing widgets, your goal is for zero defects. From the start of the industrial revolution until relatively recently, it was a firmly held belief that you could hire inspectors to look at every single part coming off of the final assembly line and determine whether or not it sufficiently conformed to the requirements; whatever those may be. This was a great plan except for one minor detail; it doesn’t work very well. As it turns out, there are not enough hours in the day, not enough test equipment available, and not enough technical skill to inspect every single widget and catch every single defective part. Some will always slip through. Many companies may have discovered this fact, but typically adopted the “close enough” strategy.

As it turns out, over time manufacturers discovered much more reliable methods for producing widgets of superior quality. They understood that the best way to avoid shipping defective widgets was to prevent defects from happening in the first place, not simply scrapping the defective part when it was found at final inspection. How did they do this? There were two main components of the strategy.

Sampling

It can be mathematically demonstrated that taking a “statistically relevant” sampling of parts from an assembly line and measuring critical control parameters to ensure that the process is “in control” can result in far better overall quality than 100% inspection. It also has two additional benefits. First, because you are only inspecting a sampling of the overall production stream, it requires fewer resources and costs less. Second, this step can be performed at each step in the production process, which can catch problems earlier on and reduce scrap losses.

The challenges here are in a) determining statistical relevance and b) identifying critical control parameters. The equivalents in the world of IT security are not necessarily apparent but, the principals are still relevant in some areas such as intrusion detection and Internet usage.

Training

The factor that makes the most significant difference and is also the most directly applicable to IT security is training. In most Japanese manufacturing facilities, assemblers are responsible for the maintenance of the machines they use. There are two reasons for this. The first is to establish a sense of ownership of the process. Operators who are responsible for repairing their own machines will generally treat them with greater care and respect. The second reason is to give the operator a much deeper understanding of the process and an innate ability to sense when something is not quite right. This approach obviously involves a significant amount of training. However, in the long run it saves money by significantly reducing defects and producing more efficient workers.

The equivalent in the IT world is to train and empower users to be the mechanics for their own production tools; their computers. This does not mean turning them all into PC technicians. It does, however, mean training them in its proper use and preventative maintenance and making them responsible for ensuring that their tool is in good working order. By giving them a sense of ownership, you incent them to treat the machine (computer) with more care and respect. By training them in its proper use and maintenance, you empower them to use the computer as a tool and become true innovators, not simply trained chimps tapping the same series of keys in their cages.
When you treat people like adults and professionals, you are bound to be disappointed from time to time. However, it has been my experience that the numbers of humans who will exceed expectations far outweigh those who fall short. Far too many IT departments view it as no coincidence that “user” is a four letter word. That’s unfortunate because when you stop viewing users as an inconvenience and start viewing them as an asset, wonderful things can happen.

Conclusion

1417422595 2415d348bf m The Fatal Flaw In IT Security

The answer isn't more locks - it's smarter security guards.

There is no such thing as 100% inspection, just like there is no such thing as an impenetrable firewall, an unhackable password policy, an infallible virus protection program, or a memory stick that can’t be lost. Each and every IT security tactic comes at a price in terms of both cash outlay and diminished efficiency.  Furthermore, the most common tactic employed by deliberate hackers is social engineering.  There are still no hardware or software solutions to that vulnerability

Incidentally, I have never seen an IT department measure, much less justify, the cost and impact of many security measures in reduced worker productivity. But much more dangerous than that, too many companies have sold themselves on the lie that 100% inspection is “good enough.”

Continue Reading

0

This afternoon I presented “Introduction to Cybersecurity” to members of the New England Water Works Association in New Haven, CT.  The presentation focuses a recurring theme of this blog; no/low cost options for improving security.  This particular presentation focuses on the particular challenges faced with securing SCADA (Supervisory Control And Data Acquisition) systems.

During the presenation, I stressed the point that humans are the weakest link.  I wish it had occured to me to embed the following video of Kevin Mitnick demonstrating social engineering techniques:

Remember, people are the weakest link.

Continue Reading

1
MrOblivious
officetheif Top 5 No Cost Cyber Security Practices Is cyber security a technology problem or a people problem?

Cyber security is complex, highly technical subject that is best left to the Asperger-nerd in the computer room battling against the pimply-faced hacker sucking down Mountain Dew in his mother’s basement, right?  It’s a cat and mouse game that pits the white hats against the black hats, the antivirus computer scientists against the hackers, right?  It’s certainly not the realm of the average small business owner, right?  Wrong, wrong, and wrong!

What if I told you that human error was more responsible for data breaches in 2008 than hacking?  What if I told you that hacking was third on the Identity Theft Resource Center’s (ITRC) categorized list of data loss methods?  The reality is that cyber security is a people problem first and a technology problem second.

More Awareness, Less Reliance

mroblivious 150x150 Top 5 No Cost Cyber Security Practices

Most organizations are oblivious to the weakest link in the security chain

I’ve come to a remarkable, if not depressing realization in my information technology career.  Over the last 20 years of consulting, I’ve visited scores of clients in hundreds of facilities and I can easily count the number of times I was ever given any sort of cyber security orientation – exactly once.  I’ve walked into propped-open back doors of more manufacturing facilities than you can shake a stick at, and more often than not waltzed right up to a machine control panel, hooked up my laptop, and started pounding away at the keyboard while smiling and waving at trusting operators I had never before met in my life.  The realization is this; the vast majority of companies, large and small alike, is completely oblivious to the weakest link in the security chain; people.

The misperception that cyber security is all about technology is a serious mistake that is made by both small and large businesses.  The small businesses often believe that they are not sophisticated enough to employ their own cyber security programs and, therefore, either ignore it altogether or simply outsource it to an IT subcontractor.  The large businesses spend millions of dollars on intrusion prevention systems, biometric security, and other sophisticated technological countermeasures.

Hopefully by now I’ve made the point that cyber security is about much more than firewalls, Trojans, and keyboard loggers.  So without further delay, here is a list of five no-cost practices every organization can implement that will go a long way toward securing their data.

Use Passwords, Use Them Well

OK, show of hands… how many of you are rolling your eyes?  It sounds obvious, but password laziness and ignorance is still the number one vulnerability for computer systems.  I understand how painful it is these days to maintain all of the user names and passwords in our lives these days.  However, it is the world we live in and we must accept it and follow these bare minimum password practices:

  • No shared passwords:  This is especially common in process automation where there are many users of the same machine.  Everyone must have their own unique user name and password.
  • Complex passwords:  Use combinations of letters and numbers, preferably composed of one or more words that are not in the dictionary.  Why?  Read this article about Dictionary Attacks.
  • Change passwords:  This is probably the most annoying of these three practices, and I confess that it aggravates me to have to do.  However, changing passwords periodically is one of the best ways to prevent misuse of a password that is unknowingly (or even deliberately) disclosed.

Utilize Automatic Updates

Unpatched operating systems and out of date virus definitions are like the gimpy prey of a flock; they are the first to be targeted by the hunter.  Many computer viruses and other exploits rely on software vulnerabilities that are typically patched within days or weeks.  However, it is not at all unusual for me to see network servers out of date by more than a year.  Another common problem is for antivirus subscriptions to expire, preventing the virus definitions from updating.

Clean House

Every program loaded on a computer is a potential vulnerability.  The fewer of them there are, the better.  A typical Windows PC has loads of “crap-ware” installed on them that can and should be removed using the Add/Remove Programs option in Control Panel.  Additionally, there are Windows Components (e.g. Messenger, Media Player) that should be removed if not used.  Finally, there are usually Windows Services running by default that are not used.  This particular cleanup is generally left to computer professionals, as it is not always obvious which of these is required and disabling the wrong service can lead to “unexpected behavior.”

Create Policies

There are many reasons for establishing written computer and internet policies for employees.  One, of course, is legal liability for the employer.  The other is (or at least should be) educational.  It’s not enough to write up these policies; they need to be presented and explained in an open environment to ensure that they are understood and appreciated.  These policies go far beyond telling users they can’t surf porn on the company’s computers.  They need to include things like proper care and usage of portable storage devices, remote access procedures and policies, e-mail policies, etc…  You can find a list of templates at the SANS Security Policy Project web site.

Protect Sensitive Information

Insiders and subcontractors are another major vulnerability and care must be taken to provide information necessary for them to do their jobs, but no more.  This is especially true of subcontractors, of which I am one, who are frequently given and/or create sensitive documents, diagrams, lists, and other data.  It is important to establish guidelines for its use to ensure that the information is handled with care and returned or disposed of when the job is complete.  As incredible as it sounds, a subcontractor published a complete schematic of Pearl Harbor Naval Base’s power monitoring control system in a white paper available publically on the Internet (I just checked and the information has apparently been removed).

The Bonus Round

What is the hacker’s #1 tool of the trade?  I’ll give you a hint; it has nothing to do with computers.  It’s called Social Engineering and you can read more of it in my blog, “The Hacker as a Magician.”

Feel free to share your own anecdotes and pearls of wisdom on the subject.  What are some of the head-shaking moments you’ve witnessed?  Are there any “doh!” moments you care to share?

Credits and citations:

Continue Reading