<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="http://feeds.feedburner.com/~d/styles/rss2full.xsl" type="text/xsl" media="screen"?><?xml-stylesheet href="http://feeds.feedburner.com/~d/styles/itemcontent.css" type="text/css" media="screen"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" version="2.0">
<channel>
	<title>Comments for Not So Relevant</title>
	
	<link>http://notsorelevant.com</link>
	<description>no expert in technology</description>
	<pubDate>Tue, 06 Jan 2009 00:36:45 +0000</pubDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
	<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" /><meta xmlns="http://pipes.yahoo.com" name="pipes" content="noprocess" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/commentsNotSoRelevant" type="application/rss+xml" /><item>
		<title>Comment on DiSo: WordPress as a Social Network? by The Painter</title>
		<link>http://notsorelevant.com/2007-12-18/diso-wordpress-as-a-social-network/comment-page-1/#comment-7591</link>
		<dc:creator>The Painter</dc:creator>
		<pubDate>Mon, 05 Jan 2009 02:41:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.notsorelevant.com/2007-12-18/diso-wordpress-as-a-social-network/#comment-7591</guid>
		<description>Actually with a good CMS and some good plugins / components you could turn "your blog" into your own social networking portal. The beauty of most of the great CMS programs out there, Joomla, Drupal, WP, etc is flexibility for exactly this type of usage. Trying to convince your friends to start using your social network and not facebook?... Thanks a whole nother story.</description>
		<content:encoded><![CDATA[<p>Actually with a good CMS and some good plugins / components you could turn &#8220;your blog&#8221; into your own social networking portal. The beauty of most of the great CMS programs out there, Joomla, Drupal, WP, etc is flexibility for exactly this type of usage. Trying to convince your friends to start using your social network and not facebook?&#8230; Thanks a whole nother story.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on OpenID: Successful in Japan by Perception and reality in the land of OpenID | FactoryCity</title>
		<link>http://notsorelevant.com/2009-01-04/openid-successful-in-japan/comment-page-1/#comment-7590</link>
		<dc:creator>Perception and reality in the land of OpenID | FactoryCity</dc:creator>
		<pubDate>Sun, 04 Jan 2009 23:11:53 +0000</pubDate>
		<guid isPermaLink="false">http://notsorelevant.com/?p=728#comment-7590</guid>
		<description>[...] findings (PDF) that Yahoo presented last year (on which so much criticism was heaped), few seem to [...]</description>
		<content:encoded><![CDATA[<p>[...] findings (PDF) that Yahoo presented last year (on which so much criticism was heaped), few seem to [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Your Passwords Are Sold. And Plaxo? by Carsten Pötter</title>
		<link>http://notsorelevant.com/2009-01-02/your-passwords-are-sold-and-plaxo/comment-page-1/#comment-7589</link>
		<dc:creator>Carsten Pötter</dc:creator>
		<pubDate>Sun, 04 Jan 2009 20:46:53 +0000</pubDate>
		<guid isPermaLink="false">http://notsorelevant.com/?p=715#comment-7589</guid>
		<description>Of course, trust is necessary in quite a lot of activities on the web. I have to trust my email provider, my OpenID provider, merchants,... The list is endless. Though I think it's different with Plaxo:

1. It knows better. That's really simple.
2. Plaxo has a bad reputation about spamming people's contacts. While this is a thing of the past, Plaxo still suffers from it and some people still make unfounded allegations. Scraping plays into the hands of those people.</description>
		<content:encoded><![CDATA[<p>Of course, trust is necessary in quite a lot of activities on the web. I have to trust my email provider, my OpenID provider, merchants,&#8230; The list is endless. Though I think it&#8217;s different with Plaxo:</p>
<p>1. It knows better. That&#8217;s really simple.<br />
2. Plaxo has a bad reputation about spamming people&#8217;s contacts. While this is a thing of the past, Plaxo still suffers from it and some people still make unfounded allegations. Scraping plays into the hands of those people.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Your Passwords Are Sold. And Plaxo? by Chris Messina</title>
		<link>http://notsorelevant.com/2009-01-02/your-passwords-are-sold-and-plaxo/comment-page-1/#comment-7588</link>
		<dc:creator>Chris Messina</dc:creator>
		<pubDate>Sun, 04 Jan 2009 20:13:55 +0000</pubDate>
		<guid isPermaLink="false">http://notsorelevant.com/?p=715#comment-7588</guid>
		<description>I'd like to give John the benefit of the doubt, not just because we're friends, but because I know how long and much work needs to go into getting large organizations to shift.

That said, I agree with Jeremy's point with two additional questions and one statement:

1. What's the delta between how things are today with your scraper and getting to a point where you can simply use PoCo? If you're waiting on the service providers to adopt the protocol (clearly it needs to get finished in the mean time!), how far away are we from seeing live support? Two months? Three? Six months? Perhaps providing a non-binding timeline, and the things it depends on, would help to assuage these claims of hypocrisy. At least you're doing something about it.

2. Why don't you at least offer optional support for the delegated authentication protocols provided by all of the major service providers in the meantime? At least the solutions exist today and would show a genuine commitment to making it possible for people to have control over how they provided access to their data.

3. While I'm an advocate against the password anti-pattern like the rest of you, I do think that giving up your account credentials to sites and companies you trust is not always a bad thing. It certainly isn't an ideal solution, and in fact makes for lazy developers, but if you trust a company, say, with your credit card number and secret code, that's hardly different than trusting a company with your email credentials. If people make an informed decision about trusting Plaxo and hand over the keys to their accounts, that's their decision. How they become informed, is another topic, though — and the greater point about teaching people bad security hygiene still stands.</description>
		<content:encoded><![CDATA[<p>I&#8217;d like to give John the benefit of the doubt, not just because we&#8217;re friends, but because I know how long and much work needs to go into getting large organizations to shift.</p>
<p>That said, I agree with Jeremy&#8217;s point with two additional questions and one statement:</p>
<p>1. What&#8217;s the delta between how things are today with your scraper and getting to a point where you can simply use PoCo? If you&#8217;re waiting on the service providers to adopt the protocol (clearly it needs to get finished in the mean time!), how far away are we from seeing live support? Two months? Three? Six months? Perhaps providing a non-binding timeline, and the things it depends on, would help to assuage these claims of hypocrisy. At least you&#8217;re doing something about it.</p>
<p>2. Why don&#8217;t you at least offer optional support for the delegated authentication protocols provided by all of the major service providers in the meantime? At least the solutions exist today and would show a genuine commitment to making it possible for people to have control over how they provided access to their data.</p>
<p>3. While I&#8217;m an advocate against the password anti-pattern like the rest of you, I do think that giving up your account credentials to sites and companies you trust is not always a bad thing. It certainly isn&#8217;t an ideal solution, and in fact makes for lazy developers, but if you trust a company, say, with your credit card number and secret code, that&#8217;s hardly different than trusting a company with your email credentials. If people make an informed decision about trusting Plaxo and hand over the keys to their accounts, that&#8217;s their decision. How they become informed, is another topic, though — and the greater point about teaching people bad security hygiene still stands.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Back by Matthias Gutjahr</title>
		<link>http://notsorelevant.com/2008-12-31/back/comment-page-1/#comment-7586</link>
		<dc:creator>Matthias Gutjahr</dc:creator>
		<pubDate>Sat, 03 Jan 2009 20:30:25 +0000</pubDate>
		<guid isPermaLink="false">http://notsorelevant.com/?p=697#comment-7586</guid>
		<description>Great to have you back. But I already told you this ;O)</description>
		<content:encoded><![CDATA[<p>Great to have you back. But I already told you this ;O)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Your Passwords Are Sold. And Plaxo? by Jeremy Keith</title>
		<link>http://notsorelevant.com/2009-01-02/your-passwords-are-sold-and-plaxo/comment-page-1/#comment-7585</link>
		<dc:creator>Jeremy Keith</dc:creator>
		<pubDate>Sat, 03 Jan 2009 19:21:32 +0000</pubDate>
		<guid isPermaLink="false">http://notsorelevant.com/?p=715#comment-7585</guid>
		<description>I deleted my Plaxo account a while back precisely because of this.

John, I'm sorry but it *is* hypocrisy. As it is now, you are scraping email addresses differently for each email provider—that is as much work (if not more) than implementing using the APIs now provided by each provider.

More importantly, the ethical issue here is that you are telling people it's perfectly okay to hand over their email passwords to anyone who asks. That may make "business sense" but "business sense" does not trump moral responsibility.

John, you and Joseph know better than this. It is precisely because you know better than this that I was so disgusted by Plaxo's continued support of the password anti-pattern. Hence, my account deletion.</description>
		<content:encoded><![CDATA[<p>I deleted my Plaxo account a while back precisely because of this.</p>
<p>John, I&#8217;m sorry but it *is* hypocrisy. As it is now, you are scraping email addresses differently for each email provider—that is as much work (if not more) than implementing using the APIs now provided by each provider.</p>
<p>More importantly, the ethical issue here is that you are telling people it&#8217;s perfectly okay to hand over their email passwords to anyone who asks. That may make &#8220;business sense&#8221; but &#8220;business sense&#8221; does not trump moral responsibility.</p>
<p>John, you and Joseph know better than this. It is precisely because you know better than this that I was so disgusted by Plaxo&#8217;s continued support of the password anti-pattern. Hence, my account deletion.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Back by Carsten Pötter</title>
		<link>http://notsorelevant.com/2008-12-31/back/comment-page-1/#comment-7584</link>
		<dc:creator>Carsten Pötter</dc:creator>
		<pubDate>Fri, 02 Jan 2009 20:41:17 +0000</pubDate>
		<guid isPermaLink="false">http://notsorelevant.com/?p=697#comment-7584</guid>
		<description>:D</description>
		<content:encoded><![CDATA[<p> <img src='http://notsorelevant.com/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Back by Panxatony</title>
		<link>http://notsorelevant.com/2008-12-31/back/comment-page-1/#comment-7583</link>
		<dc:creator>Panxatony</dc:creator>
		<pubDate>Fri, 02 Jan 2009 20:21:16 +0000</pubDate>
		<guid isPermaLink="false">http://notsorelevant.com/?p=697#comment-7583</guid>
		<description>Alles eine Frage von lausig programmierten Wordpress Plugins und php fcgi Fehlern. Dann geht das fix.

Bin ich froh wenn PHP irgendwann mal nicht mehr verwendet wird. :-)</description>
		<content:encoded><![CDATA[<p>Alles eine Frage von lausig programmierten Wordpress Plugins und php fcgi Fehlern. Dann geht das fix.</p>
<p>Bin ich froh wenn PHP irgendwann mal nicht mehr verwendet wird. <img src='http://notsorelevant.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Your Passwords Are Sold. And Plaxo? by Matthias Pfefferle</title>
		<link>http://notsorelevant.com/2009-01-02/your-passwords-are-sold-and-plaxo/comment-page-1/#comment-7582</link>
		<dc:creator>Matthias Pfefferle</dc:creator>
		<pubDate>Fri, 02 Jan 2009 16:41:30 +0000</pubDate>
		<guid isPermaLink="false">http://notsorelevant.com/?p=715#comment-7582</guid>
		<description>I agree, that implementing a whole bunch of APIs isn't the right way and definitively not a good solution for a business.

But why is screen-scraping the easier method? Because there are a bunch of classes around there ready to implement. And if a service like Plaxo is using such functionality it becomes "state of the art" for other sites and companies, because users are habituated to use them... so I think using other standardize ways to import contacts like XFN/hCard, Foaf or vCards is much better than using the "password antipattern". We have to educate our users first, because they have to use the things we build!

And that shouldn't be an attack to what plaxo is doing, because I love what you guys have done with "Portable Contacts", "The Social Web TV" and your dedication to many other "Open" solutions... but the "password antipattern" can't be an alternative!</description>
		<content:encoded><![CDATA[<p>I agree, that implementing a whole bunch of APIs isn&#8217;t the right way and definitively not a good solution for a business.</p>
<p>But why is screen-scraping the easier method? Because there are a bunch of classes around there ready to implement. And if a service like Plaxo is using such functionality it becomes &#8220;state of the art&#8221; for other sites and companies, because users are habituated to use them&#8230; so I think using other standardize ways to import contacts like XFN/hCard, Foaf or vCards is much better than using the &#8220;password antipattern&#8221;. We have to educate our users first, because they have to use the things we build!</p>
<p>And that shouldn&#8217;t be an attack to what plaxo is doing, because I love what you guys have done with &#8220;Portable Contacts&#8221;, &#8220;The Social Web TV&#8221; and your dedication to many other &#8220;Open&#8221; solutions&#8230; but the &#8220;password antipattern&#8221; can&#8217;t be an alternative!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Your Passwords Are Sold. And Plaxo? by Carsten Pötter</title>
		<link>http://notsorelevant.com/2009-01-02/your-passwords-are-sold-and-plaxo/comment-page-1/#comment-7581</link>
		<dc:creator>Carsten Pötter</dc:creator>
		<pubDate>Fri, 02 Jan 2009 16:11:16 +0000</pubDate>
		<guid isPermaLink="false">http://notsorelevant.com/?p=715#comment-7581</guid>
		<description>Thanks for your comment, John.

I am well aware of Joseph's demos of Portable Contacts working with Gmail. I have linked to your article about it. I am also not suggesting that web services like Plaxo should develop code for every single API out there. Like you have written above, that doesn't make (business) sense. OAuth and Portable Contacts are the way to go. There is no diagreement between you and me.

I admit that the title of the posting is provocative - but that's been the intention - and I understand that you take issue with being called "hypocritical", however just "a little bit". Though believe me, we're both supporting the same cause.</description>
		<content:encoded><![CDATA[<p>Thanks for your comment, John.</p>
<p>I am well aware of Joseph&#8217;s demos of Portable Contacts working with Gmail. I have linked to your article about it. I am also not suggesting that web services like Plaxo should develop code for every single API out there. Like you have written above, that doesn&#8217;t make (business) sense. OAuth and Portable Contacts are the way to go. There is no diagreement between you and me.</p>
<p>I admit that the title of the posting is provocative - but that&#8217;s been the intention - and I understand that you take issue with being called &#8220;hypocritical&#8221;, however just &#8220;a little bit&#8221;. Though believe me, we&#8217;re both supporting the same cause.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
