<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments on: Collaborative word processing online with Writely</title>
	<link>http://www.makeyougohmm.com/20050917/2389/</link>
	<description>Technology, music, video, art, news, reviews and muse on the web</description>
	<pubDate>Wed, 07 Jan 2009 22:01:19 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2</generator>

	<item>
		<title>By: Make You Go Hmm: &#187; Google Writelys a check</title>
		<link>http://www.makeyougohmm.com/20050917/2389/#comment-56543</link>
		<author>Make You Go Hmm: &#187; Google Writelys a check</author>
		<pubDate>Fri, 10 Mar 2006 15:17:14 +0000</pubDate>
		<guid>http://www.makeyougohmm.com/20050917/2389/#comment-56543</guid>
		<description>[...] Writely an online wordprocessor with some collaboration features, which we reviewed back in September 2005 has become Google&#8217;s newest acquisition. [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] Writely an online wordprocessor with some collaboration features, which we reviewed back in September 2005 has become Google&#8217;s newest acquisition. [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sam</title>
		<link>http://www.makeyougohmm.com/20050917/2389/#comment-21045</link>
		<author>Sam</author>
		<pubDate>Sun, 18 Sep 2005 19:00:12 +0000</pubDate>
		<guid>http://www.makeyougohmm.com/20050917/2389/#comment-21045</guid>
		<description>Actually, re-reading this, I think I'm being a dope...we don't put the user name in the URL, that would be stupid. I must be tired. You mean, you don't want your user email in the RSS feed itself, right? Easier said than done.</description>
		<content:encoded><![CDATA[<p>Actually, re-reading this, I think I&#8217;m being a dope&#8230;we don&#8217;t put the user name in the URL, that would be stupid. I must be tired. You mean, you don&#8217;t want your user email in the RSS feed itself, right? Easier said than done.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sam</title>
		<link>http://www.makeyougohmm.com/20050917/2389/#comment-20995</link>
		<author>Sam</author>
		<pubDate>Sun, 18 Sep 2005 18:29:01 +0000</pubDate>
		<guid>http://www.makeyougohmm.com/20050917/2389/#comment-20995</guid>
		<description>Ah, that abuse hadn't occurred to me, that someone would get your email addr out of the RSS feed URL itself. You're right, that's lame, we should encrypt the user name. We do care a great deal about user security, of course. This was just me missing a spot. 

The reason it's there is so I can tell which user's feed to send back out...I didn't want to do authentication in the RSS request itself, becuase that seems incompletely supported by the RSS readers out there, and it makes it hard to validate the feed, etc. 

The deal with the beta being open and closed just has to do with scaling - we want to make sure the server scales smoothly, so every time we double in size, we pause for a bit to look at the load profile  and re-tune. I'd rather have a few folks impatiently waiting, than a lot of folks unhappy. 

I'll look at that JS issue, I hadn't seen it before. Ink would be cool, I agree, we just can't do it all at once.</description>
		<content:encoded><![CDATA[<p>Ah, that abuse hadn&#8217;t occurred to me, that someone would get your email addr out of the RSS feed URL itself. You&#8217;re right, that&#8217;s lame, we should encrypt the user name. We do care a great deal about user security, of course. This was just me missing a spot. </p>
<p>The reason it&#8217;s there is so I can tell which user&#8217;s feed to send back out&#8230;I didn&#8217;t want to do authentication in the RSS request itself, becuase that seems incompletely supported by the RSS readers out there, and it makes it hard to validate the feed, etc. </p>
<p>The deal with the beta being open and closed just has to do with scaling - we want to make sure the server scales smoothly, so every time we double in size, we pause for a bit to look at the load profile  and re-tune. I&#8217;d rather have a few folks impatiently waiting, than a lot of folks unhappy. </p>
<p>I&#8217;ll look at that JS issue, I hadn&#8217;t seen it before. Ink would be cool, I agree, we just can&#8217;t do it all at once.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: TDavid</title>
		<link>http://www.makeyougohmm.com/20050917/2389/#comment-20963</link>
		<author>TDavid</author>
		<pubDate>Sun, 18 Sep 2005 05:48:40 +0000</pubDate>
		<guid>http://www.makeyougohmm.com/20050917/2389/#comment-20963</guid>
		<description>Oh and it is IE version 6.0.2900.2180.xpsp_sp2_gdr.050301-1519, 128-bit

The JavaScript popup for the new document name appeared just fine it was only when I hit Ok that it would return that "javascript must be enabled" error message. You guys could capture the USER AGENT on that error message, BTW.</description>
		<content:encoded><![CDATA[<p>Oh and it is IE version 6.0.2900.2180.xpsp_sp2_gdr.050301-1519, 128-bit</p>
<p>The JavaScript popup for the new document name appeared just fine it was only when I hit Ok that it would return that &#8220;javascript must be enabled&#8221; error message. You guys could capture the USER AGENT on that error message, BTW.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: TDavid</title>
		<link>http://www.makeyougohmm.com/20050917/2389/#comment-20962</link>
		<author>TDavid</author>
		<pubDate>Sun, 18 Sep 2005 05:46:21 +0000</pubDate>
		<guid>http://www.makeyougohmm.com/20050917/2389/#comment-20962</guid>
		<description>Hi Sam - thanks for stopping by, reading and replying. 

User salting aside, I still don't care for my email address being in that feed, and since I'm the author of the document I already know my email address, so what's the point? Additionally, *I* should have control over what information goes there, not Writely. If your system gets hacked then that becomes a virtual spam haven waiting to be picked. It's putting user's information at risk and it's darn sure something I wouldn't pay for unless I could have much more control over what shows up in that RSS feed.

Hopefully you won't need that many users to tell you how important security is with the information they share across your service.

For that matter, I can use OneNote sessions to share documents securely across the web (with other OneNote users) and in ink! Ink support would be very cool for Writely, but it's probably a very small percentage of users that would like that ... but still!

Glad to see that you lifted the whole invite a friend deal though as far as beta invites go. 

Best of luck with Writely :)</description>
		<content:encoded><![CDATA[<p>Hi Sam - thanks for stopping by, reading and replying. </p>
<p>User salting aside, I still don&#8217;t care for my email address being in that feed, and since I&#8217;m the author of the document I already know my email address, so what&#8217;s the point? Additionally, *I* should have control over what information goes there, not Writely. If your system gets hacked then that becomes a virtual spam haven waiting to be picked. It&#8217;s putting user&#8217;s information at risk and it&#8217;s darn sure something I wouldn&#8217;t pay for unless I could have much more control over what shows up in that RSS feed.</p>
<p>Hopefully you won&#8217;t need that many users to tell you how important security is with the information they share across your service.</p>
<p>For that matter, I can use OneNote sessions to share documents securely across the web (with other OneNote users) and in ink! Ink support would be very cool for Writely, but it&#8217;s probably a very small percentage of users that would like that &#8230; but still!</p>
<p>Glad to see that you lifted the whole invite a friend deal though as far as beta invites go. </p>
<p>Best of luck with Writely <img src='http://www.makeyougohmm.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sam Schillace</title>
		<link>http://www.makeyougohmm.com/20050917/2389/#comment-20961</link>
		<author>Sam Schillace</author>
		<pubDate>Sun, 18 Sep 2005 05:30:35 +0000</pubDate>
		<guid>http://www.makeyougohmm.com/20050917/2389/#comment-20961</guid>
		<description>Hi, 

It's Sam from Writely. 

Thanks for the nice review, despite the issues you found! 

I haven't heard the IE/JS issue - if you could let me know the version and OS, that would help me track it down. 

As for the RSS feed, it's not quite as open as it seems - we put in a bit of "user salt" into the URL. This is a random number that we only show to you when you're logged in. So, it's not possible for someone to guess your feed url and see your documents. It's as safe as having the password in cleartext would be. The next step up from here would be something like WSSE, which we might do in the future if people ask for it.

Thanks for using Writely! 

Sam</description>
		<content:encoded><![CDATA[<p>Hi, </p>
<p>It&#8217;s Sam from Writely. </p>
<p>Thanks for the nice review, despite the issues you found! </p>
<p>I haven&#8217;t heard the IE/JS issue - if you could let me know the version and OS, that would help me track it down. </p>
<p>As for the RSS feed, it&#8217;s not quite as open as it seems - we put in a bit of &#8220;user salt&#8221; into the URL. This is a random number that we only show to you when you&#8217;re logged in. So, it&#8217;s not possible for someone to guess your feed url and see your documents. It&#8217;s as safe as having the password in cleartext would be. The next step up from here would be something like WSSE, which we might do in the future if people ask for it.</p>
<p>Thanks for using Writely! </p>
<p>Sam</p>
]]></content:encoded>
	</item>
</channel>
</rss>
