Tuesday, September 14, 2010

Dimmable 120 volt LEDs for the house?

In the past there have been multiple articles on Technoracle about energy efficiency and ideas for greener, lower footprint living.  Recently we came across a number of really cool LED products that advertise they are ready to replace conventional bulbs and save consumers money while using far less energy.  We're going to test a number of them over the next year and report back.

The first item is a 120 volt, 2 watt LED Dimmable G16.5 Decorative Globe.   This is a product from TCP, which is advertised as a medium base that throws off Halogen white color.  We have ordered two of these (Cost is $17-18 each) to test to see if they do pay for themselves, which we suspect they will.


The second is a comparable product, which is also dimmable. It has slightly more power (rated at 3 watts) and is the dimmable G16.5 Decorative Globe with Candelabra Base.  This product also advertises Halogen  white light.  Our hope is that both of these are able to do the job of regular light bulbs while saving money and throwing off a light that is indistinguishable from conventional bulbs.  



Both of these are advertised as comparable to a 15 watt conventional bulb.  These should therefore be effectively reducing electrical bills by 80% and lasting much longer.  Given conventional incandescent bulbs last around 2 years and cost $1, these should have an ROI of around 4 years based on 1500 hours per year at 8c/kwh.

Technoracle will also begin testing some LED Ceiling Lights to replace conventional Halogen designs. 1000bulbs.com has these on sale for 50% below retail price today so we will order a few and report back.

Monday, September 13, 2010

Weekly LiveCycle@MAX Highlighted Session!

Every week leading up to Adobe MAX 2010 we will feature a special Adobe LiveCycle ES related session on Technoracle.  This week's session is very special and unique in two facets.  First, it is the very first time a LiveCycle ES 2.5 lab has been offered to members of the general public.  This in itself is reason enough to attend this session as it gives developers a head start over the rest of the pack in terms of getting familiar with the next generation of LiveCycle.  Second, this is a complete A-Z hands on lab covering a ton of material over 1.5 full days.  This makes it the longest session we have ever offered at a MAX event.

This session is already nearing sell out capacity so if you are going, please register as soon as you can.

Developing a LiveCycle ES2.5 Application
This program for enterprise developers combines 1.5 days of introductory preconference training on LiveCycle ES2.5 (Enterprise Suite) with a full conference pass to MAX 2010.  The preconference lab, "Developing a LiveCycle ES2.5 Application," is an essential introduction to developing user-centric applications with Adobe LiveCycle ES2.5. LiveCycle ES2.5 allows both business and IT professionals to visually assemble end-to-end processes, which when combined with rich interfaces, create engaging applications that unify systems and people quickly and flexibly. We'll present an end-to-end use case bringing a rich Internet application (RIA) and a LiveCycle application together. You will learn about the LiveCycle IDE, the Admin User Interface, and the LiveCycle ES2.5 solution components as we guide the participants through the development of this comprehensive use case.

We strongly recommend this training to those new to LiveCycle ES2.5, or those who would like a refresher, in order to get the most value out of the more advanced LiveCycle topics that will be presented during the MAX event.

Tracks:    Develop
Audience:    Web Developer, Application Developer
Skill Level:    Beginner
Product:    LiveCycle ES
Speakers:    Chantal Richard, Valerie Snider-Lynch
Times:   
Saturday, October, 23rd, 1:00 pm - 5:00 pm
Sunday, October, 24th, 9:00 am - 5:00 pm

Here is a video from Chantal Richard highlighting some more reason why this session is a "must attend" event.

Thursday, September 09, 2010

Why Cyber Crimes are Thriving in Canada and Profitable

It is no secret.  Cyber crimes are growing in most countries.  In 2009, cyber crime in America grew 22%.  According to the US Treasury Department, Cyber Crime Has Surpassed Illegal Drug Trafficking as a criminal money-maker.   The trend in Canada is unknown but I would bet it follows the same growth pattern.  Statistics Canada, where my tax dollars go to fund this type of research, seems incapable of making any report on cyber crime since 2002 available.  While not publicly available, I saw a report yesterday during an ITAC call that showed reported incidents increased to over 200,000 incidents per month!  That is reported.  Now imagine the ones that are unreported.

I suspect the crime incident numbers are much higher due to our total lack of infrastructure to deal with cyber crimes.  While this seems like a brash statement to make, I make it from practical experience.  Earlier this year I found myself as the intended victim of a cyber crime.  I quickly realized what was happening and collected all the evidence that any prosecutor would require to punish the scammers.  I had a phone number I could call them at, an internet address, IP address, saved emails and recorded telephone conversations.  I tried to report it.  Guess what???  Not one single agency in Canada was willing to take any action against the criminals.  Vancouver City Police said not their concern, call the RCMP. RCMP Fraud department and various other departments reacted with a belief that PhoneBusters was properly equipped to handle this.  Upon contacting PhoneBusters, I quickly realized they only take reports.  Again, not one single agency would lift a finger to go after the criminals.

But hey - don't take my word for it.  Consider this:

Scenario: Imagine you just found out that your IT systems are being scanned and attacked right now and you have information about exactly  who and where the attack initiates from.  You find out that it is a criminal group who is responsible for other crimes and they are not relenting.   What do you do?

Exercise:  Try to find any authority in Canada (Police, CSIS, phone busters, etc.) who will actively take the case and go after the attacker (prosecute, arrest, stop, etc.).  Call the local police, RCMP, etc. on the phone, explain the scenario above and ask them to get involved and do something.

Reality:  You will not find one single organization that is willing to do anything.  They all refer you to someone else who at most will take a report and do nothing.

This is very sad and is why the crimes are growing.  What we need is a rapid response team who will actually be available to do something.  Otherwise, Canadians and Canadian companies are going to only be victims while the bad guys make $ millions.

In the meantime, criminals have a free run on Canadians and can basically do what they want for fun and profit.

Find merchant accounts at Meoneris.com

Wednesday, September 08, 2010

Flash on mobile, the facts.

Yesterday morning I got an email from fellow Adobean Danny Winokur in my inbox discussing the state of the union with respect to Flash on the mobile. The synopsis of the conversation went something like this.

Flash Player 10.1 is now beginning to ship in volume on many smartphones.    Many of you may have seen the attached full page Motorola ad which ran on Friday in the NY Times, the Wall Street Journal and USA Today.  There are other similar ads being planned by major carriers and handset manufacturers.  This is the culmination of years of co-development to migrate Flash (not just Flash light) to the mobile.  Some have criticized Adobe for not doing this earlier but the reality is that the technology just wasn't ready earlier (hardware, software and infrastructure).

As the masses are starting to understand that video performance challenges on mobile devices, the truth has started to emerge that many of these issues are not isolated for Flash.  Many of the technical issues are a function of the hardware capabilities and the drivers which expose them.  Just for one example, if you take the same video with the same encoding and use any other player technology, and it is likely to perform about the same or worse than when played using Flash (the abc.com problem stems from code on their site which tries to use the hardware decoder for two snips concurrently, while the hardware only allows one - a constraint shared by any player on this hardware).

Flash video performance, along with other video experiences on mobile, should substantially improve.  We are all in still in the genesis days of mobile and the truth is that a consistent experience over multiple screens and devices is a lot of work.  As Adobe rolls out improvements such as StageVideo in future releases, allowing video to be sent directly to the screen (instead of being returned to the Flash Player) after being decoded in hardware, these experiences will get better and better.  This point, among others, is made articulately here:
http://www.streaminglearningcenter.com/articles/the-five-key-myths-about -html5.html?page=1. 

As others have right noted, the way to get great performing video on mobile devices is for content publishers to encode in ways that are supported by mobile *hardware*.

I don't expect the naysayers to be quiet any time soon.  Several of my brethren on Slashdot have already complained bitterly about the intrusion of Flash onto their devices.  The reality is that it is the users choice.  Adobe, as I understand it, has never been concerned about forcing things on users.  In fact, quite the opposite is true.  The exec's I talk to seem quite concerned about people having the choice.  If they don't want Flash, they can turn it off.  I myself turn of a lot of features on my Nexus 1 Android device when I am not requiring them to save battery life.  When I want my GPS data, I turn it on.  Flash is no different (although it has been architected and engineered not to squander device resources when not in use).   Long live choice!

I am stoked about the future of mobile. It took me a while to get there but now that we are rolling it out, many of the enterprises I am working with are bombarding me with new ideas for extendingh their infrastructure to mobile.  Some of these are simply items like extending a Livecycle ES business process to a Droid device or as complex as dynamic routing changes in task assignment due to geo-location.  Very cool.

Tuesday, September 07, 2010

LiveCycle@MAX pick of the week!

This week, I have selected what could be one of the single best sessions at MAX 2010.  Not only is this session extremely relevant to a lot of enterprises as they migrate some enterprise functionality to mobile, it is also taught by my long time friend and business partner Matt MacKenzie along with Stacy Young.  For those of you who do not know Matt, he is an extremely talented architect and probably the smartest developer I know.  Stacy's credentials are simply too long to list and is every bit as talented at Matt!

Matt came to Adobe with me as part of the Adobe acquisition of Yellow Dragon Software and has moved steadily up the rungs of the LiveCycle team.  He is now heavily involved in the outreach of core LiveCycle functionality to mobile platforms.  This is a session I want to attend and trust me, this will sell out fast.  Register today here if you plan to attend.  This one already has a second session added due to popularity and IMO will fill up fast.  

The Mobile Enterprise (click on title to see the official listing)



Registration LINK HERE

Hear from product experts and discover how you can extend your enterprise to iPhone, iPad, Android, Windows Mobile, and BlackBerry devices by leveraging the Adobe LiveCycle Enterprise Suite platform. The session will include best practices for integrating business processes, accessing shared content, and developing forms for use on mobile form factors.

Tracks:    Develop
Audience:    Architect, Partner Decision Maker, Web Developer, Application Developer, Business Decision Maker
Skill Level:    General Audience
Product:    LiveCycle ES
Speakers:    Matt MacKenzie, Stacy Young
Times:   
Tuesday, October, 26th, 4:30 pm - 5:30 pm
Wednesday, October, 27th, 8:00 am - 9:00 am

Thursday, September 02, 2010

Serge launches MAX Un-awards!

My friend and fellow evangelist Serge Jespers has just released a new "widget" for MAX.
It's not really a traditional widget anymore but a personalized interactive video where you can create a MAX un-award. I have already won awards, most notably for "Hardest Working Evangelist" and "Most Timid Developer".




Every video generates its own tweet so if you see a cool video in the player, just click on the share menu and post it on Twitter or any other social network.

Have fun! See you at MAX!

Monday, August 30, 2010

LiveCycle ES Pick of the week: A Case Study

In the past few months we have been selecting a new LiveCycle@MAX track to promote as the Pick of the Week via Technoracle. One type of session that provides a lot of value is the case study so this week we are proud to present the following track.

Just as a reminder, whether you are a business person, developer or architect, if you are planning to attend MAX in 2010 and want to take a serious dive into LiveCycle ES, it is highly recommended to register ahead of the deadlines. In addition to saving money, you will likely find out that the selection of available sessions is far greater the more you book in advance. Several of our sessions sold out in previous years well ahead of the deadlines.

This week's pick:

Transforming the Value of IT for Government through Modernization at South African Revenue Service

Come see how the South African Revenue Service (SARS) provides improved benefits and services delivery to customers through online, automated tax filing. e@syFile is a set of Adobe AIR applications that leverage the Flash Platform and Adobe LiveCycle to enable manual and electronic tax filing. The solution delivers one form that is used in multiple channels, including print, web portal, branch/on-demand print, and offline via AIR. Using the system, SARS achieved 100% application adoption in two years and now collects in excess of 35 billion rand per month, equaling 60% of the South African revenue.

Tracks: Envision, Design, Develop
Audience: Architect, Partner Decision Maker, IS/IT, Web Developer, Application Developer, Business Decision Maker
Skill Level: General Audience
Products: AIR, Creative Suite, Flash Builder, Flash Player, Flex, LiveCycle DS, LiveCycle ES
Speakers: Rob Pinkerton, Barry Hore, Christopher Belford
Times:
Tuesday, October, 26th, 4:30 pm - 5:30 pm

I'll see you there!

Wednesday, August 25, 2010

Flash Player 10.1 really a major release?

Having used Flash Player 10.1 for a while now, I am blown away by the number of very cool advances. Most of these are subtle yet some are of staggering implication. Recently, I came accross a video made by Neil Trevett from NVIDIA where he discusses GPU acceleration in Flash Player 10.1. The video showcases how Flash Player and NVIDIA offload work from the CPU to the GPU (NVIDIA’s ION chip). The results are very impressive, enabling Flash Player to provide HD video on a range of devices — even the smaller netbooks.

As Neil says, “Flash Player 10.1 is a real advance for Flash Player, actually much more than the ‘dot one’ would indicate.” I am tending to agree with him. Here is the video:




Tuesday, August 24, 2010

Adobe AIR Launchpad - WOW!!!

So it seems that while I was sitting in the hospital, my colleagues were designing and delivering one of the coolest things I have ever seen. The Adobe AIR Launchpad kick starts any RIA project by allowing you to import a pre-built project with the major functionality groups you need. The URL is http://labs.adobe.com/downloads/airlaunchpad.html ( you are going to want to download this as soon as you finish reading this blog). According to the labs website:
"Adobe AIR Launchpad is a new desktop tool that helps Adobe Flex® developers get started building desktop applications deployed on Adobe AIR. Simply run Adobe AIR Launchpad and select the capabilities you need; Adobe AIR Launchpad will create a ready-to-import Flex project with your selected features implemented in a way that can be easily modified and extended. You can use the resulting project as a starting point for your AIR application."
I decided to try it out. Since I have been sick my imagination seems to lack a bit so I just picked a random set of things for the application. You can drag and drop icons and select the application descriptor file settings from the main GUI as shown below:


From the next wizard menu you can select items like global error handling, detection of idle time or network capabilities etc.

and finally, the ability to select some standard types of things many developers would use.



and generate your project!


I imported and opened up the resulting project and found all the generated code and assets neatly placed into the same directory structure I would have used. Very cool!

I did have one small red X in the project which was thrown as the compiler did not recognize "e:UncaughtErrorEvent".

It turns out I failed to read the instructions (seems to be a major pattern in my life) that clearly instructed me to use the Flex SDK 4.1. I just wanted to post this here in case anyone else, like myself, believes reading the manuals are only a last resort. I can hear my teachers back in school now:

Duane. You must read this great novel about a Spanish guy named 'Manual'.


From Technoracle, Adobe AIR Launchpad scores a solid 9/10 for the first release, largely due to the fact it saves lazy developers like me a lot of work!

Monday, August 23, 2010

MAX Pick of the Week

Well, I am not really fully back at work but since I have a computer in front of me, figured I'd get a little work done. Every week (barring the hospital stay) I have been promoting a different MAX 2010 Livecycle ES session. This week, the session I will promote is one I am co-leading with Scott MacDonald. If you do not know who Scott is, he is the guy who writes most of the Livecycle ES Quickstarts and has a full depth of knowledge when it comes to LC ES. If you've ever needed to integrate LC ES with CMS or invoke an API remotely, you need to meet Scott!

This session is for anyone who has worked with Livecycle ES and found a need to extend it. It can be quite daunting your first time and that is why we have put this session together. Building and deploying a custom component and integrating Livecycle ES with other J2EE environment applications should not be feared. Once you have the know how, it is actually very easy due largely to the great architecture and abundance of collateral to help you. This session will impart this knowledge to attendees and you'll walk away with more than your money's worth for a 90 minute session.

Here is the session - register now:

Extending LiveCycle ES for Java Developers


Join product experts and others as we work through the process of creating a Plain Old Java Object (POJO) that will be packaged and deployed to the Adobe LiveCycle Enterprise Suite service container as a custom component. Once your component has been deployed and activated, you'll then explore several invocation methods (SOAP, REST, and Remoting) to call your newly available service.

Tracks: Develop
Audience: Architect, Web Developer, Application Developer
Skill Level: Advanced
Products: Flash Builder, LiveCycle ES
Speakers: Duane Nickull, Scott MacDonald
Times:
Monday, October, 25th, 5:00 pm - 6:30 pm

See you there!

Sunday, August 22, 2010

UPDATE on Meningitis/Kidney failure

Hey everyone. I am so humbled by the thousands of comments, messages, emails, SMS's etc. I have received. I am truly the luckiest person alive to have so many great friends and it made a huge difference when I was sitting in the hospital room alone. You’re all correct – I’m gonna kick this sickness in the arse so hard it won’t come within a 1,000 KM of Vancouver. Cannot believe I was even thinking of letting this thing make me a victim.

So I got the renal biopsy done on Thursday and the first results were in Friday AM. The unbelievable is happening - > my own kidney’s seem to be starting to heal themselves (prognosis was less than 5% this would happen). The Creatinine score fell from over 350 to 314 with no treatment. It’s too early to tell if this is a real trend or not but I’m gonna ride this wave as if it is. There is still a long road ahead to full recovery but the best thing happened. I got discharged from the hospital after two weeks and am now getting treated as an outpatient. This means I get to be at home to recover. I still have to have daily blood tests and monitoring done so it will be a while before I am back to full speed.

I also set a short term goal to be able to play with 22nd Century on Sept 2nd at the Backstage Lounge for Jesus Krysler’s CD release party along with Blackburn X and Helmz Deep. Focusing on this show as a goalpost will help. I hope you'll join me there.

Again – I really want to thank you all. Please accept apologies if it takes a while to individually thank you but know you made a huge difference.

Peace love and chaos!

duane

Wednesday, August 18, 2010

Spinal Meningitis (not Spinal Tap)

Friends – I want to thank all of you for your immense support during the last two weeks. The support and well wishes from friends and family was extremely critical for me to have while being in an isolation chamber in a hospital thinking I was dying. Right now I am on a short reprieve of 12 hours ( must be back at VHG at 07:00) but wanted to write to update you all on what has happened and the current status.

Basically, in the early morning hours two weeks ago, I was rushed to Vancouver General Hospital with near paralysis and severe pain in my head and torso. This was a complete shock as there was no prior indication anything was wrong and I have enjoyed great health most of my life. After several tests including a spinal tap to retrieve spinal cord fluids, the diagnoses came in as Spinal Meningitis. For those of you who do not know this illness, 70 percent (http://www.idph.state.il.us/public/hb/hbmening.htm) or more of bacterial meningitis cases were fatal before antibiotics were developed and with antibiotic treatment, the fatality rate has dropped to 15 percent. The hospital basically pulled out all the stops to rid me of this disease.

Unfortunately, in doing so, they introduced a wide spectrum anti-viral medication into my blood stream. My kidneys reacted very badly and I currently have a creatinine count of around 357 (when I came into the hospital, the count was 62). 300 + is a very bad score indicating kidney impairment (ref: http://www.medicinenet.com/creatinine_blood_test/article.htm). Currently the doctors are trying to find both the exact reason for the high creatinine count as well as a cure. Tomorrow morning I will get a kidney biopsy (basically a series of 6 drill tests through the kidneys) to try and find exactly what has gone wrong. The results will not be known for a while (Monday maybe) and I will update here.

I want to acknowledge the support of my wife and all my family and friends. There is nothing specific we need at this time so please just well wishes and if you really want to do something, be nice to a random stranger tomorrow. Knowing my life is influencing people I do not know in a good way is the best gift you could give.

Thank you again.

Peace, love and may your code compile on the first try!

d

Thursday, August 05, 2010

SOA has not failed, Adobe's Enterprise Software successes

Recently I have seen more than a few people jump on the "SOA has failed" bandwagon. My perception is different. I have actually seen many platforms that adopted the core principles of SOA, as defined by the OASIS Reference Model for SOA, flourish and owners reap large rewards.

Adobe's own platforms are a primary example of this. Having recently written about the differences in patterns of SOA vs REST within the Flash Platform, I now feel compelled to point out that SOA is far from dead. In fact, I received an internal email today within Adobe that clarifies this point. The email outlined the percentages of the top companies that are using Adobe LiveCycle ES or other Adobe enterprise software. This was published in last week’s Adobe internal business intelligence website and while I cannot divulge the raw data sources, I believe this to be accurate.

Fact: Over 27,000 Companies use Adobe Enterprise products (Connect, Flash Builder, LiveCycle).

Fact: These products embrace the concept of services to enable consumers to gain access to blocks of functionality encapsulated within the software. Acrobat Connect is even deployed using the Software as a Service (SaaS) model.

All Industries
22 of the top 25 global companies, as measured by Forbes, use Adobe Enterprise products.
23 of the top 25 U.S. companies, as measured by Fortune, use Adobe Enterprise products.
23 of the top 25 European companies, as measured by Forbes, use Adobe Enterprise products.

Banking Industry
7 of the top 10 global Banks use Adobe to deliver better customer experiences.
16 of the top 20 U.S. Banks use Adobe to deliver better customer experiences.
23 of the top 25 global Banking companies, as measured by Forbes, use Adobe Enterprise products.
20 of the top 20 U.S. Banking companies, as measured by Fortune, use Adobe Enterprise products.
10 of the top 10 European Banking companies, as measured by Forbes, use Adobe Enterprise products.

Insurance Industry
24 of the top 25 global Insurance companies, as measured by Forbes, use Adobe Enterprise products.
7 of the top 10 U.S. Insurance companies, as measured by Fortune, use Adobe Enterprise products.

This does not sound like SOA is failing to me. In fact, far from it. Services will be around for a long time in the future. Why? The concept of services is durable. It will be relevant over many generations of the same technology and it will also be a form of architecture practiced in new technologies.

One of my friends recently stated that "SOA is dead" then followed it up with "long live services". This caused my brain to spin a bit. If an architecture has services, wouldn't that make the architecture ipso facto service oriented? Perhaps I missed something?

If you are new to LiveCycle ES and want to get up to speed, do not overlook the benefits of coming to Adobe MAX 2010. Be warned however that space is filling up fast.

Final synopsis: SOA is not dead. Services will continue to be the dominant action boundary between capabilities and consumers of those capabilities who may be from disparate domains of ownership.

Long live SOA!!!

Monday, August 02, 2010

Livecycle@MAX 2010 - Pick of the Week!

What can I say? There are so many quality Livecycle ES sessions at MAX this year that it makes it hard to pick a new candidate each week to highlight. Nevertheless, after much investigation, here is the one I want to promote.

Advanced Dynamic Form Design

Join author J.P. Terry for a hands-on lab covering advanced form design techniques and his latest tips and tricks. For instance, you'll learn how to add an auto-completion feature to a PDF form that provides relevant suggestions as the user types into the form. See other advanced techniques that make form completion much easier and more accurate. The techniques will be taught within the context of the Institutional Investor case study from Terry's book “Paperless: Real-World Solutions with Adobe Technology.”


Tracks:Design, Develop
Audience:Web Designer, Web Developer, Application Developer
Skill Level:Advanced
Speaker:J.P. Terry
Product:LiveCycle ES
Times:
Monday, October, 25th, 12:45 pm - 2:15 pm
Tuesday, October, 26th, 3:30 pm - 5:00 pm

Note that this is an advanced level session. I want to attend this myself and get the tips right from J.P. Just to let you know who he is, J.P. Terry is the CEO of SmartDoc Technologies, a leading consulting firm in the field of intelligent document solutions with offices in NY, NJ, and Beijing, China. SmartDoc specializes in LiveCycle and has developed paperless solutions for Fidelity Investments, Merrill Lynch, and Citigroup. J.P. often writes and speaks about dynamic PDF and is the author of “Creating Dynamic Forms with Adobe LiveCycle Designer” (Adobe Press, 2007) and “Paperless: Real-World Solutions with Adobe Technology” (Adobe Press, 2010). Prior to SmartDoc Technologies, J.P. founded BrandWizard Technologies, a division of Omnicom (OMC), and was the CEO of BrandWizard from 2000 until 2005.

Remember, Livecycle@MAX also sold out early last year. Register now if you are going so you don't have to wait another year. I'm going to be there the whole week.

See you!

Friday, July 30, 2010

SOA vs. REST in Flash Player

After reading this I have to rant a bit. The architecture of Flash has been done right and is in alignment with the core principles of SOA, as defined by the OASIS Reference Model for SOA, an abstract model that describes the core principles of SOA at much the same level of abstraction as Roy Fielding's doctorate thesis on REST. Flash is also in alignment with the core principles of REST. For those who are not familiar with REST, I have written an article called "Understanding REST". Note that "REST" does not mean "HTTP".

Disclaimers (to disclose any conflicts of interest): I work for Adobe. I worked on the W3C Web Services Architecture Working Group, several other Web Services standards groups and chaired the OASIS SOA Reference Model Technical Committee for over 3 years. I speak only for myself, based on my ignorant views of the way of the world.

REST is in no way dependent upon HTTP although section 6.3 of Fielding's thesis does elaborate on how to use the principles of REST with HTTP, with several notes where there are departures. On that note, I’ve always found it odd that HTTP was considered an application layer protocol in the OSI stack however I can live with this. TCP/IP are the true transport workhorses but I have always believed HTTP is tasked largely with delivering messages to HTTP servers. This does however, raise the differences of a REST style to an SOA approach. SOA uses services as an action boundary between a capability and the consumer. A service has a deliberate design to be as opaque as possible as the consumer should not necessarily know how the capability is being fulfilled (monkey's on typewriters, Cray supercomputer....doesn’t matter). Having an application layer semantic like “DELETE” in a transport protocol (yes - I know it is considered an application layer protocol by the OSI crowd) like HTTP seems to break this architecture principle since it prescribes a method on the capability (the functionality layer, which lives below the service), thus making the service less opaque. This brings up an interesting difference in the architectural ways of SOA vs REST.

The SOA-ish way to architect applications is to keep the semantics of data management out of the transportation workhorse where possible. There is no hard set of rules for this, yet many architects I talk to seem convinced this is the best way to build. Every service has an associated data model and action model for processing the service invocation. The data model is the data and the processing/action models are the place whereby the "verb" of the service invocation can be expressed. In SOA, there is also a concept of "Reach-ability and Visibility", which is usually manifested in the real world by using a transportation protocol sending electronic signals (usually by using SOAP with the HTTP binding) to a destination denoted by a URI (very similar to REST).

I personally think that in a perfect world, layers of an architecture should ideally be independent of each other. In an SOA world, the transport functionality (usually implemented using SOAP) should focus on just delivering the message and it’s associated payload(s) to the destination(s), optionally enforcing rules of reliability and security rather than declaring to the application layer processing instructions to the service endpoint. This is why in the W3C Web Services working groups, we chose to use only “GET” and “POST” in the SOAP HTTP binding, as denoted in the SOAP work itself in section 7.4 (don't believe me? Read it here).



In defense of the author, Flash's HTTP libraries currently support GET and POST. My architectural view of this is that the HTTP libraries only should really support these and not worry about the others. The HTTP POST and GET themselves are very similar if you remove the semantics (both carry some bytes over the wire in a Request-Response message exchange pattern). When you start comparing POST and PUT, the confusion gets worse. To understand this more, let's examine what Roy Fielding wrote in section 6.3:

"The Hypertext Transfer Protocol (HTTP) has a special role in the Web architecture as both the primary application-level protocol for communication between Web components and the only protocol designed specifically for the transfer of resource representations. Unlike URI, there were a large number of changes needed in order for HTTP to support the modern Web architecture. The developers of HTTP implementations have been conservative in their adoption of proposed enhancements, and thus extensions needed to be proven and subjected to standards review before they could be deployed. REST was used to identify problems with the existing HTTP implementations, specify an interoperable subset of that protocol as HTTP/1.0 [19], analyze proposed extensions for HTTP/1.1 [42], and provide motivating rationale for deploying HTTP/1.1.

The key problem areas in HTTP that were identified by REST included planning for the deployment of new protocol versions, separating message parsing from HTTP semantics and the underlying transport layer (TCP), distinguishing between authoritative and non-authoritative responses, fine-grained control of caching, and various aspects of the protocol that failed to be self-descriptive. REST has also been used to model the performance of Web applications based on HTTP and anticipate the impact of such extensions as persistent connections and content negotiation. Finally, REST has been used to limit the scope of standardized HTTP extensions to those that fit within the architectural model, rather than allowing the applications that misuse HTTP to equally influence the standard."

Sounds a lot like the SOA approach doesn't it? So let's analyze why an enterprise architect (regardless of using REST or SOA styles) would want to stay with these and keep the processing semantics in the payload. If you are architecting a client-service architecture where the cardinality is 1:1, it might make sense to start overloading HTTP with things like "UPDATE", which some people have proposed. Some time ago, architects realized that keeping layers of applications as independent from each other as possible is a desirable trait. The rationale is that over time, changes can be made to one layer without affecting the others. When cardinality goes to multiple clients per service, you end up with conflicts in state, marshaling and ordering requests and many other issues.

Adding in things like "DELETE" exposes methods publicly that may not be available to all consumers of a service. Specifically for DELETE, in many Flash MEPs, this is not an option you want to bestow upon non-authenticated users. If you want to expose this for consumers of a service, my preferred way would be to build a second service exposing this but keep the back-end processing semantics in the payload (SOAP body in many cases). For this reason, I have also been skeptical about about WS-TX as it also exposes back-end semantics into the SOAP header.
Another way would be to keep the endpoint the same, but have other permitted operations exposed and declared in the WSDL instance.

Using POST vs PUT is also something that is confusing. Some have equated PUT to be synonymous with an INSERT in SQL terms and POST to be equivalent to CREATE. While this is sort of true, in the real world, the physical bytes of both operations overwrite the existing copy of a resource, hence it is really an UPDATE in CRUD terms. The author of the other article that started this rant asserts that PUT must be supported for REST. In reality, it is not an explicit requirement. In fact, in section 6.3.3.1 of his thesis, Fielding writes:

"HTTP does not support write-back caching. An HTTP cache cannot assume that what gets written through it is the same as what would be retrievable from a subsequent request for that resource, and thus it cannot cache a PUT request body and reuse it for a later GET response. There are two reasons for this rule: 1) metadata might be generated behind-the-scenes, and 2) access control on later GET requests cannot be determined from the PUT request. However, since write actions using the Web are extremely rare, the lack of write-back caching does not have a significant impact on performance."
Again, this shows a heavy alignment between the SOA approach to transparency and the REST-afarian approach. Both groups have realized that assumptions about something behind a service endpoint are not optimal. The Flash platform architecture adheres to this methodology.

Now on to Cookies. HTTP requests are idempotent by nature. This means that any new request is not dependent upon knowledge of a previous exchange of messages. Again, most architects I work with prefer to not introduce dependencies where they are not necessary. The reason for this is that services (whether SOA or REST style endpoints) are "slaves" to a higher level of logic where things like the state of an overall process or a long running orchestration is kept. Keeping the state at the individual service level is a bad idea as conflicts will arise. This can be proven to be mathematically troublesome when cardinality of service/process goes higher.

Now cookies do offer some good functionality, yet again, the REST-afarians have taken a similar approach to SOA:

6.3.4.2 Cookies

An example of where an inappropriate extension has been made to the protocol to support features that contradict the desired properties of the generic interface is the introduction of site-wide state information in the form of HTTP cookies [73]. Cookie interaction fails to match REST's model of application state, often resulting in confusion for the typical browser application.

...

Cookies also violate REST because they allow data to be passed without sufficiently identifying its semantics, thus becoming a concern for both security and privacy. The combination of cookies with the Referer [sic] header field makes it possible to track a user as they browse between sites.

Says it all, doesn't it! Cookies are for the browser and belong in the browser. Having Flash Player able to access cookies would be a mistake in my own opinion. Any logic that is facilitated by a browser should probably be dealt with at the browser layer before Flash Player is used.

Conclusions:

1. The original post I responded to actually was valuable as it got me thinking about the real differences between REST and SOA, but the more I look at it, the core architectural principles of REST are aligned with SOA. There are some minor differences.

2. Flash's architecture is staying true WRT to REST and SOA. The runtime supports the right level of functionality while balancing out features. There is NO explicit requirement to support DELETE and PUT in REST as it is currently written. If you do not believe me, see for yourself here.

3. To be fair to the author of the article, I would invite a discussion on what the end goal was to see if there is some use case that Flash Player has missed.

Have a great weekend!

Monday, July 26, 2010

Livecycle@MAX 2010 Pick of the Week!

This is the third of my favorite sessions (ones I want to attend) that are focused on Adobe Livecycle in the enterprise. This one is going to sell out fast!

Building Flex Applications with Advanced Real Time Messaging

Join Mete Atamel, Adobe LiveCycle Data Services architect, to learn all you need to know to build the most demanding Flex applications with real-time data. The latest version of LiveCycle Data Services comes with an extensive set of advanced messaging features, including reliable messaging, message throttling, edge server deployment, and a NIO-based Java load testing tool. In this session, you'll not only get in-depth coverage of these features but you'll also see them in action with live demos.

Sign up here - this sells out fast!

Monday, July 19, 2010

MAX 2010 Session of the Week!

Every week I will be highlighting a new session for MAX 2010. MAX 2010 will take place on October 23 -27th at the LA Convention Center and will feature an expanded LiveCycle ES bundle including tons of new materials and topics. All sessions and hands-on training will be done with the latest versions including such awesome improvements as Action Builder and the Service Discovery plug-in. I'll be teaching two sessions, which will be featured in a later post. Every week on Technoracle, we'll try to feature one new MAX 2010 LiveCycle featured promotion.

Here is Technoracle's featured promotion for MAX 2010 for the week of July 19, 2010:

Building Composite Rich Internet Applications

Join product experts and learn how to build an enterprise composite application using Adobe LiveCycle Mosaic ES. Discover how to assemble and integrate multiple enterprise applications on the client side while ensuring user interface integrity of your enterprise look and feel. You'll also learn how to include embedded collaboration to enable users to communicate while remaining within the application context.

Tracks:Develop
Audience:Architect, Partner Decision Maker, Web Designer, Web Developer, Application Developer, Business Decision Maker
Skill Level:Intermediate
Speaker:Don Walling
Products:Flash Builder, LiveCycle ES
Times:
Tuesday, October, 26th, 1:00 pm - 2:30 pm

As reported last week: It's no secret, LiveCycle ES developers are in high demand. Don't believe me, check out the barrage of "LiveCycle Developers Wanted" postings (297 results) on the Google LiveCycle Developers list. Some pay as high as $400/hour! If you want to put your tech career into high gear, you will definitely want to get the “LiveCycle@MAX” bundle, which includes LiveCycle preconference training and full MAX conference pass. THIS SOLD OUT EARLY LAST YEAR so book it soon. The 2009 preconference LiveCycle ES workshops even sold out faster than the Photoshop training.

Sign up for the LiveCycle @ MAX Bundle now: http://max.adobe.com/sessions/livecycle/

Thursday, July 15, 2010

More Adobe Open Source and Transparency

I got an email from Dave McAllister I want to post here. It really makes me proud that we are moving in this direction. It was also written up here.

"Today, we formally launched phase 1 of open@adobe, our new portal for open stuff. Open@Adobe (http://sourceforge.net/adobe) is the first instantiation of SourceForge's new developer platform. Open@Adobe is a site aggregating Adobe's openness programs, which includes source code hosting, such as the Adobe® Flex framework, and contributions from Adobe to standards organizations, as well as specifications.

It has been clear for some time that we needed to become more aligned with development principles is seen in open source projects. We've always followed a open process model, with exposure to our bug bases, open discussion forums , roadmaps for products, and early access through Adobe Labs. However, our current repository was not meeting the desire to allow our projects to evolve in multiple directions simultaneously.

In short, Source Forge was beginning to redesign their forge. Because of this we had the chance to add our requests, such as the ability to link back to existing Adobe properties (like forums) and in the future, adding the ability to unify the bugbase to our engineering teams. We worked with a number of existing projects to get their input, and it was fascinating the input we did get.

We wanted to tap the creative and innovative energies of the open source community. SF today hosts over 250K projects and has around 3M downloads a day. We’ve seen some increase in our numbers since its been up, even though it wasn’t announced to today. We wanted the ability for groups and individuals to self create projects; and in the near future to recognize the existence of projects built on our open source core technologies. There are planned updates during the next year, and the various projects will move from opensource.adobe.com to open@adobe as it makes sense.

Feel free to take a look, and if you want to join in (even if you just want us to point to something you’re doing. Let us know.

Monday, July 12, 2010

MAX 2010 - Get your LiveCycle ES Career on Track!

MAX 2010, October 23 -27th at the LA Convention Center, will feature an expanded LiveCycle ES bundle including tons of new materials and topics. All sessions and hands-on training will be done with the latest versions including such awesome improvements as Action Builder and the Service Discovery plug-in.

It's no secret, LiveCycle ES developers are in high demand. Don't believe me, check out the barrage of "LiveCycle Developers Wanted" postings (297 results) on the Google LiveCycle Developers list. Some pay as high as $400/hour! If you want to put your tech career into high gear, you will definitely want to get the “LiveCycle@MAX” bundle, which includes LiveCycle preconference training and full MAX conference pass. THIS SOLD OUT EARLY LAST YEAR so book it soon. The 2009 preconference LiveCycle ES workshops even sold out faster than the Photoshop training.

Sign up for the LiveCycle @ MAX Bundle now: http://max.adobe.com/sessions/livecycle/

I'll be teaching one session, which will be featured in a later post. Every week on Technoracle, we'll try to feature one new MAX 2010 LiveCycle featured promotion.

Here is Technoracle's featured promotion for MAX 2010 for the week of July 12, 2010:

Developing a LiveCycle ES2.5 Application

This program for enterprise developers combines one-and-a-half days of introductory preconference training on Adobe® LiveCycle® Enterprise Suite 2.5 with a full conference pass to MAX 2010.

The "Developing a LiveCycle ES2.5 Application" preconference lab is an essential introduction to developing user-centric applications with Adobe LiveCycle ES2.5. LiveCycle ES2.5 allows both business and IT professionals to visually assemble end-to-end processes, which when combined with rich interfaces, create engaging applications that unify systems and people quickly and flexibly. We'll present an end-to-end use case bringing a rich Internet application (RIA) and a LiveCycle application together. You'll learn about the LiveCycle IDE, the Admin User Interface, and the LiveCycle ES2.5 solution components as we guide you through development of this comprehensive use case.

We strongly recommend this training to those new to LiveCycle ES2.5, or those who would like a refresher, in order to get the most value out of the more advanced LiveCycle topics that will be presented during MAX.

The Developing a LiveCycle ES2.5 Application preconference lab will take place October 23rd and 24th at the Los Angeles Convention Center.

Friday, July 02, 2010

Hero - The Flex Framework

Adobe is currently building new mobile development capabilities into the Flex framework. The next version of Flex, codenamed “Hero”, will enable developers to create application experiences that translate well across platforms, and make it easy to build applications that work well on a wide variety of mobile devices. To understand this more, take a look at this video.




“Hero” will augment a number of existing Flex components with mobile- and touch-optimized skins and functionality, and will also add new components that support mobile-specific UI patterns.

Previously, Adobe had investigated splitting off mobile development into a new branch of the Flex framework code-named “Slider”. However, the rapid increases in performance on smartphone-class devices over the past year, combined with the highly optimized performance of Adobe runtimes on these devices, now make it feasible to support mobile use cases directly with the core Flex framework.

Read the rest of what we're doing here:
http://labs.adobe.com/technologies/flex/mobile/faq.html

Wednesday, June 30, 2010

Professional Web Designing

A Technoracle guest post written by James Mowery.

With technology and the Internet still growing after 15 years, web
design has become an industry in itself. The world is filled with
eager, talented graphic designers who are learning as the technology
itself progresses, each with the goal of putting their own spin on the
world of design. Many web designers who do their work professionally
rely heavily on Adobe products such as Illustrator and InDesign,
which have become the standard for designing web pages. However, while
Photoshop is not used as often as these programs, it can be an
extremely versatile and valuable tool for the modern web designer and
should never be ignored.

Illustrator and InDesign are used frequently because they were both
created as ways to graphically design images and pages for the web.
The web is an environment that must be respected when it comes to
design, as some things will work and many others will not. That being
said, these programs are well-suited to designing for the web
environment, as they often will default to what will work online.
Photoshop is not used as often for design, as it doesn't have the
power that these other programs have for designing for web. However,
it can be a powerful add-on tool to be used in conjunction with other
Adobe products. After all, they are all part of the same creative
suite and are meant specifically to play off of one another.

Photoshop's power comes from its ability to enhance and alter images
to great effect. Since web design is often made up of large amounts of
images, Photoshop becomes a very powerful ally. From the ability to
create collages for a web environment to the program's ability to
greatly enhance the quality of low-res images, what Photoshop lends to
the web environment is absolutely critical. In fact, Photoshop can
actually be used to enhance an alter entire web pages, which is a
technique that many of the best web designers in the world use on a
regular basis.

Put simply, the web designer who doesn't take advantage of Photoshop
is not using all the tools available and is thus only seeing half the
picture.

About the author: James Mowery is a computer geek that writes about
technology and related topics. To read more blog posts by him, go to
his blog.

Technoracle Road Test: Google Nexus One Car Dock

Having recently switched from iPhone to Nexus One, I have been really impressed by the functionality and ease of use. On a recent trip to Victoria, I decided to test out the new Navigation features of the Nexus One using the Car Dock. The Car Dock is available from Google or a number of other resellers. It keeps your device constantly charging and also turns the Nexus One into a speaker phone (legal in most states, provinces).

Here is the video of the recent test. There are also a few drawbacks. One wish is that the Bluetooth stayed connected while in the Car Dock. For some reason, as soon as the Car Dock mode is engaged, Bluetooth headsets no longer work. This can be annoying if you want to make a private call with other passengers in the car. Other than this minor nit, I give it a solid 10/10.

Monday, June 28, 2010

Send us (22nd Century) to India!



Dear Friends:

If you haven't heard yet, you have helped 22nd Century (my band) win the provincial portion of a national battle of the bands called Band on the Run (see http://www.supernova.com/shows/9553) . We're now in the finals of national level competition and first prize is an all expenses paid plus paying gig at the Independence Festival in India in August which means performing in front of an audience of over 200,000. In order to beat the 5 bands from the other provinces participating we needs votes. The online voting starts tomorrow at 1:00 PM eastern and only lasts one week. We stand a one in 6 chance of winning.

In the last 3 years, we played a lot of charity gigs to raise money for causes of others and want to ask for a favor now in return. We would like to ask you to vote for us every day for the next 7 days at this link: http://www.supernova.com/shows/10044. We also know we've asked a lot and want to be really honest and say that we know many of you have given us more than we can ever repay. Having said that, it is a dream of ours to play at one of the world's largest rock festivals and represent Canada!! By the time you read this, there should be a "VOTE" button on the page.

We want to propose that each day (only for the next 7 days) you click here to vote http://www.supernova.com/shows/10044

All you have to do is take 1 minute to open it, click on the link and vote.

In return, all we can do is keep thanking you. Any money we receive above and beyond our expenses in India will be donated towards a charitable cause (perhaps to clean up the gulf, build more school houses in Tanzania, fight the HST, buy Donald Trump a new hair cut?).

Again, we're humbled by this opportunity and realize it wouldn't have happened without you. Votes from any country count!

duane, tim and zippy

Wednesday, June 23, 2010

The Software as a Service (SaaS) Pattern Explained


(Reprinted courtesy of O'Reilly from the Book "Web 2.0 Architectures".
Purchase book here)

The Software as a Service (SaaS) acronym has confused many people as vendors have abused the term to hawk anything with a network capability. In order to understand it, it is useful to tease out the core aspects of it agnostic to any specific implementation or product. James Governor, Dion Hinchcliffe and I wrote about it in the book "Web 2.0 Architectures" along with other patterns. In this context, a pattern is the idea of capturing architectural design ideas as archetypal and reusable description. SaaS is in effect, a pattern specifically for the delivery of software functionality to the end consumer.

To describe it within the book, we used the MacKenzie-Nickull Architectural Patterns meta-model.

Pattern

Software as a Service (SaaS)

Also Known As

Terms often associated with the Software as a Service pattern include:

Utility Computing and Cloud Computing
Cloud Computing is not the same as SaaS; rather, it is a specialized pattern of virtualization. Utility and Cloud Computing refer to treating computing resources as virtualized, metered services, similar from a consumer’s perspective to how we consume other utilities (such as water, gas, electricity, and pay-per-view cable).

On-demand applications
On-demand applications provide access to computing resources on an ad hoc basis when the functionality is required. Using the http://createpdf.adobe.com service to create a single PDF document online rather than having to download and install a version of Acrobat is a good example.

Software Above the Level of a Single Device
This pattern relates to software that spans Internet-connected devices and builds on the growing pervasiveness of the online experience. It touches on various aspects of the SaaS pattern; in particular, the concepts of distributed computing of tasks via network connections.

Model-View-Controller (MVC)
Some people consider SaaS a specialization of the MVC pattern that distributes the Model, View, and Controller (or parts thereof) over multiple resources located on the Internet. It is strongly related to SaaS, and most SaaS providers follow the MVC pattern when implementing SaaS.

Business Problem (Story)

Consider a software vendor that wishes to develop spam removal software to keep spam from reaching its clients’ inboxes. This can be achieved by writing algorithms that analyze incoming local email messages, detect possible spam messages, and flag them in such a way that the mailbox owners can filter them out automatically without having to manually sort through all the messages.

The business problem arises from the fact that spam is constantly changing, which makes it difficult to detect and flag. Spam is typically sent from a variety of spoofed email addresses, and the specific text patterns are changed frequently. For example, if you wanted to detect any spam that had the word “Viagra” in it, you could simply use Perl’s regular expression matching syntax:

if ($emailString =~ m/viagra/;)
{
$SpamScore =+ 1;
}
However, all the spammer would have to do is alter the case of some of the letters to thwart this detection, as in the following:

"ViAGRA"
You could counter this in Perl by adding an i flag to ignore case, as follows:

if ($emailString =~ m/viagra/i;)
{
$SpamScore =+ 1;
}
However, the spammer could then substitute an exclamation point, the number 1, or the letter l for the letter I, capitalizing on the face that the human mind will perceive “Viagra” if it sees “V!AGRA,” “V1AGRA,” or “VlAGRA.” To a human these terms might semantically be the same, but changing the one byte from an I to another character will render useless the efforts of a computer trying to filter spam based on a string of characters. Each possible mutation would require the software vendor to write and distribute new patches to detect the latest variations to each client, possibly on a daily or even hourly basis. In this case, the Perl syntax could be changed to:

if ($emailString =~ m/v.*gra/i;) {
{
$SpamScore =+ 1;
}
The ballet between those who create and send spam and those who try to detect and delete it is a constantly morphing work in progress, with new steps being introduced every day. Each individual the company serves could attempt to create these rules by himself for his own mailbox, but this would be both ineffective and inefficient. Users would each sample only a small subset of all spam, would not be able to easily create heuristic filters to detect spam, and would likely spend an inordinately large amount of time on this activity.

Context

The SaaS pattern is useful any time a customer base has needs that could be addressed more efficiently or reliably by creating a service all of them can share across organizational boundaries.

This pattern occurs whenever a person or organization is building an application whose model, control, or view aspects must be refreshed based on dynamic circumstances or instances in which specialized functionality of the application must be delivered. The pattern could apply anywhere a static application does not easily lend itself to frequent specialization of the model, view, or control aspects required to make it function properly.

The pattern is useful in situations in which users need more computer resources than they can easily support on their local systems and in those situations where users need particular computing resources only occasionally.

Derived Requirements

Computing resources should be architected to be reachable (as discussed in the section on SOA) over whatever network or fabric the architect designs the application to work with. For example, most web-enabled SaaS applications use a common transport protocol, and most ham radio operators use a common frequency to broadcast information or pass it along in a chain.

Functional components of the core computing resources must be usable via a well-defined interface. Such an interface should not be bound to a single client or single model for delivery (such as installation of an application) and should support multiple options for building the user interface (e.g., web-based or client application interface).

Generalized Solution

SaaS is a model of software delivery in which the manufacturer is responsible for the daily technical operation of the software provided to the clients (including maintenance and support), while the clients enjoy the full benefits of the software from remote locations. SaaS is a model of “functionality delivery” rather than “software distribution.” Most of the functionality can be delivered over the Internet or made available in such a way that the end user can interact with the application to get that functionality without having to install the software on her machine. This approach can deliver functionality to any market segment, from home consumers to corporations, and hybrid solutions can deliver small pieces of client-side software that make certain tasks easier.

Static Structure

The basic deployment pattern for SaaS involves deploying different aspects of the model, view, and control components of an application to multiple physical locations. The deployment approach may vary greatly depending on the software and its complexity and dependence on other aspects. Figure 7.9, “Deployment patterns contrasted (SaaS versus conventional approach)” shows how the basic deployment pattern for SaaS differs from traditional software distribution.


Figure 7.9. Deployment patterns contrasted (SaaS versus conventional approach)



The service should also be able to learn from its users when appropriate. This concept of “software that gets better as more people use it,” a hallmark of Web 2.0, has many advantages. For example, in the business story shown in Figure 7.10, “Spam filter software as a service”, if enough email flows through a pattern detector, spam recognition becomes much more accurate based on the collective interactions of thousands of users. As more and more users flag the same messages as spam, the server will begin to recognize those messages as spam, and the global filter will then prevent them from being delivered to other end users. Many readers probably use this type of functionality already without really knowing it.

Google’s Gmail is a prime example of this pattern in action. Google Search is another dynamic example of Software as a Service that gets better the more that people use it. Google actually tracks the links users click on to determine how many people seek the same resource for the same search term. This system is much more sophisticated than a simple adaptive algorithm, yet the principle benefit of large-scale use is that the system learns and adapts based on users’ behaviors.

This functionality is a side benefit of SaaS rather than a core aspect of the pattern.



Figure 7.10. Spam filter software as a service



Dynamic Behavior

The dynamic behavior of the SaaS pattern can vary greatly depending on which protocols, standards, and architectural approaches are chosen. Figure 7.11, “A dynamic view of one way to visualize SaaS” shows a common depiction of the pattern.



Figure 7.11. A dynamic view of one way to visualize SaaS



First, a user identifies his requirements for consuming computing resources. This pattern can be implemented at many levels of complexity, from a secure web service to a simple user interface such as an HTML web page in a browser. The user will interact with the service (the service in this case is a proxy), which will then invoke the core functionality. The responses are appropriately directed back to the user, as required.

Note that this pattern becomes very interesting when multiple users employ the resources and implementers have capabilities that do not exist for their non-SaaS counterparts. First, the functionality provider can detect and act on patterns in runtime interactions. An example of this might be the detection of some error state that is occurring for multiple users of the system (e.g., the email clients are crashing because of a nefarious script contained within some emails). Rather than waiting for enough users to contact the software provider with enough information to enable it to fix the error, the provider can detect the condition itself at an early stage and has access to sufficient information to enable it to trace the source of the error. Ultimately, all users of the software will have a much better user experience if problems are mitigated sooner rather than later and before they feel compelled to complain about them.

Second, a provider may want to consider scaling the system in the backend to handle large numbers of requests. Sudden traffic spikes can adversely impact the user experience, making the system seem unresponsive. Service providers may want to investigate other services, notably those of Cloud Computing providers, if they need to support widely varying usage levels. Most Cloud Computing providers offer automatic scaling to support the amount of processing power and storage needed by an application.

Implementation

As shown in Figure 7.12, “Distinctions of the SaaS pattern”,[75] designers of software provided as a service rather than as a static, installed entity must consider several new nuances of the industry, as these changes in how users interact with software vendors are affecting the way we should design and architect SaaS.



Figure 7.12. Distinctions of the SaaS pattern



When implementing SaaS, you may need to ensure that no one can take advantage of your license model. For example, if you license only one user, what keeps that user from simply sharing her username and password and reselling your service? There are various types of license models for SaaS. Some are single-enterprise licenses, with the cost based on the size of the enterprise. Spam software and Microsoft Exchange Server are reported to use this model. By contrast, Adobe Systems uses a “per use” model for http://createpdf.acrobat.com, where users can either create PDFs one at a time or protect them with a persistent policy. Other software business models (e.g., for Google Search and other widgets) are built around advertising revenue models.

A software vendor implementing SaaS also can react swiftly to bugs in the system. The vendor can monitor all users concurrently to detect software glitches that may require immediate attention and may be able to fix them before most users even notice.

Business Problem (Story) Resolved

The spam detection software is housed in a federated server environment, and users’ incoming email can be automatically pre-passed through the filters to detect spam. Any spam that sneaks through can be recognized and trapped by secondary mechanisms (including human users) and reported back to the spam detection infrastructure, enabling the system to adapt to the latest spammer tactics. There is no discernable delay or lag in incoming email, and most spam email gets eliminated.

Sampling a very large cross section of all mail makes it easier to detect patterns indicating spam emails. This results in the entire system performing better, to the benefit of all users.

Specializations

SaaS may be specialized by using advanced computer algorithms to perform reasoning tasks such as inference. These ultra-advanced systems may one day be able to use cognitive skills to recognize and act on certain patterns of events. For example, these hybrid systems could use a combination of the Bayesian Theorem (conditional probability) and lexical heuristic filtering (finding evidence to support a hypothesis) to dynamically change their functionality. Such specializations will also benefit from adoption of the Collaborative Tagging (a.k.a. folksonomy) pattern, discussed later in this chapter, as it will help foster computational intelligence applications that can reason and infer hypotheses.

Known Uses


Postini, Inc. (which Google acquired in 2007[76]) figured out quite a while ago that centralization and offering its security, compliance, and productivity solutions as a service would result in better spam detection for end users. Recently, many other email companies have begun to use similar SaaS models. Apple’s iTunes music application is perhaps one of the most prominent examples of a hybrid approach to the Software as a Service pattern. The iTunes application has some predetermined functionality and user interfaces (the “V” and “C” components of “Model-View-Controller”); however, much of the information presented to the user is based on information (the “M” in “MVC”) the application receives from the iTunes servers during runtime. This hybrid approach can link user profiles to service calls to offer users better experiences.

Adobe Systems recently launched a service that allows people to manually create small numbers of PDF documents online and optionally link to them other functionality for things such as enabling rights management. Google continues to expand its SaaS offerings. Initially, its search service used algorithms to vary search result rankings based on user interaction patterns. Recently, Google has added multiple other SaaS offerings, including creation and manipulation of online documents, spreadsheets, and more. Note that most of Gmail has always been provided as a service rather than as an application.

Consequences


The negative consequences of using the SaaS pattern are minimal, but they need to be addressed from the outset. Offering software as a service may create additional complexity in supporting computing resources for large numbers of users. The ability to dynamically scale an offering based on surges in the number of users requesting the functionality is also an issue.

In addition, authentication—especially when used to force compliance with software licensing—can be difficult to implement and to police.

The most noteworthy consequence of implementing this pattern is that the software may have a dependency on an Internet connection. In many cases, if the connection does not work, neither will the software. When such a mechanism is possible and makes sense, the best way to avoid such issues is to employ client-side caching. The appropriateness of this strategy varies by application. Caching Google Search is difficult, and would be mostly useless in an environment where readers couldn’t go to the linked articles anyway. On the other hand, technologies like the Adobe Integrated Runtime (AIR) and Google Gears are steps in the right direction.

Denial-of-service attacks can also be a threat. A malicious user may be able to overpower the bandwidth or computational capabilities of software implemented as a service and effectively deny or greatly slow down other users’ experiences.

End users often prefer to keep their software in a controlled and secure environment. Because SaaS applications are not hosted or controlled by the user, the user might be subjected to occasional outages when service upgrades or other events take place on the provider side.

Also, personal security risks are inherent in passing information back and forth on the open Internet. Users should carefully assess what risks are acceptable for their purposes.

(c) Copyright - O'Reilly Media. See this and other patterns via the book at http://oreilly.com/web2/excerpts/9780596514433/specific-patterns-web20.html

Tuesday, June 22, 2010

Mingleverse 3D Telepresence running on Google Nexus One/Flash Player!

This video showcases an absolutely astounding capability of the new Google Nexus One smartphone running the Android operating system (Froyo 2.2) with Adobe Flash Player 10.1. Mingleverse.com is a 3D immersion technology that allows individuals to teleport their avatars into virtual universes.