Website traffic as proxy for real-estate correction

Amidst the sub-prime lending mess, it is difficult to gauge the true state of the real-estate market. Several blogs track the inevitable correction, and academic Casandras such as Robert Shiller– who correctly called the end of the 2000 technology-fueled stock bubble– have been predicting doom and gloom for some time. Meanwhile the National Association of Realtors would like to assure you that all is well, pay no attention to the man behind the curtain please. (In fact, one full-page ad published in the New York Times in late 2006 hoping to stem the rising tide of panic stated: “It’s a great time to buy or sell a house.” Simple economics would dictate that it can’t be a both buyer’s market and a seller’s market but hey, irrational exuberance is all about freedom from the dictates of logic. BigPicture blog compared the advice to an investment banker suggesting that it’s a great time to buy or sell the same stock.)

It does not help that the market indicators themselves have been completely skewed, in spite of the full disclosure tradition. Keeping with Justice Brandeis’s principle that sunlight is the best disinfectant, few other markets have so much regulation intended to keep the level of transparency. From the seller’s obligation to disclose known defects to the public database of all transactions, residential real estate makes the post Sarbannes-Oxley corporation look like the Iran Curtain. But compelling disclosure does nothing to ensure the accuracy or relevance of the data published. Since perception is everything in market-setting, it is very much in the interest of sellers to project the existence of high demand and a robust market firing on all cylinders. Nothing ruins that picture as evidence of price declines.

Because the entire history of the transaction including original asking price is conveniently available on MLS, it would obvious when the seller did not succeed. That sets a bad precedent, especially when identical units have to be moved. If the average cookie-cutter suburban development has 100 units and the first few go below market, the next customers in line will demand deeper discounts. Soon the builder is in trouble. Much better to inflate the selling price by throwing all types of incentives. Paying the buyer under the table by the way, is illegal, so builders need more subtlety, in the same way car dealerships charge exorbitant premiums under the “fresh-air-and-sunshine” package. Paying closing costs, throwing in extras and upgrades, in one case offering a car along with the house, are all examples of incentives that are not reflected in the recorded sale price in MLS and not visible to prospective buyers looking for comparison basis. (Here is another article from the San Diego Union Tribune on incentives skewing the data and how that impacts lenders.)

So one must turn to more indirect signs to measure the correction. Fore-closures are one gauge that can’t be faked or sugar-coated, but they reflect the worst-case scenario. Money/CNN now reports on another: the traffic on a website that helps home owners quickly sell their property. According to Florida foreclosure future shock, the House Buyer Network website guarantees a sale by pricing it below market (one would hope, based on an honest appraisal this time, instead of the equally inflated appraisals used to secure financing) and having a real-estate agent commit to purchasing at even lower price if no buyers are found after a specified time. Company president claims to have correctly called the correction in Phoenix, Palm Beach FL and two California counties ahead of time. Their next reading: Central Florida is in trouble, even though Gainesville, FL home of the University of Florida Gators still posted the fourth highest year-over-year gain of all US cities.

cemp

On Chinese gold-farming operations

Not everything originating from China is toxic or dangerous to your health but the economic dependency is under scrutiny more than ever. (In retrospect, James Fallows seems to have picked a particularly bad time for his July/August article in the Atlantic Monthly titled Why China’s Rise Is Good For Us.) On the virtual side of the trade, New York Times Sunday magazine published an article about gold-farming operations. These are the contemporary equivalent of sweat-shops where employees are paid to play online games. Specifically massively multi-player online role-playing games, or MMORPGs such as World of Warcraft. These games all share one key trait: users get to build “characters” over time, sometimes years. Characters gain experience and skill based on their exploits, and the newly acqui pred power open the door to more interesting aspects of the game.

Intended to approximate the competitive nature of real life, where hard work and persistence over time leads to results, or so the children are counseled endlessly, this naturally leads to a black market in developed game characters. While the idea of trading virtual characters did not originate in China (and eBay provided the early marketplace) the gold-farmers have industrialized the practice, churning out fully developed avatars in 80-hour work weeks around the clock.

This issue is full of interesting risk and business trade offs. First the buyer needs to trust the seller– and this is why established online websites with a history of delivering the goods has a competitive advantage over the one-off eBay auction. A virtual world meeting and perhaps a mock battle can prove that the character in question has the right magic spell but there is no element of escrow. After payment exchanges hands, the seller must release the credentials to the online account and this is where he/she can defect. Buyer has no recourse other than hoping to recover the payment by filing a dispute. In principle a trusted 3rd party can solve this system by temporarily holding on to the character until payment clears, in the same way exchange of valuable physical goods are facilitated by escrow agents.

Sellers face a different problem, namely that gaming companies have started cracking down on gold-farming operations. Large number of different characters played by same IP address in China is likely a dead giveaway of something sketchy. But farmers have come up with responses: instead of creating and developing characters from scratch, they agree to take over existing characters. Gaming enterprises have no problem targeting the farmed avatars but shutting down legitimate US customers’ characters is bad for business. (The author compares this to the drug problem: going after producers/suppliers/traffickers is far more politically wise than going after users.) Then there is the problem that some experiences can not be traded; the author cites WoW where groups of elite players get to raid dungeons in groups to recover loot which can’t be given away. But the farms responded by creating bands of mercenaries, 40 people playing at once, for hire by a novice seeking to storm the virtual castle, no battle experience required. Spoils go to the payer.

It turns out that gaming companies are not the only ones with missile lock on gold-farmers. Vigilante players have also banded together to opportunistically kill farmed characters. (Virtual death however is not particularly fatal to the economic well being of a farming operation, because the character can be resurrected with most if not all powers intact in a matter of minutes. But when you are punching the clock and getting paid in virtual-coins, that’s a dent in revenue.)

At the end of the day, gold-farming brings up the question of fairness. Games are not about skill alone; luck and circumstances often factor into it. But it offends people’s sense of equity when other players can get ahead by simply paying more. This is where games are supposed to be distinct from real life, where $$$ can be converted into advantage in almost any other arena. Influence of money in sports is undeniable: and the manufacturer of that expensive titanium driver would like to emphasize that. But the competitive spirit remains alive to the extent that correlation between budget and success remains low. Nothing delights the sports fan more than seeing the scrappy Oakland Athletics edging out the Yankees, or the dedicated rider on his ancient bike dropping a youngster pedaling away on a cutting edge carbon fiber frame during an intimidating climb. Even Barry Bonds owes his steroid inflated home-run total to the ufair advantage of better chemistry, not the unfair advantage of better venture capitalism. From that point of view, gold farming represents an unashamed attempt at buying one’s way into success. Not surprisingly some players are offendedp, others jump at the opportunity, meanwhile entrepreneurs in China find another way to increase US the trading deficit.

Why do the gaming companies care? They are conflicted. Farming operations do pay the online gaming fee after all. But lower customer satisfaction (from perceived inbalance) is one reason to act, and probably correct PR response. In reality they are probably more offended that there is money left on the table. After all the number of virtual coins and healing power of spells is nothing more than a bunch of numbers stored in a database that Blizzard Entertainment, the parent company, runs. If anybody should be getting paid to fudge those numbers, it is Blizzard.

cemp

Virtualization considered harmful?

First Gartner published a report in April arguing that virtualization– which the company had called a “mega trend” earlier– presents security risks. Now a more recent article in DarkReading suggests that it is not just Gartner consultants who share that opinion. In Security Fears Slow Virtualization, the website reports that about 50% of IT professionals who are either using VT today or considering adoption in the next 18 months believe it introduces new security challenges.

Among the respondents to the emedia survey, the chief security concerns were about virtualization patching and updates (32 percent), guest-to-guest attacks (27 percent), and the addition of new host software (22 percent).

This echoes the risk pointed out by the Gartner, which included the observations that network based intrusion detection/prevention systems do not have visibility into intra-VM traffic. (That limitation only applies when the VMs are on the same physical host.) Even stranger according to DarkReading, is the finding that the later an IT shop is considering implementation, the greater their security concerns. This could be interpreted in two ways. Either  there is insufficient information and the more people learn about VT– inevitably at the 11th hour when the project is going live– they become more comfortable. The second interpretation is a selection bias: the system administrator concerned about a technology is not going to deploy it anytime soon, so the answers are consistent with prioritization.

But backtracking for a minute, these articles seem to miss the bigger picture, namely that properly used, virtualization can be an important weapon for improved security. It provides compartmentalization between different components of a system running on the same hardware and does so with assurance greater than any other mechanism, including operating systems or constrained programming environments such as Java. For example, using a virtual machine to experiment with malware is standard practice among researchers. Many trees were killed over academic papers suggesting various designs that employ VMs to confine untrusted applications. Similarly, the paper When Virtual Is Harder Than Real pre-dated Gartner’s critique, pointing out the security challenges for virtualization in a much broader context than enterprise hardware consolidation. For example the authors noted that when VMs are used for mobility, integrity of the image becomes crucial because infection of a machine image is equivalent to a virus infecting a binary.  Bottom line is that few of these concerns are new. Virtualization can be (and has been) leveraged in ways that increase security assurance. Equally likely is a configuration that aggravates one or more existing problems such as patch management that get an added dimension in the context of VT.

cemp

Posting with Windows Live Writer

This is a first-attempt to post to WordPress blog using Windows Live Writer. Currently in beta, WLW allows using a native Windows application to publish to Spaces, WordPress (which is the platform underpinning RandomOracle), Blogger, LiveJournal, MoveableType and even SharePoint blogs for the enterprise-oriented.

Arguments in favor of posting this way? Rich-clients have more more polished UI, boast greater flexibility, and can function offline. But taking each of these in turn, the advantage disappears on closer look:

  • User interface– yes client UI is easier and more familiar than web UI but what is the complexity of the average blog post? It is neither War and Peace, nor a template letter with embedded macros getting mail-merged against a spreadsheet of names that calls for the 2000+ features in Word 2007. (Although familiar Office interface for editing tables is there for example.)
  • Similar arguments apply on the point of flexibility. Most of the flexibility gained by using a native client that has close integration with the OS is lost on the simplicity of the task.
  • Offline mode. This is probably the best argument to justify the heavyweight solution. Blogging UI has become more sophisticated– for example losing an entire post because of a connectivity issue or accidentally hitting “back button” is rarely an issue now. But when one considers blogging a type of interactive online communication, offline mode has limited value. Rarely does an article emerge with the author locked up in an office, ruminating on a subject out of his/her imagination. Posts are often responses to other blogs, track-backs, commentary on a recent article etc. and seeing all of that requires being online. So at best offline mode is useful when the author has all the relevant information collected (including hyperlinks) but has lost connectivity temporarily, for example during a flight. But for those temporary situations, there is Google Gears API released last month. It provides a generic offline capability for any web application, taking the wind out of the argument that smart-clients are necessary.

cemp

Fighting 419 scams, the vigilante way

It turns out that an interviewed with Chris Hansen of DateLine is not the worst thing that can happen to a Nigerian fraudster preying on victims on the other side of the world, with promises of getting a cut from non-existent fortunes hidden away in Swiss bank accounts. An article in the June issue of Atlantic Monthly looks at a group of volunteers who have taken art of fighting Internet scams to a new level.

Best exemplified by the site 419 Eater, these vigilantes turn the tables on scammers by playing the part of a gullible/greedy target, with the objective of causing maximum effort, wasted time or humiliation on the con artists. Some of the stories are familiar extensions of the To catch and ID thief TV series: the scammer travels a long distance to close the deal but the victim never shows up, or a payment promised never arrives after multiple creative excuses. Others border on the absurd: a photograph accompanying the article shows a Commodore 64 carved out of wood, by the enterprising scammer, tricked into believing that the victim is collecting items for his art gallery. In fact the self-styled “scambaiters” try to one-up each other with more outrageous exploits by getting scammers to send pictures holding up embarrassing signs, displayed in the Trophy Room. (Most comply, supporting the theory that when it comes to crime we catch the dumb ones. A few respond with amazingly awful and obviously fake digitally retouched pictures, which find a home in the Hall Of Shame on the same website.)

Revenge is good but in the collective frenzy over humiliating pwned spammers, the cyber-vigilante seem to have lost sight of the over-arching goal: reduce total damage from fraud. To the extent that the miscreants waste time and effort chasing scambaiters, there is some benefit because those resources are being tied up in unproductive ways instead of going after truly vulnerable victims.  That distraction is expensive because it also requires that the good guys waste their time keeping up their side of the story– although turning it into a competitive public sport with a web site seems to have turned up no shortage of volunteers. The basic problem is that once a scammer operation is revealed, including an authentic picture of the perpetrators, he/she remains in business. Future victims remain just as vulnerable to wiring money  overseas based on vague hints of a deposed African dictator’s hidden cash.

Parallel situation from phishing: flooding a phishing site with bogus submissions may temporarily reduce its effectiveness or pollute the database sufficiently to reduce the value of the ill-gotten gains. On the other hand, submitting legitimate credentials to a valid “honeypot” account and then carefully monitoring any activity on that account can protect other users. By design, any activity on the account is fraudulent and any IP address used for logging in is suspicious: all activity from that source can be screened to protect users whose data had been obtained in other unrelated scams.

cemp

Identity thiefs tag team with data-sellers to target elderly

In what may be the newest low-point in data-mining and marketing, first-page story from the New York Times last Sunday details how identity thieves are turning their attention to scamming elderly persons living alone, a particularly vulnerable group. This by itself would not be unexpected from the low-lifes hiding out in the comfort of their dysfunctional countries in Africa and Eastern Europe to target US consumers. But the disturbing part is how data-mining and aggregation companies are knowing aiding and abetting the criminal enterprise:

“These people are gullible. They want to believe that their luck can change and it’s just a matter of catching a bit of star dust.”

Comment over-heard on an IRC channel populated by carders?
No, that would be a quote from the official marketing literature for InfoUSA, which sells lists of consumers often collected by dubious schemes such as sweepstakes, where the true purpose of data collection, if disclosed at all, appears in fine-print.

The article titled “Bilking the elderly, with a corporate assist” details the story of one 92 year-old World War II veteran and Purple Heart winner who frequently received calls from telemarketers– and did not mind it, as they provided some solace for a person living alone at home. InfoUSA sold his name/contact information to scamers, who contacted him to extract more information using standard pressure tactics (“your benefits will be canceled unless you provide us your SSN/bank account # etc.”) and proceeded to wipe out his life savings.

This not an isolated incident, and the companies selling the author contends that the companies selling data are fully aware that they are being used by criminals. Quoting a Canadian police officers:

Only one kind of customer wants to buy lists of seniors interested in lotteries and sweepstakes: criminals. If someone advertises a list by saying it contains gullible or elderly people, it’s like putting out a sign saying ‘Thieves welcome here’

In fact internal company documents obtained by NYT show that InfoUSA executives were aware of suspicious activity but knowing continued to profit from the sale of information to criminals. The company has since then posted a response– which is nothing more than a transparent spin attempt, except for the allegation that NYT story is based on events 3 years old– but they could not be bothered to respond to the author who claims they were contacted by phone and email at least thirty times.

InfoUSA is not the only player in this disgraceful episode, published one week before Memorial Day. Wachovia Bank also profited from the criminal activity, hosting the accounts used by the scam artists, where they collected money withdrawn from victims’ accounts. (To the tune of accepting $142 million in deposits with unsigned checks.) Particularly appalling is the fact that often the victim’s bank would detect suspicious activity, protect its own customer and then contact Wachovia to urge them to shut down the accounts. In one case 59% of all checks from a company were returned, in each case Wachovia being informed of the rejection. No action was taken.

Not surprisingly Wachovia declined to comment on the story and issues a content-free statement to the effect that they are continuing to cooperate with authorities. Lesson learned: spin doctoring after a screw up is always easier than protecting customers in the first place.

cemp

Reputation on the web: puzzling persistence of comment spam

Reflections on the pingback and comment flood from 2 weeks ago. Most of the spam has been removed. In retrospect, three issues stand out:

  • WordPress should have stopped this in the first place. All of the track-backs point to the same website, there are multiple ones for each post. That screams “spam;” this was not a subtle attacker trying to stay under the radar.
  • Removing the junk is tedious. Even in mass-edit mode, only 20 at a time are displayed and there is no option to “check all” before hitting the delete button.
  • Marking the comment as spam seems to have no effect on deleting other comments from the same source. This is perhaps the most fundamental problem. Ordinary users do not switch between adding witty comments on one blog to hawking cheap printer cartridges on the next. If one track-back had been flagged as spam by the blog author, chances are 100% are. They should have been removed automatically. In fact if multiple unrelated blogs all flagged the same source as spam, this is a strong hint that future comments need to be blocked.

This is another case of the non-existence of online “reputation”.  It’s as if actions by the same person have no connection to each other. There are no consequences to having a comment tagged as spam or even being black-listed from a blog– miscreants are free to continue doing the same, on a different post.

Lack of a strong identity system is often cited as the reason reputation has not taken hold. A persistent ID is required to attach a reputation. Ability to get a new ID and start from a clean state when things go wrong is not good for accountability. (This is why black-listing email addresses was a pointless anti-spam feature to start with, at best window dressing dreamed up by email providers to comfort annoyed users. Email addresses are  easily acquired/fabricated. Black-listing IP addresses or entire domains is more effective.)

But in this case all the comment spam pointed to the same source. WordPress logs the originating IP address  for comments and links to a whois query, supposedly to trace spam back to its source. Detection and response capabilities are all good but blocking is far more effective.

cemp

Fuel prices and used cars

A growing number of articles are predicting that fuel prices will hit $4/gallon this summer. CNN/Money has recently joined the speculation with an article pointing out that according to one source a new nationwide record had been set last Sunday, exceeding previous $3.05 spike following Hurricane Katrina. It can only get worse from here: refining capacity is still  at historic lows. Meanwhile demand will increase over the summer as more families hit the road, in search of the perfect vacation.

It remains to be seen whether the higher prices will have any affect on the purchasing patterns in the automative industry. In the past, the price of gasoline defied economic theory: demand for driving and for that matter, gas-guzzling SUVs showed no elasticity based on oil prices. “People respond to incentives” goes the theory but during the late 1990s and early years of this decade, it was hard to see any evidence of that. That may be changing now. New York Times reported that in April GM sales are down 2% and Ford down 7%.

“Rick Wagoner, the chief executive of G.M., said during an interview on CNBC, the financial news cable network, citing gas prices that have topped $3 a gallon in many parts of the country as one reason.”

This excuse is slightly more credible than Krispy Kreme blaming Atkins diet for its lack-luster quarterly results. While Detroit can not control fuel prices directly, they should have felt free to adjust their own product line and manufacturing numbers based on projected trends. In the 1990s SUVs were the right business investment, as consumers paid hefty premium for the appearance of a vehicle ready to conquer the wilderness. But once global warming, talk of carbon taxes and higher fuel prices started, focus would have logically shifted to smaller, efficient passenger vehicles and disruptive technologies such as hybrids. (A well managed company is supposed to look ahead  and invest part of the SUV windfall in the next thing.)

A better indication of economic sanity restored to the markets may be in used cars. If fuel prices affect behavior, one would expect to see greater demand in efficient cars and by contrast, a shift away from the gas guzzlers. This is similar to the inverse correlation between interest rates and bond prices. Once hybrids start trading well above their blue-book price, there is an argument that cost of fuel is impacting purchasing decision.

cemp

Comments and track-backs disabled after spam flood

Yesterday was the Random Oracle blog’s turn to become targetted in a track-back spam attack. Each post ended up with a handful of track-backs to articles on the same bogus blog, which appears to be nothing more than an undigested collection of random paragraphs from different WordPress blogs.

Requiring a CAPTCHA solution with each comment/track-back would have solved this problem. Windows Live Spaces (formerly MSN Spaces) has this option. It is far more effective than the alternatives of allowing public commenting or requiring authentication. The latter is not a barrier since the underlying identity system is disconnected from the real world and has no reputation attached. Spammers can register one account, use this to spam hundreds of blogs and move on to start from clean slate when the ID is black-listed. WordPress controls on commenting are primitive by comparison. Ping-backs and track-backs can be disabled, comments can be disabled or held in the queue for moderation. Finally comments can bet limited to users who had a previously approved comment, which creates a boot-strapping problem. Proof-of-work by solving CAPTCHAs is much better suited to this problem: users serious enough to comment on an article will not mind taking a few extra seconds to solve the puzzle. Spammers will give up and move on to the next blog.

cemp

HD-DVD processing key and Internet censorship

More observations:

  • Attempting to suppress information after it has been leaked on the Internet is highly counter-productive. The heavy-handed tactics required to force the hand of web-site owners and publishes across the world only serve to draw more attention to the problem. This is a lesson that DVD Copy Control Association learned the had way with DeCSS.  But it should have been an obvious point to extrapolate from individual experiences. For example Outlook/Exchange have a feature to recall messages– but the “recall” works by sending another message which the recipient must first open, before Outlook will process it to remove the original one. Emails are often sent by mistake; to err is human. But sending a recall only draws attention to the original blunder and virtually guarantees more people will read it. This is because most errors involve sending a message to the wrong audience: not recognizing the subject line or sender, most  busy people may be tempted to ignore the message or file it away for later review. Send a recall message though, and suddenly everyone dropals their work and dig up the original. (Bonus points for sending an additional message on top of the recall: in 2004 an HR person sent email containing salary information to an entire building at MSFT campus. She followed up with a high-priority message admonishing people not to open the original, even kindly explaining the contents of the confidential attachment. )
  • User generated content cuts both ways. It can fuel a website, but it can also bring untold dangers in the way of legal risk. Digg is far from alone here– witness the Viacom litigation over copyrighted content posted to YouTube. This is the trade off associated with riding an economic externality in the form of getting your audience to build your business: the result is a t the whim of users. Trying to shape the externality by weeding out the negatives can back fire. It is difficult to build a sense of ownership unless users feel they can post their choice of content, as opposed to content approved by the omniscient moderators.
  • Commercial ventures have a lot more to lose than individual bloggers. Deeper pockets equals greater incentives to be litigated for perceived wrongs. Digg has decided to take a stand and ignore the C&D letters. Depending on your perspective, this is either a principled stand to be applauded, or unabashed grab for cheap publicity via corporate martyrdom. Developments over the next few days will be interesting. Already there is speculation on whether Digg has any legal ground to stand on. But either way, the decision to stop censoring the content would have been difficult to justify for any reason to an established company.

cemp