Monday, May 18, 2015

Bug Bounties: Wild West of Information Security

How the West was Pwned

While "bug bounty" programs are a license to ill for digital gunslingers, they must survive a wild west of shoot-first lawmen and a hacker hysteria that wants to hang 'em high.

Sunday, March 15, 2015

Priority Human Interrupt: A Robotic Imperative?

[This article proposes, by way of an oversimplified fictional UN resolution, a framework guaranteeing human safety and sovereignty in an age of autonomous robotics. At the end, I discuss it in plain language.]


United Nations Document #86065-63

Priority Human Interrupt Resolution

Enacted March 15, 2020

This resolution acknowledges the basic rights, safety, and sovereignty of humans as they relate to advanced technologies including but not limited to autonomous robots. In the interest of protecting those rights, participating members agree to observe and enforce a "Priority Human Interrupt Resolution" (PHIR).

Owing to the matter's technical nature, the focus of PHIR is an architecture, systems and protocols for compliant solutions in the engineering and commercial sectors.

The remainder of this document describes that architecture and its application.

PHIR Basic Proposition

Advanced technologies including but not limited to autonomous robotics can fail, or be operated intentionally or otherwise in such a manner as to infringe on basic human rights and safety. Under these conditions, such systems can be unable to halt the offending operation on their own accord.

These scenarios can put humans at great risk, physical and otherwise. Designed as they are under the constraints of economy and efficiency, these systems make no effort to protect humans from these risks.

PHIR-compliant technologies are designed in a manner prioritizing the basic rights and sovereignty of humans, above all other programming or directives.

Simplified PHIR Architecture
Systems and devices which are compliant have, at all times during operation, the ability to recognize a "priority human interrupt" - and to respond in the safest possible manner.

These capabilities are to be implemented in distinct and independent computational, electronic and mechanical channels, such that failure of the primary ("host") device can not impede compliance.

The diagram at left illustrates key aspects of the PHIR architeture.

PHIR Basic Requirements

The specific requirements for PHIR systems are presented as situations which call for immediate priority human interrupt. Compliant devices must detect these situations, and respond in the safest possible manner by immediately halting all operations, or turning themselves off.

Each of the following situations must initiate a Priority Human Interrupt:

  • Physical: The device must detect a severe physical contact initiated by a human. These should include slaps, punches, kicks, tackles, tipping, and rocking.
  • Projectile: The device must detect projectiles launched at it by humans. These should include such things as bullets, rocks, bricks, mud, and dirt as well as domestic items such as blankets or clothing.
  • Weapon: The device must detect violent contact with a inorganic material wielded by a human. These should include sticks, poles, clubs or bats, shovels and the like.
  • Verbal: The device must detect distressed, fearful or aggressive speech directed at it by a human, regardless of the language or context. These should include shouts, sustained yelling or screaming, and repeated commands of increasing volume.
  • Vulnerable: The device must detect humans under the age of 6 years, or weight of 34kg, and cease active operation of components with external physical surfaces. In the specific case of autonomous devices with mobile capability, this requires maintaining either a minimum distance of 15 feet, or a grounded inert position for the duration of the contact.

PHIR Opt-Out Requirements

Additionally, the following "Opt-Out" requirements apply to any device which collects or processes external data - such as visual, audio or location information - regarding any human, from any sensor that has not been explicitly granted permission to do so by that human.

Opt-Out requirements apply particularly to passive devices used in the consumer sector such as product scanners, point-of-sale systems, and image recognition systems. Individuals who wish to use their Opt-Out rights generate the PHIR Signal (described below). 

Compliant devices must detect the PHIR signal, and observe the following restrictions with respect to data regarding the signal source:
  • Anonymous: No identifying data is to be stored or processed.
  • Invisible: No visual data, including photographic, is to be stored or processed.
  • Mobile: No positional data is to be collected, stored or processed.
  • Silent: No audio data is to be collected, stored or processed.
  • Null: No digital data, such as financial data or product selection is to be collected.

PHIR Opt-Out Signal

To aid in the implementation of the opt-out requirements, an FM radio signal is to be allocated for the PHIR Opt-Out Signal. Compliant devices are required to detect this signal, and enforce the opt-out program in full.

Open-source circuits designs and software are to be made available, and citizens are to be permitted without license or authorization to generate the signal by any means available to them.

Illustrative Examples

Next-Generation Washing Machine
A mechanical consumer device such as a washing machine must include resistive and shock-detection circuits capable of recognizing repeated, forceful physical contact initiated by a human, and treating that as a priority human interrupt. It must respond to this signal by immediately ceasing all mechanical operations, and breaking all electrical circuits.

Point of Sale Facial Recognition System
A facial recognition system capable of correlating image data to human individual's identity must be able to detect the PHIR Opt-Out Signal. On receipt of the signal, the system must immediately discard any data collected, visual or otherwise, correlated to the signal source. Additionally, facilities must be made available for any person to validate the proper handling of this operation, and to be shown evidence for it.

Wedding Photography Aerial Drone
Whether operated privately, commercially, or autonomously, all mobile robotic devices capable of violating the safety, privacy or sovereignty of humans are to be held to the strictest PHIR compliance. A privately-operated aerial drone for wedding photographs, for example, must comply both PHIR Opt-Out requirements, as well as with all Basic Requirements.

Autonomous Traffic Data Collection Robot
A mobile, autonomous device exposed to the public at large and not under the operation of a human must adhere to the strictest PHIR compliance. Especially important in such cases are the Physical, Verbal and Vulnerable requirements.

Discussion

Okay, end scene. Now straight up, what am I talking about?

Yeah but neither do most humans
First-off: No, I'm not one of these "robots are here to kill us" nuts (are they?). Actually I'm certainly what you would call an amateur robotics enthusiast,having built plenty myself.

I'm also knee-deep in Genetic Algorithms, Evolutionary Computing and the other techniques behind this newest generation of "AI" driving cars, kicking your ass at video games and generally freaking everyone out.

I'm more likely to be accused of ushering-in a techno-apocalypse.

But hacking on this for a decade does give one perspective that probably isn't shared by the uninitiated. I won't go as far as Elan, yet - but he is correct about the speed at which autonomous systems can advance, all on their own.

Evolutionary Computing techniques don't work like the traditional machines you are accustomed to: They "learn" (sort of - close enough, in any case), and do so very, very quickly.

You may not be very impressed by an algorithm that beats a video game. But put in charge of an autonomous (possibly armed) drone, the effects will be devastating. You and I are much easier to track and fire upon than most video game targets.

Has already beaten my high score
You will not be able to evade a drone piloted by genetic algorithm. It will have simulated your next move millions of times before your nerves even signal your legs to run. It will have other weaknesses, yes - but not the sort that favor a 6-year old girl or 85-year old man, running from a malfunctioning surveillance drone gone amok.

I could (probably should) talk about this lots more, but I want to move on - so let's just assume that 20 years hence we'll have fast-learning, possibly armed drones and autonomous devices running about the streets.

But the thing that has always struck me as insane about this possible future is that, as advanced as these machines have already gotten, they seem completely incapable of relating to humans in the simplest terms.

I mean that literally - the simplest things are what our current machines are lacking. I don't really think it's important yet for machines to parse our speech to know what kind of tea we want. I'd rather they first mastered simply knowing that you are screaming at it, and it needs to stop driving over your leg.

This robot, for example, retains its upright position even when bombarded by basketballs. My question is this: Is that a good thing? Is it wise to make such a thing without precautions protecting, you know - us?

Definitely not PHIR compliant
How have we even started down the engineering path to machines that are capable autonomous action, but not of the simplest civility one would demand from, say, a domesticated animal?

Thinking on this for some years, I eventually came-up with the "Priority Human Interrupt" - the principle that automated systems must be capable of prioritizing basic human sovereignty and safety.

Technologically, it is a simple matter - trivial, in fact. In many scenarios $10-50 USD in electronics is capable of making these determinations, and cutting power or otherwise overriding an autonomous "host" device. The rough sketch I included here would cost about $100, but that's cobbled from commodity parts. A real electronics engineer could cram it into $30.

Given that is the case, should it be acceptable for a flying delivery drone, Internet-controlled garage door, or even an escalator to not know that a human being is being violated? If a human is beating on a machine, screaming at it - should it not know about this, and stop? This seems an increasingly serious gap in our traditional engineering approach.

Maybe it is a bit early for a PHIR movement. At the moment, most of these devices are far more vulnerable than we fear. I can't think of a single consumer-grade aerial drone, for instance, that could withstand an attack of bed-sheet-and-garden-hose.

Yes, I just now invented that countermeasure. See how formidable humans are? We are clever, sneaky, and sometimes just plain unpredictable. For the moment, at least, 200 thousand years of Evolution have granted us the upper hand.

How long that will last, however, remains to be seen.

Wednesday, March 11, 2015

Three Things Hackers Know That You Don't

[In this intermission in the "Personal Data Security" series, I discuss important key factors in the security landscape that the general public and media overlook.]

The Situation?
The situation is this: In an increasingly digital society, the forces of crime, espionage and anarchy have turned their attacks to the modern computing infrastructure.

Vendors and software developers simply can't keep up with the round-the-clock onslaught, as genius uber-hackers and cyber-terrorists write bewildering, masterful code that no one could have predicted.

Despite their best efforts, major businesses fall prey: Customer data is lost, all parties suffer equally. Curse you, demon horde!

Sorry, but - bullshit.

The Situation
These systems have never, ever been secure.

They were designed insecurely, because market pressures reward the release of the product far more than its security, the latter being basically invisible.

Increasing the security of an operating system, application, or device is mostly a matter of diligence - which means increased complexity. The code will be more complicated, as it checks for many "edge cases" that shouldn't ordinarily occur - but would be deadly if they did. All of this extra checking will slow it down. More time and effort must be invested to make it secure, but also still fast.

If life is good, you will never even know the difference. Because the condition is not supposed to happen, anyways. So that's a lot of extra resources invested in features that you will never know about.

Um, yeah...we're going to invest in that - and lag the competition to market. Real soon.

The Bottom Line is Still Tops
Do you get the "network inspection engine" part of the security product alone, or with the "security intelligence and monitoring" component - which doubles the cost. Can you live without the monitoring component? Probably. Should you? Clearly not. But of course the bottom line will usually win-out.

High encryption on everything, or just the "important" systems? Encryption slows everything down, which means you'll need more powerful computers (or routers, or VPN concentrators).

At every turn, the basic economies of business force almost everyone to the lowest common denominator - lest your competitor make widgets cheaper or faster than you.

Cutting close to the bone and running against an enemy of unknown size and force? Sounds like a heartbreak in the works, folks.

Fat is in the Fire
The systems are then deployed insecurely, owing to much the same corner-cutting dynamic.

Sometimes systems are deployed insecurely against the vendor instructions or designs. But often, no additional ineptitude is required: Many of these products bring with them inherently insecure architectures.

For example, most corporate LANs are overflowing with local (usually Windows) communications traffic and capabilities. If you are at your work computer now, there's a very good chance it's offering a wealth of totally superfluous network services - for file sharing, for example - that you never use. What's that you say? Close those unused doors and instantly decrease the "attack surface" dramatically? Great idea! (1)

Unfortunately, years of experience has taught savvy field admins that it is far more expensive to turn such things on "as needed" - usually an in person, i.e. expensive process - than to simply turn on everything they even remotely think you might ever use.

But even if you've never used them - and never will - there are people who can and do put them to use (and most of them are on IRC).

The implication that these weaknesses in security (which have lead to every single compromise you've ever heard of) are somehow endemic to the nature of modern digital business, is provably false. One may as well claim that scissors are just inherently dangerous, and running with them had nothing to do with one's gushing stomach wound. "We are mere victims!" they cry.

Each of these services acts a lot like a door. Some may be locked. Some have little more than an "Employees Only" sign. Others can be tricked into opening, because (guess what) someone didn't write the code to check for that trick. Because (guess why) it wasn't profitable.

Absolutely typical internet stupidity.
This proliferation of services permeates the internets: The computers inside them, their network infrastructure (2) - sometimes even the systems actually designed to defend this stuff.

Nearly everything, everywhere - running unnecessary services and other superfluous components that offer doors that don't even need to exist - out of ignorance, laziness, convenience, or financial expediency.

And you can add your phone to the list. (3)

Give Me Convenience Or Give Me Death
Security experts have long acknowledged that these compound factors make computing too variable to assume everything a machine is asked to do is actually safe.

The solution is limiting what users can do to "ordinary" tasks (say, computing a spreadsheet) and requiring special "super powers" to do crazy things like update Operating System components. Or install software that records your keystrokes.

Oh, hey, funny story: Remember when that IT geek came to install the new Office? Then you tried to print and it said you had to install a printer driver? You clicked "Ok" but it said you needed to be an administrator. Well, you caught geek boy (or girl)  and they said they'd install it for you. But you're no baby! Man, you gave them what-for. You must have administrative authority over your machine, right? Make me god, techno gopher! (4)

There's a very good reason that they wanted you to run as a "powerless" user. A powerless user is a safe user. Well - safer, anyway. Unix took this lesson to heart early, though it still falls to users to live by it.

And did someone mention digital death? Well...that would be my department.

Securing the Eggshell
Now you've got a network full of insecure operating systems, dialed-down to their weakest setting so you don't complain to the admins - who have given up, and are trolling Craigslist and playing Fantasy Football.

But we can still secure the network itself, right? You've got firewalls, and intrusion prevention systems, and web application filtering doohickeys. We can watch for foul play, and release the hounds at the first sign of trouble!

But at what sign? There is so much activity in and around a modern corporate or service network, it's like trying to hear a whisper at a Metallica concert (5). The subtleties of these architectures are now such that it requires an expert - in your specific environment - and armed with some pretty fancy technology, to distinguish between what is "normal" and what is not.

In the best environments, you will find this person (or persons) in and around the Network Engineering, Network Security and/or Security teams. They'll have spent sufficient time and effort - the company will have invested those resources - to know the strengths and weaknesses of the digital "castle" they have vowed to protect. They'll have the tools they need to monitor the chaos, and keep order. They are the cyber-knights of this chapter of digital security. Their story is for another day.

But these capabilities are expensive, and - when employed properly - have no noticeable impact. That's right: If we do our job right, you won't even know we do anything useful, at all. How's that for a selling point, huh?

As you can imagine, this doesn't inspire businesses - who are in it for, you know, profit - to spend a lot of money on security. Or like - any. And if they haven't been hacked, why should they? As far as they know, there's no actual existing problem to be addressed, yet. You try convincing the board to spend half a million dollars on "security intelligence" which hopes to discover - best case scenario - nothing at all.

Of course, as should be obvious to all by now, you either have been - or will be - compromised. You just don't know which, yet.

Regulations to the Rescrew
Wait, did I mean rescue? No. I definitely did not.

The situation is further constrained by regulations that, sadly, are designed to help. While the threat of regulatory penalties (6) help to balance the demands of running a business at the lowest cost against the expense of good information security, it necessarily inspires companies to prioritize the regulatory demands first.

First in the security budget are all of the things required to ensure the company does not fail an audit for regulatory compliance. Auditing systems, software and services will be bought, and extensive records will be kept. All of which does absolutely nothing to help secure the network, users or systems - but does a great job protecting the company from liabilities when the inevitable incident occurs.

No surprise, then, that there's not usually much left - in love or resources - for the mission of "riding range" in these digital badlands. And as a result, they're just about as rowdy and lawless as the real deal.

Bake Until Crispy
So that's the situation you've got. Inside pretty much every corporate network, most university campuses, nearly every service or vendor network that has anything of value to anyone, and also at a horrifyingly large percentage of important networks and systems that you would really rather not even know about.

For our younger readers: The Clash
That's the rule of the day, in the digital world: Overflowing chaos, mismanagement, and the absolute minimum investment required to cover one's own ass - "never mind the people" as The Clash put it.

In this morass, brilliant but too-small in number, dedicated but under-powered white hats, grey hats, and unhackers (hi!) are losing a battle against expanding hordes of an organism similar to them genetically, but of a lineage criminal, economically disadvantaged, or nihilist. (7)

Mea Culpa, Ad Infinitum
And all of this hand-waving from the businesses, vendors and services begging forgiveness when they lose your data? It is totally - and completely - bullshit.

They knew precisely the risks of the systems, applications and configurations they chose. Because their security people told them. There was a 30-page report. There were instructions on what had to be done and how much it would cost. It was all delivered, signed-off as "accepted risks", and promptly lost behind a filing cabinet in a flooded basement.

They run fast and loose because it is cheap. And that's business - you can't really blame them, any more than you blame car makers for not adding seat belts to cars until customers demanded it.

Nor can you blame them any less.

And that is really where the conversation needs to go: Business  must be held accountable to what amounts to a modern consumer's digital safety, with respect to their products and services. It is absolutely not sufficient, or acceptable, for them to simply fall on their swords and claim they were outsmarted by "genius hackers".

Because we know they were not: They were running naked in a world populated by flying, heat-seeking piranhas. And yeah, that's going to hurt. Unfortunately we are all bitten in the process.

Given that the capabilities exist to avoid these incidents, and they choose not to spend money they are not required to spend (big surprise), the now-accepted "oops, sorry" response is not even valid.

Simply put, it's just a cost-effective lie.

The current "digital contract" between business and consumer abandons you and your data to the tender mercies of the internets.

But this isn't new, is it? Isn't it really just the time-honored business classic known as the "screw you?" They cut the corners, you pay the price. I'm pretty sure that if we look at the history of capitalism, we'll find this situation doesn't usually resolve itself in the consumer's favor.

We're the ones that have to demand digital seat belts.

Why Three Things is Enough
That's really the only thing hackers know that others don't. The rest is just "geek trivia" - what code goes where, how some protocol works. None of these things, in their design, are supposed to be dangerous.

What hackers know that you don't is that the "information superhighway" (6) is constructed of eggshells, suspended on popsicle sticks and guarded by unarmed Red Shirts. (8)

The Hacker Secret is simply the reality of the chaos that you are already soaking in:
  1. Systems are not built as well as they could be, and code is not as secure as it could be, because those things cost money, and no one really sees the benefit. (9)
  2. It is all then deployed insecurely because it's easier and cheaper, and because you insist on installing your own printer drivers. Also Angry Birds.
  3. The people who could help, who are indeed your only defense, are negated by economic constraints, poorly equipped for the fight, and quickly being overpowered by sheer numbers.

Humans Are Stupid - But Computers Are Still Stupider
Computers are, even now, still utterly stupid. Hard-wired to obey any instruction alleged to come from their user, in their current form they will probably always be hackable (10). Future computing paradigms may well change this, but the problem we face isn't subtle or academic in any way.

The current security "standard operating procedure" for businesses is so fast and loose, that were it applied to their financial dealings, they'd be in jail. Tomorrow.

This aspect doesn't get much coverage in most media reporting, but you wouldn't expect it to. The corporate victims, paying the technical debt incurred by their shortcuts, would certainly love you to believe there is nothing they could possibly have done any better, in your defense.

Just ask yourself how often, in your dealings with for-profit business, has that ever - ever - been true?

And it's not a glamorous tale to tell, either. A super hacker outsmarting a Fortune 500 has got to be a more romantic story than - oh, say - just plain getting screwed over by negligent business practices, again, for (big surprise) an extra buck on the bottom line?

No, hackers - by and large - are not super-powered cyber wizards. Not that they couldn't be. They just don't have to be.

Because the target is soft as cream cheese. And no one is even watching.


Tuesday, January 27, 2015

Top 10 Personal Data Security Tips from a Hacker, # 10 - Cash

A Quick Disclaimer

Okay I'm really an unhacker, a subtle but important distinction we can cover later. For now, interpret it as meaning I have much of the insight of the hackers you love to fear - but am on your side.

I will also articulate further what I mean by "Personal Data Security", a concept I hope you take to heart: That the conveniences of digital life come with serious risks, which warrant the same rigorous caution you grant a 3,000 pound vehicle, or table saw.

And that this responsibility, of keeping your digital fingers free of the blade, as it were - is yours alone. Criminals are to blame, to be certain - and layers of corporate bureaucracies are, ultimately, the guilty parties.

But these are still your fingers.

So lets kick this off with a bang, and probably start arguments right away by strongly recommending that you...

Tip #10: Use Cash

What?! Gary want's us all to be robbed in the streets, he's mad!

No, I am not suggesting you waltz-around toting gangsta wads of cash - rather that you limit your risk, appropriately. Here, the risk is that your credit card or other financial account information could be captured. We'll leave the means of this "capture" unspecified, but will later explore in great technical detail how such things are accomplished.

Chances are extremely high that you do not live in an area where traditional muggings are common. If you do, you know better than I how much cash you can safely carry. But for most of you, the number of times daily that you are exposed to a "digital mugging" is much higher than for the real-world version.

So let's look at those exposures: When are they occurring? And are the risks being taken appropriate to what is being gained? This is how Corporate Information Security thinks, and it is time you start thinking the same way about your own Personal Data Security.

If you look at transactions for which you use your digital credentials (credit cards, debit cards) you will probably find that most are for fairly small-ticket items: A cappuccino and croissant, $6. A hot-dog at lunch, $5. A beer and chips after work, $8. Would it really be a significant risk to carry $20 or $40 in your pocket?

Learning to Think About Risk Exposure

And here's the important bit that has not been made widely known outside of the Information Security industry: Each of these transactions is exposing your credentials to potentially serious risk of capture. 

How much risk? Each time you hand your card to a vendor, data necessary to place transactions against the account is processed by their systems. What does that mean, "their systems"? Well, it could mean a tightly-secured network, closely monitored 24/7 by security experts. Or it could mean a rusty Windows95 PC in the back office, poorly administered by the store owner, infected with colonies of malware.

So which is which? It can be tough to be sure, but we can draw solid conclusions from simple, empirical observations. The size of the vendor, for instance: It is unlikely that Joe's Hot Dogs can afford a team of specialists to secure their systems: Joe does it himself.

And how about Joe? Does he seem the computer-savvy sort who would know how to safely handle your transaction data? Maybe not.

This might be a good time to just buy your hot-dog with cash.

In It Together: Your Risk and Theirs

Another factor you should consider is the level of exposure to risk shared by the vendor. How motivated are they to secure your transaction data? It is not unusual for vendors to keep transaction details for days, months or forever. Your data will be at risk during the transaction, and possibly long afterward.

Is Joe's exposure to this risk as high as yours? I'm sorry to tell you that it is not.

We're all familiar with the public announcements of compromises at big name vendors (HomeDepot, Target) - but what compromises occur with smaller vendors? We don't know, and there's a reason for that: Companies of a certain size are required by law (or other constraints) to disclose these incidents. That is not necessarily so with Joe's Hot Dogs.

With these factors in mind, it should be clear that each digital transaction - online or offline - is a new instance of risk exposure for your data. It should also be obvious that it is wise to limit the number of these instances, and one of the easiest ways is to replace low-ticket digital transactions with good old-fashioned cash.

You may also have drawn conclusions about which vendors you should trust with your data, and it should have something to do with the level of risk you and the vendor both share. This is smart, and is an aspect we will explore at length, later in this series.

About Personal Data Security

Okay so what is this "Personal Data Security" I keep going on about?

Quite simply, I'm suggesting that you need to start thinking about your own personal data assets in the same way as corporations have for decades thought of theirs.

Modern businesses must expose themselves to serious security risks, in order to do business. They cannot circumvent the issue as easily as you and I. Risk is accepted as part of doing business.

But they make sure they understand what the risks are, what can be done about them, and - most importantly - the potential for financial loss in each case. This, by the way, is what unhackers do during the day.

From this, businesses make informed decisions about which risks are worth taking, and which are not. Using this "loss expectancy" insight, they determine how much effort should be invested in securing against a risk, and at what point a risk outweighs the potential benefits.

In your Personal Data Security too, risk cannot be completely avoided. But understanding this dynamic will tell you that the convenience of paying for a hot dog with a card is not sufficient to expose your account data to risks which could lead to serious losses.

Welcome to the Jungle

For the moment, digital commerce is a jungle: Until it is as secure as its real-world counterparts, modern consumers (that's you!) must learn to be aware of the risks involved, and make logical, informed decisions about when those risks are appropriate.

Up Next in this Series...

Coming up (in no order): Devil You Know, Lose Your Stuff, Hedge Your Bets, Fancy Gadgets, Your Friend 7-11, Going Schizo, Uninstall It, and Fake Everything. Yes those are all real article titles.

Sunday, January 25, 2015

New Tricks for an Old Blog?

I've been wanting to write on a few new topics, so this now ancient and disused blog will be taking a dramatic turn.

Stay tuned for new articles on . . .
  • Unhacking: That is to say, not getting hacked.
  • Information Security: In general, that is.
  • Making: This will be a nice place to write about works-in-progress, before they become articles on my main site
  • Genetic Algorithms: A topic in which I'm increasingly active.
  • Android: And Java and Perl and Linux, and other code stuffs.
And probably a new title.

You can probably ignore the ancient archive content, unless you're interested in what the Virtual Worlds industry looked like in 2009.

Next up: "Top 10 Personal Data Security Tips from a Hacker"

Saturday, January 09, 2010

Virtual Worlds: The Next Ten Years.


It's true, I do my (un)fair share of mocking these yearly predictions. But here's my promise: I will only do this once a decade.

So you won't see another of these until 2020. At which time I may be posting via my brain implant, from my space ship orbiting Mars. But that's another story.

As to my perspective, I've been living in Second Life since June 2004 when it was a lot more primitive (see screenshot), and I run The Wishfarmers. 'Nuff said.

So here we go (drum roll), a few predictions for virtual worlds over the next decade.


2010 to 2013

1. In a fading celebrity's publicity stunt, they'll announce they're marrying someone they've only known in a virtual world. This person turns out to be impossibly beautiful, and the stunt blows up in their faces. But the publicity will finally catapult virtual worlds into the mainstream consciousness.

Alternate: Politician instead of celebrity.

2. Machinima: That's really all I need to say about that one!

2014 to 2016

1. Virtual worlds are more popular than video games.

2. Very few games or virtual worlds are still "shipped" with player characters. Users instead log-in with their global account, and their avatar is automatically rezzed-into the game. Most users have a variety of outfits for different settings (Fantasy, Sci-Fi, Realistic) and a cottage industry of specialized "avatar stylists" has reached $3bn annually.

3. With the exception of unique "3D artisan crafts", nearly all 3D virtual goods are free. Large "content publishers" buy-up most 3D content for popular platforms, brand them for their advertisers, distribute them to users and charge advertisers. The world's most popular virtual t-shirt is worth $300m in sponsor revenue annually.

4. Meanwhile, "Virtual Fine Artists" use technology to create 3D works of sculpture and interaction that have unique value - Richard Branson buys an important virtual sculpture for $1.2m.

5. "Something Awful" creates the first worldwide virtual experience meme, a simulation of being kicked in the face by Chuck Norris.

It is soon available for every conceivable platform.


6. People do not recreate meetings virtually, because that is silly.

But they do use advanced 3D environments to interact with and visualize data, objects and processes collaboratively, because that is productive.

The most advanced I.T. departments have a team of "3D geeks" for simulation systems administration, development and virtual asset management - giving rise to a new form of Uber Geeks with crap on their heads.

2017 to 2020

1. Anywhere you are, you can see the avatars of most people around you - through your phone, or on your tricorder thing - whatever.

At discotheques, giant screens display the crowd as their avatars. Movie theaters show the audience, seated as their avatars, during intermission.

As an unfortunate side-effect, "Hey babe I dig your polygons" is a common pick-up line. It never works.

2. Most business cards have a picture of the owner's avatar - probably animated. Tattoos of avatars, also, are not uncommon.

3. Few people's avatars look exactly like the person they represent. Because that is boring. Those who do are called "standers", because they also tend to stand rather than fly.

Among the cornucopia of avatars that make up the metaverse, approximately 600 million are Furries.


Who Are The Wishfarmers?

The Wishfarmers LLC is a small California design and development studio innovating for virtual worlds since 2004.

Check us out at wishfarmers.com, and let's talk about your crazy ideas!


Monday, December 28, 2009


Virtual Goods versus

Virtual Goodies


[This article is also available as a PDF]
You've probably been hearing a lot about "virtual goods" lately. These are micro-luxuries - small indulgences - that comfort us in lean times - but now they are virtual, existing in social networks, and emerging "virtual world" platforms.

But virtual goods (and their uses) vary a bit more widely than is usually reported in these articles.

The term is applied in relation to companies ranging from Zynga - who profit directly from user micro-purchases - to IMVU, and Linden Lab, whose business models rely on a symbiotic relationship with user content creators.

In virtual worlds like Linden's "Second Life", these goods can take the form of almost any kind of clothing or accessory, vehicles, custom toys and pretty much anything else you can dream-up (and quite a few things you never would).

But if you've been wracking your brain trying to figure out how to sell a virtual version of your "real-world" products, just stop.

And start making something cool. Then give it away. For free.

Why Virtual Goodies Make Great Schwag

Obviously, once virtual goods are created, it costs nothing to reproduce them. In most cases, you can give out hundreds (or thousands!) as easily as just one.

Now, if you could afford to give out goodies to everyone on the street, just to promote your brand / product / bake sale - you would, right?

Well, now you can. Sort of.

No, of course I won't try to tell you that a virtual t-shirt is the same as real. But by now you've understood that these virtual luxuries have their own, specific value. If not, go read some of these articles and come back.

The point is that you can now afford to give away something that really does have value to the audience.

And this isn't just some pretty (though ultimately useless) brochure, or coupon for next Tuesday - it can be a favorite hat in someone's virtual wardrobe, or the central component in their virtual living room.

In other words: Something they see and/or use often.

Now all you need is to make sure they think of you when they use it.

How to Make Cool Stuff Relevant

Okay sure - maybe that sounds a little easier than it is. Lots of people do need help making cool virtual stuff, but there are always talented folks to lean on if you haven't got the time or chops to make your own content.

But the real question is what sort of virtual goodies would work best for you. It's something you must invest plenty of your own thought in, first.

The best promotional goodies relate naturally to what they promote: If you've got a business that lends itself to this (a shoe store), then the right promo may be obvious (virtual shoes). Other cases may not be so easy, but it is worth the effort to dream-up something that will best represent your brand out in the (virtual) field.

In Second Life, virtual goodies tend to fall into these categories:

  • Clothing and Accessories

  • Functional "Gadgets"

  • Toys (including Games)


While clothing and accessories are always wildly popular, useful virtual gadgets for Second Life also have great sticking power: Residents make extensive use of Twitter relays, job search tools and other gadgets.

And if they like it, they will remember your brand.

Finally, never underestimate the value of pure enjoyment: These platforms are great for delivering small, fun toys and games. These can really help you connect with users, even if it bears only the slightest relation to your product - as long as it's fun!

Depending on the type of schwag, there will be opportunities to include links to your websites, logos, or other branding. Take full advantage of this, but be tasteful about it.

The important part is to make it something worth having - and you've got yourself a first-rate freebie.

Laughing in the Face of Capitalism: Giving It Away

You will be surprised to learn how easy it is to distribute virtual goods for most of these platforms.

For example, with virtual goodies for Second Life, you have the option of making them freely copyable - meaning anyone with your promo t-shirt can give a copy to another user.

Think about this for a moment: It has incredible implications. Your promotional material now spreads in the same manner as free software. For as long as it remains worth having, people will be sharing it.

That beats the lifetime of most other advertising media, by a long shot.

Another great venue (for Second Life) is provided in the form of XStreetSL, now the official shopping portal. Users browse XStreetSL, choose and buy virtual products, and have them delivered directly to their avatar.

And, as you might imagine, free stuff sells very well.

Using XStreetSL, you can set up a vendor presence for your campaign, complete with a catalog of your virtual goodies. Now users have instant access to your virtual schwag, always.

Your cost: $0.

The Real Value of Virtual Good(ie)s

The real value of virtual goods to most initiatives is as a direct promotional vehicle. In this regard they offer some truly unique advantages.

They are a no-cost promotional venue, with no real distribution overhead, through which you can give infinitely copyable virtual goodies.

You see - I told you this was awesome!


Who Are The Wishfarmers?

The Wishfarmers LLC is a small California design and development studio innovating for virtual worlds since 2004.

Check us out at wishfarmers.com, and let's talk about your crazy ideas!


Wednesday, November 19, 2008

Wishfarming Real Jobs in the Virtual World



Jobbit Intro Clip on Wishfarmer TV

The Wishfarmers have just released the Kelly Services Jobbit - a simple and effective job search aid for Second Life, that combines Kelly's extensive job listings with unique perks for the metaverse.

The Jobbit is an example of how virtual worlds offer some really new approaches to user engagement. While there has been a lot of focus on virtual "installations" that users can visit (and that plays a role), there are still many other unique opportunities.

One of these is the chance to "ride along" with users in their daily virtual lives - by providing a utility that they use, and will keep at the ready. The key is simply to provide a real, practical value - without getting in the way.

With the Jobbit, The Wishfarmers achieved this in the form of a "Heads Up Display" (HUD) that attaches directly to the user interface. Users can configure it simply with statements like "chemistry in chicago", and apply for jobs they find with just a click. It then monitors the search, and alerts them to new job postings.

We also came up with a virtual twist on the idea of a hot lead. Users can "beam" any job they find to other nearby avatars, sending them right to the job posting. For your jobless virtual friends - the ones always borrowing L$ from you.

This is just one way in which these emerging platforms (Second Life, Opensim, Croquet, etc) can be used for outreach, and engagement and - yes - marketing (the M word) - in forms from the mundane to the exotic.

And honestly we're really just getting started here. So stay tuned.

Drop us a line any time.

Thursday, August 21, 2008

Conspicuously (Conveniently) Absent?

Yet to Ride the Virtual Worlds Wagon

So here we are, in the second (or perhaps third) wave of virtual worlds evolution. We've seen some successful early adopters - and some case-study worthy failures.

And yet, there are still some almost obligatory entrants, which remain conspicuously absent.

No, I'm not talking about the fields we all know are still emerging (such as education) or not yet supportable (gambling, or banking). I'm talking about the businesses that, given the constant flow of announcements, we really might expect to see in a virtual world by now.

For example...

1. Where is the Avon Lady?

I simply can't believe that the Avon lady is not yet a fixture in all of our worlds.

The timeless salesperson of "hope in a jar" translates as well into any virtual world as into any region in flat land. Did you know there are over 700,000 Avon ladies in Brazil? I have not seen a single one in Second Life, nor anywhere else virtual.

Some of you are laughing now, but am I joking?

2. Grocery stores

If you've followed my posts (and The Wishfarmers) you already know I am not about to suggest that grocery stores are a good candidate for virtual worlds. On the contrary, I think they are extraordinarily bad - possibly second only to soft-drinks in the dire prospects of connecting with the audience.

But that alone doesn't explain their absence. Plenty of ill-advised campaigns have been undertaken on behalf of even less relevant products.

So where are the virtual shopping carts to complicate my essentially web-based purchase? I don't want to see it - I just want to know where it is.

3. Heavy Metal Music

Businesses in other musical genres have taken the leap: Where is the hairy, ear-splitting mosh pit crowd?

Yes, I'm dead serious: Metal is big business . . . very. Three of 2007's top 10 albums were heavy metal.

Do metal-heads just not like virtual worlds? Do they even have computers?* Perhaps they're simply waiting for a virtual world they can operate while plastered.

Platform developers: Please remember to include the staffs of "Cream" and "Kerrang" in your product test cycles.

4. Oprah

Actually, this is not a business - it's an autonomous nation-state.

We can only presume that the reason behind this absence is the imminent debut of The Opraverse.

5. Viagra and Those Other Pills Too

Again, I'm not advocating this, I'm just saying: I'm relieved that one of these hasn't sponsored some gigantic phallus hat yet.


Barriers to Entry: A Blessing in Disguise?
I suppose we will simply remain grateful that some of these have never made it past the login screen. Particularly that last one.

If I've overlooked an implementation that conflicts with this, drop me a line - we sure wouldn't want to miss one of these glorious milestones!
*Psst: Yes, some of us do have computers.

Shameless Plug

Are you Slayer? Dudes, call us. That would freaking rock!

Are you Oprah? Please call us, ma'am. Yes that would be quite nice.


Innovations - not decorations



Thursday, April 24, 2008


Sorting, Scoring, and Avatarism
A Wishfarmer Labs Research Brief

This article is also available as a PDF

What is Sorting and Scoring?

This term isn't being used to refer to any specific systems, but to processes both manual and automatic which attempt to sort individuals into groups, based on some linear measurement. The form that these take depend on the objectives.


Sound obscure? It's really not; Here are some everyday situations in which individuals are scored, and sorted:

  • Being scored on SATs, and sorted into a college

  • Being scored on resume key words, and sorted into an employers hiring system

  • Being 'scored' on age and color, and sorted into a penal sentence category

There's nothing insidious about the process; It's a normal side-effect of trying to manage large numbers of people. While we all acknowledge that everyone is different, “everyone” and “different” work out to a very large number of things to think about. The larger things get, the greater our need to flatten them into something simple enough to take in all at once.


But are these aspects of size and diversity really at odds with our ability to comprehend? After all, we managed to navigate the forest, surrounded by thousands of unique life forms, without tripping over ourselves. Most of the time.


Maybe, instead of looking to logical simplification (and sorting) to help us here, we could look backward to nature instead – and benefit from the robust technology that we call “looking at something”.


How? By re-purposing a familiar method of symbolic personal representation, as a visual and psychological model for thinking about the evaluation (scoring) of individuals?

Spreadsheets, Avatars and Eyeballs

The shift proposed here is similar to that introduced by the first wave of accounting tools in personal computing, such as “Lotus 123”.


These were the first to offer advanced graphing capabilities to the general public. By providing a new way to visualize complex data, they enabled users to think at a higher level, applying their entire analytical engine (brain) to all of the data at once.


This was a huge leap in the Average Joe's ability to comprehend complex data.


Sorting and scoring systems measure (and represent) individuals as columns of numbers and attributes: Years of something, rating of something else. But this doesn't support a high-level evaluation considering the whole.


What we want is to represent individuals in the way best suited to the human animal: Such as looking at on another with our eyeballs.


The concept we need here is the “avatar, and it has been a fixture in computer games since their invention (and even board games before that). It is second nature to modern users as a model for personal representation. The concept is no longer confined to games, and is now a common element in communication programs, social networking systems and virtual spaces.


Users are already familiar with the avatar as persona, and with the concept of various inventory items with unique attributes. For most, these are simply natural.


Some of the common properties of an avatar that lend themselves very well to the purposes of subjective evaluation are:

  • Avatars may have inventories of objects collected from their past

  • Avatars may have points, levels, or other measure of experience

  • Avatars may have personalizations selected by the users they represent

  • Avatars may attach or “wield” items representing specialization, or training

  • Avatars can have special skills and strengths in standardized categories


Most importantly:


Avatars represent a large amount of information at one time, and in a natural visual context.





With the ubiquity of avatars in instant messaging and social networks, the re-application of these concepts toward serious work should no longer be seen as novel. It is simply a user interface upgrade.

Benefits of Avatars in Sorting and Scoring

  • 1. Builds into the system a recognition of the wide diversity of backgrounds, strengths and challenges of individuals.

  • 2. Builds into the system a recognition that no single “asset” (positive or negative) represents the entirety. This premise is communicated to both subjects and consumers through this choice of visualization.

  • 3. Supports quantitative scoring, but works to counter the negative effect of “direct numeric comparison” by encouraging subjective thinking that considers the whole.

  • 4. Immediately recognizable to both subjects and consumers of scoring systems

  • 5. Encourages realistic profiling. A horse-mounted rider in a scientist's lab coat, wielding a wrench in one hand and a broom in the other is visually nonsensical. Concepts such as “inventory load” can also be applied to further re-enforce this message.

  • 6. Upgradeable. New measures can easily be added, either in a monolithic “formal” system or in small “local systems” such as a rehabilitation setting.

  • 7. Universal reach: The concept is readily accessible across cultures and age groups

As Next-Generation Scoring Representations

For users (“subjects” of scoring systems), a very new and natural way of representing themselves and their professional and personal history visually. Functionally, this could take the form of a user interface for “dragging experience” onto a visual representation of themselves.


For consumers of scoring systems (such as employers), this could take the form of visualizations of applicant pools. For example, a crowd (literally) of their available applicant pool, with representations of people conveying their personal and professional attributes “at a glance”.


For educators, this could be an engaging way to invest young people in the development of their educational and professional careers. Applications could allow students to maintain avatars representing both their current and future (desired) selves throughout enrollment. This functions as a very complex sort of “string around the finger”, but on many dimensions at once. An visual representation of an idealized future self is much harder to forget than a list of resolutions for the new semester.

As Personal/Professional Development Tool

As a browser-based system on corporate portal, representing the employee as an avatar, equipped with items representing previous experience and inputs, as well as personal elements and representation of where they are “headed” in their career.


As “target avatars”, idealized profiles of a model employee for a certain position, or of specific improvements for an employee.

As Next-Generation Professional “Curricula Vitae

Targeting the developing convergence of virtual worlds and popular culture, provide tools and standards for representing professional and non-professional recognitions. Example: Red briefcase representing a verified (accredited or otherwise) project management aptitude.

On Implementation: How Might We Get There?

Technologically, we're really not talking about changing the way that mountains of data on individuals is organized, or stored electronically. As previously suggested, this is a change to the way individuals are represented and, as a result, the way they are thought of. All that is needed to support that are a few bits of extra data, and the means to interact with them.


A foundation of basic technologies could speed adoption, so a few of those possibilities are considered here.

Open Source Distributed Asset Type Catalog

Think: Domain Name System (DNS), but for “personal assets”.


A distributed, hierarchical database of attribute types and their visual representations. The “Professional” domain might contain thousands of standard representations for things like jobs, skills, certifications, etc. Obviously there would be a huge Hobbies domain.


Open-Source Avatar Data Format

Think XML, for standardized “avatarism”. Loosely-defined and extensible, a minimal specification for packing up data about avatars would allow developers to easily write client applications, and would promote the growth of large collections of avatars.

Software

Think: Flash API, but for representing avatars.

With a minimal set of routines for displaying the visual elements that comprise an avatar, developers could easily add avatar support to their applications.


Resumes could move quickly into an interim “hybrid” phase, with the addition of simple ActiveX controls (for example) that display an applicant's avatar among the traditional flat resume.


It's Only a Model

This does not change the mechanisms of scoring and sorting, either current or future.


This is a simple “baby step” change, specifically targeting the “front end” of the societal process of sorting and scoring individuals. Its aim is to (slowly) inspire a change in the way people think about the meaning and application of these systems, whatever form they take.

Shameless Plug

Are you interested in pursuing some of these ideas, or related concepts, or something completely different?


Are you looking for a dedicated team combining both inspired creative designers and world-class technologists? Do you need a team like IDEO, combined with a team like Xerox PARC, who is still cool enough to understand the relevance of both?


Do you want to hire someone to turn your drawings of stick figures on napkins into something you can blog about?


Stop nodding your head to a computer . . . and come talk to real people about a virtual world.


The Wishfarmers

Wishes outside. Realities inside.



Wednesday, April 23, 2008


Next Generation Virtual Television
A Wishfarmer Labs Research Brief

Also available as PDF or HTML

What's a Virtual TV, Anyway?

Currently, virtual television is the television-like experience, presented in (or from) virtual worlds. Sometimes audiences sit "outside" (in their web browsers), and watch events taking place "inside" (somewhere like Second Life). Sometimes they are inside, watching content "from outside", that may have been created traditionally - or virtually.


It sounds interesting . . . and it is!

But it could be so much more.

Assertion: Virtual Television Does Not Yet Leverage Metaverse


Existing incarnations of virtual television do not yet take advantage of the unique capabilities of the metaverse.


This is not due to audience preconceptions: Audiences are eager to be engaged in innovative new ways.


The currently limited interpretations of this medium stem from knee-jerk replication of the traditional broadcast media model. To take things to the “next level,” we have to throw that away, and go all the way back to the real objectives.


What should the objectives of virtual television be? Well, as we see them:

  • To be highly visual, and to be animate

  • To entertain, amuse, interest, inform, engage

  • To be communicable (be a “spreadable” medium)

Barriers to Innovation: Mostly Conceptual

Let's examine the key elements of current incarnations, the false barriers to innovation. Toss these:

  • The “view screen”: The traditional concept of a flat ‘screen’ as viewable area need not be observed in a metaverse. Chuck it, and start over from scratch: What would a ‘view area’ be like, if television had been invented in a metaverse instead?


  • The “speaker”: Similar to the screen, there has always been an ‘audio signal’ alongside the video. In the real world, this is always been linear: You don't tune the video to news, and the audio to heavy metal (well, we do). You also don't complain about the plot twist, and hear someone in Italy respond. Explore these possibilities.


  • One-way model: Arguably the root of all the conceptual obstacles, real-world television is presumed to be primarily passive on behalf of the viewer: Content comes in, and they consume it…period. Old-school media hacks (ex: dial-in vote) don’t even scratch the surface of what could be accomplished in a metaverse. This is the most obvious direction of innovation, but is also the largest frontier. Read Stephenson’s “Diamond Age” (regarding “racting”) for inspiration.

What follows are some very rudimentary techniques, all of which are feasible in one form or another. Some require only changes in the way things are done - most require both that, as well as some clever technology. Some may require audience ‘education’, but more than likely metaverse audiences would not have any problems adjusting.

Road to Innovation

Most of the ideas presented here relate to virtual television being viewed inside a space like Second Life.


It may be hard to believe right now, but this diagram may help you make sense of the following discussion (click to open it in a new window).

Effects++

Let's go back to the old standby: The ever-mighty pie-in-the-face.


Wouldn’t it be cool to “throw” a pie at the virtual camera, and have it “come out” of the other side? And what if they could throw one back? Funny, huh? Well wait till someone loses an eye, then it won’t be funny anymore.


Now skip past food fights to Real Applications: A public seminar including analysis of some set of statistics. The presenter skips PowerPoint-like slides, and is using a live graphing object that illustrates his topics. But instead of simply showing this, each screen also provides a remotely-controlled copy of the same graphing gadget, for viewers. Now everyone has their own close-up private presentation, live. At the end, a signal is sent from the view screen to destroy the display objects.


There are many creative avenues arising from this which are not even touched on here. Explore them.

Audience++

Get out your copy of Neal Stephenson’s “The Diamond Age,” and refresh yourself with the concept of “ractives”: Clustered, semi-interactive single-user movies where viewers fill the role of the main character, usually for key story junctions. Yes, “Dragon’s Lair,” in a sense – except that many of the character roles are filled by professional remote actors.


These also come in multi-user versions, where a single live broadcast is still viewed by multiple audiences – but at key moments, there are opportunities for audience interaction.


This is also similar to various sci-fi ideas that have been around since the 1960s, such as the futuristic passage in Ray Bradbury’s “Illustrated Man” in which one character sits in front of a large television watching a serial. At a key point, the actors turn to the camera and say “What do you think we should do, Margaret?”. A light above her television indicates that she is now ‘live’. She stumbles, but eventually speaks in character, and the actors turn away from the 4th wall and continue the scene, changed based on her input.


Worth noting: Bradbury anticipated here the need to ‘dumb it down’ a bit. Not everyone is prepared for live improvisation, but even rare brief interactions greatly improve the “potato” effect of traditional TV.


Immediately after her “scene,” Margaret’s phone is buzzing off the hook, friends all congratulating her on her micro-role.

Taking this to the next level still, consider interaction between viewers.


Here is an example: In today’s episode of “Metasleuth,” a fiendish fiend has stolen the hero's mojo. With investigations mired, the cast turns to the entire audience: “Can you solve the crime for us before the deadline in 1 hour?”


An “investigator’s kit” is delivered to viewers from the view screen, including a small CB radio used to communicate with other viewers of the show. It also includes the necessary clues, such as a lead pipe, or candlestick, or whatever.


While players race to solve the crime, the stars of the show eat lunch, engage in small talk and occasionally look at the 4th wall telling the audience to hurry up because the hero's mojo expires soon.

Screen++

The astute reader will already have recognized the potential to actually change the “screen,” from capabilities already described. Not only can the video surface itself be changed in real-time, but objects linked to (and nearby) the screen can be controlled by various techniques.


Combined with the ability to rezz objects on demand, this supports dynamic “set dressings” for the view area – deployed and changed, on queue.


For example:

  • 1. During the previously-mentioned presentation covering statistics, the viewer itself can be instructed to provide UI elements such as a button to get a copy of the raw data collected by the presenter.


  • 2. The screen could make use of various kitschy effects such as shaking, bobbing, twisting, which occur in response to control messages from the director.

But that’s just kid's stuff. Let's take it to the next level:

  • 3. During an episode of an in-world serial, the screen rezzes an ocean surface floor, a few low-flying clouds, some seagulls and a tiny desert island to sit on – to go with a the theme of the show, where the protagonist is stranded on a desert island.


  • 4. During a newscast about current RL events, the screen rezzes three walls to form an enclosed “room.” Each of the new walls is a display panel set to show a series of textures – photos or graphics related to today’s news coverage

Of course, all of these ‘scenes’ destroy themselves when they receive the appropriate signal. Keep in mind that any of these objects, rezzed by remote, could be as simple as a floor panel, or as complex as a functional, animated device.

To Be Concluded?

It shouldn't take much to improve on the “real world” version of television, because – let's face it – real world television sucks.


The dimensions in which the “medium” can be expanded, in the metaverse, are dizzying; But we needn't be dizzied.


Just a dash or two of the abundant virtual “spice” should be enough to get started in a big way.

Shameless Plug

Are you interested in pursuing some of these ideas, or related concepts, or something completely different?


Are you looking for a dedicated team combining both inspired creative designers and world-class technologists? Do you need a team like IDEO, combined with a team like Xerox PARC, who is still cool enough to understand the relevance of both?


Do you want to hire someone to turn your drawings of stick figures on napkins into something you can blog about?


Stop nodding your head to a computer . . . and come talk to real people about a virtual world.



The Wishfarmers

Wishes outside. Realities inside.