Private Email to Foil the Snoops – ProtonMail Review

As we’ve been learning over the past few years, privacy has been getting the thousand cuts treatment. Everyone’s been in the act. Et tu Google? You betcha.

Fortunately, you can stop inadvertently BCC’ing Google, the NSA, the Chinese government, hackers, marketers and other creepers of your personal content. That’s thanks to some good people who actually live by the mantra to “Do No Evil” who have created ways for email users everywhere to keep their messages between them and their recipients.

Over the past week, I’ve been exploring one of these, ProtonMail.

The True Cost of Free Email

Most email services are profitable because they sell everything that you type and attach in your emails to marketing companies. Vast profiles about you are generated from this content. Think about it: what diseases you talk to your relatives about, your political and religious beliefs, who you spend your time with, even documents you attach from tax info to intimate photos. It’s all in there, and it’s all for sale.

You might immediately wonder why your email provider is collecting all this. It’s none of their business, right? Well, it is because you made it their business when you agreed to the terms of service. Even down to the attachments, by using services like Gmail and Yahoo! Mail, you are granting that company to access and sell the content to ad companies and beyond.

Now imagine that this database on you was to be hacked. Can’t happen? It has. The Chinese government hacked Gmail and has likely gleaned a ton of information on the world’s Gmail users. Most likely, they were interested in what their own citizens were writing, but if you ever wrote anything critical of China or work for a company with exposure to China, they might find that interesting too. Who knows!

The US Government has also hacked into Google (and just about every other Western tech firm) as well.

And if these entities can do it, so can criminals and the mischievous. So, again, why are we letting these firms put our information at risk in the first place?

Good news: you don’t have to anymore…

Private and Secure Email

Alternatives to Gmail and other market intelligence-based email services include:

HushMail and StartMail were early services that took your privacy seriously. Both promised not to ever sell your data, but their business model made up the difference by charging you for the pleasure of living privately and secure.

Tutanota and ProtonMail, on the other hand, are free. Both use similar end-to-end encryption techniques and are quite similar in most respects. When I weighed which one to go with, I ended up choosing ProtonMail, only because their servers are based in Switzerland, a country that has outlawed the seizure of private computer content.

My ProtonMail Experience

ProtonMail was created by developers working at the CERN lab in Switzerland who were inspired by Edward Snowden and who were shocked at how weak online security was becoming, thanks to very aggressive and dangerous actions by global intelligence services.

ProtonMail uses encryption that is unlocked locally, on your machine, so even if anyone broke into ProtonMail’s servers, they would need a few more years than the age of the Universe to decrypt your content. Translation: it’s pretty damn secure, despite claims that the NSA can decrypt encrypted data. They would still need a lot of time and effort to do so, so it’s unlikely they’ll go to such an effort unless you’re an active terrorist (or the leader of Germany).

Best of all, you can send securely encrypted emails even to people using Gmail or Hotmail. You do this by checking a box, creating a password and an optional password hint for the recipient. They then receive an email with a link to ProtonMail. By following that link, they are taken to a secure web page inside ProtonMail where they can read and reply to your message by using the password. Or, if it’s nothing you’re worried about sending, you can just send it as regular, unsecured email to your Gmail friends, in which case it works as normal…but can be gleaned for any info you might have carelessly included.

Here’s how ProtonMail pans out.

UI and Functionality

This is more than just a bare bones email service. ProtonMail comes with a secure Contacts manager, email search and many other features you would expect in a modern email service.

The UI is clean and very straightforward.

Probably the hardest thing about using ProtonMail is the encryption, but not because it’s complicated…it’s drop dead simple…but only because it adds a step to your email creation if you plan on sending encrypted emails to people on Gmail, for example. In this case, you just have to come up with a good password and hint that your friends can figure out. It can actually be a little hard to come up with something that isn’t as easily hacked as “The city we met in.”

The other complication is that you have two passwords. One is used to access your mailbox and the other is used to decrypt the messages. So you have to enter two of these. In my case, I use KeePass password manager, so I just create super crazy, long, gibberish-based passwords for both of these and store them in the manager. Then it’s just a copy and paste action that I need to do twice when I log in…slightly easier, in fact, than using the two-factor authentication I use with Google, compounded by my non-use of cookies.

The Mom Test

I tested the recipient experience with my Mom (very non-technical) and some friends (generally non-technical) to see if any of this would keep people from reading and replying to me. So far, ProtonMail only snagged my mom, because she didn’t think of using caps on a name I was using for the password.

My mom also didn’t understand that she had to reply from within the browser window. Some caveats here: I believe she still thinks of email as something that she has to do in AOL.

My friends fared much better with no reports of trouble. So overall, I’d say there is a small learning curve for some recipients.

The Private Future

The hope here is that most people will gravitate over to ProtonMail or services like them, so that everyone’s on the same, private page. As I mentioned above, there are some extra steps with using ProtonMail with non-ProtonMail recipients. But if you’re communicating with friends that also use ProtonMail, the encryption is already there and you can relax…so obviously, I hope you all join ProtonMail.

Your Job Has Been Robot-sourced

rosie-the-robot

“People are racing against the machine, and many of them are losing that race…Instead of racing against the machine, we need to learn to race with the machine.”

– Erik Brynjolfsson, Innovation Researcher

Libraries are busy making lots of metadata and data networks. But who are we making this for anyway? Answer: The Machines

I spent the last week catching up on what the TED Conference has to say on robots, artificial intelligence and what these portend for the future of humans…all with an eye on the impact on my own profession: librarians.

A digest of the various talks would go as follows:

    • Machine learning and AI capabilities are advancing at an exponential rate, just as forecast
    • Robots are getting smarter and more ubiquitous by the year (Roomba, Siri, Google self-driving cars, drone strikes)

Machines are replacing humans at an increasing rate and impacting unemployment rates

The experts are personally torn on the rise of the machines, noting that there are huge benefits to society, but that we are facing a future where almost every job will be at risk of being taken by a machine. Jeremy Howard used words like “wonderful” and “terrifying” in his talk about how quickly machines are getting smarter (quicker than you think!). Erik Brynjolfsson (quoted above) shared a mixed optimism about the prospects this robotification holds for us, saying that a major retooling of the workforce and even the way society shares wealth is inevitable.

Personally, I’m thinking this is going to be more disruptive than the Industrial Revolution, which stirred up some serious feelings as you may recall: Unionization, Urbanization, Anarchism, Bolshevikism…but also some nice stuff (once we got through the riots, revolutions and Pinkertons): like the majority of the world not having to shovel animal manure and live in sod houses on the prairie. But what a ride!

This got me thinking about the end game the speakers were loosely describing and how it relates to libraries. In their estimation, we will see many, many jobs disappear in our lifetimes, including lots of knowledge worker jobs. Brynjolfsson says the way we need to react is to integrate new human roles into the work of the machines. For example, having AI partners that act as consultants to human workers. In this scenario (already happening in healthcare with IBM Watson), machines scour huge datasets and then give their advice/prognosis to a human, who still gets to make the final call. That might work for some jobs, but I don’t think it’s hard to imagine that being a little redundant at some point, especially when you’re talking about machines that may even be smarter than their human partner.

But still, let’s take the typical public-facing librarian, already under threat by the likes of an ever-improving Google. As I discussed briefly in Rise of the Machines, services like Google, IBM Watson, Siri and the like are only getting better and will likely, and possibly very soon, put the reference aspect of librarianship out of business altogether. In fact, because these automated information services exist on mobile/online environments with no library required, they will likely exacerbate the library relevance issue, at least as far as traditional library models are concerned.

Of course, we’re quickly re-inventing ourselves (read how in my post Tomorrow’s Tool Library on Steroids), but one thing is clear, the library as the community’s warehouse and service center for information will be replaced by machines. In fact, a more likely model would be one where libraries pool community resources to provide access to cutting-edge AI services with access to expensive data resources, if proprietary data even exists in the future (a big if, IMO).

What is ironic, is that technical service librarians are actually laying the groundwork for this transformation of the library profession. Every time technical service librarians work out a new metadata schema, mark up digital content with micro-data, write a line of RDF, enhance SEO of their collections or connect a record to linked data, they are really setting the stage for machines to not only index knowledge, but understand its semantic and ontological relationships. That is, they’re building the infrastructure for the robot-infused future. Funny that.

As Brynjolfsson suggests, we will have to create new roles where we work side-by-side with the machines, if we are to stay employed.

On this point, I’d add that we very well could see that human creativity still trumps machine logic. It might be that this particular aspect of humanity doesn’t translate into code all that well. So maybe the robots will be a great liberation and we all get to be artists and designers!

Or maybe we’ll all lose our jobs, unite in anguish with the rest of the unemployed 99% and decide it’s time the other 1% share the wealth so we can all, live off the work of our robots, bliss-out in virtual reality and plan our next vacations to Mars.

Or, as Ray Kurzweil would say, we’ll just merge with the machines and trump the whole question of unemployment, let alone mortality.

Or we could just outlaw AI altogether and hold back the tide permanently, like they did in Dune. Somehow that doesn’t seem likely…and the machines probably won’t allow it. LOL

Anyway, food for thought. As Yoda said: “Difficult to see. Always in motion is the future.”

Meanwhile, speaking of movies…

If this subject intrigues you, Hollywood is also jumping into this intellectual meme, pushing out several robot and AI films over the last couple years. If you’re interested, here’s my list of the ones I’ve watched, ordered by my rating (good to less good).

  1. Her: Wow! Spike Jonze gives his quirky, moody, emotion-driven interpretation of the AI question. Thought provoking and compelling in every regard.
  2. Black Mirror, S02E01 – Be Right Back: Creepy to the max and coming to a bedroom near you soon!
  3. Automata: Bleak but interesting. Be sure NOT to read the expository intro text at the beginning. I kept thinking this was unnecessary to the film and ruined the mystery of the story. But still pretty good.
  4. Transcendence: A play on Ray Kurzwell’s singularity concept, but done with explosions and Hollywood formulas.
  5. The Machine: You can skip it.

Two more are on my must watch list: Chappie and Ex Machina, both of which look like they’ll be quality films that explore human-robot relations. They may be machines, but I love when we dress them up with emotions…I guess that’s what you should expect from a human being. 🙂

Is Apple Pay Really Private?

Apply Pay, the new payment system unveiled by Apple yesterday was an intriguing alternative to using Debit and Credit Cards. But how private, and how secure, is this new payment system going to really be?

Tim Cook, Apple CEO, made it very clear that Apple intends to never collect data on you or what you purchase via Apple Pay. The service, in fact, adds a few new layers of security to transactions. But you have to wonder.

A typical model for data collection business models is to promise robust privacy assurances in their service agreements and marketing even though the long-term strategy is to leverage that data for profit. Anyone who was with Facebook early on knows how quickly these terms can change.

So, when we’re assured that our purchases will remain wholly private and marketing firms will never have access to them, how can we really be confident that this will always remain the case? We can’t. So, as users, we should approach such services with skepticism.

As with anything related to personal data, we should assume that enterprising hackers or government agents can and will figure out a way to access and exploit our information. Just last week, celebrities using Apple’s iCloud had their accounts compromised and embarrassing photos were made public. And while Apple has done a pretty good job at securing Apple Pay, it’s still possible someone could figure out a way in…and then you’re not just dealing with incriminating photos, you’ve got your financial history exposed.

So ask yourself:

  1. Can you think of things you buy that could prove embarrassing or might give people with malign intent a way to blackmail or do financial damage to me?
  2. If my most embarrassing purchases were to become permanently public, can I live with that?
  3. How would such public exposure impact my reputation, professionally and personally?
  4. Does the convenience of purchasing something with my phone outweigh the risks to my financial security?

Depending on how you answer this, you may want to stick with your credit card.

Or just go the analog route and use the most anonymous medium of exchange: cash.

Return to Firefox

Firefox Logo by Andrew McCarthy & Kara Zichittella : Appicns“If you have something that you don’t want anyone to know, maybe you shouldn’t be doing it in the first place.”
–Eric Schmidt, Google CEO

“If you want to stay anonymous online, you have to break links at every step”
–Ashkan Soltaini, privacy consultant

I’m breaking up with Google, one service at a time. Last week it was Google’s search engine, which I swapped for DuckDuckGo. This week, it’s Google’s Chrome Browser.

As I said a week ago, recent revelations of the commodification of our personal information, the revolving door our personal information swings through between tech companies and the world governments and the increasingly effective hacking of our financial transactions and personal information, has made me rethink my decision to trade privacy for convenience.

Step one was to wean myself off of Google.com.

Step two will be to sever another link in the chain between me and Google’s databases: the Chrome Browser.

To be fair, Chrome can be configured and used in a very private and secure way. You can surf “incognito,” leaving no history of what pages you have traversed. You can also use the browser so that it deletes your cookies when you end a session.

And as always, some of the best encryption freely available comes built into the Chrome browser.

So, you could easily argue that dropping Chrome is actually less secure.

But, I think you could equally argue that handing over your private data to any company is taking a big leap of faith. Especially, when that data can add up to a very personal and detailed profile of you. For example, the consolidation of Google Plus, Gmail and YouTube accounts meant that user data across these sites could now be consolidated into a single database of web activity that included a matrix of personal email, web searches, social connections, video views and even the text of attachments. Worse, Google claims ownership to this data once you “share” it with them.

So just because Chrome can be directed (by advanced users) to minimize the data shared with Google, you have to wonder. A breach of this very robust personal data is entirely possible. Indeed, the Chinese apparently already did this. And, as privacy expert Ashkan Soltaini (quoted above) notes, why help snoopers, hackers and commercial interests gather intelligence on you by (unnecessarily) relying on its browser?

¡Adiós el Chromo!

I was once a big Firefox fan, so switching back was not that hard. I stopped using Firefox, only because another Firefox-clone, called Flock, came out in 2009 with many social networking features built in. This was largely around the time the Add-on marketplace for Firefox wasn’t really keeping up. But the people behind Flock eventually abandoned the project and so I was momentarily back in Firefox. But around that time, Firefox (at least the Mac OS version) was pretty lousy in terms of handling complex websites that were deploying AJAX and other javascript intensive activities.

One of the best things about Chrome, in fact, was its speed…and some built-in development tools that I felt were way superior to their closest Firefox Add-ons, like Firebug. So, I started using Chrome…until a week ago.

First and foremost, Firefox comes to us from Mozilla, an open-source organization that has proven itself deeply concerned with protecting privacy and security on the web.

Firefox Privacy Settings

I’ve experimented with the privacy settings in Firefox, and I consider my current setup a work in progress. My focus here is to give some guidelines for how one might configure Firefox to maximize their privacy while not making everything a test of their faith.

Search

  • Remove Google, Bing and Yahoo! from the search engines installed in Firefox
  • Add a private search engine as the default. As of this writing, I use DuckDuckGo right now, but I’m experimenting with others. Update: Read my post on Startpage, which is my preferred private search engine now.
  • Optional: I added the Omnibar add-on for a more Chrome-like experience, which as far as I can tell does not report back what you enter it to the developer’s database. If you’re concerned about this, just don’t add the Omnibar.

Privacy

  • Obviously be sure to select the “Tell sites I do not want to be tracked” setting.
  • History and Cookies: I go back and forth between not capturing history, keeping all history and deleting history upon closing Firefox. Currently, I have everything deleted when I end the session.
  • Set the browser to Never Accept Third Party Cookies

Security

  • I use a master password…and you’d be crazy not to. To understand why, just open your preferences and, under Security, click the Saved Passwords button. Then click Show Passwords. There they are…hopefully you’re not sharing your screen when you do this!

Sync and Advanced

  • I don’t sync, but I’ve been tempted to. I need to research this more before committing, but on the face of it, it feels less secure to do so.
  • Network, you can set up a SOCKS Proxy, but I use Private Internet Access VPN, when I’m using public wi-fi, so I haven’t explored this.
  • Make sure you have Auto-updates installed to be confident Firefox has the latest security patches, etc.

It’s been fun to be back in Firefox. I feel a little bit like a rebel, in fact! And the good news, the browser feels more light-weight and agile then in the past with all those heavy JavaScript-ladden sites running at a good clip! And, whoa! The developer tools are now built into Firefox, so that means one less Add-on slowing things down.

Meanwhile, I’m continuing to explore other secure ways of living online. Coming soon: Thumb drive applications, Gmail alternatives and a secure way to get Google search without using Google!

Rise of the Machines

As I write, the Roomba is cleaning my house. Googlebots are driving cars on California roads. Siri is learning what you want.

And, to the dread of many reference librarians, Watson is beating the pants off Jeopardy Champions in an opening AI move that will surely impact the library in the near future.

Already, robot shelvers are in place in many libraries, such as Santa Clara University’s Library. And if you saw the recent executive summary of Library Journal’s Patron Profiles, you saw that 76% of students reported turning to Google first when initiating their research. Compare that to just 24% that opted for the library.

This isn’t news, really, but when I heard economist Paul Krugman connecting the dots of automation, nagging unemployment, innovation and worker productivity and identifying it as a challenge to society, I had to agree with his thesis: robots are replacing people at an ever-increasing rate…and in parts of the economy we once considered safe.

Like I said in my previous post, sometimes the future sneaks up on you. But even if robotification is inevitable, we must ask ourselves, what are the human qualities that make us a value to other people?

Some might say that it’s about the in-person assistance that we can bring to our libraries: true. They might emphasize the smiles, encouraging words and subtle forms of non-verbal communication machines are pretty lousy with so far (until the David 8 release at least).

But we have to be very careful about convincing ourselves that retreating to our ramparts of physicality and empathy will serve us for very long. As the Library Journal survey illustrates, the cold, white Googlean box is often a superior tool than a library website…and quite possibly more approachable than our staff.

No, to be effective and valuable, we have to embrace the shifting technological realm and make it our own…and humanize it, improve it, augment it.

Until David 8, that is…

Tomorrow’s Tool Library on Steroids

The pace of change (and of devices) is outpacing the consumer’s ability to purchase the latest and greatest. Couple that with asset-light trends toward sharing commodities and you can see a niche for libraries.

The public has just spent billions on touch screen devices, smartphones and upgrades to our computers. And now, this year, we’re being presented with Microsoft’s Surface and soon wearable computers. Even the most savvy techsumers, wielding the latest MacRumors Buyer’s Guide is having trouble keeping up with the dot.joneses.

And, if Ray Kurzweil is to be believed (and I am a Kurzweilian true believer), the rate of technological change, and therefore consumer gadget innovations, will surely decimate our Google Wallets in short order.

But a recent trend in libraries to rethink themselves as gadget bars, maker spaces and digital media delivery centers could very well be the cure to the world’s ever-quickening pulse rate.

My favorite library of all time was the Berkeley Public Library’s Tool Library which I once used to turn the urban waste dump behind my old East Bay apartment into tranquil, solar-powered salad delivery system. Fast-forward a decade or two and you can see the slightly different, yet similar need that is arising from the gadget frenzy that is only getting worse.

Actually, many public library’s have been delivering computer power, laptop checkout and even courses for some time. But let’s add some Lance Armstrong-strength steroids to this model and see what we can come up with.

But first, what are the gaps that need filling?

  1. Devices are being upgraded and made obsolete at an increasingly fast pace. Why not just provide our users with the lastest and greatest either free or at a small subscription rate…rent by the hour, the week or by the month.
  2. Include in our offerings all kinds of equipment from laptops to tablets, cameras to e-readers, 3D printers to digital drawing tablets…and oh yes! The latest versions of software!!!
  3. And for those that opt for the hourly model, let’s support them by moving their digital content to the cloud…a sort of cloud migration service.
  4. But the cloud is such a drag. There are so many options out there: Evernote, iCloud, Google Drive, Dropbox. How’s your average person supposed to make sure they do it right? How about we librarians come up with consultant staff that can recommend solutions based on the user’s specific needs…ala the Geek Squads and Apple Store models.

Below the Microsoft Surface

Silverlight required to get product info: #FAIL

Coming back from Thanksgiving with my family, I came across a Microsoft Surface demo in the airport. Normally, I would have dismissed it immediately, the same way you might dismiss suggestions about trying a new dish at Chipotle after that first, stale burrito you had on your initial visit. But, I was trapped in airport limbo for 40 minutes, so the Surface seemed like a good way to pass some time.

Microsoft’s new tablet is really a new spin on the laptop, which, if you’re like me and need to create more than you consume online, is a much better solution than the typical Android or Apple tablet. That is, Microsoft kept the keyboard in mind when looking for their much required business strategy. Unfortunately, the new tablet does not come equipped with the full-blown Windows 8 OS, which seems like a big, bad burrito. That won’t come until after Xmas (did someone say missed opportunity here?).

Anyway, I was impressed, generally. Of course, we’re still talking Windoze, so the experience was fraught with so many error messages and OS-fails, that even the woman giving the demo seemed annoyed. But is still had enough new takes on what is now an old market (for tablets), that I had to give Microsoft some credit.

The most telling experience, though, came after the demo when I was asked to take a brief survey. The questions just said it all:

  • What would you buy before seeing the Surface/after seeing the Surface? (Apple)
  • Did you consider MSFT an innovative company before seeing the Surface? How about now? (If you have to ask, the answer is no)

But at least they woke up to the bleakness of their market position to even start asking these questions and try to change things, albeit soooooo late. On the train back from the airport, a fellow passenger and I discussed the Surface. He noted that MSFT is opening retail shops beside Apple Stores in shopping malls across the country. When I mentioned this to a colleague at work, he laughed, mentioning that he’d seen one of these shops. Apparently the Apple Store was jam-packed, while the MSFT store went ignored.

For now, at least, people will get their tacos from the place with the fresh ingredients.

Apple is the New Enemy

I was pretty shocked by the jury verdict that allowed Apple to assert proprietorship over things like pinch zoom and icon design in their proxy war with Google via Samsung. Apparently, others are too. Slate urged us to imagine the state of our world had a single car company been allowed to claim rights to the design of the steering wheel, forcing all others to create different means for directing a vehicle. Never mind if the steering wheel was the most obvious, best design. Had a single auto manufacturer been allowed to patent the steering wheel, all others would be using levers, knobs and joysticks for cars and the auto market would effectively be captured by a single company that filed its patent first.

Watching TED tonight, I saw this reality check on where patent law has brought us. Take a look:

We Are All Terminators Now

For years, tech analysts and insiders have speculated that augmented reality goggles were just a few years away. These products would provide a data layer superimposed over the real world similar to that depicted in the Terminator movies…albeit one less likely to place crosshairs over Sarah Conner, and more likely to allow you to friend her.

Well, last week, the NYT wrote that such products are within months of coming onto the market, and will likely be released in time for Planet Niburu’s arrival (aka Christmas 2012). That’s right, folks, all that talk about the world-as-we-know-it coming to an end in 2012 is really going to happen. Only, future historians will log 2012 not as the realization of a Mayan apocalypse, but as the beginning of the end of the Internet and the rise of something much better.

Imagine you’re walking down the street and want to find the closest biker bar. Simply input your search (I’m fascinated to see how this will get pulled off) and then start scanning the surrounding world around you for the results.

Far more than virtual reality or cyberspace, augmented reality is the real future for information seekers. My guess is that 20 years out, people will look at examples of web pages and have to laugh at how rooted in the 20th Century file cabinet mentality they were. They will scratch their heads and wonder how anyone ever found anything relevant. The very idea that you would create information that was not tied to a physical space will astonish them.

Once AR goggles come online, relevance will be tied to location…period. We’ve already seen this with our location based services via our smartphones, but these too, are merely a stepping stone. And I think if you look at Google’s product line you’ll start to see that they have been anticipating the AR future for some time.

Here’s my take: The web of the future will be something akin to Google Earth + Planet Earth. Let’s say that you’re looking for a woman named Sarah Conner. A few years ago, if you ran this search, you would be treated to all kinds of location-agnostic results that would drown you in a flood of irrelevant data. Run that search on Google today and you might get the Sarah Conners your contacts on Google Plus are associated with and perhaps the ones listed in directories in your current town. Fast-forward to an Internet that is oriented around goggles, and suddenly your top search result would be the Sarah Conner closest to you on Planet Earth at that moment (assuming she allows any random killer robot from the future to locate her online).

Or, let’s say that you really don’t want the closest Sarah, but just the ones in Los Angeles. Flip over to Google Earth in your goggles, run your search and zoom in on L.A.

Termination was never so easy!

All of this will really challenge the utility of the simple web site, suspended in the cloud, independent of the real world. It seems that at the very least, web sites will be dramatically reorganized over the next decade as we scramble to geo-locate wikipedia articles and the like. Some things may not be so helpful if they are tied to a location (where does StarWars.com go? Up in the sky? Lucas Ranch in California?), but the vast bulk of sites related to locations will move from the web to the world.

And now for the compulsory cliché: The future’s so bright, we gotta wear…

Why Drupal is Just Okay

Project Spork continues…I’m reporting on my first impressions with Drupal. Short version: It’s confirmation for why I often steer clear of open source solutions.

First, a few words on my previous web development experience. I’ve designed and run several sites mostly the old-fashioned way: hand-coding with a few leanings on development environments like Dreamweaver to quickly build the more complicated dynamic elements. Throughout most of this work, the closest I’ve ever come to using a CMS was integrating tagged WordPress feeds in a way that allowed site owners to publish and edit content to their public sites via a private blog. Aside from the SEO issues this raised, it was a great solution for my non-technical clients.

Since those days, I’ve used a custom-built CMS which was more of a PDF cataloging system for a research portal at Adobe Systems (the shell of that site had to be managed by hand-coding in Dreamweaver); and I’ve been using Serena Collage at my current job, which is half-way between straight hand-coding and the full-on CMS that is Drupal.

If I had to describe Drupal in one word, it would be “patchy.” If you’ve worked with this platform for more than a day, you’ll probably know what I’m talking about. Drupal is built for very, very simple, collaborative sites that are more akin to blogs or wikis than traditional institutional sites. To get it to provide features that act more like applications, you’ll have to deploy those features  elsewhere and bring them in through iframes, etc.; or start building up the patches.

The Drupal community calls these patches “modules.” The problem is, because Drupal is an open-source product, these modules are not built with one focused direction in mind as might be the case with a CMS built by a company. Some might call this a strength, since it means that there are modules out there for pretty much any CMS problem that needs a solution. But often these modules rely on one-another to function and sometimes they don’t play nicely together, meaning that a web manager might spend more time trying to troubleshoot module disunion than they might otherwise take to build a custom solution in-house the old-fashioned way.

This was the case with Spork’s Drupal instance.

The problem we faced was re-creating our library hours widget, which is essentially a database-driven application that sits on our library homepage and functions much like the opening hours feature on a Yelp page. If the Library is open, a green OPEN message is displayed; if closed, you get the red CLOSED message. This feature works across our various locations, which often have special opening hours that change around holidays and finals. It also allows users to work with a calendar widget to select date ranges in the future or past.

This is where Drupal started to break down on us.

Building the databases in Drupal 7 is quite easy and I had great success building a tagged set of FAQs that could display only on relevant sections of our Drupal site. No doubt, the hour database would be easy to build, but creating the app and site functionality that made this database pop would require dozens (seriously) of inter-related modules. To add all these modules took significant time to upload and install. When it was all said and done, I still did not have the hours application I was hoping for, but worse, I had a dizzying array of modules imported into my site, which just felt like a administrative nightmare waiting to spring forth at the next Drupal update.

Drupal themes also seemed problematic. These also appeared largely dependent on one’s version and any customizations might be lost if one were to upgrade. Moreover, there were a few themes that did not seem to function all that well. Yeah, I understand that this is open source. But this is also my professional reputation being tied up in someone else’s hobby.

But the real problem I have with Drupal (and this may turn out to be with all CMS), is that I really just want to add code to my sites the old-fashioned way when I need to get something done…and done quick and done well. From my experience thus far, Drupal does not make this part easy and I was actually missing LibGuides and even the broken CMS we currently use.

Case in point, my colleague Jim LeFager was trying to add JQuery functionality to a Drupal page. JQuery is supposed to be integrated in Druapl 7, but it turns out that to get any JQuery to work, you have to include one line of php referencing the JQuery library. Okay, not so hard, except that this critical piece is not documented anywhere. We only discovered it when Jim found a blog entry by someone out there who had run into the same issue.

Really? Is that what we can expect?

Sorry, but for all the hype about Drupal, I’m not sold. The new Views module and CCK integration are great additions for building database-driven sites, but a CMS built for web developers, this is not. There has to be a better way.