Thursday, December 31, 2009

A Year in Review

As 2009 comes to an end, let's take a few moments to look at some of the accomplishments we've made over the past year...

1. Mastered Joomla! - Francomedia can just about do anything with this Content Management System (CMS), it was a big learning curve, but we dedicated hundreds of hours into learning it inside and out. The result now, is we can offer great web sites with endless functionality, endless SEO options and the customers can drive the content themselves. Well done Sandor and Nicholas.

2. Created Brands - Our design team has unveiled some great looking wordmarks and logos this year which I believe can be the start of some great brands. These designs have made it onto business cards, web sites, letterhead, billboards, the sides of vehicles, baby food packaging, pharmaceutical capsules, mobile web sites, point of sale materials, cleaning products, oil well sites, hats, presentation screens and onto coffee mugs. Well done Dave, Colin and Ryan.

3. Won Awards - The Francomedia team earned some street cred this year with 5 international awards. Spring arrived with a Platinum Hermes and Gold Hermes for the design of our own business card and the design of our own envelope with custom postage stamp. In the fall we learned that we won Platinum MarCom and Gold MarCom for the design of the Alternate Reality Game (ARG), Experience the Node and for the design of our own business cards. Then towards the end of the year we learned that we won the top honor, a Platinum Ava Award for the ARG we developed for our client, The Node. In December, it was announced that Francomedia is a finalist for the Marketing Award of Distinction and the Premiere's Award - handed out by the Alberta Chambers of Commerce. Well done team!

4. Continued to Grow - Despite the economic conditions, Francomedia was fortunate enough to grow over the past year, increasing sales and headcount. We have a great group of dedicated, talented and creative staff. I can attribute this past years' success to our team - no doubt their hard work and perseverance has solidified Francomedia's reputation in the market place as a reputable creative boutique. We were on the receiving end of many new customers who made the switch to our little shop of honors. We made many friends this year.

5. "Got Involved" - This year we did quite a bit of work for non-profit organizations, putting in many extra hours on projects for Volunteer Calgary, Servants Annonymous, The United Nations Association of Canada, The Santa Cause, Science Alberta and even became a platinum sponsor of a non-profit organization - the Calgary Council for Advanced Technology. In addition to that, we got involved with a for profit organization because we believed in what they were doing, we sponsored the "Access to Capital Conference", a platform to help businesses learn about and find alternate financing at time when businesses needed it most. We are proud of all these associations.

6. Got Famous - Well, we didn't, our business cards did. In addition to our business card designs picking up some international awards, they got featured in several blogs from around the world which resulted in us being interviewed for books, blogs and magazines. If you do a google image search of us and images of our business cards will fill your screen, well... almost. Every week or so we discover a new web site that is featuring our cards. We've had a lot of customers ask us about doing similar cards for them, but when they learn how much they are, they tend to drop the issue. Fame has a price and it's five bucks per.

7. Developed a Game - Every year as a holiday gift we like to do something creative. This year, we opted out on doing a physical printed card (sorry to our fine print suppliers) and decided to do something digital. A simple e-mail greeting wouldn't suffice, so we developed an arcade style video game and sent it to customers - it's called, "Mistletoe Command" and garnered much attention and adoration from our clients, friends and some new acquaintances. In addition to the game, we purchased 125 Colorado Spruce tree grow kits to promote the game as well as to award to winners of the game (the contest ends in 5 minutes).

I'm sure I've missed a few things, but those were a few of the highlights of the year, a few of many. So, with that said, I have just a few minutes before the clock strikes 12... from everyone at Francomedia to everyone... OK, both of you reading this, All the best in 2010 and have a prosperous New Year.

Labels: , , , , , ,

Thursday, May 14, 2009

Joomla Security

Introduction

According to Google Trends (1), Joomla is the most widely used CMS on the market today. With its ease of use, developer community, and immense library of third party add-ons, it’s no surprise why Joomla is so popular. Popularity, though comes with a price - the issue of security.

It’s comforting to know that, out of the box, Joomla 1.5.10 is a very secure CMS (2); and when maintained properly, keeps your site nearly hack- free. But do keep in mind that nothing is 100% hack-free.

The key here is maintenance. Aside from typical security measures, the owner must be vigilant in keeping up to date with security patches, regular backups, and monitoring unauthorized access.

There is official Joomla documentation on a security checklist (3), that if not taken for granted, can reduce any downtime in having to re-implement a compromised site.


What can the Developer Do?


The developer can do a lot to ensure that the client’s new Joomla site is safe and secure. Here is a list of some of the most important things:

- use a secure host (www.siteground.com is popular)
- install recent Joomla version (ensures latest security update)
- ensure sensitive directories are write-protected (prevents unauthorized access)
- enable .htaccess (this prevents unauthorized scripting)
- enable SEF urls (this hides URLs)
- turn Magic Quotes off (prevents SQL injections)
- turn Register Globals off (prevents access to global variables)
- delete unused templates (prevents unwanted display of pages)


What can the Client Do?


The client needs to acknowledge the fact that all websites are vulnerable to attack, even those found on Secure Server Layers (SSL) like Bank websites for example. Certain precautions need to be taken to avoid potential disaster:

- secure usernames and passwords (combinations of numbers/letters/uppercase)
- an offsite backup system (don’t rely on the host to do this)
- secure third party Joomla extensions/plugins (buyer beware)
- tracking and monitoring (be aware of unauthorized traffic)


Conclusion

In summary Joomla is the number one open-source CMS on the web. This popularity has led to more than its fair share of hacking attempts, but this is normal. It’s the PC vs MAC analogy. Apple boasts that MACs have zero viruses, but this is simply due to the fact that it has less market share, thus less interest from hackers. To be sure, the underlying UNIX-based system behind a MAC is very secure to begin with, but that does not mean it cannot get hacked.

Joomla is very similar in this regard. With the release of Joomla 1.5, significant security measures have been integrated into its core. Things like SEF urls, and .htaccess do a lot to ensure your Joomla site is safe from exploits. However it is up to the developer to make sure everything is setup correctly. Thereafter, it is the client’s responsibility to change passwords, monitor third party access, and perform regular backups.

In the end, Joomla is what you make it.


SOURCES

(1) Google Trends

(2) ”Is Joomla A Secure Platform for a Business?”

(3) Joomla Security Checklist

Labels: , , , ,