ETacts (YC W10) will help you manage your relationships
techcrunch.com
techcrunch.com
The bad news is that "bank-level" encryption and assertions of good intentions are not sufficient for me to give you my Google password. My Google password is one of two that is not recorded anywhere. The second is for the vault that contains my other 575 passwords. I almost edited my original post to be less melodramatic, but on reflection I think it's right. For a cool grand, I would spend the time to completely separate the associated accounts (analytics, webmaster, docs, calendar, talk, voice) and any password reminders that forward into my gmail now into a separate account. Short of that, I just can't do it. I'm selfishly hopeful that Google gives you a way in without needing to store my password.
indeed I'd say my google account needs more inventive protection than my bank detail. The chance of misuse is a lot higher.
The Google Contact API supports OAuth, which is fantastic because so many sites want your email address and password to get contacts (for like invite friend style functionality) but it doesn't appear they store any kind of communication frequency data.
[1] I Am Not a Security Expert
Have you had a vulnerability assessment done? Do you protect against SQL Injection? Do you protect against Cross-Site Scripting? How about Cross-Site Request Forgery? What preventative measures have you taken to lock down your servers?
I know most users don't care about all of those and you're trying to be friendly by saying you use "bank-level" encryption, but some more info would be nice for those of us that care.
We use the latest in bank-level 256-bit SSL encryption to protect your information, and your passwords are securely encrypted.
Right. 256 bits, like everyone else, like it makes some critical difference over 128 unless you're the freaking NSA, and like anyone even bothers trying to break into a TLS session. Not encouraging.
First thing I always check is whether the site's behind a gateway, so let's try and connect on 22:
$ ssh etacts.com
The authenticity of host 'etacts.com (173.203.202.141)' can't be established.
RSA key fingerprint is ec:c2:2f:fe:ef:7e:06:a3:a5:f0:a3:54:04:79:2a:16.
Are you sure you want to continue connecting (yes/no)? yes
Warning: Permanently added 'etacts.com,173.203.202.141' (RSA) to the list of known hosts.
sailormoon@etacts.com's password:
Permission denied, please try again.
Tsk. Early days I know, but .. if you become popular for storing a large database of people's login creds for gmail .. that's a nice juicy target.And I actually found the mention that they're encrypting the passwords, like that means anything (the key is obviously somewhere on the server, and once they're in, they're in) to be more worrisome than not.
You can consult this hardening guide written by the NSA for Red Hat: http://www.nsa.gov/ia/_files/os/redhat/rhel5-guide-i731.pdf. Even though you're using Ubuntu, the same general principles apply. Follow that guide to the letter and you will be secure enough until you can afford to higher professional pen testers.
Note that the NSA guide doesn't cover web application security, so you'll need to take other steps to ensure that part of your business is secure.
Just curious, what encryption scheme are you using?
Of course, this would limit the reliability of your service to the reliability of my connection, but that's a trade-off I'd be willing to make.
EVERY company in the world promises to not be evil. Not all of them keep their promise.
But when it asked for my Gmail password, I just can't type it in. My calendar, email, Android, etc. are all on Google.
My Google and to a slightly lower importance, my facebook account are the most important accounts of my online life.
http://groups.google.com/group/gmail-labs-suggest-a-labs-fea...
(Why this is safe)
We use the latest in bank-level 256-bit SSL encryption to protect your information, and your passwords are securely encrypted.Etacts will never email your contacts without your permission.
Your data is completely private and will not be shared with other users.
To help you keep track of who you haven't spoken with, we fetch your email headers. We don't store the content of your emails or attachments. When you view an email in etacts, we fetch the email directly from your Gmail server and don't store it on our servers.
Uh. Hey, Etacts. Are you storing my password long term or not? That's my question. Glad you're doing the bank security encrypty thing. But you can't keep my Gmail password.
The security advantages are limited– the password has to go through you guys either way– but there may be a difference psychologically.
I don't think mail2web would be as widely-used if they didn't have a policy against storing passwords.
You can't convince people like me to give you a gmail password. It's simply not going to happen.
Meanwhile, you could convince my mom to give up her gmail password with an animated GIF of a cartoon padlock.
What we can help you with here is how to communicate about security without setting off alarm bells. Your security page isn't awful; "bank security" is a security idiom, it's fine that you use it. But we can help you make it better. Make it clear that you're storing passwords so nobody can say they're surprised about, and make sure security researchers know how to contact you.
Please, fix the lander. It looks way too close to http://www.getballpark.com/ but only worse. If the metalab guys haven't tweeted about it yet, they definitely will. If you need some tips about it just send me a note jay (at) anomalyinnovations.com.
@ETacts Again if you need any help let me know.
However, I had never looked at Basecamp vs. Ballpark (though I could tell that they both follow the same trends) and if Metalab were to call Etacts out for their design as jayair suggests, I'd like to hear Metalab's explanation for the copy of Basecamp's design and copy.
"The Better Way To Get Projects Done" => "The Better Way To Get Paid"; "See Plans and Pricing/30-day free trial, sign up in 60 seconds" => "See Plans and Pricing/30-day Free Trial. Get started in 60 seconds."
Anyway, what I'm trying to say is that Metalab does have a distinct style in a lot of their designs (they seem to love text-shadows for example) but they're not the inventors of it either. The layout is pretty common place nowadays. (or as lunaru put it about a year ago when Ballpark came out: "the layout is pretty much a de facto standard" http://news.ycombinator.com/item?id=557277)
#1 on my list is my girlfriend (cool). #2 is my co-founder from my last company (also cool). #3 is my dad.
#4 is my ex-girlfriend, and it's telling me to email her (fail).
I'm guessing they are probably targeting gmail first so that they get bought out by Google if they get a ton of users.
That kind of kills the convenience of the service, but personally I would accept that for increased security.
I also suspect that outside of business contacts I view lack of communication with someone as a signal that I'm not that interested in talking to them.
If it's really important to integrate other services, you can do that later. (I don't think it is, personally. At least not for the kind of people who would pay you money.)
What this sort of thing does really bring home for me is that in terms of trying to do a startup through y-combinator I should probably ignore whether I believe there is a market for something as long as I think some people would find it useful.
I hate feature creep too, but important:
1. Company pages for company e-mails
2. Merging contacts
3. how to smartly import facebook and linkedin like gist does i.e. keep the people with companies, chuck the rest.
4. Updating/removing accounts etc needs some QA
But it looks like that's not the case.
edit: nevermind, I just saw a comment on Techcrunch that they may add Facebook/Twitter support
Having graphs in etacts would be nice, but I think you nailed the really important features! Now I just have to wait for the solution to the password problem. A desktop application, while less convenient than a web app, would still be awesome, and could even be made a portable install I take around on a USB stick.
If you can't see it, here's a method I use:
Paste a screenshot in photoshop. Hit Ctrl+U and turn the saturation all the way up. Then change the hue so the whole site looks orange or green (the eye tends to blur blue together). You'll more easily notice where the gradients are cut off.
The other two email addresses visible are the founders'.
I had an idea for a work-around for you for people who don't want to give their password. What if BCCing myaccount@etacts.com updated your info? Doesn't seem like it'd be hard to implement. I'd use the service if it had that feature, it looks really good. I think you guys are doing something really needed and cool, cheers and good luck,
Sebastian
Note - we are a company that hosts email on google apps. However, we can not and will not use this service through your website. However, something that we can host ourselves, and includes pricing that is friendly to small companies will be eagerly looked at.