epiic (SpookyElectric) ([info]epiic) wrote,
@ 2009-06-10 04:38:00
Previous Entry  Add to memories!  Tell a Friend  Next Entry
Entry tags:workstuff

Make Me Money and Your Life Easier at the Same Time
Mitto LogoMitto.com: The best Safe, Secure, Buzzword, Synergy, Online, Web 2.0 Software as a Service for Password Management and Sharing and Ultimate Enlightenment
Mitto is my company, started as a spin-off of an internal project at my previous employer. We are now initiating a push to widen our user base beyond the initial testers. As such, I'd appreciate it if you took some time to check it out, and relay the message to anyone you know who may be interested. And if you want some random YouTube content to explore, watch Mitto commercials.

The Idea

At my previous company, we had passwords that needed to be shared among several people. And those passwords often needed to periodically change. So, I made a tool to collectively manage them. Passwords could be shared (via internal RSA public key cryptographic system, transparent to the users) and instantly updated for everyone when the time came to do so. The base version took about a weekend. It had to expand a lot from there, and mitto.com is a fresh-rewrite sharing only the base concept in common.

Then we started using it for pretty much everything - even for personal stuff. And it became apparent that many of us really use far more sites than we thought. (In my case, I think I have something like 130 sites setup)

Since it doesn't require installation, I can use it from any computer. And security measures like two-factor authentication help keep data secure even on untrusted machines.

One Ring to Rule Them All


One big concern people have is that now they have a bigger problem if their Mitto password is compromised.

Previously, I had about 9 passwords, but most of my websites (except banking & E-Mail) shared just two of those. Many sites do not use SSL, and I use public wifi often, and many sites have very poor password management, such as storing them in plain text or E-mailing them to you in plain text. So it's easy for a malicious party to have intercepted one of those, and with that potentially gain access to a more important service. So, compromising one of those re-used passwords, or my E-Mail account already was a large single vulnerability.

Now that problem does still exist, but with Mitto, I have two factor authentication, so even if my password to that is compromised, my account is still safe. And if any one of those sites is compromised, it's just that site, since passwords are now unique. So, overall, I'm much safer than with passwords re-used many places floating around wifi networks and E-Mail servers.

Not a Hoax

This would be a great scam. I assure you, it isn't. I believe disreputable practices will inevitably be undermined. Especially since I don't see myself as very lucky, hoping I don't get caught isn't something I could count on even if I did try to do something malicious.
However, skepticism is well founded. I store banking information in our service because I believe in eating my own dog food. But others would be understandably not so comfortable. But much of what you log into, such as online communities, are not that critical. So, I hope you'll at least consider using us for those sorts of sites.

Also, this is not a small operating running off a shared hosting provider. We operate a half rack full of equipment in our own locked half-cabinet in a datacenter. Servers run with their operating systems and software read-only, among many other security measures. (With more even layers of security in the works.) No critical data (i.e. your usernames, passwords, notes, etc) touches hard disks or travels outside a server (i.e. over Ethernet cables) unless it is encrypted.

In the works

Right now, you can't auto-login to some sites. I'm working on a new version of the bookmarklet that will allow you to login to pretty much anything, without having to go to our site first. Unfortunately, it's a bit tricky due to measures I'm taking to prevent XSS vulnerabilities in other sites from possibly being used to extract data from us. Unfortunately that will probably not be ready for about two months.

Also, I'm planning an API that would facilitate using Mitto for things other than websites. (Again, this is a much more challenging task than it sounds due to the tricky matter of being flexible enough to be widely useful, while ensuring sufficient security, while maintaining ease of use.)

In the distant future (i.e. not this year, maybe next), Mitto may also be usable to sign up for new sites.

What I do


The company is small, but not just me. Arsen, a friend from college, and co-worker at my prior job founded it with me. He is in charge of most business aspects, and manages the support system. I am the lead software architect, and do the majority of the implementation for app.mitto.com. Network engineering and system administration ends up being my domain as well. Most graphic design type tasks, are Matt Ash's work, such CSS/Logos/Icons, and well as most of the brochure website at mitto.com.

Feedback?


I'm interested in any thoughts, questions, etc., that you may have. And if you find anything confusing, or have idea for improvements, please let me know.
You may post here, or E-Mail, or use the "Feedback" option when you are logged into Mitto.



Oh... and if you want free stuff, like Netflix, Southerwest, or Amazon gift certificates, you may be interested in out one-day only promotional contest. Get others to sign up and list your E-Mail address when they do, and you can win stuff.

Regularly scheduled programming of photos, cosplay, and random outings will resume when I get some more photos processed. I promise I won't spam again any time soon. On the subject of cosplay, I was meaning to visit FD Friday or Sunday, but neither worked out, so my next plan is visiting FD this Friday (or *possibly* Thursday). Anyone interested in meeting up? Maybe for lunch around there?



(5 comments) - (Post a new comment)


[info]yoshikochan
2009-06-10 02:49 pm UTC (link)
:D If it's Friday, give me a call! Thursday...mm... I'm a little more 'watched' .__. ~

(Reply to this)


[info]shiroin168
2009-06-12 08:10 am UTC (link)
Seems legit. Will sign up after I finish exams.

I actually had this idea in mind a while back, a website that allows me to manage login information of multiple sites. Seems like you already got a very good start on this one, so good for you!!!!!

Mind I ask, what is your business model?

(Reply to this) (Thread)


[info]epiic
2009-06-12 08:22 am UTC (link)
Will have ads at some point. It would already, but most ad providers don't support SSL and/or don't allow ads on password-protected pages. So, we're looking into affiliate marketing programs to start with. (and may make it so logging in with us is the same as clicking on their ad. But we have to be careful about how we do that to not essentially steal from others.) (And then there's the matter of sufficiently partitioning the ads from the rest of the site, probably with an iframe on a separate domain, so any security issues in the ad service can't be used to compromise our service.)
Alternate ad-free pay service. With possible additional pay feature for businesses. Possibly when using us to sign up for new sites, we offer a service to pay us to make our service work with your site.

(Reply to this) (Parent)


[info]shiroin168
2009-06-12 08:19 am UTC (link)
1. site in general is kinda slow to load...
2. be nice to have a link to confirmation in the email instead of having me copy and paste it.

anyways, i would really love to chat with you in general about the site.

cheers!!!!

(Reply to this) (Thread)


[info]epiic
2009-06-12 08:58 am UTC (link)
Kinda slow like 5 seconds, or like a minute?
There is a lot of optimization that needs to be done. That keeps getting put off in favor of functionality and other tasks. In a week or two, once I get some extra clustering things worked out, I'll hopefully be addressing some of the more significant bottlenecks, before moving on to the new bookmarklet. (But that depends, since bookmarklet may take priority, since with that more sites can be auto-logged into, and it makes less of a need to spend time on our site.)

If it's a really long time, then you seem to be part of a small group of people hotting what seems to be some sort of routing issue that is causing problems. For some people the site is extremely very slow. In such cases, even the login page is slow. We're working with our datacenter to try to figure out what exactly is going on.


As for no link in the E-Mail, the service is a great potential target for phishers. So we're trying to de-train users from clicking things in E-Mails. (Or more specifically, our current plan is to not have links to places where you may need to log in. In the case of the confirmation code, if your session expires, you may need re-login in before entering the code.)

(Reply to this) (Parent)


(5 comments) - (Post a new comment)

Create an Account
Forgot your login or password?
Login w/ OpenID
English • Español • Deutsch • Русский…