Tuesday, September 6, 2011

A Simpler Approach to Online Identity

Many people struggle to remember scores of passwords for different websites. They often have to reset an account or dig through years of e-mail to find stored log-in information. A common trick is to use the same password for lots of accounts, but this can be a security risk, potentially allowing many accounts to be hijacked at once.

Even as identity becomes increasingly important online, it is becoming more fragmented, with users signing up for ever more websites and services. Account Chooser, a new service launched by the OpenID Foundation, an organization that includes the major websites Google, Facebook, Microsoft, and Yahoo, is the latest effort to solve this problem. Instead of having to create yet another account, Account Chooser lets users choose one account—their Gmail or Facebook log-in, for example—and then use it to log in to many other sites. The technology was developed by Eric Sachs, a Google project manager and OpenID Foundation board member. Google is backing the project by hosting the code.

Account Chooser is far from the first effort to create a single account that can be used on lots of websites. But previous endeavors, including the one launched by OpenID, have proven complicated to use. Previously, users had to create an OpenID account, and then manually link it with all of his or her other accounts, which meant figuring out which sites would accept the consolidated account as verification. A number of companies, including ClaimID and Verisign, are trying to tackle the issue with their own unified account technology, but they have so far seen limited acceptance from users and websites.

Chris Messina, developer advocate at Google, says OpenID is trying to create a system that users can easily understand, and companies can easily support. "The lack of a novice-friendly solution to authentication on the Web is one of the OpenID Foundation's greatest opportunities," he says.

Account Chooser lets users select any account managed by a company that has chosen to support Account Chooser, and then link that account to whichever websites they choose. It has already been implemented as the log-in page at Flickr, which now lets users access the site using not only a Yahoo account (Yahoo is Flickr's parent company), but also a Facebook or Gmail account.

Kaliya Hamlin, an independent industry expert who is a founder of the Internet Identity Workshop, feels that identity consolidation is very important. "This should be an aspect that most people shouldn't have to be aware of. It should just work," she says. Hamlin believes that the Account Chooser system is the clearest way for users to understand and control how their identities are being verified.

Don Thibeau, executive director of the OpenID Foundation, says the code behind Account Chooser was released under an open source license (meaning it can be reused and modified without charge) so that Web developers can implement it more easily, and can offer users a free choice of identity provider to use with the system. Account Chooser will also support a variety of standards used for identity verification, such as OAuth, SAML, and OpenIDConnect.

Mozilla, which makes the popular Firefox Web browser, has a developed a similar approach, with a system called BrowserID. After verifying that a user owns an e-mail address, BrowserID downloads a browser add-on that can be used to identify the user to sites that support the system. Ben Adida, technical lead for identity at Mozilla, says this is more secure than Account Chooser because information flows through the user's browser, and because it "limits the flow of information to what is strictly necessary to let users log in."

However, both Account Chooser and BrowserID need to be widely adopted by website owners and companies in order to reach a broad audience of users. Sachs hopes that Account Chooser's connection with Google (which is hosting the open-sourced code through the Google Identity Toolkit) will inspire other companies to join in. The full list of participants has not yet been released, but Sachs says that, besides Google, it includes companies such as Microsoft and Wordpress, and ranges from big names to small startups.

Account Chooser will be officially announced, along with more details, at the upcoming OpenID Connect Tech Summit, which starts on September 12 at Microsoft's Research Campus in Mountain View, California. Sachs says that "many vendors will be announcing their participation in the project over the course of the summit." (Technologyreview)

Friday, August 26, 2011

ISPs Could Make More Money by Offering Multiple Service Plans

With just a handful of different pricing packages, Internet service providers (ISPs) can increase profits and better meet demand, says a new paper by Nick Feamster, an associate professor in Georgia Tech's college of computing, and colleagues. (The paper, presented at the Special Interest Group on Data Communication conference, aka SIGCOMM, last week, is available here.) Tiered pricing is not new—several ISPs already implement it—but Feamster's team analyzed the effectiveness of tiers using models built from real-world ISP data.

"The research addresses the fundamental tension between the desire for simple billing models ... and the economic efficiency of the resulting flow of traffic," says Jennifer Rexford, a professor in Princeton's department of computer science. Simple models, like the blended rates based on megabytes of information per second per month that most ISPs use today, are easy to understand and enforce. However, blended rates disregard other factors, such as the distance the packets of data travel, that can influence the costs of providing service. Ideally, says Feamster, ISPs would offer an "infinite" number of tiers in which the price precisely reflected the costs of the service provided. But how much benefit do tiers offer compared to the bundled pricing used in today's systems? And how many tiers does it take to approach the optimal results?

To test the effectiveness of tiered pricing, Feamster used data gathered from existing networks to construct a theoretically optimal model with infinite tiers based on traffic and the distance that information had to travel. He also created models of pricing schemes with different numbers of tiers, based on the same criteria, and compared the price effects of these models with the optimal model. He found that the three-to-four-tier model was nearly as efficient (80 percent to 90 percent) as the optimal one.

The handful of easy-to-design tiers that Feamster tested offers "a great 'sweet spot' in the trade-off between simplicity and efficiency," says Rexford. "This work should be very useful to ISPs in fine-tuning their pricing models."

Andrew Odlyzko, a professor of mathematics at the University of Minnesota who studies Internet traffic, adds that this work provides some science-driven support to the emerging trend toward more complicated pricing models. Several ISPs have already switched to a tiered system, he says, but at this point "there are few guidelines for the carriers to follow."

Feamster points out that the research is not meant to advocate any particular method of designing tiers. The team organized the tiers based on demand and distance traveled because it was relatively simple, not because they expected it to be the most efficient tier design. More efficient tiers may be possible.

The study focused on Internet transit providers: large ISPs with a national or international reach whose networks act as go-betweens, allowing through-traffic to connect to smaller networks such as enterprises and universities. There are some hints, says Feamster, that similar patterns may emerge in the commercial market, where end users pay for access to the Internet; he and his team hope to investigate this area next.

Sascha Meinrath, director of the New America Foundation's Open Technology Initiative, sees implications for everyday Internet users. "Many of the core practices used by ISPs ... may be remarkably inefficient, a problem that would result in higher prices for end users." (Technologyreview)

Saturday, August 20, 2011

Is Your Internet Connection as Fast as You Think It Is?

The U.S. Federal Communications Commission released its first comprehensive study of broadband speeds across the United States on Tuesday. The study revealed that many Internet providers still advertise speeds higher than they deliver.

The report, "Measuring Broadband America," was commissioned as part of the FCC's efforts to promote improved broadband services across the United States. According to the Internet networking company Akamai, the U.S. ranks 14th in the world in terms of average Internet speeds, behind the Czech Republic, Latvia, and Belgium. Some U.S. ISPs have also been criticized for delivering Internet speeds that are lower than those advertised to users. The new report suggests that most providers now operate within 20 percent of their advertised speeds, even during peak hours; that's an improvement over the figures recorded in a 2009 report from the FCC.

The report also quantified the effects on home broadband connections of peak-time Internet traffic, which happens between 7 p.m. and 11 p.m. While fiber-optic connections were barely affected, cable and DSL users saw decreases of about 5.5 percent and 7.3 percent in download speeds, respectively.

The report highlights two metrics as most indicative of broadband service quality: throughput, measured in megabits of data per second (Mbps), and latency, measured in milliseconds, which is the time it takes for information to travel across a segment of a network. On faster networks, the effects of latency are proportionately more noticeable.

While other reports, including that of Akamai, have taken a wide view of broadband use around the world, this study offers a more in-depth examination of services in the United States. Shane Greenstein, a professor of management and strategy at Northwestern University's Kellogg School of Management, says this kind of report is needed. "We did not have a mature electricity industry until everybody agreed on how to measure use of electricity. And we cannot reach a similar state in our broadband industry without a similar agreement. This is a big step towards that, even though we still have a longer conversation in front of us."

The report is the result of a collaborative study with 13 major ISPs, including Comcast and Verizon; academics and other researchers, including from MIT; and consultants and consumer organizations. SamKnows, an analytics company, was selected to administer the FCC's broadband performance testing initiative.

According to the report, the FCC examined 6,800 homes and "conducted 13 different tests in each home, multiple times per day, over several months, to produce more than four billion data points from more than 100 million tests of broadband performance."

The report also quantifies the connection speeds required by consumers for various tasks. For basic Web browsing—"accessing a series of Web pages, but not streaming video or using video chat sites or applications"—a speed of one Mbps is sufficient, says the report, which also found that after 10 Mbps, there's no significant increase in page download speeds for basic Web browsing.

Sascha Meinrath, director of the New America Foundation's Open Technology Initiative, points out that some providers seem much better at delivering their promised speeds than others. "This study is indicative of the need for some sort of truth in ISP advertising," he says.

Meinrath also says that because the FCC did not release this data in advance, his group and other third-party researchers are only now beginning to review the data. He expects thorough analyses to take a few days.

A statement by FCC chairman Julius Genachowski summed up the FCC's perspective: "I expect broadband providers will look closely at the data we're releasing today and ensure they're providing accurate, relevant, and easily understandable information to consumers about their services. Providers should be aware that this survey isn't intended as a one-time thing." (Technologyreview)

Amazon Sees a Good Read in the Cloud

Yesterday, Amazon launched Kindle Cloud Reader, a Web browser-based version of its popular e-reading platform.

Built using HTML5, an emerging standard that lets Web applications function like desktop ones, the Kindle Cloud Reader looks and acts a lot like the Kindle apps created for the iPad, Android tablets, and PCs, even offering the ability to store content so it can be read in the browser offline. Experts say the move furthers Amazon's efforts to make Kindle the dominant standard for e-books.

Amazon's original Kindle, a device designed specifically for electronic reading, has long enjoyed dominance in the e-reader market. But Amazon has also built an empire that stretches far beyond this one device. The company gives away Kindle apps for a wide variety of devices, including PCs, Macs, Android tablets and phones, Windows Phone 7, Blackberry smart phones and tablets, and the iPad and iPhone. These free apps get readers to expect the Kindle format, and they encourage those who don't own a Kindle to build up a Kindle library.

The cloud-based app could extend Amazon's reach farther still. In a statement released at launch, Amazon noted that the Kindle Cloud Reader supports its philosophy of "Buy Once, Read Everywhere." The Kindle device and related apps all sync with one another via the cloud, so that a user can access her full library—with bookmarks, notes, and highlights intact—from any device.

Much of the early discussion around the launch has focused on the way the new app circumvents Apple's stringent App Store rules, because it can be accessed via the iPhone or iPad's browser, and doesn't need to be approved by Apple. Apple recently limited developers' ability to take users out of an app—such as by offering a link to make a purchase on Amazon.com. But publishing experts say that focusing on this squabble is shortsighted.

"The Kindle Cloud Reader is a game changer, from my perspective," says Kassia Krozser, owner of Booksquare, a site that tracks the publishing industry. "What really excites me about this platform is that it is browser-based; it uses the technology that people are using all day long. No special software is needed, no dedicated devices."

Krozser believes the browser is "the future of reading," since it gives aficionados the most flexibility and provides a familiar, easy-to-use environment for newcomers to test the waters.

The Kindle Cloud Reader is likely to make things easier for Amazon, too. "Amazon has worked hard to create apps specific to pretty much every platform available, which is one of the biggest reasons I read Kindle books almost exclusively," says Brian Sawyer, a senior editor at O'Reilly Media who manages the company's Missing Manuals division. "But it becomes a huge burden—and a losing game—to put this much development effort into every new operating system, especially ones whose user base and outlook [are] questionable."

The first version of Amazon's reader is designed primarily for the Safari and Chrome OS browsers, but the company plans to add support for other browsers, including Firefox and Internet Explorer, in the coming months. Sawyer says that once Amazon does this, the availability of Kindle books will leave Apple and other formats "far behind." He adds, "Amazon's Kindle platform is indeed becoming the de facto standard for consumer books."

Despite the likely impact of Cloud Reader, Amazon's format has its flaws. Michael J. Deluca, cofounder of independent e-bookstore Weightless Books, says that Cloud Reader makes him worry about privacy and control of his own digital assets. Deluca says that the Kindle format limits a publisher's design options. PDFs, which are by far Weightless's best-selling format, allow for artistic page designs. However, he notes, "The bottom line is that no matter how we or any small press feels about it, Kindle is already too big to ignore."

"[As both a publisher and a consumer], I'm disappointed that Amazon decided to try to carve out [its] own format," says Joe Wikert, who is general manager and publisher at O'Reilly. He says that Epub, a free, open standard supported by many in the publishing industry, offers a richer experience than the Kindle allows.

But Krozser wonders if Amazon will take this opportunity to embrace more-advanced technology. The latest version of Epub, Epub 3, is based on HTML5, she says, and it might make sense for Amazon to abandon its format to make better use of the browser. (Technologyreview)

When Social Media Mining Gets It Wrong

A complex picture of your personal life can now be pieced together using a variety of public data sources, and increasingly sophisticated data-mining techniques. But just how accurate is that picture?

Last week in Las Vegas, at the computer security conference Black Hat, Alessandro Acquisti, an associate professor of information technology and public policy at the Heinz College at Carnegie Mellon University, showed how a photograph of a person can be used to find his or her date of birth, social security number, and other information by using facial recognition technology to match the image to a profile on Facebook and other websites. Acquisti acknowledges the privacy implications of this work, but he warns that the biggest problem could be the inaccuracy of this and other data-mining techniques.

Acquisti says that his current work is an attempt "to capture the future we are walking into." In this future, he sees online information being used to prejudge a person on many levels—as a prospective date, borrower, employee, tenant, and so on. The Internet, he says, could become "a place where everyone knows your name"—a worldwide small town that won't let you live anything down.

Beyond the obvious concerns about strangers knowing more than ever about you, Acquisti worries about what will happen when the technology makes mistakes. "We tend to make strong extrapolations about weak data," says Acquisti. "It's impossible to fight that, because it's in our nature."

A number of companies have already begun using social media to measure and track reputation. The Santa Barbara, California, company Social Intelligence, for example, performs social-media background screenings on prospective employees, promising to reveal negative information such as racist remarks or sexually explicit photos, or positive information such as signs of social media influence within a specific field. Other companies, such as Klout, track users' level of social influence, allowing advertisers to offer special rewards to those with high scores.

But Acquisti's research demonstrated the pitfalls of placing too much relevance on social networking data. His team took photos of volunteers and used an off-the-shelf face recognizer called PittPatt (recently acquired by Google) to find each volunteer's Facebook profile—which often revealed that person's real name and much more personal information. Using this information, the team could sometimes figure out part of a person's social security number. They also created a prototype smart-phone app that pulls up personal information about a person after they are snapped with the device's camera.

In their experiment, the team was able to match about one-third of subjects to the correct profiles. From there, they made other predictions. Seventy-five percent of the time, they correctly predicted subjects' interests. They correctly predicted the first five digits of volunteers' social security numbers about 16 percent of the time given two tries. (Accuracy increased with more attempts.)

But this means that two-thirds of the time, they did not identify people correctly. And those who were correctly identified were still incorrectly matched 25 percent of the time to particular personal interests, and more than 80 percent of the time to the wrong social security number.

Acquisti expects facial recognition technology to continue improving in coming years, and he asks what will happen once it is considered good enough to be trusted most of the time. It could be nightmarish for those who are misidentified. "There's nothing that we, as individuals, can control," he says.

Other researchers are exploring the reliability of mining social data. At Defcon, a hacking conference in Las Vegas last weekend, a group called the Online Privacy Foundation presented results of its "Big Five Experiment," a study that aimed to match volunteers' personality traits to qualities on Facebook profiles. After administering a personality test to volunteers, they mined profiles to identify key characteristics.

The Online Privacy Foundation researchers found a positive correlation between people whose personalities tended toward openness and those whose Facebook profiles were loaded with more information: longer lists of interests, longer bios, and more discussion of money, religion, death, and negative emotions. They also found a positive correlation between "agreeable people"—defined as "being compassionate, cooperative, having the ability to forgive and be pragmatic"—and Facebook statuses that were written in longer sentences, that discussed positive emotions, or had relatively more comments, friends, and photos. However, in both cases, the correlations were relatively weak.

The researchers conclude that a Facebook profile is hardly a reliable source of information. "The key point is to remember that this is a bet," says the foundation's cofounder Chris Sumner. "The message is that, yes, there is a link, but don't use it on its own for critical decisions."

Acquisti and Sumner say that new government policies may be needed to protect individuals from excessive data mining and from the misuse of their information. This could involve setting standards of accuracy for organizations to abide by. "The defining question of our time," Acquisti says, "is how do we, as a society, deal with big data?" (Technologyreview)

Friday, August 19, 2011

Status Update: What's Facebook's Effect on Kids?

Some parents wonder if Facebook could be harming our ability to socialize. A handful of psychologists are now starting to ask same the question.

Larry Rosen, author of several books on the psychology of technology, and a research psychologist at California State University, Dominguez Hills, is one of several researchers trying to quantify the psychological effects that Facebook is having on users across generations, with a particular eye toward teens and young adults.

Rosen has already collected some early evidence that suggests that Facebook use may somehow be connected to narcissistic behavior, alcohol dependence, and other psychiatric disorders. But he has also found evidence that Facebook use may be associated with increases in virtual empathy—the ability to consider someone else's emotional state from a distance.

Rosen has carried out surveys measuring a person's (self-reported) level of Facebook use—how often he or she reads wall postings, posted photographs, etc.—along with his or her psychological state, using classical psychological questionnaires, as well as an analysis of his or her Facebook posts.

Rosen presented preliminary findings from several research projects during a talk titled "Poke Me: Kids and Social Networking" at the American Psychological Association Convention in Washington, D.C., this weekend. His was not the only talk to address this issue; "social media and technology" was one of the key subject areas of this year's convention, which gathered leading researchers from around the world.

Rosen's work is part of a broader debate over what effect the Internet is having on our minds. While some observers suggest that microblog posts, social networking updates, and other bite-sized forms of expression and communication could be making us less able to think deeply, others argue that these technologies are simply being exploited by our brains in new ways, and say such fears are common with any disruptive new technology.

Rosen's work focuses on the differences between generations, and on the way technology affects kids. "All of these technologies have to be evaluated as they impact your life," he says. Adults can evaluate and reject various technologies—he offers the example of people turning down Google+ invites—but kids lack the experience and self-control to do so, he says. They may be more tech-savvy than their parents, but they are also under greater social pressure to engage with the next big thing, Rosen argues.

Zeynep Tufekci, an assistant professor of sociology at the University of North Carolina, Chapel Hill, who specializes in the social impact of technology, suggests that parents' worries about the effects of social networks on children may be overblown. "While changes to the technological environment real are and do have important consequences, today's youth are interested in very similar things compared to past generations and are not some sort of alien race unlike any that walked the earth," she says.

Rosen cautions that his work thus far has only shown a connection between certain kinds of behavior and Facebook use, not causation. Whether Facebook encourages narcissistic tendencies in its users, for example, or happens to attract narcissistic users in the first place, is not clear yet.

At the American Psychological Association Convention, Elizabeth Carll, a clinical psychologist and author, presented a talk on the effects of cyberbullying and online harassment. She offered the observation, based on experiences at her own clinical practice, that the negative effects of cyberbullying can be more severe than face-to-face confrontations. The thing that makes it different, she says, is the fact that it's impossible to escape. "Cyberstalking is 24/7," she says. "The world knows instantly. If your boyfriend has a compromising picture of you, he can send it to anyone."

Some psychologists are more skeptical about the impact of recent technological shifts. John Suler, a professor of psychology at Rider University, says "the current fascination with technology and social media is, in my opinion, just a stage we're going through ... Over time, as the technology craze starts to quiet down, we'll realize once again that balance in online/offline activity is as important as any kind of balance in life."

Michele Strano, assistant professor in the department of communication studies at Bridgewater College, says Facebook may simply reinforce existing behavior. "Many of our Facebook friends are people we also interact with in face-to-face environments," she says. "Thus, our online and offline identities tend to have some consistent threads."

Ultimately, says Tufekci, the needs of kids today are not all that different from those of kids in the past, Facebook or no: "They want approval of their peers, are often interested in pushing and testing boundaries, and need support and love from their parents as they deal with the pressures and rewards of growing up." (Technologyreview)

The TV That Watches You

Many people surf the Web while they watch television. Soon­­­ the websites they visit could adapt in real time themselves to the shows being watched—automatically presenting information relevant to the show, or even tuning their ads in response to what you're watching.

A new type of Internet-connected television, due out before the end of the year, has built-in software and hardware that send data about what is on-screen to an Internet server that can identify the content. Web pages being viewed using the same Internet connection as the TV set can then tap into that information. The system can identify any content onscreen, whatever the source, whether live TV, DVDs or movie files playing from a computer.

Flingo, the San Francisco-based startup that developed the technology, known as Sync Apps, says the new set is already being mass-produced by one of the top five television brands in the U.S. and will retail for less than $500.

"Any mobile app or Web page being used in front of your TV can ask our servers what is on right now," says David Harrison, cofounder and CTO of Flingo. "For example, you could go to Google or IMDB and the page would already know what's on the screen. Retailers like Amazon or Walmart might want to show you things to buy related to a show, like DVDs, or what people are wearing in it." Social sites such as Facebook or Twitter can use the service to connect viewers to a TV show's official page or stream. When a user flips channels, or a show ends, the Webpage being viewed knows about it and can instantly update to the new viewing.

Flingo has made available a public API (application programming interface), so developers can build mobile and Web apps that use the television's inside knowledge. The TV will also display pop-ups on-screen, offering further Web-retrieved information about a show, or links to apps on the set itself.

All of this occurs with the permission of the television's owner, says Harrison. The first time the TV is switched on, it asks users if they would like to opt in to the data-sharing service. If they say yes, it prompts them to accept a terms-of-service agreement. Individual sites and apps must ask for, and be granted, permission to access the data the TV makes available.

Ashwin Navin, Flingo's CEO and other cofounder, says he expects people to opt in because the service offers an automatic way to do what people are already doing manually. "People are doing the work to search for information to go with their viewing," he says. "We'll have all that information right there."

The data generated by a television with Sync Apps is also valuable to advertisers. Already, online ads can be targeted based on the content of a Web page and the viewer's browsing history. Navin says that his company will enable sites to match ads to a person's TV-viewing history too, at least on sites that have received permission to use the television's data.

"If we can improve the recommendations made in ads, people will get a better experience," says Navin. "Otherwise, they are noise."

Andy Tarczon, an analyst covering consumer electronics and media with TDG Research, says his research shows there is a ready audience for extra information and context about television content. "In surveys and interviews, we see that consumers want to have more information around their programs, because it's how they find new content to watch," says Tarczon. "Social media, 'checking in' to shows like you do places on Facebook, always scores the lowest." That is, consumers want more information, but they'd rather not have to work to get it.

Tarczon notes that Flingo already has strong relationships with television companies including CBS, MTV, and Fox, after spending several years helping them develop apps for Internet-connected televisions. In this respect, Flingo contrasts sharply with Google, which has its own ideas about combining Web and television. CBS and Fox, among other content providers, block devices using Google TV from accessing their online television content, because Google TV encourages users to discover content via a Web search on their TV screen, which can point them to pirated material.

Tarczon says that Flingo's approach fits better with the networks' desire to use the Web to build stronger relationships with viewers while keeping their traditional business model. "They want to use the Web and apps as an augmentation to their existing content." (Technologyreview)

Facebook Wants to Supply Your Internet Driver's License

Although it's not apparent to many, Facebook is in the process of transforming itself from the world's most popular social-media website into a critical part of the Internet's identity infrastructure. If it succeeds, Facebook and Facebook accounts will become an even bigger target for hackers.

As security professionals debate whether the Internet needs an "identity layer"—a uniform protocol for authenticating users' identities—a growing number of websites are voting with their code, adopting "Facebook Connect" as a way for anyone with a Facebook account to log into the site at the click of a button.

Facebook introduced Connect back in July 2008, offering third-party websites tools to coordinate with the user information that Facebook holds, including logins. Thus websites had the option of allowing Facebook users to identify themselves with their Facebook identities.

So, for instance, the Web statistics vendor Alexa gives new users the choice of creating an account by entering a username and a password or by simply clicking the "Connect with Facebook" button. Well-known websites that also use Connect include the Internet Movie Database, Ask.com, and ESPN. Others will almost certainly jump on the bandwagon in 2011.

Facebook's identity system might very well supply something that VeriSign, Microsoft, Yahoo, and Google have all struggled to offer: a single "driver's license" for the Internet. (This leaves aside the question of whether it's a good thing for one company to hold such a position of power.)

A unique combination of factors makes Facebook well suited to being the repository for people's identities on the Internet. Unlike many popular websites, it requires users to register and log in. And Facebook's terms of service require that "users provide their real names and information"—indeed, Facebook has terminated accounts that were created with seemingly fake names or for fictional characters. Since Facebook users invest their accounts with a tremendous amount of durable personal content—including photographs, contact information, and connections to their social network—they are likely to keep a long-term relationship with the site.

This persistence of real identity puts Facebook in a position to solve one of the most pressing problems on the Internet today—the proliferation of user names and passwords.

Contrary to today's practice, there is no reason for most websites to force their users to create usernames and passwords. Most websites don't need or even want or need to manage the identities of their users—they simply want a way to reliably identify their users over time. Media websites, for instance, want to be able to attribute comments and limit spam. Personal-finance websites want to give users a way to monitor highly personal information securely—for example, a portfolio of stocks that the user might enter.

What's more, maintaining a user-identity infrastructure has its risks—as was made painfully clear last month when hackers broke into servers operated by Gawker Media and downloaded the user names and passwords for more than a million of Gawker's accounts. Even though the passwords were encrypted, many were easy to guess, so the accounts could be readily cracked, according to an analysis of the attack by security researchers at the University of Cambridge. Following the attack several unrelated websites, including LinkedIn and Woot, sent e-mail to their users warning them to change their passwords if these were the same ones as they used for Gawker.

Facebook Login lets any website on the planet use its identity infrastructure—and underlying security safeguards. It's easy to implement Facebook Login, simply by adding few lines of code to a web server. Once that change is made, the site's users will see a "Connect with Facebook" button. If they're already logged into Facebook (having recently visited the site), they can just click on it and they're in. If they haven't logged in recently, they are prompted for their Facebook user name and password.

An interesting side benefit for website operators is that Facebook Login provides the site with users' real names (in most cases) and optionallya variety of other information, such as the users' "friends" and "likes." Currently, Facebook doesn't charge websites to use its identity infrastructure or access this additional information, though Facebook certainly could in the future.

Facebook is already well acquainted with Internet security issues, simply because it holds personal data for more than 500 million people. The increased use of the Facebook platform for things beyond social media—a bank in New Zealand, for instance, announced in November that it would allow customers to access banking information on Facebook—obviously raises new concerns. And if the company extends its reach to offer a universal login on the Web, the challenges it's likely to face will become greater still.

Indeed, over the last few years Facebook has taken steps to improve the security of its platform in several ways.

For example, last year Facebook introduced a system that lets users request a one-time password to log in from a public terminal that might have keystroke-logging spy software installed. Users send an SMS text message containing the letters "otp" to 32665 ("FBOOK") from a registered cell phone, and Facebook's servers send back a password that can be used just once to log into the user's account. The theory is that it doesn't matter if a hacker is running a password sniffer, since the password won't work a second time.

Another innovation is the way that Facebook allows users to monitor the various Web browsers and devices from which they log into Facebook. By clicking on the "Account Settings" pull-down menu and selecting the "Account Security" section, Facebook users are able to see all of the devices currently authenticated, any of which can be remotely logged out—useful if you happen to leave yourself logged in on your parents' computer. You can also have Facebook send an SMS notification to your cell phone whenever a new device accesses your Facebook account. Of course, if you see a connection from a machine that you don't recognize, it's time to change your password.

Unfortunately, Facebook still has two important vulnerabilities that makes its website significantly less secure than those of most U.S. banks: its reliance on a single user name and password to gain access to an account, and its use of an unencrypted cookie for tracking which web browsers are logged in.

The user name and password combo provide a point of weakness. Facebook accounts can be compromised by an attacker who might steal this information from another site—or guess it by trying many combinations in succession (a so-called brute-force attack).

"We've built systems to protect against these types of brute-force attacks," says Simon Axten, a spokesperson for Facebook. "For example, if we detect a number of suspicious login attempts for a given account, we will require a CAPTCHA, and we may even temporarily suspend access to the account."

Facebook monitors a number of "signals," including location and device, Axten says, to determine when an account is being subjected to a sustained attack. "Once we've flagged an attempt—even if the correct login credentials have been entered—we'll require the person logging in to provide additional authentication by, for example, answering a security question, entering a code sent via SMS, or identifying friends tagged in photos to which the account owner has access."

Nonetheless, there are ways to gain access to a person's Facebook account even without knowing the password. That's because Facebook uses something called an authentication cookie to keep track of a Web browser when it's logged in. Unlike Facebook passwords, which are encrypted when they're sent over the Internet, the cookies are sent to Facebook's non-encrypted Web servers every time a computer communicates with the site. This isn't much of a risk if you are using a hard-wired Internet connection or an encrypted wireless connection at work or at home. But if you are using Facebook over an unencrypted wireless access point at a coffee shop or airport, someone running a packet sniffer on a laptop could steal your authentication cookie out of the air and then log into Facebook as you.

Such sniffing became easier than ever to perpetrate last fall, when Eric Butler, a freelance Web application and software developer in Seattle, released a Firefox plug-in called Firesheep that automates the process. With Firesheep running inside Firefox, you get a list of every authentication cookie that's been sniffed: just click on the account name and—voilà—you are accessing the user's account without even having to log in.

Right now the only way to protect yourself against cookie sniffing is by accessing Facebook using the encrypted connection at https://ssl.facebook.com/. According to Axten, the server is still undergoing testing and will be more widely promoted as an option "in the coming months." He adds, "As always, we advise people to use caution when sending or receiving information over unsecured Wi-Fi networks."

Axten says, "Facebook faces a security challenge that few, if any, other companies, or even governments, have faced—protecting more than 500 million people on a service that is under constant attack. The fact that less than one percent of Facebook users have ever encountered a security issue on the site is a significant achievement of which we are very proud." (Technologyreview)

Why Google Bought Motorola

Google announced today that it has agreed to acquire the smart-phone manufacturer Motorola Mobility for $12.5 billion.

In a statement, Google said the deal was largely driven by the need to acquire Motorola's patent portfolio, which it said would help it defend Android against legal threats from competitors armed with their own patents. This issue has come to the fore since a consortium of technology companies led by Apple and Microsoft purchased more than 6,000 mobile-device-related patents from Nortel Networks for about $4.5 billion, in early July. Battle lines are being drawn around patents, as companies seek to protect their interests in the competitive mobile industry through litigation as well as innovation.

However, as people increasingly access the Web via mobile devices, the acquisition could also help Google remain central to their Web experience in the years to come. As Apple has demonstrated with its wildly popular iPhone, this is far easier to achieve if a company can control the hardware, as well as the software, people carry in their pockets. Comments made by Google executives hint that Motorola could also play a role in shaping the future of the Web in other areas—for instance, in set-top boxes.

Motorola is by far Google's largest acquisition, and it takes the company into uncertain new territory. The deal is also likely to draw antitrust scrutiny because of the reach Google already has with Android, which runs on around half of all smart phones in the United States.

Motorola, which makes the Droid smart phone, went all-in with Google's Android platform in 2008, declaring that all of its devices would use the open-source mobile operating system.

Before his departure as Google CEO, Eric Schmidt had begun pressing Google employees to shift their attention to mobile. Cofounder and new CEO Larry Page seems determined to maintain this change of focus. In a conference call this morning, he told investors, "It's no secret that Web usage is increasingly shifting to mobile devices, a trend I expect to continue. With mobility continuing to take center stage in the computing revolution, the combination with Motorola is an extremely important event in Google's continuing evolution that will drive a lot of improvements in our ability to deliver great user experiences."

Motorola engineers have extensively modified Google's basic Android platform for its devices. For example, the company designed Motoblur, a user interface that pulls together Twitter, Facebook, and other social sites, into a single stream of data, and this has been a major selling point for the company's phones. (Technologyreview)

Mozilla Wants a Browser to Control Your Phone

The makers of the Firefox browser are trying to create a mobile browser powerful enough to run your smart phone.

The Mozilla Foundation's Boot 2 Gecko project is part of a shift toward software that runs largely on the Web—instead of on the device itself—for all sorts of tasks, and on all sorts of gadgets.

Boot 2 Gecko is similar to Google's browser-based Chrome OS, an operating system built into the browser. But the Mozilla effort could have a broader impact, by changing the way all Web browsers function, not just Mozilla's.

Mozilla engineers want to significantly expand the things browsers can do. They want the browser to access the contacts list and other data on a device, and connect to the camera and other hardware. The final step will be to replace the phone's operating system itself. The effort will start, naturally enough, with Firefox (Gecko is the name of the rendering engine at the heart of the Firefox browser).

If it succeeds, the Boot 2 Gecko project will move many of the functions now carried out by mobile operating systems—Android, Apple's iOS, WebOS, MeeGo, and others—into the browser itself. Basic phone functions like the dialer would be recoded in JavaScript so they could run in the browser. In time, almost all of the functions of a conventional operating system could run in the browser, in code cached on the phone and updated from the Web when necessary. Ultimately, say those involved, this trend would eliminate the need for proprietary operating systems, replacing them all with open standards that could run on any mobile browser.

"On the Web, an application is accessible to everyone, regardless of operating system. This should be the same with applications on phones," says Mike Shaver, Mozilla's vice president of technical strategy.

It isn't the first time that someone has tried to build an open-source Web-based OS. Ben Francis, founder of the Webian browser-based OS project, sees the Mozilla team's efforts as complementary to his own. While the Webian project focuses on "the user experience for a device dedicated to browsing the Web," the Mozilla team is pushing for new capabilities to be built into Web browsers—such capabilities are already the backbone of many sophisticated websites.

Ironically, underneath the hood of Mozilla's prototype Boot 2 Gecko platform is the core of one of the platforms it hopes to supplant—Android. As the Mozilla team outlined on the developer forum for the project, it needed a basic, stable kernel on which to build the platform to avoid spending too much time simply getting the prototype to boot up.

Ultimately, contends Boot 2 Gecko developer Mike Shaver, the project is about developing standards that will run in any browser, on any core software, and on any hardware—rendering the choice of prototype platform irrelevant.

Boot 2 Gecko also differs from most mobile platforms in that it is not designed to give any one company an advantage. "That's an important difference between what we're doing and proprietary mobile stacks today," says Shaver. "We don't want a competitive advantage for Mozilla, we want a competitive advantage for the Web."

As Mozilla contributor Robert Kaiser pointed out in the initial discussion following the announcement of the project, the end result may not look anything like a conventional browser.

"It's likely that [mobile Web apps] would run in something that didn't have all the usual trappings of a browser, but the underlying technology would be the same," Shaver wrote.

Truly open Web technologies in this mold would have another advantage over native ones—endless customizability. Don't like your phone dialer? Just download a different one. It's easy to see how some makers of mobile devices wouldn't like that. "I expect some heel-dragging from those who stand to benefit from closed proprietary systems," says Francis. (Technologyreview)