Showing posts with label Google. Show all posts
Showing posts with label Google. Show all posts

Monday, March 18, 2013

When Google’s Eric Schmidt introduced “The New Motorola”

When Google’s Eric Schmidt introduced “The New Motorola” on stage last year, after appointing Googler Dennis Woodside CEO of Motorola, it was made clear that the company would undergo some serious restructuring to fit in more with Google’s corporate values. What was unclear at the time was the volume of jobs the company would be shaving in order to bring the mobile manufacturer to profitability.

Google inherited quite a mess when they purchased Motorola. 18 months of products that weren’t likely to sell particularly well, a relationship with Verizon Wireless that promoted things like locked bootloader and bloatware, and a corporate ecosystem that was too large to succeed in the market today.

Since the announcement of “The New Motorola” there’s been a lot of changes made to try and right the ship. Google employees were put in key leadership positions, rumors of a powerful X Phone coupled with UI changes to make their phones look more like Stock Android, and now two different workforce adjustments. The company has confirmed today that 1,200 jobs have been cut on top of the 4,000 jobs that were cut back in August, with no confirmation as to whether or not more will come after this.

It’s not all layoffs in Motorola land. Recently the company hired Guy Kawasaki to advise on the next steps for the company. Guy made a name for himself as an Apple evangelist early on, but has since moved to support the Android platform as well as Google’s social network. The hope is that Guy’s influence alongside other Google transplants will work to fix the existing pipeline of products and set up a business model moving forward that leaves the company more able to compete with Samsung and Apple in the next year.
Reade more >>

Google is in the business of extracting as much information as possible

Google is in the business of extracting as much information as possible from the world so they can better target ads for their customers. Many of their ideas for doing this, like Android, are not only great but terribly effective. This talking shoe concept, which was shown off at SXSWi recently, goes a little too far.

Imagine sneakers that could connect to your phone via Bluetooth and feed apps information about how your run is going. They maybe they will pull in GPS data and create some nice graphs about your run. Maybe this information is exciting enough to you that Google will wrap it up in a format that can be easily posted to Google+. It’s even possible that, after a certain number of steps at a certain speed, your phone polls your GPS and Google Local for a good place to stop and get a drink or an energy bar. Sound like ideas that a lot of people would enjoy, right? What’s the one thing that could ruin that entire experience? When your phone uses all of that information to talk to you.

It’s no shock that Google’s Bluetooth-enabled shoe prototypes are all about collecting information and presenting it for both the users and the advertisers. It’s really unlikely that Google is going to get into the shoe business anytime soon — this is more a proof-of-concept. And as far as tech demos go, this isn’t so bad. When you look at how personal area networks and the “internet of things” comes together to grab tons of little bits of data from all over and turn it into useful personal add-ons, shoes that could help you out like this would be great.

The problem with this concept comes in right at the end, where the shoes feel the need to let you know when they are bored, or to congratulate you when you are really active. It could just be me, but I’ve got a feeling that there’s not many people out there who want their robotic shoes to cheer them on.
Reade more >>

Sunday, March 17, 2013

As Android’s market share grows and software like Chrome OS become more popular

As Android’s market share grows and software like Chrome OS become more popular, so does the desire to attend Google’s main event. This means every year the registration process for Google’s I/O developer conference gets more difficult and the competition to get a ticket ramps up. This year Google seemed to have everything under control, but it looks like many users feel the search giant tripped at the finish line.

The I/O registration process was entirely Google-centric this year. You needed a Google+ account, with your payment information pre-loaded into Google Wallet. After that everyone was told that if you followed the instructions you’d have a fair shot getting in.

The instructions were simple, though mildly akin to being told not to look down when standing somewhere very high. If you parked yourself at the I/O registration page a few minutes before 10AM ET, you’d be put in line to get a ticket. Registrants were warned: Don’t refresh, don’t mess with the site, and don’t have multiple tabs open if you want things to go smoothly and to ensure your place in line. Google gave people plenty of warning and explained everything clearly, but smooth is about the furthest thing from how most would describe today’s registration.

If you were waiting well in advance, the website shifted at 9:30 to a countdown for the registration to be open. As the count drew closer to zero, the color changed to a bright red, just in case you weren’t starting at the ticking clock. When the virtual doors opened, a loading ring GIF sat and informed you that Google was searching for a ticket to give you.

If this didn’t timeout and offer you an Error 500 page, you were to confirm your information and head to checkout. Google placed a five minute timer on registration, and at the end of that period your ticket was put back in the general access pile. Five minutes would be more than enough time to checkout under normal circumstances. Unfortunately, Google’s own checkout service hung for many, leaving them unable to complete the transaction in time.

Google Wallet offered users a different loading ring, this time in an attempt to pull the records for their payment information. Given Google’s stern warnings regarding refreshing or tampering with the site, users were left with little option but to sit and watch as the clock counted down on the registration. When it did inevitably time out, they had to start the process over and hope that they would not suffer the same fate as before. After 45 minutes of the process, social networks finally began to populate with users who had gotten tickets to the conference. Minutes later, the website announced that tickets were sold out.
Reade more >>

While some browsers fell fast at CanSecWest’s hacking competition, Google’s Chrome fared pretty well

While some browsers fell fast at CanSecWest’s hacking competition, Google’s Chrome fared pretty well. In fact, it has yet to have a zero day exploit emerge in the wild during its four years on the market. No doubt this invincibility comes from the efforts Google put in to securing its web browser, a browser Chaouki Bekrar, chief researcher at French cyber security contractor VUPEN, sings the praises of for its security measures.

Chris Evans is the Googler in charge of security for Chrome. We had the opportunity to chat with him at CanSecWest in Vancouver about browser security.

Geek.com: Security contractors at this conference have usually ranked Chrome as the most secure browser. Why is this? What’s the key to Chrome’s security?

Chris Evans: Chrome was designed from the start with security in mind, including integrated sandboxing and Safe Browsing malware protection. We have a large Chrome security team who engage in proactive hardening measures, fuzzing at scale and fast patching of bugs.

And beyond our team we make it a priority to engage with the wider community–one of our core security principles — via our Chromium Vulnerability Rewards Program and Pwnium competitions. Securing a browser takes a lot of effort, but it’s important work as it’s often a user’s first line of defense against bad actors on the web.

What’s the process between discovery of a threat in the wild and rolling out a patch?
There is an important distinction between controlled and responsible (“white hat”) exploit discovery, and threats “in the wild” or zero days. We proactively seek the former to allow us to better manage in the event we experience the latter.
In Chrome’s four years we haven’t had an zero-day situation, but we feel we’re battle ready if the situation arises. Through our three prior Pwnium competitions we’ve demonstrated two 24-hour turnarounds and one 12-hour turnaround. It is important to have a well-practiced incident response process and team.
Our process involves convening a war room of engineers, reviewers, and release managers. We’ve also built a fantastic thorough and automated testing infrastructure that gives fast confidence in any proposed patches. The most important part of course is our ability to quickly push updates to our users, which is possible thanks to Chrome’s seamless auto-update feature. The auto-update approach is now used by most other browser makers, validating its effectiveness.
Over the last year, what trends in malicious code and exploits have you noticed emerge in the wild?
There’s been a continued focus on browser plug-ins. The most interesting thing I’ve seen is some in-the-wild attacks (and escapes) against plug-in sandboxes. As sandboxes are recognized as a best practice they are becoming more prevalent. Still, escaping a sandbox is hard work so this gives an idea of the resources attackers are willing to invest.

What’s the biggest threat vector for web browsers? What constantly gives you the most headaches?

Plug-ins continue to be a big security issue. They add extra exploit real-estate for online threats and since they’re separate software they require separate updates, which most often requires action on the part of the user. So oftentimes plugins on users’ machines are out-of-date, which compounds their vulnerability.

In Chrome we’ve bundled Flash and a PDF reader and placed them inside a separate sandbox that’s as strong as Chrome’s native sandbox to help protect users. Because they’re packaged these plugins are auto-updated with Chrome, which significantly improves the likelihood of users being up-to-date. Chrome also blocks out-of-date plugins from running. Chrome even blocks up-to-date plug-ins from running until the user indicates permission, if that plug-in has a history of zero-day attacks against it.

Are there different threats with the mobile edition of Chrome? Or is the malware experience the same?

We build Chrome for Android to the same standards of security we have for desktop Chrome. This includes an integrated sandbox, various security hardening features, and fast  regular patches.

Firefox seems to fare poorly at events like Pwn2Own. If you could be Mozilla for a day, what would you do?
Reade more >>

Saturday, March 16, 2013

As Andy Rubin, the father of Android, steps down to pursue other Google-based projects

As Andy Rubin, the father of Android, steps down to pursue other Google-based projects, and Chrome lead Sundar Pichai will step up to handle his existing workload as well as instructions to “double down” on Android. It’s pretty natural to assume that there will be some cross communication between Android and Chrome, but how far will that really go?

Imagine the world that we would live in if Android and Chrome OS played together. Android apps running in Chrome tabs, background updates for Android that happen without interrupting the user, and everything in the cloud. There’s plenty of reasons to want this merger to happen, and there’s more than enough talent at Google to make it happen. The line between these platforms has always seemed pretty thin anyway, especially since they are both made by Google. If you take a step back and look at the two platforms from the ground up, however, you’ll see that there’s more than a few necessary differences.

Android grew in popularity by being something open source that any company could pick up and make their own. The Android platform focused on easy sharing and enabling location-aware devices that made your mobile tasks easier. The specific focus there was enabling the user to be able to do more on these tiny pocket computers. Along the way, this design has changed shape a bit, but the overall focus hasn’t changed.

This is wildly different from Chrome OS, which aims to remove as many layers as possible between you and the web. Hassles like file systems, apps, and having to be concerned about the way your computer is behaving are seen as distractions. Chrome OS isn’t about being more productive with a more powerful machine, it’s about being more productive by removing distractions.

In order to see a real merger here, Pichai would have to embark on the same journey he did with Chrome. The browser needs to be something that requires no thought from the user, and in many ways that is exactly what Chrome is. If you apply that same logic to Android you would be looking at an OS where version number is irrelevant. Everything is always up to date, and the hardware is never something you have to think about because it is always something that “just works”. Android is pretty far from that luxury right now, especially since they are part of an aggressive ecosystem whose primary focus right now is delivering the best features.
Reade more >>

Like most smartphone releases, details surrounding the Samsung Galaxy S4

Like most smartphone releases, details surrounding the Samsung Galaxy S4 are pouring in from every direction just before the official unveiling this evening. More information about the international (or at least the Chinese) variant of the phone have popped up, this time bringing higher quality photos, components details, and videos of the headlining features for Samsung’s next flagship Android smartphone.

There’s been no shortage of whispers surrounding the Samsung Galaxy S4 and its suspected innards, though the sheer volume of rumors breeds doubt that most of them are true. Samsung’s Galaxy line has grown popular enough that the first wave of renders and specs that “leak” are often little more than wishlists from fans eager to see their favorite manufacturer deliver the best possible product for the coming year. The Galaxy S4 is upon us nevertheless, and while it may not have a lock on being the best phone of 2013, what we know about it so far assures that it will be a highly sought after handset.
 
From previous leaks of Chinese models and a sneak peak from Samsung earlier in the week, we know that the front of the Galaxy S4 will be nearly identical to its predecessor. The Galaxy S3 is hands-down the best selling Android phone to have ever been made, so it would be silly to mess with that design if you don’t have to. Today more images and video emerged, giving expectant fans a nearly completely look at what seems to be a variant of the GS4.

There are some subtle differences to the casing, since the 4.99-inch screen is a slight increase over the 4.8-inch found in last year’s Galaxy S3. The increase in size is matched by a drastic increase in resolution, bringing the often rumored 1080p SAMOLED+ screen to replace the previous 720p screen. The added screen size and extra 500mAh found in the battery make the GS4 an imperceptible 5 grams heavier, but will also be a full millimeter thinner than the Galaxy S3.

As if the display and battery weren’t impressive by themselves, it’s being reported that the Galaxy S4 will pack a tri-core PowerVR 544MP3 GPU alongside the previously unearthed sort-of-but-not-really octo-core processor. The Exynos Octa has eight physical cores, split between four Cortex-A15 and four Cortex-A7 cores. The big.LITTLE setup here is designed to allow the more powerful cored to handle any heavy lifting that needs doing, while the less powerful cores handle low power tasks like garbage collection. This is the first Android phone to deploy this setup, and while the concept suggests that there will be significant gains in battery life there’s yet to be any significant real world testing.

Samsung won’t win the hearts and minds of the world on hardware alone, and just like last year it looks like the company is stuffing their TouchWiz flavor of Android with a ton of features that you can only find on their phones. We’ve heard plenty about the ability to use your eyes to control the phone, and now there’s a video of one such behavior in action. If you are watching a video on the Galaxy S4 and you look away from the screen, Samsung’s Smart Pause will pause the video without any commands from the user, and will begin playing again once your face is detected by the front facing camera. Like many of Samsung’s features, SmartPause is likely something that you’ll have to activate and it is unlikely to work in apps like YouTube and Netflix.
Reade more >>

If you use Outlook.com for email, the last few days may have been a frustrating time for you.

Upset that Google is shutting down Google Reader this summer? You’re not alone. The death of RSS, on numerous occasions, has been greatly exaggerated. The truth is that millions of people still use feed readers on a daily basis. They’re a convenient way to sift through the mountain of near-real-time content that gets published every day on the web.
So where do you turn now that Google Reader is being put out to pasture? You could use a desktop RSS reader, but chances are that if you were using Google Reader you’d probably prefer to stick with a web app instead.
Some better-known alternatives are Bloglines and Netvibes. Both are solid options, but Bloglines is a better choice if you’re after something that works a lot like Google Reader does. Netvibes is more of a personal start page, while Bloglines more closely resembles a traditional feed reader. It’s also got loads of personalization options and it’s totally free — Netvibes charges for some functionality.
There’s also The Old Reader which claims to be just like the old Google Reader, only better. It’s getting hammered right now, so you’ll have to take their word for it, but TOR has been a popular alternative for quite some time.

If you don’t mind switching up to something that places more emphasis on aesthetics than Google Reader, have a look at NewsBlur, Taptu, or Pulse. Newsblur is laid out a lot like Google Reader, but “feels” more like a desktop app. The others are all presented in more of a thumbnailed, curated digital magazine format — not a bad thing, just not the workmanlike experience Reader provides.


You may find that all of these services are struggling to keep up with the demand for new accounts, and that’s no surprise. Google might think that Reader was underused, but there are still millions of avid news readers on the web that are out there looking for a new services that works well and isn’t going to be shut down any time soon.

Reade more >>

Friday, March 15, 2013

As many of you might have noticed

As many of you might have noticed, Google announced that it would be sending its RSS reader gentle into that good night. With the amount of outrage and shock that you most likely saw spread across your favorite blogs and social networks, the shuttering of Google Reader probably seemed like a crazy move from a company that would be losing a popular service with an extremely dedicate following. The thing is, though, it’s not like Google doesn’t have access to Reader’s numbers. So, when Google says Reader’s population wasn’t enough to justify the service’s existence, the amount of outrage you saw on the internet about it is most likely from a very vocal minority. In response, Brian Shih, a former product manager for Google Reader, took to Quora to explain why Google had to shut down the service.

You might have found that most people assume that Reader simply didn’t generate enough revenue to cover operating costs. Shih explains that Reader never directly made money, and recalls that Reader was faced with moving its staff onto other projects more than once, in order to build OpenSocial, Buzz, and Google+. All of those projects were social-based, and Shih believes Google always wanted to use the Reader team on other social projects because the Reader team understood the socialscape. So, it’s not like Google didn’t value the people behind Reader.

reader_android_appGoogle decided to shut down Reader in 2010, and then when Google+ hit the market and the sharing features of Reader were diminished, Shih suspects that is when the Reader population began to plummet. So, with Reader’s sharing features taking a backseat to Google+, and with Google aiming for a more consolidated, focused effort in recent times, the company decided it was time to focus more, and kill off a product that wasn’t being used enough.

The reason why you’re seeing seemingly universal outrage is because you read blogs, and bloggers use Google Reader much more than the more average internet user does.

Shih left Google in 2011, so what he speaks isn’t — as he puts it — gospel. However, he recently held a position that provided him with knowledge of how Google operates, and how the company felt about Reader. So, he’s most likely more informed than your favorite bloggers using all those sad face emoticons filling up your Twitter feed.
Reade more >>

With Google Reader shutting down this July

With Google Reader shutting down this July, you might be looking for another way to stay on top of your feed subscriptions. Why not set up a Raspberry Pi to do the not-so-heavy lifting instead of importing your feeds into yet another web-based service? After all, you never know when anyone (or everyone) is going to pull the pin on their aggregators — especially since RSS is supposed to be dead already anyway.

Just follow Conor O’Neill’s lead and install Tiny Tiny RSS on your Raspberry Pi. It’s an open-source app that has been around for ages, and its developers provide a tarball that makes setup on the Pi (or any Linux-powered system) a simple task. You’ll need a basic LAMP stack running, too, because Tiny Tiny RSS isn’t a desktop app, it’s a web app that you can self-host.

That makes it a pretty ideal Google Reader replacement if you’ve got a decent internet connection and are comfortable setting up port forwarding on your router. Once everything’s configured, you’ll be able to access your feeds anywhere you have a browser available — just like you can with Reader. And since you’re in control, you don’t have to worry about a startup going under or someone going on a spring cleaning purgefest. As long as your ISP bill is up-to-date, you’ll always be able to read your feeds in the comfort of Tiny Tiny RSS.

Don’t have a Raspberry Pi? Loads of other devices will do the trick. SheevaPlug devices should work nicely, too, and so will those nifty little HDMI stick PCs — as long as you own one that can handle an ARM-friendly Linux distro.
Reade more >>

Android remains the dominant OS in China’s exploding mobile marketplace

Android remains the dominant OS in China’s exploding mobile marketplace, but there’s a downside to its popularity. Chinese app stores are packed with apps that harvest user data. Many of the offending apps are hauling off everything they can get their hands on, not just data that’s related in any way to their functionality.

According to the Data Center of China Internet’s analysis of the top 1,400 apps, roughly 66% are phoning home with private data. The Center also found that 34.5% of apps are guilty of full-on pillaging, uploading everything from address book entries to phone call and SMS messaging history. Around 15% of these apps are even making calls and sending texts — and that almost always means the user is incurring an unexpected cost. Pilfered data doesn’t end with what’s in your phone either: many apps want to know where you are. That’s fine if you’re using a location app like Foursquare, but nearly a quarter of the apps DCCI found tracking user locations don’t have any reason to do so.

Compounding the problem is the fact that almost all of this unsavory data collection takes place without users being notified. That’s not a huge surprise when you understand that the Chinese Android ecosystem is a bit like a lawless frontier town.

Low-cost Chinese smartphones ship with heavily-modified Android ROMs and users frequently don’t install apps from Google Play. Instead they turn to the same unofficial sources that routinely pop up in reports about the prevalence of Android malware in China, or download .APK installers directly from developers, both of which do an end-run around Google’s security measures.

The big reason unofficial distribution channels are so popular in China is that Google Play doesn’t support paid apps there. With users already accustomed to paying for apps from outside sources, there’s no reason to believe that the vast majority would have many concerns about installing any kind of non-Play app.

Reade more >>

One of the great and terrible things about Android

One of the great and terrible things about Android is the level of control that is available to the user. Your smartphone is as secure as you are, and as long as you don’t go poking around in thing you don’t understand you’ll be fine. Facebook’s most recent update upsets this general rule, and the end result could be disastrous.

The easiest way to keep your Android smartphone safe is to use it with the out-of-the-box settings — there are plenty of ways you can leave yourself vulnerable to attacks on Android if you do anything else. Rooting your phone can expose you to software attacks, but that usually requires a fair bit of know how. The Android software utilities include the ability to install apps from unknown sources. This feature is great for installing apps that are being beta tested, or apps that aren’t available in the Google Play Store. Facebook has decided to take advantage of this ability through an update to their app.

Facebook’s Android app is pushing an update that bears an oddly technical message. The app explains that you will be able to download new updates as they are available right through the app. The language is a little funny, prompting you to install the latest build, and Facebook has such confidence in their app’s ability to deliver the download that there’s a retry button just in case. This update happens over WiFi, which Facebook touts is a feature for some reason. There are two big issues with this method of updating that have nasty implications for Android users.

The first issue is a fight between Google and Facebook, which may cause the app to be removed from the Play Store at some point. Google has a check system that verifies apps that are installed through their service are only accessing the parts of your phone that you have given permission to access. This goes back to Facebook’s behavior in the past, where they have grabbed contact data from Android phones but refused to share their data back with Android.

The second issue, and perhaps the most significant, is how the app updates are installed. Users will need to have the ability to install software from unverified sources.
Reade more >>