Showing posts with label signon. Show all posts
Showing posts with label signon. Show all posts

Friday, August 26, 2011

OpenFeint’s single sign-on for social games to replace Apple’s UDID (exclusive)

Apple caused panic among app developers last week when it announced that it would phase out an identification system for users on its mobile devices such as the iPhone. Mobile gaming company OpenFeint says it will help solve the problem created by the elimination of this feature by offering its own “single sign-on” identification system for app developers.

Apple’s announcement caused fear among developers because many use this unique device identifier (UDID) number to identify a user in order to quickly access that person’s history and offer cross promotions.?Apple decided to “deprecate” the UDID, meaning the company will phase out the use of the feature and no longer support it at some point in the future. Apple gave no explanation for the deprecation, but some speculated it was to end concerns about privacy.

“Developers have been panicking to some extent,” chief executive of OpenFeint, Jason Citron said. “That is why we decided to do this product.”

OpenFeint, which is owned by Japan’s Gree, said it already has 115 million users logging into games that use the OpenFeint mobile social gaming network for online play and leaderboards. Third-party app developers can now use the OFUID (OpenFeint user identification) to identify users in the same way that Apple did with UDUDs.

When a user starts playing a game or app with the OpenFeint system built-in, OpenFeint asks them to sign into their account. It asks the user if they want to access online play. If the user answers yes, OpenFeint signs them in and the app developer can get access to the player’s anonymized data and history, Citron said. OpenFeint has more than 6,800 games using its platform.

That’s certainly better than the alternative, where developers would have to create their own identification system requiring users to sign in with a username and password before playing a game. OpenFeint removes some of the potential hassle with a more streamlined sign-in system.

It isn’t a perfect replacement for UDID, which was able to log every time a user started a game. The OFUID can only gather information when the user logs into OpenFeint. That doesn’t happen every time a user plays a game. But Citron said this was the next best thing, as “the user can opt in with just one click.” The user has to have the OpenFeint app in order to sign in. However, to play online, users often have to download the OpenFeint app anyway.

The OFUID will give developers access to information such as what games are installed on the user’s phone, their usage of games, and what offers they have taken before. Developers would have otherwise had to figure out a way to do this on their own. To create the workaround, Citron said OpenFeint engineers had to figure out a way to do the single sign-on without using UDID numbers. Citron said that developers who use OpenFeint can learn how to better monetize their users with better targeting.

OpenFeint also announced an “install trade program” for developers that use the new sign-on process. OpenFeint will guarantee developers 1.5 new installs for every new install of Game Channel, an app that is needed for users to enjoy the benefits of single sign on. Game developers will be able to offer incentives for users to use the sign-on process, said Ethan Fassett, senior vice president of product at OpenFeint.

The single sign-on with OFUID will launch later this fall. Citron said that OpenFeint does not make money on this feature. On Android, Citron said that there are fewer restrictions related to the use of a UDID. But OpenFeint also offers its own single-sign-on process there.

Next Story: Steve Jobs’s most ambitious product: Apple?Inc.
Previous Story: Verizon acquires enterprise services provider?CloudSwitch

Tags: single sign on, UDID

Companies: Apple, Gree, OpenFeint

People: Jason Citron


View the original article here

Sunday, August 21, 2011

Centrify’s single sign-on secures servers, scores $16M

Centrify, a company securing on-premise and cloud servers, raised $16 million in its fourth round of funding yesterday.

The company provides a single sign-on for access to servers in addition to management solutions. These solutions include the ability to turn off potentially compromised machines, restrict user privileges, and monitor all activity on the servers.

“A lot of breaches come from insiders who have the keys to the kingdom. We eliminate the keys to the kingdom,” chief executive Tom Kemp told VentureBeat in an interview.

Kemp explained that having multiple sign-ons for various applications on the server is a vulnerability. For instance, firing an employee requires the disabling of his user names and passwords. But this leaves room for access points to fall through the cracks. You may have removed their Google Apps access, but what about the Salesforce account you forgot about?

If there is only one sign-on, however, you can easily retract server access from Centrify’s hub. Okta, which also recently announced a round of funding, is a direct competitor to Centrify’s cloud security offerings.

But what Centrify is most concerned about is how many different devices can now access server information.

“The data center of the future is very heterogeneous and very hybrid,” said Kemp.

He means smartphones and tablets are quickly entering the enterprise as viable ways to distribute data. But these devices are easily compromised. Not everyone password-protects their mobile devices, and they are often forgotten on a train seat or in a restaurant.?This pokes an immediate hole in the security of that company’s server infrastructure — cloud or on-premise.

The funding was led by Index Ventures.

Centrify is using some of the funds to build a product combating this vulnerability. The product will allow server managers to deactivate any mobile device associated with a company, in the same way that they can deactivate computers and servers.

While simple, this could bring some peace to worried managers as more and more devices store proprietary information in the cloud.

But while a single sign-on is a good way to manage security, a watchful eye still needs to be placed on existing user activity.

“We do have an auditing solution that provides, in effect, a security camera on the servers and logs all activity done on that server,” said Kemp.

That security camera can be set up to send alerts to a manger and can even be programmed to shut down all systems when a potential security threat is identified. This latter solution could be more effort than it’s worth given the possibility of false alarms.

Another flaw is the inability to detect security threats during work hours. Some threats may come at night and are easily detected. But what about the ones that occur during the normal pace of work? Many servers are exporting and importing data regularly. And if what Kemp says is true, and many breaches come from the inside, it is even harder to detect usual operations versus threats.

According to Kemp, Centrify cannot identify those breaches at this time.

Centrify will also use the funding to expand internationally. Kemp is particularly excited about leveraging Index Ventures’ international presence and believes the firm will play a role in Centrify’s expansion.

Currently, the company has over 3,500 customers including Research in Motion, Pfizer, and the U.S. Army. It has 150 employees, headquartered in Sunnyvale, Calif. Thus far, Centrify has accumulated $52 million in funding from Index Ventures, Mayfield Fund, Accel Partners, INVESCO Private Capital and Sigma Partners.

Next Story: Shotgun networking is no way to make?contacts
Previous Story: HP faces ridicule in social media for abandoning tablets and?PCs

Tags: data centers, servers, single sign on

Companies: Centrify

People: Tom Kemp


View the original article here