Friends

An Ultra-High-Definition 3-D TV

 
New electronics enable a jump in performance in a
prototype display made by Samsung

Samsung has shown off a prototype of an ultra-high-definition 3-D television. The 70-inch prototype uses a novel electronic circuitry to control eight million pixels. It's not likely to go into volume production soon, and there isn't any content to display on it, says Paul Semenza, a senior analyst at Display Search. But at last month's Society for Information Display conference in Los Angeles, the display drew crowds and garnered a best-in-show award.
Samsung is the latest TV manufacturer to demonstrate a technology that uses a type of backplane—the array of transistors used to switch the pixels on and off—based on metal oxide semiconductors. These materials offer higher performance than the amorphous silicon widely used today, without increasing costs. In April, manufacturer Sharp announced it will begin manufacturing displays based on metal oxide transistor arrays by the end of the year at its plant in Kameyana, Japan.
It wouldn't have been possible to make the ultra-high-definition display using a conventional backplane, says Sangheon Kenneth Koo, director of LCD marketing at Samsung Semiconductor. That's because making the pixels smaller requires making each of the controlling transistors smaller, too. And the amorphous silicon used in conventional backplanes doesn't conduct electrons fast enough for this kind of miniaturization.
Metal oxide semiconductors conduct electrons very rapidly, and they can be deposited using relatively inexpensive methods. The hurdle has been figuring out which mixtures of metals to use and how exactly to work with them on today's equipment, says Randy Hoffman, a senior engineer at HP. The leading material is now a mixture of indium, gallium, and zinc called IGZO.
Semenza speculates that Sharp might be planning to take advantage of the high pixel densities enabled by metal oxide backplanes to make crisper mobile displays. Based on the size of the equipment at the company's Kameyana production line, he speculates that the company may be aiming to provide a high-resolution tablet display, perhaps for the next generation of Apple's iPad. "The high-water mark for this," says Semenza, "is the retina display" in the latest iPhone, which uses an expensive backplane based on another form of silicon transistor called low-temperature polysilicon. Metal oxide transistor arrays are less expensive to make and provide the necessary performance. Sharp might be able to offer a very good performance alternative to the retina display at a lower price, says Semenza.
Volume manufacturing of metal oxide backplanes could also be a boon for richly colored, energy-efficient organic light-emitting diode displays (OLEDs). These displays have been incorporated into some mobile devices and small high-end televisions, but they tend to be expensive. Part of the problem is that they can't be made with conventional backplanes: the high currents needed for these devices burn out amorphous-silicon transistors. So, OLED makers have been using the expensive polysilicon backplanes. Replacing those with metal oxide backplanes could make OLEDs more competitive.
Other qualities of metal oxides will be attractive in future display technologies, says HP's Hoffman. Every layer in a display tends to absorb some light and decrease overall efficiency and brightness. But metal oxides are transparent, so displays with these backplanes should get more light out and operate more efficiently. Hoffman expects this to be a particular advantage in reflective displays. HP is working on a flexible display that integrates a metal oxide backplane with a full-color reflective display.

Putting Location-Based Ads to Work


Ads targeted to a person's location are an advertiser's dream.
The reality is more complicated.

The spread of smart phones that track their owners' precise location seems like a wonderful development for advertisers. These devices could enable completely new kinds of digital marketing that make ads more relevant, meaningful, and effective. At the Location Based Marketing Summit, held last week in New York City, experts discussed the promise--and teething problems--facing this new section of the advertising industry.
Search engines already use positioning information from smart phones to deliver search results--and search ads--that are more relevant to a person's location. And location-based games, such as Foursquare and SCVNGR, which let users "check in" or perform other activities at locations to earn points or rewards, could enable new ways of reaching customers. These companies can make deals with local businesses to show users special offers when they are nearby.
According to a March 2010 survey conducted by the Mobile Marketing Association, 10 percent of all cell-phone users access location-based services at least once a week, and about 50 percent of those people have clicked on a location-based ad, or interacted with it in some other way.
Some early results suggest that location-based marketing could be every bit as effective as the industry dreams. A survey conducted in May 2010 by Placecast, a location-based advertising company based in San Francisco, found that 80 percent of consumers who have opted in to use a location-based service were receptive to being contacted by companies with offers based on their location. Placecast's data suggests that one-third of those who use location-based services have entered a store in response to a mobile ad, and 27 percent have been influenced to buy something.
Placecast's CEO Alistair Goodman notes, however, that the type of product being offered and its cost can have a huge impact on how effective a mobile ad is. For example, 33 percent of Placecast's survey respondents expressed interest in getting offers related to fashion and beauty, but 50 percent were interested in restaurant promotions.
Big brands such as Starbucks and Charmin are already exploring location-focused phone apps. Charmin has created an application that locates public bathrooms and lets users rate how clean and well-maintained they are. But experts at the New York event note that it's hard to determine whether many apps actually influence consumers' buying decisions.
Jed Rice, vice president of market development for Boston-based Skyhook Wireless, which provides location information, says it's important to find ways to measure the effects of these and other campaigns. Rice says that location-based services have a lot to offer small local businesses, which can make sure their ads are going to customers who are close enough to actually act on them. However, he says big brands are needed for the industry to take off.
In order to capture big brands' interest beyond throwaway experiments, Rice says, it's important to be able to analyze campaigns effectively. For example, even when a location-based ad campaign isn't likely to cause an impulse buy, services will need to show that the advertising was useful. He estimates it will take at least another year before businesses discover ways to measure the effectiveness of location-based ads.

Goodman noted that small businesses can watch for changes in foot traffic, but large businesses might have more trouble measuring how a campaign is affecting sales. Products such as Coca-Cola or Pringles are already being purchased by many consumers in many locations, and location-based services will need to find ways to demonstrate the value of adding the element of location to the companies' national marketing campaigns.
Andrew Turner, chief technology officer of Arlington, Virginia-based Fortius One, which offers a Web-based location analysis platform, says other types of information might make location-based advertising more effective and measurable. His company's software tracks how fast a person is moving. If she is going at walking speed, this might suggest she's open to receiving suggestions of things to look at in the area. But if she's traveling at driving speed, it's much less likely that an ad targeted to her location will be effective.


Using Wi-Fi for Navigating the Great Indoors


A phone can locate you indoors to within a few paces by
combining Wi-Fi signals and the jolt of your footsteps.

The arrival of GPS receivers in cell phones led to a boom in location-based apps and services—everything from maps that show you where you are, to new kinds of social networking. But step inside a building and GPS often fails. Now a startup has technology that enables devices to know their position inside a building to within a few steps, and it hopes this could lead to a second wave of indoor location-aware services.
WiFiSLAM, which publically demonstrated its technology for the first time last week, enables a phone to work out its position by combining the "fingerprint" of nearby Wi-Fi networks with information taken from a device's accelerometers and compass. The company was founded by students from Stanford University, with the aid of the university's StartX accelerator program for startups.
Mobile devices already use Wi-Fi networks to refine outdoor GPS fixes by accessing databases maintained by companies including Skyhook and Google, created by driving around "sniffing" for wireless networks. However this technology can today only allow accuracy of 10 meters at best and is primarily aimed at outdoor use.
The technology is typically accurate to within a "couple of steps" of your current location, says Anand Atreya, cofounder of WiFiSLAM: "This accuracy will change how you interact with indoor environments." The technology could aid with navigation inside large and complex buildings such as hospitals or airports, he says, adding that app developers will likely find more imaginative uses, too.
"Think about going to the supermarket," says Atreya. "We can provide information relevant to the product right in front of you." Another possibility is allowing users to find the nearest store clerk, as long as that person is also being tracked.
When a gadget using WiFiSLAM wants to know its location, it analyzes the signal strengths and unique IDs of all the Wi-Fi networks around it. That is matched against a reference data set for the area either accessed over the Internet, or stored on the device. The estimate of location can be sharpened if a gadget moves slightly, because WiFiSLAM's algorithms can gather multiple fingerprints. Compass data and accelerometer signals capturing a person's footsteps are also used to refine the accuracy of subsequent location fixes as a person moves around. 
WiFiSLAM needs similar data to be gathered in advance inside a particular building before it can offer location fixes. A person running another special app must walk around a building a few times, entering every room at least once. Algorithms originally developed for robot navigation process the changing pattern of Wi-Fi fingerprints and footsteps to re-create the path the person covered. That trace is then manually associated with a map of the place so that WiFiSLAM can tell a user in that environment where they are.
Other technology that uses Wi-Fi to for location sensing relied on expensive additional equipment, says Atreya. "I could walk into your building and have Wi-FI location working within an hour," he says, claiming this will allow WiFiSLAM to be rapidly adopted by many places.
Eladio Martin, a researcher at University of California, Berkeley, is part of a team developing another Wi-Fi-based location app that's accurate to 1.5 meters. Like WiFiSLAM's, Martin's team uses Wi-Fi fingerprinting and needs no equipment other than a cell phone, although it is currently just an academic project.
"Public buildings and especially those related to health care are some of the main candidates for the implementation of this technology," he says. Martin is not familiar with WiFiSLAM's implementation, but says that academic work published by members of the company suggests they could reduce the computational load of calculating traces from Wi-Fi fingerprints, which would make the technology more scalable.
WiFiSLAM plans to deploy the technology in a number of hospitals—including Stanford hospital—as well as shopping malls. The technology will initially take the form of stand-alone apps for navigation, for example, an app provided by a particular mall. However, the technology could eventually be built into apps with more general mapping

Rise of the Point-and-Click Botnet


In 2005, a Russian hacker group known as UpLevel developed Zeus, a point-and-click program for creating and controlling a network of compromised computer systems, also known as a botnet. Five years of development later, the latest version of this software, which can be downloaded for free and requires very little technical skill to operate, is one of the most popular botnet platforms for spammers, fraudsters, and people who deal in stolen personal information.
Last week, the security firm NetWitness, based in Herndon, VA, released a report highlighting the kind of havoc the software can wreak. It documents a Zeus botnet that controlled nearly 75,000 computers in more than 2,400 organizations, including the drug producer Merck, the network equipment maker Juniper Networks, and the Hollywood studio Paramount Pictures. Over four weeks, the software was used to steal more than 68,000 log-in credentials, including thousands of Facebook log-ins and Yahoo e-mail log-ins.
"They had compromised systems inside both companies and government agencies," says Alex Cox, a principal analyst at NetWitness.
A survey conducted by another security firm--Atlanta-based Damballa--found Zeus-controlled programs to be the second most common inside corporate networks in 2009. Damballa tracked more than 200 Zeus-based botnets in enterprise networks. The largest single botnet controlled using the Zeus platform consisted of 600,000 compromised computers.
The Zeus software is less important for its conquests than for its high regard among cybercriminals. "Zeus is incredibly popular with people that want to tinker and start their own small business, if you will," says Gunter Ollman, vice president of research for Damballa.
A group of four or five developers started working on Zeus in 2005. The following year they released the first version of the program, a basic Trojan designed to hide on an infected system and steal information. In 2007, the group came out with a more modular version, which allowed other underground developers to create plug-ins to add to its functionality.
The latest Zeus platform allows users to build custom malicious software to infect target systems, manage a far-flung network of compromised machines, and use the resulting botnet for illegal gain. The construction kit contains a program for building the bot software and Web scripts for creating and hosting a central command-and-control server.
Independent developers have created compatible "exploit packs" capable of infecting victims' systems using vulnerabilities in the operating system or browser. Other developers focus on creating plug-in software to help would-be cybercriminals make money from a Zeus botnet. Some add-ons focus on phishing attacks--delivering the images and Web pages needed to create fraudulent banking sites, for example. Other add-ons give bot operators the tools to create spam campaigns. "There is a whole cottage industry around creating add-ons for Zeus," says Don Jackson, a security researcher with the Counter Threat Unit at SecureWorks, a company based in Atlanta
The availability of the source code for Zeus has attracted many developers, says Jackson. Online miscreants looking to control their own botnet start with Zeus, because it is simple to use, he says, while the add-ons and extensions satisfy more sophisticated users. "It's very easy to use right out of the gate," Jackson says. "But when you add the advanced functionality that costs thousands of dollars, then it becomes a tool for advanced operators."
Even the basic Zeus kits include obfuscation techniques to help escape detection by antivirus software and other security measures. In one experiment, consultant Alex Heid of Information Security Services found that only about half of antivirus software detected a known Zeus payload. After employing some simple techniques for masking the code, the detection rate dropped even further, to 10 percent. "The cybercrime technologies are advancing faster than the security technologies," Heid says.
Once Zeus has compromised a system, it gives the user no sign that it's there, according to Jackson. "What does Zeus look like when it infects your computer? Well, stare at your computer now, and that's what it looks like," Jackson says. "It's designed to do its job and do it successfully and do it silently."
While both Damballa and NetWitness sell technologies and services for detecting compromises on corporate networks, they do not provide software for end users.
"Most enterprises that we work with have a large number of users, so they basically give up on defending their computers," Ollmann says. "You make the best attempt with antivirus and firewalls, but they accept that some percentage of their systems are going to be infected, so they focus on detecting and rebuilding the (compromised) systems rather than defending against all threats."
Cox adds that focusing on the communications between infected systems and a command-and-control server is usually the best way to catch infections. "Understanding what normalcy looks like on your network so you can pinpoint abnormality is what is really important in the current threat environment," he says. "Don't trust only your existing security controls, and get eyes on your network."

Most Malware Tied to 'Pay-Per-Install' Market


A shadowy industry lets spammers and other
cybercriminals pay their way into your computer.

New research suggests that the majority of personal computers infected with malicious software may have arrived at that state thanks to a bustling underground market that matches criminal gangs who pay for malware installations with enterprising hackers looking to sell access to compromised PCs.
Pay-per-install (PPI) services are advertised on shadowy underground Web forums. Clients submit their malware—a spambot, fake antivirus software, or password-stealing Trojan—to the PPI service, which in turn charges rates from $7 to $180 per thousand successful installations, depending on the requested geographic location of the desired victims.
The PPI services also attract entrepreneurial malware distributors, or "affiliates," hackers who are tasked with figuring out how to install the malware on victims' machines. Typical installation schemes involve uploading tainted programs to public file-sharing networks; hacking legitimate websites in order to automatically download the files onto visitors; and quietly running the programs on PCs they have already compromised. Affiliates are credited only for successful installations, via a unique and static affiliate code stitched into the installer programs and communicated back to the PPI service after each install.
In a new paper researchers from the University of California, Berkeley, and the Madrid Institute for Advanced Studies in Software Development Technologies describe infiltrating four competing PPI services in August 2010, by surreptitiously hijacking multiple affiliate accounts. The team built an automated system to regularly download the installers being pushed by the different PPI services.
The researchers analyzed more than one million installers offered by PPI services. That analysis led to a startling discovery: Of the world's top 20 types of malware, 12 employed PPI services to buy infections.

"Going into this study, I didn't appreciate that PPI is potentially the number one vector for badness out there," said Vern Paxson, associate professor of electrical engineering and computer sciences at UC Berkeley. "We have a sense now that botnets potentially are worth millions [of dollars] per year, because they provide a means for miscreants to outsource the global dissemination of their malware."

The researchers set out to map the geographic distribution of malware being pushed by these services, so they devised an automated way to download installers. They used services such as Amazon's EC2 cloud computing platform, and "Tor," a free service that lets users communicate anonymously by routing their connections through multiple computers around the world, to trick the pay-per-install program into thinking requests were coming from locations around the globe.
The system classified the collected malware by type of network traffic each sample generated when run on a test system. The researchers said they took precautions to prevent affiliate accounts from being credited with the test installations.

The analysis of the PPI services indicates that they most frequently target PCs in Europe and the United States. These regions are wealthier than most others, and offer affiliates the highest per-install rates.
But the researchers surmise that there are factors beyond price that may influence a PPI client's choice of country. For example, a spambot such as Rustock requires little more than a unique Internet address to send spam, whereas fake antivirus software relies on the victim to make a credit card or bank payment, and thus may need to support multiple languages or purchasing methods.
The team also found that PPI programs almost always installed bots that engage infected systems in a variety of "click fraud" schemes, involving fraudulent or automated clicks on ads to falsely generate ad revenue.

One unexpected finding may help explain why PCs infected with one type of malware often quickly become bogged down with multiple infections: Downloaders that are part of one scheme often fetch downloaders from another. In other words, affiliates from one PPI service themselves sometimes act as clients of other services. Consequently, many of the installers pushed by affiliates will overwhelm recipient PCs with many types of malicious software.

"We speculate that some of these multi-PPI-service affiliates are arbitrageurs, trying to take advantage of pricing differentials between the (higher) install rates paid to the affiliates of one service for some geographical region versus the (lower) install rates charged to clients of another PPI service," the researchers wrote.

This dynamic lends an inherent conflict of interest to the PPI market that hurts both clients and affiliates: The more installations an affiliate provides, the larger the payment received. But the more malware is installed, the greater the likelihood that the owner of an infected system will notice a problem and take steps to eradicate the malware.

PPI services have ominous implications for coordinated efforts to shut down botnets. In recent months, security researchers, Internet service providers, and law enforcement agencies have worked together to dismantle some of the world's biggest botnets. In March, for example, Microsoft teamed with security firms to cripple the Rustock botnet, long one of the most active spam botnets on the planet.

The Berkeley researchers argue that even if defenders can clean up a botnet—by hijacking its control servers and even remotely disinfecting PCs—the controller of that botnet can rebuild it by making modest payments to one or more PPI services.
"In today's market, the entire process costs pennies per target host—cheap enough for botmasters to simply rebuild their ranks from scratch in the face of defenders launching extensive, energetic takedown efforts," the researchers wrote.

A New Kind of Smart-Phone Connection

Several smart-phone manufacturers are developing plans to launch U.S. handsets that can connect to other devices when tapped together, or act as electronic wallets by instantly paying for goods when waved over a reader.
The technology to make this possible--Near Field Communications (NFC)--is a step beyond the contactless radio-frequency identification (RFID) technology used in many transit systems or security access cards for buildings. NFC uses the same high-frequency radio waves as RFID and can make a connection over a distance of up to around 10 meters. It is also compatible with existing RFID systems. But NFC devices can both send and receive data--something that will enable many new applications when coupled with the computational power of a smart phone.
"I think 2011 will be the inflection point for NFC--that's when we should see volume availability of handsets in the U.S.," said Didier Serra, founder of Inside Contactless, which makes chips and software for NFC devices, at the CTIA Enterprise & Applications meeting in San Francisco. Shipping a product with NFC hardware in large volumes takes a company around 18 months, he said and "the work started around nine months ago." he said.
Small-scale trials have already taken place in various U.S. cities in recent years. In late 2007, Sprint handed out Samsung NFC phones in San Francisco that allowed people to use transit and make payments in stores; Visa is now running trials in New York and Los Angeles, among other cities, of a gadget made by DeviceFidelity that slides into a smart phone's memory slot to give it NFC capabilities.
Nokia, the world's largest phone manufacturer, announced in June that all of its smart phones would gain NFC capabilities in 2011; Samsung has been testing handsets for some time, and Apple is widely rumored to be preparing an iPhone with NFC.
Apple could have an advantage over other handset makers, said Avivah Litan, a Gartner analyst specializing in banking and payments technology. She recently coauthored a report on the possible strategy of the Cupertino, California, company's move into contactless payments. "Apple already has a closed system of its own in iTunes that can act as a money transmitter," said Litan. "They don't want to become a bank--the way you get money into your iTunes account may be through your credit or debit card or a bank account--but they would handle the payment." Litan said she expects the firm to unveil an NFC-packing iPhone next year, citing a suite of relevant patents filed by the company and recent hires who have relevant experience.
All future NFC phones should be compatible with existing contactless payment and transport systems introduced by banks and others, for example, those used on transit systems in Boston and Los Angeles, and at 7-11 and Office Depot stores. But that infrastructure isn't pervasive enough to make that the main selling point of contactless handsets, said Serra.
"NFC enables more than just payments," he said. "Think about being able to exchange information by tapping your device against someone else's." He expects manufacturers to initially pitch the technology as a way to connect a phone with another handset and device--for example, making it possible to tap a Bluetooth headset to a phone to have the two instantly pair.
"I think people will see a lot of value in that," said Mohamed Awad of the NFC Forum, an industry body that has created specifications for NFC. "You can just tap a handset on a printer or laptop and it just connects. It's so natural." Although NFC can be used to transfer data at up to 424 kilobits per second--perhaps enough to transfer a document for printing, said Awad--it works best as a "helper" for setting up a higher-bandwidth Bluetooth or Wi-Fi connection.
The NFC Forum is already working on certifying the first wave of NFC devices for the U.S. market, according to Awad. "We've got a batch of products coming through today," he said.
However, as Serra points out, smart-phone manufacturers and carriers are now heavily dependent on third-party developers. "For NFC to be successful, the industry has to be app-centric and allow creative developers to provide ideas and apps that users want," he said. Social networking apps that enable people to exchange information or play games using NFC are one possible example, and this could play an important role in making the technology popular, he said.
However, consumers will also have to feel assured that NFC is safe, said Jean-Louis Carrara of the security firm Gemalto, which makes chips for smart cards and SIM cards. "People will be interested in the security of their phones, their personal information, and their payment data," he said, adding that NFC will likely make smart phones even more attractive to hackers. "Malware is rising on smart phones already," he notes.

New System Swaps the Cash Register for an iPhone


Square, a new startup based in San Francisco and headed by Twitter cofounder Jack Dorsey, opened its doors amid much hype and fanfare last week. But some experts are already questioning whether the company will be able to sustain itself.
The startup hopes to make it make it big by allowing virtually anyone to accept credit card payments by connecting a simple reader to a mobile device. Dorsey, Square's CEO, envisions the technology being used by small businesses, street vendors, and even individuals who want to sell a couch on Craigslist or collect money from a friend.
However, some experts question whether the device will find a niche in the mobile payments market and say the startup will face a challenge trying to win consumer confidence with such a novel approach. "In retrospect, PayPal's biggest innovation was putting together a system to protect both their users and themselves against fraud," says Charles Kahn, a professor of finance at the University of Illinois at Urbana-Champaign. "Before a system like this has any effect on consumer behavior it will have to convince consumers that their cards are protected."
To take a payment with Square, a user swipes a credit card's magnetic stripe through a small reading device that plugs into a phone's audio jack. The reader is currently compatible with the iPhone, but Square is working on versions for Android and Blackberry phones. Dorsey says the device communicates through the audio jack because it's cheaper to manufacture that way and because it should allow Square's technology to work on a wider variety of mobile devices. After the card is swiped, the user submits his signature using the touchscreen. And if the user chooses to enter an e-mail address, the system will send an electronic receipt.
Only the person who is receiving payment needs to have an account with Square, and the company hasn't yet set a pricing structure. But Dorsey says the pricing will allow for different levels of customer involvement. Someone who wants to use the service once for a yard sale should be able to get started easily and cheaply, while a small business might upgrade to a more full-featured version of Square.
"The credit card stack is quite complicated," Dorsey says. "We tried to find a simplest path to the parties who really need to be involved. We're taking a lot of the upfront cost away from the process."
Dorsey notes that Square uses encrypted protocols to send transaction information, and doesn't store card information on the seller's device. The device is subject to the same regulations as any other payment system.

By creating a Square account, payers can obtain extra features, too, Dorsey says. For example, a user can arrange to receive a text message every time his credit card is charged using Square. Or he can upload a picture that will display to the seller whenever the user's credit card is swiped. "We put a big focus on how to get the payer involved in managing security," Dorsey says.
Still, some experts are skeptical of Square's prospects. Jon Paisner, a senior analyst at Yankee Group who studies mobile transactions, says the need to plug in an extra piece of hardware to use Square might prevent people from adopting it. Paisner also worries that the device won't be sturdy enough in the long-term, and that audio jacks may not stand up to this kind of unintended use.
Paisner thinks there is potential for payments via mobile phones to take off in the United States and United Kingdom, but he thinks near-field wireless communication technology, which would allow users to make payments by tapping a phone against a reader, is more promising.
Mark Beccue, a senior analyst at Abi Research who studies consumer mobile technology, also has reservations. "What puzzles me is, what market we are addressing here?" he says. "I saw a video of using [Square] in a coffee shop and thought, 'Don't they have a cash register?' " Beccue concedes that the product may work for certain niches, such as markets or art fairs, but he doesn't think it has mainstream appeal. He suggests that most small businesses will prefer traditional point-of-sale systems for managing credit cards, and that ATMs are convenient enough that individuals aren't likely to turn to Square to pay each other.
Pilot tests of Square are being conducted in San Francisco, Los Angeles, New York, and St. Louis. Dorsey says the company hopes to open to the public in early 2010.

Twitter Delicious Facebook Digg Stumbleupon Favorites More