{"id":78708,"date":"2015-01-31T11:00:57","date_gmt":"2015-01-31T09:00:57","guid":{"rendered":"http:\/\/businesstech.co.za\/news\/?p=78708"},"modified":"2015-01-30T15:28:43","modified_gmt":"2015-01-30T13:28:43","slug":"facebook-downtime-creates-black-holes-online","status":"publish","type":"post","link":"https:\/\/businesstech.co.za\/news\/internet\/78708\/facebook-downtime-creates-black-holes-online\/","title":{"rendered":"Facebook downtime creates black holes online"},"content":{"rendered":"<p>Checking social networks is a morning ritual for many, and when that routine is disrupted \u2013 as it was recently when Facebook\u2019s servers went down \u2013 its absence <a href=\"http:\/\/www.washingtonpost.com\/blogs\/compost\/wp\/2015\/01\/27\/facebook-goes-down-for-40-minutes-world-falls-into-chaos\/\">can come as a surprise<\/a>.<\/p>\n<p>But what also becomes apparent is that when the world\u2019s most popular social network is inaccessible, so too are many thousands of websites that rely upon Facebook services.<\/p>\n<p>Although <a href=\"http:\/\/www.telegraph.co.uk\/technology\/facebook\/11371181\/Facebook-and-Instagram-down-due-to-technical-difficulties.html\">it lasted less than an hour<\/a>, Facebook\u2019s downtime gave a rare glimpse into the extent to which it \u2013 and other social networks \u2013 have penetrated our daily use of the web.<\/p>\n<p>Instagram, <a href=\"http:\/\/www.bbc.co.uk\/news\/technology-17658264\">bought by Facebook in 2012<\/a>, and Tinder, which requires a Facebook account to log in, were among the big sites that were also brought down. But many thousands of websites rely on a Facebook account as a means for users to log in or post comments \u2013 including The Conversation.<\/p>\n<p>This cascading failure shows how the need for websites to provide a means to authenticate users has given rise to a centralising trend \u2013 and the vulnerability to failure that brings.<\/p>\n<h2 class=\"my-4\">Identity mistakes are costly<\/h2>\n<p>For the developer of a website or app user management is a difficult problem. You must be able to store, encrypt and decrypt users&#8217; information securely, allow them to reset their forgotten password, offer them a range of secret questions and other account management options.<\/p>\n<p>The more secure systems use <a href=\"https:\/\/theconversation.com\/after-all-these-hacks-tech-firms-could-do-more-but-better-security-starts-with-you-32051\">two-factor authentication<\/a>, which requires authentication via unconnected systems \u2013 for example combining username and password, mobile phone text message, fingerprint or keycard.<\/p>\n<p>If not implemented perfectly correctly, user authentication can be vulnerable to abuse \u2013 as exemplified by the theft of intimate photos from celebrities&#8217; poorly secured Apple iCloud accounts last year, where attackers gained access by <a href=\"https:\/\/theconversation.com\/three-ways-your-personal-photos-are-vulnerable-to-hackers-31134\">abusing password reset features and guessing simple passwords<\/a>. If Apple can\u2019t get it right, what hope for your average developer?<\/p>\n<h2 class=\"my-4\">Outsourcing identity<\/h2>\n<p>An appealing solution for developers is to outsource the problem to a third-party service. Back in the heady days of <a href=\"http:\/\/www.oreilly.com\/pub\/a\/web2\/archive\/what-is-web-20.html\">Web 2.0<\/a> in the mid-2000s, this problem was first addressed with the development of <a href=\"http:\/\/openidexplained.com\/\">OpenID<\/a> \u2013 a distributed, open standard for authentication that could work across many sites and services.<\/p>\n<p>Users chose a single identity provider to securely hold their OpenID digital identity on their behalf, which third-party websites or services could use to authenticate them.<\/p>\n<p>Initially popular, it fell out of favour with the rise of social networks as companies realised the value in holding their users&#8217; identities themselves. Google will <a href=\"https:\/\/developers.google.com\/accounts\/docs\/OpenID#shutdown-timetable\">stop supporting OpenID this April<\/a> in favour of the approach taken by Facebook, Twitter, LinkedIn and most other social networks.<\/p>\n<p>This will involve offering its own authentication service as part of a set of services and functionality aimed at developers, known as an application programming interface <a href=\"https:\/\/developers.facebook.com\/docs\/apis-and-sdks\">(API)<\/a>.<\/p>\n<p>Using just a few lines of code, a developer can rely on a social network to carry out all the tricky user management business on their behalf leaving them to get on with building their app or website. As a bonus, using a social network API offers other features such as easy content sharing and demographic and social statistics.<\/p>\n<p>It seems like win-win-win exchange: the developer has less work to do, the user has a smooth log-in experience and the social media site parades its brand across a little more of the web, annexing a little more of online life.<\/p>\n<h2 class=\"my-4\">When Facebook\u2019s down \u2026 so are you<\/h2>\n<p>So the Facebook crash accidentally communicated a powerful but hidden message to millions of users: we own your online identity. Although news items may <a href=\"http:\/\/edition.cnn.com\/2015\/01\/27\/tech\/facebook-instagram-down\/index.html\">jokingly mourn<\/a>for all the humblebrags and selfies lost that morning, we rely more and more on social networks to mediate our online existence.<\/p>\n<p>They are a vital source of both personal and global news, a source of social capital, define our personalities, manage our relationships and increasingly act as the social glue between our different haunts on the web. The companies controlling them have unprecedented access to much of our lives.<\/p>\n<p>I\u2019d imagine that the developers at Tinder \u2013 like many developers of other applications that rely on Facebook\u2019s authentication service \u2013 were summoned to emergency meetings this week as bosses realised exactly how dependent their business is on a third party out of their control.<\/p>\n<p>We should take this brief disruption as opportunity to think about the extent that Facebook and its ilk own, control and facilitate our online lives \u2013 even far beyond their own sites. The disruption was short, but hints at the wider problems in the online identity business.<\/p>\n<p>If you have thoughts, you can leave a comment. But as with most other news sites you have an important choice: will your identity on The Conversation belong to Twitter, Facebook or LinkedIn?<\/p>\n<p><em>By <strong>Ben Kirman<\/strong>, Senior Lecturer in Computer Science at University of Lincoln; and <strong>Tom Feltwell<\/strong>, Research Assistant at University of Lincoln.<\/em><\/p>\n<ul>\n<li>This article was originally published on <a title=\"http:\/\/theconversation.com\/rude-comments-online-are-a-reality-we-cant-get-away-from-34560\" href=\"http:\/\/theconversation.com\/rude-comments-online-are-a-reality-we-cant-get-away-from-34560\" target=\"_blank\">The Conversation<\/a>.<\/li>\n<li>Read the <a title=\"http:\/\/theconversation.com\/when-facebook-goes-down-it-takes-big-chunks-of-the-internet-with-it-36873\" href=\"http:\/\/theconversation.com\/when-facebook-goes-down-it-takes-big-chunks-of-the-internet-with-it-36873\">original article<\/a>.<\/li>\n<\/ul>\n<h3 class=\"fn\">More from The Conversation<\/h3>\n<p><strong><a title=\"Permalink to Can you save money with a half-filled fuel tank?\" href=\"http:\/\/businesstech.co.za\/news\/general\/78139\/can-you-save-money-with-a-half-filled-fuel-tank\/\" rel=\"bookmark\">Can you save money with a half-filled fuel tank?<\/a><\/strong><\/p>\n<p><strong><a title=\"Permalink to After Earth, will space be our new home?\" href=\"http:\/\/businesstech.co.za\/news\/international\/78137\/after-earth-will-space-be-our-new-home\/\" rel=\"bookmark\">After Earth, will space be our new home?<\/a><\/strong><\/p>\n<p><strong><a title=\"Permalink to The real cost of cyber crime\" href=\"http:\/\/businesstech.co.za\/news\/internet\/77523\/the-real-cost-of-cyber-crime\/\" rel=\"bookmark\">The real cost of cyber crime<\/a><\/strong><\/p>\n<p><strong><a title=\"Permalink to Are quantum dot TVs safe?\" href=\"http:\/\/businesstech.co.za\/news\/electronics\/76935\/are-quantum-dot-tvs-safe\/\" rel=\"bookmark\">Are quantum dot TVs safe?<\/a><\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>When the world\u2019s most popular social network is inaccessible, so too are many thousands of websites that rely on its services.<\/p>\n","protected":false},"author":29,"featured_media":30003,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[9882],"tags":[45,26],"class_list":["post-78708","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-internet","tag-facebook","tag-headline"],"_links":{"self":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts\/78708","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/users\/29"}],"replies":[{"embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/comments?post=78708"}],"version-history":[{"count":1,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts\/78708\/revisions"}],"predecessor-version":[{"id":78712,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts\/78708\/revisions\/78712"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/media\/30003"}],"wp:attachment":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/media?parent=78708"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/categories?post=78708"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/tags?post=78708"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}