Jump to content

Orkut

From Wikipedia, the free encyclopedia

This is an old revision of this page, as edited by Skanter (talk | contribs) at 21:44, 5 December 2008 (→‎India). The present address (URL) is a permanent link to this revision, which may differ significantly from the current revision.

Orkut
File:Orkut.gif
File:Orkut - login.png
The new Orkut interface
Type of site
Social Network Service
Available inmultilingual
OwnerUnited States Google
Created byTurkey Orkut Büyükkökten
URLhttp://www.orkut.com/
CommercialYes
Registrationrequired

Orkut is a social networking service which is run by Google and named after its creator, an employee of Google - Orkut Büyükkökten. The service states that it was designed to help users meet new friends and maintain existing relationships. Orkut is similar to other networking sites. Since October 2006, Orkut has permitted users to create accounts without an invitation.

Orkut is the most visited website in Brazil and second most visited site in India. A large percentage of users in India are high school and college students. The initial target market for Orkut was the United States, but the majority of its users are in Brazil and India.[2] In fact, as of May 2008, 53.86% of Orkut's users are from Brazil, followed by India with 16.97%[3] and 23.4% of the traffic comes from Brazil, followed by India with 18.0%.[4] Unlike Facebook and Friendster, it is not a popular website in the United States of America and Canada.

Originally hosted in California, in August 2008 Google announced that Orkut will be fully managed and operated in Brazil, by Google Brazil, in the city of Belo Horizonte. This was decided due to the large Brazilian user base and growth of legal issues.[5][6][7][8]

Features

Users ranking by country
Demographics of Orkut on March 31, 2004[9]
United States
51.36%
Japan
7.74%
Brazil
5.16%
Netherlands
4.10%
United Kingdom
3.72%
Demographics of Orkut on November 6, 2008
Brazil
51.18%
United States
17.46%
India
17.40%
Pakistan
1.01%
United Kingdom
0.49%
Afghanistan
0.48%
Japan
0.43%
Portugal
0.39%
Germany
0.39%
Australia
0.39%

A user first creates a "Profile", in which the user provides "Social", "Professional" and "Personal" details. Users can upload photos into their Orkut profile with a caption. Users can also add videos to their profile from either YouTube or Google Video with the additional option of creating either restricted or unrestricted polls for polling a community of users.There is an option to integrate GTalk (An instant messenger from Google) with Orkut enabling chatting and file sharing.

Scrapbook

"Scrapping" is popular among the Orkut community as a form of offline and online communication. In December 2007, the ability to pop up alerts immediately when a scrap is received was added. The scrap feature is sometimes used for chatting.

Communities

Another feature of Orkut are "Communities". Anyone with an Orkut account can create a community on anything. One can post topics, inform users about an event, ask them questions or just play games. There are more than one million communities on Orkut with topics ranging from pizza to pasta. The first five communities on Orkut were started within 24 hrs of the site's launch. There were a total of 47,092,584 communities on Orkut as per March 24, 2008 4:25PM IST (+5:30 GMT). With the recent addition of the search topic feature in the communities, some Orkut communities become the in fact source for the website links to movies, e-books etc. A community's members may also create polls, and invite other members.

Other miscellaneous features

Members can make groups to join friends according to their wishes. Further, each member can become fans of any of the friends in their list and can also evaluate whether their friend is "Trustworthy", "Cool", "Sexy" on a scale of 1 to 3 (marked by icons) and is aggregated in terms of a percentage. Unlike Facebook, where a member can view profile details of people only on their network, Orkut allows anyone to visit anyone's profile, unless a potential visitor is on your "Ignore List" (This feature has been recently changed so that users can choose between showing their profile to all networks or specified ones). Importantly, each member can also customize their profile preferences and can restrict information that appear on their profile from their friends and/or others (not on the friends list). Another feature is that any member can add any other member on Orkut to his/her "Crush List" and both of them will be informed only when both parties have added each other to their "Crush List".

When a user logs in, they see the people in their friends list in the order of their logging in to the site, the first person being the latest one to do so.[10] Orkut's competitors are other social networking sites including MySpace and Facebook. Ning is a more direct competitor, as they allow creation of Social Networks which are similar to Orkut's communities.

Orkut Redesign

On Friday, August 24, 2007, Orkut announced a redesign. The new UI contains round corners and soft colors including small logotype at upper left corner. The redesign has been announced on the official Orkut Blog. By Thursday, August 30, 2007, most users on Orkut could see changes on their profile pages as per the new redesign. On the 31st, Orkut announced its new features including improvements to the way you view your friends, 9 rather than 8 of your friends displayed on your homepage and profile page and basic links to your friends' content right under their profile picture as you browse through their different pages. It also announced the initial related languages: Hindi, Bengali, Marathi, Tamil, and Telugu. Profile editing can take place by clicking the settings button under your profile photo (or alternatively, click the blue settings link at the top of any page).

On September 4, 2007, Orkut announced another new feature. You can now see an "Updates from your friends" box on the homepage, where you'll get real-time updates when your friends make changes to their profiles, photos and videos. Moreover, in case you want to keep some things on your profile private, Orkut has added an easy opt-out button on the settings page. Scraps (popularly word for messages in orkut) was also HTML-enabled letting users now interact in a more interesting manner. On November 8, 2007, Orkut greeted its Indian users Happy Diwali in a very special way, by allowing them to change their Orkut look to a Diwali-flavored reddish theme. On April Fools' Day 2008, Orkut temporarily changed its name on its webpage to yogurt, apparently as a prank. On 2 June 2008, Orkut has launched its theming engine with a small set of default themes.[11] along with this PHOTO tagging has also finally arrived at orkut.

Orkut Applications

On 16 April, 2008, Orkut began rolling out applications to everyone in India and then in phases to the rest of the world.[12] Orkut has several applications launched today.

Criticism

Flooders and fake profiles

As with any online social networking community, a number of fake and cloned profiles exist on Orkut.[13] Due to the large number of users, and the deactivation of the jail system, the profiles were often left unremoved or, when removed, recreated easily. These profiles are normally created to troll, to spam, to flood or just for fun. It is not hard to find users owning more than one profile, with some stating they own hundreds.

In 2005 invisible profiles, communities and topics started to appear in Orkut. This could be achieved by using HTML escaping codes and 1x1 pixel photos to fool the engine behind the site.[14] This hole was later fixed, and currently there is a lower limit on profile image dimensions.

In August 2005 a freeware program was made in Delphi called Floodtudo ("tudo" in Portuguese means "everything" - this was developed by a Brazilian) specifically for flooding Orkut. It quickly spread through the users and was easily downloadable (the most common Floodtudo versions were 1.2, 1.5, 2.0 and 2.2). As this program was massively used by thousands of spammers, a big spam wave struck Orkut in September and October 2005. Another most commonly used Scrap Flooder "Carbon Copy Scraper" & "Blind Carbon Copy Scraper" (commonly called CCS & BCCS ) was javascript based (popular versions 2.4, 3.3, and 5.1), available in every famous orkut communities.The main idea behind this was ( by Master Blaster an Indian Cracker ) only allowing the profile holders to send a same scrap to all friends at a single time, but was missued by spammers.

As the flooding of Orkut was becoming out of control, the developers implemented some features in order to stop this. These features included not allowing two or more verbatim topics or scrapbook entries to be submitted, forcing the user to wait before posting another topic or scrapbook entry, and the usage of captchas, whenever a scrap entry is hyperlinked. They gave more rights to community moderators as well, so that users can be banned outright instead of relying on the developers to remove them.

There has recently been controversy revolving around the use of Orkut by various hate groups. Virulent racists and religious fanatics allegedly have a solid following there. Several hate communities focused on racism, Nazism and white supremacy have been deleted due to guideline violation.

In 2005, various cases of racism were brought to police attention and reported on in the Brazilian media.[15] In 2006, a judicial measure was opened by the Brazil federal justice denouncing a 20-year-old student accused of racism against those of Black African ancestry and spreading defamatory content on Orkut.[16] Brazilian Federal Justice subpoenaed Google on March 2006 to explain the crimes that had occurred in Orkut.[17]

Anti-religion, anti-national, and anti-ethnic hate groups have also been spotted. Recently an Indian court has issued notices to Google on some of the groups. The Mumbai Police are seeking a ban on Orkut post objections raised by political groups. Groups denigrating various political leaders and celebrities have also emerged. Also in a reported case of 2005, racist groups have been reported. They were anti-Tamil groups. Recently a member of a Tamil hate group is currently being tracked down.

State Censorship

Orkut was very popular in Iran, but the website is now blocked by the government. According to official reports, this is due to national security issues, and Islamic ethical issues about dating and match making. To get around this block, sites such as orkutproxy.com (now defunct) were made for Iranian users. Other websites such as Yahoo! Groups and Google Groups have communities dedicated to receiving updates on the newest location of Iran's Orkut proxy. Though it was once possible to bypass governmental blockage of Orkut, the site has closed its HTTPS pages on all anonymous proxies. Now it is almost impossible for ordinary users to visit this site inside Iran.[18] Many other sites have been published in Iran since Orkut's blockage, using the same social-networking model - examples include MyPardis, Cloob and Bahaneh. Of course, these websites run a high risk of being blocked as well, so they have their own censorship policies to meet Iran's unwritten regulations and rules of filtering.

In August 2006, United Arab Emirates followed the footsteps of Iran in blocking the site. This block was subsequently removed in October 2006. On July 3, 2007, Gulf News revisited the issue, publishing complaints from members of the public against Orkut communities like "Dubai Sex", and officially bringing the complaints to the attention of the state telecom monopoly Etisalat [19]. By July 4, 2007, Etisalat had placed a renewed ban on the site,[20] which remains in effect despite Google's promise to negotiate the ban with the UAE.[21] Saudi Arabia is another country that has blocked access to Orkut, while Bahrain's information ministry is also under pressure to follow suit.[22]

Privacy

Earlier in Orkut it was allowed for anybody to view any one's pictures, videos as well as scraps. But this gave promotion to the people who started misusing the photos and videos and placed them on the internet with fake details. Many of them were vulgar, especially pictures of women. Moreover the scraps could be read easily. Currently privacy covers such features as scraps (separately read and write access), videos, photoalbums, testimonials, applications. The following privacy levels are currently available to users: friends/friends of friends/everyone in the network. The user can limit visibility of her/his profile to a certain region or group of regions (that's what is called "network"); in this case outside of these regions no user information is available.

Initially, the common opinion was that out of the two major countries, only users in India will be interested in privacy on orkut, while Brazil, being a very open society, will not need it. In reality, the percentage of users choosing to hide their data is the same in India and Brazil. The only difference is that in Brazilian sector of orkut there is a community "Quer privacidade? Sai do orkut" ("Want privacy? Get out of orkut") against other people's privacy.

Funny Error Message

File:OrkutFunnyErrorMessage.jpg
Funny Orkut Error Message.

Bad, bad server. No donut for you.

Unfortunately, the orkut.com server has acted out in an unexpected way. Hopefully, it will return to its helpful self if you try again in a few minutes.

It's likely that the server will behave this way on occasion during the coming months. We apologize for the inconvenience and for our server's lack of consideration for others.

This is a common error message when the Orkut server encounters heavy traffic. In this way Orkut developers attempt to show their sense of humor.

Security and safety

Hacking accounts and communities with XSS

On January 1, 2005 a Brazilian hacker called Vinícius K-Max attacked Orkut, stealing community ownership rights, using a cross-site scripting (XSS) vulnerability.[23][24] Eventually, various phishing sites were developed with the intent of stealing other people's accounts and communities.

In December 2007, hundreds of thousands of users accounts were affected, using another XSS vulnerability and a worm. A user's account was affected when the user simply read a particular scrap containing an embed which caused the user to automatically become a part of a community on the site, without approval. The affected user's account was then used to send this scrap to everyone present in the user's friend list thereby creating a sort of a huge wave.

MW.Orc worm

On June 19, 2006 FaceTime Security Labs' security researchers Christopher Boyd and Wayne Porter discovered a worm, dubbed MW.Orc.[25] The worm steals users' banking details, usernames and passwords by propagating through Orkut. The attack was triggered as users launched an executable file disguised as a JPEG file. The initial executable file that causes the infection installs two additional files on the user's computer. These files then e-mail banking details and passwords to the worm's anonymous creator when infected users click on the "My Computer" icon.

The infection spreads automatically by posting a URL in another user's Orkut Scrapbook, a guestbook where visitors can leave comments visible on the user's page. This link lures visitors with a message in Portuguese, falsely claiming to offer additional photos. The message text that carries an infection link can vary from case to case. In addition to stealing personal information, the malware can also enable a remote user to control the PC and make it part of a botnet, a network of infected PCs. The botnet in this case uses an infected PC's bandwidth to distribute large, pirated movie files, potentially slowing down an end-user's connection speed.

The initial executable file (Minhasfotos.exe) creates two additional files when activated, winlogon_.jpg and wzip32.exe (located in the System32 Folder). When the user clicks the "My Computer" icon, a mail is sent containing their personal data. In addition, they may be added to an XDCC Botnet (used for file sharing), and the infection link may be sent to other users that they know in the Orkut network. The infection can be spread manually, but also has the ability to send "back dated" infection links to people in the "friends list" of the infected user. According to statements made by Google, as noted in Facetime's Greynets Blog, the company had implemented a temporary fix for the dangerous worm.[25]

HTTPS Not Obvious

In and around April 17, 2007 users began reporting that secure (https) access to the Orkut login server was no longer available. In fact, Google had changed the main login page to http delivery to improve efficiency, but the actual login remained secure using https in an iframe.[26] This information had not been well-published by Google, and did not give the users the reassurance of seeing the "secure connection" padlock in the browser. On July 17, 2007, a revised login page, which is delivered via https, addressed these issues.

Session Management and Authentication Issues

On June 22, 2007 Susam Pal and Vipul Agarwal published a security advisory on Orkut vulnerabilities related to authentication issues.[27] The vulnerabilities are considered very dangerous in cybercafes, or in the case of man-in-the-middle attack as they can lead to session hijacking and misuse of legitimate accounts.[28] The vulnerabilities are not known to be fixed yet and therefore pose threat to the Orkut users.

A week later, on June 29, 2007 Susam Pal published another security advisory which described how the Orkut authentication issue can be exploited to hijack Google and Gmail sessions and misuse the compromised account of a legitimate user under certain conditions.

Joseph Hick performed an experiment on the basis of the advisories published by Susam Pal, to find out how long a session remains alive even after a user logs out.[29] His experiment confirmed that the sessions remain alive for 14 days after the user has logged out. It implies that a hijacked session can be used for 14 days by the hijacker because logging out does not kill the session.[30]

W32/KutWormer

On December 19, 2007, a worm written in Javascript started to cause havoc. Created by a Brazilian user called "Rodrigo Lacerda", it automatically made the user join the virus related community and infect all friends' scrapbooks with copies of itself, the worm infected over 700,000 orkut users, it was a huge wave of infection. The worm is spreading through Orkut’s recently introduced tool that allows users to write messages that contain HTML code. The ability to add Flash/Javascript content to Orkut scraps was only recently introduced.[31][32] On March 3, 2008 W32/Scrapkut.worm was found. The worm attempts to spread itself by sending orkut users scraps that contains the link to the worm itself. Aliases Downloader.Banload.ONK (GRISoft) TR/Dldr.Orkut.A (Avira) Trojan-Downloader.Win32.Banload.auf (IKARUS) Trojan.DL.Win32.Banload.dzm (Rising) W32.Scrapkut (Symantec).

Other Attacks

Private Album Crack

In December 2007, a Brazilian cracker named "Rodrigo Lacerda" published a script that allowed users to scrape other people's private photos. The exploit consisted of generating album photo urls, due to their simple structure. The main idea behind this was by "Master Shekhar" an Indian Cracker. This crack made Orkut team implement new secure album/photos implementation. Although a web developer Manish Surjan from India created a few tools to help protect orkut profiles. He firstly implemented that tools using firefox monkey and then it was majorly implemented to all new profiles.

Social Engineering

Attacks on orkut using social engineering never stop. Among these the easiest kind is to offer a user to enter a script into the browser's address area, to "improve performance".

Brazil

On August 22, 2006, Brazilian Federal Judge José Marcos Lunardelli ordered Google to release Orkut user’s information of a list of about two dozen Brazilian nationals, believed to be using Orkut to sell drugs and involved in child pornography by September 28. The judge ordered Google to pay $23,000 per day in fines until the information is turned over to the Brazilian government. The information the government is requesting would also be used to identify individuals that are spreading child pornography[33] and hate speech, according to the Brazilian government. As of September 27, 2006 Google has stated that they will not release the information, on the grounds that the requested information is on Google servers in the U.S. and not Google servers in Brazil, and is therefore not subject to Brazilian laws.

India

Of late, the number of Indians on Orkut has been increasing rapidly. On October 10, 2006, the Bombay High Court's Aurangabad bench served a notice on Google for allowing a hate campaign against India.[34] This referred to a community on Orkut called 'We Hate India', which initially carried a picture of an Indian flag being burned and some anti-India content.[35] The High Court order was issued in response to a public-interest petition filed by an Aurangabad advocate. Google had six weeks to respond. Even before the petition was filed, many Orkut users had noticed this community and were mailing or otherwise messaging their contacts on Orkut to report the community as bogus to Google, which could result in its removal. The community has now been deleted but has spawned several 'We hate those who hate India' communities. Prior to the 60th Independence Day of India, orkut's main page was revamped. The section which usually displayed a collage of photos of various people, showed a stylized orkut logo. The word orkut was written in the Devanagiri script and was colored in the Indian national colours. Clicking on the logo redirects to a post by the orkut India Product Manager, Manu Rekhi,[36] on the orkut internal blog. There has also been some media outcry against Orkut after a couple of youngsters were apparently lured by fake profiles on the site and later murdered.[37]

On November 23, Bombay High Court asked the state government to file its reply in connection with a petition demanding a ban on social networking site, Orkut, for hosting an anti-Shivaji Web community.[38] Recently, the Pune rural police cracked a rave party filled with narcotics.[39] The accused have been charged under anti-narcotic laws, the (Indian) Narcotic Drugs and Psychotropics Substances Act, 1985 (NDPS). Besides the NDPS, according to some media reports, the police were deliberating on the issue of charging the accused under the (Indian) Information Technology Act, 2000 perhaps because Orkut was believed to be one of the mode of communication for these kind of drug abuses.[40] The Cyber police in India have entered into an agreement with Orkut to have a facility to catch and prosecute those misusing Orkut since the complaints is in a rising stage.[41]

See also

References

  1. ^ http://www.alexa.com/data/details/traffic_details/orkut.com
  2. ^ "Why Google Turned Into a Social Butterfly". The New York Times. November 4, 2007. Retrieved 2007-11-07.
  3. ^ "Orkut Demographics". orkut. Retrieved 2008-06-01.
  4. ^ "Traffic Details for: orkut.com/". Alexa. Retrieved 2008-07-19.
  5. ^ Folha Online - Informática - Orkut passa para as mãos do Google Brasil; empresa muda diretoria no país - 07/08/2008
  6. ^ G1 > Tecnologia - NOTÍCIAS - Filial brasileira do Google vai assumir controle mundial do Orkut
  7. ^ http://info.abril.com.br/aberto/infonews/082008/07082008-23.shl
  8. ^ Estadao.com.br :: Tecnologia:: Google Brasil assumirá o controle mundial do Orkut
  9. ^ Demographics of Orkut by country
  10. ^ ""How are the friends on my homepage ordered?"".
  11. ^ orkut Blog: If you're in India and feel like a change of scene
  12. ^ orkut Blog: Apps are live in India
  13. ^ "Fake Orkut profile of schoolgirl posted". Rediff. February 6, 2007. Retrieved 2007-07-10.
  14. ^ "Invisible picture on orkut: become invisible". Orkut proxy and tricks. June 19, 2007. Retrieved 2007-07-10.
  15. ^ Racism in Brazilian Orkut
  16. ^ "Racismo na internet chega à Justiça" (in Portuguese). Estadão. February 1, 2006. Retrieved 2007-07-10.{{cite news}}: CS1 maint: unrecognized language (link)
  17. ^ "Ministério Público pede que Google explique crimes no Orkut" (in Portuguese). Folha Online. March 10, 2006. Retrieved 2007-07-10.{{cite news}}: CS1 maint: unrecognized language (link)
  18. ^ Orkut and Iran
  19. ^ Gulfnews: Orkut.com 'being used for immoral activities'
  20. ^ Gulfnews: Orkut.com banned in the UAE
  21. ^ Orkut blocked in sex row | Media and Advertising
  22. ^ Gulf Daily News
  23. ^ Terra - Informática
  24. ^ Newsvine - Orkut: a Google project gone terribly wrong
  25. ^ a b "Data-Theft Worm Targets Google's Orkut". SpywareGuide. June 16, 2006. Retrieved 2007-07-10.
  26. ^ http://groups.google.com/group/orkut-help-profiles/browse_frm/thread/8fd95fe3aae5b839/204595c9069fb9d9?lnk=gst&q=https+login&rnum=1#204595c9069fb9d9
  27. ^ "Orkut Authentication Issues - Full Disclosure".
  28. ^ "XSSED News Report on Authentication Issues".
  29. ^ "Google/Orkut Authentication Issue PoC".
  30. ^ "Google/Orkut Session Expiry PoC - Results".
  31. ^ Worm Hits Google's Orkut - washingtonpost.com
  32. ^ Worm Squirms Through Google`s Orkut
  33. ^ "Meninas a um clique do abuso sexual com fotos sensuais em blogs e no orkut". Revista Orkut.etc.br. May 10, 2006. Retrieved 2007-07-10.
  34. ^ "Google's social networking site in trouble". The Times of India. October 10, 2006. Retrieved 2007-07-10.
  35. ^ "Police planning to ban Orkut in India". February 22, 2007. Retrieved 2007-07-10.
  36. ^ orkut blog: Post to commemorate 60 years of Indian Independence
  37. ^ Friends of slain teen arrested, Orkut angle being probed - India PRwire
  38. ^ "File reply on plea for ban on Orkut: HC". Rediff. November 23, 2006. Retrieved 2007-07-10.
  39. ^ "Pune rural police crack a rave party". March 5, 2007. Retrieved 2007-07-10.
  40. ^ "Pune rave party breached IT Act?". Ciol. March 6, 2007. Retrieved 2007-07-10.
  41. ^ "Police tie up with Orkut". The Hindu. November 20, 2007. Retrieved 2007-11-29.