Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Google Account Recovery via SMS

Google added a new password recovery option: you can now associate a mobile phone number with your Google Account and Google will send a recovery code by SMS.

"Since most people use cell phones these days, we decided text messaging would be an easy, convenient addition to our password recovery options. To set up password recovery via your mobile phone, just sign in to your account and click Change Password Recovery Options. Enter your mobile phone number and current password and then click Save. If you lose access to your account for any reason, you'll be able to regain access by entering a code we'll send in a text message."


For now, the options is only available in the US, so you need to use a US proxy to see it. Google also updated the password recovery settings page to include all the account-recovery options: secondary email addresses, text messages and the security question.

Update: the feature is now available everywhere.

{ via Blogoscoped Forum }

Update Vulnerable Programs

Secunia is a respected security service provider that tracks vulnerabilities in more than 20,000 applications and operating systems. To find information about the latest vulnerabilities, you could subscribe to Secunia's mailing lists, but if you want to know whether there are known security issues for the software installed in your computer, install Secunia Personal Security Inspector.

The Windows application scans your computer and it lists the insecure programs, information about vulnerabilities and links to the patches. In most cases, Secunia provides direct links to the latest updates, so they are easy to download and install. To find more information about security problems and to list all the software from your computer that needs to be updated, switch to the advanced interface.


Secunia collected data from 20,000 users of the software and found at least one vulnerability in 98.09% of the cases. "By insecure program it is understood, that there is a newer version of the program available from the vendor that corrects one or more vulnerabilities, but the user has yet to install the secure version. A vulnerability in a program can be exploited by hackers to anything from compromising a PC, to automatically install trojans/viruses, to sniff out private information (passwords, credit cards information, etc)."

Not all applications include auto-update and users have to manually update to the latest versions. Google is one of the companies that thinks it's important to update software without any user intervention, that's why most Google software has an auto-update feature or is integrated with Google Update.

Secunia's software focuses on updates that solve security problems. More comprehensive solutions for updating your software include UpdateStar, FileHippo Update Checker and Appget, but none of them is very reliable.



Force Gmail to Always Use Secure Connection

Gmail rolls out a new option that lets you set the https version as default. If you go to the Settings and select "always use https", Gmail will automatically redirect to the secure version. Until now, you had to manually type https://mail.google.com in the address bar, bookmark the address or use a Greasemonkey script.


"If you sign in to Gmail via a non-secure Internet connection, like a public wireless or non-encrypted network, your Google account may be more vulnerable to hijacking. Non-secure networks make it easier for someone to impersonate you and gain full access to your Google account, including any sensitive data it may contain like bank statements or online log-in credentials. We recommend selecting the 'Always use https' option in Gmail any time your network may be non-secure," explains Google.

Read, for example, David Pogue's post about Wi-Fi eavesdropping. "All Jon needed [to read my mail] was a packet sniffing program; such software is free and widely available. (He used a Mac program called Eavesdrop.) It sniffs the airwaves and displays whatever data it finds being transmitted in the public hot spot."

Https is typically used for sites that deal with sensitive data, so you'll see it when you authenticate to sites like Google or Facebook and when you use your mobile banking account, PayPal, Google AdWords and a handful of similar sites. The benefit is that the connection between your browser and the remote servers is encrypted and nobody could capture the sensitive data.

"We use https to protect your password every time you log into Gmail, but we don't use https once you're in your mail unless you ask for it (by visiting https://mail.google.com rather than http://mail.google.com). Why not? Because the downside is that https can make your mail slower. Your computer has to do extra work to decrypt all that data, and encrypted data doesn't travel across the internet as efficiently as unencrypted data," says the Gmail blog.

In addition to the worse performance, Google also mentions that the mobile application could show errors if you don't enable 'Always use secure network connections (slower performance)' in the app's settings section. If you use Firefox, don't forget to disable the Greasemonkey scripts that redirect Gmail to the secure version and to deactivate the similar option from Firefox extensions like Better Gmail and CustomizeGoogle.

The good news is that you don't need a similar setting for other Google applications if you use the navigation bar: Google automatically links to the secure versions of Google Calendar, Google Docs, Google Reader and Google Sites. If you don't see the new option in Gmail's settings, you have to wait until Gmail enables it in your account.


Find Who Has Access to Your Gmail Account

After years of testing, Gmail has finally added a very useful security feature: tracking open sessions. If you log in to Gmail from more than one computer and you forget to sign out, you'll be able to see the list of locations where your account can still be accessed.


Until now, the only solution when you forgot to log out from Gmail after using a public computer was to change your password. Otherwise, anyone could access your account without knowing the password. Now you can sign out remotely from all the locations where your Gmail account is still open.

If you click on "Details" in Gmail's footer, you'll find a lot of interesting information about your sessions. "The top table, under Concurrent session information, indicates all open sessions, along with IP address and access type -- which refers to how email was retrieved, for example, through iGoogle, POP3 or a mobile phone. The bottom table, under Recent activity, contains my most recent history along with times of access. I can also view my current IP address at the very bottom of this window, where it says This computer is using IP address...".


This could be useful if you want to find whether someone else has access to your account: you'll be able to find the IP address and the date of the most recent activity in your account.

Gmail's blog mentions that this feature is currently being rolled out in the new version of Gmail, so you may not see it right now. Google AdSense, PayPal and orkut are three other services that show the time of your last login so you can protect against abuse, but Gmail's new feature is much more advanced.

Among the things you can do to protect your Gmail account, it's a good idea to sign out after reading your email, not to select "remember me" when you log in from a public computer and to choose a good password that should remain secret.

Google Anti-Malware Diagnostic Pages

ZDNet's security blog points to an update to Google's malware warnings. Like McAfee SiteAdvisor, now each web site has a special diagnostic page that lists answers to four questions:

1. What is the current listing status?
2. What happened when Google visited this site?
3. Has this site acted as an intermediary resulting in further distribution of malware?
4. Has this site hosted malware?

Here's, for example, the diagnostic page for google.com: http://www.google.com/safebrowsing/diagnostic?site=google.com, which lists some interesting facts.

"Of the 274621 pages we tested on the site over the past 90 days, 4 page(s) resulted in malicious software being downloaded and installed without user consent. The last time Google visited this site was on 05/22/2008, and the last time suspicious content was found on this site was on 03/13/2008. Malicious software includes 4 scripting exploit(s), 4 trojan(s). Successful infection resulted in an average of 10 new processes on the target machine. Malicious software is hosted on 4 domain(s), including 58.65.239.0, truemaybe.com, abc-powers.com. 5 domain(s) appear to be functioning as intermediaries for distributing malware to visitors of this site, including xtraff.biz, x-traffic.ws, smartvideochannel.com."

Despite all of these findings, google.com is not listed as suspicious, probably because the domain is whitelisted or the suspicious content is not very significant. It's likely that the domains listed above are from Google's search results, so that means the anti-malware system doesn't respect robots.txt.

Google Phishing Warning

After flagging search results that distribute malware, Google will also show warnings for web pages used for phishing. Most of these pages are active one or two days before they are taken down by hosting providers, but some of them could be indexed by search engines. While the latest versions of Internet Explorer, Firefox and Opera have anti-phishing protection, a new security layer still have some usefulness.

"Warning - phishing (web forgery) suspected. The site you are trying to visit has been identified as a forgery, intended to trick you into disclosing financial, personal or other sensitive information," mentions the page displayed by Google instead of the search result.


Google also has a Safe Browsing API "that enables client applications to check URLs against Google's constantly updated blacklists of suspected phishing and malware pages." The API is used by Firefox and Google Desktop.

Google Offers Security Services for Mail Servers

Google acquired last year Postini, a company that offered hosted services for email servers. "Postini invented the software as a service approach to providing communications security and compliance, and holds two fundamental patents in the space, with more patents pending." Google integrated a small part of the offering in Google Apps Premier Edition: policy management, spam/virus filtering and 90-days message recovery.

Now Google offers the rest of the Postini services under the Google Apps umbrella, but without tying them with Google Apps Premier Edition and Gmail. Google Apps Security Services work with the most important email servers (Microsoft Exchange Server, Lotus Domino, Postfix, Sendmail, Macintosh OS X Server, Novell Groupwise) and offer three levels of protection, priced differently:


* message filtering: anti-spam, anti-virus, anti-phishing, and malware protection for inbound messages - $3/user/year
* message security: inbound and outbound mail filtering, email encryption, content policy management - $12/user/year
* message discovery: the same as above plus one-year message archiving, audit reports - $25/user/year

For educational institutions and non-profit organizations, the prices are much smaller: $1, $4 and $8.33/user/year. For all the services, Google provides 99.999% service level assurance.

Here's how the service works: you change the MX records to point your mail traffic to Google's data centers and all the bad traffic will be stopped before reaching your mail server. Google processes email in RAM and doesn't write the valid messages to disk.
Google provides multiple layers of protection against viruses. The service leverages its visibility to emerging threats by monitoring attacks against our customer base and - in real-time - blocks IP addresses that are issuing virus attacks. In addition, Google utilities multiple anti-virus protections including zero-hour heuristics, coupled with multiple commercial anti-virus engines to detect existing and emerging threats.

As with our virus protection, Google leverages visibility into billions of daily message connections to monitor spam attacks and blocks the most obvious spam. Our heuristic engine then filters the incoming mail traffic and captures any suspicious messages. This is all performed in real-time (processed in RAM memory in our data centers) without delays to your email delivery. With these capabilities, Google combines an extremely effective capture rate with an exceptionally low false positive rate.

Google says that Postini already has 40,000 customers and 14 million users and these affordable prices should increase the user base. Unfortunately, the association between these security services and Google Apps might confuse the potential clients and make them think that the services are only available for Gmail.

In fact, Gmail already includes anti-spam, basic anti-virus, anti-phishing and the corporate version of Google Apps includes content policy management and basic message archiving at no additional cost. Maybe Google will use the data obtained from Postini's services to enhance Gmail's security features.

Google Custom Search Blog Hacked?

All the posts from Google's Custom Search blog were deleted and there's a new post written by someone who doesn't speak English very well (my emphases).

Google Custom Search, is the wonderful product from Google which many webmasters have been looking and dream for. It allows webmasters to create their own custom search engines to search only the sites he/she wants.

Also Google Custom Search is integrated with Ad-sense, which means make money while keeping users on your site for longer time with custom search engine.

I'll cover up more on this powerful tool very soon in my next blog.

Good Luck for all the Custom Search customers(??).

Cheers,
Srikanth


Google uses Blogger for all of its 50+ blogs. It wouldn't be the first time when one of Google's official blogs has problems: last year, Google's main blog was accidentally deleted in March and was hacked in October.

Update (90 minutes later): Everything is back to normal. There's no official explanation for this incident.

Update 2: The explanation is pretty strange. "We accidentally classified ourselves as spam, and our ever-perceptive Blogger settings caught us. The Custom Search Blog has since been restored, and we're taking steps to ensure this doesn't happen with other Google blogs in the future." So Google deleted the blog because it was classified as spam and then someone set up a new blog at the same address.

Update 3 (August 10): More details from Google's Sean Carlson via Search Engine Watch. "Blogger's spam classifier misidentified the Custom Search Blog as spam. If a spammer gets caught by our automated classifier, the blog owner will receive notification of this identification. At the owner's request, the Blogger team will review the blog to verify that the blog in question isn't spam. In this case, the Custom Search Blog bloggers overlooked their notification, and after a period of time passed, the blog was disabled. The content wasn't deleted, but it was removed from the URL. Even after blogs are disabled as spam, the owner can write in requesting a review for her or his blog to be restored. If the review proves that the owner's content was not in fact spam, the blog will be restored with all content. So, when we saw what happened on Tuesday -- and we're well aware that our content wasn't spam -- we restored the official Google Custom Search Blog. The individual who had claimed the URL and published the blog post in reference still has his content; it's just hosted at a new URL."

Users Report Gaining Access to Random Google Accounts

There are many problems with Google's services lately. After Google Groups had some temporary glitches, some people report that Google switches them to random accounts.

Jvy Loh writes on his blog about the incidents:

"It started off when I was using gg docs and after closing 1 of my docs, I was returned to my 'doc home', however, someone else's email was reflected at the top instead of mine. It disappeared soon after before I could catch what was going on. (...) Lately, the google problem came up again. Nearly everytime I boot up my computer, and login to google toolbar or gmail, I began to notice that when I went further to click on other google services, e.g. gg reader, very often I went into someone else's reader. Not just their email id replacing mine at the top, it was literally someone's reader. I could read their feeds and so on. (...) The MOST SERIOUS thing so far is that you can accidentally made changes to other user's account while you think you are modifying your own. I realized that when I was making changes/adding items, like adding a bookmark, adding a feed into my reader, and adding notes to my notebook, adding gg gadgets to my igoogle, rearranging my igoogle layout, the changes all went to the other party, not mine, and hey this is scary!"

He also mentions that the users seem "to be originating from the same city, which is Singapore, and I suspect some of them are students, by browsing through the gg reader feeds presented to me, and supposingly 'my bookmarks'. (...) Not only did it appear in Singapore, those users seem to be from the same organization, which are local universities, 1 from NTU, and some may be from NUS, and fyi the 2 top universities in Singapore are located in the west of Singapore, and I am in the north-west, which is pretty near to each other."

Other Google user complains over at Google Groups: "Whenever I use Google Reader, I would 'cross-over' to another user's account."

And another one: "I've been login to other users today, seeing their feeds instead of mine. I login to gmail and google reader. While reading the feeds halfway I would see my feeds change into other user's [feeds], my account will also change to other google user account."

Other report from a regular reader of this blog: "While I was reading posts in Google Reader today, my account was switched to someone else's account. The account name on the upper right corner changed and I could see all his or her subscriptions in my Google Reader. I closed the Reader and open it again. Nice! I could read another person's subscriptions. I tried iGoogle and it was also changed."

It seems that this isn't an isolated incident and it may have something to do with Google cookies and Google Reader, but it's not very clear. If you had similar problems or you know what causes them, please let us know.

Update. Matt Cutts, from Google, posted this: "Given that most of these reports are coming from a single area (Singapore), it sounds like an ISP isn't handling their connections correctly. We've certainly seen ISPs mess up their proxies before. I'll still ask about this though."

Update 2. Jvy Loh writes: "Since last Saturday [July 22] after Google Reader was patched (need confirmation from Google whether the Google Reader or local ISP proxy/cache played a bigger part in this security problem), I have not noticed any more security glitches. Two other Singapore users who contacted me also reported no more security issues since then. So, we have enough reasons to think that the security issues related to what I have reported have been eliminated."

Google Buys Postini to Expand Enterprise Offering


After the launch of Google Apps Premier Edition, more than 100,000 companies switched to Google's hosted services, but large companies couldn't use it "due to issues of security and corporate compliance". To provide better services for these companies, Google bought Postini, "the global leader in on-demand solutions that deliver on the promise of communication security and compliance". Postini is also a variation of postino, the Italian word for postman. Like Google Apps, Postini doesn't require you to install special software or hardware, as all the data is hosted and processed on their servers. "Postini invented the software as a service approach to providing communications security and compliance, and holds two fundamental patents in the space, with more patents pending."

Postini lets you recover messages, set policies for individual users or groups (block all the messages that contain a certain a keyword), archive and delete messages according to company's policy. "When an email message is sent, it passes through Postini's datacenters and a copy is saved while the original continues on its way. All of this happens within milliseconds, so there is no delay to your messages. When you configure rules for your users we can also check for violations and, if necessary, block the message or take other actions that you define."

Postini has already been a Google Enterprise Partner for Google Apps and it serves 35,000 business clients. The press release notes that Google paid $625 million in cash.

Firefox 3 Will Include Malware Protection


Mozilla intends to extend Firefox's phishing protection to include a list of sites that try to install malware. "Similar to how Firefox 2 blocks Web sites that are potentially going to try to steal your personal information, Firefox 3 will block Web sites that we believe are going to try to install malicious programs on your computer. Mozilla is coordinating with Google on this feature," says Alex Faaborg.

ComputerWorld quotes Gervase Markham, a developer for Bugzilla, who says: "What we are actually doing here is giving Google veto power over any Web page." The list of potentially harmful sites is managed by StopBadware, an organization that fights against spyware, malware, and deceptive adware. StopBadware is sponsored by Google, Lenovo and Sun.

Google already shows alerts if you try to visit a search result that may install malicious software on your computer. The feature is also included in Google Desktop, which automatically updates a list of suspicious or malicious sites from Google's servers. Firefox will probably work the same.

Other new features that will be included in Firefox 3: a unified way of storing bookmarks, history, and information about Web pages, microformat detection, private browsing, support for offline web applications. Firefox 3 should be launched at the end of the year, but you can still try the Alpha 5 version at your own risk.

{ The mockup is licensed as Creative Commons Share-Alike. }

Google Buys GreenBorder, Web Sandbox

Google bought GreenBorder, a Mountain View-based company that creates security software designed to protect a computer as you surf the web. According to Silicon Valley Watcher, GreenBorder developed "an easy solution to virus, spyware, and trojan threats by isolating each Internet session from the rest of the PC and earlier Internet sessions. The beauty of the Green Border Pro software is it doesn't need to be updated to guard against new virus signatures or new types of malware. It creates a secluded, virtual Internet session and when you are done, it flushes everything away, in your cache and in temporary files."

The application was initially a sandbox for Internet Explorer, but now it also supports Firefox and lets you open files downloaded from the Internet in a virtual environment. Each application protected by GreenBorder has a colored border around the window, so you know you're safe.


Other features include:

* Keeps your PC from getting infested by "drive-by" downloads.

* Blocks theft of your private identity information.

* Prevents thieves from stealing your confidential files.

* Protects your applications from hijacking.

The Windows software is still available as a trial version at Download.com, but the full version used to cost $29.95 / year. Hopefully, Google will release a free version.

{ via Googlified }

Google and the Web-Based Malware

Google made an interesting study [PDF, 438 KB] about the pages that try to automatically install malware (the so-called "drive-by download") by exploiting flaws in Microsoft's Internet Explorer. By analyzing all the pages from Google's index, the study found that 450,000 URLs launched files that contained malware. If we assume Google's index has 20 billion pages, that means one in 2,222 pages launches malware. Trojans were the most frequent category of malware, followed by adware.

"The installed malware often enables an adversary to gain remote control over the compromised computer system and can be used to steal sensitive information such as banking passwords, to send out spam or to install more malicious executables over time."

It's also useful to know "the four prevalent mechanisms used to inject malicious content on popular websites: web server security, user contributed content, advertising and third-party widgets". As an example of widget, the study mentions a free stats counter that required users to include links to some external JavaScript files in order to monitor the traffic. At some point, the files started to include exploit code. In this case, the malware was outside the control of the webmaster, but could still be dangerous to the users.

"Examining our data corpus over time, we discovered that the majority of the exploits were hosted on third-party servers and not on the compromised web sites. The attacker had managed to compromise the web site content to point towards an external URL hosting the exploit either via iframes or external JavaScript."

Google started to flag the web sites that try to install malware (example of query). They're still included in Google's index, but you'll have to manually copy the URL and paste it in the address bar to visit the site. Most of the pages let you download pirated software and music. Also the newest version of Google Desktop shows warnings if you visit one of these sites.


The best defense against these threats is to use more secure browsers like Firefox or Opera and to install anti-virus / anti-spyware software (Google Pack includes all of these: Firefox, Norton Security Scan and Spyware Doctor, but there other free alternatives).

{ via BBC, that hires people who don't know how to count and draw the inaccurate conclusion that "one in 10 web pages scrutinised by search giant Google contained malicious code that could infect a user's PC" .}

Gadgets and Personal Data

User-generated gadgets made personalized homepages a better place because users can choose from a wider variety of content and even create their own gadget if they have programming skills. But just because you see a gadget in Google's directory or elsewhere doesn't mean you have to trust it and handover personal information or credentials.

Jason wrote a popular gadget that showed your MySpace alerts. Of course, the gadget required you to enter your MySpace username and password (ideally, MySpace should have an API for authentication and data).

"A few months back, a flaw was discovered whereby usernames were being passed in clear-text as a querystring parameter when using the gadget. As a result of Google's mechanism that caches web-content, a list of usernames on a phishing watchlist website was cached in Google's search index, thus making them publicly accessible. Once Google was alerted of the issue, they contacted me immediately. Google took action and removed the cached content from their search index, and I took numerous steps to strengthen the security of the gadget - and to mitigate any future risks. Google even went as far as to work with the operators of the phishing watchlist to remove my name and IP addresses from the suspected phishers list."

But people thought that the flaw was intentional and accused him of phishing. "Due to a common misconception that the Gadget was actually being used to facilitate phishing activity, I have decided to remove it permanently. This is a particularly difficult decision because of the large number of users and the popularity of this gadget."

Google shows a warning everytime you add third-party gadgets, so you should be careful when you add gadgets from unknown sources. You should be even more careful when you enter personal data.

Scan a File Using the Top Antivirus Software

If you get a file from a site you don't know very well (like a game or a screensaver), the first thing you should do is scan it using an antivirus. The problem is that your antivirus might not be very good or might not include the signature of the trojan included in the file you've just downloaded. So a good idea is to have a second opinion, but you can't install more than one antivirus (unless you disable the real-time protection).

VirusTotal is a site where you can upload a file smaller than 10 MB and it will be scanned by a large number of antivirus software (the current number is 31), including: Kaspersky, BitDefender, F-Secure, Panda. The file will not be scanned instantly, but you'll have to wait a short time (usually around one minute), depending on site's load. You'll get a report like:


If you see conflicting responses, look at the most trustworthy engines (some tests) and at the number of engines that report a virus. In the situation depicted in the screenshot, I can safely assume that the file is clean.

The service is available by email too: send a mail to scan@virustotal.com with the subject SCAN. If you use Gmail, you'll have to rename executable files (for example, from setup.exe to setup.ex1) to be able to send them.

A similar service is Jotti's malware scan, that has a bigger limit for the file size: 15 MB, but uses less antivirus engines.

{ Thank you, Google! }

SuperGenPass - Simple Password Generator

Yesterday I suggested some ideas to keep your passwords secure. In the comments, Thunder Rabbit pointed to a very simple solution to generate secure passwords, without having to remember them. SuperGenPass is a bookmarklet (a bookmark consisting mostly of JavaScript code) that uses a master password as a seed to create passwords for different sites. The nice thing is that the script generates the same password for a domain, but the process is unidirectional: you can't obtain the master password from a generated password. It's also cool that your master password is not stored anywhere (unless you want it to be stored in the bookmarklet).

The script works for any browser, but for Internet Explorer it needs to download some JavaScript code because of IE's limitations. If you don't want to rely on that site, you can save it to your site.

If you decide to use this solution, you'll have to change your passwords for each site where you want to use passwords generated by SuperGenPass. You can first try it with an unimportant site to see if you like it. Also you'll have to stop storing passwords in your browser or other password managers.

How will you use it?
* type the username and the master password when you log in
* click on the bookmarklet [extra-click]
* click on "Populate" [extra-click]
* submit the form

So two extra-clicks, no required software, no stored password and just a bookmarklet that could be easily stored on a USB drive (there's an alternative page for mobile phones). And, best of all, you can use a single password for all the sites that need one.

Keeping your Passwords Secure

Many people think it's hard to have a good password because it should be complicated and, as a result, hard to remember. When you create a new Google account, you can read some nice tips that prove you can create a strong yet memorable password.
* Include punctuation marks and/or numbers.
* Mix capital and lowercase letters.
* Include similar looking substitutions, such as the number zero for the letter 'O' or '$' for the letter 'S'.
* Create a unique acronym.
* Include phonetic replacements, such as 'Luv 2 Laf' for 'Love to Laugh'.

And some things to avoid (that could be summarized as: don't use passwords that are easy to guess).
* Don't use a password that is listed as an example of how to pick a good password.
* Don't use a password that contains personal information (name, birth date, etc.)
* Don't use words or acronyms that can be found in a dictionary.
* Don't use keyboard patterns (asdf) or sequential numbers (1234).
* Don't make your password all numbers, uppercase letters or lowercase letters.
* Don't use repeating characters (aa11).

And, of course, the obvious: "never tell your password to anyone (this includes significant others, roommates, parrots, etc.), never write your password down, never send your password by email."

So, the next time when you create a new passwords, think of a quote you like, an old saying (maybe not in English or your native language), use punctuation and replace some letters with similar digits or other characters. You can also use short forms for some of the words.

There are many places where you can test show strong a password is. One of them is available if you go to Google.com, sign out and then click on "sign in". Choose "create an account now" and type your password. Google will indicate you if your password is strong, fair or weak. Then you can use the password wherever you need it.

If you can't come up with a new password for each new site you sign up, at least try not to use the same password you have for your mail account (many people sign up using the email address: myemail@yahoo.com and choose the Yahoo password). If that site has security problems and your account is compromised, your Yahoo account will be compromised as well.

Also, be aware that most browsers offer to store your passwords, so they can auto-complete them. Many times they are not stored securely and anyone who has physical access to your computer can find the passwords (for example, go to Firefox > Tools > Options > Security > Show passwords > Show passwords again). That's why it's a better idea to use password managers like Password Safe, KeePass, RoboForm, that store your passwords securely and can manage any kind of password. In Firefox and Opera you could also use a master password, but there are commercially tools that can recover master passwords.

A small summary and some other tips:
* create strong passwords that mix digits, punctuation, capital and lowercase letters by thinking at a memorable quote and making some replacements or using acronyms
* don't share your passwords with anyone
* don't use the same password for all your accounts
* try not to use the built-in password managers from your browser. Use safer tools, if you really need a password manager.
* change your password from time to time
* try to stay away from sites that don't use secure authentication (look for https in the address bar)
* sign out when you finish a session

Do you have other ways to keep your passwords secure?

Security at Google

To prove to the potential customers of Google Apps' business edition that Google cares about security, they released a white paper titled "Comprehensive review of security and vulnerability protections for Google Apps" (available as PDF). Here are some interesting details:
Google operates one of the largest networks of distributed datacenters in the world, and goes to great lengths to protect the data and intellectual property in these centers. Google operates an undisclosed number of datacenters worldwide. Many primary Google datacenters are wholly owned and managed ensuring that no outside parties can gain access. The geographic locations of the datacenters were chosen to give protection against catastrophic events. The datacenters are at confidential, undisclosed locations in order to guard against user data being targeted. These facilities are protected with armed personnel around the clock. In addition, strong methods of entry protection such as biometric devices and secure token cards are used to ensure that only authorized personnel are granted access. Only select Google employees have access to the datacenter facilities and the servers contained therein, and this access is tightly controlled and audited.

The facilities themselves are engineered not only for maximum efficiency, but also for security and reliability. Multiple levels of redundancy ensure ongoing operation and service availability in even the harshest and most extreme of circumstances. This includes multiple levels of redundancy within a center, generator-powered backup for ongoing operations, and full redundancy across multiple dispersed centers. State of the art controls are used to monitor the centers both locally and remotely, and automated failover systems are present to safeguard systems. (...)

Data such as email is stored in a difficult to decipher format optimized for performance, rather than stored in a traditional file system or database manner. Data is dispersed across a number of physical and logical volumes for redundancy and expedient access, thereby obfuscating it from tampering. Google's physical protections described above ensure that no physical access to servers is possible. All access to production systems is conducted by cleared personnel using encrypted SSH (secure shell). Specialized knowledge of the data structures and Google's proprietary distributed architecture is built to provide a higher level of security and reliability than a traditional single tenant architecture. Individual user data is dispersed across a number of anonymous servers, clusters, and data centers. This ensures that data is not only safe from potential loss, but also highly secure.

Despite all these protection measures, Google had problems with cross-site scripting and some people even lost their Gmail accounts. If you find a security breach in a Google product, report it at security@google.com and wait a reasonable amount of time before revealing the details to the public.

Malware Warnings in Image Search

Google started to show warnings for search results that install malicious software. The same warnings can be seen in image search (one example is an "innocent" query like site:crackserver.com, that shows all the images indexed from crackserver.com). If you click on a thumbnail from the search results, you'll be sent to an interstitial that recommends to try another search result.

In the new interface of image search, the domain name is less visible, as you have to hover over the thumbnail to see it. So these malware warnings could help you avoid sites that might damage you computer.

Google Redirect Notice

Let's say I have a site that sells Cialis, and I have to use spam to promote it. Wouldn't be nice to use a trusted site like google.com to make a redirect to my site? For a very long time, if you used a URL like http://www.google.com/url?q=http://www.mysiteaboutcialis.com , Google sent you to mysiteaboutcialis.com without a notice. Many people were tempted to think that this must have been a Google site (it starts with google.com).

Google's redirection URL was also used for phishing to fool people or phishing filters. But it also had a valid reason for being there: tracking user clicks. If you go to a search results pages and copy the address of a result, you'll notice a long URL that starts with http://www.google.com/url?q=. Google uses that information to improve search results and to aggregate information about users.

Well, Google thought about that and decided to show a warning (similar to the malware warnings for pages that install malicious software) if you use the redirect directly. The redirects from search results pages use some complicated hashes, so it's difficult to bypass the warning, unless you know to build those hashes. The redirect notice says:

"The previous page is sending you to [new address].

If you do not want to visit that page, you can return to the previous page."


This is a clear sign that Google decided to do more to protect its users.
Related Posts Plugin for WordPress, Blogger...