Showing posts with label Google. Show all posts
Showing posts with label Google. Show all posts

Friday, May 25, 2018

More GDPR





If you are like me, you have likely seen more notices about privacy policy updates during recent days and weeks than the entire time you have been on the Internet.  Although, I must admit that I particularly enjoyed the "First message from deep space", that I saw on Twitter via Marcin Kleczynski.









Even after all the privacy policy notices I have seen, I was surprised when opening my blog account this morning to find the the information below that Google placed in my account:



Following the "Learn more" link which redirects to Cookies notification in European Union countries - Blogger Help, I discovered that visitors to Security Garden from the EU should be seeing the following notice:

Google Added Cookie Notice

 "LEARN MORE" from the notice leads to How Google uses cookies – Privacy & Terms – Google.

 Since I have confirmed that the notice works and displays, do not use AdSense and am not aware of any functionality from other providers, I gather that GDR requirements have been fulfilled with respect to this blog.  However, that may not be the case with Google as indicated in Google and Facebook accused of breaking GDPR laws - BBC News and Facebook and Google hit with $8.8 billion in GDPR lawsuits - The Verge.



Home
Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Tuesday, August 30, 2011

Fraudulent *.google.com SSL Certificate

A fraudulent SSL certificate was issued for the .google.com domain name from Diginotar, a Dutch Certificate Authority on July 10,2011. The articles referenced below provide background information and a time-line about the events.  

Of concern, is whether your browser is protected from spoofs, phishing attacks, or man-in-the-middle attacks from subdomains of google.com.

Internet Explorer

Microsoft issued Security Advisory (2607712): Fraudulent Digital Certificates Could Allow Spoofing, indicating that the precautionary step of removing the DigiNotar root certificate from the Microsoft Certificate Trust List.

All supported editions of Windows Vista, Windows 7, Windows Server 2008, and Windows Server 2008 R2 use the Microsoft Certificate Trust List to validate the trust of a certification authority.  Should you land on a website or attempt to install a program signed by the DigiNotar root certificate, you will receive an invalid certificate error.

A future update will be released to address this issue for all supported editions of Windows XP and Windows Server 2003.

Mozilla Firefox

The Mozilla Security Blog reported at Fraudulent *.google.com Certificate at Mozilla Security Blog that new versions of Firefox for desktop (3.6.21, 6.0.1, 7, 8, and 9) and mobile (6.0.1, 7, 8, and 9), Thunderbird (3.1.13, and 6.0.1) and SeaMonkey (2.3.2) will be released shortly that will revoke trust in the DigiNotar root.

Rather than waiting for the update, action can be taken now by following the instructions at Deleting the DigiNotar CA certificate.

Other Browsers

As reported in the Google Online Security Blog at An update on attempted man-in-the-middle attacks, steps were taken to disable the DigiNotar certificate authority in Chrome.  This was done while the investigations continues because it is not known if other fraudulent certificates were exist that have yet to be discovered.

Google Chrome is expected to be updated soon.  Chrome 13 and newer have legitimate Google certificates, hard-coded.

No official word has been issued regarding an update for either the Safari or Opera browser.

Background Articles

Computerworld: Hackers stole Google SSL certificate, Dutch firm admits
F-Secure: Diginotar Hacked by Black.Spook and Iranian Hackers
PC World: Google One of Many Victims in SSL Certificate Hack



Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...


Thursday, May 14, 2009

Google currently falls short

In a carefully documented report, Ben Edelman, a well known and respected security expert, reveals how Google and its partners
  • intercede to divert traffic that would have reached advertisers' sites directly -- without advertisers incurring any advertising expense.
  • pass the traffic back to the advertisers users were trying to reach -- but only after collecting pay-per-click advertising fees.
Also demonstrated is what appears to be conveniently overlooking Google's "Software Principles" requirements for their WhenU and IAC partners.

See how
  • WhenU Covers Advertisers' Sites with Advertisers' Own Google Ads
  • IAC's SmileyCentral Grab Advertisers' Organic Traffic to Show Google Ads
  • Typosquatting: Cmcast.com, MediaLogik, and Thousands More Intercept Users' Misspellings to Show Google Ads
  • Google Chrome Suggestions Divert Users from Direct Navigation to Search
in How Google and Its Partners Inflate Measured Conversion Rates and Inflate Advertisers' Costs.




Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Saturday, March 14, 2009

Privacy and Google Ads, Voice, Docs

Yesterday morning I was reading about Google's change to "interest-based advertising" when I received a message from a friend at WinVistaClub directing me to a Preston Gralla article at ComputerWorld about Google Voice. Then I came across an article at TechCrunch about "inadvertent" sharing of documents. Individually, these three topics are worth being concerned about. Taken in combination, one followiong the other, I find it quite disturbing.

Google Ads

Google has given in to their advertisers and announced "interest-based advertising". What is the difference between "interest-based advertising" and the ads you see now? With the current format of serving ads, if you are on a website reading about computer keyboard shortcuts, the ads presented will be targeted toward the key words on that page -- i.e., keyboards, mice or other computer-related products.

With interest-based advertising, the ads will be based on the types of sites you visit and the pages you view. For example, if you spend a lot of time on sports-related websites, you are likely to see ads for running shoes when investigating the purchase of a new refrigerator. In other words, the ads will be based on your browsing history.

As Google admits:
This kind of tailored advertising does raise questions about user choice and privacy — questions the whole online ad industry has a responsibility to answer.
As a result, in the Google Privacy Center, Advertising and Privacy, there is an Opt out option:


Edit Note: It appears that my security settings were such that I was unable to access the Opt Out links. Thanks to the comment posted by Microsoft MVP Donna Buenaventura and the information she provided at Calendar of Updates, I followed Donna's lead and as a result have accordingly edited this posting.

Only one minor problem. When I clicked the Opt out link, this is what happened each time I tried:

[Image Removed]

It didn't matter which browser I used.

[Image Removed]

There is also supposed to be the ability to edit the preferences that are associated with the cookie at the Ads Preferences Manager. That link does not work either.

Based on the inability of those opt-out options to work, do I really want to trust installing the browser plugin to permanently opt-out of the Double Click cookie?

Google Voice

Google Voice unifies your phone numbers, transcribes your voice mail, blocks telemarketers and allows you to archive and search all of the SMS text messages you send and receive and more. (Features: Google Voice).

As Marc Rotenberg indicated, with those features come other concerns.
"The service would allow Google, which already collects vast amounts of data about the behavior of Internet users, to gather information on their calling habits.

“It raises two distinct problems,” said Marc Rotenberg, executive director of the Electronic Privacy Information Center. “In the privacy world, it is increased profiling and tracking of users without safeguards. But the other problem is the growing consolidation of Internet-based services around one dominant company.”"

Google Docs

As reported at TechCrunch, Google sent a notice to a number of users of its Document and Spreadsheets products informing them that it may have inadvertently shared some of their documents with contacts who were never granted access to them. Reportedly the sharing was limited to people “with whom you, or a collaborator with sharing rights, had previously shared a document”.

TechCrunch reported that they were informed by Google that the error affected less than .05% of all documents. Is that .05% of one hundred documents or multiple millions of documents? Consider carefully what you share and who you share documents with.

References:


Remember - "A day without laughter is a day wasted."

May the wind sing to you and the sun rise in your heart...

Tuesday, December 02, 2008

Google Chrome Beta Security Update

Google Chrome Beta 0.4.154.29 update addresses the following security issue:
"Gears Cross-Origin Worker Vulnerability
CVE: CVE-2008-5258
A vulnerability in Gears could allow an attacker to run code in the context of a site that serves user-controlled files. To exploit this, an attacker needs to upload a malicious file to the victim's site and convince the user to allow the attacker's site to use Gears.

Severity: High. Even though this requires convincing users to allow a third-party site to use Gears, it could allow data theft and cross-site scripting on sites hosting user-created content, even those that do not use Gears.
Credit: Thanks to Yair Amit, Senior Security Researcher, IBM Rational Application Security Research Team for responsibly reporting the issue to Google."
Reminder: It is not advisable to use Beta software on production systems.

Reference:





Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Tuesday, November 25, 2008

Google Chrome Beta Update

Beta release: 0.4.154.25 includes feature and bug fixes as well as the following Security Update:

"Security Issues

  • This release fixes an issue with downloaded HTML files being able to read other files on your computer and send them to sites on the Internet. We now prevent local files from connecting to the network with XMLHttpRequest() and also prompt you to confirm a download if it is an HTML file.

Severity: Moderate. If a user could be enticed to open a downloaded HTML file, this flaw could be exploited to send arbitrary files to an attacker.
[Originally fixed in 154.18]"
Reminder: It is not advisable to use Beta software on production systems.




Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Thursday, October 30, 2008

Security Updates for Chrome and Opera

Google's Chrome Beta:

Beta release: 0.3.154.9

Included among various issues that were fixed in the Beta release, the following Security Update was included in the latest release:
"Security Update
  • This release fixes an issue with address spoofing in pop-ups. A site could convince a user to click a link to open a pop-up window. The window's address bar could be manipulated to show a different address than the actual origin of the content.
    Security rating: Medium. This flaw could be used to mislead people about the origin of a web site in order to get them to divulge sensitive information.
    Disclosed by: Liu Die Yu of the TopsecTianRongXin research lab."

Opera:

From Certified Bug, I see that Opera also has a security update, with Advisory 906, labeled "Extremely Severe" and Advisory 907 as "Highly Severe". If you use Opera, update to Version 9.62.










Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Monday, October 27, 2008

New Google Chrome (Beta) Browser Vulnerability

As reported in The Register, a "proof of concept" of new vulnerability has been reported for the Google Chrome (Beta) browser which allows attackers to impersonate websites of groups such as the Better Business Bureau, PayPal or even Google.

According to Google, the development version Dev Release: 0.3.154.6 addresses the vulnerability.

Reminder: Beta software should not be used in a production environment.

References:








Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Sunday, October 26, 2008

Cyber Security Awareness Tip of the Day: October 26

Do you "Google"? According to Security Garden blog analytics, over 90% of visitors who come here as a result of search results, arrived via Google search results. Such overwhelming results leads to the tip today being a two-for-one!

October 26 Tip(s) of the Day:

1) If you see a warning as illustrated below in Google search results, pay attention and, by all means, do not go there. Even if it is a site you have been too before and it was "perfectly safe" does not mean that it is now. It may be the site or the host server that has been infected.


Additional information is available in Malware? We don't need no stinking malware!

2) The second tip for today is to exercise caution with Google's "Sponsored Links" which can lead to malicious sites and infections. Microsoft MVP Mike Burgess demonstrates what he regularly finding in Is Security overwhelmed by Malware?


References
:








Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Saturday, October 11, 2008

Google Open to Frame Injection Attack

Wayne Porter's Google Open to Frame Injection Attack leads to an interesting report by Aviv Raff of his discovery over six months ago -- a discovery reported to Google, yet still without response other than they're looking into it:

"You all learned about the value of sharing. When I was a kid my mother taught me that I should share my stuff with my friends. Unfortunately, sharing is not always a good thing. Especially, when talking about sharing web-applications across domains.

Over six months ago I've discovered an interesting, yet troubling, issue - Google.com suffers from a cross-domain web-application sharing security design flaw. There are several Google web applications which are accessible over multiple google.com subdomains. The following are some of those web-applications and subdomains:

  • Google Maps (maps.google.com)
  • Google Mail (mail.google.com)
  • Google Images (images.google.com)
  • Google News (news.google.com)
  • Google.com (Google Search, Google Accounts, Google Apps, Google History, etc.)"

Following the Proof of Concept by Adrian Pastor and no further response from the Google security team, the decision was made to publish the findings.

References:

Frame Injection Fun
Frame Injection Vulnerabilities
Google Open to Frame Injection Attack
Sharing is not always a good thing









Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Friday, September 19, 2008

Google Chrome Beta Update

Unfortunately, the Google Chrome home page does not provide any information regarding the development and changes to the beta browser. Although rather slow to provide update information for their own product, there is a Google-sponsored blog that provides announcements and release notes for the browser.

Beta 0.2.149.30 was released September 17, but the update notice was not made until yesterday afternoon:
"Google Chrome version 0.2.149.30 was released on 17 September 2008. Users will get automatic updates over the next few days.

Security Updates

  • [r2042] Fix a potential denial of service with very long title attributes on tags. The title attribute sets the tooltip text when you hover the mouse over an element.
    Security Rating: Low risk. This can lead to 100% CPU usage or a tab crash.
    More information: http://www.securityfocus.com/bid/30975"
For some reason, Google does not consider changes such as " [r1927] Stop adding content from HTTPS sites to the searchable index" and " [r1978] Don't send sensitive URLs to search suggest services" as security updates but rather categorizes them in the list of "Other Changes".

Although the changes issued in this update are important for anyone using the beta product, if another vendor automatically pushed out software updates without providing the option to review, accept or reject the changes, the users of that software would be up in arms. Where is the uproar surrounding Google's manner of issuing and classifying updates?

Again, this reminder: Beta software should never be used in a production environment.




Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Tuesday, September 09, 2008

Google Chrome Beta Updated

Google Chrome Beta issued a security update -- in fact, if people who downloaded the beta browser didn't manually update, the update was automatically pushed and installed! From Beta release: 0.2.149.29:
"Google Chrome version 0.2.149.29 was released on 5 September 2008, and all users are being automatically updated. Automatic updates are a key security feature in helping to ensure the safety of Google Chrome users."
I know a lot of people who prefer to wait until a security update has been out for a few days before installing. This lack of control over what could be installed on my computer is yet one more reason why I do not intend to use the Google Chrome browser. Although I am prompt installing software security updates, it is my computer. Prior to installing, I review the updates and choose the time for installation.

Reminder: Beta software should never be used in a production environment. Although I have quoted SpyDie's definition of Beta before, but once again . . .

Beta as defined by SpyDie:
Software undergoes beta testing shortly before it's released.
Beta is Latin for 'still doesn't work.'

You can review the vulnerabilities and bugs reported fixed in the update to Google Chrome Beta at Beta release: 0.2.149.29.



Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Wednesday, September 03, 2008

Google Chrome

Thanks, but no thanks. I'm quite happy with the browsers I have right now, particularly in view of the CNET article, "Be sure to read Chrome's fine print" which you really need to read for yourself.

After seeing the CNET article regarding the EULA (end user license agreement), I learned about two security issues posted at SecurityTeam.com. I understand this is beta software and hope that people who trust Google recognize the difference between beta and production.

From Google Chrome Browser Automatic File Download,3 Sep. 2008:
"Summary
Google's new Web browser (Chrome) allows files (e.g., executables) to be automatically downloaded to the user's computer without any user prompt.

Credit:
The information has been provided by nerex.
The original article can be found at: http://www.milw0rm.com/exploits/6355

and from Google Chrome Browser URL Handler Crash, 3 Sep. 2008:

"Summary
An issue exists in how chrome behaves with undefined-handlers in chrome.dll version 0.2.149.27. A crash can result without user interaction. When a user is made to visit a malicious link, which has an undefined handler followed by a 'special' character, the chrome crashes with a Google Chrome message window "Whoa! Google Chrome has crashed. Restart now?". It crashes on "int 3" at 0x01002FF3 as an exception/trap, followed by "POP EBP" instruction when pointed out by the EIP register at 0x01002FF4.

Credit:
The information has been provided by Rishi Narang.
The original article can be found at: http://evilfingers.com/advisory/google_chrome_poc.php




Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Thursday, December 28, 2006

Got Google Email? Update Firefox!

It has been reported that the problem that resulted in the 60 or so Google email users to lose all email and contacts in their Gmail accounts was a flaw in Firefox 2.0.0.0.

The update to Firefox 2.0.0.1 is available at Firefox. The update included a fixes for a number of vulnerabilities, making it a wise move to update, regardless of the Gmail problem.

See Garett Rogers report, Some Gmail accounts were cleaned out.


Friday, December 15, 2006

Google Patent Search

(Click the image to open site in a new tab/window)


Spotted this addition to Google's latest search "portfolio" over at SunbeltBLOG. Having worked with people in the Patent area for many years, I am sure they will find this interesting.

By the way, Patent Friends, Garett Rogers at ZD Net would like to know if Google Patents will make the job easier for patent lawyers. Apparently he doesn't realize that (1) the patent lawyers rely on someone else to obtain the patent copies and (2) there has been services for obtaining patent copies for many years, some free while others are fee-based.

One nice feature I observed is that it is easy to copy/paste the text from the patents in Google Patent. That will at least make it easier when quoting portions of patents the "Description of the Prior Art".

This is what a friend who has "been in the business" for many years had to say about Google Patent:
"Interesting. Nice search page. Nothing "new and improved" though."
It doesn't sound as though Google should bother running to the USPTO with this feature.