«  Pew study: Web search growing MORE important fast Main Does "Google Insights" reveal anything important?  »


InformationWeek


Google Gets Raked Over The Coals At Black Hat

Posted by Thomas Claburn, Aug 6, 2008 10:57 PM

Robert "RSnake" Hansen, CEO of SecTheory, and Tom Stracener, senior security analyst at Cenzic, had some harsh words for Google at their Black Hat presentation, "Xploiting Google Gadgets."

"Google cares more about tracking users than they do about consumer safety," said Hansen.

Hansen said that four years ago, he found a Web redirection vulnerability that was being actively used by phishers. He alerted Google, eBay, DoubleClick, and Visa. Visa closed the hole in hours. DoubleClick had a partial fix in place in days. It took eBay several weeks to fix the problem. But Google still hasn't fixed all the vulnerabilities.

Google and Hansen aren't on the best of terms. According to Hansen, Google threatened to take legal action for claiming that Google was a phishing site. And he said that someone from Google disparaged a previous critique of the company's security in a comment post that didn't identify the affiliation of the person commenting -- Hansen said the post showed an internal Google IP address.

Hansen recounted his contentious history with Google to provide some context to the vulnerabilities in Google Gadgets.

Google declined to comment about Google Gadget security when asked about it two weeks ago. When Hansen asked if anyone from Google was in the audience and was answered in the affirmative, he invited the unidentified Google employee to respond but was rebuffed. (It's hard to blame the Google employee for not wanting to take the bait.)

Google appears not to take the issue too seriously. To demonstrate that, Stracener showed a screenshot of an input form for Google Gadget creation that includes a "Do Evil" checkbox, an obvious attempt to make light of Google's unofficial motto, "Don't be evil."

The problem Google faces is that it doesn't have a way to make sure that Gadgets don't include malicious content. ...

arrow

Post a comment

We had to crank up the spam filter so it may take a little while to appear. Thanks.

(If you haven't left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won't appear on the entry. Thanks for waiting.)

A book in progress by

Siva Vaidhyanathan

Siva Vaidhyanathan

This blog, the result of a collaboration between myself and the Institute for the Future of the Book, is dedicated to exploring the process of writing a critical interpretation of the actions and intentions behind the cultural behemoth that is Google, Inc. The book will answer three key questions: What does the world look like through the lens of Google?; How is Google's ubiquity affecting the production and dissemination of knowledge?; and how has the corporation altered the rules and practices that govern other companies, institutions, and states? [more]

» Send links, questions and ideas:
siva [at] googlizationofeverything [dot] com

» To reach me for a press query, please write to SIVAMEDIA ut POBOX dut COM

» To reach me for a speaking invitation, please write to SIVASPEAK ut POBOX dut COM

» Visit my main blog: SIVACRACY.NET

» More about me

Topics

Like the Mind of God (57 posts)

All the World's Information (75 posts)

What If Big Ads Don't Work (20 posts)

Don't Be Evil (16 posts)

Is Google a Library? (84 posts)

Challenging Big Media (46 posts)

The Dossier (49 posts)

Global Google (26 posts)

Google Earth (6 posts)

A Public Utility? (37 posts)

About this Book (28 posts)

RSS Feed icon  RSS Feed


Powered by Movable Type 3.35