Feeds

Google finally fixes Desktop security vuln

Staff: 'Gone phishing'

  • alert
  • submit to reddit

New hybrid storage solutions

The first flaw in Google's Desktop Search product has been discovered, and now fixed, according to the giant ad broker. The JavaScript vulnerability allowed third party websites to view the results of searches made on your local hard drive. It took Google four days to address the problem, and according to the Javascript expert who raised the alarm, it still hasn't been adequately patched.

Software developer Jim Ley, who maintains the comp.lang.javascript FAQ, announced the flaw on Monday on his weblog. But nobody noticed. Ley's email message to security@google.com bounced. He looked in vain for a security hotline number.

On Tuesday he demonstrated an ingenious potential application of the bug: a phishing exploit that announced that Google was becoming a subscription service, and invited the victim to enter their credit card details. Still no response.

Google finally sat up and took notice after the vulnerability was posted on the Security Focus BugTraq mailing list. Google couldn't explain why it didn't have a working email or phone contact for security alerts, but according to Jim, seemed anxious that he remove the phishing example.

In fact as he points out, the vulnerability is over two years old.

"Hopefully Google will get in touch explain what went wrong with the communication of the issue, hopefully Google will realise that a phone number of the security team on the web would also help," he writes.

"The fix they put in place is still flawed, it relies on special casing the vbscript, javascript and perlscript strings, meaning other language protocols are still at risk in IE with its multiple scripting language capability."

It's good to know Google takes security as seriously as it takes privacy. ®

Related Links

Jim's weblog
Bugtraq alert

Related stories

Gates: PC will replace TV, TV will become a giant Google
Talented flunkeys unite against phishing
Google Desktop privacy branded 'unacceptable'
Google's Gmail: spook heaven?
Google's Ethics Committee revealed
Google decides banner ads, skyscrapers are not evil
Google values its own privacy. How does it value yours?
Google revives discredited Microsoft privacy policy for Friendster clone

Secure remote control for conventional and virtual desktops

More from The Register

next story
Leak of '5 MEELLLION Gmail passwords' creates security flap
You should be OK if you're not using ANCIENT password
Google recommends pronounceable passwords
Super Chrome goes into battle with Mr Mxyzptlk
Reddit wipes clean leaked celeb nudie pics, tells users to zip it
Now we've had all THAT TRAFFIC, we 'deplore' this theft
Enigmail PGP plugin forgets to encrypt mail sent as blind copies
User now 'waiting for the bad guys come and get me with their water-boards'
YouTube, Amazon and Yahoo! caught in malvertising mess
Cisco says 'Kyle and Stan' attack is spreading through compromised ad networks
prev story

Whitepapers

Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.