Feeds

Google finally fixes Desktop security vuln

Staff: 'Gone phishing'

  • alert
  • submit to reddit

Secure remote control for conventional and virtual desktops

The first flaw in Google's Desktop Search product has been discovered, and now fixed, according to the giant ad broker. The JavaScript vulnerability allowed third party websites to view the results of searches made on your local hard drive. It took Google four days to address the problem, and according to the Javascript expert who raised the alarm, it still hasn't been adequately patched.

Software developer Jim Ley, who maintains the comp.lang.javascript FAQ, announced the flaw on Monday on his weblog. But nobody noticed. Ley's email message to security@google.com bounced. He looked in vain for a security hotline number.

On Tuesday he demonstrated an ingenious potential application of the bug: a phishing exploit that announced that Google was becoming a subscription service, and invited the victim to enter their credit card details. Still no response.

Google finally sat up and took notice after the vulnerability was posted on the Security Focus BugTraq mailing list. Google couldn't explain why it didn't have a working email or phone contact for security alerts, but according to Jim, seemed anxious that he remove the phishing example.

In fact as he points out, the vulnerability is over two years old.

"Hopefully Google will get in touch explain what went wrong with the communication of the issue, hopefully Google will realise that a phone number of the security team on the web would also help," he writes.

"The fix they put in place is still flawed, it relies on special casing the vbscript, javascript and perlscript strings, meaning other language protocols are still at risk in IE with its multiple scripting language capability."

It's good to know Google takes security as seriously as it takes privacy. ®

Related Links

Jim's weblog
Bugtraq alert

Related stories

Gates: PC will replace TV, TV will become a giant Google
Talented flunkeys unite against phishing
Google Desktop privacy branded 'unacceptable'
Google's Gmail: spook heaven?
Google's Ethics Committee revealed
Google decides banner ads, skyscrapers are not evil
Google values its own privacy. How does it value yours?
Google revives discredited Microsoft privacy policy for Friendster clone

Beginner's guide to SSL certificates

More from The Register

next story
Webcam hacker pervs in MASS HOME INVASION
You thought you were all alone? Nope – change your password, says ICO
You really need to do some tech support for Aunty Agnes
Free anti-virus software, expires, stops updating and p0wns the world
Meet OneRNG: a fully-open entropy generator for a paranoid age
Kiwis to seek random investors for crowd-funded randomiser
USB coding anarchy: Consider all sticks licked
Thumb drive design ruled by almighty buck
Attack reveals 81 percent of Tor users but admins call for calm
Cisco Netflow a handy tool for cheapskate attackers
Patch NOW! Microsoft slings emergency bug fix at Windows admins
Vulnerability promotes lusers to domain overlords ... oops
prev story

Whitepapers

Choosing cloud Backup services
Demystify how you can address your data protection needs in your small- to medium-sized business and select the best online backup service to meet your needs.
Getting started with customer-focused identity management
Learn why identity is a fundamental requirement to digital growth, and how without it there is no way to identify and engage customers in a meaningful way.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Internet Security Threat Report 2014
An overview and analysis of the year in global threat activity: identify, analyze, and provide commentary on emerging trends in the dynamic threat landscape.
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.