Feeds

Google: Our rapid load won't give you anything nasty

You could get exploited without even saying yes

Providing a secure and efficient Helpdesk

Google has downplayed concerns that refinements to its search technology could leave surfers more exposed to search engine manipulation attacks.

Google Inside Search aims to speed up web searches by pre-loading content from remote sites. The so-called Instant Pages technology only works with Google Chrome.

Miscreants often manipulate search engine results so that links to scareware portals and the like appear prominently in search results for newsworthy terms. These search engine poisoning tactics rely on establishing link farms after hacking into portions of popular websites, using search engines’ “sponsored” links to reference malicious sites and injecting HTML code, among other tricks.

Scareware affiliates normally rely on potential victims to click on links to malicious sites among search results before they are whisked away towards dangerous domains. However, the Instant Pages technology might remove this requirement, pre-fetching content from malicious websites and "creating a possibility that a user can be exploited by simply searching, without even clicking on a link," warns Dan Hubbard of Websense Security Labs.

Google maintains that is being careful to minimise the possibility of harmful content getting pre-fetched.

"We've thought hard about this issue, and we don't believe there is any additional risk to users," a Google spokesman explained.

"Sites marked as potentially harmful by our Safe Browsing technology will not be pre-rendered, nor will sites that Chrome detects as suspicious. We also exclude sites with SSL certificate issues and those that try to download files or display popup alerts."

Google added that search engine poisoning to promote scareware sites and the like is an industry-wide problem. ®

Choosing a cloud hosting partner with confidence

More from The Register

next story
SMASH the Bash bug! Apple and Red Hat scramble for patch batches
'Applying multiple security updates is extremely difficult'
Shellshock: 'Larger scale attack' on its way, warn securo-bods
Not just web servers under threat - though TENS of THOUSANDS have been hit
Apple's new iPhone 6 vulnerable to last year's TouchID fingerprint hack
But unsophisticated thieves need not attempt this trick
PEAK IPV4? Global IPv6 traffic is growing, DDoS dying, says Akamai
First time the cache network has seen drop in use of 32-bit-wide IP addresses
Oracle SHELLSHOCKER - data titan lists unpatchables
Database kingpin lists 32 products that can't be patched (yet) as GNU fixes second vuln
Who.is does the Harlem Shake
Blame it on LOLing XSS terroristas
Researchers tell black hats: 'YOU'RE SOOO PREDICTABLE'
Want to register that domain? We're way ahead of you.
prev story

Whitepapers

A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Beginner's guide to SSL certificates
De-mystify the technology involved and give you the information you need to make the best decision when considering your online security options.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.