<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" gd:etag="W/&quot;DU4DRX4_fip7ImA9WhRUFk0.&quot;"><id>tag:blogger.com,1999:blog-1176949257541686127</id><updated>2012-01-26T11:59:34.046-08:00</updated><title type="text">Google Online Security Blog</title><subtitle type="html">The latest news and insights from Google on security and safety on the Internet.</subtitle><link rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" href="http://googleonlinesecurity.blogspot.com/feeds/posts/default" /><link rel="alternate" type="text/html" href="http://googleonlinesecurity.blogspot.com/" /><link rel="next" type="application/atom+xml" href="http://www.blogger.com/feeds/1176949257541686127/posts/default?start-index=26&amp;max-results=25&amp;redirect=false&amp;v=2" /><author><name>Molly Graham</name><uri>http://www.blogger.com/profile/14622034276288473028</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><generator version="7.00" uri="http://www.blogger.com">Blogger</generator><openSearch:totalResults>76</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://feeds.feedburner.com/GoogleOnlineSecurityBlog" /><feedburner:info uri="googleonlinesecurityblog" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><entry gd:etag="W/&quot;CUIDRXw8cCp7ImA9WhRVGE8.&quot;"><id>tag:blogger.com,1999:blog-1176949257541686127.post-3139438300671009235</id><published>2012-01-16T22:37:00.000-08:00</published><updated>2012-01-17T10:06:14.278-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-01-17T10:06:14.278-08:00</app:edited><title>Tech tips that are Good to Know</title><content type="html">&lt;span class="byline-author"&gt;Posted by Alma Whitten, Director of Privacy, Product and Engineering&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;i&gt;(Cross-posted from the &lt;a href="http://googleblog.blogspot.com/2012/01/tech-tips-that-are-good-to-know.html"&gt;Official Google Blog&lt;/a&gt;)&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;Does this person sound familiar? He can’t be bothered to type a password into his phone every time he wants to play a game of Angry Birds. When he does need a password, maybe for his email or bank website, he chooses one that’s easy to remember like his sister’s name—and he uses the same one for each website he visits. For him, cookies come from the bakery, IP addresses are the locations of Intellectual Property and a correct Google search result is basically magic.&lt;br /&gt;&lt;br /&gt;Most of us know someone like this. Technology can be confusing, and the industry often fails to explain clearly enough why digital literacy matters. So today in the U.S. we’re kicking off &lt;a href="http://google.com/goodtoknow"&gt;Good to Know&lt;/a&gt;, our biggest-ever consumer education campaign focused on making the web a safer, more comfortable place. Our ad campaign, which we introduced in the U.K. and Germany last fall, offers privacy and security tips: Use &lt;a href="http://www.google.com/goodtoknow/online-safety/security-tools/"&gt;2-step verification&lt;/a&gt;! Remember to lock your computer when you step away! Make sure your connection to a website is &lt;a href="http://www.google.com/goodtoknow/online-safety/secure-sites/"&gt;secure&lt;/a&gt;! It also &lt;a href="http://www.google.com/goodtoknow/data-on-the-web/"&gt;explains&lt;/a&gt; some of the building blocks of the web like cookies and IP addresses. Keep an eye out for the ads in newspapers and magazines, online and in New York and Washington, D.C. subway stations.&lt;br /&gt;&lt;br /&gt;&lt;embed flashvars="host=picasaweb.google.com&amp;amp;hl=en_US&amp;amp;feat=flashalbum&amp;amp;RGB=0x000000&amp;amp;feed=https%3A%2F%2Fpicasaweb.google.com%2Fdata%2Ffeed%2Fapi%2Fuser%2F116887554964117158278%2Falbumid%2F5698403762820753729%3Falt%3Drss%26kind%3Dphoto%26authkey%3DGv1sRgCKWdqPvJqo2aHg%26hl%3Den_US" height="334" pluginspage="http://www.macromedia.com/go/getflashplayer" src="https://picasaweb.google.com/s/c/bin/slideshow.swf" type="application/x-shockwave-flash" width="500"&gt;&lt;/embed&gt;&lt;br /&gt;&lt;br /&gt;The campaign and &lt;a href="http://www.google.com/goodtoknow"&gt;Good to Know website&lt;/a&gt; build on our commitment to keeping people safe online. We’ve created resources like &lt;a href="http://youtube.com/googleprivacy"&gt;privacy videos&lt;/a&gt;, the &lt;a href="http://www.google.com/security/"&gt;Google Security Center&lt;/a&gt;, the &lt;a href="http://www.google.com/familysafety/"&gt;Family Safety Center&lt;/a&gt; and &lt;a href="http://www.teachparentstech.org/"&gt;Teach Parents Tech&lt;/a&gt; to help you develop strong privacy and security habits. We design for privacy, building tools like &lt;a href="http://google.com/dashboard"&gt;Google Dashboard&lt;/a&gt;, &lt;a href="http://googlepublicpolicy.blogspot.com/2011/06/me-myself-and-i-helping-to-manage-your.html"&gt;Me on the Web&lt;/a&gt;, the &lt;a href="http://www.google.com/ads/preferences"&gt;Ads Preferences Manager&lt;/a&gt; and &lt;a href="http://www.youtube.com/watch?v=BeMZP-oyOII"&gt;Google+ Circles&lt;/a&gt;—with more on the way.&lt;br /&gt;&lt;br /&gt;We encourage you to take a few minutes to check out the &lt;a href="http://www.google.com/goodtoknow"&gt;Good to Know site&lt;/a&gt;, watch &lt;a href="http://www.youtube.com/watch?v=qjxDrmAaZIs&amp;amp;feature=endscreen&amp;amp;NR=1"&gt;some&lt;/a&gt; &lt;a href="http://www.youtube.com/watch?v=tz0FEnve_rs&amp;amp;feature=relmfu"&gt;of&lt;/a&gt; &lt;a href="http://www.youtube.com/watch?v=U4FLL0TL6_4&amp;amp;feature=relmfu"&gt;the&lt;/a&gt; &lt;a href="http://www.youtube.com/watch?v=A5wR9eEbHoY&amp;amp;feature=relmfu"&gt;videos&lt;/a&gt;, and be on the lookout for ads in your favorite newspaper or website. We hope you’ll learn something new about how to protect yourself online—tips that are always good to know!&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;&lt;b&gt;Update&lt;/b&gt; 1/17&lt;/i&gt;: Updated to include more background on Good to Know.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1176949257541686127-3139438300671009235?l=googleonlinesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?a=QW0ETABR7Rs:Agn_28nN0WM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?a=QW0ETABR7Rs:Agn_28nN0WM:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?i=QW0ETABR7Rs:Agn_28nN0WM:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/GoogleOnlineSecurityBlog/~4/QW0ETABR7Rs" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://googleonlinesecurity.blogspot.com/feeds/3139438300671009235/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=1176949257541686127&amp;postID=3139438300671009235&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1176949257541686127/posts/default/3139438300671009235?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/1176949257541686127/posts/default/3139438300671009235?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/GoogleOnlineSecurityBlog/~3/QW0ETABR7Rs/tech-tips-that-are-good-to-know.html" title="Tech tips that are Good to Know" /><author><name>Jay</name><uri>http://www.blogger.com/profile/08177113963774105206</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://googleonlinesecurity.blogspot.com/2012/01/tech-tips-that-are-good-to-know.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEQFSHk_eCp7ImA9WhRRF0s.&quot;"><id>tag:blogger.com,1999:blog-1176949257541686127.post-1226806321887732434</id><published>2011-12-01T11:05:00.000-08:00</published><updated>2011-12-01T11:05:19.740-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-01T11:05:19.740-08:00</app:edited><title>Expanding Safe Browsing Alerts to include malware distribution domains</title><content type="html">&lt;span class="byline-author"&gt;Posted by Nav Jagpal, Security Team&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;For the past year, we’ve been sending notifications to network administrators registered through the &lt;a href="http://googleonlinesecurity.blogspot.com/2010/09/safe-browsing-alerts-for-network.html"&gt;Safe Browsing Alerts for Network Administrators&lt;/a&gt; service when our automated tools find phishing URLs or compromised sites that lead to malware on their networks. These notifications provide administrators with important information to help them improve the security of their networks.&lt;br /&gt;&lt;br /&gt;Today we’re adding distribution domains to the set of information we share. These are domains that are responsible for launching exploits and serving malware. Unlike compromised sites, which are often run by innocent webmasters, distribution domains are set up with the primary purpose of serving malicious content.&lt;br /&gt;&lt;br /&gt;If you’re a network administrator and haven’t yet registered your AS, you can do so &lt;a href="http://www.google.com/safebrowsing/alerts/"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1176949257541686127-1226806321887732434?l=googleonlinesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?a=ZO2GWcXBdS0:upMx-wdQYMI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?a=ZO2GWcXBdS0:upMx-wdQYMI:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?i=ZO2GWcXBdS0:upMx-wdQYMI:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/GoogleOnlineSecurityBlog/~4/ZO2GWcXBdS0" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://googleonlinesecurity.blogspot.com/feeds/1226806321887732434/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=1176949257541686127&amp;postID=1226806321887732434&amp;isPopup=true" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1176949257541686127/posts/default/1226806321887732434?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/1176949257541686127/posts/default/1226806321887732434?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/GoogleOnlineSecurityBlog/~3/ZO2GWcXBdS0/expanding-safe-browsing-alerts-to.html" title="Expanding Safe Browsing Alerts to include malware distribution domains" /><author><name>Jay</name><uri>http://www.blogger.com/profile/08177113963774105206</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>1</thr:total><feedburner:origLink>http://googleonlinesecurity.blogspot.com/2011/12/expanding-safe-browsing-alerts-to.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkAMQXoyfCp7ImA9WhRSGUQ.&quot;"><id>tag:blogger.com,1999:blog-1176949257541686127.post-1505127665693931147</id><published>2011-11-22T12:46:00.000-08:00</published><updated>2011-11-22T12:46:20.494-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-11-22T12:46:20.494-08:00</app:edited><title>Reminder: Safe Browsing version 1 API turning down December 1</title><content type="html">&lt;span class="byline-author"&gt;Posted by Brian Ryner, Security Team&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;In May we &lt;a href="http://googleonlinesecurity.blogspot.com/2011/05/safe-browsing-protocol-v2-transition.html"&gt;announced&lt;/a&gt; that we are ending support for the Safe Browsing protocol version 1 on December 1 in order to focus our resources on the &lt;a href="http://code.google.com/apis/safebrowsing/developers_guide_v2.html"&gt;new version 2 API&lt;/a&gt; and the &lt;a href="http://code.google.com/apis/safebrowsing/lookup_guide.html"&gt;lookup service&lt;/a&gt;. These new APIs provide simpler and more efficient access to the same data, and they use significantly less bandwidth. If you haven't yet migrated off of the version 1 API, we encourage you to do so as soon as possible. Our &lt;a href="http://googleonlinesecurity.blogspot.com/2011/05/safe-browsing-protocol-v2-transition.html"&gt;earlier post&lt;/a&gt; contains links to documentation for the new protocol version and other resources to help you make the transition smoothly.&lt;br /&gt;&lt;br /&gt;After December 1, we will remove all data from the version 1 API list to ensure that any remaining clients do not have false positives in their database. After January 1, 2012, we will turn off the version 1 service completely, and all requests will return a 404 error.&lt;br /&gt;&lt;br /&gt;Thanks for your cooperation, and enjoy using the next generation of Safe Browsing.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1176949257541686127-1505127665693931147?l=googleonlinesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?a=4AnmnqAYBvs:NxHyfWWx19s:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?a=4AnmnqAYBvs:NxHyfWWx19s:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?i=4AnmnqAYBvs:NxHyfWWx19s:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/GoogleOnlineSecurityBlog/~4/4AnmnqAYBvs" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://googleonlinesecurity.blogspot.com/feeds/1505127665693931147/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=1176949257541686127&amp;postID=1505127665693931147&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1176949257541686127/posts/default/1505127665693931147?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/1176949257541686127/posts/default/1505127665693931147?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/GoogleOnlineSecurityBlog/~3/4AnmnqAYBvs/reminder-safe-browsing-version-1-api.html" title="Reminder: Safe Browsing version 1 API turning down December 1" /><author><name>Jay</name><uri>http://www.blogger.com/profile/08177113963774105206</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://googleonlinesecurity.blogspot.com/2011/11/reminder-safe-browsing-version-1-api.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DE4CRns5fip7ImA9WhRSGUU.&quot;"><id>tag:blogger.com,1999:blog-1176949257541686127.post-1552631326272284679</id><published>2011-11-22T10:35:00.000-08:00</published><updated>2011-11-22T10:36:07.526-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-11-22T10:36:07.526-08:00</app:edited><title>Protecting data for the long term with forward secrecy</title><content type="html">&lt;span class="byline-author"&gt;Posted by Adam Langley, Security Team&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Last year we introduced &lt;a href="http://gmailblog.blogspot.com/2010/01/default-https-access-for-gmail.html"&gt;HTTPS by default for Gmail&lt;/a&gt; and &lt;a href="http://googleblog.blogspot.com/2010/05/search-more-securely-with-encrypted.html"&gt;encrypted search&lt;/a&gt;. We’re pleased to see that other major communications sites are following suit and deploying HTTPS in one form or another. We are now pushing forward by enabling &lt;a href="http://en.wikipedia.org/wiki/Perfect_forward_secrecy"&gt;forward secrecy&lt;/a&gt; by default.&lt;br /&gt;&lt;br /&gt;Most major sites supporting HTTPS operate in a non-forward secret fashion, which runs the risk of retrospective decryption. In other words, an encrypted, unreadable email could be recorded while being delivered to your computer today. In ten years time, when computers are much faster, an adversary could break the server private key and retrospectively decrypt today’s email traffic.&lt;br /&gt;&lt;br /&gt;Forward secrecy requires that the private keys for a connection are not kept in persistent storage. An adversary that breaks a single key will no longer be able to decrypt months’ worth of connections; in fact, not even the server operator will be able to retroactively decrypt HTTPS sessions.&lt;br /&gt;&lt;br /&gt;Forward secret HTTPS is now live for Gmail and many other Google HTTPS services(*), like SSL Search, Docs and Google+. We have also &lt;a href="http://cvs.openssl.org/fileview?f=openssl/CHANGES&amp;amp;v=1.1481.2.56.2.57"&gt;released the work&lt;/a&gt; that we did on the open source OpenSSL library that made this possible. You can check whether you have forward secret connections in Chrome by clicking on the green padlock in the address bar of HTTPS sites. Google’s forward secret connections will have a key exchange mechanism of ECDHE_RSA.&lt;br /&gt;&lt;br /&gt;We would very much like to see forward secrecy become the norm and hope that our deployment serves as a demonstration of the practicality of that vision.&lt;br /&gt;&lt;br /&gt;&lt;img src="http://2.bp.blogspot.com/-20_ugsK-IWE/TsvjjV1HeEI/AAAAAAAABB0/po9E_RCeEns/s400/ecdhe.png" border="0" alt="" id="BLOGGER_PHOTO_ID_5677881951525500994" style="display: block; margin-top: 0px; margin-right: auto; margin-bottom: 10px; margin-left: auto; text-align: center; cursor: pointer; width: 400px; height: 270px; " /&gt;&lt;br /&gt;(* Chrome, Firefox (all platforms) and Internet Explorer (Vista or later) support forward secrecy using elliptic curve Diffie-Hellman. Initially, only Chrome and Firefox will use it by default with Google services because IE doesn’t support the combination of ECDHE and RC4. We hope to support IE in the future.)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1176949257541686127-1552631326272284679?l=googleonlinesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?a=yn00boLnfaQ:D3evdwOWV_8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?a=yn00boLnfaQ:D3evdwOWV_8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?i=yn00boLnfaQ:D3evdwOWV_8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/GoogleOnlineSecurityBlog/~4/yn00boLnfaQ" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://googleonlinesecurity.blogspot.com/feeds/1552631326272284679/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=1176949257541686127&amp;postID=1552631326272284679&amp;isPopup=true" title="11 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1176949257541686127/posts/default/1552631326272284679?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/1176949257541686127/posts/default/1552631326272284679?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/GoogleOnlineSecurityBlog/~3/yn00boLnfaQ/protecting-data-for-long-term-with.html" title="Protecting data for the long term with forward secrecy" /><author><name>Jay</name><uri>http://www.blogger.com/profile/08177113963774105206</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-20_ugsK-IWE/TsvjjV1HeEI/AAAAAAAABB0/po9E_RCeEns/s72-c/ecdhe.png" height="72" width="72" /><thr:total>11</thr:total><feedburner:origLink>http://googleonlinesecurity.blogspot.com/2011/11/protecting-data-for-long-term-with.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CkcCQHc6fyp7ImA9WhdUGU8.&quot;"><id>tag:blogger.com,1999:blog-1176949257541686127.post-588724102287335204</id><published>2011-10-06T09:54:00.000-07:00</published><updated>2011-10-06T09:54:21.917-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-10-06T09:54:21.917-07:00</app:edited><title>Safe Browsing Alerts for Network Administrators is graduating from Labs</title><content type="html">&lt;span class="byline-author"&gt;Posted by Nav Jagpal, Security Team&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
Today, we’re congratulating Safe Browsing Alerts for Network Administrators on its graduation from Labs to its new home at &lt;a href="http://www.google.com/safebrowsing/alerts/"&gt;http://www.google.com/safebrowsing/alerts/&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
We &lt;a href="http://googleonlinesecurity.blogspot.com/2010/09/safe-browsing-alerts-for-network.html"&gt;announced&lt;/a&gt; the tool about a year ago and have received a lot of positive feedback. Network administrators, large and small, are using the information we provide about malware and phishing URLs to clean up their networks and help webmasters make their sites safer. Earlier this year, &lt;a href="http://searchsecurity.techtarget.com.au/news/2240035959/Winners-at-the-AusCERT-2011-awards-night"&gt;AusCert recognized our efforts&lt;/a&gt; by awarding Safe Browsing Alerts for Network Administrators the title of “Best Security Initiative.” &lt;br /&gt;
&lt;br /&gt;
If you’re a network administrator and haven’t yet registered your AS, you can do so &lt;a href="http://www.google.com/safebrowsing/alerts/"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1176949257541686127-588724102287335204?l=googleonlinesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?a=dLJL4-pFLek:On3DBidOoI4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?a=dLJL4-pFLek:On3DBidOoI4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?i=dLJL4-pFLek:On3DBidOoI4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/GoogleOnlineSecurityBlog/~4/dLJL4-pFLek" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://googleonlinesecurity.blogspot.com/feeds/588724102287335204/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=1176949257541686127&amp;postID=588724102287335204&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1176949257541686127/posts/default/588724102287335204?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/1176949257541686127/posts/default/588724102287335204?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/GoogleOnlineSecurityBlog/~3/dLJL4-pFLek/safe-browsing-alerts-for-network.html" title="Safe Browsing Alerts for Network Administrators is graduating from Labs" /><author><name>Panayiotis Mavrommatis</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://googleonlinesecurity.blogspot.com/2011/10/safe-browsing-alerts-for-network.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0QNQXc9eSp7ImA9WhdWFU8.&quot;"><id>tag:blogger.com,1999:blog-1176949257541686127.post-2450884721254666605</id><published>2011-09-08T17:49:00.000-07:00</published><updated>2011-09-08T17:49:50.961-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-09-08T17:49:50.961-07:00</app:edited><title>Gmail account security in Iran</title><content type="html">&lt;span class="byline-author"&gt;Posted by Eric Grosse, VP Security Engineering&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;We &lt;a href="http://googleonlinesecurity.blogspot.com/2011/08/update-on-attempted-man-in-middle.html"&gt;learned last week&lt;/a&gt; that the compromise of a Dutch company involved with verifying the authenticity of websites could have put the Internet communications of many Iranians at risk, including their Gmail. While Google’s internal systems were not compromised, we are directly contacting possibly affected users and providing similar information below because our top priority is to protect the privacy and security of our users.&lt;br /&gt;&lt;br /&gt;While users of the Chrome browser were protected from this threat, we advise all users in Iran to take concrete steps to secure their accounts:&lt;br /&gt;&lt;div&gt;&lt;ol&gt;&lt;li&gt;Change your password. You may have already been asked to change your password when you signed in to your Google Account. If not, you can change it &lt;a href="https://mail.google.com/support/bin/answer.py?answer=6567"&gt;here&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;Verify your account recovery options. Secondary email addresses, phone numbers, and other information can help you regain access to your account if you lose your password. Check to be sure your recovery options are correct and up to date &lt;a href="http://www.google.com/support/accounts/bin/answer.py?answer=183723"&gt;here&lt;/a&gt;. &lt;/li&gt;&lt;li&gt;Check the websites and applications that are allowed to access your account, and revoke any that are unfamiliar &lt;a href="http://www.google.com/support/accounts/bin/answer.py?answer=41236"&gt;here&lt;/a&gt;. &lt;/li&gt;&lt;li&gt;Check your Gmail settings for suspicious &lt;a href="https://mail.google.com/support/bin/answer.py?answer=10957"&gt;forwarding addresses&lt;/a&gt; or &lt;a href="https://mail.google.com/support/bin/answer.py?hl=en&amp;amp;ctx=mail&amp;amp;answer=138350"&gt;delegated accounts&lt;/a&gt;. &lt;/li&gt;&lt;li&gt;Pay careful attention to &lt;a href="http://www.google.com/support/chrome/bin/answer.py?answer=95617"&gt;warnings that appear&lt;/a&gt; in your web browser and don’t click past them.&lt;/li&gt;&lt;/ol&gt;For more ways to secure your account, you can visit &lt;a href="http://www.google.com/help/security"&gt;http://www.google.com/help/security&lt;/a&gt;. If you believe your account has been compromised, you can start the recovery process &lt;a href="https://mail.google.com/support/bin/answer.py?answer=50270"&gt;here&lt;/a&gt;.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1176949257541686127-2450884721254666605?l=googleonlinesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?a=-tqUzPtaLKU:g0q2NgLrZag:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?a=-tqUzPtaLKU:g0q2NgLrZag:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?i=-tqUzPtaLKU:g0q2NgLrZag:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/GoogleOnlineSecurityBlog/~4/-tqUzPtaLKU" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://googleonlinesecurity.blogspot.com/feeds/2450884721254666605/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=1176949257541686127&amp;postID=2450884721254666605&amp;isPopup=true" title="6 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1176949257541686127/posts/default/2450884721254666605?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/1176949257541686127/posts/default/2450884721254666605?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/GoogleOnlineSecurityBlog/~3/-tqUzPtaLKU/gmail-account-security-in-iran.html" title="Gmail account security in Iran" /><author><name>Jay</name><uri>http://www.blogger.com/profile/08177113963774105206</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>6</thr:total><feedburner:origLink>http://googleonlinesecurity.blogspot.com/2011/09/gmail-account-security-in-iran.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0YGRHs5eip7ImA9WhdWEEo.&quot;"><id>tag:blogger.com,1999:blog-1176949257541686127.post-386783284323132943</id><published>2011-08-29T20:59:00.000-07:00</published><updated>2011-09-03T11:38:45.522-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-09-03T11:38:45.522-07:00</app:edited><title>An update on attempted man-in-the-middle attacks</title><content type="html">&lt;span class="byline-author"&gt;Posted by Heather Adkins, Information Security Manager&lt;/span&gt;
&lt;br /&gt;
&lt;br /&gt;Today we received reports of attempted SSL man-in-the-middle (MITM) attacks against Google users, whereby someone tried to get between them and encrypted Google services. The people affected were primarily located in Iran. The attacker used a fraudulent SSL certificate issued by DigiNotar, a root certificate authority that should not issue certificates for Google (and has since revoked it).
&lt;br /&gt;
&lt;br /&gt;Google Chrome users were protected from this attack because Chrome was able to &lt;a href="http://blog.chromium.org/2011/06/new-chromium-security-features-june.html"&gt;detect&lt;/a&gt; the fraudulent certificate.
&lt;br /&gt;
&lt;br /&gt;To further protect the safety and privacy of our users, we plan to disable the DigiNotar certificate authority in Chrome while investigations continue. Mozilla also &lt;a href="http://blog.mozilla.com/security/2011/08/29/fraudulent-google-com-certificate/"&gt;moved quickly&lt;/a&gt; to protect its users. This means that Chrome and Firefox users will receive alerts if they try to visit websites that use DigiNotar certificates. Microsoft also has &lt;a href="http://blogs.technet.com/b/msrc/archive/2011/08/29/microsoft-releases-security-advisory-2607712.aspx"&gt;taken prompt action&lt;/a&gt;.
&lt;br /&gt;
&lt;br /&gt;To help deter unwanted surveillance, we recommend that users, especially those in Iran, keep their web browsers and operating systems up to date and pay attention to web browser security warnings.
&lt;br /&gt;
&lt;br /&gt;&lt;i&gt;&lt;b&gt;Update&lt;/b&gt; Aug 30:&lt;/i&gt; Added information about Microsoft's response.
&lt;br /&gt;
&lt;br /&gt;&lt;i&gt;&lt;b&gt;Update&lt;/b&gt; Sept 3:&lt;/i&gt; Our top priority is to protect the privacy and security of our users. Based on the findings and decision of the Dutch government, as well as conversations with other browser makers, we have decided to reject all of the Certificate Authorities operated by DigiNotar. We encourage DigiNotar to provide a complete analysis of the situation.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1176949257541686127-386783284323132943?l=googleonlinesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?a=ydAgFaT14dI:j3tHq_xVmnA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?a=ydAgFaT14dI:j3tHq_xVmnA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?i=ydAgFaT14dI:j3tHq_xVmnA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/GoogleOnlineSecurityBlog/~4/ydAgFaT14dI" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://googleonlinesecurity.blogspot.com/feeds/386783284323132943/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=1176949257541686127&amp;postID=386783284323132943&amp;isPopup=true" title="25 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1176949257541686127/posts/default/386783284323132943?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/1176949257541686127/posts/default/386783284323132943?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/GoogleOnlineSecurityBlog/~3/ydAgFaT14dI/update-on-attempted-man-in-middle.html" title="An update on attempted man-in-the-middle attacks" /><author><name>Chris Evans</name><uri>http://www.blogger.com/profile/09064213468843556734</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>25</thr:total><feedburner:origLink>http://googleonlinesecurity.blogspot.com/2011/08/update-on-attempted-man-in-middle.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkMHQ305fCp7ImA9WhdQFk8.&quot;"><id>tag:blogger.com,1999:blog-1176949257541686127.post-6465575028195159013</id><published>2011-08-17T15:41:00.000-07:00</published><updated>2011-08-17T16:40:32.324-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-08-17T16:40:32.324-07:00</app:edited><title>Four Years of Web Malware</title><content type="html">&lt;span class="byline-author"&gt;Posted by Lucas Ballard and Niels Provos, Google Security Team&lt;/span&gt;
&lt;br /&gt;
&lt;br /&gt;Google’s Safe Browsing initiative has been protecting users from web pages that install malware for over five years now. Each day we show around 3 million malware warnings to over four hundred million users whose browsers implement the Safe Browsing API. Like other service providers, we are engaged in an arms race with malware distributors. Over time, we have adapted our original system to incorporate new detection algorithms that allow us to keep pace. We recently completed an analysis of four years of data that explores the evasive techniques that malware distributors employ. We compiled the results in a technical report, entitled “&lt;a href="http://research.google.com/archive/papers/rajab-2011a.pdf"&gt;Trends in Circumventing Web-Malware Detection&lt;/a&gt;.”
&lt;br /&gt;
&lt;br /&gt;Below are a few of the research highlights, but we recommend reviewing the &lt;a href="http://research.google.com/archive/papers/rajab-2011a.pdf"&gt;full report&lt;/a&gt; for details on our methodology and measurements. The analysis covers approximately 160 million web pages hosted on approximately 8 million sites.
&lt;br /&gt;
&lt;br /&gt;&lt;b&gt;Social Engineering&lt;/b&gt;
&lt;br /&gt;Social engineering is a malware distribution mechanism that relies on tricking a user into installing malware. Typically, the malware is disguised as an anti-virus product or browser plugin. Social engineering has increased in frequency significantly and is still rising. However, it’s important to keep this growth in perspective — sites that rely on social engineering comprise only 2% of all sites that distribute malware.
&lt;br /&gt;
&lt;br /&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5641924082717200370" src="http://2.bp.blogspot.com/-pd4wqihsTIQ/TkwkD6AUj_I/AAAAAAAAAuY/TeJEAciv9Sg/social-distribution.png" style="cursor: pointer; display: block; margin-bottom: 10px; margin-left: auto; margin-right: auto; margin-top: 0px; text-align: center; width: 450px;" /&gt; &lt;div style="text-align: center;"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;Number of sites distributing Social Engineering Malware and Exploits over time&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;
&lt;br /&gt;&lt;b&gt;Drive-by Download Exploit Trends&lt;/b&gt;
&lt;br /&gt;Far more common than social engineering, malicious pages install malware after exploiting a vulnerability in the browser or a plugin. This type of infection is often called a drive-by download. Our analysis of which vulnerabilities are actively being exploited over time shows that adversaries quickly switch to new and more reliable exploits to help avoid detection. The graph below shows the ratio of exploits targeting a vulnerability in one CVE to all exploits over time.  Most vulnerabilities are exploited only for a short period of time until new vulnerabilities become available. A prominent exception is the MDAC vulnerability which is present in most exploit kits.
&lt;br /&gt;
&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-a4FwsvAv2uo/TkwlJmsQ0ZI/AAAAAAAAAug/sDVrNJ8DIaw/s1600/cveheatmap.png"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5641925280123638162" src="http://1.bp.blogspot.com/-a4FwsvAv2uo/TkwlJmsQ0ZI/AAAAAAAAAug/sDVrNJ8DIaw/cveheatmap.png" style="cursor: hand; cursor: pointer; display: block; margin: 0px auto 10px; text-align: center; width: 450px;" /&gt;&lt;/a&gt;&lt;div style="text-align: center;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;i&gt;Prevalence of exploits targeting specific CVEs over time&lt;/i&gt;&lt;/span&gt; &lt;/div&gt;
&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;b&gt;Increase in IP Cloaking&lt;/b&gt;
&lt;br /&gt;Malware distributors are increasingly relying upon ‘cloaking’ as a technique to evade detection.  The concept behind cloaking is simple: serve benign content to detection systems, but serve malicious content to normal web page visitors. Over the years, we have seen more malicious sites engaging in IP cloaking. To bypass the cloaking defense, we run our scanners in different ways to mimic regular user traffic.
&lt;br /&gt;
&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-BYgPmr6BlPg/Tkwlhr_F9fI/AAAAAAAAAuo/ayh90GC9cgQ/s1600/cloaking_impact.png"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5641925693861656050" src="http://2.bp.blogspot.com/-BYgPmr6BlPg/Tkwlhr_F9fI/AAAAAAAAAuo/ayh90GC9cgQ/cloaking_impact.png" style="cursor: hand; cursor: pointer; display: block; margin: 0px auto 10px; text-align: center; width: 450px;" /&gt;&lt;/a&gt;&lt;div style="text-align: center;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;i&gt;Number of sites practicing IP Cloaking over time&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;
&lt;br /&gt;&lt;b&gt;New Detection Capabilities&lt;/b&gt;
&lt;br /&gt;Our report analyzed four years of data to uncover trends in malware distribution on the web, and it demonstrates the ongoing tension between malware distributors and malware detectors. To help protect Internet users, even those who don’t use Google, we have updated the Safe Browsing infrastructure over the years to incorporate many state-of-the-art malware detection technologies. We hope the findings outlined in this report will help other researchers in this area and raise awareness of some of the current challenges. &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1176949257541686127-6465575028195159013?l=googleonlinesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?a=jYrdUWafR8M:0JeOoFK7V0I:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?a=jYrdUWafR8M:0JeOoFK7V0I:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?i=jYrdUWafR8M:0JeOoFK7V0I:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/GoogleOnlineSecurityBlog/~4/jYrdUWafR8M" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://googleonlinesecurity.blogspot.com/feeds/6465575028195159013/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=1176949257541686127&amp;postID=6465575028195159013&amp;isPopup=true" title="3 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1176949257541686127/posts/default/6465575028195159013?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/1176949257541686127/posts/default/6465575028195159013?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/GoogleOnlineSecurityBlog/~3/jYrdUWafR8M/four-years-of-web-malware.html" title="Four Years of Web Malware" /><author><name>Jay</name><uri>http://www.blogger.com/profile/08177113963774105206</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-pd4wqihsTIQ/TkwkD6AUj_I/AAAAAAAAAuY/TeJEAciv9Sg/s72-c/social-distribution.png" height="72" width="72" /><thr:total>3</thr:total><feedburner:origLink>http://googleonlinesecurity.blogspot.com/2011/08/four-years-of-web-malware.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEMESHc4fyp7ImA9WhdQEUU.&quot;"><id>tag:blogger.com,1999:blog-1176949257541686127.post-3679451503660073250</id><published>2011-08-12T14:59:00.000-07:00</published><updated>2011-08-12T15:00:09.937-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-08-12T15:00:09.937-07:00</app:edited><title>Fuzzing at scale</title><content type="html">&lt;span class="byline-author"&gt;Posted by Chris Evans, Matt Moore and Tavis Ormandy, Google Security Team&lt;/span&gt;
&lt;br /&gt;
&lt;br /&gt;One of the exciting things about working on security at Google is that you have a lot of compute horsepower available if you need it. This is very useful if you’re looking to &lt;a href="http://en.wikipedia.org/wiki/Fuzz_testing"&gt;fuzz&lt;/a&gt; something, and especially if you’re going to use modern fuzzing techniques.
&lt;br /&gt;
&lt;br /&gt;Using these techniques and large amounts of compute power, we’ve found hundreds of bugs in our own code, including Chrome components such as WebKit and the PDF viewer. We recently decided to apply the same techniques to fuzz Adobe’s Flash Player, which we include with Chrome in partnership with Adobe.
&lt;br /&gt;
&lt;br /&gt;A good overview of some modern techniques can be read &lt;a href="http://taviso.decsystem.org/making_software_dumber.pdf"&gt;in this presentation&lt;/a&gt;. For the purposes of fuzzing Flash, we mainly relied on “corpus distillation”. This is a technique whereby you locate a large number of sample files for the format at hand (SWF in this case). You then see which areas of code are reached by each of the sample files. Finally, you run an algorithm to generate a minimal set of sample files that achieves the code coverage of the full set. This calculated set of files is a great basis for fuzzing: a manageable number of files that exercise lots of unusual code paths.
&lt;br /&gt;
&lt;br /&gt;What does corpus distillation look like at Google scale? Turns out we have a large index of the web, so we cranked through 20 terabytes of SWF file downloads followed by 1 week of run time on 2,000 CPU cores to calculate the minimal set of about 20,000 files. Finally, those same 2,000 cores plus 3 more weeks of runtime were put to good work mutating the files in the minimal set (bitflipping, etc.) and generating crash cases. These crash cases included an interesting range of vulnerability categories, including buffer overflows, integer overflows, use-after-frees and object type confusions.
&lt;br /&gt;
&lt;br /&gt;The initial run of the ongoing effort resulted in about 400 unique crash signatures, which were logged as 106 individual security bugs following Adobe's initial triage. As these bugs were resolved, many were identified as duplicates that weren't caught during the initial triage. A unique crash signature does not always indicate a unique bug. Since Adobe has access to symbols and sources, they were able to group similar crashes to perform root cause analysis reducing the actual number of changes to the code. No analysis was performed to determine how many of the identified crashes were actually exploitable. However, each crash was treated as though it were potentially exploitable and addressed by Adobe. In the final analysis, the Flash Player update Adobe shipped earlier this week contained about 80 code changes to fix these bugs.
&lt;br /&gt;
&lt;br /&gt;Commandeering massive resource to improve security is rewarding on its own, but the real highlight of this exercise has been Adobe’s response. The &lt;a href="http://www.adobe.com/support/security/bulletins/apsb11-21.html"&gt;Flash patch&lt;/a&gt; earlier this week fixes these bugs and incorporates UIPI protections for the Flash Player sandbox in Chrome which Justin Schuh contributed assistance on developing. Fixing &lt;a href="http://blogs.adobe.com/asset/2011/08/how-did-you-get-to-that-number.html"&gt;so many issues&lt;/a&gt; in such a short time frame shows a real commitment to security from Adobe, for which we are grateful.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1176949257541686127-3679451503660073250?l=googleonlinesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?a=YdGsL28v75w:-cCNMrzhoeM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?a=YdGsL28v75w:-cCNMrzhoeM:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?i=YdGsL28v75w:-cCNMrzhoeM:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/GoogleOnlineSecurityBlog/~4/YdGsL28v75w" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://googleonlinesecurity.blogspot.com/feeds/3679451503660073250/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=1176949257541686127&amp;postID=3679451503660073250&amp;isPopup=true" title="20 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1176949257541686127/posts/default/3679451503660073250?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/1176949257541686127/posts/default/3679451503660073250?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/GoogleOnlineSecurityBlog/~3/YdGsL28v75w/fuzzing-at-scale.html" title="Fuzzing at scale" /><author><name>Jay</name><uri>http://www.blogger.com/profile/08177113963774105206</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>20</thr:total><feedburner:origLink>http://googleonlinesecurity.blogspot.com/2011/08/fuzzing-at-scale.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkIMRnY5eCp7ImA9WhRRF0s.&quot;"><id>tag:blogger.com,1999:blog-1176949257541686127.post-8706672392619937063</id><published>2011-07-28T09:08:00.000-07:00</published><updated>2011-12-01T11:43:07.820-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-01T11:43:07.820-08:00</app:edited><title>2-step verification: stay safe around the world in 40 languages</title><content type="html">&lt;span class="byline-author"&gt;Posted by Nishit Shah, Product Manager, Google Security&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;(Cross-posted from the &lt;a href="http://googleblog.blogspot.com/2011/07/2-step-verification-stay-safe-around.html"&gt;Official Google Blog&lt;/a&gt;)&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
Earlier this year, we &lt;a href="http://googleblog.blogspot.com/2011/02/advanced-sign-in-security-for-your.html"&gt;introduced&lt;/a&gt; a security feature called &lt;i&gt;2-step verification&lt;/i&gt; that helps protect your Google Account from threats like password compromise and identity theft. By entering a one-time verification code from your phone after you type your password, you can make it much tougher for an unauthorized person to gain access to your account.&lt;br /&gt;
&lt;br /&gt;
People have told us how much they like the feature, which is why we're thrilled to offer 2-step verification in 40 languages and in more than 150 countries. There’s never been a better time to set it up: Examples in the news of password theft and data breaches constantly remind us to stay on our toes and take advantage of tools to properly secure our valuable online information. Email, social networking and other online accounts still get compromised today, but 2-step verification cuts those risks significantly.&lt;br /&gt;
&lt;br /&gt;
We recommend investing some time in keeping your information safe by watching our &lt;a href="http://www.google.com/support/accounts/bin/static.py?page=guide.cs&amp;amp;guide=1056283&amp;amp;topic=1056284"&gt;2-step verification video&lt;/a&gt; to learn how to quickly increase your Google Account’s resistance to common problems like reused passwords and &lt;a href="http://www.google.com/support/chrome/bin/answer.py?answer=99020"&gt;malware and phishing scams&lt;/a&gt;. Wherever you are in the world, &lt;a href="http://www.google.com/support/accounts/bin/static.py?page=guide.cs&amp;amp;guide=1056283&amp;amp;topic=1056284"&gt;sign up for 2-step verification&lt;/a&gt; and help keep yourself one step ahead of the bad guys.&lt;br /&gt;
&lt;br /&gt;
To learn more about online safety tips and resources, visit our ongoing security &lt;a href="http://googleblog.blogspot.com/search/label/security"&gt;blog series&lt;/a&gt;, and review a couple of simple &lt;a href="http://www.google.com/help/security/"&gt;tips and tricks&lt;/a&gt; for online security. Also, watch our video about &lt;a href="http://www.youtube.com/watch?hl=en&amp;amp;v=nOgsXdB67Pc"&gt;five easy ways&lt;/a&gt; to help you stay safe and secure as you browse.&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;&lt;b&gt;Update&lt;/b&gt; on 12/1/11&lt;/i&gt;: We recently made 2-step verification available for users in even more places, including Iran, Japan, Liberia, Myanmar (Burma), Sudan and Syria. This enhanced security feature for Google Accounts is now available in more than 175 countries.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1176949257541686127-8706672392619937063?l=googleonlinesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?a=WKbCuh3lSXg:xj6rnSlzDes:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?a=WKbCuh3lSXg:xj6rnSlzDes:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?i=WKbCuh3lSXg:xj6rnSlzDes:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/GoogleOnlineSecurityBlog/~4/WKbCuh3lSXg" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://googleonlinesecurity.blogspot.com/feeds/8706672392619937063/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=1176949257541686127&amp;postID=8706672392619937063&amp;isPopup=true" title="9 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1176949257541686127/posts/default/8706672392619937063?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/1176949257541686127/posts/default/8706672392619937063?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/GoogleOnlineSecurityBlog/~3/WKbCuh3lSXg/2-step-verification-stay-safe-around.html" title="2-step verification: stay safe around the world in 40 languages" /><author><name>Jay</name><uri>http://www.blogger.com/profile/08177113963774105206</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>9</thr:total><feedburner:origLink>http://googleonlinesecurity.blogspot.com/2011/07/2-step-verification-stay-safe-around.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEQMRXozcCp7ImA9WhdSEUU.&quot;"><id>tag:blogger.com,1999:blog-1176949257541686127.post-2370052525378628789</id><published>2011-07-19T16:57:00.000-07:00</published><updated>2011-07-20T11:26:24.488-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-07-20T11:26:24.488-07:00</app:edited><title>Using data to protect people from malware</title><content type="html">&lt;span class="byline-author"&gt;Posted by Damian Menscher, Security Engineer&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;i&gt;(Cross-posted from the &lt;a href="http://googleblog.blogspot.com/2011/07/using-data-to-protect-people-from.html"&gt;Official Google Blog&lt;/a&gt;)&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;The Internet brings remarkable benefits to society. Unfortunately, some people use it for harm and their own gain at the expense of others. We believe in the power of the web and information, and we work every day to detect potential abuse of our services and ward off attacks.&lt;br /&gt;&lt;br /&gt;As we work to protect our users and their information, we sometimes discover unusual patterns of activity. Recently, we found some unusual search traffic while performing routine maintenance on one of our data centers. After collaborating with security engineers at several companies that were sending this modified traffic, we determined that the computers exhibiting this behavior were infected with a particular strain of malicious software, or “malware.” As a result of this discovery, today some people will see a prominent notification at the top of their Google web search results:&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-VqrlpNf54Ts/TiYXvXVaNgI/AAAAAAAAISA/ObM12zWg2ZI/s1600/MalwareWarningScreenshot.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-VqrlpNf54Ts/TiYXvXVaNgI/AAAAAAAAISA/ObM12zWg2ZI/MalwareWarningScreenshot.png" width="500" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;This particular malware causes infected computers to send traffic to Google through a small number of intermediary servers called “proxies.” We hope that by taking steps to notify users whose traffic is coming through these proxies, we can help them update their antivirus software and remove the infections.&lt;br /&gt;&lt;br /&gt;We hope to use the knowledge we’ve gathered to assist as many people as possible. In case our notice doesn’t reach everyone directly, you can run a system scan on your computer yourself by following the steps in our &lt;a href="http://www.google.com/support/websearch/bin/answer.py?answer=1182191"&gt;Help Center article&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Updated July 20, 2011:&lt;/b&gt; We've seen a few common questions we thought we'd address here:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;The malware appears to have gotten onto users' computers from one of roughly a hundred variants of fake antivirus, or "fake AV" software that has been in circulation for a while. We aren't aware of a common name for the malware.&lt;/li&gt;&lt;li&gt;We believe a couple million machines are affected by this malware.&lt;/li&gt;&lt;li&gt;We've heard from a number of you that you're thinking about the potential for an attacker to copy our notice and attempt to point users to a dangerous site instead. It's a good security practice to be cautious about the links you click, so the spirit of those comments is spot-on. We thought about this, too, which is why the notice appears only at the top of our search results page. Falsifying the message on this page would require prior compromise of that computer, so the notice is not a risk to additional users. &lt;/li&gt;&lt;li&gt;In the meantime, we've been able to successfully warn hundreds of thousands of users that their computer is infected. These are people who otherwise may never have known.&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1176949257541686127-2370052525378628789?l=googleonlinesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?a=Mn3lylUnEMc:AiQhWNjrSZo:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?a=Mn3lylUnEMc:AiQhWNjrSZo:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?i=Mn3lylUnEMc:AiQhWNjrSZo:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/GoogleOnlineSecurityBlog/~4/Mn3lylUnEMc" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://googleonlinesecurity.blogspot.com/feeds/2370052525378628789/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=1176949257541686127&amp;postID=2370052525378628789&amp;isPopup=true" title="37 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1176949257541686127/posts/default/2370052525378628789?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/1176949257541686127/posts/default/2370052525378628789?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/GoogleOnlineSecurityBlog/~3/Mn3lylUnEMc/using-data-to-protect-people-from.html" title="Using data to protect people from malware" /><author><name>A Googler</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-VqrlpNf54Ts/TiYXvXVaNgI/AAAAAAAAISA/ObM12zWg2ZI/s72-c/MalwareWarningScreenshot.png" height="72" width="72" /><thr:total>37</thr:total><feedburner:origLink>http://googleonlinesecurity.blogspot.com/2011/07/using-data-to-protect-people-from.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C04MQn06eSp7ImA9WhZbFkU.&quot;"><id>tag:blogger.com,1999:blog-1176949257541686127.post-3707854928375167843</id><published>2011-06-21T11:46:00.000-07:00</published><updated>2011-06-21T11:46:23.311-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-06-21T11:46:23.311-07:00</app:edited><title>Introducing DOM Snitch, our passive in-the-browser reconnaissance tool</title><content type="html">&lt;div style="text-align: left;"&gt;Posted by Radoslav Vasilev, Security Test Engineer&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;(Cross-posted from the &lt;a href="http://googletesting.blogspot.com/2011/06/introducing-dom-snitch-our-passive-in.html"&gt;Google Testing Blog&lt;/a&gt;)&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;Every day modern web applications are becoming increasingly sophisticated, and as their complexity grows so does their attack surface. Previously we introduced open source tools such as &lt;a href="https://code.google.com/p/skipfish/"&gt;Skipfish&lt;/a&gt; and &lt;a href="https://code.google.com/p/ratproxy/"&gt;Ratproxy&lt;/a&gt; to assist developers in understanding and securing these applications.&lt;br /&gt;&lt;br /&gt;As existing tools focus mostly on testingserver-side code, today we are happy to introduce &lt;a href="https://code.google.com/p/domsnitch/"&gt;DOM Snitch&lt;/a&gt; — an experimental* Chrome extension that enables developers and testers to identify insecure practices commonly found in client-side code. To do this, we have adopted &lt;a href="http://code.google.com/p/domsnitch/wiki/DOMSnitchDoc#How_does_DOM_Snitch_work_under_the_hood?"&gt;several approaches&lt;/a&gt; to intercepting JavaScript calls to key and potentially dangerous browser infrastructure such as document.write or HTMLElement.innerHTML (&lt;a href="http://code.google.com/p/domsnitch/wiki/DOMSnitchDoc#What_can_DOM_Snitch_intercept?"&gt;among others&lt;/a&gt;). Once a JavaScript call has been intercepted, DOM Snitch records the document URL and a complete stack trace that will help assess if the intercepted call can lead to cross-site scripting, mixed content, insecure modifications to the &lt;a href="https://code.google.com/p/browsersec/wiki/Part2#Same-origin_policy_for_DOM_access"&gt;same-origin policy for DOM access&lt;/a&gt;, or other client-side issues.&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;img src="http://4.bp.blogspot.com/-3xmWRSsMB2g/TgDmE-F6ptI/AAAAAAAAAk4/ty1nL1ZY570/s400/domsnitch.png" style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 211px;" border="0" alt="" id="BLOGGER_PHOTO_ID_5620745308020057810" /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Here are the benefits of DOM Snitch:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;Real-time:&lt;/b&gt; Developers can observe DOM modifications as they happen inside the browser without the need to step through JavaScript code with a debugger or pause the execution of their application.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Easy to use:&lt;/b&gt; With built-in &lt;a href="https://code.google.com/p/domsnitch/wiki/QuickIntro#Current_capabilities"&gt;security heuristics&lt;/a&gt; and nested views, both advanced and less experienced developers and testers can quickly spot areas of the application being tested that need more attention.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Easier collaboration:&lt;/b&gt; Enables developers to easily export and share captured DOM modifications while troubleshooting an issue with their peers.&lt;/li&gt;&lt;/ul&gt;DOM Snitch is intended for use by developers, testers, and security researchers alike. &lt;a href="https://code.google.com/p/domsnitch/downloads/list"&gt;Click here&lt;/a&gt; to download DOM Snitch. To read the documentation, please visit &lt;a href="https://code.google.com/p/domsnitch/wiki/DOMSnitchDoc"&gt;this page&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;*Developers and testers should be aware that DOM Snitch is currently experimental. We do not guarantee that it will work flawlessly for all web applications. More details on known issues can be found &lt;a href="https://code.google.com/p/domsnitch/wiki/KnownIssues"&gt;here&lt;/a&gt; or in the project’s &lt;a href="https://code.google.com/p/domsnitch/issues/list"&gt;issues tracker&lt;/a&gt;.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1176949257541686127-3707854928375167843?l=googleonlinesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?a=VqtkgM9J298:0c2Ss8Mh38I:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?a=VqtkgM9J298:0c2Ss8Mh38I:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?i=VqtkgM9J298:0c2Ss8Mh38I:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/GoogleOnlineSecurityBlog/~4/VqtkgM9J298" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://googleonlinesecurity.blogspot.com/feeds/3707854928375167843/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=1176949257541686127&amp;postID=3707854928375167843&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1176949257541686127/posts/default/3707854928375167843?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/1176949257541686127/posts/default/3707854928375167843?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/GoogleOnlineSecurityBlog/~3/VqtkgM9J298/introducing-dom-snitch-our-passive-in.html" title="Introducing DOM Snitch, our passive in-the-browser reconnaissance tool" /><author><name>Jay</name><uri>http://www.blogger.com/profile/08177113963774105206</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-3xmWRSsMB2g/TgDmE-F6ptI/AAAAAAAAAk4/ty1nL1ZY570/s72-c/domsnitch.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://googleonlinesecurity.blogspot.com/2011/06/introducing-dom-snitch-our-passive-in.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CU4DQH09cCp7ImA9WhZbE08.&quot;"><id>tag:blogger.com,1999:blog-1176949257541686127.post-1314099224771804657</id><published>2011-06-17T08:19:00.000-07:00</published><updated>2011-06-17T08:19:31.368-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-06-17T08:19:31.368-07:00</app:edited><title>Protecting users from malware hosted on bulk subdomain services</title><content type="html">&lt;span class="byline-author"&gt;Posted by Oliver Fisher, Google Anti-Malware Team&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Over the past few months, Google’s systems have detected a number of bulk subdomain providers becoming targets of abuse by malware distributors. Bulk subdomain providers register a domain name, like example.com, and then sell subdomains of this domain name, like subdomain.example.com. Subdomains are often registered by the thousands at one time and are used to distribute malware and fake anti-virus products on the web. In some cases our malware scanners have found more than 50,000 malware domains from a single bulk provider.&lt;br /&gt;&lt;br /&gt;Google’s automated malware scanning systems detect sites that distribute malware. To help protect users we recently modified those systems to identify bulk subdomain services which are being abused. In some severe cases our systems may now flag the whole bulk domain.&lt;br /&gt;&lt;br /&gt;We offer many services to webmasters to help them fight abuse, such as:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.google.com/webmasters/tools/"&gt;Webmaster Tools&lt;/a&gt; lets webmasters find examples of URLs under their domains that may be distributing malware.&lt;/li&gt;&lt;li&gt;&lt;a href="http://googleonlinesecurity.blogspot.com/2010/09/safe-browsing-alerts-for-network.html"&gt;Google Safe Browsing Alerts for Network Administrators&lt;/a&gt; allows owners of Autonomous Systems to get notifications for hosts that are involved in malware delivery. &lt;/li&gt;&lt;/ul&gt;If you are the owner of a website that is hosted in a bulk subdomain service, please consider contacting your bulk subdomain provider if Google SafeBrowsing shows a warning for your site. The top-level bulk subdomain may be a target of abuse. Bulk subdomain service providers may use Google’s tools to help identify and disable abusive subdomains and accounts.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1176949257541686127-1314099224771804657?l=googleonlinesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?a=W-P9CvkKpds:QmydM-mw3bQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?a=W-P9CvkKpds:QmydM-mw3bQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?i=W-P9CvkKpds:QmydM-mw3bQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/GoogleOnlineSecurityBlog/~4/W-P9CvkKpds" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://googleonlinesecurity.blogspot.com/feeds/1314099224771804657/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=1176949257541686127&amp;postID=1314099224771804657&amp;isPopup=true" title="23 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1176949257541686127/posts/default/1314099224771804657?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/1176949257541686127/posts/default/1314099224771804657?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/GoogleOnlineSecurityBlog/~3/W-P9CvkKpds/protecting-users-from-malware-hosted-on.html" title="Protecting users from malware hosted on bulk subdomain services" /><author><name>Jay</name><uri>http://www.blogger.com/profile/08177113963774105206</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>23</thr:total><feedburner:origLink>http://googleonlinesecurity.blogspot.com/2011/06/protecting-users-from-malware-hosted-on.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CU8DQ3kzeip7ImA9WhdWFEw.&quot;"><id>tag:blogger.com,1999:blog-1176949257541686127.post-196134317956426840</id><published>2011-06-16T11:37:00.000-07:00</published><updated>2011-09-07T09:44:32.782-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-09-07T09:44:32.782-07:00</app:edited><title>Trying to end mixed scripting vulnerabilities</title><content type="html">&lt;span class="byline-author"&gt;Posted by Chris Evans and Tom Sepez, Google Chrome Security Team&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;A “mixed sc&lt;span &gt;ripting” vulnerability is caused when a page served over HTTPS loads a script, CSS, or plug-in resource over HTTP. A man-in-the-middle attacker (such as someone on the same wireless network) can typically intercept the HTTP resource&lt;/span&gt; load and gain full access to the website loading the resource. It’s often as bad as if the web page hadn’t used HTTPS at all.&lt;br /&gt;&lt;br /&gt;A less severe but similar problem -- let’s call it a “mixed display” vulnerability -- is caused when a page served over HTTPS loads an image, iFrame, or font over HTTP. A man-in-the-middle attacker can again intercept the HTTP resource load but normally can only affect the appearance of the page.&lt;br /&gt;&lt;br /&gt;Browsers have long used different indicators, modal dialogs, block options or even click-throughs to indicate these conditions to users. If a page on your website has a mixed scripting issue, Chromium will currently indicate it like this in the URL bar:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-kxHM-rEzNaU/TfqIqJmearI/AAAAAAAAIJg/01SwJ_T_PqQ/s1600/https1.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="82" src="http://3.bp.blogspot.com/-kxHM-rEzNaU/TfqIqJmearI/AAAAAAAAIJg/01SwJ_T_PqQ/s400/https1.png" style="cursor: move;" width="243" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;And for a mixed display issue:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-k-oSX8-CxmM/TfqIpwNsC5I/AAAAAAAAIJY/avmMj1u2FXY/s1600/https2.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="82" src="http://4.bp.blogspot.com/-k-oSX8-CxmM/TfqIpwNsC5I/AAAAAAAAIJY/avmMj1u2FXY/s400/https2.png" width="243" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;If any of the HTTPS pages on your website show the cross-out red https, there are good reasons to investigate promptly:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Your website won’t work as well in other modern browsers (such as IE9 or FF4) due to click-throughs and ugly modal dialogs.&lt;/li&gt;&lt;li&gt;You may have a security vulnerability that could compromise the entire HTTPS connection.&lt;/li&gt;&lt;/ul&gt;As of the first Chromium 14 canary release (14.0.785.0), we are trialing blocking mixed scripting conditions by default. We’ll be carefully listening to feedback; please leave it on &lt;a href="https://code.google.com/p/chromium/issues/detail?id=81637"&gt;this Chromium bug&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;We also added an infobar that shows when a script is being blocked:&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-DO9bA_NOFjQ/TfqIpU7Zb8I/AAAAAAAAIJI/ePLB8p3algc/s1600/blocked%2B%25281%2529.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/-DO9bA_NOFjQ/TfqIpU7Zb8I/AAAAAAAAIJI/ePLB8p3algc/blocked%2B%25281%2529.png" width="500" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;As a user, you can choose to reload the website without the block applied. Ideally, in the longer term, the infobar will not have the option for the user to bypass it. Our experience shows that some subset of users will attempt to “click through” even the scariest of warnings -- despite the hazards that can follow.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Tools that can help website owners&lt;/b&gt;&lt;br /&gt;If Chromium’s UI shows any mixed content issues on your site, you can try to use a couple of our developer tools to locate the problem. A useful message is typically logged to the JavaScript console (Menu -&amp;gt; Tools -&amp;gt; JavaScript Console):&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-YxIUhcyEcJE/TfqIpr7-1uI/AAAAAAAAIJQ/pfFpAqN1PdU/s1600/mixedscriptconsole.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/-YxIUhcyEcJE/TfqIpr7-1uI/AAAAAAAAIJQ/pfFpAqN1PdU/mixedscriptconsole.png" width="500" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;You can also reload the page with the “Network” tab active and look for requests that were issued over the http:// protocol. It’s worth noting that the entire origin is poisoned when mixed scripting occurs in it, so you’ll want to look at the console for all tabs that reference the indicated origin. To clear the error, all tabs that reference the poisoned origin need to be closed. For particularly tough cases where it’s not clear how the origin became poisoned, you can also &lt;a href="http://www.chromium.org/for-testers/enable-logging"&gt;enable debugging to the command-line console&lt;/a&gt; to see the relevant warning message.&lt;br /&gt;&lt;br /&gt;The latest Chromium 13 dev channel build (13.0.782.10) has a command line flag: &lt;b&gt;--no-running-insecure-content&lt;/b&gt;. We recommend that website owners and advanced users run with this flag, so we can all help mop up errant sites. (We also have the flag &lt;b&gt;--no-displaying-insecure-content&lt;/b&gt; for the less serious class of mixed content issues; there are no plans to block this by default in Chromium 14).&lt;br /&gt;&lt;br /&gt;The Chromium 14 release will come with an inverse flag: --allow-running-insecure-content, as a convenience for users and admins who have internal applications without immediate fixes for these errors.&lt;br /&gt;&lt;br /&gt;Thanks for helping us push website security forward as a community. Until this class of bug is stamped out, Chromium has your back.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1176949257541686127-196134317956426840?l=googleonlinesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?a=nA_cKGwtQrk:cy4RboGstFk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?a=nA_cKGwtQrk:cy4RboGstFk:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?i=nA_cKGwtQrk:cy4RboGstFk:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/GoogleOnlineSecurityBlog/~4/nA_cKGwtQrk" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://googleonlinesecurity.blogspot.com/feeds/196134317956426840/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=1176949257541686127&amp;postID=196134317956426840&amp;isPopup=true" title="13 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1176949257541686127/posts/default/196134317956426840?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/1176949257541686127/posts/default/196134317956426840?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/GoogleOnlineSecurityBlog/~3/nA_cKGwtQrk/trying-to-end-mixed-scripting.html" title="Trying to end mixed scripting vulnerabilities" /><author><name>Chris Evans</name><uri>http://www.blogger.com/profile/09064213468843556734</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-kxHM-rEzNaU/TfqIqJmearI/AAAAAAAAIJg/01SwJ_T_PqQ/s72-c/https1.png" height="72" width="72" /><thr:total>13</thr:total><feedburner:origLink>http://googleonlinesecurity.blogspot.com/2011/06/trying-to-end-mixed-scripting.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEMCQ34_fCp7ImA9WhZVFEk.&quot;"><id>tag:blogger.com,1999:blog-1176949257541686127.post-6362648509819552812</id><published>2011-05-26T14:41:00.000-07:00</published><updated>2011-05-26T14:47:42.044-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-05-26T14:47:42.044-07:00</app:edited><title>Safe Browsing Protocol v2 Transition</title><content type="html">&lt;span class="byline-author"&gt;Posted by Ian Fette, Google Security Team&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Last year, we released &lt;a href="http://code.google.com/apis/safebrowsing/developers_guide_v2.html"&gt;version 2&lt;/a&gt; of the Safe Browsing API, along with a &lt;a href="http://code.google.com/p/google-safe-browsing/downloads/list"&gt;reference implementation&lt;/a&gt; in Python. This version provides more efficient updates compared to version 1, giving clients the most useful (freshest) data first. The new version uses significantly less bandwidth, and also allows us to serve data that covers more URLs than previously possible. Browsers including Chrome and Firefox have already migrated to version 2, and we are confident that the new version works well and delivers significant benefits compared to the previous version.&lt;br /&gt;&lt;br /&gt;We are now planning to discontinue version 1 of the protocol to help us better focus our efforts and resources. On December 1, 2011, we will stop supporting version 1 and will take the service down shortly thereafter. If you are currently using version 1 of the protocol, we encourage you to migrate as soon as possible to the new version. In addition to the &lt;a href="http://code.google.com/apis/safebrowsing/developers_guide_v2.html"&gt;documentation&lt;/a&gt; and &lt;a href="http://code.google.com/p/google-safe-browsing/downloads/list"&gt;reference implementation&lt;/a&gt;, there’s a &lt;a href="http://groups.google.com/group/google-safe-browsing-api"&gt;Google Group&lt;/a&gt; dedicated to the API where you may be able to get additional advice or ask questions as you prepare to transition. Those of you who who have already migrated to version 2 will not be affected and do not need to take any further action.&lt;br /&gt;&lt;br /&gt;If you are looking to migrate from the version 1 API and are worried about the complexity of the version 2 API, we now have a &lt;a href="http://code.google.com/apis/safebrowsing/lookup_guide.html"&gt;lookup service&lt;/a&gt; that you can use in lieu of version 2 of the Safe Browsing Protocol if your usage is relatively low. The lookup service is a RESTful service that lets you send a URL or set of URLs to Google and receive a reply indicating the state of those URLs. You can use this API  if you check fewer than 100,000 URLs per day and don’t mind waiting on a network roundtrip. This process may be simpler to use than version 2 of the Safe Browsing Protocol, but it is not supported for users who will generate excessive load (meaning that your software, either your servers or deployed clients, will collectively generate over 100,000 requests to Google in a 24-hour period).&lt;br /&gt;&lt;br /&gt;If you are currently using version 1 of the Safe Browsing Protocol, please update to either the Safe Browsing Protocol version 2, or the lookup service, before December 1, 2011. If you have any questions, feel free to check out the Google Safe Browsing API &lt;a href="http://groups.google.com/group/google-safe-browsing-api"&gt;discussion list&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1176949257541686127-6362648509819552812?l=googleonlinesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?a=YxqGnkVOQWQ:m1Qa6lBBs20:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?a=YxqGnkVOQWQ:m1Qa6lBBs20:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?i=YxqGnkVOQWQ:m1Qa6lBBs20:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/GoogleOnlineSecurityBlog/~4/YxqGnkVOQWQ" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://googleonlinesecurity.blogspot.com/feeds/6362648509819552812/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=1176949257541686127&amp;postID=6362648509819552812&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1176949257541686127/posts/default/6362648509819552812?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/1176949257541686127/posts/default/6362648509819552812?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/GoogleOnlineSecurityBlog/~3/YxqGnkVOQWQ/safe-browsing-protocol-v2-transition.html" title="Safe Browsing Protocol v2 Transition" /><author><name>Niels Provos</name><uri>http://www.blogger.com/profile/17807363822730767592</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://googleonlinesecurity.blogspot.com/2011/05/safe-browsing-protocol-v2-transition.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkYEQn44eCp7ImA9WhZXFk8.&quot;"><id>tag:blogger.com,1999:blog-1176949257541686127.post-9008002394805788310</id><published>2011-05-05T12:33:00.000-07:00</published><updated>2011-05-05T12:35:03.030-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-05-05T12:35:03.030-07:00</app:edited><title>Website Security for Webmasters</title><content type="html">&lt;span class="byline-author"&gt;Posted by Gary Illyes, Webmaster Trends Analyst&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;i&gt;(Cross-posted from the &lt;a href="http://googlewebmastercentral.blogspot.com/2011/05/website-security-for-webmasters.html"&gt;Webmaster Central Blog&lt;/a&gt;)&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;Users are taught to protect themselves from malicious programs by installing sophisticated antivirus software, but they often also entrust their private information to various websites. As a result, webmasters have a dual task to protect both their website itself and the user data that they receive.&lt;br /&gt;&lt;br /&gt;Over the years companies and webmasters have learned—often the hard way—that web application security is not a joke; we’ve seen user passwords leaked due to &lt;a href="http://en.wikipedia.org/wiki/SQL_injection"&gt;SQL injection&lt;/a&gt; attacks, cookies stolen with &lt;a href="http://en.wikipedia.org/wiki/Cross-site_scripting"&gt;XSS&lt;/a&gt;, and websites taken over by hackers due to negligent input validation.&lt;br /&gt;&lt;br /&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5603170363751903522" src="http://4.bp.blogspot.com/-edYHtaKmejg/TcJ1wkttsSI/AAAAAAAAABI/pcTuQ092SRU/s320/image05.png" style="cursor: hand; cursor: pointer; float: left; height: 40px; margin: 0 10px 10px 0; width: 40px;" /&gt;Today we’ll show you some examples of how a web application can be exploited so you can learn from them; for this we’ll use &lt;a href="http://google-gruyere.appspot.com/"&gt;Gruyere&lt;/a&gt;, an intentionally vulnerable application we use for security training internally, and that we introduced here &lt;a href="http://googleonlinesecurity.blogspot.com/2010/05/do-know-evil-web-application.html"&gt;last year&lt;/a&gt;. &lt;span style="font-weight: bold;"&gt;Do not probe others’ websites for vulnerabilities without permission&lt;/span&gt; as it may be perceived as hacking; but you’re welcome—nay, encouraged—to run tests on Gruyere.&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Client state manipulation - What will happen if I alter the URL?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Let’s say you have an image hosting site and you’re using a PHP script to display the images users have uploaded:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;http://www.example.com/showimage.php?imgloc=/garyillyes/kitten.jpg&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;So what will the application do if I alter the URL to something like this and userpasswords.txt is an actual file?&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;http://www.example.com/showimage.php?imgloc=/../../userpasswords.txt&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Will I get the content of userpasswords.txt?&lt;br /&gt;&lt;br /&gt;Another example of client state manipulation is when form fields are not validated. For instance, let’s say you have this form:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-CUl2wmaPSfU/TcJ26natwlI/AAAAAAAAABY/FJLhqkOijIE/s1600/image01.png" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5603171635787842130" src="http://4.bp.blogspot.com/-CUl2wmaPSfU/TcJ26natwlI/AAAAAAAAABY/FJLhqkOijIE/s400/image01.png" style="cursor: hand; cursor: pointer; display: block; height: 224px; margin: 0px auto 10px; text-align: center; width: 400px;" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;It seems that the username of the submitter is stored in a hidden input field. Well, that’s great! Does that mean that if I change the value of that field to another username, I can submit the form as that user? It may very well happen; the user input is apparently not authenticated with, for example, a token which can be verified on the server.&lt;br /&gt;Imagine the situation if that form were part of your shopping cart and I modified the price of a $1000 item to $1, and then placed the order.&lt;br /&gt;&lt;br /&gt;Protecting your application against this kind of attack is not easy; take a look at the third part of &lt;a href="http://google-gruyere.appspot.com/part3"&gt;Gruyere&lt;/a&gt; to learn a few tips about how to defend your app.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Cross-site scripting (XSS) - User input can’t be trusted&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-zl9GLNOZTSU/TcJ3RWU3pHI/AAAAAAAAABg/QWpA-wnwCkE/s1600/image04.png" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5603172026336912498" src="http://1.bp.blogspot.com/-zl9GLNOZTSU/TcJ3RWU3pHI/AAAAAAAAABg/QWpA-wnwCkE/s400/image04.png" style="cursor: hand; cursor: pointer; display: block; height: 250px; margin: 0px auto 10px; text-align: center; width: 350px;" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;A simple, harmless URL:&lt;br /&gt;&lt;span style="font-style: italic;"&gt;http://google-gruyere.appspot.com/611788451095/%3Cscript%3Ealert('0wn3d')%3C/script%3E&lt;/span&gt;&lt;br /&gt;But is it truly harmless? If I decode the &lt;a href="http://en.wikipedia.org/wiki/Percent_encoding"&gt;percent-encoded&lt;/a&gt; characters, I get:&lt;br /&gt;&lt;pre style="text-align: center;"&gt;&amp;lt;script&amp;gt;alert('0wn3d')&amp;lt;/script&amp;gt;&lt;/pre&gt;&lt;br /&gt;Gruyere, just like many sites with &lt;a href="http://www.google.com/support/webmasters/bin/answer.py?answer=93641"&gt;custom error pages&lt;/a&gt;, is designed to include the path component in the HTML page. This can introduce security bugs, like XSS, as it introduces user input directly into the rendered HTML page of the web application. You might say, “It’s just an alert box, so what?” The thing is, if I can inject an alert box, I can most likely inject something else, too, and maybe steal your cookies which I could use to sign in to your site as you.&lt;br /&gt;&lt;br /&gt;Another example is when the stored user input isn’t sanitized. Let’s say I write a comment on your blog; the comment is simple:&lt;br /&gt;&lt;pre style="text-align: center;"&gt;&amp;lt;a href=”javascript:alert(‘0wn3d’)”&amp;gt;Click here to see a kitten&amp;lt;/a&amp;gt;&lt;/pre&gt;&lt;br /&gt;If other users click on my innocent link, I have their cookies:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-G5gvanGzYso/TcJ4Y21jlrI/AAAAAAAAABo/dBxxlOCeNCU/s1600/image00.png" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5603173254834656946" src="http://3.bp.blogspot.com/-G5gvanGzYso/TcJ4Y21jlrI/AAAAAAAAABo/dBxxlOCeNCU/s400/image00.png" style="cursor: hand; cursor: pointer; display: block; height: 210px; margin: 0px auto 10px; text-align: center; width: 300px;" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;You can learn how to find XSS vulnerabilities in your own web app and how to fix them in the second part of &lt;a href="http://google-gruyere.appspot.com/part2"&gt;Gruyere&lt;/a&gt;; or, if you’re an advanced developer, take a look at the automatic escaping features in template systems we blogged about previously on &lt;a href="http://googleonlinesecurity.blogspot.com/2009/03/reducing-xss-by-way-of-automatic.html"&gt;this blog&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Cross-site request forgery (XSRF) - Should I trust requests from evil.com?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-oGUWkyOcgVI/TcJ5Jlnc02I/AAAAAAAAAB4/W2LgndPdgLE/s1600/image03.png" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5603174092025680738" src="http://3.bp.blogspot.com/-oGUWkyOcgVI/TcJ5Jlnc02I/AAAAAAAAAB4/W2LgndPdgLE/s400/image03.png" style="cursor: hand; cursor: pointer; float: left; height: 80px; margin: 0 10px 10px 0; width: 250px;" /&gt;&lt;/a&gt; Oops, a broken picture. It can’t be dangerous--it’s broken, after all--which means that the URL of the image returns a 404 or it’s just malformed. Is that true in all of the cases?&lt;br /&gt;&lt;br /&gt;No, it’s not! You can specify any URL as an image source, regardless of its content type. It can be an HTML page, a JavaScript file, or some other potentially malicious resource. In this case the image source was a simple page’s URL:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-W5Kf2VzGYQ4/TcJ5YqZ5qJI/AAAAAAAAACA/a7ir-pIueG0/s1600/image02.png" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5603174351009065106" src="http://4.bp.blogspot.com/-W5Kf2VzGYQ4/TcJ5YqZ5qJI/AAAAAAAAACA/a7ir-pIueG0/s400/image02.png" style="cursor: hand; cursor: pointer; display: block; height: 50px; margin: 0px auto 10px; text-align: center; width: 400px;" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;That page will only work if I’m logged in and I have some cookies set. Since I was actually logged in to the application, when the browser tried to fetch the image by accessing the image source URL, it also deleted my first snippet. This doesn’t sound particularly dangerous, but if I’m a bit familiar with the app, I could also invoke a URL which deletes a user’s profile or lets admins grant permissions for other users.&lt;br /&gt;&lt;br /&gt;To protect your app against XSRF you should not allow state changing actions to be called via GET; the POST method was invented for this kind of state-changing request. This change alone may have mitigated the above attack, but usually it's not enough and you need to include an unpredictable value in all state changing requests to prevent XSRF. Please head to &lt;a href="http://google-gruyere.appspot.com/part3"&gt;Gruyere&lt;/a&gt; if you want to learn more about XSRF.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Cross-site script inclusion (XSSI) - All your script are belong to us&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Many sites today can dynamically update a page's content via asynchronous JavaScript  requests that return JSON data. Sometimes, JSON can contain sensitive data, and if the correct precautions are not in place, it may be possible for an attacker to steal this sensitive information.&lt;br /&gt;&lt;br /&gt;Let’s imagine the following scenario: I have created a standard HTML page and send you the link; since you trust me, you visit the link I sent you. The page contains only a few lines:&lt;br /&gt;&lt;pre&gt;&amp;lt;script&amp;gt;function _feed(s) {alert("Your private snippet is: " + s['private_snippet']);}&amp;lt;/script&amp;gt;&amp;lt;script src="http://google-gruyere.appspot.com/611788451095/feed.gtl"&amp;gt;&amp;lt;/script&amp;gt;&lt;/pre&gt;&lt;br /&gt;Since you’re signed in to Gruyere and you have a private snippet, you’ll see an alert box on my page informing you about the contents of your snippet. As always, if I managed to fire up an alert box, I can do whatever else I want; in this case it was a simple snippet, but it could have been your biggest secret, too.&lt;br /&gt;&lt;br /&gt;It’s not too hard to defend your app against XSSI, but it still requires careful thinking. You can use tokens as explained in the XSRF section, set your script to answer only POST requests, or simply start the JSON response with ‘\n’ to make sure the script is not executable.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;SQL Injection - Still think user input is safe?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;What will happen if I try to sign in to your app with a username like&lt;br /&gt;&lt;pre style="text-align: center;"&gt;JohnDoe’; DROP TABLE members;--&lt;/pre&gt;&lt;br /&gt;While this specific example won’t expose user data, it can cause great headaches because it has the potential to completely remove the SQL table where your app stores information about members.&lt;br /&gt;&lt;br /&gt;Generally, you can protect your app from SQL injection with proactive thinking and input validation. First, are you sure the SQL user needs to have permission to execute “DROP TABLE members”? Wouldn’t it be enough to grant only SELECT rights? By setting the SQL user’s permissions carefully, you can avoid painful experiences and lots of troubles. You might also want to configure error reporting in such way that the database and its tables’ names aren’t exposed in the case of a failed query.&lt;br /&gt;Second, as we learned in the XSS case, never trust user input: what looks like a login form to you, looks like a potential doorway to an attacker. Always sanitize and quotesafe the input that will be stored in a database, and whenever possible make use of statements generally referred to as prepared or parametrized statements available in most database programming interfaces.&lt;br /&gt;&lt;br /&gt;Knowing how web applications can be exploited is the first step in understanding how to defend them. In light of this, we encourage you to take the &lt;a href="http://google-gruyere.appspot.com/"&gt;Gruyere course&lt;/a&gt;, take other web security courses from the &lt;a href="http://code.google.com/edu/security/index.html"&gt;Google Code University&lt;/a&gt; and check out &lt;a href="http://code.google.com/p/skipfish/wiki/SkipfishDoc"&gt;skipfish&lt;/a&gt; if you're looking for an automated web application security testing tool. If you have more questions please post them in our &lt;a href="http://www.google.com/support/forum/p/Webmasters/browse?hl=en"&gt;Webmaster Help Forum&lt;/a&gt;.&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1176949257541686127-9008002394805788310?l=googleonlinesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?a=3dffwYwNm4k:vzXPC_uHhCg:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?a=3dffwYwNm4k:vzXPC_uHhCg:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?i=3dffwYwNm4k:vzXPC_uHhCg:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/GoogleOnlineSecurityBlog/~4/3dffwYwNm4k" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://googleonlinesecurity.blogspot.com/feeds/9008002394805788310/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=1176949257541686127&amp;postID=9008002394805788310&amp;isPopup=true" title="2 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1176949257541686127/posts/default/9008002394805788310?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/1176949257541686127/posts/default/9008002394805788310?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/GoogleOnlineSecurityBlog/~3/3dffwYwNm4k/website-security-for-webmasters.html" title="Website Security for Webmasters" /><author><name>Jay</name><uri>http://www.blogger.com/profile/08177113963774105206</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-edYHtaKmejg/TcJ1wkttsSI/AAAAAAAAABI/pcTuQ092SRU/s72-c/image05.png" height="72" width="72" /><thr:total>2</thr:total><feedburner:origLink>http://googleonlinesecurity.blogspot.com/2011/05/website-security-for-webmasters.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkcBQ3Yzeyp7ImA9WhZREE8.&quot;"><id>tag:blogger.com,1999:blog-1176949257541686127.post-8114550924546216008</id><published>2011-04-05T11:27:00.000-07:00</published><updated>2011-04-05T11:27:32.883-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-04-05T11:27:32.883-07:00</app:edited><title>Protecting users from malicious downloads</title><content type="html">&lt;span class="byline-author"&gt;Posted by Moheeb Abu Rajab, Google Security Team&lt;/span&gt; &lt;br /&gt;
&lt;br /&gt;
For the past five years Google has been offering protection to users against websites that attempt to distribute malware via drive-by downloads — that is, infections that harm users’ computers when they simply visit a vulnerable site. The data produced by our systems and published via the &lt;a href="http://code.google.com/apis/safebrowsing/"&gt;Safe Browsing API&lt;/a&gt; is used by Google search and browsers such as Google Chrome, Firefox, and Safari to warn users who may attempt to visit these dangerous webpages. &lt;br /&gt;
&lt;br /&gt;
Safe Browsing has done a lot of good for the web, yet the Internet remains rife with deceptive and harmful content. It’s easy to find sites hosting free downloads that promise one thing but actually behave quite differently. These downloads may even perform actions without the user’s consent, such as displaying spam ads, performing click fraud, or stealing other users’ passwords. Such sites usually don’t attempt to exploit vulnerabilities on the user’s computer system. Instead, they use social engineering to entice users to download and run the malicious content.   &lt;br /&gt;
&lt;br /&gt;
Today we’re pleased to announce a new feature that aims to protect users against these kinds of downloads, starting with malicious Windows executables. The new feature will be integrated with Google Chrome and will display a warning if a user attempts to download a suspected malicious executable file:&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-daarKD9UaMg/TZtdGDuxx3I/AAAAAAAC22k/4j6y3nM3MtE/s1600/warning.png" imageanchor="1" style=""&gt;&lt;img border="0" height="53" width="400" src="http://3.bp.blogspot.com/-daarKD9UaMg/TZtdGDuxx3I/AAAAAAAC22k/4j6y3nM3MtE/s400/warning.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;center&gt;&lt;i&gt;Download warning&lt;/i&gt;&lt;/center&gt;&lt;br /&gt;
&lt;br /&gt;
This warning will be displayed for any download URL that matches the latest list of malicious websites published by the &lt;a href="http://code.google.com/apis/safebrowsing/"&gt;Safe Browsing API&lt;/a&gt;. The new feature follows the same &lt;a href="http://www.google.com/chrome/intl/en/privacy.html"&gt;privacy policy&lt;/a&gt; currently in use by the Safe Browsing feature. For example, this feature does not enable Google to determine the URLs you are visiting.&lt;br /&gt;
&lt;br /&gt;
We’re starting with a small-scale experimental phase for a subset of our users who subscribe to the Chrome development release channel, and we hope to make this feature available to all users in the next stable release of Google Chrome. We hope that the feature will improve our users’ online experience and help make the Internet a safer place.&lt;br /&gt;
&lt;br /&gt;
For webmasters, you can continue to use the same interface provided by &lt;a href="https://www.google.com/webmasters/tools/"&gt;Google Webmaster Tools&lt;/a&gt; to learn about malware issues with your sites. These tools include binaries that have been identified by this new feature, and the same &lt;a href="http://googleonlinesecurity.blogspot.com/2009/10/malware-warning-review-process.html"&gt;review process&lt;/a&gt; will apply.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1176949257541686127-8114550924546216008?l=googleonlinesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?a=B0-DQZoBL1g:_j1eS7_Lk74:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?a=B0-DQZoBL1g:_j1eS7_Lk74:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?i=B0-DQZoBL1g:_j1eS7_Lk74:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/GoogleOnlineSecurityBlog/~4/B0-DQZoBL1g" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://googleonlinesecurity.blogspot.com/feeds/8114550924546216008/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=1176949257541686127&amp;postID=8114550924546216008&amp;isPopup=true" title="4 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1176949257541686127/posts/default/8114550924546216008?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/1176949257541686127/posts/default/8114550924546216008?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/GoogleOnlineSecurityBlog/~3/B0-DQZoBL1g/protecting-users-from-malicious.html" title="Protecting users from malicious downloads" /><author><name>Panayiotis Mavrommatis</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-daarKD9UaMg/TZtdGDuxx3I/AAAAAAAC22k/4j6y3nM3MtE/s72-c/warning.png" height="72" width="72" /><thr:total>4</thr:total><feedburner:origLink>http://googleonlinesecurity.blogspot.com/2011/04/protecting-users-from-malicious.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkAER3s6fyp7ImA9WhZSFko.&quot;"><id>tag:blogger.com,1999:blog-1176949257541686127.post-2029461104519147234</id><published>2011-04-01T09:05:00.000-07:00</published><updated>2011-04-01T09:18:26.517-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-04-01T09:18:26.517-07:00</app:edited><title>Improving SSL certificate security</title><content type="html">&lt;span class="byline-author"&gt;Posted by Ben Laurie, Google Security Team&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
In the wake of the recent &lt;a href="http://www.comodo.com/Comodo-Fraud-Incident-2011-03-23.html"&gt;Comodo fraud incident&lt;/a&gt;, there has been a great deal of speculation about how to improve the public key infrastructure, on which the security of the Internet rests. Unfortunately, this isn’t a problem that will be fixed overnight. Luckily, however, experts have long known about these issues and have been devising solutions for some time.&lt;br /&gt;
&lt;br /&gt;
Given the current interest it seems like a good time to talk about two projects in which Google is engaged.&lt;br /&gt;
&lt;br /&gt;
The first is the Google Certificate Catalog. Google’s web crawlers scan the web on a regular basis in order to provide our search and other services. In the process, we also keep a record of all the SSL certificates we see. The Google Certificate Catalog is a database of all of those certificates, published in DNS. So, for example, if you wanted to see what we think of &lt;a href="https://www.google.com/"&gt;https://www.google.com/&lt;/a&gt;’s certificate, you could do this:&lt;br /&gt;
&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: 'Courier New', Courier, monospace;"&gt;$ &lt;b&gt;openssl s_client -connect www.google.com:443 &amp;lt; /dev/null | openssl x509 -outform DER | openssl sha1&lt;/b&gt;&lt;br /&gt;
depth=1 /C=ZA/O=Thawte Consulting (Pty) Ltd./CN=Thawte SGC CA&lt;br /&gt;
verify error:num=20:unable to get local issuer certificate&lt;br /&gt;
verify return:0&lt;br /&gt;
DONE&lt;br /&gt;
405062e5befde4af97e9382af16cc87c8fb7c4e2&lt;br /&gt;
$ &lt;b&gt;dig +short 405062e5befde4af97e9382af16cc87c8fb7c4e2.certs.googlednstest.com TXT&lt;/b&gt;&lt;br /&gt;
"14867 15062 74"&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
In other words: take the SHA-1 hash of the certificate, represent it as a hexadecimal number, then look up a TXT record with that name in the &lt;span class="Apple-style-span" style="font-family: 'Courier New', Courier, monospace;"&gt;certs.googlednstest.com&lt;/span&gt; domain. What you get back is a set of three numbers. The first number is the day that Google’s crawlers first saw that certificate, the second is the most recent day, and the third is the number of days we saw it in between.&lt;br /&gt;
&lt;br /&gt;
In order for the hash of a certificate to appear in our database, it must satisfy some criteria:&lt;br /&gt;
&lt;ul&gt;&lt;li&gt;It must be correctly signed (either by a CA or self-signed).&lt;/li&gt;
&lt;li&gt;It must have the correct domain name — that is, one that matches the one we used to retrieve the certificate.&lt;/li&gt;
&lt;/ul&gt;The basic idea is that if a certificate doesn’t appear in our database, despite being correctly signed by a well-known CA and having a matching domain name, then there may be something suspicious about that certificate. This endeavor owes much to the excellent &lt;a href="http://www.networknotary.org/"&gt;Perspectives&lt;/a&gt; project, but it is a somewhat different approach.&lt;br /&gt;
&lt;br /&gt;
Accessing the data manually is rather difficult and painful, so we’re thinking about how to add opt-in support to the Chrome browser. We hope other browsers will in time consider acting similarly.&lt;br /&gt;
&lt;br /&gt;
The second initiative to discuss is the &lt;a href="https://datatracker.ietf.org/wg/dane/charter/"&gt;DANE Working Group at the IETF&lt;/a&gt;. DANE stands for DNS-based Authentication of Named Entities. In short, the idea is to allow domain operators to publish information about SSL certificates used on their hosts. It should be possible, using DANE DNS records, to specify particular certificates which are valid, or CAs that are allowed to sign certificates for those hosts. So, once more, if a certificate is seen that isn’t consistent with the DANE records, it should be treated with suspicion. Related to the DANE effort is the individually contributed &lt;a href="http://tools.ietf.org/html/draft-hallambaker-donotissue-03"&gt;CAA record&lt;/a&gt;, which predates the DANE WG and provides similar functionality.&lt;br /&gt;
&lt;br /&gt;
One could rightly point out that both of these efforts rely on DNS, which is not secure. Luckily we’ve been working on that problem for even longer than this one, and a reasonable answer is DNSSEC, which enables publishing DNS records that are cryptographically protected against forgery and modification.&lt;br /&gt;
&lt;br /&gt;
It will be some time before DNSSEC is deployed widely enough for DANE to be broadly useful, since DANE requires every domain to be able to use DNSSEC. However, work is on the way to use DNSSEC for the Certificate Catalog well before the entire DNSSEC infrastructure is ready. If we publish a key for the domain in which we publish the catalog, clients can simply incorporate this key as an interim measure until DNSSEC is properly deployed.&lt;br /&gt;
&lt;br /&gt;
Improving the public key infrastructure of the web is a big task and one that’s going to require the cooperation of many parties to be widely effective. We hope these projects will help point us in the right direction.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1176949257541686127-2029461104519147234?l=googleonlinesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?a=It5bOXSayBA:l7MvXY8xtCY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?a=It5bOXSayBA:l7MvXY8xtCY:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?i=It5bOXSayBA:l7MvXY8xtCY:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/GoogleOnlineSecurityBlog/~4/It5bOXSayBA" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://googleonlinesecurity.blogspot.com/feeds/2029461104519147234/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=1176949257541686127&amp;postID=2029461104519147234&amp;isPopup=true" title="20 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1176949257541686127/posts/default/2029461104519147234?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/1176949257541686127/posts/default/2029461104519147234?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/GoogleOnlineSecurityBlog/~3/It5bOXSayBA/improving-ssl-certificate-security.html" title="Improving SSL certificate security" /><author><name>Jay</name><uri>http://www.blogger.com/profile/08177113963774105206</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>20</thr:total><feedburner:origLink>http://googleonlinesecurity.blogspot.com/2011/04/improving-ssl-certificate-security.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DE8DRn8zcSp7ImA9WhZSFUQ.&quot;"><id>tag:blogger.com,1999:blog-1176949257541686127.post-6482786953427442924</id><published>2011-03-31T11:04:00.000-07:00</published><updated>2011-03-31T11:41:17.189-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-03-31T11:41:17.189-07:00</app:edited><title>Chrome warns users of out-of-date browser plugins</title><content type="html">&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;span class="byline-author"&gt;Posted by Panayiotis Mavrommatis and Noé Lutz, Google Security Team&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The new version of Google Chrome is not only &lt;a href="http://chrome.blogspot.com/2011/03/speedier-simpler-and-safer-chromes.html"&gt;speedier and simpler&lt;/a&gt; but it also improves user security by automatically disabling out-of-date, vulnerable browser plugins.&lt;br /&gt;&lt;br /&gt;As browsers get better at auto-updating, out-of-date plugins are becoming the weakest link against malware attacks. Thousands of web sites are compromised every week, turning those sites into malware distribution vectors by actively exploiting out-of-date plugins that run in the browser. Simply visiting one of these sites is usually enough to get your computer infected.&lt;br /&gt;&lt;br /&gt;Keeping all of your plugins up-to-date with the latest security fixes can be a hassle, so a while ago we started using our 20% time to develop a solution. The initial implementation was a Chrome extension called &lt;a href="https://chrome.google.com/extensions/detail/pgkcfihepeihdlfphbndagmompiakeci"&gt;“SecBrowsing,”&lt;/a&gt; which kept track of the latest plugin versions and encouraged users to update accordingly. The extension helped us gather valuable knowledge about plugins, and we started working with the Chrome team to build the feature right inside the browser.&lt;br /&gt;&lt;br /&gt;With the latest version of Chrome, users will be automatically warned about any out-of-date plugins. If you run into a page that requires a plugin that’s not current, it won’t run by default. Instead, you’ll see a message that will help you get the latest, most secure version of the plugin. An example of this message is below, and you can read more about the feature at the &lt;a href="http://blog.chromium.org/2011/03/mini-newsletter-from-your-google-chrome.html"&gt;Chromium blog&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;img src="http://3.bp.blogspot.com/-a4wFYvCMaOU/TZTKJdi3-qI/AAAAAAAAAkQ/i0gUISzUrdU/s400/out%2Bof%2Bdate%2Bplugin.png" style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 146px;" border="0" alt="" id="BLOGGER_PHOTO_ID_5590315301372164770" /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1176949257541686127-6482786953427442924?l=googleonlinesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?a=a1WyJa4rEGc:Gsc_W3njNXE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?a=a1WyJa4rEGc:Gsc_W3njNXE:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?i=a1WyJa4rEGc:Gsc_W3njNXE:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/GoogleOnlineSecurityBlog/~4/a1WyJa4rEGc" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://googleonlinesecurity.blogspot.com/feeds/6482786953427442924/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=1176949257541686127&amp;postID=6482786953427442924&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1176949257541686127/posts/default/6482786953427442924?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/1176949257541686127/posts/default/6482786953427442924?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/GoogleOnlineSecurityBlog/~3/a1WyJa4rEGc/chrome-warns-users-of-out-of-date.html" title="Chrome warns users of out-of-date browser plugins" /><author><name>Jay</name><uri>http://www.blogger.com/profile/08177113963774105206</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-a4wFYvCMaOU/TZTKJdi3-qI/AAAAAAAAAkQ/i0gUISzUrdU/s72-c/out%2Bof%2Bdate%2Bplugin.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://googleonlinesecurity.blogspot.com/2011/03/chrome-warns-users-of-out-of-date.html</feedburner:origLink></entry><entry gd:etag="W/&quot;Dk4CSXY-eyp7ImA9Wx9aGEU.&quot;"><id>tag:blogger.com,1999:blog-1176949257541686127.post-6431747515119342935</id><published>2011-03-11T14:13:00.000-08:00</published><updated>2011-03-11T15:09:28.853-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-03-11T15:09:28.853-08:00</app:edited><title>MHTML vulnerability under active exploitation</title><content type="html">&lt;span class="byline-author"&gt;Posted by Chris Evans, Robert Swiecki, Michal Zalewski, and Billy Rios, Google Security Team&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
We’ve noticed some highly targeted and apparently politically motivated attacks against our users. We believe activists may have been a specific target. We’ve also seen attacks against users of another popular social site. All these attacks abuse a publicly-disclosed &lt;a href="http://lcamtuf.blogspot.com/2011/03/note-on-mhtml-vulnerability.html"&gt;MHTML vulnerability&lt;/a&gt; for which an exploit was publicly posted in January 2011. Users browsing with the Internet Explorer browser are affected.&lt;br /&gt;
&lt;br /&gt;
For now, we recommend concerned users and corporations seriously consider &lt;a href="http://support.microsoft.com/kb/2501696"&gt;deploying Microsoft’s temporary Fixit&lt;/a&gt; to block this attack until an official patch is available.&lt;br /&gt;
&lt;br /&gt;
To help protect users of our services, we have deployed various server-side defenses to make the MHTML vulnerability harder to exploit. That said, these are not tenable long-term solutions, and we can’t guarantee them to be 100% reliable or comprehensive.  We’re working with Microsoft to develop a comprehensive solution for this issue.&lt;br /&gt;
&lt;br /&gt;
The abuse of this vulnerability is also interesting because it represents a new quality in the exploitation of web-level vulnerabilities. To date, similar attacks focused on directly compromising users' systems, as opposed to leveraging vulnerabilities to interact with web&lt;br /&gt;
services.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1176949257541686127-6431747515119342935?l=googleonlinesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?a=AP2ld1uW5Ng:e0wkbYL8NQ8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?a=AP2ld1uW5Ng:e0wkbYL8NQ8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?i=AP2ld1uW5Ng:e0wkbYL8NQ8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/GoogleOnlineSecurityBlog/~4/AP2ld1uW5Ng" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://googleonlinesecurity.blogspot.com/feeds/6431747515119342935/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=1176949257541686127&amp;postID=6431747515119342935&amp;isPopup=true" title="28 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1176949257541686127/posts/default/6431747515119342935?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/1176949257541686127/posts/default/6431747515119342935?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/GoogleOnlineSecurityBlog/~3/AP2ld1uW5Ng/mhtml-vulnerability-under-active.html" title="MHTML vulnerability under active exploitation" /><author><name>Jay</name><uri>http://www.blogger.com/profile/08177113963774105206</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>28</thr:total><feedburner:origLink>http://googleonlinesecurity.blogspot.com/2011/03/mhtml-vulnerability-under-active.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CUYCRn4yfSp7ImA9WhRQEkQ.&quot;"><id>tag:blogger.com,1999:blog-1176949257541686127.post-3813461209748256544</id><published>2011-02-10T12:02:00.000-08:00</published><updated>2011-12-07T13:26:07.095-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-07T13:26:07.095-08:00</app:edited><title>Advanced sign-in security for your Google account</title><content type="html">&lt;span class="byline-author"&gt;Posted by Nishit Shah, Product Manager, Google Security&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;(Cross-posted from the &lt;a href="http://googleblog.blogspot.com/2011/02/advanced-sign-in-security-for-your.html"&gt;Official Google Blog&lt;/a&gt;)&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
Has anyone you know ever lost control of an email account and inadvertently sent spam—or worse—to their friends and family? There are plenty of examples (like the classic &lt;a href="http://gmailblog.blogspot.com/2010/03/detecting-suspicious-account-activity.html"&gt;"Mugged in London" scam&lt;/a&gt;) that demonstrate why it's important to take steps to help secure your activities online. Your Gmail account, your photos, your private documents—if you reuse the same password on multiple sites and one of those sites gets hacked, or your password is conned out of you directly through a phishing scam, it can be used to access some of your most closely-held information.&lt;br /&gt;
&lt;br /&gt;
Most of us are used to entrusting our information to a password, but we know that some of you are looking for something stronger. As we announced to our Google Apps customers &lt;a href="http://googleenterprise.blogspot.com/2010/09/more-secure-cloud-for-millions-of.html"&gt;a few months ago&lt;/a&gt;, we've developed an advanced opt-in security feature called &lt;i&gt;2-step verification&lt;/i&gt; that makes your Google Account significantly more secure by helping to verify that you're the real owner of your account. Now it's time to offer the same advanced protection to all of our users.&lt;br /&gt;
&lt;br /&gt;
2-step verification requires two independent factors for authentication, much like you might see on your banking website: your password, plus a code obtained using your phone. Over the next few days, you'll see a new link on your &lt;a href="https://www.google.com/accounts/ManageAccount"&gt;Account Settings page&lt;/a&gt; that looks like this:&lt;br /&gt;
&lt;div&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://2.bp.blogspot.com/-7ED-NjokTKA/Tt_YfAhMBcI/AAAAAAAAIx0/norP7_KGsmE/s1600/AccountSettings.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="251" src="http://2.bp.blogspot.com/-7ED-NjokTKA/Tt_YfAhMBcI/AAAAAAAAIx0/norP7_KGsmE/s400/AccountSettings.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style="text-align: center;"&gt;
&lt;br /&gt;&lt;/div&gt;
Take your time to carefully set up 2-step verification—we expect it may take up to 15 minutes to enroll. A user-friendly set-up wizard will guide you through the process, including setting up a backup phone and creating backup codes in case you lose access to your primary phone. Once you enable 2-step verification, you'll see an extra page that prompts you for a code when you sign in to your account. After entering your password, Google will call you with the code, send you an SMS message or give you the choice to generate the code for yourself using a mobile application on your Android, BlackBerry or iPhone device. The choice is up to you. When you enter this code after correctly submitting your password we'll have a pretty good idea that the person signing in is actually you.&lt;br /&gt;
&lt;div&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://1.bp.blogspot.com/-z1MrzrMJMxQ/Tt_YbIKoMFI/AAAAAAAAIxs/1OVcbqkNZ_o/s1600/step1and2.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/-z1MrzrMJMxQ/Tt_YbIKoMFI/AAAAAAAAIxs/1OVcbqkNZ_o/s500/step1and2.png" width="500" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style="text-align: center;"&gt;
&lt;br /&gt;&lt;/div&gt;
It's an extra step, but it's one that significantly improves the security of your Google Account because it requires the powerful combination of both something you &lt;i&gt;know&lt;/i&gt;—your username and password—and something that only you should &lt;i&gt;have&lt;/i&gt;—your phone. A hacker would need access to both of these factors to gain access to your account. If you like, you can always choose a "Remember verification for this computer for 30 days" option, and you won't need to re-enter a code for another 30 days. You can also set up one-time &lt;i&gt;application-specific passwords&lt;/i&gt; to sign in to your account from non-browser based applications that are designed to only ask for a password, and cannot prompt for the code.&lt;br /&gt;
&lt;br /&gt;
To learn more about 2-step verification and get started, visit our &lt;a href="http://www.google.com/support/accounts/bin/answer.py?answer=180744"&gt;Help Center&lt;/a&gt;. And for more about staying safe online, see our ongoing &lt;a href="http://googleblog.blogspot.com/search/label/security"&gt;security blog series&lt;/a&gt; or visit &lt;a href="http://www.staysafeonline.org/"&gt;http://www.staysafeonline.org/&lt;/a&gt;. Be safe!&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;&lt;b&gt;Update&lt;/b&gt;&lt;/i&gt; &lt;i&gt;Dec 7, 2011&lt;/i&gt;: Updated the screenshots in this post.&lt;/div&gt;
&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1176949257541686127-3813461209748256544?l=googleonlinesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?a=fKkli7_9uoI:O_Yo-66t3cI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?a=fKkli7_9uoI:O_Yo-66t3cI:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?i=fKkli7_9uoI:O_Yo-66t3cI:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/GoogleOnlineSecurityBlog/~4/fKkli7_9uoI" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://googleonlinesecurity.blogspot.com/feeds/3813461209748256544/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=1176949257541686127&amp;postID=3813461209748256544&amp;isPopup=true" title="15 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1176949257541686127/posts/default/3813461209748256544?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/1176949257541686127/posts/default/3813461209748256544?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/GoogleOnlineSecurityBlog/~3/fKkli7_9uoI/advanced-sign-in-security-for-your.html" title="Advanced sign-in security for your Google account" /><author><name>Jay</name><uri>http://www.blogger.com/profile/08177113963774105206</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-7ED-NjokTKA/Tt_YfAhMBcI/AAAAAAAAIx0/norP7_KGsmE/s72-c/AccountSettings.png" height="72" width="72" /><thr:total>15</thr:total><feedburner:origLink>http://googleonlinesecurity.blogspot.com/2011/02/advanced-sign-in-security-for-your.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CkEASH0yfSp7ImA9Wx5aFU8.&quot;"><id>tag:blogger.com,1999:blog-1176949257541686127.post-7782890792074920522</id><published>2010-11-11T16:10:00.000-08:00</published><updated>2010-11-11T16:10:49.395-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-11-11T16:10:49.395-08:00</app:edited><title>Quick update on our vulnerability reward program</title><content type="html">&lt;span class="byline-author"&gt;Posted by Matt Moore, Michal Zalewski, Adam Mein, Chris Evans; Google Security Team&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;About a week and a half ago we launched a new &lt;a href="http://googleonlinesecurity.blogspot.com/2010/11/rewarding-web-application-security.html"&gt;web vulnerability reward program&lt;/a&gt;, and the response has been fantastic. We've received many high quality reports from across the globe. Our bug review committee has been working hard, and we’re pleased to say that so far we plan to award over $20,000 to various talented researchers. We'll update our 'Hall of Fame' page with relevant details over the next few days.&lt;br /&gt;&lt;br /&gt;Based on what we've received over the past week, we've &lt;a href="http://www.google.com/corporate/rewardprogram.html"&gt;clarified&lt;/a&gt; a few things about the program — in particular, the types of issues and Google services that are in scope for a reward. The review committee has been somewhat generous this first week, and we’ve granted a number of awards for bugs of low severity, or that wouldn’t normally fall under the conditions we originally described. Please be sure to review our &lt;a href="http://googleonlinesecurity.blogspot.com/2010/11/rewarding-web-application-security.html"&gt;original post&lt;/a&gt; and &lt;a href="http://www.google.com/corporate/rewardprogram.html"&gt;clarification&lt;/a&gt; thoroughly before reporting a potential issue to us.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1176949257541686127-7782890792074920522?l=googleonlinesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?a=9TuxxKDEZNA:LAQenu_L3zM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?a=9TuxxKDEZNA:LAQenu_L3zM:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?i=9TuxxKDEZNA:LAQenu_L3zM:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/GoogleOnlineSecurityBlog/~4/9TuxxKDEZNA" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://googleonlinesecurity.blogspot.com/feeds/7782890792074920522/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=1176949257541686127&amp;postID=7782890792074920522&amp;isPopup=true" title="10 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1176949257541686127/posts/default/7782890792074920522?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/1176949257541686127/posts/default/7782890792074920522?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/GoogleOnlineSecurityBlog/~3/9TuxxKDEZNA/quick-update-on-our-vulnerability.html" title="Quick update on our vulnerability reward program" /><author><name>Jay</name><uri>http://www.blogger.com/profile/08177113963774105206</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>10</thr:total><feedburner:origLink>http://googleonlinesecurity.blogspot.com/2010/11/quick-update-on-our-vulnerability.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CUYNQ3w8fyp7ImA9Wx5aF0o.&quot;"><id>tag:blogger.com,1999:blog-1176949257541686127.post-7147046743093191966</id><published>2010-11-01T12:30:00.000-07:00</published><updated>2010-11-14T14:19:52.277-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-11-14T14:19:52.277-08:00</app:edited><title>Rewarding web application security research</title><content type="html">&lt;span class="byline-author"&gt;Posted by Chris Evans, Neel Mehta, Adam Mein, Matt Moore, and Michal Zalewski; Google Security Team&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Back in January of this year, the Chromium open source project &lt;a href="http://blog.chromium.org/2010/01/encouraging-more-chromium-security.html"&gt;launched a well-received vulnerability reward program&lt;/a&gt;. In the months since launch, researchers reporting a wide range of great bugs have received rewards — a small summary of which can be found in the &lt;a href="http://dev.chromium.org/Home/chromium-security/hall-of-fame"&gt;Hall of Fame&lt;/a&gt;. We've seen a sustained increase in the number of high quality reports from researchers, and their combined efforts are contributing to a more secure Chromium browser for millions of users.&lt;br /&gt;&lt;br /&gt;Today, we are announcing an experimental new vulnerability reward program that applies to Google web properties. We already enjoy working with an array of researchers to improve Google security, and some individuals who have provided high caliber reports are listed on &lt;a href="http://www.google.com/corporate/security.html"&gt;our credits page&lt;/a&gt;. As well as enabling us to thank regular contributors in a new way, we hope our new program will attract new researchers and the types of reports that help make our users safer.&lt;br /&gt;&lt;br /&gt;In the spirit of the original Chromium blog post, we have some information about the new program in a question and answer format below:&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Q) What applications are in scope?&lt;/b&gt;&lt;br /&gt;A) Any Google web properties which display or manage highly sensitive authenticated user data or accounts may be in scope. Some examples could include:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;*.google.com&lt;/li&gt;&lt;li&gt;*.youtube.com&lt;/li&gt;&lt;li&gt;*.blogger.com&lt;/li&gt;&lt;li&gt;*.orkut.com&lt;/li&gt;&lt;/ul&gt;For now, Google's client applications (e.g. Android, Picasa, Google Desktop, etc) are not in scope. We may expand the program in the future.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;UPDATE: We also recommend reading our &lt;a href="http://www.google.com/corporate/rewardprogram.html"&gt;additional thoughts&lt;/a&gt; about these guidelines to help clarify what types of applications and bugs are eligible for this program.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Q) What classes of bug are in scope? &lt;/b&gt;&lt;br /&gt;A) It's difficult to provide a definitive list of vulnerabilities that will be rewarded; however, any serious bug which directly affects the confidentiality or integrity of user data may be in scope. We anticipate most rewards will be in bug categories such as:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;XSS&lt;/li&gt;&lt;li&gt;XSRF / CSRF&lt;/li&gt;&lt;li&gt;XSSI (cross-site script inclusion)&lt;/li&gt;&lt;li&gt;Bypassing authorization controls (e.g. User A can access User B's private data)&lt;/li&gt;&lt;li&gt;Server side code execution or command injection&lt;/li&gt;&lt;/ul&gt;Out of concern for the availability of our services to all users, we ask you to refrain from using automated testing tools.&lt;br /&gt;&lt;br /&gt;These categories of bugs are definitively excluded:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;attacks against Google’s corporate infrastructure&lt;/li&gt;&lt;li&gt;social engineering and physical attacks&lt;/li&gt;&lt;li&gt;denial of service bugs&lt;/li&gt;&lt;li&gt;non-web application vulnerabilities, including vulnerabilities in client applications&lt;/li&gt;&lt;li&gt;SEO blackhat techniques&lt;/li&gt;&lt;li&gt;vulnerabilities in Google-branded websites hosted by third parties&lt;/li&gt;&lt;li&gt;bugs in technologies recently acquired by Google&lt;/li&gt;&lt;/ul&gt;&lt;b&gt;Q) How far should I go to demonstrate a vulnerability?&lt;/b&gt;&lt;br /&gt;A) Please, only ever target your own account or a test account. Never attempt to access anyone else's data. Do not engage in any activity that bombards Google services with large numbers of requests or large volumes of data.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Q) I've found a vulnerability — how do I report it?&lt;/b&gt;&lt;br /&gt;A) Contact details are &lt;a href="http://www.google.com/corporate/security.html"&gt;listed here&lt;/a&gt;. Please only use the email address given for actual vulnerabilities in Google products. Non-security bugs and queries about problems with your account should should instead be directed to the &lt;a href="http://www.google.com/support/"&gt;Google Help Centers&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Q) What reward might I get?&lt;/b&gt;&lt;br /&gt;A) The base reward for qualifying bugs is $500. If the rewards panel finds a particular bug to be severe or unusually clever, rewards of up to $3,133.7 may be issued. The panel may also decide a single report actually constitutes multiple bugs requiring reward, or that multiple reports constitute only a single reward.&lt;br /&gt;&lt;br /&gt;We understand that some researchers aren’t interested in the money, so we’d also like to give you the option to donate your reward to charity. If you do, we'll match it — subject to our discretion.&lt;br /&gt;&lt;br /&gt;Regardless of whether you're rewarded monetarily or not, all vulnerability reporters who interact with us in a respectful, productive manner will be credited on a new vulnerability reporter page. If we file a bug internally, you'll be credited.&lt;br /&gt;&lt;br /&gt;Superstar performers will continue to be acknowledged under the "We Thank You" section of &lt;a href="http://www.google.com/corporate/security.html"&gt;this&lt;/a&gt; page.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Q) How do I find out if my bug qualified for a reward?&lt;/b&gt;&lt;br /&gt;A) You will receive a comment to this effect in an emailed response from the Google Security Team.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Q) What if someone else also found the same bug&lt;/b&gt;?&lt;br /&gt;A) Only the first report of a given issue that we had not yet identified is eligible. In the event of a duplicate submission, only the earliest received report is considered.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Q) Will bugs disclosed without giving Google developers an opportunity to fix them first still qualify?&lt;/b&gt;&lt;br /&gt;A) &lt;a href="http://googleonlinesecurity.blogspot.com/2010/07/rebooting-responsible-disclosure-focus.html"&gt;We believe&lt;/a&gt; handling vulnerabilities responsibly is a two-way street. It's our job to fix serious bugs within a reasonable time frame, and we in turn request advance, private notice of any issues that are uncovered. Vulnerabilities that are disclosed to any party other than Google, except for the purposes of resolving the vulnerability (for example, an issue affecting multiple vendors), will usually not qualify. This includes both full public disclosure and limited private release.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Q) Do I still qualify if I disclose the problem publicly once fixed?&lt;/b&gt;&lt;br /&gt;A) Yes, absolutely! We encourage open collaboration. We will also make sure to credit you on our new vulnerability reporter page.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Q) Who determines whether a given bug is eligible?&lt;/b&gt;&lt;br /&gt;A) Several members of the Google Security Team including Chris Evans, Neel Mehta, Adam Mein, Matt Moore, and Michal Zalewski.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Q) Are you going to list my name on a public web page?&lt;/b&gt;&lt;br /&gt;A) Only if you want us to. If selected as the recipient of a reward, and you accept, we will need your contact details in order to pay you. However, at your discretion, you can choose not to be listed on any credit page.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Q) No doubt you wanted to make some legal points?&lt;/b&gt;&lt;br /&gt;A) Sure. We encourage broad participation. However, we are unable to issue rewards to individuals who are on sanctions lists, or who are in countries (e.g. Cuba, Iran, North Korea, Sudan and Syria) on sanctions lists. This program is also not open to minors. You are responsible for any tax implications depending on your country of residency and citizenship. There may be additional restrictions on your ability to enter depending upon your local law.&lt;br /&gt;&lt;br /&gt;This is not a competition, but rather an experimental and discretionary rewards program. You should understand that we can cancel the program at any time, and the decision as to whether or not to pay a reward has to be entirely at our discretion.&lt;br /&gt;&lt;br /&gt;Of course, your testing must not violate any law, or disrupt or compromise any data that is not your own.&lt;br /&gt;&lt;br /&gt;Thank you for helping us to make Google's products more secure. We look forward to issuing our first reward in this new program.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1176949257541686127-7147046743093191966?l=googleonlinesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?a=BnoaH_jIsLA:t_LeTNlTvT0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?a=BnoaH_jIsLA:t_LeTNlTvT0:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?i=BnoaH_jIsLA:t_LeTNlTvT0:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/GoogleOnlineSecurityBlog/~4/BnoaH_jIsLA" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://googleonlinesecurity.blogspot.com/feeds/7147046743093191966/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=1176949257541686127&amp;postID=7147046743093191966&amp;isPopup=true" title="30 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1176949257541686127/posts/default/7147046743093191966?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/1176949257541686127/posts/default/7147046743093191966?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/GoogleOnlineSecurityBlog/~3/BnoaH_jIsLA/rewarding-web-application-security.html" title="Rewarding web application security research" /><author><name>Jay</name><uri>http://www.blogger.com/profile/08177113963774105206</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>30</thr:total><feedburner:origLink>http://googleonlinesecurity.blogspot.com/2010/11/rewarding-web-application-security.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CUUCSHo_fyp7ImA9Wx5UFkQ.&quot;"><id>tag:blogger.com,1999:blog-1176949257541686127.post-3635103819389992565</id><published>2010-10-21T11:33:00.000-07:00</published><updated>2010-10-21T13:34:29.447-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-10-21T13:34:29.447-07:00</app:edited><title>This Internet is Your Internet: Digital Citizenship from California to Washtenaw County</title><content type="html">&lt;span class="byline-author"&gt;Posted by Adrienne St. Aubin, Public Policy Analyst&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;In the physical world, basic safety measures are second-nature to almost everyone (look both ways, stop drop and roll!). In the digital world, however, many of us expect security to be handled on our behalf by experts, or come in a single-box solution. Together, we must reset those expectations.&lt;br /&gt;&lt;br /&gt;The Internet is the biggest neighborhood in the world. Security-related initiatives in the technology sector and government play an important role in making the Internet safer, but efforts from Silicon Valley and Washington, D.C. alone are not enough. Much of the important work that needs to be done must happen closer to home—wherever that may be.&lt;br /&gt;&lt;br /&gt;As part of &lt;a href="http://googleblog.blogspot.com/2010/10/national-cyber-security-awareness-month.html"&gt;National Cyber Security Awareness Month&lt;/a&gt; I recently traveled from California to Washtenaw County, MI to speak to group of local community leaders, educators, business owners, law enforcement officials and residents who recently formed the &lt;a href="http://washtenawcybercoalition.org/"&gt;Washtenaw Cyber Citizenship Coalition&lt;/a&gt;. They are working to create a digitally aware, knowledgeable and more secure community by providing residents with the tools and resources to be good digital citizens. No one in the room self-identified as a “cyber security expert,” but the information sharing that’s happening in Washtenaw County is the kind of holistic effort that can enable everyone to use the Internet more safely and benefit from the great opportunities that it provides.&lt;br /&gt;&lt;br /&gt;The Washtenaw Cyber Citizenship Coalition is channeling the community’s efforts through volunteer workgroups in areas such as public/private partnerships, awareness, education and law enforcement. Their strategy is to “share the wheel" whenever possible, instead of recreating it. They’ve collected tips and resources for kids, parents, businesses, educators and crime victims so that citizens can find and access these materials with ease.&lt;br /&gt;&lt;br /&gt;If you are interested in raising awareness in your own community, &lt;a href="http://www.staysafeonline.org/"&gt;staysafeonline.org&lt;/a&gt;, &lt;a href="http://www.stopthinkconnect.org"&gt;stopthinkconnect.org&lt;/a&gt; and &lt;a href="http://www.onguardonline.gov"&gt;onguardonline.gov&lt;/a&gt; are examples of sites that offer such materials for public use.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1176949257541686127-3635103819389992565?l=googleonlinesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?a=ELRlAGc6qZs:A-sJE9C8NKk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?a=ELRlAGc6qZs:A-sJE9C8NKk:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?i=ELRlAGc6qZs:A-sJE9C8NKk:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/GoogleOnlineSecurityBlog/~4/ELRlAGc6qZs" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://googleonlinesecurity.blogspot.com/feeds/3635103819389992565/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=1176949257541686127&amp;postID=3635103819389992565&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1176949257541686127/posts/default/3635103819389992565?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/1176949257541686127/posts/default/3635103819389992565?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/GoogleOnlineSecurityBlog/~3/ELRlAGc6qZs/this-internet-is-your-internet-digital.html" title="This Internet is Your Internet: Digital Citizenship from California to Washtenaw County" /><author><name>Jay</name><uri>http://www.blogger.com/profile/08177113963774105206</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://googleonlinesecurity.blogspot.com/2010/10/this-internet-is-your-internet-digital.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0EDQXkycSp7ImA9Wx5UEUs.&quot;"><id>tag:blogger.com,1999:blog-1176949257541686127.post-2216743235851549551</id><published>2010-10-15T09:38:00.000-07:00</published><updated>2010-10-15T09:54:30.799-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-10-15T09:54:30.799-07:00</app:edited><title>Protecting your data in the cloud</title><content type="html">&lt;span class="byline-author"&gt;Posted by Priya Nayak, Consumer Operations, Google Accounts&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Like many people, you probably store a lot of important information in your Google Account. I personally check my Gmail account every day (sometimes several times a day) and rely on having access to my mail and contacts wherever I go. Aside from Gmail, my Google Account is tied to lots of other services that help me manage my life and interests: photos, documents, blogs, calendars, and more. That is to say, my Google Account is very valuable to me.&lt;br /&gt;&lt;br /&gt;Unfortunately, a Google Account is also valuable in the eyes of spammers and other people looking to do harm. It’s not so much about your specific account, but rather the fact that your friends and family see your Google Account as trustworthy. A perfect example is the &lt;a href="http://gmailblog.blogspot.com/2010/03/detecting-suspicious-account-activity.html"&gt;“Mugged in London” phishing scam&lt;/a&gt; that aims to trick your contacts into wiring money — ostensibly to help you out. If your account is compromised and used to send these messages, your well-meaning friends may find themselves out a chunk of change. If you have sensitive information in your account, it may also be at risk of improper access.&lt;br /&gt;&lt;br /&gt;As part of &lt;a href="http://googleblog.blogspot.com/2010/10/national-cyber-security-awareness-month.html"&gt;National Cyber Security Awareness month&lt;/a&gt;, we want to let you know what you can do to better protect your Google Account.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Stay one step ahead of the bad guys&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Account hijackers prey on the bad habits of the average Internet user. Understanding common hijacking techniques and using better security practices will help you stay one step ahead of them.&lt;br /&gt;&lt;br /&gt;The most common ways hijackers can get access to your Google password are:&lt;div&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;Password re-use&lt;/b&gt;: You sign up for an account on a third-party site with your Google username and password. If that site is hacked and your sign-in information is discovered, the hijacker has easy access to your Google Account.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Malware&lt;/b&gt;: You use a computer with infected software that is designed to steal your passwords as you type (“keylogging”) or grab them from your browser’s cache data.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Phishing&lt;/b&gt;: You respond to a website, email, or phone call that claims to come from a legitimate organization and asks for your username and password.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Brute force&lt;/b&gt;: You use a password that’s easy to guess, like your first or last name plus your birth date (“Laura1968”), or you provide an answer to a secret question that’s common and therefore easy to guess, like “pizza” for “What is your favorite food?”&lt;/li&gt;&lt;/ul&gt;As you can see, hijackers have many tactics for stealing your password, and it’s important to be aware of all of them.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Take control of your account security across the web &lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Online accounts that share passwords are like a line of dominoes: When one falls, it doesn’t take much for the others to fall, too. This is why you should choose unique passwords for important accounts like Gmail (your Google Account), your bank, commerce sites, and social networking sites. We’re also &lt;a href="http://googleonlinesecurity.blogspot.com/2010/09/moving-security-beyond-passwords.html"&gt;working on technology&lt;/a&gt; that adds another layer of protection beyond your password to make your Google Account significantly more secure.&lt;br /&gt;&lt;br /&gt;Choosing a unique password is not enough to secure your Google Account against every possible threat. That’s why we’ve created an easy-to-use &lt;a href="http://mail.google.com/support/bin/static.py?page=checklist.cs&amp;amp;tab=29488"&gt;checklist&lt;/a&gt; to help you secure your computer, browser, Gmail, and Google Account. We encourage you to go through the entire checklist, but want to highlight these tips:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;Never re-use passwords&lt;/b&gt; for your important accounts like online banking, email, social networking, and commerce.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Change your password periodically&lt;/b&gt;, and be sure to do so for important accounts whenever you suspect one of them may have been at risk. Don’t just change your password by a few letters or numbers (“Aquarius5” to “Aquarius6”); change the combination of letters and numbers to something unique each time.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Never respond to messages, non-Google websites, or phone calls&lt;/b&gt; asking for your Google username or password; a legitimate organization will not ask you for this type of information. &lt;a href="http://mail.google.com/support/bin/answer.py?hl=en&amp;amp;answer=184963"&gt;Report these messages&lt;/a&gt; to us so we can take action. If you responded and can no longer access your account, &lt;a href="https://www.google.com/accounts/recovery?hl=en"&gt;visit our account recovery page&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;We hope you’ll take action to ensure your security across the web, not just on Google. Run regular virus scans, don’t re-use your passwords, and keep your software and &lt;a href="http://www.google.com/support/accounts/bin/answer.py?hl=en&amp;amp;answer=183723"&gt;account recovery information&lt;/a&gt; up to date. These simple yet powerful steps can make a difference when it really counts.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1176949257541686127-2216743235851549551?l=googleonlinesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?a=fgyhovHUKp4:rnZg4SUYhXw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?a=fgyhovHUKp4:rnZg4SUYhXw:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/GoogleOnlineSecurityBlog?i=fgyhovHUKp4:rnZg4SUYhXw:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/GoogleOnlineSecurityBlog/~4/fgyhovHUKp4" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://googleonlinesecurity.blogspot.com/feeds/2216743235851549551/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=1176949257541686127&amp;postID=2216743235851549551&amp;isPopup=true" title="29 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1176949257541686127/posts/default/2216743235851549551?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/1176949257541686127/posts/default/2216743235851549551?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/GoogleOnlineSecurityBlog/~3/fgyhovHUKp4/protecting-your-data-in-cloud.html" title="Protecting your data in the cloud" /><author><name>Jay</name><uri>http://www.blogger.com/profile/08177113963774105206</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>29</thr:total><feedburner:origLink>http://googleonlinesecurity.blogspot.com/2010/10/protecting-your-data-in-cloud.html</feedburner:origLink></entry></feed>

