Showing posts with label Google. Show all posts
Showing posts with label Google. Show all posts

Wednesday, 5 September 2018

MEGA Warns Against An Infected Chrome Extension That Steals Data



The popular cloud storage service MEGA has warned users of an infected version of its own Chrome extension that was distributed through the official download channel and tried to steal all kinds of user data. According to MEGA, the cloud storage service of internet entrepreneur Kim Dotcom, an attacker has gained access to the official Chrome Web Store account of the company.

Then an infected version of the MEGA Chrome extension was placed in the Web Store and automatically offered to existing users. This version required permission to read data on all websites. As soon as users granted this permission, the extension tried to steal private keys for cryptocurrency wallets and user names and passwords for Amazon, GitHub, Google and Microsoft accounts.

After five hours, the infected Chrome extension was removed from the Chrome Web Store by Google. MEGA states that it has initiated an investigation to find out how the Web Store account could be taken over. The cloud storage service also gets to Google because it does not allow developers to sign their Chrome extensions. The extensions are now automatically signed after being uploaded to the Chrome Web Store. According to MEGA, this will remove an important measure that must protect against attackers.

Before MEGA gave the warning, Jeremy Nation of MetaCert already came up with an analysis of the infected extension. It is not the first time that attackers get access to the Web Store account of an extension developer and then distribute an infected update or version. At the end of last year, eight Chrome extensions were discovered that had been hacked and adware was installed by the 4.6 million users. The attackers had been able to trace the login data for the Web Store through these phishing attacks.

Tuesday, 4 September 2018

Mozilla's New VP Will Focus On Privacy & Security



Mozilla has a new security chief who will focus on privacy and security. Alan Davidson is the new vice president for "Policy, Trust and Security" with the open source developer. He will be responsible for promoting an open internet and a 'healthy web'.

He will also lead a 'trust and security' team that will focus on promoting innovative privacy and security features in Mozilla products. Previously, Davidson worked at the US Department of Commerce and in 2011 he was the policy leader at Google. "I am very happy to work for an organization that is so dedicated to putting the user first", Davidson said.

Thursday, 15 March 2018

Google Removed 3.2 Billion Malicious Ads In 2017



Last year, Google removed more than 3.2 billion malicious ads because they tried to infect Internet users with malware, went to phishing sites, committed advertising fraud, or for other reasons - more than 100 ads removed per second.

For example, 79 million advertisements were removed because they sent internet users to websites with malware. Google removed another 48 million ads because they let users install unwanted software. Furthermore, 66 million "trick-to-click" ads were removed. In addition to advertising, 320,000 of the advertising network were also banned and Google decided to blacklist 90,000 websites and 700,000 mobile apps.

Wednesday, 25 October 2017

Researchers Crack Google's Audio Captcha


Researchers have managed to crack Google's audio captcha with an average of 85 percent accuracy, allowing bots to automatically create accounts on websites and place spam messages. To distinguish robots from people, captcha's often need to solve puzzles and distorted texts. The captcha of Google also allows users to resolve an audio captcha.

The audio captcha consists of multiple digits read in different speeds, accents and pitches with background noise. Researchers at the University of Maryland devised an attack targeting Google's audio captcha. To crack the audio captcha, the researchers developed " unCaptcha ", software that downloads the captcha audio file and then splits the parts with voice.


The split audio fragment of each digit is then sent to six free online audio transcription services, including Google's. Based on the different results, which figure was read in the audio clip. The results are then entered 'organic' by the software in the captcha window. On average, the software knows how to solve the captcha with 85 percent accuracy. After the researchers published their research ( pdf ), Google has taken various measures that limit the effectiveness of unCaptcha.

Tuesday, 24 October 2017

Lenovo Provides Computers With FIDO Authenticators



Lenovo has provided various computer models of so-called FIDO authenticators that let users login their accounts via a fingerprint scan or click on a prompt on the screen. The Fast IDentity Online (FIDO) Alliance has set itself the goal of replacing the password with authentication methods that are "safer and user-friendly."

Lenovo is one of the FIDO members, among other things, Google, Microsoft, MasterCard and PayPal. The parties involved develop products and services that make use of the FIDO protocol. This would automatically recognize devices that support FIDO and allow users to replace passwords by another authentication method.

Lenovo now claims that it is the first PC manufacturer to integrate directly into Windows computers by FIDO certified authenticators. Instead of a password to log in, users can choose from an alternative. For example, a fingerprint scan can be logged through the Universal Authentication Framework (UAF). In addition, the system also supports Universal 2nd Factor (U2F).

In case a user has enabled two-factor authentication for his account, it is no longer necessary to enter a separate security key or SMS. The two-factor authentication is built directly into the computer. In the case of two-factor authentication via U2F, users get a prompt to confirm, after which they are logged in to their account. This login method is supported by Google, Facebook and Dropbox.

To support UAF and U2F, Lenovo uses Intel Online Connect and Intel Software Guard Extensions (Intel SGX) on the latest Intel processors. The functionality will be delivered with different computer models and available for all models delivered. Intel Online Connect is available for download from Lenovo's website and will be available through Lenovo System Update and Lenovo App Explorer.

Thursday, 5 May 2016

Google: Virustotal Not Intended To Compare Anti-Virus


VirusTotal is a popular service from Google that charge suspicious files can be scanned by dozens of virus, but to keep health service and to prevent abuse have now announced new rules and users are reminded of their responsibilities.

According to Google VirusTotal is a nice collaboration between anti-virus companies and users. Users upload suspicious files, which are then shared with the anti-virus companies. "It's an ecosystem where everyone contributes, everyone benefits, and we work together to improve safety on the Internet," said Bernardo Quintero.

Rules

To ensure that the ecosystem is in good working there new rules announced. So all anti-virus companies are obliged to integrate their detection scanner in the public interface of VirusTotal. New scanners wishing to apply must first be able to present a certification or independent reviews of security testers, with the best practices of the Anti-Malware Testing Standards Organization (AMTSO) followed by VirusTotal.

Additionally VirusTotal users must follow the requirements and best practices, let Google know. "It's frustrating to see abuse and is detrimental to our community," said Quintero. He points out that VirusTotal is not substitute for a virus. In addition, the service must also not be used to compare virus scanners with each other. "Virus scanners are complex programs on additional detection properties which may not operate within the scanning area of ​​VirusTotal. Therefore, the scanning results from VirusTotal are not designed to compare the effectiveness of anti-virus products," Quintero says.

Wednesday, 4 May 2016

Google Encrypts All Traffic To blogs On Blogspot



Google has decided to encrypt all traffic to the blogs on its own Blogspot blogging service. In September last year the Internet giant began offering the option for bloggers to activate it yourself. This option has now been removed and traffic to all blogs are now encrypted.

There is also a new option available for bloggers called "HTTPS Redirect", making it possible to enable all visitors to the HTTP version of the blog visit automatically redirected to the https version. In case the option is disabled, it is possible to visit the blog via both http and https. Google warns however for mixed content that may not work properly the https version of the blogs.

It is in this case content such as images, gadgets, ads or templates that are invoked via http. In the case of an https site may cause a mixed content warning. Google argues that it can solve many of these problems, but some must be resolved by the bloggers themselves. To help bloggers and administrators with this, there is now a special tool launched to find mixed content into blogs and posts.

Tuesday, 19 April 2016

Adobe: Flash Player Security Thwart Hackers


Adobe security measures in recent months have added to Flash Player ensures that hackers could not carry out successful attacks on the media player during a recent hacking contest, as the software company announced.

During the annual Pwn2Own contest hackers are rewarded for demonstrating unknown vulnerabilities in different browsers and Adobe Flash Player. During the last edition of March Flash Player was finally twice successfully hacked , but that number could be higher, says Peleus Uhley of Adobe. In preparation for the hack contest Adobe rolled several updates to enhance the security of Flash Player.

These measures paid off as several attempts to hack Flash Player failed thus said Uhley. Still, Flash Player has been successfully hacked twice. "These victories show that there is always more vendors can do to improve security," he continues. Uhley notes that companies such as Adobe, Microsoft and Google are engaged in a race with hackers.

Adobe invests in his own words than a lot of security and regularly adds features to thwart it. hackers as only goal. "Such measures are increasingly being added. The companies themselves will change on the frontline of this battle and to grow the more expensive." According Uhley help hacking contests like Pwn2Own software companies to develop. "While Pwn2Own each year seems to take the same required innovations and challenges to books every year results," said Uhley.

Google Helps Owners Hacked Websites With Maid


If Google webmasters and owners of a hacked website helps to existing vulnerabilities and malicious code quickly resolved, according to research. According to Google , more than 10 million Internet users every week with malicious Web sites in touch.

It often involves hacked websites which install owner or webmaster failed security updates or to choose a strong password.This makes it easy for cyber criminals to take over a website and use for example distributing malware. Google warns Internet users of such web sites, but many webmasters do not follow the Internet giant by that something is wrong.

And even if they are informed of the security incident, they miss to overcome the knowledge to solve the problem. Google therefore decided to look together with the University of California at Berkeley how webmasters can be best informed and the problem as soon as possible can be resolved. From the research shows that if Google cooperates directly with the webmaster, 75% of webmasters manages to secure their website. A process that takes an average of three days.

To help webmasters soon be considered by investigators three important steps. The first and most difficult step is to inform the webmaster. In the case webmasters their website via Webmaster Tools have registered a Google mail ensures that 75% of webmasters secures the website. In the case of the webmaster is unknown the e-mail address, have browser warnings and alerts in the search engine a success rate of 54% and 43%.

The second step in the process is to give hints about the harmful content. Attackers often hide their files, which complicates the cleaning process. In the event Google tips on the infection to the webmaster e-mailed this made sure that the cleaning sheet was 62% faster than warnings without tips. The third step is to make sure that continues to clean the site. Google investigated and cleaned hacked websites and found that 12% had been hacked again within 30 days. That shows, according to the Internet giant how important it is to find the cause of a hack rather than to remedy the effects.

New York Police Launch Campaign Against Encryption



The police force of New York 's Manhattan along with the Attorney General and various organizations for crime victims a campaign against encryption starts. According to the initiators of the campaign "#UnlockJustice 'it is important to highlight the impact of encryption for public safety and crime victims.

"The debate over encryption is often determined by privacy and security, where there is no thought about the impact on victims," ​​said Attorney General Manhattan Cyrus Vance. "That narrow view ignores the impact of encryption for the investigation and prosecution of crimes." According to Vance all consumer must be able to be searched by investigators.

Apple and Google have, however, ensured that this is not currently the case, he said. "Congress should not allow companies to make devices that against his injunctions file. Companies should not be allowed to give criminals a place where they can go about their business. Victims of crime are entitled to greater protection than criminals."

According to Police Commissioner William Bratton undermines the existence of devices for which a court order is not the justice system applies. "This is a crisis in the making and goes beyond a single terror case. Providing shelter for pedophiles, rapists and murderers through their mobile phone affects unprecedented casualties. This exception of the judicial system is unsustainable and must be corrected immediately . "

In addition, hundreds of the initiators point for devices that can not be searched. Through the campaign, they hope to educate the public about this. The created for the campaign hashtag was quickly adopted by proponents of encryption. "People deserve better protection than criminals. Standard strong encryption protects citizens against robbers and thieves," said security expert The Grugq . Other Twitter users claim that it is a campaign of misinformation and encryption just helps in protecting data.

Thursday, 11 February 2016

Google Stops From 2017 With Flash Ads


From January 2017 Google stops displaying Flash ads on their own ad networks, such as the Google Display Network and DoubleClick, as the Internet giant has over Google Plus disclosed. According to Google, it's important for advertisers to switch to HTML5 ads, so many people can be reached.

To accelerate this process will AdWords and DoubleClick Digital Marketing from June 30 to accept new Flash ads this year.From January 2, 2017 Flash ads will no longer be on the Google Display Network are displayed via DoubleClick. Google warns advertisers that they should have converted their ads to HTML5 for these dates. For now, the new measure does not affect video ads created in Flash.

Google has long been working to make Flash unnecessary. As YouTube videos are automatically played through HTML5. In the case of Flash ads that are distributed through AdWords, which are automatically converted to HTML5 since February last year. Since September 1st of last year, most Flash ads automatically in Google Chrome paused .

Last year, also called Alex Stamos, the new Chief Security Officer (CSO) of Facebook, which with Adobe Flash technology to stop , so that it can be switched completely on HTML5. HTML5 is natively supported by modern browsers and allows playback of videos and other "rich content" without installing additional plug-ins possible.

Wednesday, 10 February 2016

Gmail Notifies Users Of Unencrypted Messages



Google Gmail users will now warn if they receive unencrypted messages, as the Internet giant has on Safer Internet Day 2016 announced . Google itself uses TLS encryption for encrypting messages. Gmail users can send encrypted messages to each other in this way. TLS is not yet used by all email providers.

This allows messages that Gmail users received via this e-mail providers, or send to this, be read. Gmail will therefore present a warning showing that the email provider of the addressee no encryption support, or if a message is received that is not encrypted via TLS. There will also be a warning if the sender's domain could not be authenticated. Gmail recently did not know that more and more support major email providers tls and domain authentication.


From investigation of Google, the University of Michigan and the University of Illinois show that from December 2013 to October 2015 the number of encrypted emails rose Gmail non-Gmail users received from 33% to 61%. In the same period, the number of emails were encrypted using TLS and Gmail to non-Gmail users was sent from 60% to 80%. Further uses 94% of the incoming email for Gmail, a form of authentication to protect against phishing and spoofing.

John Rae-Grant Google argues that not all e-mails which warned is dangerous. "But we advise you to be extra careful when answering or opening links in messages that you have doubts about. And by this update, you have the resources to make that decision."

Tuesday, 1 December 2015

Linux Ransomware Encrypts 3000 Websites



In recent weeks there have been the ransomware which it has provided encrypted hit 3,000 websites on Linux web servers. This places the Russian anti-virus company Doctor Web, which relies on weather data from Google. It is called ransomware Linux.encoder.

Attackers behind ransomware deliberately set WordPress websites and online stores using Magento. Through a still unknown vulnerability know the attackers to gain access to the Web server that hosts the website and then perform Linux.encoder.This ransomware, which additional duties require encrypts all kinds of files, and then asks one bitcoin, what with the current exchange rate is 349 euros. It is unknown how many webmasters have finally paid the ransom.

F-Secure reported in early November, about 36 people had paid, which at that time corresponded to an amount of 12,000 euros. Due to an error encrypted files can be decrypted without paying. The Romanian anti-virus company BitDefender has developed a free decryption tool for victims. From examination of the virus fighter shows that an early version of ransomware already was distributed on August 25 of this year and then seven people paid the ransom.

Thursday, 19 November 2015

Amazon Makes Two-Factor Authentication


Amazon has quietly for the shop two-factor authentication enabled. The option is currently still stand out. Logging in Amazon normally goes with a username and password. But for added security, users can now also receive a code on their phone they have to fill in the login.

The introduction of two-factor authentication will the attackers more difficult for someone else to log on because they need to know in this case, both username and password, but also have access to the smartphone.

An employee of Engadget discovered the new option this week. According to reports on Twitter, Amazon would be the new two-factor identification introduced about two weeks ago.

Two-factor authentication is a widely used method to prevent abuse of login data. Other major Internet companies that offer this login method, include Google, Twitter and Facebook.

Who at Amazon wants to use the two-factor authentication, should go to their account settings and select it by changing the settings for 'advanced settings'.

Wednesday, 18 November 2015

Gmail App Allows Spoofing


The Gmail app for Android installed already standard on many smart phones, enables users to send spoof emails. Google acknowledges the findings, but still taking no steps to remedy it.

Security Researcher Yan Zhu discovered that it is possible in the Gmail app to send emails from a fake sender address. The trick is very simple and will only work with the Gmail app for Android.


If the display name is changed in the settings, the app itself removes the real address from which the message is sent. For the receiver it is therefore difficult to check the sender via the headers. For demonstration Zhu sent a mail from the account security@google.com.

Although not found bug is serious, it can easily be abused. Spoofing is a technique widely used by cyber criminals to lure potential victims to a particular site.

Yan Zhu its findings in late October when Google reported, writes Motherboard, but who denies that this is a vulnerability.

Monday, 9 November 2015

Police Raided Researcher Link From Script Kiddie Opened

An American system and security researcher who has lived in Austria had to deal with a police raid after his own words opened a link from a script kiddie. Christian Haschek decided to visit an IRC channel of the hacker collective Lulzsec.

There he made contact with a boy who had discovered Nikto, a tool to help search automatically for vulnerabilities in Web servers. "It was a nice guy, but obviously a script kiddie, so I did not too long talk with him," said Haschek. A few hours later he was approached by the boy through a private chat and was sent to a link. It was the address of a political party behind it a directory called 'tools'. Directory listing was switched so that all files in the directory were visible. The researcher claims to have a number of files opened, but it seemed to him as a folder where the webmaster had placed a number of files that may have been linked elsewhere on this website.

Because Haschek only wanted to chat on IRC he used to have no VPN or proxy. "And usually I open any links, but in this case seemed to link legitimate and not suspicious." He thought therefore no more about it until the next day he read in the media that the website of a political party was hacked. The same website that he had visited the night before. The attacker had usernames, email addresses and hashed passwords found and posted on Pastebin. "The kiddie had clearly found an exploit in the tools directory and used to access the server," says the researcher.

Police raid

Four months passed and Haschek had already forgotten the incident until he came home and the police anti-terror officers and a prosecutor encountered. The police claimed that they had evidence that he had hacked the website of the political party and they had a search warrant. "They thought I was the script kiddie and that my VPN any time had not worked and she therefore saw my public IP address." The police also asked for his password and encrypted data that he had on his computer, which was not the case.

Haschek stated that he had only the link from the script kiddie opened and that he had not used a VPN because he had done nothing illegal. The police revealed the investigator to have followed for weeks and drained in order if possible to identify the leaders. Eventually took all his computers, hard drives, USB sticks and laptops. In addition, he was told that his property would probably recover a year later. When the incident occurred not know exactly Haschek late, but he reports that he is indeed back a year later got everything.

Dropbox

"By a happy coincidence, I had all my personal and business files a few days before the invasion put in Dropbox," he observes. The police let the investigator know that they cloud data not like it, because they have to get an international warrant to retrieve the data to Google or Dropbox. Eighteen months after the incident, the Austrian Public Prosecutor's Office decided to drop the case to Haschek nothing was wrong. However, he had to buy a new computer because the police who held him so long. In addition, he found one of his USB sticks a Word document containing a photograph of someone. The Word document was not of the investigator and he suspects that the Austrian police file accidentally posted on his USB stick.However Haschek has learned his lesson. "Do not open links from random people on the Internet."

Sunday, 8 November 2015

Rediscovered Adware That Replaces Full Browser


Warning for the second time in a short time researchers for browsers that have the display of advertisements as target and all installed browsers trying to replace. It involves two browsers called eFast and Cross Browser, which both are based on Chromium.

Chromium is an open source web browser developed by Google that is the basis for Google Chrome. Other parties can use Chromium as the basis for their browser, such as Comodo Dragon, Vivaldi, SRWare Iron and Opera. Also dubious parties seem now to deal with Chromium. Instead of infecting existing browsers with adware is chosen to develop its own browser that displays ads and replaces the existing browser. Once the browser is started and ads appear dubious domains are loaded.

Browse Cross is part of a notorious adware family called Cross Rider. Initially it went to "browser hijackers' and adware were only existing browsers hijacked. According to anti-malware company Malwarebytes does so still, but there is now also a fully functional browser appeared. Once active remove both cross Browse eFast as shortcuts to the default browser on the desktop, start menu and taskbar, and then add a shortcut to the native browser.

The rogue browsers via 'wrappers and bundled software distributed. A wrapper is an installer that besides a certain program can also install other software.

Friday, 6 November 2015

BlackBerry Comes With Monthly Android Updates


Smartphone manufacturer BlackBerry is echoing include Google and Samsung also monthly Android updates will roll out, as it has announced. In the case of very serious Android leaks from the patch cycle will be rejected and the updates are immediately dispersed.

BlackBerry receives, like other manufacturers, each month a list of Google with recently discovered vulnerabilities in the Android platform. A month later, Google announced these vulnerabilities. According to David Kleidermacher BlackBerry is therefore important that the updates previously been patched. The smartphone manufacturer will therefore be rolling out monthly updates. The updates are currently only for the BlackBerry Priv, the privacy of the telephone company.

In the case of very serious vulnerabilities, for example, which are remote exploits, BlackBerry can intervene earlier.Depending on the severity of the vulnerability, the complexity of the update and time in relation to the monthly patch cycle, BlackBerry will roll out a "hotfix". In that case, the update for the problem is rolled out directly among users. Before rolling out the BlackBerry hotfixes working together with partners, but if necessary, the smartphone manufacturer may choose to distribute the update directly without the intervention of third parties.

Wednesday, 4 November 2015

Gmail Will Automatically Generate Replies To Emails


To ensure that Gmail users are able to answer emails quickly and have more time this week, Google will roll out a new feature called "Smart Reply". In this case, e-mails Google will offer suggestions that can be answered with a short reply.

Via a tap the answer can then be sent. Smart Reply shall propose three possible answers, based on the emails received by a user. "The e-mails that only require you do not have to think a quick response and can save valuable time," says software engineer Miklos Balin. To present the answers, Google uses "machine learning" so that the inbox does not recognize the e-mails that require an answer and it is real-time generated a response.

British Government Would Want To Prohibit End-To-End Encryption



The British government should IT companies to commit to no longer offer encryption services even where they have no access to the data. The bill will be presented tomorrow, as claims the Daily Telegraph. According to British newspaper allowed companies like Apple and Google will soon no longer offer advanced encryption which even they can not decrypt.

The UK government is not going to ban encryption in its entirety, because it plays an important role in protecting data. It is especially end-to-end encryption, where only the sender and recipient can read the message that the authorities concern. The bill would require IT companies soon to always be able to access the customer data.

"The government is clear that we must find a way to collaborate with industry and ensure that with clear monitoring and a robust legal framework, the police and intelligence services access to the content of the communications of terrorists and criminals can get, to resolve such matters and police to prevent crime, "said a ministry spokesman. He says that this means that companies communicate on their networks should be able to approach if they get a warrant.