Commentary

Thomas Claburn
 

Google Gets Raked Over The Coals At Black Hat

Robert "RSnake" Hansen, CEO of SecTheory, and Tom Stracener, senior security analyst at Cenzic, had some harsh words for Google at their Black Hat presentation, "Xploiting Google Gadgets."

Robert "RSnake" Hansen, CEO of SecTheory, and Tom Stracener, senior security analyst at Cenzic, had some harsh words for Google at their Black Hat presentation, "Xploiting Google Gadgets.""Google cares more about tracking users than they do about consumer safety," said Hansen.

Hansen said that four years ago, he found a Web redirection vulnerability that was being actively used by phishers. He alerted Google, eBay, DoubleClick, and Visa. Visa closed the hole in hours. DoubleClick had a partial fix in place in days. It took eBay several weeks to fix the problem. But Google still hasn't fixed all the vulnerabilities.


More Internet Insights

White Papers

More >>

Reports

More >>

Webcasts

More >>

Google and Hansen aren't on the best of terms. According to Hansen, Google threatened to take legal action for claiming that Google was a phishing site. And he said that someone from Google disparaged a previous critique of the company's security in a comment post that didn't identify the affiliation of the person commenting -- Hansen said the post showed an internal Google IP address.

Hansen recounted his contentious history with Google to provide some context to the vulnerabilities in Google Gadgets.

Google declined to comment about Google Gadget security when asked about it two weeks ago. When Hansen asked if anyone from Google was in the audience and was answered in the affirmative, he invited the unidentified Google employee to respond but was rebuffed. (It's hard to blame the Google employee for not wanting to take the bait.)

Google appears not to take the issue too seriously. To demonstrate that, Stracener showed a screenshot of an input form for Google Gadget creation that includes a "Do Evil" checkbox, an obvious attempt to make light of Google's unofficial motto, "Don't be evil."

The problem Google faces is that it doesn't have a way to make sure that Gadgets don't include malicious content.

As Hansen and Stracener tell it, that means Gadgets can be used for JavaScript and HTML injection, Web site defacement, data poisoning, content and gateway spoofing, surveillance and spyware, exposure and theft of data, gmalware (DDoS, cookie theft, zombies), worms, and coercive functionality.

Google's response to all this: "On further review, it turns out this is not a bug, but instead the expected behavior of this domain."

At least that's how Hansen spun his correspondence with Google.

Google may have reason to discount the vulnerability of Google Gadgets. Perhaps the attack isn't practical, despite the convincing presentation by Hansen and Stracener. Perhaps it knows something the security community doesn't.

But if that's the case, Google owes its users an explanation. It cannot afford to treat security the way it treats privacy, as something to be sacrificed in the name of new services. It cannot afford to treat malicious content like copyrighted content, as something someone else is responsible for.


Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

InformationWeek encourages readers to engage in spirited, healthy debate, including taking us to task. However, InformationWeek moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. InformationWeek further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
T-Shirt Giveaway T-Shirt Giveaway: Each week we're selecting one great comment from our readers. The author of the comment will receive an InformaitonWeek Community t-shirt. So get posting!
Subscribe to RSS

Resource Links