Translate

Posts mit dem Label Google werden angezeigt. Alle Posts anzeigen
Posts mit dem Label Google werden angezeigt. Alle Posts anzeigen

1/28/2014

SECURITY UPDATE: Google Releases Google Chrome Update 32.0.1700.102

Google has released Google Chrome 32.0.1700.102 for Windows, Mac, Linux and Chrome Frame to address multiple vulnerabilities. These vulnerabilities could allow a remote attacker to cause a denial of service or bypass intended security restrictions. Follow the Link for Update:


Stable Channel Update

Chrome has been updated to 32.0.1700.102 for Windows, Mac, Linux and Chrome Frame.

This update has fixes for the following issues:
  • Mouse Pointer disappears after exiting full-screen mode. (317496)
  • Drag and drop files into Chrome may not work properly. (332579
  • Quicktime Plugin crashes in Chrome. (308466)
  • Chrome becomes unresponsive. (335248)
  • Trackpad users may not be able to scroll horizontally. (332797
  • Scrolling does not work in combo box. (334454)
  • Chrome does not work with all CSS minifiers such as whitespace around a media query's `and` keyword. (333035)
Security Fixes and Rewards
This update includes 14 security fixes. Below, we highlight fixes that were either contributed by external researchers or particularly interesting. Please see the Chromium security page for more information.

[$1000][330420] High CVE-2013-6649: Use-after-free in SVG images. Credit to Atte Kettunen of OUSPG.
[$3000][331444] High CVE-2013-6650: Memory corruption in V8. This issue was fixed in v8 version 3.22.24.16. Credit to Christian Holler.

We would also like to thank cloudfuzzer and miaubiz for working with us during the development cycle to prevent security bugs from ever reaching the stable channel. $6000 in additional rewards were issued.

Many of the above bugs were detected using AddressSanitizer.

A partial list of changes is available in the SVN log. Interested in switching release channels? Find out how. If you find a new issue, please let us know by filing a bug.

12/12/2013

NEW LEAK: Are Google Cookies used by the NSA To Pinpoint individual Targets ?



The National Security Agency (NSA) is stealthily using tools that permit Internet advertisers to track Onlineconsuming Users, getting hold of those "cookies" and location data, to ID targets for government hacking (e.g.) and to reinforce surveillance.

A slide from an internal NSA presentation indicating that the agency uses at least one Google cookie as a way to identify targets for exploitation. (Washington Post)

The NSA internal presentation slides, provided by former NSA contractor Edward Snowden, show that when companies follow consumers on the Web to better serve them advertising, the same Know-How opens the door for a similar bird-dogging by the government. The slides also suggest that the agency is using these same procedures to help identifing Hackers (and Terrorists....?).

Tracking-Microchips in Chocolatebars ? Will that someday be reality ?
For years, privacy defenders have raised concerns about this sort of commercial tracking, to ID and object consumers with advertisement publications. The online Advertising Businesses have said, its method are insipid and gains consumers by serving them ads, that are more likely custom-built.

This new Leak about the NSA using these same commercial technologies, could fuel this developing dispute, handing privacy advocates a new argument for repressing in commercial vigilance. According to the documents, the NSA and its British Doppelganger, GCHQ, are using these (same) "cookies", that advertising platforms place on CPUs to ID consumers browsing the WorlWideWeb.

The intelligence agencies have found distinct use for a part of the Google tracking mechanism known as the “PREF”-Cookie. These cookies typically don't contain personal information (or should not...), such as someone's name or e-mail address, but they do contain a numeric code that enables Web sites to individually identify & track a Users browsing-behaviour. Besides of tracking Internet visits, this cookie allows NSA to follow the User's communications among the endless Ocean of Internet information in order to send out software that can hack that person's computer, for the final act, gathering the data on any given PC. The cookie is the connecting part between you and the Web. The slides show, that the cookies are used to "enable remote exploitation," although the specific attack used by the NSA against individual targets are not addressed in these leaked documents.

Christmas & Cookies are coming soon...
The NSA's use of these cookies (see left Pic) is not a technique for filtering through endless amounts of data to find suspicious behavior. Comparatively, it lets the NSA concentrate on someone already under suspicion.

Separately, the NSA is also using commercially collected data to help locate mobile devices around the world, the documents point out. Many smartphone apps, running on Android & iPhones accessories, and the Apple and Google operating systems themselves, track the location of each device, mostly without a Warning to the mobile devices owner. This information is more specific than the large location-identification data the government is collecting from Cellphone networks (Towers), as reported by the Washington Post lately.

These slides do not demonstrate how the NSA obtains Google "PREF"-Cookies or whether the company cooperates in these programs, but other documents reviewed by the Washington Post indicate that the cookie data IS among the information the NSA can obtain with or through a so called Foreign Intelligence Surveillance Act Order. If the NSA gets the data that way, the involved companies seem to know and are legally enforced to assist.

(Of course) the NSA declined to comment on those specific tactics, but an NSA spokesman sent the Wahington Post a statement that says: "As we have said before, the NSA, within its lawful mission to collect foreign intelligence to protect the United States, uses intelligence tools to understand the intent of foreign attacker and prevent them from bringing harm to innocent Americans."

Google declined as well to comment on the subject, but chief executive Larry Page joined the leaders of other technology companies earlier this week, in calling for an end to bulk collection of user data and for new limits on court-approved surveillance requests.

"The security of users' data is critical, which is why we've invested so much in encryption and fight for transparency around government requests for information," ...

...Page said in a statement on the coalition's Web site.

"This is undermined by the apparent wholesale collection of data, in secret and without independent oversight, by many foreign governments around the globe."

Larry Page 2009

The way how consumers are tracked online 

Internet companies store small filed cookies on a users CPU to uniquely identify them. Few consumers are aware of the full mesure to which advertisers, services and any given Web sites (including Intelligence Agencies) track their activities through the Web and/or mobile devices. This data collection mechanism is most unseeable to all, except the most refined users. Including, the available tools to withdraw or block them, have a limited effectiveness.

The NSA program, named Program Happyfoot (not to be mixed up with Operation Happyfeet), helps the NSA to map Internet addresses to physical locations more precisely, than it is possible with traditional Internet geolocation services. Many mobile applications and operating systems (OS) use location-based services to help users find for instance, Gasstations or Restaurants and Hotels nearby. Fact is, even when the GPS is disabled, most mobile devices still silently determine a users location in the background, using Wi-Fi networks or cellular towers signals.

Cellphone Towers are a
must in tracking down mobile devices
Apps, that do not need geolocation-data may still collect it anyway to share with 3rd party advertisers. Last week, the Federal Trade Commission announced a settlement for a seemingly innocuous flashlight app that allegedly leaked user location information to advertisers without consumers' knowledge.

Applications transmit their locations (to Google e.g.) and/or other Internet businesses, because Advertisements, tied to a explicit physical location can be more fruitful than generic ads, depending on the circumstances, where you are at a given Moment. But in the process, they appear to tip off the NSA to a mobile device's precise physical location. That makes it easier for the involved spy agency to engage in the sophisticated tracking techniques the Washington Post described in a story.

Those Leaks about the NSA practices unmask the difficulty facing online businesses, which have faced a repercussion against tracking for commercial purposes and their obfuscated role in the governments surveillance Operations.

"If data is used and it stops the next 9/11 our fellow citizens wouldn't have any problem with it no matter what it is," says Stuart P. Ingis, General Counsel at the Digital Advertising Association. But he says that it is a sensitive act to pursue the bad guys "while at the same time preserving civil liberties." Other defenders of online advertising companies have argued that its unfair to unify private companies with ad-tracking activities, with the NSA activities revealed through the Snowden leaks. Marvin Ammori, a lawyer who advises technology companies including Google itself on surveillance issues, wrote in a USA Today article, that "limiting bulk data collection by private companies - whether they advertise or not - would do little or nothing to limit the NSA."

One noting that the latest documents show that the unique identifiers that are being placed on users' computers are not only being used by analytic and advertising companies, but also being used by the NSA for targeting. He also says that there are things those companies could do to protect their users from the type of attacks described in the slides, like "not sending tracking IDs, or at least not sending them in the clear without some layer of encryption."

Similarly, he says, "Browser companies can help by giving users better control over the use of third-party tracking cookies and by making sure that their browsers are not sending unique Cookie-IDs as a side effect of their safe-browsing behavior."

Stanford's Mayer says the revelations suggest the need for limits on the data that companies collect about consumers. "There's increasingly a sense that giving consumers control over the information they share with companies is all the more important, because you're also giving them control over the information they share with government."

Lets just wait the next upcoming: Leak...

12/07/2013

Pony Botnet Controller - Facebook, Google, Twitter, Yahoo:
Almost 2 Million Usernames & Passwords Stolen in a Mass Hack

Almost 2 million accounts on Facebook, Google, Twitter, Yahoo and other social media and Internet sites have been breached, according to a Chicago-based cybersecurity firm.


The hackers stole 1.58 million website login credentials and 320.000 e-mail account credentials, among other items, the firm Trustwave reported in a blogpost. Included in the hacks were thefts of 318.121 passwords from Facebook, 59.549 from Yahoo, 54.437 from Google, 21.708 from Twitter and
8.490 from LinkedIn. The list also includes 7.978 from ADP, the payroll service provider.

According to Trustwave, "Payroll services accounts could actually have direct financial repercussions."

Stolen Passwords by Day
Most of those stolen passwords were from the Netherlands, followed by Thailand, Germany, Singapore, Indonesia and the United States, which accounted for 859 reports from machines and 1.943 passwords, according to Trustwave. All inn all, just over 100 countries were affected, and Trustwave said this shows the attack is "fairly global."



The hacking began October 21st 2013 and might still be taking place, according to a CNN article, on this case.

The massive data crack was a result of keylogging software maliciously installed on an untold number of CPUs around the world, according to researchers at Trustwave. The Malware was capturing log-in credentials for key websites over the past month and sending those usernames and passwords to a server controlled by the hackers. On November 24th 2013, Trustwave Analysts tracked that server, located in the Netherlands. Google itself declined to comment on this subject.

John Miller, a security research manager at Trustwave, told CNN, "We don't have evidence they logged into these accounts, but they probably did." (So what now....?)

Miller said the team doesn't yet know how the virus got onto so many personal computers. The hackers set up the keylogging software to rout information through a proxy server, so it's impossible to track down which computers are infected.

Among the compromised data are about 41.000 credentials used to connect to File Transfer Protocol (FTP, the standard network used when transferring big files) and 6.000 remote log-ins.

 There are several other servers Trustwave has not yet tracked down, Miller said. ADP, Facebook, LinkedIn and Twitter told CNN they have notified users and reset passwords for compromised accounts. Google declined to comment and Yahoo did not respond immediately.

In compiling the data, Trustwave also discovered that many users are doing just what computer specialists advise against, using simplistic passwords that can easily be guessed. For instance, the top five passwords Trustwave found in researching the breaches were: 123456, 123456789, 1234, password and 12345.

Read the whole Blogpost from Trustwave @:
Look What I Found: Moar Pony!

SOURCE: Money CNN

11/19/2013

Google & Microsoft announce to combat together against Online Child Porn

Google and Microsoft announced today (November 18th 2013) that they will introduce new software controls aimed at reducing the distribution of child pornography online. Eric Schmidt, Executive Chairman of Google, announced today that the Multi-Business-Concern Google in Cooperation with MS will roll out new Control(ed)-Software designed to curb child porn searches on the Google Searchengine(s).
 


In a joint announcement, both Companies have introduced on the British summit on Internet safety 2013, a software that makes it harder for Pedophiles, Sadists and wannabe`s to search for child abuse material online.



Writing ahead of that British summit on Internet safety, Google's executive chairman Eric Schmidt said his company has fine-tuned Google Search to clean up results for over 100.000 search terms in connection to child porn. When users (Pedophiles) type in queries that may be related to child sexual abuse, they will find no results that link to illegal content.

(My opinion: If this would be possible (and not only a trying promise), this would be one of the biggest breakthrough(s) in this disturbing and growing Internetcrime(s), that "kills" Children emotionally, for the rest of their lives, if they come away without killing after an sexual raping act).

Schmidt wrote in the Daily Mail newspaper: "We will soon roll out these changes in more than 150 languages, so the impact will be truly global". Globalization ?

The restrictions are being launched in the United Kingdom and other English-speaking countries first and similar changes are being brought out on Microsoft's Bing search engine (Where is YAHOO ?). The two companies are sharing picture detection technology to identify child abuse photographs whenever they appear on their systems, and Google is also testing technology to identify and remove illegal videos.


Other measures include warnings shown at the top of Google search for more than 13.000 queries to make it clear that child abuse is not only illegal but a crime indescribable. Schmidt acknowledged that no algorithm is perfect and Google cannot prevent pedophiles adding new images to the web. Maybe someday they will be able, on the long run. Campaigners welcomed the move but doubted how much impact the changes would bring. Pedophiles tend to share images away from the public search engines, they say...

Jim Gamble, the former chief of Britain's Child Exploitation and Online Protection Center said: "They don't go on to Google to search for images, they go on to the dark corners of the Internet on peer-to-peer websites."




Jim Gamble


According to a briefing issued by Mr. Cameron's office, changes to be introduced by the search engines include, but not limited :


- The introduction of new algorithms that will block child abuse images, videos and pathways that lead to illegal content, covering 100.000 unique searches on Google (Worldwide).

Stopping auto-complete features from offering people (...with Pedophilia disorder...), child abuse search terms.

- Google as well as Microsoft will now work with the National Crime Agency and the Internet Watch Foundation to bring forward a plan to tackle peer to peer networks featuring child abuse images.

Google will bring forward new technology that will put a unique identification mark on illegal child abuse videos, which will mean all copies are removed from the web once a single copy is identified or uploaded.

OTHER LINKS TO THIS TOPIC:
-  http://www.telegraph.co.uk/news/uknews/10457458/Google-New-technology-to-identify-child-abuse.html
http://www.fbi.gov/stats-services/publications/parent-guide
https://www.gov.uk/government/news/internet-safety-summit-at-downing-street-communique
http://www.theguardian.com/technology/2013/nov/18/uk-us-dark-web-online-child-abuse-internet