Security Blog

The latest news and insights from Google on security and safety on the Internet

Introducing Google's online security efforts

21 maggio 2007
Share on Twitter Share on Facebook
Google

52 commenti :

sebastian ha detto...

You should mention that most threats to the average surfer can be eliminated by disabling active contents like JavaScript, Java, Flash etc. Most sites work without, the few that don't can be managed with the Firefox NoScript extension or the IE zone model.

22 maggio 2007 alle ore 06:57
Nebon ha detto...

Its good big companies, like google are finally recognising malware as a problem. I am part of some of the security communities that deal with the cleanup of such malware and spyware.

Maybe this will trigger other services involved like ISP's to aid the anti-malware effort. At the moment it feels like a war with the casualities on only one side. We need to take more action to punish the producers of malware.

22 maggio 2007 alle ore 08:19
Unknown ha detto...

Glad this blog enables comment. But it seems the RSS isn't working properly.

22 maggio 2007 alle ore 09:15
Unknown ha detto...

Welcome aboard. I've added GoogleOnlineSecurity to the list of "Blogs I Read" and look forward to regular postings.


Bill Pytlovany

22 maggio 2007 alle ore 09:19
坚硬的泡沫 ha detto...
Questo commento è stato eliminato dall'autore.
22 maggio 2007 alle ore 11:30
Unknown ha detto...

Google and security...
http://ha.ckers.org/blog/20070520/phishing-through-google-yet-again/

Well close your holes first!

22 maggio 2007 alle ore 12:46
H.L. DeVore ha detto...

"Security is the condition of being protected against danger or loss." from Wikipedia...

Gentlemen...Ladies... I appreciate very much your technology focus on 'security' however I find it incredibly disheartening to see such extraordinary efforts when other blatantly obvious issues are affecting the user experience.

I have four young daughters. They use the word 'Google' as a verb. I recently spent over 6 hours of my precious weekend time messing with Norton 360 trying to install it and block video.google.com because of the inappropriate content presented to them.

Note that your 'Safe Search Filtering' doesn't do anything to eliminate access to videos of "Webcam Girls Go Wild", "Hot girls making out", "Tokio Hotel Sex", "Naughty Golf Lessons"...

The "Top 100" is particularly troubling because it lists this stuff directly in their face and IS NOT excluded by the 'Safe Search Filtering'...

So this is a different kind of security...important in a different way than malware but no less, if not even more important.

Most parents I know don't let their young kids on the internet at all. Personally I want them to learn and be empowered and knowledgable in the future...but I also want some semblance of security and don't need them watching bed bouncing t&a and women kissing each other so prominently pushed at them...

If they have to search deep to find it, so be it...like the kids back in the day that had to flip through the Natl Geo's to find the Polynesia women bare breasted...

C'mon...how about a parental security blog? And a set of parental security tools from the best minds at Google?

22 maggio 2007 alle ore 15:59
H.L. DeVore ha detto...
Questo commento è stato eliminato dall'autore.
22 maggio 2007 alle ore 15:59
Jay Neely ha detto...

From my blog, Social Strategist:

Whenever Google enters a market, big changes happen. It happened with search, it happened with advertising, and one of the key points of my Innovation in E-mail post is that it happened in webmail. Now Google is stepping up to the plate as one of the largest global Internet corporations, and on their new blog they're talking about tackling malware. The advantage a search company has in tracking this sort of thing is enormous, and Google's renowned data-center processing power is sure to help too. I can't help but note that this is another jab at software rival Microsoft and its perceived security vulnerability. A few predictions:

1: Google hasn't been lax in making acquisitions, and I expect them to buy the expertise they need both to complement their knowledge of search, and possibly to enter the desktop security market. The Google Pack, "a free collection of essential software" already includes Norton Security Scan and Spyware Doctor Starter Edition. I wouldn't be surprised if Google replaced these with it's own re-branded tool, but I also think they're more likely to offer an online utility.

2: In the past, when Google has entered a market, some aspects of the service they've offered have usually seen reductions in prices. Search was free to begin with, but AdSense and AdWords made advertising available to all kinds of budgets, and Gmail brought data storage to the commodity-level pricing it deserved to be at.

Unlike security companies, Google's long-term profitability is enhanced by *fewer* threats on the web, and even fewer threats of threats on the web.

22 maggio 2007 alle ore 16:31
Kairoer ha detto...

Great input!
Having your real-time monitoring data as background for the analysis of malware distribution surely helps pinpointing the problem.

I like the idea of Google beeing able to let me know if a webserver is infected before I click the link. I know a lot of users who need more than just a warning, tho.

22 maggio 2007 alle ore 17:02
Unknown ha detto...
Questo commento è stato eliminato da un amministratore del blog.
22 maggio 2007 alle ore 18:05
H.L. DeVore ha detto...

Thanks Terry. I visited K9 and poked around...I may even try them out. FYI, Norton 360 messed with enough of my system(s) that it flaked my Wi-fi somehow! I'm not techie enough I guess to know what was happening and why. I want simple protection for my kids...i.e. at least make it a little hard to find bad stuff. The world has plenty of bad, they do need to learn about it. Google's malware efforts certainly should be applauded, but it also sure seems to me that I should be finding solutions to basic Maslowian-hierarchical needs from them instead of from Canine Security systems? Who's the marketer over at Blue Coat Systems that came up with that? Sure I get it K thru 9, Kindergarten through 9th grade... My kids aren't dogs, but I do have a Black Lab!?!? C'mon Google. S-e-c-u-r-i-t-y Wake up! http://en.wikipedia.org/wiki/Maslow%27s_hierarchy

22 maggio 2007 alle ore 18:28
pbitton ha detto...

I'd also recommend webmasters concerned with site security add LinkScanner Online to their sites. It's free, and helps your visitors to know they'll be safe at the next site they hit after yours. Don't get blamed for some infection that you didn't cause! Check it out at http://www.explabs.com/LinkScanner/MyLinkScanner/

22 maggio 2007 alle ore 20:04
Unknown ha detto...

Nice job, Google!

We need people to fight malware.

22 maggio 2007 alle ore 21:02
Unknown ha detto...

ebastian Nohn said...

You should mention that most threats to the average surfer can be eliminated by disabling active contents like JavaScript, Java, Flash etc. Most sites work without, the few that don't can be managed with the Firefox NoScript extension or the IE zone model.

May 22, 2007 3:57 AM
I wanted to repeat the above so more will see it. That is part of my safe surfing strategy and can vouch for it.
One other comment: If Google is reading these, I like the idea of identifying bad sites, but it would be much more effective in RED as the warning is easy to miss when trying to find a link.

22 maggio 2007 alle ore 22:25
est ha detto...

Red star over China, not bad, not bad

23 maggio 2007 alle ore 00:54
sz-iris ha detto...

哈哈!看来我是第一个中文评论者了!
在中国上网建议大家使用:
360度安全卫士,瑞星卡卡,超级兔子等等

我的最爱360!

to est:yes,not bad.

23 maggio 2007 alle ore 02:03
Kevin W. ha detto...

我挖网 www.5dig.net 全体员工表示支持!

23 maggio 2007 alle ore 03:41
Lino Uruñuela ha detto...

Why do not you add antivirus to the Google Tool bar? Hereby, not only it would report of the infected pages when you do a search but also it would warn you when you come for other sites

23 maggio 2007 alle ore 04:10
Unknown ha detto...

Of course, the safest way to avoid Malware is to NOT use your computer as an Administrator.

Hopefully, Vista will help eliminate some of the outcome from this societal negligence

23 maggio 2007 alle ore 06:13
http://search-engines-web.com/ ha detto...

from the two maps, it appears that the USA is almost completely filled with a very high level of drive by malware servers and malware distribution.


How has this occurred. Is it because of being a target or having a high degree of malware perpertrators??

23 maggio 2007 alle ore 06:28
William Black ha detto...
Questo commento è stato eliminato da un amministratore del blog.
23 maggio 2007 alle ore 07:13
kyant ha detto...
Questo commento è stato eliminato da un amministratore del blog.
23 maggio 2007 alle ore 07:51
steve ha detto...

i think google and the other search engines could do more by tying up with a stronger player in this market and NOT listing sites in SERPS if identified as malware or dodgy

23 maggio 2007 alle ore 08:35
Unknown ha detto...

Infiltrated.net is another site doing something similar by tracking infected machines trying to brute force other machines using ssh Why don't some of these sites create a collaborative effort?

23 maggio 2007 alle ore 14:25
Ronald Paul Hughes ha detto...

Anti-malware software does some good, but it also seems to lull users into a false sense of security. If it is necessary to run software that removes already-known malware from your computer, isn't that a tacit admission that your computer may already be infected by as-yet-undiscovered malware?

We're doomed...

23 maggio 2007 alle ore 14:30
Unknown ha detto...

It would be *great* if google would pro-actively notify site admins (particularly at public uni's), when their sites are hosting malware or spammy content.

Definitely would 'not be evil', IMHO.

23 maggio 2007 alle ore 17:38
Unknown ha detto...
Questo commento è stato eliminato dall'autore.
24 maggio 2007 alle ore 00:44
Unknown ha detto...

Great, Google is now going to provide security. Let’s see the Google secured world !!!

24 maggio 2007 alle ore 03:03
Nebon ha detto...

I highly doubt it google will provide an anti-malware product. The best way they can help to prevent malware is monitoring and shielding. I would like to see the big companies, ie google, and security companies, norton for example, get more involved in the Security community. There is alot of ideas out there and most of these Online Communities have alot of users with expertise in malware and security.
A list of all the offical Security boards can be found here: http://asap.maddoktor2.com/

24 maggio 2007 alle ore 03:53
Nebon ha detto...

In response to:

from the two maps, it appears that the USA is almost completely filled with a very high level of drive by malware servers and malware distribution.


How has this occurred. Is it because of being a target or having a high degree of malware perpertrators??

May 23, 2007 3:28 AM

I would say that there is alot of users in the USA so the more users that can be targeted the better for the guy who infects them. I personally think its as America is a target rather than has a high degree of malware perpertrators. Alot of these hackers and such also come from mainly eastern Europe and Russia, so that is another reason why America is a target.

24 maggio 2007 alle ore 03:56
rAmIx ha detto...

Spanish translation: http://docs.google.com/Doc?id=dcnj5zwh_7gw3hh3

24 maggio 2007 alle ore 06:01
sectorzero ha detto...

I like the single secure sign-on of Google Accounts. Now that more and more of my dat is becoming Google-centric, I like to have a default method of switching between HTTPS and non secure reads.

Also, a big flaw is that, Orkut does not allow secure sign-on. I just cannot sign into Orkut without exposing my 'Google Account' password to the world. This is a huge bug, which I do not expect from Google. There are no excuses for this, since it is a pretty simple standard feature

24 maggio 2007 alle ore 12:02
Philipp Lenssen ha detto...

Is it possible for you to license your blog under Creative Commons, so other bloggers like me can work with your stuff (like the interesting map image of this post)?

24 maggio 2007 alle ore 16:20
Unknown ha detto...

OK. very cool this site but why the most information here isn't applicated on Orkut (for example)?

The Orkut Community "Orkut Exploits" http://www.orkut.com/Community.aspx?cmm=3537644 are disseminating a javascript code to stole anothers communities.

The case was notorious knowed, the same code work in the same way for more than 2 years and what the Orkut and Googles engineers make to resolve yours own problems? Nothing much serious, just some patches here and there - but the code continues to work.

So the point is, how can someone beleave in a security blog from a people that can not clean your own home?

If do you like to contact me let me a "scrap" on the Orkut [Profile.aspx?uid=1020317660623072042] i got many, many materials that i have collected about these "bugs" and these cracks.

.

25 maggio 2007 alle ore 17:25
All About Me ha detto...

google uses Malware as marketing stragties to find a new base to market to new users every day...malware is not bad unless you know how to uese it's technology in the right way....in my opionion if there was not such thing as Malware there will noot be a google.yahoo.myspace.facebook.ect.....they all need something to keep track of infomation on people surfing....and use that infomation to serve new customers....

25 maggio 2007 alle ore 19:36
Jay Neely ha detto...

Google beat my earlier prediction to the punch. They've already made an acquisition related to security. From my blog, Social Strategist:

"When I first wrote Google Enters the Security Market, I predicted they would “buy the expertise they need both to complement their knowledge of search, and possibly to enter the desktop security market”. Today I found out via Gizmo Richards that Google had beaten my prediction to the punch, and none of us had heard about it.

On May 17th, GreenBorder announced they had been acquired by Google. [...]"

26 maggio 2007 alle ore 20:42
Daniel Merege ha detto...

Congratulations Google for this initiative. We always need to be updated on the recent problems about system security.

I´d like to see here a post about Google´s information security policy. It´s a good and important subject.

Thanks..

28 maggio 2007 alle ore 19:38
Unknown ha detto...
Questo commento è stato eliminato da un amministratore del blog.
29 maggio 2007 alle ore 03:09
Jerry ha detto...

Green Border with Safe Files is definitely the
way to go!

*Before* you make "improvements," DON'T.

29 maggio 2007 alle ore 19:02
Unknown ha detto...

I speak to a variety of people of people every day. It seems those in the know, know how and what protection to use. However the more home users I speak to seem completely oblivious to the threats in the market place. One thing I have found a great tool for those who use web browsers is Finjan Secure Browsing. It allows immediate visualistaion of potential threat to web links. A great tool.

30 maggio 2007 alle ore 06:50
Alex Ott ha detto...

Besides the malware, exists also other usages of web-search results for the security purposes.
On the base of collected data, company could prepare profiles of the sites in different categories - pornography, etc., and provide them for the schools, and other organization/users, that need to have a parental control. Or use this data to build web categorization/reputation databases

30 maggio 2007 alle ore 07:02
MyLongLakesBuildingExperience ha detto...

I got a very suspicious email today that said my gmail account could be upgraded to 100gb and that I could register a free domain name with Google. The email takes you to a link after requesting a sign in. Its scary because I'm a techie and I usually catch stuff like this immediately. It looked genuine and the wording was pretty close to what you might expect Google to send. Looks like an asian or eastern european phish hack to me.

I changed my password to prevent a problem. If you'd like to see the email or want a copy of it.. just email me.

9 agosto 2007 alle ore 12:34
Anonimo ha detto...

My step-son received two $1 Google xharges along with large sum fraudulent purchases. Explain how google's name gets in the mix

13 settembre 2007 alle ore 10:31
Anonimo ha detto...
Questo commento è stato eliminato da un amministratore del blog.
19 ottobre 2007 alle ore 02:06
Scott ha detto...
Questo commento è stato eliminato da un amministratore del blog.
23 ottobre 2007 alle ore 10:42
Nebon ha detto...

It would be great to see the blog administrator comment on some of these issues.

26 novembre 2007 alle ore 01:46
Peter ha detto...

My site has been hacked, unfortunately, and I'm working to clean it. The malware notification that appears in front of the site lists several of our customers who have also been infected, but not the full list. In order to contact them, how can I get access to the full list?

Thanks,
Peter

28 maggio 2009 alle ore 19:01
Unknown ha detto...

WARNING... and I hope someone at Google will see this:

www.ShoppersInlet.com is an INFECTED site that attempts to launch a trojan horse when simply visiting the site. Here's the report from our Virus Scan/Blocker:

detected: Trojan program Trojan-Downloader.JS.LuckySploit.q

URL: http://pwgegrsdfs.ru/aety....

Anyone without an active virus scan would have been instantaneously infected.

Google has not identified this as an infected site and should do so.

29 maggio 2009 alle ore 18:02
Unknown ha detto...

Security in any medium is only the assumption of safety, threats can come in many forms but only when you are either open to it or looking for it. You will never get hurt by anyone living in a box but is that a comfort as you starve to death!

12 ottobre 2009 alle ore 22:18
Unknown ha detto...

Good to read you guys are doin all this and much more to make browsing safer. I just tried searching this feature on my gmail account but was not able to find it. One more thing i`m an administrator of the website spcet.org which was earlier infected with malware code, as of now i hv sent many review requests,your partners at stopbadware.com have checked the website and found no suspicous link, i want to know what all do i need to do now to remove that "This is an attack site" from my site. thank You keep up the good work!!

13 ottobre 2009 alle ore 01:05
Unknown ha detto...

Whatever happened to Googles "Report Infected Site" in its search engine?
I just got a trojan from http://topsoft10.com/?WinRAR_3.90
WHICH WAS A GOOGLE AD!!!!
There was nowhere even to just notify google they had a malicious website ad.
You need fix this problem google and screen the sites you advertise for!!!

24 gennaio 2011 alle ore 16:22

Posta un commento

  

Etichette


  • #sharethemicincyber
  • #supplychain #security #opensource
  • android
  • android security
  • android tr
  • app security
  • big data
  • biometrics
  • blackhat
  • C++
  • chrome
  • chrome enterprise
  • chrome security
  • connected devices
  • CTF
  • diversity
  • encryption
  • federated learning
  • fuzzing
  • Gboard
  • google play
  • google play protect
  • hacking
  • interoperability
  • iot security
  • kubernetes
  • linux kernel
  • memory safety
  • Open Source
  • pha family highlights
  • pixel
  • privacy
  • private compute core
  • Rowhammer
  • rust
  • Security
  • security rewards program
  • sigstore
  • spyware
  • supply chain
  • targeted spyware
  • tensor
  • Titan M2
  • VDP
  • vulnerabilities
  • workshop


Archive


  •     2025
    • mag
    • apr
    • mar
    • feb
    • gen
  •     2024
    • dic
    • nov
    • ott
    • set
    • ago
    • lug
    • giu
    • mag
    • apr
    • mar
    • feb
    • gen
  •     2023
    • dic
    • nov
    • ott
    • set
    • ago
    • lug
    • giu
    • mag
    • apr
    • mar
    • feb
    • gen
  •     2022
    • dic
    • nov
    • ott
    • set
    • ago
    • lug
    • giu
    • mag
    • apr
    • mar
    • feb
    • gen
  •     2021
    • dic
    • nov
    • ott
    • set
    • ago
    • lug
    • giu
    • mag
    • apr
    • mar
    • feb
    • gen
  •     2020
    • dic
    • nov
    • ott
    • set
    • ago
    • lug
    • giu
    • mag
    • apr
    • mar
    • feb
    • gen
  •     2019
    • dic
    • nov
    • ott
    • set
    • ago
    • lug
    • giu
    • mag
    • apr
    • mar
    • feb
    • gen
  •     2018
    • dic
    • nov
    • ott
    • set
    • ago
    • lug
    • giu
    • mag
    • apr
    • mar
    • feb
    • gen
  •     2017
    • dic
    • nov
    • ott
    • set
    • lug
    • giu
    • mag
    • apr
    • mar
    • feb
    • gen
  •     2016
    • dic
    • nov
    • ott
    • set
    • ago
    • lug
    • giu
    • mag
    • apr
    • mar
    • feb
    • gen
  •     2015
    • dic
    • nov
    • ott
    • set
    • ago
    • lug
    • giu
    • mag
    • apr
    • mar
    • feb
    • gen
  •     2014
    • dic
    • nov
    • ott
    • set
    • ago
    • lug
    • giu
    • apr
    • mar
    • feb
    • gen
  •     2013
    • dic
    • nov
    • ott
    • ago
    • giu
    • mag
    • apr
    • mar
    • feb
    • gen
  •     2012
    • dic
    • set
    • ago
    • giu
    • mag
    • apr
    • mar
    • feb
    • gen
  •     2011
    • dic
    • nov
    • ott
    • set
    • ago
    • lug
    • giu
    • mag
    • apr
    • mar
    • feb
  •     2010
    • nov
    • ott
    • set
    • ago
    • lug
    • mag
    • apr
    • mar
  •     2009
    • nov
    • ott
    • ago
    • lug
    • giu
    • mar
  •     2008
    • dic
    • nov
    • ott
    • ago
    • lug
    • mag
    • feb
  •     2007
    • nov
    • ott
    • set
    • lug
    • giu
    • mag

Feed

Follow
Give us feedback in our Product Forums.
  • Google
  • Privacy
  • Terms