Skip to main content

Security Fix for Gmail

Google Inc. has quietly patched a security bug in its Gmail service, but the company is downplaying the severity of the risk to its users.

Google confirmed that it made "modifications" to Gmail to cover an attack vector that allowed malicious hackers to take complete control of a victim's Gmail account.

The elhacker.net advisory described how a Gmail user token could be used in conjunction with other hacking tricks to take control of the victim account.

However, Google spokesperson Sonya Boralv told Ziff Davis Internet News that a successful attack would require the victim to open up an authenticated token and willingly give it to the attacker.

The risk of an actual attack is so slim, she said the company did not consider it a security vulnerability. Boralv said the authentication token is totally encrypted and cannot be sniffed by an attacker.

"Nevertheless, we have made some modifications to Gmail to mitigate these kinds of issues in the future," Boralv added.

In the face of concerns that Google never notified users of the Gmail issue, Boralv insist that the company follows security best practices.

"We take security very seriously, investigate vulnerability reports immediately and resolve them with highest priority. We looked into this issue and learned that it can only occur if a user knowingly provides their authentication token," she said.

To avoid this problem, Boralv said, Google tries to educate its users not to provide sensitive information to unidentified individuals. Google also provides anti-phishing guidance to its users.

"All Google products are put through a rigorous security review process to identify security issues and fix them before the product is released. If security vulnerabilities are identified after the product is available, we fix them immediately and automatically update the service for our customers," Boralv said.

Popular posts from this blog

iPod Nano 5G synchronization issues in Ubuntu

I was able to manage my iPod Nano using Ubuntu until now. When I recently upgraded to Ubuntu 11.04 Natty which was a clean install, a weird problem started. I could not synchronize my iPod using any application like Banshee, Rhythmbox, gtkpod, Amarok etc. On closer look, I realized that when I transferred any file, it was copied to the iPod but the database on iPod was not updated. None of the applications seemed to work and it was same error in each case. Since the iPod database was not updated, iPod could not see the file and was unable to play it. It was an iPod Nano generation 5, which comes with a video camera on the back side. To debug the issue, I executed Banshee in debug mode (banshee -debug on the terminal), and I noticed the following error when trying to transfer any file on iPod. ‘Failed to save iPod database – GLib.GException: Failed to generate sqlite database (in `libgpod-sharp)’ I searched for solutions on Internet but was confused at various solutions suggest...

Sydney Trip

I went to Sydney on a business trip for 2-3 weeks. Since, it was a business trip I was going to travel alone and miss my family. Therefore, I appreciated the short duration of the trip but it did not feel like a short one. Most of it was work only and some time for me during the two weekends. I had decided to make the most of available time instead of idling and feel more homesick. Also, I was going to stay in the CBD area so it was a big advantageous factor since not much effort was to be spent for sightseeing. The journey began with the longest flight I’ve ever been on (17 hours) with a stopover at Bangkok for 2 hours. I had a terrible time in the flight from Delhi to Bangkok; I was struggling a lot in the airplane seats and couldn’t sleep at all. However, the flight from Bangkok to Sydney was much better. On my flight from Bangkok to Sydney, an Australian lady was seated at the window seat on my right hand side. She asked me if I wanted to swap my seat with hers as I had starte...

Busy or Lazy?

Either of the two. But that’s been the case after my wedding. I’ve not done a blog post, neither I did anything on Facebook, Twitter, Google+ for that matter. Whatever! Better late than never. So, in order of priority, I wanted to write down a few important events that happened since my last post - We were blessed with a baby daughter – Naisha. Literal meaning of Naisha is ‘Special’ and she justifies this meaning completely. She’s beautiful, cranky and a fighter. She’s awesome! Naisha is one creature in the house. She just celebrated her first birthday dressed up as a Barbie, which was cute. All the day she’s running around the house and interpreting various things and objects in her unique style. I cannot understand much of it, but most of it appears very logical somehow. I switched from X to Y organization. It was a long pending decision for me and thankfully it worked out this time. It took its own time and I was recruited after long six months of interviewing process. A...