Microsoft and Google are requesting permission to publish data on the number of requests received from the Government
Companies believe that the government has no evidence that the disclosure of statistical data could harm the state.
In the Monday, September 9, Microsoft, Google, Yahoo! and Facebook are applied to the Court for the U.S. intelligence (US Foreign Intelligence Surveillance Court, FISC) for permission to publish statistics on the number of requests received by companies from the government. Microsoft and Google filed a petition for disclosure of these data are still many weeks ago, but their case was postponed at the request of the government. Negotiations with the government companies have failed, so the proceedings will FISC.
IT Safety News - Your source for network security news, opinion, product comparisons and reviews. Virus, Worms, Antivirus and Security Information.
Showing posts with label Google. Show all posts
Showing posts with label Google. Show all posts
Tuesday, September 10, 2013
Wednesday, August 28, 2013
Website The New York Times was incapacitated by hackers
Attackers hacked domain name registrar, provides services NYT, Yahoo, Google, Microsoft, Ikea and AOL.
Website of Edition The New York Times was disabled on August 27 of this year. Failure of the portal associated with the attack on the Australian domain name registrar - Melbourne IT. At the time of the attack to all employees edition forbidden to send sensitive information via e-mail.
Director of Information Technology NYT Marc Frons said that the failure of the site is the result of an external cyber attacks by the Syrian Electronic Army, or other intruders posing as this hacker group. Initially, in the publication of failure associated with technical problems.
Attack on Melbourne IT not only caused a problem with the site NYT, but with an account in Twitter edition.
Website of Edition The New York Times was disabled on August 27 of this year. Failure of the portal associated with the attack on the Australian domain name registrar - Melbourne IT. At the time of the attack to all employees edition forbidden to send sensitive information via e-mail.
Director of Information Technology NYT Marc Frons said that the failure of the site is the result of an external cyber attacks by the Syrian Electronic Army, or other intruders posing as this hacker group. Initially, in the publication of failure associated with technical problems.
Attack on Melbourne IT not only caused a problem with the site NYT, but with an account in Twitter edition.
Friday, May 31, 2013
Google: Disclosure timeline for zero-day vulnerabilities
Google has identified a firm deadline for disclosing zero-day vulnerabilities
Google has introduced rules for the disclosure of information about new vulnerabilities, analyzed by security Google.
To correct actively exploited "zero-day" vulnerabilities manufacturers now has 7 days, after which all of the available information will be published in the public domain. The changes apply only to "zero-day" problems that are already being used to commit attacks, but fixes are not yet available.
For many producers, seven days is too short a period for preparation and distribution of updates. For example, the elimination of critical security issues that do not fall under the category of "zero-day", recommended to be made within 60 days.
Google has introduced rules for the disclosure of information about new vulnerabilities, analyzed by security Google.
To correct actively exploited "zero-day" vulnerabilities manufacturers now has 7 days, after which all of the available information will be published in the public domain. The changes apply only to "zero-day" problems that are already being used to commit attacks, but fixes are not yet available.
For many producers, seven days is too short a period for preparation and distribution of updates. For example, the elimination of critical security issues that do not fall under the category of "zero-day", recommended to be made within 60 days.
Thursday, March 7, 2013
In the browser Chrome removed the 10 vulnerabilities
Google has released a security update for its web-browser that fixes 10 vulnerabilities, according to a blog developer Chrome. The new version (25.0.1364.152) experts have eliminated 10 vulnerabilities, six of which were labeled as "dangerous".
The experts also noted that the program of remuneration for identifying vulnerabilities independent researchers were given five thousand dollars. In total, various experts were awarded four awards - three for $ 1,000 each and one at $ 2,000.
Note that the most dangerous vulnerabilities eliminated in the latest stable version, related to the processing of navigation in the browser, as well as a memory corruption in the process of Web Audio and Indexed DB.
Tuesday, February 12, 2013
Google warns of attacks by hackers in Myanmar
According to the business publication The Wall Street Journal, Google has recently sent preduprzhedeniya number of independent journalists in Myanmar that their work email accounts have been hacked into Gmail, and Google said that the accounts were hacked with sophisticated multi-pass tactics that typically use the so-called "state hackers" who are interested in identifying sources of leaks dangerous to the political regime of information.
In Google said that Gmail automated monitoring could quite quickly identify suspicious hacker activity. At the same time, the company in an interview with WSJ refused to provide more details about what actions led to intrusion detection, for whom specifically hunted by hackers and what data they were interested.
The authorities of Myanmar has rejected accusations made by Google. In a statement to the same WSJ spokesman for the Government of Myanmar Thein Sein said that at present neither in the government structure, or the structure of the federal government there is no unit that would be involved in attacks on the "other" computer systems and collecting data using malicious codes.
Thursday, October 25, 2012
Google, Microsoft and Yahoo fix serious vulnerabilities in the mail system
Operators of the popular e-mail systems Google, Microsoft and Yahoo at the same time eliminate the vulnerabilities in their server software that allows you to bypass security algorithm verification. This allows potential attackers to exploit the weakest element of the cryptosystem and generate fake messages.
The vulnerability affects DKIM or DomainKeys Identified Mail, which in addition to Google, Yahoo and Microsoft is used by many other mail servers. DKIM provides cryptographic envelope the letter, which verifies the domain name through which a letter that allows you to discard messages with forged addresses (spam) and miss legitimate messages.
The problem was related to the signature key length of 1024 bits. Forge such keys can be on a PC. In the US-Cert report that they were able to recreate the 1024 - and 768-bit keys for RSA-signature. Experts say that in this respect the situation is the worst situation was in the system of Google, which used a 512-bit keys. Independent experts say that they were able to create a fake email claiming to be from a person, Larry Page and Sergey Brin, and run them through DKIM, applied in Google Gmail.
Friday, August 31, 2012
Hosting user-generated content is a very dangerous thing
Michal Zalewski of the security department Google: hosting user-generated content is a very dangerous thing
Google has been doing this for many years and has accumulated a lot of experience from which to draw definite conclusions. The main conclusion that the voice of Michael, - hosting user-generated content is a very dangerous business.
Historically, all browsers and browser plug-ins are designed in such a way as to show multiple types of content, ignoring any errors on the website. In the days of static HTML and simple Web applications, this approach was normal, because all the content was controlled by the webmaster.
Friday, August 24, 2012
Google Red Team - Rapid Response Team
Google creates the structure of the Audit department of food safety
Recently, Google increasingly comes under fire for its methods of work with personal data, as well as the controversial company policy to collect information. Just recently, the Internet giant resolved claims by the U.S. Federal Trade Commission, having paid for the unauthorized collection of A 22.5 million.
On the trail of these events, the company today announced the creation of the so-called rapid response team Google Red Team, which will be in real-time to deal with the privacy of data and prayvisi-risk for corporate and private users working with the products of the company.
Subscribe to:
Posts (Atom)





