Hackers Target Google Gadgets

One of the biggest problems with the so-called Web 2.0 movement has been its encouragement of oversharing -- which often means underestimating security risks. Adding doodads of varying quality to a home page can add a lot of pizazz, but can also be fraught with danger, since they can open a door for hackers.

It's a threat even for the biggest Web companies, including Google Inc., whose "gadgets" -- little programs like calendars or daily photo feeds that users can implant onto their personalized Google home pages -- are increasingly juicy targets for hackers, two security researchers said Wednesday.

It's not that Google is designing insecure programs.

The issue is that users building their own customized applications, and distributing them through Google, might have evil intentions and try to exploit those programs once they're installed on users' pages. Many users are inclined to inherently trust what they download from Google.

Robert Hansen, chief executive of security consultant SecTheory, and Tom Stracener, senior security analyst with security testing software maker Cenzic Inc., demonstrated an attack Wednesday at the Black Hat hacker conference in Las Vegas in which they used a malicious gadget to break into a person's Web browser and read their searches in real time.

Malicious gadgets -- if a user were to download one of them -- could be used in a variety of other attacks, including one where one gadget steals information from another, a valuable attack against gadgets that store personal user information, Hansen and Stracener said.

"How do you know it's a legitimate gadget?" Hansen asked. "Because someone uploaded it? There's no moderation, there's no way to guarantee it won't turn bad."


Post new comment

  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <h1> <quote> <img>
  • Lines and paragraphs break automatically.

More information about formatting options

CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.
Image CAPTCHA
Copy the characters (respecting upper/lower case) from the image.