Google Search

Showing posts with label results. Show all posts
Showing posts with label results. Show all posts

Sunday, June 15, 2014

Google to flag 'right to be forgotten' censored search results

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Image of Removed stamp courtesy of Shutterstock, Google search results from Wikimedia CommonsGoogle may be forced to forget about you, but it just might stick a flag on the search results it's reluctantly expunged.

According to The Guardian, the search giant plans to put an alert at the bottom of every page where it's been compelled to remove links in the wake of the recent, landmark "right to be forgotten" court ruling.

Last month, at the command of the EU's Court of Justice, Google reluctantly put out a "forget me" form to enable European Union citizens to request that it remove links that include their name and that are deemed "inadequate, irrelevant or no longer relevant, or excessive in relation to the purposes for which they were processed."

By the end of the first day, 12,000 Europeans had submitted the form.

As of last week, that number had hit 41,000 requests, at the rate of about 10,000 per day.

According to the Financial Times, those familiar with the search results removal process say that the takedown requests are coming in from across the EU, with a particularly high proportion coming from Germany and the UK.

The requests reportedly include one from a man who tried to kill his family and wanted a link to a news article about it taken down.

Other requests have come in from a politician with a murky past and a convicted paedophile, the Guardian reports.

Google chief executive Larry Page has said that nearly a third of the 41,000 requests received related to a fraud or scam, one-fifth concerned serious crime, and 12% are connected to child pornography arrests.

The Guardian says that Google plans to flag censored search results much like it alerts users to takedown requests over copyright infringing material.

When links have been removed from a list of search results, Google provides a notification at the bottom of that page and links to a separate page at chillingeffects.org, an archive of cease-and-desist notices meant to protect lawful online activity from legal threats.

On the site, each listing displays the name of the complainant, the title of the copyrighted content and a list of allegedly infringing URLs. The site at the link given above, for example, lists 640 URLs that allegedly infringe on Walt Disney's "Maleficent" film.

Google considers the enforced expunging to be censorship, and it's got some heavyweights on its side.

Wikipedia founder Jimmy Wales has condemned the ruling, telling Tech Crunch in an interview over the weekend that it was a "terrible danger" that could make it more difficult to make "real progress on privacy issues."

Wales is one of a seven-person advisory committee set up by Google to issue recommendations about where the boundaries of the public interest lie in the requests.

Wales told Tech Crunch that in spite of the tens of thousands of people eager to have their pasts erased from search results, the ruling simply amounts to censorship of knowledge, packaged in "incoherent legislation":

In the case of truthful, non-defamatory information obtained legally, I think there is no possibility of any defensible 'right' to censor what other people are saying.

We have a typical situation where incompetent politicians have written well-meaning but incoherent legislation without due consideration for human rights and technical matters.

I've asked Google if it will begin placing notifications on pages where it has removed links due to "right to be forgotten" requests. I'll update the story if any comment is forthcoming.

Follow @LisaVaas

Follow @NakedSecurity

Images from Shutterstock and Creative Commons.


View the original article here

Tuesday, October 29, 2013

Computer hacking for grade changes results in arrests

Three students have been involved in hacking into a professor's computer and changing the grades they had received, which has resulted in two arrests and a lengthy investigation.  

Two current engineering students, Sujay Sharma and Mitsutoshi Shirasaki, have been arrested by the Purdue University Police Department (PUPD) on a lengthy list of charges from burglary, to computer tampering, to forgery. Former student, Roy Sun, is also involved in the case. Sun, now a graduate student at Boston University. He is currently in his home country of Japan and his future has yet to be determined. 

The case arose in January when a Purdue professor alerted to Information Technology at Purdue (ITaP) that his University account password had been changed, along with the security question he had set. This is when he noticed that grades had been changed from previous semesters. 

The three students somehow switched the keyboards in an ITaP computer lab that professors used  and received information from there to change the grades. 

John Cox, police chief for PUPD, said the police have been working with ITaP, the FBI, Boston University Police Department and Pat Harrington, the prosecutor for the case, to investigate the situation since January. Cox said that this case was the first of this magnitude. 

"This was no outside attack," Cox said. "This was some students who were very smart and used their knowledge and wisdom to do something they shouldn't have."

Sharma and Shirasaki are no longer enrolled at Purdue and their grades have been changed back to reflect what each student had originally received. They also face local and state charges for the grade changes. 

According to Jeff Stefancic, associate dean for the Office of Rights and Responsibilities, the University is still looking at Roy's status as he is no longer a Purdue student. 

"We can examine a student's graduation status and potentially revoke a degree that was granted if the situation warrants it. That's currently under our administrative review right now," Stefancic said. 


View the original article here

Monday, May 20, 2013

PWN2OWN results Day Two - Adobe Reader and Flash owned, Java felled yet again

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Filed Under: Adobe, Adobe Flash, Apple, Apple Safari, Featured, Firefox, Google, Google Chrome, Internet Explorer, Java, Microsoft, Oracle, PDF, Security threats, Vulnerability

PWN2OWN 2013 is over.

Day Two ended in a similar fashion to Day One, with everyone who went in to bat slugging the ball into the crowd.

Yesterday, all the mainstream browsers (sorry, Opera fans!) except for Safari fell, though no-one actually tried Safari and failed.

Java fell three times yesterday, though under the contest rules, only the first attacker was due to win the $20,000 prize.

But in a fit of largesse, the sponsors announced that they'd pay up not just to the first successful attacker in each category, but to everyone who popped any of the products:

That put a biggish additional lump of cash on the table, with two more Java attacks to pay out on from yesterday ($40k), and a possible $100k extra if Pham Toan's scheduled attack on IE 10 worked out.

As it happened, IE 10 wasn't owned today.

From the results shown below, it looks as though Pham didn't actually make his attempt, as he's no longer listed at all, not even as trying and failing.

But a pre-registered contestant named Ben Murphy stepped up instead.

Not in person, but through a proxy (I assume this means a human proxy appearing live but following Ben's instructions), who successfully popped Java for a fourth time in the competition.

The final results look like this:

With HP's announcement that everyone will get paid for each attack, the prize monies will be divvied up as follows:

James Forshaw: Java = $20KJoshua Drake: Java = $20kVUPEN Security: IE10 + Firefox + Java + Flash = $250kNils & Jon: Chrome = $100kGeorge Hotz: Adobe Reader = $70kBen Murphy: Java = $20k

The total damage to the prize fund comes out at a whopping $480k.

That's only a fraction of the $p million that Google put up independently for its own Pwnium competition, held in parallel.

That was a chance to hack Chrome OS, Google's locked-down/open-source "browser is the operating system" platform that is largely based around the Chrome browser.

Chrome OS, like Android, is built on a Linux base.

In a similar way that Android has been adapted to suit mobile applications on phones and tablets, Chrome OS is adapted for web applications and the cloud.

Google will no doubt be rejoicing, from both a financial and a marketing point of view, because no-one managed to own the Chromebook (Google's name for laptops designed to run Chrome OS) used in the Pwnium 2013 contest.

And that ends the fun-and-games at this year's CanSecWest conference.

Now all that remains is to discuss whether this sort of "hacking as a professional sport" is the right way to encourage vulnerability research.

Is this competitive approach to vulnerabilities and exploits creating a market for malware that might end up out of control?

Or is it simply matching willing sellers with willing buyers, with some of the the edginess of sports-like competition thrown in?

Let us know your opinion in the comments below...

Follow @duckblog

Tags: Adobe, cansecwest, chrome, Exploit, Firefox, flash, IE, Java, Pwn2Own, reader, Safari, vulnerability


View the original article here

Monday, May 13, 2013

PWN2OWN results Day One - Java, Chrome, IE 10 and Firefox owned

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Filed Under: Adobe, Adobe Flash, Apple, Apple Safari, Featured, Firefox, Google, Google Chrome, Internet Explorer, Java, Microsoft, Oracle, Vulnerability

pwned-icons-176Of the Big Four browsers, only Apple's Safari has so far survived the onslaught of the browser-breakers at PWN2OWN 2013

Chrome, Internet Explorer 10 and Firefox, all running on Windows, have already fallen by the wayside.

To remind you: in the world of PWN2OWN, "successful attack" means that merely by browsing to untrusted web content, you're able to inject and run arbitrary executable code outside the browser.

In the real world, that means you could pull off a drive-by install, where you bypass all intended protections, preventions and pop-up warnings from the browser.

In other words, you could put malware on remote users' computers without them being involved, or even aware.

As the competition rules explain:

A successful attack ... must require little or no user interaction and must demonstrate code execution... If a sandbox is present, a full sandbox escape is required to win.

However, if you're a Safari fan, don't get too excited about your browser's resilience just yet.

None of the PWN2OWN entrants are actually scheduled to take on Safari (the only non-Windows-hosted software in the competition), and we are unlikely ever to be sure why.

Was the combination of Safari and OS X too tough? Was the prize money too low? Do the browser-breakers consider OS X malware a secondary revenue stream not glamorous enough for the limelight of competitive hacking? Are the browser-breakers simply not up to speed on Safari and OS X hacking yet?

(Let's hope that Safari's victory over the attackers was true resilience, or even simply a lack of interest from the competitors, rather than that someone came up with an exploit but chose instead to sell it to the internet underworld.)

Java, plugged into Internet Explorer on Windows, also fell today - not once, but three times.

Here's HP's summary of the results so far:

The competition continues at midday on Thursday 07 March 2013, with VUPEN Security taking a crack at Adobe Flash and George Hotz trying out his skills on the Adobe Reader plugin.

When they're done, Pham Toan will have a crack at Internet Explorer 10.

If he succeeds, he'll only win a consolation prize because, as shown above, VUPEN already took down Microsoft's latest browser.

? PWN2OWN contestants step up to the plate/crease in a randomly-chosen order. And since you only enter in the first place if you're pretty certain that you have an exploit that will work on the competition system, that usually means that it's first in, best dressed. Second and third place winners get kudos, but no cash.

With prize money at 70% of that for Chrome and IE, you'd assume that Flash and Reader are supposed to be easier to break. On the other hand, Safari was valued at just 65%, and no-one broke that.

So stay tuned. We'll let you know tomorrow how Flash and Reader stood up.

Follow @duckblog


View the original article here