Holden Frith and AP
Grab an Italian masterpiece for less
Google has fixed a potentially devastating bug in its desktop search tool that could have exposed personal files on users’ computers to data thieves. The company says it has no evidence that the vulnerability was exploited.
The flaw was uncovered late last year by Watchfire, a security-analysis provider. Danny Allan, a researcher at the company, said that the vulnerability exists in about 80 per cent of web applications, but that the risks were more extreme “given the sensitive nature of what Google Desktop is doing.”
Google’s free desktop product, first released in 2004, lets users set Google’s indexing and searching capabilities loose on their own computers. The service offers a fast, easy way to find documents, e-mails, instant-messaging transcripts and archived webpages. A Google executive once described it as “the photographic memory of your computer.”
The Watchfire researchers discovered that the set-up was open to something known as a cross-site scripting attack, which lets an attacker place malicious code on a Google Desktop user’s computer. The PC could be infected a number of ways, including an infected e-mail attachment.
A hacker would then have had free reign to use Google Desktop to search the victim’s machine, and possibly to take full control of the computer, according to Watchfire. The company’s founder and chief technical officer, Mike Weider, said the attack would have gone undetected by firewalls or antivirus software.
Watchfire said it reported the security hole to Google on January 4 and was told on February 1 that the flaw had been fixed. Barry Schnitt, a spokesman for the company, said that desktop search software is updated automatically, so users do not need to take any steps to protect themselves.
While this opportunity for data theft has been shut down, Watchfire suggested that another could emerge because Google maintains a link between desktop and web data. “There’s a high potential for this to happen again,” Mr Weider said.
However, Mr Schnitt said that Google had introduced tighter security to counter such risks. “We’ve added an additional layer of security checks to prevent the types of attacks pointed out by Watchfire and future possible attacks through this vector as well,” he wrote.
Industry sectors news at a glance. Interactive heatmap, video and podcast
Everything the Business Traveller needs to know to make a better trip
Get ready for the winter sports season, with our resort guides and snow reports
We are backing British business, what is the confidence of the nation and what businesses are succeeding?
Growing demand for energy, oil that is harder to reach and the rise of carbon dioxide emissions. We examine the energy challenge
With rail travel in Europe on the rise, we review the benefits of travelling by train
Enjoy further reading from Travel to Fashion, Business to Sport, discover more
Shortcuts to help you find sections and articles
1998
£47,955
12 months for the price of 11 and a 5% discount.
Offer ends 31/11/09
Check your free Experian credit report before applying
Car Insurance
to £60K + bonus (OTE £90k)
Lord Search & Selection
Location Flexible
PwC’s Consulting practice helps businesses of all shapes
and sizes work smarter and grow faster.
£85k
CPA
Highly Competitve
Specsavers
Whiteley, near Southampton
Moments from Battersea Park.
For sale with Winkworth
Find out about shared ownership.
See your free Experian credit report beforehand
Book now & save over £100pp.
11 cool resorts, lowest prices... Early Booking offers 15 Nov.
20% off selected Azores holidays taken in October with Sunvil Discovery
Get covered on your travels with a superb range of policies at great prices. Visit InsureandGo.com
World Class Golf, Spa and preferential Beach Club. Private estate overlooking West Coast
Villas from £275 per night inclusive of Golf
Contact our advertising team for advertising and sponsorship in Times Online, The Times and The Sunday Times, or place your advertisement.
Times Online Services: Dating | Jobs | Property Search | Used Cars | Holidays | Births, Marriages, Deaths | Subscriptions | E-paper
News International associated websites: Globrix Property Search | Milkround
Copyright 2009 Times Newspapers Ltd.
This service is provided on Times Newspapers' standard Terms and Conditions. Please read our Privacy Policy.To inquire about a licence to reproduce material from Times Online, The Times or The Sunday Times, click here.This website is published by a member of the News International Group. News International Limited, 1 Virginia St, London E98 1XY, is the holding company for the News International group and is registered in England No 81701. VAT number GB 243 8054 69.