Showing posts with label gmail. Show all posts
Showing posts with label gmail. Show all posts

Monday, September 16, 2013

Google knows every single Android user's WiFi password



New privacy issues have come to light surrounding Google's Android mobile OS. Experts on the matter are claiming that back up tools in the operating system make it so that a copy of every person's WiFi password (or the password of other networks you log onto) is being stored on Google's servers. Unfortunately, this might mean that Google could be legally forced to hand over the data at the government's request for one reason or another.

In Android 4.2, the back up service under Settings, lists WiFi passwords as part of the data that will be included, where as earlier versions of the OS did not specifically mention that. Although the feature can be turned off, users lose other, helpful functionality like bookmarks etc.

The main problem here is beyond the fact that Google is storing the passwords. The company is storing them in such a way that means it can read the passwords if it wants to. This is clear to see by the way new Android devices can suck in old passwords, login data and device settings from Google servers, once you have setup your Gmail address and new password.

Obviously, this functionality has its up sides, we can easily manage passwords for several devices and services this way, but it certainly leaves the networks we use in a much less secure state than we may have originally thought. Although this isn't shocking in the least, it is surprising that Google would leave these passwords in a readable form as well as opening itself up for an almost guaranteed public back lash if the government ever does strong arm them for that data.

Tuesday, July 31, 2012

Google upgrades Gmail video chat with Google+ Hangouts


Gmail’s video chat capabilities are set to get a major revamp, with Google announcing that they’re replacing the current implementation with the option to start ‘Hangouts’ right from users’ inboxes. This is arguably the standout feature of Google+ and now Gmail users will also be able to video chat with up to nine people at once, watch YouTube videos together, collaborate on Google documents and share their screens.
Google notes that users participating in Hangouts need to have Google+ accounts for all of these features to work in Gmail, although standard one-to-one video calls will presumably work the same as before.
The company says users can expect better reliability and enhanced quality compared to Gmail's old peer-to-peer video chats. They’ll also get the option to reach contacts not only when they are using Gmail but also if they are on Google+ in the browser or on their Android or iOS devices.
Hangouts in Gmail will begin rolling out today and then gradually over the coming weeks. It’s an interesting addition to an already-handy service and comes hot on the heels of their Sparrow acquisition, which some believe could result in an official Gmail client for the desktop eventually.

Friday, June 22, 2012

Internet Explorer zero-day flaw being used to target Gmail accounts


gmail, internet explorer, hacking, ie, exploit, vulnerability, zero-day flaw, gmail hac
A new zero-day exploit in Internet Explorer making the rounds has security experts from Microsoft and Google on their heels. The drive-by flaw is being used to gain access to Gmail accounts and remains unpatched as of writing, although Microsoft has issued a downloadable tool to block the exploit from being used.

Both companies have issues security advisories with regards to the issue. Microsoft has explained the vulnerability as one that could allow remote code execution should an IE browser user visit a website that implements the malicious code.

They point out that a user would first have to be led to the site as there’s no way the attacker can force the victim to visit an infected page. This of course could be done by clicking a link in an email, in a chat room or on an instant messaging service.

In more technical terms, the exploit happens when MSXML tries to access an object in memory that has not been initialized. This could corrupt the memory and allow an attacker to execute code.

Microsoft says that the vulnerability affects all versions of Windows and all supported editions of Office 2003 and Office 2007.

IE users are encouraged to download a tool that blocks the attack vector while a full patch is being developed. The company further recommends using the Enhanced Mitigation Experience Toolkit which helps to prevent software vulnerabilities. Furthermore, individuals can set up Internet Explorer to provide a prompt before running Active Scripting or disabling Active Scripting. These settings can be found in the Internet and Local intranet security zone.

Google gains legal right to use Gmail brand in Germany


google, germany, gmail, europe, email, government, legal, settlement, copyright, united kingdom, trademark, court, uk, infringement, webmail, patents, google mail, g-mail, daniel girs
Google happily announced on its blog todaythat @googlemail.com will now become @gmail.com in Germany. This marks the first time in several years that @gmail.com will be the default option for German users. Google had switched to @googlemail.com following a trademark dispute with businessman Daniel Girsch. Girsch was the owner of a German "electronic postal delivery" service named "G-mail", a company name which was short for "Girsch mail".

In 2005, when Google rolled out its Gmail service across Europe, both the United Kingdom and Germany quickly disputed its use based on trademark infringements. Faced with the proposition of having to pull Gmail from those countries, Google decided to re-label its service from Gmail to "Google Mail"  and offered U.K. and German citizens @googlemail.com addresses instead.

Eventually, Google settled with U.K. opposition but in 2007, Germans cemented their decision, preventing the company from operating in the country under its Gmail label.

Although the nature of the settlement is unknown, Google now appears to own both gmail.de and the German G-mail trademark, making it legal for the company to offer @gmail.com by default.

Existing users with @googlemail.com addresses will be able to transition to @gmail.com if they so desire. For users who do convert, their @googlemail.com email address will continue to remain active as an alias. This means if someone sends that user an email to their old @googlemail.com address, it will still arrive in their @gmail.com inbox. Additionally, users can even change back to @googlemail.com if they wish.