Google: Gmail Scam Signals Much Bigger Security Issue
-
Font Size:
This weekend news came that a Gmail archive service called G-Archiver, which backs up all of your Gmail emails to your hard drive, was actually the front for a scam - hard coded into the application was a “feature” that sent every user’s email address and password to the creator’s own email account, giving him access to all of their Gmail messages.
These users should have known better than to type their email credentials into a third party service, so sympathy levels are at a minimum. But there is a much bigger problem to consider. Gmail is the entry point into a vast array of Google office services - including Google Docs and Google Apps. Those services allow users to share documents with others. If one user’s email credential become compromised, all of those sensitive documents become available to the bad guys, too. So if a single user’s credentials become known, the business they work for is at risk.
That has led a number of experts to conclude that Google Apps can never be a real threat to Microsoft Exchange and Sharepoint. All of the sensitive business information of a company, if stored on Google’s servers, is just a password guess, or in this case what is effectively a phishing scam, away.
I’ve spoken with Google employees about this issue in the past, and they point out that Google Apps allows authentication mechanisms that require more than just a password. In the Google Apps Security Policy, they state: “Google Apps integrates with standard web SSO systems using the SAML 2.0 standard. This allows integration with custom sign-on and/or advanced authentication (SecureID). Solutions can be custom made or Google Partner supplied.”
Of course many companies won’t use SecureID for authentication, and they’ll still be at risk. Over time, hopefully, even smaller companies will require it.
In the meantime, something else about Google’s security policy caught my eye. They’ll turn over data to third parties when required to by law (including search warrants, court orders, or subpoenas.) Google says they will “attempt to notify users before turning over their data whenever possible and legally permissible.” That may not be good enough for many companies, who would choose to fight an information transfer in court before they turn it over. If it was on their own servers they would be able to do that. But Google, certainly, won’t be going to court to fight on your behalf.
Users should consider themselves luck just to be notified that the information was released. Caveat Emptor.
Get Seeking Alpha Free Stock Alerts by Email!
Get Free Stock Alerts by Email!
-
Editor's Picks
-
Most Popular
- A Long Housing Boom Won't Yield to a Brief Recovery
- Why Congress Blames Index Speculators
- What Are the Prospects for Stagflation?
- State Street Launches 10 Ex-U.S. Sector ETFs
- Eisai Victorious Over Teva and Dr. Reddy’s in Aciphex Compound Patent Case
- Financials Future Still Uncertain
- Full list of Editor's Picks »
- As WaMu, Wachovia Ready Earnings, Comparisons to Wells, USB Are Telling »
- Apple F3Q08 (Qtr End 6/28/08) Earnings Call Transcript »
- Three Stocks To Be Held To Infinity and Beyond »
- Crazy Dividends »
- Apple Investors Nervous as Earnings Call Approaches »
- Wall Street Breakfast: Must-Know News »
- Historic Financial Collapse Underway? »
- Mother of All Short Squeezes? »
- China Poised to Pounce on U.S. Coal Suppliers »
- Is Natural Gas Down for the Count? »
- Barron's Goes Bullish on Banks, Again »
-
Long Ideas
-
Short Ideas
-
Cramer's Picks
- Dollar Back? - Fast Money Recap (7/23/08)
- Terex: Overlooked Bargain
- EBay is a Not Com – Cramer’s Lightning Round (7/23/08)
- Buy Costco, Get Sirius -- Cramer’s Stop Trading! (7/23/08)
- Intuitive Surgical's Q2: A Lesson in Errors of Perception
- Chevron: Good Choice for Conservative Growth Investor
- Pfizer Beats: Recommended at or Below $18
- Illumini, Intuitive: This Healthcare Outperformance Brought to You by the Letter 'I'
- Cynosure: Growth Expected as Sales Go Global
- More Bad News for the Anti-Ethanol Crowd
- Full list of Long Ideas »
- Get True Religion - Cramer's Lightning Round (7/22/08)
- Principal Financial Group Vulnerable to Commercial Real Estate Softening?
- Increases in Shorting, Only for Some
- Is a Ban on Short Financial ETFs on the Horizon?
- Is There a More Efficient Shorting Tactic?
- Short Oil as a Long Investment
- Ford's Financial Services Business About to Enter the Red
- Educational and Training Services Are An Excellent Short Opportunity
- Short Selling: Others Want Protection Too
- The SEC's Campaign Against Naked Shorting: Misguided or Right On?
- Full list of Short Ideas »
- EBay is a Not Com – Cramer’s Lightning Round (7/23/08)
- Buy Costco, Get Sirius -- Cramer’s Stop Trading! (7/23/08)
- Soup Target; Cramer's Mad Money (7/22/08)
- Get True Religion - Cramer's Lightning Round (7/22/08)
- Copper Down Low - Cramer's Stop Trading! (7/22/08)
- Banks Hit Bottom – Cramer’s Mad Money (7/21/08)
- Ends In X - Cramer's Stop Trading! (7/21/08)
- Great American Companies – Cramer’s Lightning Round (7/21/08)
- Market Rotation Bolsters Financials - Fast Money Recap (7/18/08)
- For Everything, Wind - Stop Trading! (7/17/08)
- Full list of Cramers Picks »
Most Popular Feeds
-
ETFs
-
US Market
-
Long Ideas
-
Alt. Energy
- Full list of feeds »
Hedge Fund Jobs
Job Seekers:
- Search jobs by category
- Get job alerts by email or live feed
- Apply online
Employers
- See all recruitment options
- Get applications online or by email




This article has 1 comment: