Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Rice grads, professor find flaw in Google
Houston Chronicle ^ | Dec. 20, 2004 | JOHN C. ROPER

Posted on 12/21/2004 7:05:23 AM PST by Max Combined

Company says security glitch in search tool is fixed

A security flaw that could have caused big trouble for Google and its new Desktop Search tool has been fixed, thanks to a Rice University professor and two of his graduate students.

Left unchanged, the glitch could have made accessible via the Internet private data stored on personal computers.

Dan Wallach, an assistant computer science professor at Rice University, and students Seth Nielson and Seth Fogarty, were doing a project for a computer security class designed to see if Google's Desktop Search tool was safe for users.

They discovered that an attack Web site could be set up to trick the Google program, which integrates desktop and Internet searches, into believing it was communicating with the Google software. Instead, it would retrieve private data from personal computers.

"Had somebody been able to exploit this attack, they would not be able to read complete files on your machine," said Wallach, "but they could make searches against your machine."

In other words, the searches could have exposed small but important snippets of text from the files. "So, if you, for example, had a file of credit card numbers or Web passwords, I might be able to read that," Wallach said.

Nathan Tyler, a Google spokesman, said: "We were very thankful to Mr. Wallach and his team for working on it."

Google made the security problem public over the weekend. When Google unveiled a test version of Desktop Search in October, it said it was built to respect user privacy. The tool, which can be downloaded for free on the Google Web site, allows users to search documents, Web history, e-mails and even archived instant messaging chats on a PC's hard drive.

The glitch was found in a feature of the software where search results can be blended so they scour PCs and the Internet simultaneously.

Prior to the fix, for a user of the software to be exposed to attack, they would have to visit a Web site that was specifically targeting someone using the Google Desktop feature, Wallach said.

Google said there was no evidence any attacks have occurred.

Google earlier this month replaced the vulnerable version with one that Wallach said he and his students retested and confirmed safe.

Google said in a statement that the problem has been fixed "so that all current and future users are secure." Anyone who downloaded the software after Dec. 10, doesn't need to be updated, Wallach said.

Wallach said Google's Desktop Search is the only local search engine that was vulnerable to this type of attack. Last week, Microsoft launched its test version of a desktop search engine as part of its MSN Toolbar Suite. Microsoft's version does not attempt to seamlessly integrate PC searches with those of the Internet.

Wallach is no stranger to taking on computer security for the sake of privacy concerns.

When Wallach was a graduate student at Princeton University, he said he was part of a team that found serious flaws in the security of small Java computer programs known as applets, where an attacker could use the Web browser to access the contents of a user's PC.

Earlier this year, Wallach co-authored a study that made national headlines on significant flaws he said were in high-tech voting machines, enabling one person to vote multiple times.


TOPICS: Business/Economy
KEYWORDS: computers; riceu
I am glad they caught the problem. I am using Google on my desktop and I really like it.
1 posted on 12/21/2004 7:05:23 AM PST by Max Combined
[ Post Reply | Private Reply | View Replies]

To: Max Combined

Google is great. But as with any computer program or system, there will be holes that some enterprising, crafty person with too many smarts for their own good will find some way to exploit. It's the technology age version of the old adage that every rule can be broken.


2 posted on 12/21/2004 7:09:23 AM PST by susiek
[ Post Reply | Private Reply | To 1 | View Replies]

Comment #3 Removed by Moderator

To: Max Combined

Might want to check out Copernic desktop search. It seems to have more features.

http://www.copernic.com/


4 posted on 12/21/2004 7:10:45 AM PST by TomGuy (America: Best friend or worst enemy. Choose wisely.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Max Combined
I wonder if Dave's Quick Search Taskbar Toolbar Deskbar has such a flaw.
5 posted on 12/21/2004 7:19:24 AM PST by newgeezer (When encryption is outlawed, rwei qtjske ud alsx zkjwejruc.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: gohot
There is *NO* 100% glitch free program or person anywhere

Not true -- 100% secure software is possible, just much more difficult to develop -- code written the right way can be mathematically proven to be secure.

Though if it is running on top of an operating system or a BIOS that has a flaw, there will still be a security problem; the most you can do is guarantee that a piece of software doesn't create any new security holes. To get a totally secure software system you need to build the operating system and the BIOS from scratch. For extremely critical applications, this has been done. (Even then the system is vulnerable to hardware sabotage, so you need to combine this with strong physical security measures.)

6 posted on 12/21/2004 7:31:01 AM PST by VeritatisSplendor
[ Post Reply | Private Reply | To 3 | View Replies]

To: VeritatisSplendor
Not true -- 100% secure software is possible, just much more difficult to develop -- code written the right way can be mathematically proven to be secure.

Where there is a will, there is a way to subvert it.

7 posted on 12/21/2004 7:50:28 AM PST by AdamSelene235
[ Post Reply | Private Reply | To 6 | View Replies]

To: TomGuy

You may consider looking at www.blinkx.com for a great (blinkx) desktop searcher that is free. From my experience 2nd only to dtSearch (approx. $179).


8 posted on 12/21/2004 8:43:39 AM PST by Freeper (I was culture in the 60's and now with Clinton "running things" I am suddenly Counter-Culture.)
[ Post Reply | Private Reply | To 4 | View Replies]

To: Freeper

I had looked at blinkx and downloaded it, but haven't installed it yet. I liked the tv part, but wonder whether it is part of the desktop or only webpage.

Its peer2peer sounds interesting now that Torrents are disappearing. I'll have to check it out.


9 posted on 12/21/2004 9:09:47 AM PST by TomGuy (America: Best friend or worst enemy. Choose wisely.)
[ Post Reply | Private Reply | To 8 | View Replies]

To: AdamSelene235
There's no way to subvert a mathematical proof. It's still true that the software developers may make a mistake in the proof and therefore miss a hole in the software; however, the big difference is that ordinary software is not developed using the methods of mathematical proof, so there can be security holes simply from the developer's lack of imagination.

For ordinary software, there is a vulnerability to a hacker with more imagination than the programmers; for software verified with proof-theoretical techniques, only an explicit and clearly detectable error can lead to a security hole; so the process of testing and verification is much simpler and more reliable (though the development of the software is much more difficult).

10 posted on 12/21/2004 10:01:22 AM PST by VeritatisSplendor
[ Post Reply | Private Reply | To 7 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson