Hackers turned computer security specialists accuse Google of setting users up for online disasters by letting them personalize home pages with applications that could be tainted.
Software that hackers can trick people into installing on “iGoogle” home pages can track users’ activities and control their machines, SecTheory chief executive Robert Hansen said on Friday.
“I could force you to download child porn or send subversive material to China,” Hansen said. “The exploitation is almost limitless. Google has to fix it.”
Google lets people customize iGoogle home pages with mini-software programs called “gadgets,” such as to-do lists, news feeds, currency converters and calendars.
Hackers can program malicious code into proffered gadgets or break into systems hosted by engineers providing legitimate mini-programs.
“It turns out a lot of people who develop these things aren’t good at security,” Hansen said, citing research he and Cenzic security analyst Tom Stracener shared at the DefCon hacker gathering in Las Vegas.
“We pretty much break into anything we try,” Stracener said.
Hackers can resort to the tactic of luring Web surfers to sites that trick people into installing applications on iGoogle home pages.
A hacker can remotely control a victim’s computer as long as the iGoogle page is open.
Gmail users face danger from the same “hole” in security, said Hansen, whose hacker name is “RSnake.”
“We’ve been telling Google about these vulnerabilities for years and they have not made corrective actions,” Hansen said. “They chose to open the doors and insomuch put a lot of consumers at risk.”
Google says it checks gadgets for malicious code, rarely finding any, and that it removes tainted programs.
NO-LIMITS PARTNERSHIP: ‘The bottom line’ is that if the US were to have a conflict with China or Russia it would likely open up a second front with the other, a US senator said Beijing and Moscow could cooperate in a conflict over Taiwan, the top US intelligence chief told the US Senate this week. “We see China and Russia, for the first time, exercising together in relation to Taiwan and recognizing that this is a place where China definitely wants Russia to be working with them, and we see no reason why they wouldn’t,” US Director of National Intelligence Avril Haines told a US Senate Committee on Armed Services hearing on Thursday. US Senator Mike Rounds asked Haines about such a potential scenario. He also asked US Defense Intelligence Agency Director Lieutenant General Jeffrey Kruse
NOVEL METHODS: The PLA has adopted new approaches and recently conducted three combat readiness drills at night which included aircraft and ships, an official said Taiwan is monitoring China’s People’s Liberation Army (PLA) exercises for changes in their size or pattern as the nation prepares for president-elect William Lai’s (賴清德) inauguration on May 20, National Security Bureau (NSB) Director-General Tsai Ming-yen (蔡明彥) said yesterday. Tsai made the comment at a meeting of the Legislative Yuan’s Foreign Affairs and National Defense Committee, in response to Democratic Progressive Party (DPP) Legislator Wang Ting-yu’s (王定宇) questions. China continues to employ a carrot-and-stick approach, in which it applies pressure with “gray zone” tactics, while attempting to entice Taiwanese with perks, Tsai said. These actions aim to help Beijing look like it has
China’s intrusive and territorial claims in the Indo-Pacific region are “illegal, coercive, aggressive and deceptive,” new US Indo-Pacific Commander Admiral Samuel Paparo said on Friday, adding that he would continue working with allies and partners to keep the area free and open. Paparo made the remarks at a change-of-command ceremony at Joint Base Pearl Harbor-Hickam in Hawaii, where he took over the command from Admiral John Aquilino. “Our world faces a complex problem set in the troubling actions of the People’s Republic of China [PRC] and its rapid buildup of forces. We must be ready to answer the PRC’s increasingly intrusive and
UNWAVERING: Paraguay remains steadfast in its support of Taiwan, but is facing growing pressure at home and abroad to switch recognition to Beijing, Pena said Paraguayan President Santiago Pena has pledged to continue enhancing cooperation with Taiwan, as he and Japanese Prime Minister Fumio Kishida expressed opposition to any unilateral change to the “status quo” in the Taiwan Strait using force, Japanese media reported on Saturday. Kishida yesterday completed a trip to France, Brazil and Paraguay, his first visit to South America since taking office in 2021. After the Japanese leader and Pena spoke for more than an hour on Friday, exchanging views on the situation in East Asia in the face of China’s increasing military pressure on Taiwan, they affirmed that “unilateral attempts to change the