Holden Frith and AP
The man, the films, those blondes. Free DVD collection starting this Sunday
Google has fixed a potentially devastating bug in its desktop search tool that could have exposed personal files on users’ computers to data thieves. The company says it has no evidence that the vulnerability was exploited.
The flaw was uncovered late last year by Watchfire, a security-analysis provider. Danny Allan, a researcher at the company, said that the vulnerability exists in about 80 per cent of web applications, but that the risks were more extreme “given the sensitive nature of what Google Desktop is doing.”
Google’s free desktop product, first released in 2004, lets users set Google’s indexing and searching capabilities loose on their own computers. The service offers a fast, easy way to find documents, e-mails, instant-messaging transcripts and archived webpages. A Google executive once described it as “the photographic memory of your computer.”
The Watchfire researchers discovered that the set-up was open to something known as a cross-site scripting attack, which lets an attacker place malicious code on a Google Desktop user’s computer. The PC could be infected a number of ways, including an infected e-mail attachment.
A hacker would then have had free reign to use Google Desktop to search the victim’s machine, and possibly to take full control of the computer, according to Watchfire. The company’s founder and chief technical officer, Mike Weider, said the attack would have gone undetected by firewalls or antivirus software.
Watchfire said it reported the security hole to Google on January 4 and was told on February 1 that the flaw had been fixed. Barry Schnitt, a spokesman for the company, said that desktop search software is updated automatically, so users do not need to take any steps to protect themselves.
While this opportunity for data theft has been shut down, Watchfire suggested that another could emerge because Google maintains a link between desktop and web data. “There’s a high potential for this to happen again,” Mr Weider said.
However, Mr Schnitt said that Google had introduced tighter security to counter such risks. “We’ve added an additional layer of security checks to prevent the types of attacks pointed out by Watchfire and future possible attacks through this vector as well,” he wrote.
Read the training tips and advice that helped our London Triathletes
Times Online's new TV show helps you make the right decisions for your pet
Read our exclusive 100 Years of Fleming and Bond interactive timeline, packed with original Times articles and reviews
The latest travel news plus the best hotels and gadgets for business travellers
Shortcuts to help you find sections and articles

Get Times news, business and sport on your mobile. Text Times to 86626



Overseas contacts and local business information

Our Credit Clinic has free help and advice
2007
£47,700
2007
£41,899
2008
£41,445
Great car insurance deals online
£25,510 – 32,000
Transport for London
London
£50k
NHS
Nationwide
£
£90,000 + PRP
Essex County Council
Essex
100K
Confidential
London
5% below developer pre-launch price!
Luxury Appts, beautiful gardens w/ Thames views
Great Investment, River Views
By Funway – Thailand
from £589pp
Christmas Cruises
From only £995pp
APTs East Coast now from only
£2425pp.
Great travel insurance deals online
Contact our advertising team for advertising and sponsorship in Times Online, The Times and The Sunday Times. Globrix Property Search - find property for sale and rent in the UK. Visit our classified services and find jobs, used cars, property or holidays. Use our dating service, read our births, marriages and deaths announcements, or place your advertisement.
Copyright 2008 Times Newspapers Ltd.
This service is provided on Times Newspapers' standard Terms and Conditions. Please read our Privacy Policy.To inquire about a licence to reproduce material from Times Online, The Times or The Sunday Times, click here.This website is published by a member of the News International Group. News International Limited, 1 Virginia St, London E98 1XY, is the holding company for the News International group and is registered in England No 81701. VAT number GB 243 8054 69.
Get a Mac!!!
ralph koepsel, Ider, Alabama