<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Philosophically Secure &#187; google</title>
	<atom:link href="http://eugk.net/wordpress/category/google/feed/" rel="self" type="application/rss+xml" />
	<link>http://eugk.net/wordpress</link>
	<description>Eugene Kogan&#039;s blog on information security and software engineering</description>
	<lastBuildDate>Mon, 27 Jun 2011 13:25:39 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>Google vs. China</title>
		<link>http://eugk.net/wordpress/2010/01/12/google-vs-china/</link>
		<comments>http://eugk.net/wordpress/2010/01/12/google-vs-china/#comments</comments>
		<pubDate>Wed, 13 Jan 2010 01:08:01 +0000</pubDate>
		<dc:creator>eugenekogan</dc:creator>
				<category><![CDATA[google]]></category>
		<category><![CDATA[hacking]]></category>

		<guid isPermaLink="false">http://eugk.net/wordpress/?p=273</guid>
		<description><![CDATA[This is a rather interesting development&#8230; Google believes its systems are being attacked by China, in order to gain information on Chinese human rights activists who happen to use Gmail. Well, duh. What prominent company or government isn&#8217;t being targeted by Chinese state-sponsored hackers? (Perhaps the nation of Togo.) The interesting part is Google&#8217;s response: [...]]]></description>
			<content:encoded><![CDATA[<p>This is a rather interesting development&#8230;</p>
<p><a href="http://googleblog.blogspot.com/2010/01/new-approach-to-china.html" target="_blank">Google believes its systems are being attacked by China</a>, in order to gain information on Chinese human rights activists who happen to use Gmail. Well, duh. What prominent company or government isn&#8217;t being targeted by Chinese state-sponsored hackers? (Perhaps the nation of Togo.)</p>
<p>The interesting part is Google&#8217;s response: a threat to stop doing business in China. That would mean closing its office there, and shutting down Google.cn (the Chinese version of its search engine, with government-friendly censored results). If Google follows through on this threat, it will send a simple message: play nice or we&#8217;ll take our ball and go home. Hopefully they will also release more details about the attacks, so that the rest of us can learn to better defend ourselves.</p>
<p>Of course, China&#8217;s economy is huge, and the loss of business with one foreign company probably wont have a measurable impact (unless it&#8217;s Walmart). However, it&#8217;s still a powerful symbolic gesture. If China wants to be treated as a serious member of our modern global society, they need to stop acting like Mongol invaders from the 13th century.</p>
<p>Maybe if more companies took a similar stance (and followed through), then China would rethink its hostile cyber strategies. Or would they just be sneakier about it?</p>
]]></content:encoded>
			<wfw:commentRss>http://eugk.net/wordpress/2010/01/12/google-vs-china/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Web Security</title>
		<link>http://eugk.net/wordpress/2008/05/12/web-security/</link>
		<comments>http://eugk.net/wordpress/2008/05/12/web-security/#comments</comments>
		<pubDate>Mon, 12 May 2008 20:50:54 +0000</pubDate>
		<dc:creator>eugenekogan</dc:creator>
				<category><![CDATA[google]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://eugk.net/wordpress/?p=79</guid>
		<description><![CDATA[Google has some good content about web security available on their Google Code University portal. There&#8217;s introdutory course material, and even some videos. The one titled &#8220;How to Break Web Software&#8221; is pretty interesting.]]></description>
			<content:encoded><![CDATA[<p>Google has some good content about web security available on their <a href="http://code.google.com/edu/security/index.html" target="_blank">Google Code University</a> portal. There&#8217;s introdutory course material, and even some videos. The one titled &#8220;How to Break Web Software&#8221; is pretty interesting.</p>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="400" height="326" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="id" value="VideoPlayback" /><param name="flashvars" value="&amp;subtitle=on" /><param name="src" value="http://video.google.com/googleplayer.swf?docId=5159636580663884360&amp;hl=en" /><embed id="VideoPlayback" type="application/x-shockwave-flash" width="400" height="326" src="http://video.google.com/googleplayer.swf?docId=5159636580663884360&amp;hl=en" flashvars="&amp;subtitle=on"></embed></object></p>
]]></content:encoded>
			<wfw:commentRss>http://eugk.net/wordpress/2008/05/12/web-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>G-Archiver is evil</title>
		<link>http://eugk.net/wordpress/2008/03/12/g-archiver-is-evil/</link>
		<comments>http://eugk.net/wordpress/2008/03/12/g-archiver-is-evil/#comments</comments>
		<pubDate>Wed, 12 Mar 2008 23:12:36 +0000</pubDate>
		<dc:creator>eugenekogan</dc:creator>
				<category><![CDATA[google]]></category>
		<category><![CDATA[reversing]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://eugk.net/wordpress/2008/03/12/g-archiver-is-evil/</guid>
		<description><![CDATA[This is a great lesson in why not to blindly trust random software that you find on the Internet. G-Archiver, a program created to help users locally save their Gmail messages, has a piece of code in it that sends your Gmail login and password to the author. You can see a scary screen shot [...]]]></description>
			<content:encoded><![CDATA[<p>This is a great lesson in why not to blindly trust random software that you find on the Internet. G-Archiver, a program created to help users locally save their Gmail messages, has a piece of code in it that sends your Gmail login and password to the author. You can see a scary screen shot of his inbox, since the guy had his own Gmail credentials hard coded right into the program, which was obviously discovered.</p>
<p>The details are at <a href="http://isc.sans.org/diary.html?storyid=4129&amp;rss">SANS ISC (source code)</a> and <a href="http://www.codinghorror.com/blog/archives/001072.html">Coding Horror (screen shot)</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://eugk.net/wordpress/2008/03/12/g-archiver-is-evil/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Interview with Vint Cerf</title>
		<link>http://eugk.net/wordpress/2007/03/12/interview-with-vint-cerf/</link>
		<comments>http://eugk.net/wordpress/2007/03/12/interview-with-vint-cerf/#comments</comments>
		<pubDate>Mon, 12 Mar 2007 17:22:18 +0000</pubDate>
		<dc:creator>eugenekogan</dc:creator>
				<category><![CDATA[google]]></category>
		<category><![CDATA[networking]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://eugenekogan.net/wordpress/2007/03/12/interview-with-vint-cerf/</guid>
		<description><![CDATA[This short interview with Vint Cert, by Dark Reading, gives an inside look at Vint&#8217;s daily life. He talks a lot about his role at Google, as well as his many other responsibilities. I&#8217;m always amazed at how someone can be actively and productively involved in several organizations, all at once. He also mentions some [...]]]></description>
			<content:encoded><![CDATA[<p>This short <a href="http://www.darkreading.com/document.asp?doc_id=118596&amp;print=true">interview with Vint Cert, by Dark Reading</a>, gives an inside look at Vint&#8217;s daily life. He talks a lot about his role at Google, as well as his many other responsibilities. I&#8217;m always amazed at how someone can be actively and productively involved in several organizations, all at once. He also mentions some of his personal hobbies and aspirations beyond work, as well as his opinion on improving Internet security. For example, the one person Vint says he would love to meet is Richard Dawkins. That alone should give you some insight into his beliefs.</p>
]]></content:encoded>
			<wfw:commentRss>http://eugk.net/wordpress/2007/03/12/interview-with-vint-cerf/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Google Business Apps More Secure?</title>
		<link>http://eugk.net/wordpress/2007/02/25/google-business-apps-more-secure/</link>
		<comments>http://eugk.net/wordpress/2007/02/25/google-business-apps-more-secure/#comments</comments>
		<pubDate>Sun, 25 Feb 2007 18:17:29 +0000</pubDate>
		<dc:creator>eugenekogan</dc:creator>
				<category><![CDATA[google]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://eugenekogan.net/wordpress/2007/02/25/google-business-apps-more-secure/</guid>
		<description><![CDATA[According to SC Magazine, the newly released Google business application suite provides greater security than locally controlled applications, such as MS Office. I agree with some of their points. It&#8217;s true that application patches to Google&#8217;s offerings will be applied automatically by Google. However, how do you, as the customer, know that these patches wont [...]]]></description>
			<content:encoded><![CDATA[<p>According to SC Magazine, the newly released <a href="http://www.scmagazine.com/us/news/article/635360/google-business-tools-offer-fewer-features-security-say-experts/">Google business application suite provides greater security</a> than locally controlled applications, such as MS Office. I agree with some of their points. It&#8217;s true that application patches to Google&#8217;s offerings will be applied automatically by Google. However, how do you, as the customer, know that these patches wont break a feature that you rely on? Regardless, you don&#8217;t have the option to apply a patch sooner, or skip it altogether.</p>
<p>Since these <a href="http://www.google.com/a/">Google applications</a> are obviously all web-based, users now have to worry about additional exposure to web-based attacks, such as cross-site scripting. Also, are your proprietary word processor and spreadsheet documents more secure stored on a Google server, or locally? That depends on how well you do local security, but with the Google option the control is not in your hands. A business must rely on Google to keep its data confidential and out of the hands of its competitors.</p>
<p>As for availability, a business that is dependent on Google applications would be in serious trouble if the server went down, or if they were having Internet connectivity problems. I would say keep a frequently updated local backup is a must. Those of us who use GMail are very familiar with the occasional &#8220;server unavailable&#8221; message.</p>
<p>On the more positive side, I think this could be a great feature to get a business up and running with minimal infrastructure costs. As the business grows and it needs more functionality and control over its information, it could easily migrate to a standard business application suite.</p>
]]></content:encoded>
			<wfw:commentRss>http://eugk.net/wordpress/2007/02/25/google-business-apps-more-secure/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

