main

Google Antiphishing Site Exposes Private User Data

Slimy   on 23 January 2007 - 03:56 · 3 comments & 1814 views

Advertisement (Why?)
Google has removed a few user names and passwords posted inadvertently to a phishing blacklist it compiles and makes publicly available on the Web. The Mountain View, California-based company said it has also implemented a mechanism that detects and prevents a URL submission that contains login data from being available publically. The loophole was discovered in early January and Google announced Monday that the problem had been solved.

The login information was contained in 15 URLs submitted through Google's Firefox toolbar, which lets users report Web pages they suspect to belong to phishing sites. The Firefox toolbar prompts the user for a final review before the suspicious URL is sent in, but in this case, the users still sent in the URLs. "We are in the process of notifying the users who inadvertently disclosed this information and suggesting that they reset associated passwords," Google said in an e-mailed statement.

News source: InfoWorld

Post a comment · Send to friend Comments · There are 3 additional comments
#1 billyea on 23 Jan 2007 - 04:02
it's good that google notifies you, it frees them from getting blame (I think, but companies still manage to get blamed)
(1 reply) #2 Pc_Madness on 23 Jan 2007 - 08:19
If a user manages to submit an address with passwords in it, its hardly googles fault. :
#2.1 Colin-uk on 23 Jan 2007 - 10:49
it depends how the site works

some sites send user form date such as usernames and passwords through the url when submitting forms

so theres not much the user can really do about it either..

Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!

Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.

Advertisement (Why?)