Major Google Web Accelerator Security Issue


Recommended Posts

It seems that Google is expecting that every web page that asks for a login and password to be SSL secure.

Which just makes sense.

I understand that most forum software don't use SSL.. I don't know how feasible is that, but maybe they should.

Wow, now that's a beta issue if I've ever heard of one! :blink:

Well, this is definitely a slip in their QA procedures.

Their programmers are generally good though. Look at google.com, Gmail, Google Maps, and so on. :)

I'm not sure of what "conspiracy" you're talking about, when it has to do with users logging into forums with another guy's account?

585880380[/snapback]

Well, they have been hiring a boat-load of people in recent months. Might be beginning to fall under the "current structure doesn't fit that many workers" category.

WARNING!

Do NOT use any online/electronic/internet banking or credit card purchases with this 'web accellerator'. All the information that is needed tot deduce algorithms and the cardnumbers (including the security numbers) are present in the stored cache.

WARNING!

Do NOT use any online/electronic/internet banking or credit card purchases with this 'web accellerator'. All the information that is needed tot deduce algorithms and the cardnumbers (including the security numbers) are present in the stored cache.

585881200[/snapback]

If it's done on an HTTPS site, then it's not cached at all.

WARNING!

Do NOT use any online/electronic/internet banking or credit card purchases with this 'web accellerator'. All the information that is needed tot deduce algorithms and the cardnumbers (including the security numbers) are present in the stored cache.

585881200[/snapback]

WHAT???

Hopefully I don't use that junk...

But i'm sure that Google will be sued for this... I hope so...

Man... even if it's a stupid Beta...

It violate all privacy / security laws...

If it's done on an HTTPS site, then it's not cached at all.

585881227[/snapback]

But some sites... are retarded. UMB Bank has a way you can log in to your account minus all the HTTPS until your staring at your bank info...odd yet true. Hackers usually don't go after the "pot" of info without first getting slivers. Enough slivers presents a whole piece.

Most people for some reason become moronic when creating passwords to things later used for secure purposes/personal use. The odds of getting a forum password, versus that a bank.... As you know, the ideas are endless.

Beings that each time I post, no one posts after, yet reads.... oh well eh?

Doesn't surprise me, as with any new software they're going to be problems.

585881938[/snapback]

This is far more serious than some sort of "bug" that one would expect in pre-release (beta) software. Google decided to have the tool cache cookies. WHY? "For performance reasons". Bull****. There's no reason whatsoever to cache cookies from one machine and spread them to thousands of other machines. The whole concept of a cookie is to store unique information about a user or machine. Google has just made cookies a massive, worldwide security issue with this decision to "cache" (read: share) cookies.

Being a beta version isn't an excuse for such problems. Performance reasons isn't an excuse either. I believe they should remove this software from their page, untill they fix it and they remove the cookies remote caching "feature".

Edited by nickg78
Being a beta version isn't an excuse for such problems. Performance reasons isn't an excuse either. I believe they should remove this software from their page, untill they fix it and they remove the cookies remote caching "feature".

585882185[/snapback]

:yes: agree completely.

Where are the "ill follow Google into hell" fans now? i dont really buy this researchware stuff, spyware with a friendly name.

well Google made a bad bobo, they will fix it but broadband should be fast enough without it, do you really need it? you were fine before it

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Looks the same as the Air, actually. Check it out in person.
    • "This transition will take several years so we shouldn't bother doing it at all" is a naive take. This is completely normal for all specifications that cross-cut software, hardware and multiple industries. Look at the PCI specification for another example, consumers barely have PCI-E 5 yet PCI-SIG is working on PCI-E 8. AV2 will take multiple years to get adoption and even then, even a decade from now people will still have older hardware that doesn't support it. That's fine, because the savings still add up as newer devices add the hardware to deal with it. The goal is never to get 100% on the new spec overnight, but to gradually adopt it.
    • Firefox, and Vivaldi for the rare instances I need a Chrome based browser for a particular site.
    • I named Hitler because he is the de facto anti-semite. But you don't have to hate Jews to be a genocidal maniac. In fact, these days, so called semites are the ones acting in ways that would make Hitler proud.
    • 3DP Chip 26.05 by Razvan Serea 3DP Chip is a standalone, no-install portable tool that scans your computer’s hardware and automatically detects the latest drivers available for your specific configuration and external devices. It provides a clear list of drivers that need updates, locates the correct downloads, and helps you upgrade them easily. 3DP Chip will automatically detect and display the information on your CPU, motherboard, video card and sound card installed on your PC. You can also choose to copy these information into your clipboard with one click for later use (such as posting in a forum). Also, if you're upgrading your operating system or just need to reinstall Windows, 3DP Chip can backup all the drivers on your PC or laptop. 3DP Chip backup and reinstall features can save you hours of searching for and installing individual device drivers. 3DP Chip most popular drivers include: audio and sound drivers video drivers printer and scanner drivers digital camera drivers network drivers webcam drivers keyboard and mouse drivers 3DP Chip v26.05 changelog: Driver date/version information has been added or updated AMD motherboard chipset v8.03.25.247 AMD motherboard chipset v8.05.04.516 Newly added product or support has been enhanced AMD Radeon Graphics AMD Radeon 780M Graphics AMD Radeon 840M Graphics AMD Radeon 860M Graphics AMD Radeon 880M Graphics AMD Radeon RX 9070 XT AMD Radeon Pro W7500M NVIDIA GeForce RTX 3050 6GB Laptop GPU NVIDIA GeForce RTX 4050 Laptop GPU NVIDIA GeForce RTX 5050 Laptop GPU NVIDIA GeForce RTX 5050 Laptop GPU NVIDIA GeForce RTX 5060 NVIDIA GeForce RTX 5070 Laptop GPU NVIDIA GeForce RTX 5070 Ti Laptop GPU NVIDIA RTX Pro 500 Blackwell Generation Laptop GPU NVIDIA RTX Pro 1000 Blackwell Generation Laptop GPU NVIDIA RTX Pro 2000 Blackwell Generation Laptop GPU Download: 3DP Chip 26.05 | 7.2 MB (Freeware) Links: 3DP Chip Home Page | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
  • Recent Achievements

    • One Month Later
      nothanks earned a badge
      One Month Later
    • One Month Later
      B2Proxy earned a badge
      One Month Later
    • One Year In
      MadMung0 earned a badge
      One Year In
    • Week One Done
      jefred earned a badge
      Week One Done
    • Apprentice
      JoeyNeo went up a rank
      Apprentice
  • Popular Contributors

    1. 1
      +primortal
      471
    2. 2
      PsYcHoKiLLa
      230
    3. 3
      Skyfrog
      72
    4. 4
      FloatingFatMan
      63
    5. 5
      neufuse
      53
  • Tell a friend

    Love Neowin? Tell a friend!