Breaking News

TerraMaster F4-425 Plus and F2-425 Plus Debut TEAMGROUP Unveils the T-FORCE Z54E PCIe 5.0 SSD Samsung Unveils 115” 4K Smart Signage Display Viltrox Launches AF 50mm F1.4 Pro FE LIAN LI Introduces the RB Series PSU with Advanced Cable Management

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Google Tightens OAuth Rules to Block Phishing

Google Tightens OAuth Rules to Block Phishing

Enterprise & IT May 8,2017 0

Google is taking action to prevent a repeat of last week's fake Docs phishing attack, by tightening enforcement of the OAuth system it uses for linking third-party apps to Google accounts.

Lats week, Google's systems were abused to spread phishing emails using an app that purported to be Google Docs. The bogus Docs app used Google's OAuth implementation to request access to the Gmail accounts of targets. If users granted the app access, it sent the same phishing email to the user's contacts.

Chet Wisniewski, principal research scientist at security firm Sophos, says the fake Docs phishing attack was "no different than the abuse of the Google Play store by malware authors". Only instead of installing a malicious app from Google Play, the user is receiving a real email from Google and authorizing an app from Google's actual OAuth interface.

"There is very little individuals can do other than be forever suspicious about legitimate requests from services provided by Google, Twitter, Facebook, and other online services that use OAuth with an unvetted application developer program," he writes.

"Attacks on systems that are open for anyone to sign up as a developer using OAuth have been vulnerable to this type of attack for a long time, and the onus is on Google to do a better job vetting application developers," he adds.

Google has several mechanisms to combat this type of phishing attack, including machine-learning spam detection, its Safe Browsing system, and virus scans on attachments.

However, the company on Friday also said it will update its policies and enforcement on OAuth applications.

"We're taking multiple steps to combat this type of attack in the future, including updating our policies and enforcement on OAuth applications, updating our anti-spam systems to help prevent campaigns like this one, and augmenting monitoring of suspicious third-party apps that request information from our users," wrote Mark Risher, director of Google's Counter Abuse Technology.

Google has also alerted its G Suite customers who were fooled by the phishing attack.

Tags: Google
Previous Post
Samsung's Gear VR to Retain Lead in 2017 as Google's Daydream Platform Emerges
Next Post
Toshiba Demonstrates 64-Layer BiCS FLASH on Client NVM Express SSD

Related Posts

  • Google announces Pixel 10, Pixel 10 Pro Fold and Pixel Buds 2a

  • Elevate your gameplay across mobile and PC

  • What’s new in Android 15, plus more updates

  • NVIDIA Teams Up With Google DeepMind to Drive Large Language Model Innovation

  • Google at CES 2024

  • Google introduces Gemini AI model

  • Google Cloud Launches AI-Powered Anti Money Laundering Product for Financial Institutions

  • Connecting all things Android at MWC Barcelona

Latest News

TerraMaster F4-425 Plus and F2-425 Plus Debut
Enterprise & IT

TerraMaster F4-425 Plus and F2-425 Plus Debut

TEAMGROUP Unveils the T-FORCE Z54E PCIe 5.0 SSD
PC components

TEAMGROUP Unveils the T-FORCE Z54E PCIe 5.0 SSD

Samsung Unveils 115” 4K Smart Signage Display
Enterprise & IT

Samsung Unveils 115” 4K Smart Signage Display

Viltrox Launches AF 50mm F1.4 Pro FE
Cameras

Viltrox Launches AF 50mm F1.4 Pro FE

LIAN LI Introduces the RB Series PSU with Advanced Cable Management
PC components

LIAN LI Introduces the RB Series PSU with Advanced Cable Management

Popular Reviews

be quiet! Dark Mount Keyboard

be quiet! Dark Mount Keyboard

Terramaster F8-SSD

Terramaster F8-SSD

be quiet! Light Mount Keyboard

be quiet! Light Mount Keyboard

be quiet! Pure Base 501

be quiet! Pure Base 501

Soundpeats Pop Clip

Soundpeats Pop Clip

Akaso 360 Action camera

Akaso 360 Action camera

Dragon Touch Digital Calendar

Dragon Touch Digital Calendar

Noctua NF-A12x25 G2 fans

Noctua NF-A12x25 G2 fans

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed