news4geeks.net
10May/120

Plaxo online address book service warns of security breach


Online address book service Plaxo has confirmed that an unknown malicious third-party gained access to the company's API connection to Google's address book and calendar. As a result of the security breach, Google took precautionary measures and temporarily disabled the connection, and sent Google account holders a "Suspicious sign in prevented" email advising them that a hijacker was trying to access their account.

According to Preston Smalley, General Manager and Senior Director of Product at Plaxo.com, the malicious party used Plaxo's server connection to Google to access accounts using a set of credentials; Smalley specifically notes that these credentials were acquired externally by the third-party and were not obtained from the company or its servers. Apparently, the attacker used Plaxo's AB Widget function, which the company had previously "slated for retirement" on 31 October 2011, to access accounts behind its proxy. It's not clear why the function had not already been taken completely offline, but Smalley says that the company is "in full communication with Google's security team and has taken steps to prevent future attacks including the full shutdown of the AB Widget".

Plaxo is currently in the process of upgrading its API connections, including the sync service, to use the OAuth open standard for authentication. However, until this is competed, the Google Sync service will remain disabled. Users who received the email notification from Google are advised to change their Google password "as a safety measure".

(Source: h-online.com)

 

A malfunctioning log-in system affected millions of people's ability to access a variety of Google applications on Wednesday, including Gmail and Drive. The problem, which lasted for about three ...
READ MORE
Motorola Solutions has unveiled a head-mounted, voice-controlled computer that's targeted at the military and other industries where workers need hands-free access to information. Called the HC1, the device runs ...
READ MORE
Google privacy checklist: What to do before Google’s privacy policy changes on March 1
We've been talking about it for weeks, but the big day is almost here: On March 1, Google will implement its new privacy policy and terms ...
READ MORE
Did Google handicap malware defenses in Firefox and Safari?
In December a Google-funded security study slammed Firefox, putting Mozilla’s browser at the bottom of the heap when it came to protecting users as they surf. NSS labs ...
READ MORE
Google JavaScript library offers access to APIs
Google this week began offering an alpha version of Google APIs Client Library for JavaScript, which provides access to HTTP-based APIs on the Web, as well as ...
READ MORE
Google outages blamed on sign-in system
Motorola HC1: Google Goggles for the enterprise
Google privacy checklist: What to do before Google’s
Did Google handicap malware defenses in Firefox and
Google JavaScript library offers access to APIs

Comments (0) Trackbacks (0)

No comments yet.


Leave a comment

Trackbacks are disabled.