Endpoint
2/19/2013
05:28 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%
Repost This

Good News From Google: Account Hijacking Down

How Google is verifying logins, getting results

Now for some good news: During a week when Facebook and then Apple -- yes, Apple -- admitted getting hacked and a report tied the Chinese military to a major cyberspy gang targeting U.S. businesses and organizations, Google's security team said it has seen the number of compromised Gmail accounts drop 99.7 percent since 2011.

Mike Hearn, a Google security engineer, today blogged that Google's efforts to determine the legitimacy of log-ins has cut those email account hijackings since their peak in 2011. The secret sauce: using more of a risk analysis process and Google's multifactor authentication steps for Google user accounts. "Every time you sign in to Google, whether via your web browser once a month or an email program that checks for new mail every five minutes, our system performs a complex risk analysis to determine how likely it is that the sign-in really comes from you. In fact, there are more than 120 variables that can factor into how a decision is made," Hearn said in his post.

If a login attempt appears suspicious -- originating from a different country since a user's last login, for example -- Google prompts the user with a few questions. "For example, we may ask for the phone number associated with your account, or for the answer to your security question. These questions are normally hard for a hijacker to solve, but are easy for the real owner. Using security measures like these, we've dramatically reduced the number of compromised accounts by 99.7 percent since the peak of these hijacking attempts in 2011," Hearn says.

Google has witnessed some hefty account-hijacking attempts. In one case, a single user used stolen passwords to try to break into 1 million Google accounts a day for weeks at a time, according to Hearn. "A different gang attempted sign-ins at a rate of more than 100 accounts per second," he said, noting that Google's security system doesn't just check the password's validity in order to thwart these types of attacks.

Google recommends strong passwords for Google accounts, its two-step authentication option, and updating account recovery options.

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Kelly Jackson Higgins is Senior Editor at DarkReading.com. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise Magazine, ... View Full Bio

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2012-3946
Published: 2014-04-24
Cisco IOS before 15.3(2)S allows remote attackers to bypass interface ACL restrictions in opportunistic circumstances by sending IPv6 packets in an unspecified scenario in which expected packet drops do not occur for "a small percentage" of the packets, aka Bug ID CSCty73682.

CVE-2012-5723
Published: 2014-04-24
Cisco ASR 1000 devices with software before 3.8S, when BDI routing is enabled, allow remote attackers to cause a denial of service (device reload) via crafted (1) broadcast or (2) multicast ICMP packets with fragmentation, aka Bug ID CSCub55948.

CVE-2013-6738
Published: 2014-04-24
Cross-site scripting (XSS) vulnerability in IBM SmartCloud Analytics Log Analysis 1.1 and 1.2 before 1.2.0.0-CSI-SCALA-IF0003 allows remote attackers to inject arbitrary web script or HTML via an invalid query parameter in a response from an OAuth authorization endpoint.

CVE-2014-0188
Published: 2014-04-24
The openshift-origin-broker in Red Hat OpenShift Enterprise 2.0.5, 1.2.7, and earlier does not properly handle authentication requests from the remote-user auth plugin, which allows remote attackers to bypass authentication and impersonate arbitrary users via the X-Remote-User header in a request to...

CVE-2014-2391
Published: 2014-04-24
The password recovery service in Open-Xchange AppSuite before 7.2.2-rev20, 7.4.1 before 7.4.1-rev11, and 7.4.2 before 7.4.2-rev13 makes an improper decision about the sensitivity of a string representing a previously used but currently invalid password, which allows remote attackers to obtain potent...

Best of the Web