inside the man

Thursday, December 08, 2005

Google Desktop godsend or spyware?

I am not embarrassed to say it, I love Google Desktop. It has changed the way I work for the better in a way that has not been matched since WYSIWYG word processing became readily available. However, like many, I am very concerned by GT's threat to my privacy. Not only does GT index every web transaction that I make (other than those at URLs that I have explicitly excluded), every document I have, every email I send or receive, it caches it! This can be a blessing when I am trying to find something from long ago, but it is also a pretty complete log of my online life that I am not comfortable with others having access to.

Mathew Schwartz has published this interesting list of steps to managing Google Desktop securely from an enterprise risk management perspective:

"
  1. Use an enterprise DSE Google Desktop is like instant messenger software: if you don't explicitly block it, it's guaranteed to be on some users' PCs, therefore consider centrally managing it. Desktop Search for the Enterprise, Google's administrator-controlled version, has a Group Policy control. It also enables centralized distribution and adds the ability to search Lotus Notes e-mails. Microsoft's WDS also offers centralized administration tied to group policies.
  2. Encrypt the index file To secure the actual Google Desktop index -- in case an attacker manages to grab it -- set the Group Policy preference to "encrypt index." Note this only works on NTFS volumes.
  3. Change the index file's location Beyond encrypting the index file, administrators can also change its default location, which makes it more difficult for an attacker to grab it.
  4. Disallow Google Desktop on PCs with shared login names For PCs with multiple users, Google Desktop creates a different index for each user, mitigating many privacy and sensitive information-sharing concerns. However, in organizations where multiple employees share a computer and use the same username and password, prohibit the use of Google Desktop. If you don't, each user's Web sessions will be added to a centralized index.
  5. Disable HTTPS indexing By default, Google Desktop indexes all cached Web pages, even if they're secure (HTTPS). Deactivating the "secure Web pages (HTTPS)" preference will prevent the indexing of sensitive information. Most other DSEs do not offer such functionality.
"


Wednesday, December 07, 2005

How to hijack a podcast

There is an interesting story about a hijacked podcast at eWeek. It includes details of how a vegan podcaster's feed was hijacked and held for ransom. From the article:

"The manner in which the purported hijacking occurred exemplifies the fact that RSS feeds are far more vulnerable to squatters than Web site domains. The method doesn't require stolen passwords or other overtly illegal methods.

Rather, it merely involves finding a target Podcast and creating a unique URL for it on a Web site that the hijacker can control. The hijacker then points his URL to the RSS feed of the target Podcast.

Next, the hijacker does whatever it takes to ensure that, as new Podcast engines come to market, the page each engine creates for the target Podcast points to the hijacker's URL instead of to the Podcast creator's official URL.
"

Tags:

Tuesday, December 06, 2005

New go aggregation site online

Go Aggregator goes live!

There really is a wealth of English language Go / Weiqi / Baduk news, games, discussions, and blogs on the net now, and far too many English speaking go enthusiasts limit their online time to a Go server like KGS or IGS and Sensei's Library. While these places are great - in fact, they are spectacular - there is a lot more Go online that many would enjoy. So, with a little help from Blogger, Feedburner, and Feeddigest, I have put together Go Aggregator to help Go players find and stay on top of the incredible online Go resources that change daily. Check it out.

Tags:

About Me

My photo
Edmonton, Alberta, Canada
Returned to working as a Management Consultant, specializing in risk, security, and regulatory compliance, with Fujitsu Canada after running the IT shop in the largest library in the South Pacific.

CC Developing Nations
This work is licensed under a Creative Commons Developing Nations license.

Site Meter