Business Intelligence |    Certification |    Cloud Computing |    Community Manager |    CRM/ERP/ETL |    Data Center |    Database |    Enterprise 2.0 |    Enterprise Applications |    Featured stories |    Free Trials |    Green Technology |    Guest Bloggers |    Identity |    Information Technology |    IT Compliance |    IT Decision-making |    Networking |    On-Demand |    Patch Tuesday |    Podcasts |    Programming |    Security |    Social Computing |    Social Media |    Software |    Storage |    Videos |    Virtualization |    Windows |    Wireless

I’m Pretty Sure I Love You, But Still Can’t Prove It
by Tek-Tips

Tek-Tips

The first time I got a whiff of how search engines would work was in a UNIX lab at Cal around ‘93. A couple of guys were hacking out a way to browse the library stacks and they gave me a hint at what things would look like today. Flash forward a couple of years to the Yahoo IPO and we watched as ads rolled across browsers and the dream of truly low hanging fruit from search results intrigued everyone in the advertising world. The big laugh back then was the massive amounts of data that would need to be sorted to be useful to advertising. Then along came those guys from Stanford and the Google Bear.

UNIX - Server

Today we follow Google’s experience in China, that market of 350 million Internet users, hoping upon hope that it will lead to serious opportunities for more technology and science workers. Business around Silicon Valley is working hard to build relationships and deal with the deep mysteries of commerce in the land of the other bear, the one that’s been sleeping these many years.

As expected, "The recent malware hit on Google and other U.S. tech firms showed once again just how hard it is to pin a network strike on a particular person or group. Engineers are pretty sure the attack came from China." Unless Google is at risk, why the public criticisms of China?

According to SecureWorks’ Joe Stewart, in his detailed work on the code, "a snippet of the source code used in the backdoor Trojan horse program planted by the exploit (called “Hydraq” by various anti-virus companies) matched a source code sample that was detailed in a Chinese-language white paper on mathematical algorithms used in electronics."

  - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Mining the Cloud to Ease the Enterprise Compliance Burden
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Operation Aurora: Clues in the Code

"Perhaps the most interesting aspect of this source code sample is that it is of Chinese origin, released as part of a Chinese-language paper on optimizing CRC algorithms for use in microcontrollers. The full paper was published in simplified Chinese characters, and all existing references and publications of the sample source code seem to be exclusively on Chinese websites. This CRC-16 implementation seems to be virtually unknown outside of China, as shown by a Google search for one of the key variables, "crc_ta[16]". At the time of this writing, almost every page with meaningful content concerning the algorithm is China."

Still, having origins in China does not get you a public apology from the government. If that is our demand, just an apology, and a promise to quit what They’re doing, we may want to re-think our approach. After all, why is the government of China not cowering in their boots?

According to www.krebsonsecurity.com, "Chinese Windows users may have the most to lose from the public exploitation of this vulnerability." Former Washington Post blogger, Brian Krebs writes, "that one of China’s most-visited anime sites was recently hacked and seeded with the Aurora exploit, serving those who visited with IE6 a Trojan that dropped at least 32 different malicious programs, including password stealers and tools used to enlist infected PCs in coordinated, distributed cyber attacks." The site goes on to quote Gary Warner, research director at U. of Alabama computer forensics, "“There is just a lot of active exploitation going on in the Chinese market right now, and part of that is because there’s a much larger use of IE6 there than there is over in the United States.”

If Google’s technology was threatened, if that is what the markets are thinking, no one is saying.  Though this week’s 10% drop in share price after decent earnings doesn’t evoke confidence. If you have any feelings on the subject, love to hear from you.

Tags:



Share
                                                 
sharebar end


This entry was posted on Wednesday, January 27th, 2010 at 9:45 AM and is filed under Community Manager. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.


Comments



Leave a Reply
 

 

 
 
 





 
Related Tweets




Syndicated Content
  Impact of Design On Trust
We attended RSA 2010 this week where VeriSign was a Platinum Sponsor. Executive Chairman, Jim Bidzos, gave a Keynote Address on the 'Internet and Trust' explaining that without trust, people are less likely to freely share information or transact online....

Launch of VeriSign Trust Seal
With the launch of the VeriSign TrustTM Seal last week, we introduced a new section to the Website dedicated to the Trust Seal. The Seal enables Websites to communicate that they are a trusted site to do business with and...

New Video Player Experience
Videos on www.verisign.com have a new look and feel. Users will experience an improved delivery of videos that are optimized for their available bandwidth. During playback when hovering over the video, users now have the ability to quickly share (e-mail,...

  PayPal UK Launch Security Key - Guest Posting from PayPal
I am happy to say they are using VeriSign Identity Protection to deliver this, which means that PayPal Customers will be able to use their token at other sites who join the VIP network. PayPal are the first UK members of the network, but there are around 30 other members in different countries around the world so you can expect to see more places where you can use your token in the UK appearing shortly.

Facebook scam - Part 2
This just in from the BBC web site, Symantec have identified a virus that steals user names and passwords, nothing new there. But, if I understand this right, it is delivered through a Facebook invitation from someone you don't know and delivers malware which can then steal user names / passwords and also keylog credit card info.

Survey finds passwords are not secure - well d'uh!
I don't think the vendor community has been crying wolf about the problems that stronger authentication solves, more like highlighting that this problem is here and growing. Well the discussion I have had recently with many different organisations across many different industries are now resulting in more and more consumer projects in this area

  Open Identity Exchange: enabling all the VISAs of identity
The Open Identity Exchange was launched this morning at the RSA conference in San Francisco. It is a significant step for federated identity as it will enable US government web sites such as the NIH to embrace open identity standards...

Rethinking Internet Trust and Reputation
Today, we are launching the VeriSign Trust Seal, a new service for small and medium businesses with an online presence. It is a big day for everyone at VeriSign who has been working really hard on the new service the...

Google Hacked or Why the Cyber World Could Get M.A.D**
As the world already knows, Google and a few other prominent US companies got severely hacked around Christmas time last year. Sophos has an interesting analysis of the exploit. Web malware and a zero day vulnerability in IE6 were...

Search
 Whitepaper   Webcasts  Videos  All

     


Member Login
User Name  :    Password  : 

Register | Forgot Password

Sponsors
        

Sign up to receive email notifications about our newest white papers
.........................................................................
           Full Name  : 
Email Addresss  : 
   Confirm Email  : 


Breaking News
 
Featured stories