Google Desktop Privacy? OR Lack Of..

Use Netsparker


With the advent of Web 2.0 and more powerful, user friendly web applications, security and privacy concerns have increased.

Moreso with the new version of Google Desktop coming out, although this is not strictly a web application, they will be storing your data online.

Yes, version 3 adds the ability to “access your documents from anywhere”, or search across machines..meaning they’re sent to Google’s Servers.

EFF’s article about it

And yes, they will RETAIN your data for 30 days.

This means your data is stored WITH Google for 30 days, if you like it or not, so the security of your data is totally under the control of Google, not you.

Not so great eh?

Even with version 3 Google ‘connected’ its Desktop Search software.

Google has unveiled a updated version of its Google Desktop tool that will automatically transfer information between computers.

Google Desktop version 3 allows users to search and access information from any computer that runs the software, a feature that Google refers to as Search Across Computers.

A user could, for instance, access a personal file from his work PC or share information between computers in different rooms in a house.

The new version was very innocently introduced at the Google Blog.

Now there’s v.3, in which you can also search across multiple computers to find your information. You don’t have to worry about where it lives; it’s available anywhere you are. If you’ve ever created a document but forgot whether it’s on your laptop or desktop, then you can appreciate why we built this feature.

Imagine the implication of this aswell, if you can hack Google Desktop, or somehow redirect it to Search other peoples machines?

Imagine the fun we are going to have with this.

Plus the added prize now of breaking into Googles datacenter, with thousands or perhaps millions of PC’s cached their with all that lovely private data.

Something to think about eh?

We’ll be writing more about AJAX/Web 2.0 security soon, watch this space.

Posted in: Windows Hacking

, , , , ,


Latest Posts:


StaCoAn - Mobile App Static Analysis Tool StaCoAn – Mobile App Static Analysis Tool
StaCoAn is a cross-platform tool which aids developers, bug bounty hunters and ethical hackers performing mobile app static analysis on the code of the application for both native Android and iOS applications.
snallygaster - Scan For Secret Files On HTTP Servers snallygaster – Scan For Secret Files On HTTP Servers
snallygaster is a Python-based tool that can help you to scan for secret files on HTTP servers, files that are accessible that shouldn't be public and can pose a s
Portspoof - Spoof All Ports Open & Emulate Valid Services Portspoof – Spoof All Ports Open & Emulate Valid Services
The primary goal of the Portspoof program is to enhance your system security through a set of new camouflage techniques which spoof all ports open and also emulate valid services on every port.
Cambridge Analytica Facebook Data Scandal Cambridge Analytica Facebook Data Scandal
One of the biggest stories of the year so far has been the scandal surrounding Cambridge Analytica that came out after a Channel 4 expose that demonstrated the depths they are willing to go to profile voters, manipulate elections and much more.
GetAltName - Discover Sub-Domains From SSL Certificates GetAltName – Discover Sub-Domains From SSL Certificates
GetAltName it's a little script to discover sub-domains that can extract Subject Alt Names for SSL Certificates directly from HTTPS websites which can provide you with DNS names or virtual servers.
Memcrashed - Memcached DDoS Exploit Tool Memcrashed – Memcached DDoS Exploit Tool
Memcrashed is a Memcached DDoS exploit tool written in Python that allows you to send forged UDP packets to a list of Memcached servers obtained from Shodan.


2 Responses to Google Desktop Privacy? OR Lack Of..

  1. Ben February 15, 2006 at 7:25 am #

    It truly would be a handy feature to be able to access your documents anywhere in this fashion; but, the possible security problems would make it quite risky. Especially considering the recent hack of gmail. Thanks for pointing this out, might have saved me from having a bunch MORE personal documents searchable on google.
    Try on google search: filetype:qbb
    Dangerous amount of stuff in google already.

  2. Darknet February 15, 2006 at 7:53 am #

    Ben: Yah I agree it might be a good feature, but well implemented the wrong way…30 day retention on their servers if you want to use the feature? Not a good idea if you ask me. Yeah you should check out the Google Hacks Database :)