Google fixes major weakness in Google Apps

By Carl Jongsma, Computerworld Australia |  SaaS, Google, Google Apps 2 comments

Something that might have gone unnoticed from Google this week is the patching of a serious vulnerability that previously allowed an attacker to exploit a weakness in Google's Single Sign-On service used with Google Apps to take over a victim's Google account.

While the specific information about the vulnerability was not published until Google had patched the issue, it chains together simple concepts, so it is considered likely that it has already been discovered and used by others.

Single Sign On services, whether it is aborted ideas like Microsoft's PassPort, the current Open-ID, or any number of desktop-based integration tools, all have the same basic weakness. Because they are designed to allow access to varied authenticated resources through the use of a common authentication token of some form, then a compromise of the token allows for access to a much broader set of services and assets than the attacker would have had without the Single Sign On system.

Ultimately, use of Single Sign On technologies can be described as a pure security / usability trade-off. In order to gain the usability of not having to remember / provide unique authentication for a series of services, the security of having properly compartmentalized access to each service is forgone.

2 comments

    Anonymous 2 years ago
    Winter is coming, you and your families still have no ugg boots? Just a problem, Sheepskin boots like ugg classic tall boots is the necessity in the cold witer. Especially in the snow space, ugg classic short boots will keep you warm and safe. At the same time, somebody may say, all of the ugg snow boots, the ugg classic cardy bootsis the best choice. Some online stores also sell these ugg boots at low price, so come on now.
    Anonymous 3 years ago
    If you like to have more information on this vulnerability discovered in the context of a research project called AVANTSSAR, you can access the following link:http://www.ai-lab.it/armando/GoogleSSOVulnerability.html

      Add a comment

      Post a comment using one of these accounts
      Or join now
      At least 6 characters

      Note: Comment will appear soon after you have activated your account.
      Obscene/spam comments will be removed and accounts suspended.
      The information you submit is subject to our Privacy Policy and Terms of Service.

      ITworld LIVE

      SaaSWhite Papers & Webcasts

      White Paper

      The Journey to the Private Cloud

      Both business and IT need the agility enabled by the private cloud. Now you can apply technologies and processes pioneered by public cloud services to your own data center.

      Webcast On Demand

      Navigating the Public Cloud

      InfoWorld contributing editor and consultant David Linthicum offers expert advice about choosing services to outsource to the public cloud providers, cloud data security and identity, integrating public cloud services, and how to avoid provider lock-in.

      Sponsor: Intel

      White Paper

      Moving Service Management to SaaS

      Today, organizations can enjoy similarly substantial benefi ts by migrating their IT service management functions to a software-as-a-service model. This paper shows how Nimsoft Service Desk enables organizations to make the most of this opportunity.

      See more White Papers | Webcasts

      Ask a question

      Ask a Question