1. Welcome! Please take a few seconds to create your free account to post threads, make some friends, remove a few ads while surfing and much more. ClutchFans has been bringing fans together to talk Houston Sports since 1996. Join us!

[New York Times] Google Desktop Search: No match for Rice researchers

Discussion in 'BBS Hangout' started by bigtexxx, Dec 20, 2004.

Thread Status:
Not open for further replies.
  1. bigtexxx

    bigtexxx Member

    Joined:
    Jun 12, 2002
    Messages:
    26,980
    Likes Received:
    2,365
    Rice University Computer Scientists Find a Flaw in Google's New Desktop Search Program

    By JOHN MARKOFF
    20 December 2004
    The New York Times
    Late Edition - Final 3
    Copyright 2004 The New York Times Company. All Rights Reserved.

    SAN FRANCISCO, Dec. 19 -- A Rice University computer scientist and two of his students have discovered a potentially serious security flaw in the desktop search tool for personal computers that was recently distributed by Google.

    The glitch, which could permit an attacker to secretly search the contents of a personal computer via the Internet, is what computer scientists call a composition flaw -- a security weakness that emerges when separate components interact. ''When you put them together, out jumps a security flaw,'' said Dan Wallach, an assistant professor of computer science at Rice in Houston, who, with two graduate students, Seth Fogarty and Seth Nielson, discovered the flaw last month. ''These are subtle problems, and it takes a lot of experience to ferret out this kind of flaw,'' Professor Wallach said.

    Google introduced a test version of the desktop search tool on Oct. 14, and it can be downloaded at no cost. The program indexes material on a user's local hard disk and then blends Web search results with local user information like electronic mail, text documents and other files. The flaw would permit a search to reveal only small portions of the files.

    The way the software tool is designed, a user's queries, but no locally stored information, is distributed via the Internet. But by reading user queries sent to its search service, Google is able to place its AdWords text advertisements next to the search results displayed in a user's browser window.

    In a statement over the weekend, the company said that it had been notified of the flaw by the computer researchers in late November and had begun distributing a new version of the desktop search engine that repairs the potential security hole. Google's introduction of a desktop search tool has touched off a competition with its closest Web search service competitors, Microsoft and Yahoo.

    Microsoft made a test version of its desktop search tool available last Monday as part of its MSN toolbar suite, and Yahoo has said that it will begin testing a similar search tool in January.

    The Rice University researchers said that they had not yet examined Microsoft's desktop search program, but noted that the service did not appear to integrate Web and local search results in the same manner as the Google tool.

    The researchers said that the Google security weakness lay in the way that Google Desktop was designed to intercept outgoing network connections from the user's computer.

    The program looks for traffic that appears to be going to Google.com and then inserts results from a user's hard disk for a particular search. They found that it was possible to trick the Google desktop search program into inserting those results into other Web pages where an attacker could read them.

    An attack would require a user to visit the attacker's Web site first, and any type of Web browser could make a user vulnerable. Google said there was no evidence that any such attacks had occurred.

    The Rice group was able to create a Java program that makes network connections back to the computer from where it was downloaded and then make it appear as if it were asking for a search at Google.com. That was enough to fool the Google desktop software into providing the user's search information. The program was able to do anything with the results, including transmitting them back to the attacking site.

    ''This began as a student project to study how Google Desktop worked and to see if there were any security flaws,'' said Professor Wallach. ''We started by wondering how Google did the local search integration. Once we figured out how it worked, it wasn't too much extra work to break it.''

    The researchers said that Google had responded quickly to their alert last month and had begun releasing a corrected version of the program on Dec. 10.

    The Google desktop program includes an update feature that permits the company to automatically install new versions of the program on users' computers without user intervention or knowledge.

    The Rice researchers said that it was possible for users to tell if their version of the Google program had been patched by examining the ''about'' page from the Google Desktop icon in the browser task bar. Version numbers above 121,004 indicate a newer edition of the program.

    www.nytimes.com/2004/12/20/technology/20flaw.html?oref=login
     
  2. twhy77

    twhy77 Member

    Joined:
    Nov 21, 2002
    Messages:
    4,041
    Likes Received:
    73
    This just in....

    NEW YORK TIMES

    Houston (AP)--

    Recent studies have shown that a surpirsingly high number of Rice Graduates have what can commonly be called "small penis disease." Usually found in young men driving Mustang's (not in the lower half of Texas for there the Mustang is a way of life) and Pontiac Firebirds, in which meticulous time has been spent to create an engine that goes vroom vroom, the disease seems to have spread to internet message boards. Research is still being done to see what the cause is, but some have stated the cause might be in the way Rice students shower. Young men are required to work up a "manly lather" of soap suds while showering with their loofahs (whatever the hell that is-- what happened to good old soap?). Internet junkies are advised to be aware of their "shout downs" as they struggle to prove that they just might have a regular sized wiener.
     
  3. Jeff

    Jeff Clutch Crew

    Joined:
    Feb 14, 1999
    Messages:
    22,412
    Likes Received:
    362
    geek vs. geek

    winner: geek!
     
  4. BrianKagy

    BrianKagy Member

    Joined:
    Feb 14, 1999
    Messages:
    4,106
    Likes Received:
    6
    Like "Spy vs. Spy" except people who read Mad magazine probably get laid more often.
     
  5. Mulder

    Mulder Member

    Joined:
    Nov 20, 1999
    Messages:
    7,118
    Likes Received:
    81
    Reason # 963 to buy a Mac.
     
  6. meggoleggo

    meggoleggo Member

    Joined:
    Aug 21, 2003
    Messages:
    4,402
    Likes Received:
    48
    AWESOME.

    My favorite post this year.
     
  7. twhy77

    twhy77 Member

    Joined:
    Nov 21, 2002
    Messages:
    4,041
    Likes Received:
    73
    I feel like honored and stuff. :)
     
  8. bigtexxx

    bigtexxx Member

    Joined:
    Jun 12, 2002
    Messages:
    26,980
    Likes Received:
    2,365
    Not funny, not original, and just plain stupid. The word "penis" was funny in junior high, though, I'll give you that.

    If it puts your mind at ease, I will assure you that I get laid plenty, my friend.
     
  9. MadMax

    MadMax Member

    Joined:
    Sep 19, 1999
    Messages:
    76,683
    Likes Received:
    25,924
    oh, man..that's rich.
     
  10. twhy77

    twhy77 Member

    Joined:
    Nov 21, 2002
    Messages:
    4,041
    Likes Received:
    73
    Help I'm being repressed!

    Brutal internet shoutdown! Somebody please help! I'm being shouted down! I don't even think one should have sex before marriage and I'm being shouted down by one who gets laid so much!! Somebody please help me! I'm cowering!
     
  11. Jeff

    Jeff Clutch Crew

    Joined:
    Feb 14, 1999
    Messages:
    22,412
    Likes Received:
    362
    Why would you post something like that? If you were trying to make yourself look better, that isn't the way to do it.

    And it was funny. :)
     
  12. bigtexxx

    bigtexxx Member

    Joined:
    Jun 12, 2002
    Messages:
    26,980
    Likes Received:
    2,365
    Because it had nothing to do with the original post, it insulted Rice graduates (small penis?? - did you see that part, Jeff?), and it was just plain stupid, like I said.
     
  13. twhy77

    twhy77 Member

    Joined:
    Nov 21, 2002
    Messages:
    4,041
    Likes Received:
    73
    It was more of a knock off of Kagy's NUN RAPING post, but if you feel the need to tell everybody just how great Rice graduates are then you know go ahead, you and T_J seem to have an affinity for it. Sorry if your manhood was insulted.
     
  14. SamFisher

    SamFisher Member

    Joined:
    Apr 14, 2003
    Messages:
    61,864
    Likes Received:
    41,390
    My mind is now at ease!

    [​IMG]
     
  15. Jeff

    Jeff Clutch Crew

    Joined:
    Feb 14, 1999
    Messages:
    22,412
    Likes Received:
    362
    joke
    n.

    1. Something said or done to evoke laughter or amusement, especially an amusing story with a punch line.
    2. A mischievous trick; a prank.
    3. An amusing or ludicrous incident or situation.

    You say stupid. The rest of us say funny.

    Someone is so sensitive. :D
     
  16. Fatty FatBastard

    Joined:
    Jul 13, 2001
    Messages:
    15,916
    Likes Received:
    159
    I'm confused... Which level of security would that be?
     
  17. SamFisher

    SamFisher Member

    Joined:
    Apr 14, 2003
    Messages:
    61,864
    Likes Received:
    41,390
    Jeff we're waiting for an answer.

    Did you see bigtexxx's small penis? Did you see that part? Or not?
     
  18. meggoleggo

    meggoleggo Member

    Joined:
    Aug 21, 2003
    Messages:
    4,402
    Likes Received:
    48
    ROFL! I don't want to know.
     
  19. Austin70

    Austin70 Member

    Joined:
    Jul 6, 2002
    Messages:
    3,531
    Likes Received:
    13
    Do you want to answer that Jeff, or do you want to plead the 5th?
     
  20. Baqui99

    Baqui99 Member

    Joined:
    Jul 11, 2000
    Messages:
    11,495
    Likes Received:
    1,231
    Classic.
     
Thread Status:
Not open for further replies.

Share This Page

  • About ClutchFans

    Since 1996, ClutchFans has been loud and proud covering the Houston Rockets, helping set an industry standard for team fan sites. The forums have been a home for Houston sports fans as well as basketball fanatics around the globe.

  • Support ClutchFans!

    If you find that ClutchFans is a valuable resource for you, please consider becoming a Supporting Member. Supporting Members can upload photos and attachments directly to their posts, customize their user title and more. Gold Supporters see zero ads!


    Upgrade Now