Auto Check

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Tuesday, 19 February 2013

An update on our war against account hijackers

Posted on 09:00 by Unknown
Have you ever gotten a plea to wire money to a friend stranded at an international airport? An oddly written message from someone you haven’t heard from in ages? Compared to five years ago, more scams, illegal, fraudulent or spammy messages today come from someone you know. Although spam filters have become very powerful—in Gmail, less than 1 percent of spam emails make it into an inbox—these unwanted messages are much more likely to make it through if they come from someone you’ve been in contact with before. As a result, in 2010 spammers started changing their tactics—and we saw a large increase in fraudulent mail sent from Google Accounts. In turn, our security team has developed new ways to keep you safe, and dramatically reduced the amount of these messages.

Spammers’ new trick—hijacking accounts
To improve their chances of beating a spam filter by sending you spam from your contact’s account, the spammer first has to break into that account. This means many spammers are turning into account thieves. Every day, cyber criminals break into websites to steal databases of usernames and passwords—the online “keys” to accounts. They put the databases up for sale on the black market, or use them for their own nefarious purposes. Because many people re-use the same password across different accounts, stolen passwords from one site are often valid on others.

With stolen passwords in hand, attackers attempt to break into accounts across the web and across many different services. We’ve seen a single attacker using stolen passwords to attempt to break into a million different Google accounts every single day, for weeks at a time. A different gang attempted sign-ins at a rate of more than 100 accounts per second. Other services are often more vulnerable to this type of attack, but when someone tries to log into your Google Account, our security system does more than just check that a password is correct.

Legitimate accounts blocked for sending spam: Our security systems have dramatically reduced the number of Google Accounts used to send spam over the past few years

How Google Security helps protect your account
Every time you sign in to Google, whether via your web browser once a month or an email program that checks for new mail every five minutes, our system performs a complex risk analysis to determine how likely it is that the sign-in really comes from you. In fact, there are more than 120 variables that can factor into how a decision is made.

If a sign-in is deemed suspicious or risky for some reason—maybe it’s coming from a country oceans away from your last sign-in—we ask some simple questions about your account. For example, we may ask for the phone number associated with your account, or for the answer to your security question. These questions are normally hard for a hijacker to solve, but are easy for the real owner. Using security measures like these, we've dramatically reduced the number of compromised accounts by 99.7 percent since the peak of these hijacking attempts in 2011.


Help protect your account
While we do our best to keep spammers at bay, you can help protect your account by making sure you’re using a strong, unique password for your Google Account, upgrading your account to use 2-step verification, and updating the recovery options on your account such as your secondary email address and your phone number. Following these three steps can help prevent your account from being hijacked—this means less spam for your friends and contacts, and improved security and privacy for you.

Posted by Mike Hearn, Google Security Engineer
Email ThisBlogThis!Share to XShare to Facebook
Posted in privacy and security, security | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • Hulu Plus now works with Chromecast
    Hulu has added Chromecast support to their Hulu Plus app—just in time for the fall television season. Now you can easily enjoy your favori...
  • Providing a springboard for women entrepreneurs in India
    Meghana Musunuri was a typical female entrepreneur in India. Born and brought up in Medak , she received a good education and spent time ab...
  • A look inside our 2011 diversity report
    We work hard to ensure that our commitment to diversity is built into everything we do—from hiring our employees and building our company cu...
  • Software downloads in Syria
    Free expression is a fundamental human right and a core value of our company—but sometimes there are limits to where we can make our product...
  • Celebrating teachers on National Teacher Day
    One of the best parts of my job working on the Google Education team has been hearing inspiring stories time and again of great teachers who...
  • Shiver me timbers, the 2012 D4G Winner is....
    After 114,000 submissions and millions of your votes, second grader Dylan Hoffman of Caledonia, Wisc. is this year’s U.S. Doodle 4 Google N...
  • Supporting Innovation in African News
    Cross-posted from the European Public Policy Blog We’re eager to see journalism flourish in the digital age, in all forms and on all contine...
  • Google+ Hangouts On Air: broadcast your conversation to the world
    Last year we introduced Hangouts On Air to a limited number of broadcasters, enabling them to go live with friends and fans, for all the wo...
  • New research shows smartphone growth is global
    Last October, we launched Our Mobile Planet , a resource enabling anyone to visualize the ways smartphones are transforming how people conne...
  • Local—now with a dash of Zagat and a sprinkle of Google+
    Finding the best places to go is an essential part of our lives, as are the people and resources that help us make those decisions. In fact,...

Categories

  • accessibility
  • acquisition
  • ads
  • Africa
  • Android
  • apps
  • Asia
  • books + book search
  • chrome
  • chrome + chrome os
  • commerce
  • computing history
  • crisis response
  • Cultural Institute
  • culture
  • developers
  • display advertising
  • diversity
  • doodles
  • education
  • education and research
  • energy
  • enterprise
  • entrepreneurs at Google
  • entrepreneurship
  • Europe
  • events
  • faster web
  • free expression
  • g2g
  • giving
  • Google Apps highlights
  • google ideas
  • google play
  • google.org
  • google+
  • googleplus
  • googlers and culture
  • government transparency
  • green
  • innovation
  • ipv6
  • journalism and news
  • Latin America
  • local
  • maps and earth
  • mobile
  • online safety
  • open source
  • personalization
  • photos
  • policy and issues
  • politics
  • privacy
  • privacy and security
  • publishers
  • scholarships
  • search
  • search stories
  • search trends
  • security
  • security and safety tips
  • small business
  • transparency
  • youtube and video

Blog Archive

  • ▼  2013 (190)
    • ►  December (11)
    • ►  November (13)
    • ►  October (15)
    • ►  September (12)
    • ►  August (10)
    • ►  July (13)
    • ►  June (28)
    • ►  May (16)
    • ►  April (21)
    • ►  March (18)
    • ▼  February (19)
      • Making the cloud more accessible with Chrome and A...
      • Support free expression: Vote for the Netizen of t...
      • Race to win on big and small screens with Chrome S...
      • From top dresses to last-minute surprises, Google ...
      • Our first-ever Google Journalism Fellowship winners
      • The Chromebook Pixel, for what’s next
      • Doodle 4 Google: A stately competition
      • Oscar fans: we’ve got you covered
      • Fireside Hangouts: Join First Lady Michelle Obama ...
      • An update on our war against account hijackers
      • RISE Awards 2013: A global effort
      • Fireside Hangouts: Join President Obama on Google+...
      • Solve for X: Celebrating moonshot thinking—join us...
      • Zagat: Who’s serving up the best service?
      • A Chrome Experiment made with some friends from Oz
      • Safer Internet Day: How we help you stay secure on...
      • Google and Brazil celebrate Carnival 2013
      • M&M’s, Beyonce and Ravens dominate game day search...
      • Google creates €60m Digital Publishing Innovation ...
    • ►  January (14)
  • ►  2012 (269)
    • ►  December (25)
    • ►  November (20)
    • ►  October (18)
    • ►  September (16)
    • ►  August (19)
    • ►  July (20)
    • ►  June (28)
    • ►  May (30)
    • ►  April (19)
    • ►  March (27)
    • ►  February (23)
    • ►  January (24)
  • ►  2011 (41)
    • ►  December (33)
    • ►  November (8)
Powered by Blogger.

About Me

Unknown
View my complete profile