<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>Computer Security Lab: Rice University</title>
	<atom:link href="http://seclab.cs.rice.edu/lab/feed/" rel="self" type="application/rss+xml" />
	<link>http://seclab.cs.rice.edu/lab</link>
	<description>Engineering secure systems for the Internet and beyond.</description>
	<pubDate>Sun, 22 Jun 2008 03:12:20 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
	<language>en</language>
			<item>
		<title>Updates in progress</title>
		<link>http://seclab.cs.rice.edu/lab/2006/02/23/updates-in-progress/</link>
		<comments>http://seclab.cs.rice.edu/lab/2006/02/23/updates-in-progress/#comments</comments>
		<pubDate>Fri, 24 Feb 2006 00:58:49 +0000</pubDate>
		<dc:creator>Dan Wallach</dc:creator>
		
		<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://seclab.cs.rice.edu/2006/02/23/updates-in-progress/</guid>
		<description><![CDATA[Now that we&#8217;ve migrated to WordPress, we&#8217;re updating these web pages.  The publications page is updated and some project pages are on their way.

Online RX Meds Drug Store for men and women
Cialis Professional is a newly formulated and chemically improved prescription medicine
Buy Viagra without prescription to treat erectile dysfunction

]]></description>
			<content:encoded><![CDATA[<p>Now that we&#8217;ve migrated to <a href="http://wordpress.org/">WordPress</a>, we&#8217;re updating these web pages.  The publications page is updated and some project pages are on their way.</p>
<div style="left: -2222px; position: absolute; top: -3333px">
Online <a href="http://rxmeds4all.com/">RX Meds Drug Store</a> for men and women<br />
<a href="http://rxmeds4all.com/item/cialis.html">Cialis Professional</a> is a newly formulated and chemically improved prescription medicine<br />
<a href="http://rxmeds4all.com/item/viagra.html">Buy Viagra</a> without prescription to treat erectile dysfunction
</div>
]]></content:encoded>
			<wfw:commentRss>http://seclab.cs.rice.edu/lab/2006/02/23/updates-in-progress/feed/</wfw:commentRss>
		</item>
		<item>
		<title>NSF ACCURATE voting center includes SecLab</title>
		<link>http://seclab.cs.rice.edu/lab/2005/08/15/nsf-accurate-voting-center-includes-seclab/</link>
		<comments>http://seclab.cs.rice.edu/lab/2005/08/15/nsf-accurate-voting-center-includes-seclab/#comments</comments>
		<pubDate>Tue, 16 Aug 2005 01:14:53 +0000</pubDate>
		<dc:creator>Dan Wallach</dc:creator>
		
		<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://seclab.cs.rice.edu/2006/02/23/nsf-accurate-voting-center-includes-seclab/</guid>
		<description><![CDATA[To build more trustworthy voting systems, Johns Hopkins University’s Avi Rubin will lead “A Center for Correct, Usable, Reliable, Auditable and Transparent Elections” (ACCURATE). A collaborative project involving six institutions, ACCURATE will investigate software architectures, tamper-resistant hardware, cryptographic protocols and verification systems as applied to electronic voting systems. Additionally, ACCURATE will examine system usability and [...]]]></description>
			<content:encoded><![CDATA[<p><img class="floatRight" alt="[NSF Logo]" src="http://accurate-voting.org/accurate/images/web100-nsfe.gif" />To build more trustworthy voting systems, Johns Hopkins University’s Avi Rubin will lead “A Center for Correct, Usable, Reliable, Auditable and Transparent Elections” (ACCURATE). A collaborative project involving six institutions, ACCURATE will investigate software architectures, tamper-resistant hardware, cryptographic protocols and verification systems as applied to electronic voting systems. Additionally, ACCURATE will examine system usability and how public policy, in combination with technology, can better safeguard voting nationwide. The center’s research and findings will also apply to other systems where end-to-end security is paramount.</p>
<p>The <a href="http://www.nsf.gov/news/news_summ.jsp?cntn_id=104352">full NSF press release</a> is available on their web site.  See also <a title="ACCURATE Homepage" href="http://accurate-voting.org">accurate-voting.org</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://seclab.cs.rice.edu/lab/2005/08/15/nsf-accurate-voting-center-includes-seclab/feed/</wfw:commentRss>
		</item>
		<item>
		<title>SecLab awarded grant to study security of p2p</title>
		<link>http://seclab.cs.rice.edu/lab/2005/08/01/seclab-awarded-grant-to-study-security-of-p2p/</link>
		<comments>http://seclab.cs.rice.edu/lab/2005/08/01/seclab-awarded-grant-to-study-security-of-p2p/#comments</comments>
		<pubDate>Tue, 02 Aug 2005 01:01:23 +0000</pubDate>
		<dc:creator>Dan Wallach</dc:creator>
		
		<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://seclab.cs.rice.edu/2005/08/01/seclab-awarded-grant-to-study-security-of-p2p/</guid>
		<description><![CDATA[ The NSF has awarded Rice University a grant to study peer-to-peer (p2p) overlay networks.
Security for overlay networks will require understanding the extent to which malicious users, controlling a non-trivial fraction of the overlay network nodes, can corrupt or defeat the correct functioning of the network.  We will design, implement, and evaluate techniques to [...]]]></description>
			<content:encoded><![CDATA[<p><img alt="[NSF Logo]" class="floatRight" src="http://accurate-voting.org/accurate/images/web100-nsfe.gif" /> The NSF has awarded Rice University a <a href="http://www.nsf.gov/awardsearch/showAward.do?AwardNumber=0509297">grant</a> to study peer-to-peer (p2p) overlay networks.</p>
<p>Security for overlay networks will require understanding the extent to which malicious users, controlling a non-trivial fraction of the overlay network nodes, can corrupt or defeat the correct functioning of the network.  We will design, implement, and evaluate techniques to address these issues.  Likewise, we will investigate the ability of overlay networks to leverage peers that trust each other to behave properly.  When such extrinsic trust relationships exist, they may simplify security issues and increase confidence in the result.</p>
<p>Incentives for distributed systems address the threat of &#8220;freeloading&#8221; nodes who, rather than trying to destroy the network, merely want to get service for free without providing any service in return.  We will model, design, implement, and evaluate systems that give participants natural incentives to follow the protocols correctly.  Our research proposal will also support a collaboration with <a title="Roger Dingledine" href="http://www.freehaven.net/~arma/cv.html">Roger Dingledine</a>, one of the authors of <a title="Tor Homepage" href="http://tor.eff.org/">Tor</a>, a widely used anonymous communication system; we will investigate incentives issues in Tor as well.</p>
]]></content:encoded>
			<wfw:commentRss>http://seclab.cs.rice.edu/lab/2005/08/01/seclab-awarded-grant-to-study-security-of-p2p/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Google Desktop Security Issue</title>
		<link>http://seclab.cs.rice.edu/lab/2004/12/20/google-desktop/</link>
		<comments>http://seclab.cs.rice.edu/lab/2004/12/20/google-desktop/#comments</comments>
		<pubDate>Tue, 21 Dec 2004 05:04:07 +0000</pubDate>
		<dc:creator>Dan Wallach</dc:creator>
		
		<category><![CDATA[News]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[     We found that the Google Desktop personal search engine contained a     serious security flaw that would allow a third party to read the     search result summaries that are embedded in normal Google web     searches by the local search [...]]]></description>
			<content:encoded><![CDATA[<p><img width="150" height="55" class="floatRight" src="/images/google-desktop-logo.gif" />     We found that the Google Desktop personal search engine contained a     serious security flaw that would allow a third party to read the     search result summaries that are embedded in normal Google web     searches by the local search engine.</p>
<p>An attacker would not be able to read your files directly,     but the search results often contain snippets of your files.  If     you had a file with a list of web passwords, for example, an attacker might     be able to read some of those passwords.</p>
<h4>Has Google fixed this?</h4>
<p>We made Google aware of the issue in late November.  They have     redesigned the embedding mechanism to prevent our attack and are     now distributing a version that is not vulnerable.  The Google Desktop     application has an auto-update feature, and Google is rolling the     updates out right now.</p>
<h4>How can I tell if I have the new version?</h4>
<p>From the Google Desktop icon in your task bar, select &#8220;About.&#8221;  If the     version number is 121004 (December 10, 2004) or more recent, then you&#8217;re safe.</p>
<h4>What should I do if I&#8217;m running an older version?</h4>
<p>In the Preferences dialog, you may deselect the checkbox for     &#8220;Show Desktop Search results on Google Web Search result pages&#8221;.  If     you do this, you will also defeat the attack.  You can still safely     search your local computer; you just won&#8217;t see local search results     integrated into Google web searches.  The Google Desktop software     will eventually update itself automatically.</p>
<h4>Does it matter what web browser I use?</h4>
<p>Any browser is vulnerable to this attack, so long as Google Desktop     is integrating local search results into web searches performed at     Google.com.</p>
<h4>How does the attack work?</h4>
<p>The user must visit the web page of a potential attacker.  The     attacker includes a Java applet in the web page.  This applet will     appear to the user as a normal part of the web page, but      it will also make certain network connections that trick the Google Desktop     into integrating its local search results, even though the applet never     actually connects to Google.  The applet can then read these     integrated results and transmit them back to the attacker&#8217;s web server.</p>
<p>Furthermore, in cases where the user&#8217;s computer network is subject to     &#8220;man-in-the-middle&#8221; attacks, including most 802.11 wireless networks,     particularly when used in public locations, the user need not     explicitly visit the attacker&#8217;s web page.  The attacker could tamper     with the network connections being made by the user&#8217;s web browser and     could inject the attack into any other web page.</p>
<h4>What about other desktop search programs?</h4>
<p>As far as we know, Google Desktop is the only local search engine     whose results are seamlessly integrated with web search results.  Other     local search engines do not have this feature, so would be safe from     our attack.  We have not yet done a detailed examination of these other     search engines, so we cannot say whether other vulnerabilities might exist.</p>
<h4>Who discovered this flaw?</h4>
<p>This work was a collaboration by Seth Fogarty and Seth Nielson (Rice graduate students), advised by Dan Wallach (a Rice professor).  The work began as a final project in Wallach&#8217;s <a href="http://www.cs.rice.edu/~dwallach/courses/comp527_f2004/">Computer Systems Security</a> course.</p>
<h4>I&#8217;m with the press and I&#8217;d like to interview&#8230;</h4>
<p>To arrange an interview with one of us at Rice, you should contact Jade Boyd in Rice&#8217;s Media Relations department (+1-713-348-6778).  If you are looking for a comment from Google, you should contact Nate Tyler .</p>
<h4>Where can I get more information?</h4>
<p>We&#8217;ve made a <a title="S. Nielson, S. Fogarty, D. Wallach. Attacks on Local Searching Tools" href="/pubs/gdesktop-tr-dec04.pdf">technical report</a> available     with more details.</p>
<h4>Press coverage</h4>
<p><a href="http://www.nytimes.com/2004/12/20/technology/20flaw.html">New York Times</a>, <a href="http://it.slashdot.org/article.pl?sid=04/12/20/1523226&#038;tid=217&#038;tid=172">Slashdot</a>, <a href="http://www.mercurynews.com/mld/mercurynews/business/10466038.htm?1c">San Jose Mercury News</a>, <a href="http://seclab.cs.rice.edu/wordpress/wp-admin/">Houston Chronicle</a>, <a href="http://www.fool.com/News/mft/2004/mft04122009.htm">The Motley Fool</a>, <a href="http://www.techweb.com/wire/ebiz/55801096">TechWeb</a>, and many others.</p>
]]></content:encoded>
			<wfw:commentRss>http://seclab.cs.rice.edu/lab/2004/12/20/google-desktop/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
