Monday, January 18, 2010

Yes, gmail is still GREAT email!

http://googleblog.blogspot.com/2010/01/new-approach-to-china.html


Although the recent attack on the Googliath of internet email, gmail, was nothing more than a few gmail accounts being compromised through “phishing scams or malware placed on the users’ computers” and not through holes in Google's security systems, it still made headlines worldwide.

Why? Well I believe it may be because many people have a false sense of security that if they use reputable and trusted services or systems, which in themselves are very comprehensive in their security and/or privacy architecture (such as gmail), then their online personal information will always be safe and secure.

Newsflash, it's NOT!

The key issue here was that the hacked accounts were a result of malware or phishing attacks - means that allowed the hackers to bypass the most comprehensive of security systems as a result of the users unknowingly activating or authenticating malware or clicking on a rogue link in a phishing scam. The hackers did not (and probably cannot) compromise Google directly, so they utilised other sneaky means to get in to the gmail accounts.

How? Well think of it like this. You can have the most sophisticated traditional security systems protecting your house, but if you allow an intruder in through a window or door, then all of your traditional security systems render themselves useless in protecting you from the intruder once he’s inside your house. No traditional perimeter or network security systems (windows, doors, grilles, locks, guard dog, CCTV, door camera) can help you once you have allowed (authenticated) the intruder into your living room, right?

Well the same principle applies to our cyber world too! No matter how comprehensive your traditional perimeter or network security systems are (firewall, cryptic username/password, SMS/token authentication tools, antivirus/antispyware scanners, url/phishing filters), they are all helpless if you allow the malware (intruder) to enter into your living room (pc) through a window or door (installing/activating/authenticating the malware on your pc).

In an ideal world, there would exist another much more sophisticated system that would be intelligent enough to protect you from your own self. A system that would be intelligent enough to automatically and instantly determine that the intruder was NOT legitimate and then kill/freeze/suspend/disable him should he manage to enter into your house! Imagine that! Sounds like something from a futuristic sci-fi flick, huh? Bad guy disguised himself and bypassed CCTV, door camera, window grilles and guard dog, only to be then killed/frozen/suspended/disabled in real time by a sophisticated system as soon as he entered your house!

Well although such systems do not exist to protect our domestic world (I am told that a shot gun is not an acceptable system), they DO exist to protect our cyber world!

Yes, that’s right! There is a system out there that still protects your online identity and confidential information in the event that you accidently activate malware on your pc. This system will protect you from malware such as Trojans, viruses, worms and rootkits, as well as phisihing/pharming and MITM/MITB attacks. This means that even if one of these nasties did manage to get onto your pc, your online identity, usernames/passwords, credentials, banking transactions etc will always remain safe and secure from the hacker.

Oh, and surprisingly this system costs much less than my monthly mobile phone recharge and is very simple to install and use. No wonder many high-profile financial institutions are rolling out this system to their online bankers free of charge.

It’s what they refer to as online peace of mind!