One thing that irks me about jerks creating stuff on Google is it is a slow and tedious process getting anything done about it.
I recently had some clown using AppEngine and proxying part of my site along with thousands of pages from other websites, shoving ads on it and scabbing traffic from Google search.
Google's DMCA team took their sweet time to tell me it was just a proxy so I could get bent, and the AppEngine guys were just as helpful.
Reporting AdSense violations and Blogger spam as well is just a black hole of nothingness. If we didn't have a bunch of Google guys here unofficially search results would probably be a lot poorer than they are now.
the last form in question is a valid google form created by google for the purpose it stated. i have used that form. you have to be pretty naive to enter your password data into a google form. if you have ever used google forms, you will know that the data is stored in a spreadsheet.
any person could exploit forms created in salesforce or any other form creation applications on the web with similar results.
I agree. However, is it a stretch to say that those same web users who would put their passwords into a google form are not looking to see if a site is secure, either?
I think there's a subtle difference. Think of a parent who has been told to never enter sensitive information unless the URL has a little green lock. Unfortunately, as shown in the article, these phishing attempts are over SSL and might trick people into believing that the security here is same as connecting to a BoA website over SSL.
I think the difference is, this is not a legitimate website, or even if it were, people must know explicitly using Google Docs, data is stored in plaintext in a spreadsheet. There should be a way to inform users that these forms are different from the forms they normally interact with in other websites.
how are google forms different than other forms on a website?
That was poorly phrased. In "normal" websites, a form sends information to the web server and SSL ensures that no passive or active adversary listening to the wire can compromise our information. What the company does with the information is entirely unknown but hopefully they store it in a secure manner (cc no.s, for eg.)
In the case of Google Docs, all you know from SSL is that your information is securely going to a Google spreadsheet, which is information in the clear. This is different from securely connecting to a BoA server, for eg. I guess, to avoid this phishing, people must also learn to never trust forms that are hosted on Google Docs for sensitive information because the standard use case for Google docs is not to securely store information.
This happened to one of my company's inactive domains too, without me noticing it. How embarassing! The registrar (Afilias, since it was an .info domain) did notice, and put my DNS status on HOLD until I got it fixed. But nobody alerted me! It was just pure luck that I stumbled on the phishing PHP scripts someone put on that domain. Once detected and fixed, it took about a week to get the .info domain active again.
It's quite funny/scary what you can find on Google Docs, really. Start with people who have saved their resumes as public templates, and who knows where you'll end up!
This stumped the researchers, who then turned to Twitter to ask their followers what they thought. Tweets Mikko H. Hypponen, F-Secure's CRO:
"The consensus on Twitter seems to be that the weird page on google.com is a phishing site. The jury's still out though."
OK, that is settled. On the basis of the same experts who rendered the difficult decision of saying #DemiLevatoisBeautiful, the page linked to by Google employees is probably a phishing site. Excellent security research, team!
Mikko Hypponen is a very well-respected security researcher who participates quite actively in a group of highly qualified specialists on Twitter. Your implication that everyone on Twitter is obsessed with the same bits of celebrity culture and whatnot is similar to saying that HN and TMZ are the same since they're both "websites".
It is great that he is a well respected researcher, but I will question him when he implies a site is a phishing site when it quite clearly isn't (I'm sorry, if Google employees really wanted GV numbers/PINs and Gmail addresses, they wouldn't start posting a Google Doc in support forums to get them [1]) on the basis of a "Twitter consensus". I just prefer my researchers to do some actual research, not go off half baked in a public forum.
Why not? In this case, a Twitter consensus is not near sufficient evidence for the claim (especially once you see the actual consensus of 6 guys, one of whom disagrees and none of whom seem to be particularly well regarded researchers: http://www.f-secure.com/weblog/archives/spreads7.png) While it is nice to claim all forums are equal, it just is not true. If he said a group of experts agreed and then linked to their tweets, I wouldn't cry foul. But just claiming a Twitter consensus is like me interviewing the first five people I saw in Times Square and calling it a day.
So some asshole might be using Google Forms for 'phishing' (not confirmed) the same general rule of not submitting sensitive information to that which you don't completely trust still applies.
I recently had some clown using AppEngine and proxying part of my site along with thousands of pages from other websites, shoving ads on it and scabbing traffic from Google search.
Google's DMCA team took their sweet time to tell me it was just a proxy so I could get bent, and the AppEngine guys were just as helpful.
Reporting AdSense violations and Blogger spam as well is just a black hole of nothingness. If we didn't have a bunch of Google guys here unofficially search results would probably be a lot poorer than they are now.