Privacy Digest

News that can impact your privacy.
Login/Register
  • Create new account
  • Request new password
Home Blogs MacRonin's blog
  • FAQ
  • Wishlists
  • Contact
  • Categories/RSS

Bookmark Us

Bookmark Privacy Digest 
Bookmark This Page 

RSS Feed + Site Map

Syndicate content
more

Advertisements

GPS Tracking
Search By Phone Number
Hosting
Home Security Systems Toronto
Mercedes-Benz Luxury Cars News
Disk Encryption
spy camera

Popular content

Last viewed:

  • Israeli Hacker 'The Analyzer' Indicted in New York
  • Olympics reach a new low: trademarking the Canadian national anthem and threatening lawsuits over competing uses
  • Did NSA Put a Secret Backdoor in New Encryption Standard? by Bruce Schneier
  • Photo Ticket Cameras to Track Drivers Nationwide / Vendors plan to add spy technology to existing red light camera and speed cam
  • Discrimination in the genes
  • Former Justice Insider, an Unlikely Civil Lib Hero, Details Battles Over Torture and Eavesdopping
  • Internet Mysteries: How Much File Sharing Traffic Travels the Net?

tags in Topics

Activists Alert Companies Congress Copyright Court (US) Databases Data Mining Editorial EFF Entertainment Exploits Fourth Amendment Government Hmmm ID Infrastructure Law Enforcement Laws Politics Privacy Remember Reports Rights Security Software Spin Zone Surveillance Telecommunications Tracking
more tags

Performancing Metrics Blog Statistics
EatonWeb Blog Directory
Listed on BlogShares
View blog authority
Congressional Research
Broadcast Flag

Delving Into Google Health's Privacy Concerns

Submitted by MacRonin on May 27, 2008 - 8:46am.
  • Activists
  • Alert
  • Databases
  • Editorial
  • Google
  • HIPAA
  • Hmmm
  • ID
  • Infrastructure
  • Privacy
  • Security
  • Spin Zone

Delving Into Google Health's Privacy Concerns - Via Slashdot: Your Rights Online:

SecureThroughObscure writes "Security researcher Robert 'RSnake' Hansen discusses numerous concerns with Google's new Google Health application, which aims to integrate user's medical records online. We discussed Google Health's opening to the public earlier this week. RSnake mentions that Google has found a loophole allowing them to provide this service without having to follow HIPAA regulations, which, combined with Google's track record of having numerous flaws leading to private information disclosure, draws serious concern. Security researcher Nate McFeters of ZDNet's Zero-Day Security Blog also commented on the article, mentioning several past vulnerabilities: ownership of content issues, Google Docs theft, a cross-domain hole, Google XSS, and a Google Picasa protocol handler issue leading to the theft of user images. He and fellow researcher Billy Rios disclosed these issues to Google, including the ability to steal GMail contact list information. McFeters says it's likely that similar unpatched bugs would allow an attacker to view medical records if a user was also using Google Health. Both McFeters and Hansen tend to agree that Google's vulnerability disclosure/notification is non-existent and really needs to be improved. Currently, Google does not report vulnerabilities it has fixed to its user base, for the obvious reason of trying to hide the fact that user data could have been stolen."

(Read Original Article - Via Slashdot: Your Rights Online.)


Bookmark/Search this post with:
  • Delicious Delicious
  • Digg Digg
  • Reddit Reddit
  • Google Google
  • Yahoo Yahoo
  • Technorati Technorati
  • MacRonin's blog
  • Add new comment

Recent blog posts

  • Apple patching serious SMS vulnerability on iPhone
  • Enter the Advertisers - self-regulatory principles ?
  • Out of business, Clear may sell customer data
  • TSA asked to ensure safety of customer data after Clear closing
  • Several Facts about Google and HTTPS
  • China thinks twice – and its 300m internet users scent a rare victory
  • Did the Sanford E-Mail Tipster or the Newspaper Break the Law?
  • Supreme Court Serves Up Remote-Recording Victory
  • Deep-Packet Inspection in U.S. Scrutinized Following Iran Surveillance
  • ATM Vendor Halts Researcher’s Talk on Vulnerability
more
Compilation © Copyright 1997-2009 Paul Hardwick, with Web Hosting provided by MacRonin.com.