干湿分离什么意思| 眼晴干涩模糊用什么药| 前列腺炎中医叫什么病| 新生儿五行缺什么查询| 脉滑是什么意思| 愚蠢是什么意思| 腹主动脉壁钙化是什么意思| 辰时是什么时候| 尿酸高平时要注意什么| 黄芪配什么不上火| 女生的隐私长什么样子| 支气管炎挂什么科| 耳朵蝉鸣是什么原因引起的| tga是什么| 半月板是什么| 五个月宝宝吃什么辅食最好| 法国铁塔叫什么| 风平浪静是什么生肖| 青字五行属什么| 水变成冰为什么体积变大| 看脚趾头挂什么科| 血糖偏高能吃什么水果和食物最好| 虎鼠不结亲是什么意思| gst是什么意思| 血糖高早餐吃什么| gin是什么意思| 九月二十三是什么星座| 呼吸困难是什么原因引起的| 回归热是什么病| 痛风吃什么药最好| 芭蕉花炖猪心治什么病| 月经推迟量少是什么原因| 什么什么害命| 计发月数是什么意思| 阴火是什么意思| 什么东西去火| 什么是五险一金| 死鱼眼是什么样子的| 小舌头学名叫什么| 二氧化碳有什么作用| 痛经不能吃什么| 吐口水有血是什么原因| 硫酸羟氯喹片治什么病| 18罗汉都叫什么名字| silk是什么意思| 内分泌科看什么病| 胃糜烂要吃什么药| 刑冲破害是什么意思| 搬家 送什么| 阳痿早泄吃什么| 送女生什么生日礼物比较好| 受凉咳嗽吃什么药| 缺硒有什么症状| 静脉曲张什么症状| 逆天是什么意思| 与其让你在我怀中枯萎是什么歌| 锦衣夜行什么意思| 法西斯战争是什么意思| 医学上ca是什么意思| 内膜厚吃什么掉内膜| 叩首是什么意思| zoe是什么意思| 瘢痕体质是什么意思| 胶原蛋白什么牌子好| 是什么数学符号| 港币长什么样| 半边脸疼是什么原因引起的| 下野是什么意思| bp是什么单位| 有血尿是什么原因| 喝鲜羊奶有什么好处和坏处| 甘薯和红薯有什么区别| 玉树临风是什么生肖| 折耳猫什么颜色最贵| 化疗后吃什么药| 织物是什么材质| 血液是什么组织| 缱绻旖旎是什么意思| 猫藓是什么| 头晕出虚汗是什么原因引起的| 公蚊子吃什么| 农历六月十八是什么星座| 泪沟是什么| 蓝莓是什么季节的水果| 压床是什么意思| 阴阳两虚吃什么药最好| 一什么雪| vca是什么牌子| 心花怒放是什么意思| 小肚子一直疼是什么原因| 啤酒是什么味道| 58年属什么今年多大| 乳腺结节是什么病| 假牛肉干是什么做的| 引火上身是什么意思| 优思明是什么药| 猫咪能看到什么颜色| 什么是c刊| 为什么合欢树又叫鬼树| 6月28日什么星座| 心衰做什么检查能确诊| ctp是什么意思| 中午一点半是什么时辰| 窈窕淑女是什么生肖| 发烧呕吐是什么原因| 紧急避孕药吃了有什么副作用| 微波炉不热是什么原因| 茄子不能和什么食物一起吃| 魔芋丝是什么做的| 二月底是什么星座| 女生为什么会长胡子| 人乳头瘤病毒是什么病| 爱新觉罗是什么旗| 香蕉可以做什么美食| 2049年是什么年| 骨折吃什么| 0z是什么单位| 为什么手上会长小水泡| 喉咙发炎用什么药| 职称是什么| 赞赏是什么意思| 天秤座的幸运色是什么| 人出现幻觉是什么原因| 萎缩性胃炎是什么原因引起的| 318号是什么星座| sheep什么意思| 20度穿什么衣服| 女性长胡子是什么原因| 早泄吃什么药最好| 左上腹是什么器官| 娇嫩的意思是什么| 什么是讨好型人格| kda是什么意思| 七月二十是什么星座| 理想主义是什么意思| 父母都没有狐臭为什么孩子会有呢| 9月份是什么星座| 咯血是什么意思| 翡翠属于什么五行| 癌症晚期吃什么食物好| 心窝窝疼是什么原因| 消炎药吃多了有什么副作用| 转移是什么意思| 什么油好| 稷字五行属什么| 什么是闰月| 梦见病人好了什么预兆| 下面痒用什么药效果好| 蛇为什么会咬人| 汽车空调不制冷是什么原因| 益生菌和益生元有什么区别| 超五行属什么| 太阳花是什么花| 胃寒吃什么药好| 古人的婚礼在什么时候举行| 空气是由什么组成的| 汗是什么味道| swissmade是什么意思| 外交部发言人什么级别| 吃什么降血脂最好| 吝啬的意思是什么| 口腔溃疡喝什么水| 劳燕分飞是什么意思| 腰部疼痛挂什么科| 更年期吃什么药调理| 晚饭吃什么最健康| 脾虚生痰吃什么中成药| 得艾滋病的人有什么症状| 什么牌子的助听器最好| 腺体肠化是什么意思| 乳头内陷挂什么科| 170是什么码| 西洋参有什么功效| 茯苓有什么作用和功效| 美国fda认证是什么| 什么人不适合喝骆驼奶| 什么是四环素牙| 原字五行属什么| 胃病烧心吃什么药好| 醋泡脚有什么好处| 感冒了吃什么水果| 食管反流用什么药| 梦见捡到钱是什么预兆| 哺乳期妈妈感冒了可以吃什么药| 安陵容为什么恨甄嬛| cashmere是什么面料| 鱼用什么呼吸| 什么可以去湿气| 十二月十号是什么星座| 筋膜刀是什么| 特应性皮炎是什么意思| 心管是什么部位| 毕业花束选什么花| 老鼠最怕什么东西| mpa是什么单位| 桉是什么意思| 肝胆脾挂什么科| 女生小便带血是什么原因| IOM是什么意思| 伤官女是什么意思| 睡眠时间短是什么原因| 拉杆箱什么材质的好| 山水不相逢什么意思| 头发有点黄是什么原因| 春捂秋冻指的是什么意思| 心字底的字与什么有关| 点背是什么意思| 晚上喝什么茶有助于睡眠| 黄精泡酒有什么功效| 风湿和类风湿有什么区别| 精索静脉曲张是什么意思| 张钧甯为什么读mi| 美业是做什么的| 炭疽是什么病| 电离辐射是指什么| 肩袖损伤吃什么药效果最好| 艾滋病通过什么传染| 什么是电离辐射| 90年属什么| 膜性肾病什么意思| 4月3号是什么星座| 胡子发黄是什么原因| 安徽有什么土特产| 蜕变是什么意思| 吃什么补黑色素最快| 什么什么和谐| 吹空调喉咙痛什么原因| 血热吃什么药好得快| 睡眠不好吃什么药| 煲什么汤含蛋白质高| 克氏针是什么| 什么叫一桌餐| 人瘦了是什么原因| 窦性心动过速是什么意思| 求嗣是什么意思| 天龙八部是什么朝代| 夜游神是什么意思| 哑巴是什么生肖| 11月份是什么星座| 夜猫子是什么意思| 节点是什么| 嗯呢什么意思| 糖尿病吃什么食物| 肠炎什么症状| 1959属什么生肖| 磨蹭是什么意思| 17592a是什么尺码男装| 老年人腿无力是什么原因导致的| 始祖鸟是什么鸟| 怀孕周期是从什么时候开始算的| 低压偏高是什么原因引起的| 黑下打信是什么任务| 老鼠跟什么属相最配| 乙巳年是什么命| 芥蒂什么意思| 托大是什么意思| 斗战胜佛是什么意思| 早上起床腰酸痛是什么原因| 未时是什么时辰| 外阴白斑瘙痒抹什么药| 痰核是什么意思| 七匹狼男装是什么档次| 绿豆什么时候成熟| 金鱼沉底不动什么原因| 百度

Security Blog

The latest news and insights from Google on security and safety on the Internet

Security warnings for suspected state-sponsored attacks

June 5, 2012
Share on Twitter Share on Facebook
Google

32 comments :

Kevin said...

I still wonder how. Some custom plugin or HTTP header?

June 5, 2012 at 3:42 PM
Unknown said...

Except when it comes to USGov intrusion, which is where Google makes half its money.

June 5, 2012 at 3:53 PM
Richard Teahon said...

I know you guys have been getting some bad press lately, and as an SEO I can understand why, but I can only compliment you in this move to alert people who are probably going to be hit by trying to be good, no scrub that, outstanding citizens by trying to bring the truth to the masses.
It is hard enough for us to get the message across in the west, in places where state sanctioned violence is commonplace, say Syria for example, then this initiative by Google is invaluable.
It does in my book keep you above Microsoft.

June 5, 2012 at 4:37 PM
Ken Montenegro said...

Does this include activity from government actors such as municipal and state police forces? how about federal agencies (or .gov IP blocks)? Thanks!

June 5, 2012 at 4:37 PM
Mike said...

Wow.

June 5, 2012 at 5:05 PM
Ian Danforth said...

I applaud this warning and would only hope that in cases where evidence is strong enough the state in question is identified to the user.

June 5, 2012 at 5:08 PM
Unknown said...

This is helpful information, we will help spread the word.

June 5, 2012 at 5:25 PM
robinm said...

Why would an end user care? Surely this is state-sponsored propaganda?

June 5, 2012 at 5:29 PM
Adriel said...

I'd imagine that the people who are targeted by these attacks will know exactly which state would be interested in hacking into their account. Good on ya Google.

June 5, 2012 at 6:25 PM
Unknown said...

Any chance of a link to the page?

June 5, 2012 at 7:43 PM
Arron Ferguson said...

If you see this warning it does not necessarily mean that your account has been hijacked. It just means that we believe you may be a target, of phishing or malware for example, and that you should take immediate steps to secure your account.

I had this happen a few months ago. I got a rather worthless message after the fact (I did have a secondary email registered for such reasons) stating that my account had been compromised and I was alerted that there were current sessions open (in the Eastern block of Europe - I'm in Canada).

What boggles my mind is that Google's "crack security team" here had really nothing to offer other than "close the sessions" and change the password.

What Google and you are telling the entire world is that Google's security team is lazy; rather than just detect and log the incident, how about block/ignore/redirect brute force requests/logins?

Seriously, you guys want us to trust you with something like Google+ and this is what you have to offer for security? Fail!

June 5, 2012 at 8:04 PM
ASMR said...

Wow... Are there enough people wearing white collars and eating Swanson TV dinners to strike the fear nuclear war into everybody?

June 5, 2012 at 9:51 PM
Anonymous said...

Since New York Times recently reported that Stuxnet is a US State Sponsored Cyber virus - which if you recall was accidentally released into the wild and affected and attacked innocent end-user machines as collateral damage, and with the ongoing US-Israeli state sponsored cyber warfare weapons of mass destruction (operation Olympic Games) including the more recent Duqu and Flame virus.... can Google clarify if through its detailed analysis as well as victim reports if Google will apply the same standards and warn end-users of these domestic state sponsored attacks as well? Or are exceptions of convenience made in these cases due to the close and special ties that Google has with the US intelligence agencies and the confirmed but secret and classified collaboration that the Google has with the CIA and NSA in regards to GMail and Google Accounts?

June 5, 2012 at 10:52 PM
林忌 said...

It's from the PRC

People Republic of China

June 5, 2012 at 11:29 PM
Julieta Lionetti said...

Google, I'm impressed by you going out on a limb so far. I applaud this warning and will help spread the word.

Well, you are not being evil, after all.

June 5, 2012 at 11:43 PM
Bibin said...

Non US sponsored attacks - right ??

June 6, 2012 at 12:18 AM
Tenpa Gurmey Khangsar said...

I THINK THEY ARE TAKING ABOUT CHINESE GOVERNMENT

June 6, 2012 at 1:05 AM
randall said...

On a lighter note, hikingfan lives a more interesting life than I figured if he's attracted the attention of state actors.

June 6, 2012 at 1:19 AM
Anonymous said...

I believe it should be at a macro level by determining how many users will be affected by same pattern etc.. (using complex methods like geography, type of users, area of attack and so on..)

regards
www.diaryfolio.com

June 6, 2012 at 2:30 AM
ArthurX said...

I think it's good to warn users of suspicious activities, but my guess is that there also are activities like US surveillance that will not be announced, because of local court orders. Google is in no way independent.

June 6, 2012 at 5:36 AM
Adrian said...

Will Google alert users possibly infected by other types of malware than DNSChanger and not connected with certain .gov-targeted attacks?

For example i'm infected with some type of rootkit, which added my PC to botnet. My AV system doesn't alerts me - do Google system will alert me?

June 6, 2012 at 6:15 AM
Unknown said...

...good step in the right direction, if and only if there would be no bias with respect to the states behind the attacks...

June 6, 2012 at 7:32 AM
Anonymous said...

@Adrian: no, I'm pretty certain that this is simply identifying known or likely items within an email that you receive.

@eroei1021: given that Stuxnet, Duqu, Flame do not, to the best of my knowledge, rely on phishing emails as a delivery vector, this would not apply to them.

June 6, 2012 at 10:28 AM
Fellow Traveler said...

This entire page requires a premise that states do not act for our good -- but that they instead often act maliciously.

What steps can we take to insure that authorities and majorities are not able to trample on our rights to life, liberty, and property?

June 6, 2012 at 12:22 PM
Unknown said...

"We can’t go into the details without giving away information that would be helpful to these bad actors ..." and we would never dream of sharing and technical insights that might help the competition provide you the same level of security as we do, that would affect our bottom line. Right?

Oh, and could you please get one of your writers to pick a dictionary and use a slightly more specific qualifier than 'bad' for the actors? What is 'bad' anyway? Sure Google is a young high tech company, but dismissing 2000 years of research into human morality by using such childish language : 'the good guys vs. the bad guys' is way below the level of maturity we've come to expect out of google.

June 6, 2012 at 1:10 PM
makaseh said...

With Makaseh (makaseh.wordpress.com) this will not possible. Data can only be exchanged with the makaseh ids created. Data intercepted, copied or shared without authorization by the originator cannot be viewed and any attempt to break it, will send a cautionary note to the originator with the ip address, email details etc. Repeated attempts may even lead to the deactivation of the culprit userid.

June 10, 2012 at 12:37 AM
makaseh said...

If self promotion is shameless, how about companies that intrude privacy, steal information from data stored and use it for profit.

June 11, 2012 at 2:59 AM
DonFphrnqTaub ? Persina ? Persina ? Persina ? Persina hopiakuta kutahopia altacalifernia altacalifernian altacalifernean altacaliferni altacalifernea altacaliferne altacalifern altacalifer altacalife said...

« state-sponsored »‽ Florida, Iran, North Korea‽

This captcha is not disability accessible.

June 12, 2012 at 8:25 PM
AvelWorldCreator said...

Given that you provide a similar service for detecting improper email access, I'd be concerned. I've seen a quite definite fail of that service with my mother's GMail account. Apparently someone was remote accessing her account using an email program (not a browser) to comb her contacts and send spam. We are in the Central U.S.A. Her account IP log showed the two hits from someone in Mexico, yet the service did not detect, or flag, this irregular IP address.

June 13, 2012 at 9:47 PM
Ellie K said...

@AvelWorldCreator: That is a good point. I am familiar with that light blue framed page from Google Gmail. It provides a record of IP addresses and approximate locations, at a country level (and for the U.S., at state but not city level) from where one's account was recently accessed. About a year ago, I received an email from Google Gmail, advising me that there may have been some unusual recent activity on my account. It was mildly worded, nothing about powers of a foreign nation or such. Indeed, there was multiple access from 2 different IP's in Iran via IMAP or POP, and 3 from Arizona, via browser. All were within a 24-hour interval. I have never accessed Gmail from anywhere other than Arizona, so it was a good catch by Gmail.

On the other occasion, I did not receive any warning. I had just happened to check the same unusual activity link, which often resides at the footer of my Gmail inbox screen, even when all is well. Reddit offers a similar feature, in fact. So anyway, I was curious, given the Arizona-and-Iran incident of a few weeks prior. I was surprised to find a pattern of access, in alternating sequence, at less than 60 minute intervals, between my Arizona IP address and one in Washington State. Once again, Arizona access was by browser, and the other IP via IMAP. I tracked the latter to Amazon dot com's legal department. I never found out why they (or someone using EC2 or AWS perhaps?) would be reading my email. Nor did Google flag this as unusual activity.

I took screen shots, both times, but have no idea who to send it to. Or if Google would even consider it pertinent. I can't imagine why anyone, whether Iran or Amazon dot com, would want to access my boring and inconsequential information. Botnet perhaps, for spam purposes? Well, not by Amazon!

@Eric Grosse of Google Security Engineering: What is the difference is between the IP notification screen that I just alluded (at excessive length) and this new notification? Yes, I realize that they appear in different places, and have different wording. But does the Gmail-related anomalous IP message have any relationship to, or is it indicative of, the same problems flagged by this new message i.e. if I am afflicted by one problem, am I also compromised by the other?

June 14, 2012 at 7:46 AM
Anonymous said...

This is great news. Thank you google for helping us combat these perpetrators.

August 20, 2012 at 11:09 AM
Anonymous said...

I saw this security warning the other day and i was baffled to say the least. It was right after I was looking at home security systems reviews online too. What a coincidence.

February 13, 2013 at 6:47 PM

Post a Comment

  

Labels


  • #sharethemicincyber
  • #supplychain #security #opensource
  • AI Security
  • android
  • android security
  • android tr
  • app security
  • big data
  • biometrics
  • blackhat
  • C++
  • chrome
  • chrome enterprise
  • chrome security
  • connected devices
  • CTF
  • diversity
  • encryption
  • federated learning
  • fuzzing
  • Gboard
  • google play
  • google play protect
  • hacking
  • interoperability
  • iot security
  • kubernetes
  • linux kernel
  • memory safety
  • Open Source
  • pha family highlights
  • pixel
  • privacy
  • private compute core
  • Rowhammer
  • rust
  • Security
  • security rewards program
  • sigstore
  • spyware
  • supply chain
  • targeted spyware
  • tensor
  • Titan M2
  • VDP
  • vulnerabilities
  • workshop


Archive


  •     2025
    • Jul
    • Jun
    • May
    • Apr
    • Mar
    • Feb
    • Jan
  •     2024
    • Dec
    • Nov
    • Oct
    • Sep
    • Aug
    • Jul
    • Jun
    • May
    • Apr
    • Mar
    • Feb
    • Jan
  •     2023
    • Dec
    • Nov
    • Oct
    • Sep
    • Aug
    • Jul
    • Jun
    • May
    • Apr
    • Mar
    • Feb
    • Jan
  •     2022
    • Dec
    • Nov
    • Oct
    • Sep
    • Aug
    • Jul
    • Jun
    • May
    • Apr
    • Mar
    • Feb
    • Jan
  •     2021
    • Dec
    • Nov
    • Oct
    • Sep
    • Aug
    • Jul
    • Jun
    • May
    • Apr
    • Mar
    • Feb
    • Jan
  •     2020
    • Dec
    • Nov
    • Oct
    • Sep
    • Aug
    • Jul
    • Jun
    • May
    • Apr
    • Mar
    • Feb
    • Jan
  •     2019
    • Dec
    • Nov
    • Oct
    • Sep
    • Aug
    • Jul
    • Jun
    • May
    • Apr
    • Mar
    • Feb
    • Jan
  •     2018
    • Dec
    • Nov
    • Oct
    • Sep
    • Aug
    • Jul
    • Jun
    • May
    • Apr
    • Mar
    • Feb
    • Jan
  •     2017
    • Dec
    • Nov
    • Oct
    • Sep
    • Jul
    • Jun
    • May
    • Apr
    • Mar
    • Feb
    • Jan
  •     2016
    • Dec
    • Nov
    • Oct
    • Sep
    • Aug
    • Jul
    • Jun
    • May
    • Apr
    • Mar
    • Feb
    • Jan
  •     2015
    • Dec
    • Nov
    • Oct
    • Sep
    • Aug
    • Jul
    • Jun
    • May
    • Apr
    • Mar
    • Feb
    • Jan
  •     2014
    • Dec
    • Nov
    • Oct
    • Sep
    • Aug
    • Jul
    • Jun
    • Apr
    • Mar
    • Feb
    • Jan
  •     2013
    • Dec
    • Nov
    • Oct
    • Aug
    • Jun
    • May
    • Apr
    • Mar
    • Feb
    • Jan
  •     2012
    • Dec
    • Sep
    • Aug
    • Jun
    • May
    • Apr
    • Mar
    • Feb
    • Jan
  •     2011
    • Dec
    • Nov
    • Oct
    • Sep
    • Aug
    • Jul
    • Jun
    • May
    • Apr
    • Mar
    • Feb
  •     2010
    • Nov
    • Oct
    • Sep
    • Aug
    • Jul
    • May
    • Apr
    • Mar
  •     2009
    • Nov
    • Oct
    • Aug
    • Jul
    • Jun
    • Mar
  •     2008
    • Dec
    • Nov
    • Oct
    • Aug
    • Jul
    • May
    • Feb
  •     2007
    • Nov
    • Oct
    • Sep
    • Jul
    • Jun
    • May

Feed

Follow
Give us feedback in our Product Forums.
  • Google
  • Privacy
  • Terms
中国第五大发明是什么 读什么 周公吐哺天下归心是什么意思 可见原始心管搏动是什么意思 广西属于什么方向
牙神经痛吃什么药 哺乳期上火了吃什么降火最快 快乐源泉是什么意思 宫颈异常是什么意思 孕妇便秘吃什么
领盒饭是什么意思 胰腺炎适合吃什么食物 为什么会有血管瘤 拔牙之后需要注意什么事项 igg抗体阳性是什么意思
大白菜什么时候种 相声海清是什么意思 甘露醇是治什么的 心律不齐吃什么药最快 口若悬河什么意思
伏藏是什么意思hcv9jop3ns9r.cn 手掌纹路多且杂乱是为什么hcv9jop3ns1r.cn 老是打嗝是什么原因hcv9jop6ns9r.cn ABB的词语有什么sscsqa.com abcd是什么意思hcv8jop7ns4r.cn
公积金缴存基数什么意思gysmod.com 芥末是什么做的hcv7jop9ns2r.cn 慢性心肌炎有什么症状hcv9jop2ns0r.cn s.m是什么意思hcv7jop9ns7r.cn u型压迹是什么意思hcv9jop7ns2r.cn
左下眼皮跳是什么原因hcv8jop7ns2r.cn 今天是什么纪念日hcv9jop6ns8r.cn 荷花什么时候开放hcv9jop6ns1r.cn 梦见男婴儿是什么意思hcv7jop6ns1r.cn 鑫字代表什么生肖liaochangning.com
joan什么意思hcv7jop9ns6r.cn 童心未眠什么意思hcv9jop4ns6r.cn 神夫草抑菌乳膏主治什么hcv8jop2ns2r.cn 隔天是什么意思hcv9jop1ns4r.cn 八面玲珑是什么意思xscnpatent.com
百度