Saturday, January 14, 2012

Real-Life Examples Of How Google's "Search Plus" Pushes Google Over Relevance

Google's Results Get More Personal With "Search Plus Your World"

by Danny Sullivan, searchengineland.com
January 10th 2012 9:30 AM

Google’s search results are undergoing their most radical transformation ever, as a new “Search Plus Your World” format begins rolling out today. It finds both content that’s been shared with you privately along with matches from the public web, all mixed into a single set of listings.

The change is live now, though not everyone will see it until it fully launches over the next few days. It’s only for those signed-in to Google.com and searching in English. You’ll know when it happens, because Google will alert you with a message like this above your search results:

The new system will perhaps make life much easier for some people, allowing them to find both privately shared content from friends and family plus material from across the web through a single search, rather than having to search twice using two different systems.

However, Search Plus Your World may cause some privacy worries, as private content may appear as if it is exposed publicly (it is not). It might also cause concern by making private content more visible to friends and family than those sharing may have initially intended.

The new format and features will also likely cause Google to come under renewed fire that it is leveraging its search engine to favor its own content and crowd out competitors.

Below, a detailed look at what’s involved with Search Plus Your World, from how it works to some of the issues it raises.

Before: Personalized & Social Search Results Separate

Google has had personalized results since June 2005, results from across the web that are given a ranking boost because they are deemed especially of interest to someone, based on their personal behavior and interests. Without the boost, these results might not have made it into the top listings for a particular search.

Personalized results were expanded and presented in a new way in February 2007. Then, in December 2009, you no longer had to opt-in to receive personalized results. They were enabled by default for everyone, to some degree, even if you weren’t signed-in to Google.

Separately, Google has had social search results since October 2009. These are also personalized listings but ones based on the people you know, rather than your personal behavior. They’ve also been given a ranking boost.

Initially segregated from “regular” listings, Google’s social search results were blended into regular results in Feburary 2011 and expanded to include not just content created by those you know but also content shared by them through a variety of social networks.

Now: Personal, Private, Public & Social United

With Search Plus Your World, by default, there’s a new “Personal Results” view that appears. The view personalizes the listings you get based on both your own behavior and social connections, similar to what previously happened. In addition, content that’s been shared with you through the Google+ social network now also appears.

“The social search algorithm, and the personal search algorithm, and the personalized search algorithm are actually one algorithm now, and we are merging it in a way that is very pleasant and useful,” said Amit Singhal, who oversees Google’s ranking algorithms, when I talked with him about the new features.

You’ll know that personalized results are appearing when you see one or both of the indicators below:

The arrow on the left points to a message that, in this example, says that there are “50 personal results and 419,000 other results” that have been found. Some of those 50 results will be blended into the first page of results being shown.

The second arrow highlights a new toggle that Google has introduced, something that many of those who do search engine optimization have wanted for ages. It allows you to switch between personalized and unpersonalized results.

I’ll cover more about the toggle in a bit. When the button with a person icon is shown dark, that means results are being personalized.

Private Content In Your Web Results

To summarize, personalized results include:

  • Listings from the web
  • Listings from the web, boosted because of your personal behavior
  • Listings from the web, boosted because of your social connections
  • Public Google+ posts, photos or Google Picasa photos (all of which are also listings from the web)
  • Private or “Limited” Google+ posts, photos or Google Picasa photos shared with you

The last line is the most radical change, that private content will now be visible in what seems to be a search across the entire web. Here’s an example:

In this example provided by Google (complete with its arrow), you can see how one of the photos is showing up with the note: “You shared this – Limited.”

This is a real life example of how personalized search is working for Singhal. He shared this photo of his dog, Chikoo, on Google+ in a limited manner, rather than with the entire world. The other photos of the dog that you can see, including one from his wife, Shilpa, were also privately shared.

Before today’s change, a Google search wouldn’t have found any of these photos when Singhal, his wife or anyone he’s shared them with searched for “chikoo,” which is a fruit. That’s because since the photos were private, Google couldn’t see them.

Instead, if Singhal or others with access to these photos wanted to find them, they would have had to use the completely separate Google+ Search.

The new feature will also work to find Google+ posts that have been shared in a limited manner, or for Google Picasa photos shared privately.

Slightly confusing, you can drill-down into the results to get what Google also calls “Personal Results,” which is a way to get just content from Google+ or Picasa. Remember this from above?

Clicking on the “personal results” link (or “Personal” in the options under “More Search Tools” in the left-column) brings back pure personal results.

No Content From Facebook Or Others, But Google Open To This

I’ve no doubt many people will find it useful to do one search to locate both private and public information at once. However, one of the biggest depositories of private information these days — if not the biggest — is Facebook.

Search Plus Your World doesn’t cover content on Facebook. Or Twitter. Or Flickr. Or any social network or place where content might be shared to a more limited audience. Currently, “Search Plus Your World” would be better described as “Search Plus Google+”

Why are these others missing?

“Facebook and Twitter and other services, basically, their terms of service don’t allow us to crawl them deeply and store things. Google+ is the only [network] that provides such a persistent service,” Singhal told me. “Of course, going forward, if others were willing to change, we’d look at designing things to see how it would work.”

Perhaps Search Plus Your World will prove the carrot or stick that Google’s been after for years to get Facebook to share its data with Google. If the new feature takes off, searchers may wonder why they can’t find privately shared information from their Facebook friends easily on Google.

Then again, Facebook could decide to push back by beefing up its own search features. Currently, Facebook partners with Bing, allowing Bing to personalize its search results for searchers based on what their Facebook friends like.

However, only publicly shared content gets personalized like this. Potentially, Facebook and Bing could work more closely to come up with their own version of Search Plus Your World. That could happen on Bing, or it could happen within Facebook itself.

To date, Facebook’s not spent much time trying to refine its own search results. The primary reason seems to be that the company has repeatedly said that most of the Facebook-based searches it sees are to find people, not to find information about broad topics as happens at Google.

Only You & Those You Share With See Private Content

When Google first showed me Search Plus Your World, a part of me felt unsettled and uncomfortable. As I’ve thought about it more, I think it’s because it feels weird to see “private” content appearing in seems like Google’s “public” search results.

Of course, personalized results aren’t Google’s public results. They are results personalized just for the person viewing them. If private content has been shared with those people, that’s visible. If it hasn’t been, then it’s not.

Google’s also not making it possible to search for anything that you couldn’t already search for before. As I explained, private content shared on Google+ could be found with a Google+ search. Google’s really just making Google+ Search one of its Universal Search sources, in some ways.

In other words, you can search on Google and find matches from Google News, Google Images, Google Video and other Google search services without having to go to them individually. Google+ Search is now another one of those integrated services.

Will It Lead To Concerns?

As said, the ability to search for private content on Google+ isn’t new. However, I wonder if having it integrated into Google’s search results itself might cause some surprises and issues for both Google and its users.

Consider sites selling counterfeit goods. When Google links to these, it gets blamed for promoting counterfeiting, almost as if it created the sites. What’s really happening is that Google comes under fire for giving sites visibility.

Now Google’s going to give greater visibility to private information. Things that people may have forgotten sharing with others will begin to show up serendipitously through ordinary Google searches. Some might not like this, if material they’ve happily forgotten suddenly seems to reappear. Google might take the blame, even though the sharing was done by others.

It might be similar to some of the concerns that came up recently with Facebook Timeline. It’s not that the material Timeline lists wasn’t out there before. But by organizing it, forgotten things are brought back up, as this New York Times article explained well.

Another issue is that it’s very easy with Google+ (as it is with Facebook and Twitter) for someone with access to private content to reshare it publicly. Someone searching on Google, then coming across an unexpected photo or post from a friend, might reshare it to the world.

All this could happen without the search integration. Maybe none of it will be much of an issue at all. But these are concerns that come to mind.

One solution might be an option to exclude your shared content from being searchable. This is something that can be done with public content on the web. You can tell Google or other search engines not to include published material in their search listings. Perhaps Google needs to offer the same for private content, as well (it doesn’t currently).

Secure Search Protects Privacy; Referrers For Advertisers Does Not

Google’s been focused on a bigger concern. Mixing private content in with its search results means that anyone searching without a secure connection potentially exposes that private content to eavesdropping.

And now the full story about why Google rolled out secure search for signed-in users back in October can finally be told. It was necessary preparation to allow for Search Plus Your World to happen today.

“We’ve been working on it for a year, very hard to get it right,” Singhal said, of dealing with the security issues. “It’s just a hard technical problem that we bit off, and it was something that we could not launch until we had it right.”

The encryption that secure search provides means that any private material mixed in with your regular results is protected, seen only by your browser and Google, not by anyone somehow monitoring an internet connection you’re using.

Many publishers were upset about the encryption move last year because, as part of that, Google also stopped providing referrer data, information that shows what searches someone did on Google before visiting a web site.

Expect Google to point to today’s move as a further reason to justify the dropping of referrers. It’s a false justification. Indeed, the move might make things even worse, in terms of privacy, since referrer data is still being passed to advertisers.

Potentially, people are going to search for even more private things than they ever did before. Potentially, they’re going to click on ad links and pass these private search terms to advertisers.

Today’s change does nothing to change my view that Google needs to revisit the referrer blocking and either make it a block for everyone, including advertisers, or find a better way to filter search terms that get made visibile in various ways.

My post from Sunday explains this in more depth: 2011: The Year Google & Bing Took Away From SEOs & Publishers.

Opt-Out, Not Opt-In

Don’t like the idea of personalized search? Disappointingly, Google didn’t go the opt-in route. Instead, you have to deliberately opt-out.

“I think this is a much better experience, at the end of the day,” Singhal said, explaining why the default change was made.

You can opt-out permanently through the Search Settings area on Google. You can also opt-out on a per-search basis using the aforementioned toggle. Click on the globe symbol, and you’ll see unpersonalized results.

This is nice. It’s the first time since December 2009 that people have been able to easily see “normal” results, if they want them.

Personalized Is The New “Normal”

Of course, it’s a mistake to assume that doing this really shows normal results. It will eliminate personalization factors such as your web browsing history (if you provide that to Google through its toolbar in Internet Explorer), your searching history or your social connections.

But geographic targeting — which can be really significant – will still happen. So will targeting by language. Google has begun calling these contextual signals rather than personal ones. Both can be overridden, for those who want. But doing so will still produce results that are still tailored, just to a different geographical location or language.

More important, with Google heading toward 100 million users on Google+, if a good number of those are active users, then they’re logged in to Google. That means the “normal” results they see are personalized. Personalized results are normal; non-personalized are not.

Google Profiles Get Big Push

Another big change as part of today’s release is how people with Google+ accounts are going to be much more heavily highlighted in Google search.

For those logged in, they’ll begin seeing their friends appear right within the search box, like this:

You can see how for Ben Smith, a little picture of him appears next to the search suggestion for his name, which in turn is a link to his Google+ profile, if it were selected.

This is very similar to how Google Direct Connect works for Google+ Business Pages. The results individuals see are biased toward people in their own social networks, similar to how Facebook works when you search for people there.

In other words, if you searched for a friend who had a common name, you should be shown your actual friend’s Google+ profile, rather than someone you don’t know.

In addition, the search results themselves will devote much more room to displaying material from a Google+ person (and actually have been doing so since November):

In the example above, you can see how Ben Smith’s Google+ profile is listed right within the results, with some of his recent posts shown. He’s a friend of Singhal’s, which is why posts with “Limited” sharing appear. The “Friends” circle on Google+ that Singhal has put him in is also shown.

“For me, it’s going to change my relationship on how I look at Google search,” Singhal told me. “It makes it much easier for me to get to what they [someone he knows or is interested in] were saying or if there are web results I should care about.”

What About Promoting Facebook Profiles Or Even Web Sites?

Still, it’s a lot of room devoted to Google+ profiles. While Facebook’s terms have prevented Google from getting some data, I can’t see any particular reason why the type of direct connect suggestion being shown above — as well as the deep display of content from a Facebook profile page — couldn’t also be done for Facebook, not to mention Twitter.

After all, if Google can do expanded sitelinks for social media profiles like at Quora or Twitter, then expanded profile listings showing some relevant posts from those profiles doesn’t seem that difficult.

Of course, it’s harder to do in the case above since the suggestion is made because Smith is known to be one of Singhal’s friends. But Google will be suggesting some celebrities and famous people even if the searcher hasn’t connected to them yet:

The example above shows how photographer Trey Ratcliff is being suggested, with a link to his Google+ profile, even though Singhal isn’t already connected to him.

That helps Ratcliff build his Google+ following. But what if he preferred that his Facebook profile be given a link? Or a link to his own web site? Google used to do this type of thing back in 2008 and 2009:

See how a search for New York Times used to bring up a link directly to the New York Times within the search box? That seems to have quietly disappeared.

Now something similar is turning up, something so tied to only Google+ that you can bet some of Google’s anti-trust critics are going to have a field day saying the company is pushing itself unfairly. And that’s a valid criticism.

People & Pages Suggestions

In fact, if the anti-trust critics need more ammunition, there’s the last component of what’s being rolled out today, suggestions for people and pages on Google+ to follow.

These will appear on the right-hand side of search results, when Google decides they are relevant. Below, what a search for “music” might show:

That’s nice promotion for Google+ (and it also underscores yet again why search marketers simply cannot ignore Google+). But there are still many more people on Twitter and Facebook versus Google Plus.

Google should be able to easily figure out what profiles on other social networks might be relevant to searches. That’s Google’s job as a search engine, if it’s going to make these type of recommendations. But only Google+ gets this type of treatment, and it doesn’t feel right.

Wrapping Up

Overall, I like the integration that allows for searching through private and public material. As I’ve said, I think many people will find it useful.

I do think there are some additional privacy controls that could be added, in particular, the ability for people to opt their content out of being found through search, if they want.

But really, more than anything, I’d like to see Google diligently work in the coming weeks to see how it can level the playing field for the other social networks.

Yes, there are things that Facebook or Twitter might not allow, not without Google cutting deals or agreeing to terms it may not want to. But there are also above-and-beyond things that I think Google probably could do to promote these other services in the way it’s doing for Google Plus. I’d like to see that happen.

More Information

Below, a video from Google about the new features:

Google also has a blog post up with details here. Coverage from other news sources can be found here on Techmeme. Below, about a billion background stories from us that give more context about today’s change.

Postscript: Since the launch, there’s been quite a debate over whether Google is favoring itself in various ways. Please see our follow-up stories below:

Original Page: http://searchengineland.com/googles-results-get-more-personal-with-search-plus-your-world-107285

Shared from Read It Later

 אל

Posted via email from DailyDDoSe

Real-Life Examples Of How Google's "Search Plus" Pushes Google Over Relevance

Google's Results Get More Personal With "Search Plus Your World"

by Danny Sullivan, searchengineland.com
January 10th 2012 9:30 AM

Google’s search results are undergoing their most radical transformation ever, as a new “Search Plus Your World” format begins rolling out today. It finds both content that’s been shared with you privately along with matches from the public web, all mixed into a single set of listings.

The change is live now, though not everyone will see it until it fully launches over the next few days. It’s only for those signed-in to Google.com and searching in English. You’ll know when it happens, because Google will alert you with a message like this above your search results:

The new system will perhaps make life much easier for some people, allowing them to find both privately shared content from friends and family plus material from across the web through a single search, rather than having to search twice using two different systems.

However, Search Plus Your World may cause some privacy worries, as private content may appear as if it is exposed publicly (it is not). It might also cause concern by making private content more visible to friends and family than those sharing may have initially intended.

The new format and features will also likely cause Google to come under renewed fire that it is leveraging its search engine to favor its own content and crowd out competitors.

Below, a detailed look at what’s involved with Search Plus Your World, from how it works to some of the issues it raises.

Before: Personalized & Social Search Results Separate

Google has had personalized results since June 2005, results from across the web that are given a ranking boost because they are deemed especially of interest to someone, based on their personal behavior and interests. Without the boost, these results might not have made it into the top listings for a particular search.

Personalized results were expanded and presented in a new way in February 2007. Then, in December 2009, you no longer had to opt-in to receive personalized results. They were enabled by default for everyone, to some degree, even if you weren’t signed-in to Google.

Separately, Google has had social search results since October 2009. These are also personalized listings but ones based on the people you know, rather than your personal behavior. They’ve also been given a ranking boost.

Initially segregated from “regular” listings, Google’s social search results were blended into regular results in Feburary 2011 and expanded to include not just content created by those you know but also content shared by them through a variety of social networks.

Now: Personal, Private, Public & Social United

With Search Plus Your World, by default, there’s a new “Personal Results” view that appears. The view personalizes the listings you get based on both your own behavior and social connections, similar to what previously happened. In addition, content that’s been shared with you through the Google+ social network now also appears.

“The social search algorithm, and the personal search algorithm, and the personalized search algorithm are actually one algorithm now, and we are merging it in a way that is very pleasant and useful,” said Amit Singhal, who oversees Google’s ranking algorithms, when I talked with him about the new features.

You’ll know that personalized results are appearing when you see one or both of the indicators below:

The arrow on the left points to a message that, in this example, says that there are “50 personal results and 419,000 other results” that have been found. Some of those 50 results will be blended into the first page of results being shown.

The second arrow highlights a new toggle that Google has introduced, something that many of those who do search engine optimization have wanted for ages. It allows you to switch between personalized and unpersonalized results.

I’ll cover more about the toggle in a bit. When the button with a person icon is shown dark, that means results are being personalized.

Private Content In Your Web Results

To summarize, personalized results include:

  • Listings from the web
  • Listings from the web, boosted because of your personal behavior
  • Listings from the web, boosted because of your social connections
  • Public Google+ posts, photos or Google Picasa photos (all of which are also listings from the web)
  • Private or “Limited” Google+ posts, photos or Google Picasa photos shared with you

The last line is the most radical change, that private content will now be visible in what seems to be a search across the entire web. Here’s an example:

In this example provided by Google (complete with its arrow), you can see how one of the photos is showing up with the note: “You shared this – Limited.”

This is a real life example of how personalized search is working for Singhal. He shared this photo of his dog, Chikoo, on Google+ in a limited manner, rather than with the entire world. The other photos of the dog that you can see, including one from his wife, Shilpa, were also privately shared.

Before today’s change, a Google search wouldn’t have found any of these photos when Singhal, his wife or anyone he’s shared them with searched for “chikoo,” which is a fruit. That’s because since the photos were private, Google couldn’t see them.

Instead, if Singhal or others with access to these photos wanted to find them, they would have had to use the completely separate Google+ Search.

The new feature will also work to find Google+ posts that have been shared in a limited manner, or for Google Picasa photos shared privately.

Slightly confusing, you can drill-down into the results to get what Google also calls “Personal Results,” which is a way to get just content from Google+ or Picasa. Remember this from above?

Clicking on the “personal results” link (or “Personal” in the options under “More Search Tools” in the left-column) brings back pure personal results.

No Content From Facebook Or Others, But Google Open To This

I’ve no doubt many people will find it useful to do one search to locate both private and public information at once. However, one of the biggest depositories of private information these days — if not the biggest — is Facebook.

Search Plus Your World doesn’t cover content on Facebook. Or Twitter. Or Flickr. Or any social network or place where content might be shared to a more limited audience. Currently, “Search Plus Your World” would be better described as “Search Plus Google+”

Why are these others missing?

“Facebook and Twitter and other services, basically, their terms of service don’t allow us to crawl them deeply and store things. Google+ is the only [network] that provides such a persistent service,” Singhal told me. “Of course, going forward, if others were willing to change, we’d look at designing things to see how it would work.”

Perhaps Search Plus Your World will prove the carrot or stick that Google’s been after for years to get Facebook to share its data with Google. If the new feature takes off, searchers may wonder why they can’t find privately shared information from their Facebook friends easily on Google.

Then again, Facebook could decide to push back by beefing up its own search features. Currently, Facebook partners with Bing, allowing Bing to personalize its search results for searchers based on what their Facebook friends like.

However, only publicly shared content gets personalized like this. Potentially, Facebook and Bing could work more closely to come up with their own version of Search Plus Your World. That could happen on Bing, or it could happen within Facebook itself.

To date, Facebook’s not spent much time trying to refine its own search results. The primary reason seems to be that the company has repeatedly said that most of the Facebook-based searches it sees are to find people, not to find information about broad topics as happens at Google.

Only You & Those You Share With See Private Content

When Google first showed me Search Plus Your World, a part of me felt unsettled and uncomfortable. As I’ve thought about it more, I think it’s because it feels weird to see “private” content appearing in seems like Google’s “public” search results.

Of course, personalized results aren’t Google’s public results. They are results personalized just for the person viewing them. If private content has been shared with those people, that’s visible. If it hasn’t been, then it’s not.

Google’s also not making it possible to search for anything that you couldn’t already search for before. As I explained, private content shared on Google+ could be found with a Google+ search. Google’s really just making Google+ Search one of its Universal Search sources, in some ways.

In other words, you can search on Google and find matches from Google News, Google Images, Google Video and other Google search services without having to go to them individually. Google+ Search is now another one of those integrated services.

Will It Lead To Concerns?

As said, the ability to search for private content on Google+ isn’t new. However, I wonder if having it integrated into Google’s search results itself might cause some surprises and issues for both Google and its users.

Consider sites selling counterfeit goods. When Google links to these, it gets blamed for promoting counterfeiting, almost as if it created the sites. What’s really happening is that Google comes under fire for giving sites visibility.

Now Google’s going to give greater visibility to private information. Things that people may have forgotten sharing with others will begin to show up serendipitously through ordinary Google searches. Some might not like this, if material they’ve happily forgotten suddenly seems to reappear. Google might take the blame, even though the sharing was done by others.

It might be similar to some of the concerns that came up recently with Facebook Timeline. It’s not that the material Timeline lists wasn’t out there before. But by organizing it, forgotten things are brought back up, as this New York Times article explained well.

Another issue is that it’s very easy with Google+ (as it is with Facebook and Twitter) for someone with access to private content to reshare it publicly. Someone searching on Google, then coming across an unexpected photo or post from a friend, might reshare it to the world.

All this could happen without the search integration. Maybe none of it will be much of an issue at all. But these are concerns that come to mind.

One solution might be an option to exclude your shared content from being searchable. This is something that can be done with public content on the web. You can tell Google or other search engines not to include published material in their search listings. Perhaps Google needs to offer the same for private content, as well (it doesn’t currently).

Secure Search Protects Privacy; Referrers For Advertisers Does Not

Google’s been focused on a bigger concern. Mixing private content in with its search results means that anyone searching without a secure connection potentially exposes that private content to eavesdropping.

And now the full story about why Google rolled out secure search for signed-in users back in October can finally be told. It was necessary preparation to allow for Search Plus Your World to happen today.

“We’ve been working on it for a year, very hard to get it right,” Singhal said, of dealing with the security issues. “It’s just a hard technical problem that we bit off, and it was something that we could not launch until we had it right.”

The encryption that secure search provides means that any private material mixed in with your regular results is protected, seen only by your browser and Google, not by anyone somehow monitoring an internet connection you’re using.

Many publishers were upset about the encryption move last year because, as part of that, Google also stopped providing referrer data, information that shows what searches someone did on Google before visiting a web site.

Expect Google to point to today’s move as a further reason to justify the dropping of referrers. It’s a false justification. Indeed, the move might make things even worse, in terms of privacy, since referrer data is still being passed to advertisers.

Potentially, people are going to search for even more private things than they ever did before. Potentially, they’re going to click on ad links and pass these private search terms to advertisers.

Today’s change does nothing to change my view that Google needs to revisit the referrer blocking and either make it a block for everyone, including advertisers, or find a better way to filter search terms that get made visibile in various ways.

My post from Sunday explains this in more depth: 2011: The Year Google & Bing Took Away From SEOs & Publishers.

Opt-Out, Not Opt-In

Don’t like the idea of personalized search? Disappointingly, Google didn’t go the opt-in route. Instead, you have to deliberately opt-out.

“I think this is a much better experience, at the end of the day,” Singhal said, explaining why the default change was made.

You can opt-out permanently through the Search Settings area on Google. You can also opt-out on a per-search basis using the aforementioned toggle. Click on the globe symbol, and you’ll see unpersonalized results.

This is nice. It’s the first time since December 2009 that people have been able to easily see “normal” results, if they want them.

Personalized Is The New “Normal”

Of course, it’s a mistake to assume that doing this really shows normal results. It will eliminate personalization factors such as your web browsing history (if you provide that to Google through its toolbar in Internet Explorer), your searching history or your social connections.

But geographic targeting — which can be really significant – will still happen. So will targeting by language. Google has begun calling these contextual signals rather than personal ones. Both can be overridden, for those who want. But doing so will still produce results that are still tailored, just to a different geographical location or language.

More important, with Google heading toward 100 million users on Google+, if a good number of those are active users, then they’re logged in to Google. That means the “normal” results they see are personalized. Personalized results are normal; non-personalized are not.

Google Profiles Get Big Push

Another big change as part of today’s release is how people with Google+ accounts are going to be much more heavily highlighted in Google search.

For those logged in, they’ll begin seeing their friends appear right within the search box, like this:

You can see how for Ben Smith, a little picture of him appears next to the search suggestion for his name, which in turn is a link to his Google+ profile, if it were selected.

This is very similar to how Google Direct Connect works for Google+ Business Pages. The results individuals see are biased toward people in their own social networks, similar to how Facebook works when you search for people there.

In other words, if you searched for a friend who had a common name, you should be shown your actual friend’s Google+ profile, rather than someone you don’t know.

In addition, the search results themselves will devote much more room to displaying material from a Google+ person (and actually have been doing so since November):

In the example above, you can see how Ben Smith’s Google+ profile is listed right within the results, with some of his recent posts shown. He’s a friend of Singhal’s, which is why posts with “Limited” sharing appear. The “Friends” circle on Google+ that Singhal has put him in is also shown.

“For me, it’s going to change my relationship on how I look at Google search,” Singhal told me. “It makes it much easier for me to get to what they [someone he knows or is interested in] were saying or if there are web results I should care about.”

What About Promoting Facebook Profiles Or Even Web Sites?

Still, it’s a lot of room devoted to Google+ profiles. While Facebook’s terms have prevented Google from getting some data, I can’t see any particular reason why the type of direct connect suggestion being shown above — as well as the deep display of content from a Facebook profile page — couldn’t also be done for Facebook, not to mention Twitter.

After all, if Google can do expanded sitelinks for social media profiles like at Quora or Twitter, then expanded profile listings showing some relevant posts from those profiles doesn’t seem that difficult.

Of course, it’s harder to do in the case above since the suggestion is made because Smith is known to be one of Singhal’s friends. But Google will be suggesting some celebrities and famous people even if the searcher hasn’t connected to them yet:

The example above shows how photographer Trey Ratcliff is being suggested, with a link to his Google+ profile, even though Singhal isn’t already connected to him.

That helps Ratcliff build his Google+ following. But what if he preferred that his Facebook profile be given a link? Or a link to his own web site? Google used to do this type of thing back in 2008 and 2009:

See how a search for New York Times used to bring up a link directly to the New York Times within the search box? That seems to have quietly disappeared.

Now something similar is turning up, something so tied to only Google+ that you can bet some of Google’s anti-trust critics are going to have a field day saying the company is pushing itself unfairly. And that’s a valid criticism.

People & Pages Suggestions

In fact, if the anti-trust critics need more ammunition, there’s the last component of what’s being rolled out today, suggestions for people and pages on Google+ to follow.

These will appear on the right-hand side of search results, when Google decides they are relevant. Below, what a search for “music” might show:

That’s nice promotion for Google+ (and it also underscores yet again why search marketers simply cannot ignore Google+). But there are still many more people on Twitter and Facebook versus Google Plus.

Google should be able to easily figure out what profiles on other social networks might be relevant to searches. That’s Google’s job as a search engine, if it’s going to make these type of recommendations. But only Google+ gets this type of treatment, and it doesn’t feel right.

Wrapping Up

Overall, I like the integration that allows for searching through private and public material. As I’ve said, I think many people will find it useful.

I do think there are some additional privacy controls that could be added, in particular, the ability for people to opt their content out of being found through search, if they want.

But really, more than anything, I’d like to see Google diligently work in the coming weeks to see how it can level the playing field for the other social networks.

Yes, there are things that Facebook or Twitter might not allow, not without Google cutting deals or agreeing to terms it may not want to. But there are also above-and-beyond things that I think Google probably could do to promote these other services in the way it’s doing for Google Plus. I’d like to see that happen.

More Information

Below, a video from Google about the new features:

Google also has a blog post up with details here. Coverage from other news sources can be found here on Techmeme. Below, about a billion background stories from us that give more context about today’s change.

Postscript: Since the launch, there’s been quite a debate over whether Google is favoring itself in various ways. Please see our follow-up stories below:

Original Page: http://searchengineland.com/googles-results-get-more-personal-with-search-plus-your-world-107285

Shared from Read It Later

 אל

Posted via email from DailyDDoSe

Report: FTC Expanding Anti-Trust Investigation Of Google To Include Google

Report: FTC Expanding Anti-Trust Investigation Of Google To Include Plus

by Pamela Parker, searchengineland.com
January 13th 2012 5:53 PM

The wide-ranging Federal Trade Commission investigation into Google’s potential anti-competitive practices has been expanded to include its Google+ social networking service, according to a Bloomberg report citing “people familiar with the situation.”

The news is likely to please critics like the Electronic Privacy Information Center (EPIC), which earlier this week called for the FTC to investigate the recent search changes called Google Plus Your World. Besides EPIC, many others, including Twitter, have questioned whether the new features favor Google’s own services over those of competitors.

Google in June of last year acknowledged the probe by the FTC. Though the agency has never specified the scope of the investigation, it was reportedly focused on the company’s search business — trying to determine whether the search behemoth was somehow unfairly exploiting its dominance in the sector.

Google declined to comment about the widening of the probe, according to the Bloomberg report.

Original Page: http://searchengineland.com/report-ftc-expanding-anti-trust-investigation-of-google-to-include-plus-108138

Shared from Read It Later

 אל

Posted via email from DailyDDoSe

Friday, January 13, 2012

Dear Congress: It's Not OK Not To Know How Search Engines Work, Either

Privacy Watchdog EPIC Asks Federal Trade Commission To Investigate Google

by Chris Sherman, marketingland.com
January 12th 2012 4:35 PM

The Electronic Privacy Information Center has urged the FTC to investigate Google’s recent integration of search results with personal data, such as photos, posts, and contact details, gathered from Google+ in Google Search results. These changes, Google Plus Your World, “raise concerns related to both competition and the implementation of the Commission’s consent order,” EPIC said in a press release.

Google faces both criticism and governmental inquires regarding “competition” issues (aka anti-trust concerns). At Search Engine Land, we’ve covered many of them, including Bing’s Travel Search & Kayak Favoritism Angers No One, While Google’s Gets Headline Attention From WSJ, Dear Congress: It’s Not OK Not To Know How Search Engines Work, Either, Koreans Accuse Google Of “Obstructing” Antitrust Investigation and many others.

The FTC “commission’s consent order” was something Google agreed to last year over concerns about Google’s ill-fated Buzz service. With that order, Google agreed to make more prominent privacy disclosures to users (and obtain their consent for any data sharing).

“Although data from a user’s Google+ contacts is not displayed publicly, Google’s changes make the personal data of users more accessible. Users can opt out of seeing personalized search results, but cannot opt out of having their information found through Google search,” said a note on EPIC’s website.

Last September, EPIC asked the FTC to investigate Google’s acquisition of YouTube, arguing that Google was favoring YouTube videos in search results. Over on Search Engine Land, Danny Sullivan examines the allegations of favoritism in his post, To Understand Google Favoritism, Think “If Google+ Were YouTube”.

Original Page: http://marketingland.com/privacy-watchdog-epic-asks-federal-trade-commission-to-investigate-google-3298

Shared from Read It Later

 אל

Posted via email from DailyDDoSe

Privacy Watchdog EPIC Asks Federal Trade Commission To Investigate Google

Privacy Watchdog EPIC Asks Federal Trade Commission To Investigate Google

by Chris Sherman, marketingland.com
January 12th 2012 4:35 PM

The Electronic Privacy Information Center has urged the FTC to investigate Google’s recent integration of search results with personal data, such as photos, posts, and contact details, gathered from Google+ in Google Search results. These changes, Google Plus Your World, “raise concerns related to both competition and the implementation of the Commission’s consent order,” EPIC said in a press release.

Google faces both criticism and governmental inquires regarding “competition” issues (aka anti-trust concerns). At Search Engine Land, we’ve covered many of them, including Bing’s Travel Search & Kayak Favoritism Angers No One, While Google’s Gets Headline Attention From WSJ, Dear Congress: It’s Not OK Not To Know How Search Engines Work, Either, Koreans Accuse Google Of “Obstructing” Antitrust Investigation and many others.

The FTC “commission’s consent order” was something Google agreed to last year over concerns about Google’s ill-fated Buzz service. With that order, Google agreed to make more prominent privacy disclosures to users (and obtain their consent for any data sharing).

“Although data from a user’s Google+ contacts is not displayed publicly, Google’s changes make the personal data of users more accessible. Users can opt out of seeing personalized search results, but cannot opt out of having their information found through Google search,” said a note on EPIC’s website.

Last September, EPIC asked the FTC to investigate Google’s acquisition of YouTube, arguing that Google was favoring YouTube videos in search results. Over on Search Engine Land, Danny Sullivan examines the allegations of favoritism in his post, To Understand Google Favoritism, Think “If Google+ Were YouTube”.

Original Page: http://marketingland.com/privacy-watchdog-epic-asks-federal-trade-commission-to-investigate-google-3298

Shared from Read It Later

 אל

Posted via email from DailyDDoSe

Privacy Watchdog EPIC Asks Federal Trade Commission To Investigate Google

Privacy Watchdog EPIC Asks Federal Trade Commission To Investigate Google

by Chris Sherman, marketingland.com
January 12th 2012 4:35 PM

The Electronic Privacy Information Center has urged the FTC to investigate Google’s recent integration of search results with personal data, such as photos, posts, and contact details, gathered from Google+ in Google Search results. These changes, Google Plus Your World, “raise concerns related to both competition and the implementation of the Commission’s consent order,” EPIC said in a press release.

Google faces both criticism and governmental inquires regarding “competition” issues (aka anti-trust concerns). At Search Engine Land, we’ve covered many of them, including Bing’s Travel Search & Kayak Favoritism Angers No One, While Google’s Gets Headline Attention From WSJ, Dear Congress: It’s Not OK Not To Know How Search Engines Work, Either, Koreans Accuse Google Of “Obstructing” Antitrust Investigation and many others.

The FTC “commission’s consent order” was something Google agreed to last year over concerns about Google’s ill-fated Buzz service. With that order, Google agreed to make more prominent privacy disclosures to users (and obtain their consent for any data sharing).

“Although data from a user’s Google+ contacts is not displayed publicly, Google’s changes make the personal data of users more accessible. Users can opt out of seeing personalized search results, but cannot opt out of having their information found through Google search,” said a note on EPIC’s website.

Last September, EPIC asked the FTC to investigate Google’s acquisition of YouTube, arguing that Google was favoring YouTube videos in search results. Over on Search Engine Land, Danny Sullivan examines the allegations of favoritism in his post, To Understand Google Favoritism, Think “If Google+ Were YouTube”.

Original Page: http://marketingland.com/privacy-watchdog-epic-asks-federal-trade-commission-to-investigate-google-3298

Shared from Read It Later

 אל

Posted via email from DailyDDoSe

Koreans Accuse Google Of "Obstructing" Antitrust Investigation

Koreans Accuse Google Of "Obstructing" Antitrust Investigation

by Greg Sterling, searchengineland.com
January 9th 2012 9:46 AM

According to CNET, Google faces the “maximum potential penalty” for allegedly obstructing South Korea’s antitrust investigation against the company. Korean officials “raided” Google’s Seoul offices last Fall in connection with an investigation into whether Google was acting in an anti-competitive way toward home-grown Korean search/portal sites on Android devices. (It wasn’t the first time for such a “raid” of Google’s offices in Korea.)

According to the CNET article Korean official Kim Dong-soo asserted that Google has obstructed his agency’s investigation “by deleting key files from PCs and asking its employees to telecommute from home.” Google has denied obstructing the inquiry and pledged cooperation with Korean government officials.

In April of last year, NHN Corp. (Naver) and Daum Communications filed antitrust complaints with the South Korean equivalent of the US Fair Trade Commission. The complaints claim that Google is blocking them from putting their search applications on Android phones in South Korea.

NHN/Naver and Daum control roughly 90 percent of the South Korean PC search market between the two companies. Google has less than 5 percent and is using Android as part of a strategy to grow market share. Reportedly about 70 percent of the smartphones sold in South Korea are Android handsets. And South Korea’s Samsung has emerged as Google’s premier Android partner, dominating global sales of Android devices.

South Korea has historically been very aggressive in various legal actions against Google. During the Google WiFi-personal data collection scandal South Korean police sought to file criminal charges against Google executives.

Original Page: http://searchengineland.com/koreans-accuse-google-of-obstructing-antitrust-investigation-107181

Shared from Read It Later

 אל

Posted via email from DailyDDoSe

Koreans Accuse Google Of "Obstructing" Antitrust Investigation

Koreans Accuse Google Of "Obstructing" Antitrust Investigation

by Greg Sterling, searchengineland.com
January 9th 2012 9:46 AM

According to CNET, Google faces the “maximum potential penalty” for allegedly obstructing South Korea’s antitrust investigation against the company. Korean officials “raided” Google’s Seoul offices last Fall in connection with an investigation into whether Google was acting in an anti-competitive way toward home-grown Korean search/portal sites on Android devices. (It wasn’t the first time for such a “raid” of Google’s offices in Korea.)

According to the CNET article Korean official Kim Dong-soo asserted that Google has obstructed his agency’s investigation “by deleting key files from PCs and asking its employees to telecommute from home.” Google has denied obstructing the inquiry and pledged cooperation with Korean government officials.

In April of last year, NHN Corp. (Naver) and Daum Communications filed antitrust complaints with the South Korean equivalent of the US Fair Trade Commission. The complaints claim that Google is blocking them from putting their search applications on Android phones in South Korea.

NHN/Naver and Daum control roughly 90 percent of the South Korean PC search market between the two companies. Google has less than 5 percent and is using Android as part of a strategy to grow market share. Reportedly about 70 percent of the smartphones sold in South Korea are Android handsets. And South Korea’s Samsung has emerged as Google’s premier Android partner, dominating global sales of Android devices.

South Korea has historically been very aggressive in various legal actions against Google. During the Google WiFi-personal data collection scandal South Korean police sought to file criminal charges against Google executives.

Original Page: http://searchengineland.com/koreans-accuse-google-of-obstructing-antitrust-investigation-107181

Shared from Read It Later

 אל

Posted via email from DailyDDoSe

Report: FTC Expanding Anti-Trust Investigation Of Google To Include Google

Report: FTC Expanding Anti-Trust Investigation Of Google To Include Plus

by Pamela Parker, searchengineland.com
January 13th 2012 5:53 PM

The wide-ranging Federal Trade Commission investigation into Google’s potential anti-competitive practices has been expanded to include its Google+ social networking service, according to a Bloomberg report citing “people familiar with the situation.”

The news is likely to please critics like the Electronic Privacy Information Center (EPIC), which earlier this week called for the FTC to investigate the recent search changes called Google Plus Your World. Besides EPIC, many others, including Twitter, have questioned whether the new features favor Google’s own services over those of competitors.

Google in June of last year acknowledged the probe by the FTC. Though the agency has never specified the scope of the investigation, it was reportedly focused on the company’s search business — trying to determine whether the search behemoth was somehow unfairly exploiting its dominance in the sector.

Google declined to comment about the widening of the probe, according to the Bloomberg report.

Original Page: http://searchengineland.com/report-ftc-expanding-anti-trust-investigation-of-google-to-include-plus-108138

Shared from Read It Later

 אל

Posted via email from DailyDDoSe

Credit card hacker denies Israeli blogger unmasked him JPost - National News

Credit card hacker denies Israeli blogger unmasked him

by JPOST.COM STAFF and YAAKOV LAPPIN, jpost.com
January 8th 2012 3:00 AM

The hacker who published tens of thousands of Israeli credit card numbers denied reports that an Israeli blogger unmasked his identity on Friday.

Channel 10 and other media reports said Amir Fedida spent eight hours researching the hacker’s identity.

RELATED:
Hackers post 1000s of Israeli credit card numbers


Fedida said the hacker was Omar Habib, a 19-year-old man living in Mexico with origins in the UAE. The hacker goes by the online name of “OxOmar.”

But OxOmar later denied any connections to Habib, describing attempts to link the two as false. OxOmar, who was originally believed to be Saudi, dared Mossad to track him down, boasting it would be impossible to find him.

Fedida said his research found the hacker is not Saudi as widely reported, and the hacker committed several errors that allowed others to track him down.

The biggest mistake was communicating with Israeli media by e-mail, Fedida said.

The hacker is active in pro- Palestinian Internet forums, where he posts anti-Israel messages, Fedida added.

The credit card list published on Friday contains no new information, but can damage computers that run it, Leumi Bank, the CAL credit card company, and Isracard warned. They instructed their customers to refrain from downloading the file.

OxOmar reportedly responded to reports of another file disseminated on Friday that contained Trojan horse malware, and denied responsibility for it.

On Thursday, OxOmar released almost 11,000 new Israeli credit card numbers and personal contact details, following the publication of around 15,000 numbers earlier this week.

Credit card companies were examining the latest list and were prepared to cancel any affected cards for phone or Internet use, as well as issue new cards.

OxOmar threatened to release many more credit card numbers, and claimed to also be in possession of “data I have downloaded from Israeli military contractor companies.” The message, posted on the “uncensored text hosting” website Pastebin, contained numerous anti-Israel and anti- Semitic references. The hacker repeatedly referred to the “Zionist lobby” and the “Jewish lobby” throughout the post.

Original Page: http://www.jpost.com/NationalNews/Article.aspx?id=252636

Shared from Read It Later

 אל

Posted via email from DailyDDoSe

'This is just the beginning,' warns Israeli Hackers... JPost - National News

'This is just the beginning,' warns Israeli hacker

by YAAKOV LAPPIN, jpost.com
January 11th 2012 5:39 PM

He's only 17-years-old, but the Israeli hacker known as '0xOmer' has already made headlines after publishing hundreds of Saudi credit card numbers, in retaliation against Arab hackers, claiming to be Saudis, who published tens of thousands of Israeli credit card details on the internet last week. "This is just the beginning," 0xOmer told The Jerusalem Post on Wednesday. "We have over 300 Saudi credit card numbers in our possession... and over 10,000 personal details of people in Saudi Arabia, including full names, emails, and addresses. If they publish one more little detail on Israel, we will attack in full force and publish all of the credit card details," he added.RELATED:
Credit card hacker denies Israeli blogger unmasked him
Hackers hit US security think tank's website

The hacker provided a glimpse into how a developing cyberwar is being fought. Last week, Israeli credit card numbers and the Bank of Israel scrambled to quickly disable credit card numbers compromised by the actions of the anti-Israel hacker. Now, Saudi banks will have to take the same steps to protect their customers. "I belong to a group of hackers named Israel Defenders," he said. The team is made up of four members, who function like an organized cell, with a clear division of labor. "My role is to find and exploit security breaches in the highest levels," 0xomer said. Another member of the team, codenamed 7ukk1, is in charge of defacing websites targeted by the hackers, and handling foreign media relations. 7ukk1 is also an IDF soldier serving in Military Intelligence, 0xOmer said. A third member is a specialist in breaking into servers. The fourth member helps 0xOmer identify security gaps. "It's very easy to be hacker. It's a matter of studying for two to three months, and you can master the field," 0xOmer said. "the only difficulty is in finding Arab websites because they're in a different language," he added. But such websites have already been found in the form of a Saudi shopping website, and security breaches identified.

The hackers are interested only in sending a warning to anti-Israel hackers at this stage, and stopped short of providing credit card information that can be used to make fraudulent purchases, the hacker added. "I didn't publicize the three digit number at the back of the card [necessary for online shopping]," he explained. But if hostile internet activists continue attacks on Israeli targets, 'Israel Defenders' will publish hundreds of credit card numbers along with the three-digit code, he added. The four youths are taking up what they say is a deterrence posture, in an online world that is increasingly being used as a battle arena. This arena is dominated almost exclusively by the young. "Many want to know how old I am, and some think I'm an adult. The right answer is that I'm 17," 0xOmer said. On his Twitter account, the hacker posted a link to a media report on the Israeli hacking group, adding, "Israeli pride!"

He also directed expletives at "OxOmar," the hacker who exposed the Israeli credit card numbers.

Original Page: http://www.jpost.com/NationalNews/Article.aspx?id=253181

Shared from Read It Later

 אל

Posted via email from DailyDDoSe

Gaza hackers attack Israeli firefighters... JPost - National News

Gaza hackers attack Israeli firefighters' website

by JPOST.COM STAFF, jpost.com
January 13th 2012 3:35 AM

A group referring to themselves as the Gaza Hacker Team launched a cyber attack on the Israel Fire and Rescue Services' website early Friday morning, in the latest of a string of cyber-terror attacks against Israeli interests.

The same group hacked into Deputy Foreign Minister Danny Ayalon's website last week. In Friday's attack the group placed a crossed out picture of Ayalon with footprints superimposed over his face on the Fire and Rescue Services' site.

RELATED:
'This is just the beginning,' warns Israeli hacker
Blogger claims to uncover identity of 'Saudi' hacker

The hackers threatened to commandeer more Israeli websites and wrote "death to Israel" in Hebrew.

Following the attack on Ayalon's personal site last week, the deputy foreign minister said that breaches of Israel’s cyberspace are a breach of sovereignty similar to terrorism and should be treated as such.

He also referred to the recent cyber theft of thousands of Israeli credit card numbers, saying it was a warning sign, but that Israel – as one of most advanced countries in the world in terms of cyber security – knew how to protect itself.

Israel needed to take an example from the US, which recently declared that it reserved the right to respond to cyberspace attacks – seen as acts of war – with conventional weapons, Ayalon said.

Herb Keinon contributed to this report

Original Page: http://www.jpost.com/NationalNews/Article.aspx?id=253462

Shared from Read It Later

 אל

Posted via email from DailyDDoSe

IDF building elite hacker teams amid cyber threat

IDF building elite hacker teams amid cyber threat

by YAAKOV KATZ, jpost.com
January 13th 2012 7:47 AM

The IDF is assembling elite teams of computer hackers to lead the nation’s cyber-warfare efforts.

The move comes amid concern over the growing threat to Israel’s civilian and military networks from Iran, senior officers said.

RELATED:
Gaza hackers attack Israeli firefighters' website
'Saudi hacker disseminates third harmful file'
Shin Bet: Critical infrastructure targeted by cyber-warfare

Last month, the army recruited close to 300 young computer experts, many of them without college or even high-school degrees.

“These are some of the top experts in their field,” a senior officer said.

The new soldiers will serve in Military Intelligence as well as in the C4I Directorate, the two military branches responsible for cyber-warfare in the IDF.

C4I stands for command, control, communications, computers, and (military) intelligence.

The decision to recruit the soldiers is part of a new IDF multi-year plan aimed at boosting the military’s cyber-warfare capabilities.

Last month, The Jerusalem Post reported on an ambitious Iranian plan to invest $1 billion to develop technology and hire computer experts with the goal of boosting the Islamic Republic’s offensive and defensive cyber-warfare capabilities.

Israel is also concerned about terrorist cyber attacks, demonstrated by the release of thousands of Israeli credit card numbers by a Saudi hacker this past week.

“We are not where we would like to be when it comes to the cyber world and we are working to improve our capabilities,” the senior officer said.

The government recently established a cyber task force that will be responsible for improving Israeli defenses and coordinating the development of new software and capabilities between local defense and hi-tech companies.

The IDF recently organized the units that deal with cyber-warfare, establishing offensive capabilities and operations within Military Intelligence’s Unit 8200 and defensive operations within a new division within the C4I Directorate.

The new division is run by a colonel who took up his post over the summer. The officer is the former commander of Matzov, the unit that is responsible for protecting the IDF networks and a Hebrew acronym for “Center for Encryption and Information Security.”

Matzov writes the codes that encrypt IDF, Shin Bet (Israel Security Agency) and Mossad networks, as well as mainframes in national corporations, such as the Israel Electrical Corp., the Mekorot national water company and the Bezeq telephone company.

One of the IDF’s primary concerns is the possibility that an enemy will topple military networks during a war. In recent years, the military has invested heavily in digitizing its ground forces, for example with the Tzayad digital army program that allows units to share information on the location of friendly and hostile units.

“For us, cyber defense means retaining the ability to continue operating and to be able to rely on the security and availability of our networks,” a senior officer from the C4I Directorate explained recently.

Original Page: http://www.jpost.com/Defense/Article.aspx?ID=253487&R=R1

Shared from Read It Later

 אל

Posted via email from DailyDDoSe

'Saudi hacker disseminates third harmful... JPost - National News

'Saudi hacker disseminates third harmful file'

by JPOST.COM STAFF, jpost.com
January 6th 2012 6:52 PM

The Saudi hacker going by the username "0xOmar", has disseminated a third file containing Trojan horse malware, Israel Radio reported Friday.

The file reportedly contains no new information and can damage computers that run it.

RELATED:
Hackers post 1000s of Israeli credit card numbers


On Thursday the hacker released almost 11,000 new Israeli credit card numbers and personal contact details, following the
publication of around 15,000 numbers earlier this week.

Credit card companies were examining the latest list and were prepared to cancel any affected cards for phone or internet use, as well as issue new cards.

The new file that has been released contains full details of credit cards, including expiry date and CVVs (the three digits on the back of the card), full names, addresses, and telephone numbers, according to a Globes report. The file also contains e-mail addresses and passwords. Additionally, e-mail account passwords have been verified as genuine, allowing anyone with the information to break into inboxes without difficulty, according to the report.

The hacker, from "group-xp" released a statement indicating that he will release the rest of the database which contains a further 60,000 credit cards. He also threatened to release other sensitive information, such as "data I have downloaded from Israeli military contractor companies... I'm thinking to start doing it from an Israeli company which creates jammers and eavesdropping devices."

The message, posted on the 'uncensored text hosting' website Pastebin, contained numerous anti-Israel and anti-Semitic references. The hacker repeatedly referred to the "Zionist lobby" and the "Jewish lobby" throughout the post.

The Bank of Israel on Tuesday reassured customers that they would not bear responsibility for fraudulent use of their cards.

Yaakov Lappin contributed to this report

Original Page: http://www.jpost.com/NationalNews/Article.aspx?id=252416

Shared from Read It Later

 אל

Posted via email from DailyDDoSe

‘Anonymous’ vows to ‘kill’ FaceBook - JPost - Technology

‘Anonymous’ vows to ‘kill’ Facebook this year

by Michael Omer-Man, jpost.com
August 10th 2011 12:45 PM

The loosely-affiliated group of hackers that has taken responsibility for attacks on Rupert Murdoch’s media empire and, most recently, the Syrian Defense Ministry, described its reasons for a planned attack on the Facebook social network in a press release issued via YouTube last month.

“Prepare for a day that will go down in history. November 5, 2011,” Anonymous warned. “Your medium of communication you all so dearly adore will be destroyed.”

The threatened action differs from previous attacks on companies and governments, which took the form of Dedicated Denial of Service (DDoS) attacks that only temporarily overload computer systems. This attack, the group says will “kill Facebook.

“Facebook has been selling information to government agencies and giving clandestine access to information security firms so that they can spy on people from around the world,” the group charged.


Some of those firms, the press release claimed, “are working for authoritarian governments such as those of Egypt and Syria.”

Anonymous has been especially active in the past year in relation to the Arab Spring, launching attacks on Tunisian, Egyptian and Syrian government ministries, and it was reportedly involved in an effort in Egypt to provide a workaround for Internet access after the government cut connectivity during the revolution.

Citing privacy concerns with Facebook and its ability to store and sell personal information about its users, the group said in its release: “Everything you do on Facebook stays on Facebook regardless of your ‘privacy’ settings, and deleting your account is impossible.”

Deleting one’s Facebook account, it described, does not actually delete your information from the company’s computers “and can be recovered at any time. Facebook knows more about you than your family,” it said.

Described as a “battle for choice and informed consent,” the group said that Facebook tells users it gives them choices, “but that is completely false. It gives users the illusion of [choice] and hides details away from them ‘for their own good.’” The date of the attack is symbolic as one of Anonymous’s known symbols is a mask made famous most recently in the film V for Vendetta, a comic-book adaptation of a story about an effort to overthrow a totalitarian British government, inspired by the story of Guy Fawkes. November 5 is Guy Fawkes Day.

Facebook has not issued an official response to the threat.

Download JPost's iPhone application Subscribe to our Newsletter to receive news updates directly to your email

Original Page: http://www.jpost.com/Sci-Tech/Article.aspx?id=233201

Shared from Read It Later

 אל

Posted via email from DailyDDoSe

Hackers hit US security think... JPost - Environment & Technology

Hackers hit US security think tank's website

by REUTERS, jpost.com
December 26th 2011 9:57 AM

US security think tank Strategic Forecasting Inc (Stratfor) on Sunday said its website had been hacked and that some of the names of corporate subscribers had been made public.

Stratfor said the breach came from an unauthorized party, while activist hacker group Anonymous claimed responsibility.

RELATED:
‘Anonymous’ vows to ‘kill’ Facebook this year
'Anonymous hacks Syrian Ministry of Defense website'

"As a result of this incident the operation of Stratfor's servers and email have been suspended," the Austin-based company said in an email on Sunday.

Hackers claiming to be the group Anonymous said they had obtained around 4,000 credit card details, passwords and home addresses on Stratfor's private client list, which was posted on information-sharing website Pastebin.

Anonymous, reported to be a loose-knit group of hackers, became famous for attacking the companies and institutions that oppose WikiLeaks and its founder Julian Assange.

Anonymous has also been linked to attacks on the websites of the PlayStation store, the Church of Scientology and governments around the globe that it considered oppressive.

Stratfor, which describes itself as a provider of strategic intelligence for business, economic, security and geopolitical affairs, said it was "working closely with law enforcement in their investigation and will assist them with the identification of the individual(s) who are responsible."

Original Page: http://www.jpost.com/Sci-Tech/Article.aspx?id=250953

Shared from Read It Later

 אל

Posted via email from DailyDDoSe

Hackers post 1000s of Israeli credit cards

Hackers post 1000s of Israeli credit card numbers

by JPOST.COM STAFF and YAAKOV LAPPIN, jpost.com
January 3rd 2012 3:01 AM

Saudi hackers claimed Monday to have published the credit card details of 400,000 Israelis. Credit card companies said only hundreds of authentic card numbers were published in reality.

RELATED:
Hackers hit US security think tank's website

The hackers published the list of cards, names and other personal details on the One sports website, which was hacked.

The hackers published a 30 megabyte file containing the details.

Israeli credit card companies have urged their customers to remain calm, and said they are taking all the required steps to secure credit accounts.

Visa CAL announced that it would suspend all accounts that were detailed in the post. The company said it would contact the affected customers Tuesday and issue them new credit cards.

The Bank of Israel announced it would review the matter.

According to Army Radio, the hackers encouraged readers to use the information posted online to make purchases, and said they would continue to publish more account information already in their possession.

The hackers also published details of tens of thousands of Jews living around the world, Maariv reported.

Some reports have suggested that the figures were stolen from coupon websites. Many of the credit card figures repeat themselves.

Original Page: http://www.jpost.com/International/Article.aspx?id=251943

Shared from Read It Later

 אל

Posted via email from DailyDDoSe

Another Sykipot sample likely targeting US federal agencies - Alienvault Labs

Another Sykipot sample likely targeting US federal agencies

by jaime.blasco, labs.alienvault.com
December 12th 2011

Last week Adobe issued an advisory on a zero-day vulnerability  (CVE-2011-2462) that has been being used in targeted attacks, probably defense contractors.

The payload used is Sykipot, a know malware that has connections with several targeted attacks/0days during the past.

During the analysis of this attack, I’ve found a new sample with a fresh command and control server (C&C).

MD5: 4d979bb626e1e61cc4fc0cefefaa3ec7

VirusTotal:

Submission date:
2011-12-12 00:39:51 (UTC)

Result:
25 /43 (58.1%)

The binary drops a DLL:

FileName: WSE4EF1.TMP

MD5: 945FF23E9979A0867B7F3815BB0F9477

Timestamp: 22/11/2011

Original File Name: wship4.dll (IPv4 Helper DLL)

The original malware scans the list of running process looking for outlook, iexplore or firefox. If found it injects the DLL into the process.

After that, the binary will spawn a PDF file,

FY 2012 Per Diem Rates – Effective October 1, 2011

This file shows the continental United States “CONUS rates” for travelling expenses.

The injected DLL will contact XXXhksrv.hostdefence.net/asp/kys_allow_get.asp?name=getkys.kys to download an encrypted configuration file.  This file contains several commands that the victim will execute on the sending the results back to the C&C server.

Example of configuration file:

iexplore
findpass2000
process
ipconfig /all
netstat -ano
net start
net view /domain
net group “domain admins” /domain
tasklist /v
net localgroup administrators
dir c:\*.url /s

The domain info is:

Domain Name: hostdefence.net

Registrant:

Amirhosein

Amirhosein       (parviz7415@yahoo.com)

No 806 8th building YuLin City GuangXi Province

Yu Lin

Guang Xi,537500

Tel. +86.7756853792

Creation Date: 2011-11-14 15:35:24

Expiration Date: 2012-11-14 15:35:24

Original Page: http://labs.alienvault.com/labs/index.php/2011/another-sykipot-sample-likely-targeting-us-federal-agencies/

Shared from Read It Later

 אל

Posted via email from DailyDDoSe

Another Sykipot sample likely targeting US federal agencies - Alienvault Labs

Another Sykipot sample likely targeting US federal agencies

by jaime.blasco, labs.alienvault.com
December 12th 2011

Last week Adobe issued an advisory on a zero-day vulnerability  (CVE-2011-2462) that has been being used in targeted attacks, probably defense contractors.

The payload used is Sykipot, a know malware that has connections with several targeted attacks/0days during the past.

During the analysis of this attack, I’ve found a new sample with a fresh command and control server (C&C).

MD5: 4d979bb626e1e61cc4fc0cefefaa3ec7

VirusTotal:

Submission date:
2011-12-12 00:39:51 (UTC)

Result:
25 /43 (58.1%)

The binary drops a DLL:

FileName: WSE4EF1.TMP

MD5: 945FF23E9979A0867B7F3815BB0F9477

Timestamp: 22/11/2011

Original File Name: wship4.dll (IPv4 Helper DLL)

The original malware scans the list of running process looking for outlook, iexplore or firefox. If found it injects the DLL into the process.

After that, the binary will spawn a PDF file,

FY 2012 Per Diem Rates – Effective October 1, 2011

This file shows the continental United States “CONUS rates” for travelling expenses.

The injected DLL will contact XXXhksrv.hostdefence.net/asp/kys_allow_get.asp?name=getkys.kys to download an encrypted configuration file.  This file contains several commands that the victim will execute on the sending the results back to the C&C server.

Example of configuration file:

iexplore
findpass2000
process
ipconfig /all
netstat -ano
net start
net view /domain
net group “domain admins” /domain
tasklist /v
net localgroup administrators
dir c:\*.url /s

The domain info is:

Domain Name: hostdefence.net

Registrant:

Amirhosein

Amirhosein       (parviz7415@yahoo.com)

No 806 8th building YuLin City GuangXi Province

Yu Lin

Guang Xi,537500

Tel. +86.7756853792

Creation Date: 2011-11-14 15:35:24

Expiration Date: 2012-11-14 15:35:24

Original Page: http://labs.alienvault.com/labs/index.php/2011/another-sykipot-sample-likely-targeting-us-federal-agencies/

Shared from Read It Later

 אל

Posted via email from DailyDDoSe

Sykipot variant hijacks DOD and Windows smart cards - Alienvault Labs

Sykipot variant hijacks DOD and Windows smart cards

by jaime.blasco, labs.alienvault.com
January 12th 2012

Defenses of any sort, virtual or physical, are a means of forcing your attacker to attack you on your terms, not theirs. As we build more elaborate defenses within information security, we force our attacker’s hand. For instance, in many cases, implementing multi-factor authentication systems just forces the attacker to go after that system directly to achieve their goals. Take the breach at RSA, for example. It has been attributed to attackers who needed the SecurID information to go after their real targets in the defense industry.

Recently, our lab has been talking about Sykipot:

As we discussed, this malware has been used to launch targeted attacks via “spear phishing” campaigns against targets mainly in the US, since around 2007. According to our research, these attacks originate from servers in China with what appears to be the purpose of obtaining information from the defense sector: the same sector that makes extensive use of PC/SC x509 Smartcards for authentication.

Smartcards have a long history of usage in the Defense Sector, for both physical and information access management, and historically have merely forced attackers to route around the smartcard authentication system through other, more vulnerable attack vectors.

It should come as no surprise, then, that we recently discovered a variant of Sykipot with some new, interesting features that allow it to effectively hijack DOD and Windows smart cards. This variant, which appears to have been compiled in March 2011, has been seen in dozens of attack samples from the past year.

Like we have shown with previous Sykipot attacks, the attackers use a spear phishing campaign to get their targets to open a PDF attachment which then deposits the Sykipot malware onto their machine (the attackers here took advantage of a zero-day exploit in Adobe). Then, unlike previous strains, the malware uses a keylogger to steal PINs for the cards. When a card is inserted into the reader, the malware then acts as the authenticated user and can access sensitive information. The malware is controlled by the attackers from the command & control center.

Here is more detail on the attack:

Smartcard access

The first one is that it creates a new thread with a keylogger routine. The code is very basic, it stores the window name and the keys pressed under a file named MSF5F0.dat on an unencrypted format, example:

Title:Internet Explorer
www.google.es
Title:My Computer

It uses the WIN32 APIʼs functions [GetKeyState, GetAsyncKeyState,
GetForegroundWindow, GetWindowTextA].

It also saves the information contained in the clipboard using the native functions:
OpenClipboard, GetClipboardDataand CloseClipboard.

This code is very similar to other pieces of APTʼs like:

http://contagiodump.blogspot.com/2010/07/apt-activity-monitor-keylogger.html

Apart from this we found two more modules that attracted our attention. The first one is capable of listing all the certificates that are stored on the windows key store:

This next routine is called if the command “cl” is present on the config file fetched from the C&C.

When you insert a smart card into a reader attached to a Windows computer, the certificate on the smart card is registered to the local certificate store on the client computer.

The second one is even more interesting:

It loads:

C:\Program Files\ActivIdentity\ActivClient\acpkcs201.dll

(a module that handles some of the functions related with ActivIdentityʼs ActivClient solution.)

ActivClient is a smart card-based PKI authentication solution for compliance with:

  • U.S. Government Smart Card Interoperability Specifications GSC-IS 2.1
  • U.S. General Services Administration (GSA) Basic Services Interface (BSI)

(In fact it is one of the platforms used to support the Department of Defense common access card – DoD CAC)

This routine is called if the command “cm” is present on the config file fetched from the C&C:

So, the modus operandi of the attackers is listing the certificates present on the victimʼs
computer included the smartcards, stealing the PIN using the keylogger module and then
use this information to log onto remote resources protected with certificates/smartcards.

To log onto protected resources they have implemented the command “krundll”, if the C&C sends that command, the victim receives a new dll that implements the required code to login using the certificate and the stolen PIN. This DLL implements the “LoginFunc” and “GetFunc”. These methods will contain all the code depending on the application used:

Summary

We have seen how the attackers are implementing different techniques to bypass two-factor authentication with smartcard/PIN to access protected resources on the victimʼs network. By capturing the PIN for the smartcard and binding the certificate, malware can silently use the card to authenticate to secure resources, so long as the card remains physically present in the card reader. This is similar to what Mandiant described on the 2011 M-Trends report as a “Smart Card Proxy”. While trojans that have targeted smartcards are not new, there is obvious siginficance to the targeting of a particular smartcard system in wide deployment by the US DoD and other government agencies, particularly given the nature of the information the attackers seem to be targeting for exfiltration.

Implications

As defenses get better, attackers will continue to change their tactics to adapt, and as seen here, will hijack the very systems designed to provide more security, if necessary. An interesting by-product of this malware’s necessity of having the card physically present is that attackers can only leverage it for secure authentication to target systems, during times that the user them is physically present at the workstation, making unauthorized activity that much more difficult to discern from legitimate usage. Although smart cards are designed to provide a two factor system of ‘chip and pin’, again we see that true two-factor authentication is not possible without a physical component that is not accessible digitally.

Original Page: http://labs.alienvault.com/labs/index.php/2012/when-the-apt-owns-your-smart-cards-and-certs/

Shared from Read It Later

 אל

Posted via email from DailyDDoSe