Your Gmail account hacked?
Over the last few months there have been a slew of complaints about hacked Gmail accounts where spammers used these accounts to send spam to the address list of the compromised account.
While many Gmail users, whose accounts have been compromised, raised concerns that there may be a vulnerability in the security of Gmail accounts, some experts say that it is far more likely that the users are to blame for security breaches.
According to one security expert there are numerous ways in which spammers can get access to a Gmail user’s account:
- Accounts may be left open when using public computers
- Keyloggers can be used to intercept passwords
- Malware on the user’s computer can forward passwords to hackers
- Browser login or password auto-fill enabled on a computer used by multiple people can compromise accounts
- Integration from other sites can cause email account insecurities
- Using unsecure networks to access accounts
- Weak passwords being discovered in a brute force attack
- Using a Gmail account and the ‘same password’ to register on websites (like social networks) where those details are not secure
Google responds
Google has now responded to the concerns from users, and has introduced a new feature to notify you when suspicious login activity is detected on your account.
“A few weeks ago, I got an email presumably from a friend stuck in London asking for some money to help him out. It turned out that the email was sent by a scammer who had hijacked my friend’s account. By reading his email, the scammer had figured out my friend’s whereabouts and was emailing all of his contacts. Here at Google, we work hard to protect Gmail accounts against this kind of abuse,” Google Engineering Director Pavni Diwanji said in a blog post.
Diwanji added that Google launched remote sign out and information about recent account activity to help users understand and manage their account usage. “This information is still at the bottom of your inbox. Now, if it looks like something unusual is going on with your account, we’ll also alert you by posting a warning message saying, “Warning: We believe your account was last accessed from…” along with the geographic region that we can best associate with the access.”
To determine when to display this message, Gmail’s automated system matches the relevant IP address, logged per the Gmail privacy policy, to a broad geographical location. “While we don’t have the capability to determine the specific location from which an account is accessed, a login appearing to come from one country and occurring a few hours after a login from another country may trigger an alert.”
“If you think your account has been compromised, you can change your password from the same window. Or, if you know it was legitimate access, you can click ‘Dismiss’ to remove the message,” said Diwanji.
Google warned that the notifications are meant to alert Gmail users of suspicious activity, but are not a replacement for account security best practices.
Gmail accounts hacked << discussion