Hackers Impersonate Google to Snoop on Users in Iran – NYTimes.com

Hackers passed themselves off as the Internet giant Google with the apparent goal of snooping on people using Google services in Iran, the company said.

It was the latest in a string of breaches that call into question the reliability of certificates that are supposed to verify the authenticity of Web sites. Such breaches make dissidents and human rights workers particularly vulnerable because they can allow repressive regimes, or supporters of those regimes, to spy on their online activities.

In this case, the attackers hacked into the site of a Dutch company, one of many that have the authority to issue the digital certificates, and obtained one that they used to impersonate Google. When users in Iran went to a Google site, including Gmail and Google Docs, they could be intercepted by the impostors in what is known as a man-in-the-middle attack.

via Hackers Impersonate Google to Snoop on Users in Iran – NYTimes.com.

Web Security in the Cloud: More Secure! Compliant! Less Expensive!

Drawing on the findings from multiple benchmark studies on best practices in content security and security software as a service, Aberdeen’s analysis shows that users of cloud-based web security had substantially better results than users of on-premise web security implementations in the critical areas of security, compliance, reliability and cost. Compared to companies using on premise web security solutions, users of cloud-based web security solutions had 58% fewer malware incidents over the last 12 months, 93% fewer audit deficiencies, 45% less security-related downtime, and 45% fewer incidents of data loss or data exposure.

via Web Security in the Cloud: More Secure! Compliant! Less Expensive!.