[ news_security_news ] G-Archiver Swears Password Theft An Accident
David Utter Staff Writer
2008-03-11
Security News RSS Feed
Testing code left within the release version of Gmail backup software G-Archiver sent usernames and passwords to a developer's Gmail account.
Another chapter was added to the kerfuffle over G-Archiver and the discovery of its username/password catching code. The code sent over 1,700 Gmail username and password combos to the Gmail account of a developer named John Terry.
Jeff Atwood at Coding Horror reported on this, based on an email he received from the discoverer of the rogue code, Dustin Brooks. After taking a peek at G-Archiver's code, he found a name, John Terry, and a hard-coded username and password for Terry's Gmail account.
Brooks looked at that Gmail account and found 1,777 usernames and passwords for Gmail accounts, all forwarded to that address.
"I generally try to give people the benefit of the doubt, but it's difficult to imagine any scenario where this isn't a completely malicious violation of people's trust," Atwood wrote.
G-Archiver delivered on the mea culpas today:
What happened with G-Archiver?
It has come to our attention that a flaw in the coding of G-Archiver may have revealed customer's Gmail account usernames and passwords.
It is urgent that you remove the current version of G-Archiver from your computer, and change your Gmail account password right away.
What happened was that a member of our development team had inserted coding used for testing G-Archiver in the debug version and forgot to delete it in the final release version.
We sincerely apologize and assure you that this coding mishap was in no way intentional.
We'll be releasing a new version that corrects the flaw in version 1.0. The new version will be available very soon.
As Atwood noted, regaining that trust will be difficult for G-Archiver. Even if it is an innocent mistake.
View All Articles by David Utter
About the Author:
David Utter is a business and technology writer for SecurityProNews and WebProNews.
More news_security_news Articles
Security News RSS Feed
|
|