Security

Read all 'glitch' posts in Security
September 18, 2009 3:01 PM PDT

Google Apps bug: You've got (my) mail

by Elinor Mills
  • 23 comments

As a result of a bug in a Google Apps e-mail migration tool, some students at Brown University found other students' e-mail in their in-box over the weekend as Google was moving their e-mail from Exchange to Gmail, Google confirmed on Friday.

The problem affected a "handful" of organizations that use Google Apps, a spokesman said. He declined to specify how many were affected or how many individual users were affected.

Brown University newspaper the Brown Daily Herald reported that e-mail for 22 students was misdirected starting on Friday, that the university notified Google about it on Saturday, and it was fixed on Tuesday.

However, the Google spokesman said the company found out about the problem on Monday, disabled the affected accounts within hours, and then restored the accounts within a day.

"A very small number of Google Apps domains using the IMAP migration tool last weekend encountered a bug that caused a handful of their users' mail to be migrated to the wrong accounts," the spokesman said in a statement. "We quickly identified and fixed the issue, which affected less than 0.002% of users, and worked with the organizations to restore the affected accounts to their original state. We have extensive safeguards in place to ensure that users' mail is safe, and we're confident this was an isolated incident."

Donald Tom, director of IT support services at the school, complained to the newspaper that the school was not notified before the affected e-mail accounts were suspended. However, he did praise Google for moving swiftly to fix the problem.

Asked to respond to that criticism, the Google spokesman said: "In this case we made the judgment call that the safest and most expedient course of action for the affected users was to suspend affected accounts as soon as possible. In our conversations with our customers, they've appreciated our prompt actions and have been satisfied with the outcome."

Originally posted at InSecurity Complex
April 13, 2009 5:46 PM PDT

Amazon 'adult' book-delisting fail: Error or troll?

by Elinor Mills
  • 35 comments

Updated 3:15 p.m. PDT April 14 with Amazon saying the problem has been fixed and 2:15 p.m. with insider saying it was manual error by Amazon worker in France and 9:45 a.m. with background on Weev and comment from sources who say he is most likely not involved in the Amazon incident.

Amazon got blasted by gay rights groups this weekend after gay and lesbian book titles were delisted from its site. Was it an internal glitch, as Amazon claims, or is an Internet troll with a vendetta responsible?

Amazon spokeswoman Patty Smith told CNET News on Monday that the "glitch" was being fixed, but declined to elaborate. (By Tuesday afternoon the problem was all fixed, she said.)

"This is an embarrassing and ham-fisted cataloging error for a company that prides itself on offering complete selection," she wrote in an e-mail statement.

"It has been misreported that the issue was limited to Gay and Lesbian themed titles--in fact, it impacted 57,310 books in a number of broad categories such as Health, Mind and Body, Reproductive and Sexual Medicine, and Erotica," the statement said. "This problem impacted books not just in the United States but globally. It affected not just sales rank but also had the effect of removing the books from Amazon's main product search."

However, a Live Journal blogger with the alias of "weev" claims he did it to cause an outrage among the gay community, which he alleges has repeatedly flagged his online ads on Craigslist as inappropriate.

"I guess my game is up! Here's a nice piece I like to call 'how to cause moral outrage from the entire Internet in ten lines of code,'" he writes on his blog.

Weev said he figured out that he could easily get the books removed from search rankings by reporting them as inappropriate through a link at the bottom of the book page. He also claims he wrote code to identify all the gay and lesbian metadata-tagged books on Amazon and grab their IDs. He then hired people outside the U.S. to register new accounts en masse to help push the books out of the system, he said.

"Now from here it was a matter of getting a lot of people to vote for the books," he wrote. "The thing about the adult reporting function of Amazon was that it was vulnerable to something called 'cross-site request forgery.' This means if I referred someone to the URL of the successful complaint, it would resister as a complaint if they were logged in. So now it is a numbers game."

Amazon's Smith dismissed the claim and insisted the error was internal. She is not alone. Several sources have questioned Weev's account, particularly given his notoriety as an Internet troll, someone who flames others in online discussions and is intentionally disruptive on the Web.

Blogger Mike Daisey, who worked in customer support and business development at Amazon from 1998 until 2001, wrote on his blog that: "Someone was editing the category systems inside of Amazon.fr, made an error, and that system is global, so it propagated everywhere. I have no insight as to anyone's nationality, or whether it was a language gap, or anything of that nature."

Smith declined to comment on Daisey's explanation.

A Seattle Post-Intelligencer article quotes an unnamed Amazon employee who confirmed the report of manual error. "Amazon managers found that an employee who happened to work in France had filled out a field incorrectly and more than 50,000 items got flipped over to be flagged as 'adult,'" the source told the newspaper.

Blogger Bryant Durrell said he tested out Weev's concept and doesn't believe it is legitimate, partly because of buggy code.

"Summation: nope, you didn't do that, you liar you. Nice meta-troll, though," Durrell wrote on his blog.

"The really interesting thing about the troll is that he's right even if he didn't do it. The vulnerability he describes exists anywhere you make automated decisions based on third-party input."

Among the more than 1,500 products on Amazon that have been tagged "amazonfail" are "Lady Chatterley's Lover" and "Brokeback Mountain."

(Credit: Amazon)
  • prev
  • 1
  • next
advertisement

15 sites that went kaput in 2009

Web sites launch all the time, but they also shut their doors. We highlight 15 that bit the dust this year.

Top 10 news stories of the decade

Let the debate begin: Was the iPhone more important than iTunes? Was anything bigger than Google finding a great business model? CNET offers its list of the 10 most important stories of the '00s.

About Security

Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.

Add this feed to your online news reader

Security topics

Most Discussed



advertisement

Inside CNET News

Scroll Left Scroll Right