Referral Banners
Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Spam takes another hit: email authentication now available to millions of Google Apps customers

Google has been an early and consistent supporter of email authentication technologies, which help ensure senders are who they say they are, and in turn help to curb spam. Since we launched Gmail in 2004, we have supported email-signing standards such as DomainKeys and DomainKeys Identified Mail (DKIM) to help validate outbound mail with digital signatures. On the inbound side, to help our users identify email from verified senders, in 2008 we worked with eBay and PayPal to authenticate their mail with DKIM and block all unsigned messages purportedly from those companies destined for Gmail users.

But the spam and phishing epidemics aren’t letting up – every day Gmail filters out billions of unwanted messages from our users’ inboxes – so we’ve been focused on creating helpful tools and working with the email industry to bring solutions that will help our customers. Email authentication is an important mechanism to verify senders’ identities, giving users a tool to recognize potential spam messages. In addition, many mail systems can display whether a received message is DKIM-verified, which helps spam filters verify and assess the overall reputation of the sender’s domain: messages from untrusted senders are treated more skeptically than those from good senders.

Today, we mark another notch in the spam-fighting belt: we’re making it possible for all Google Apps customers to sign their outgoing messages with DKIM, so their sent mail is less likely to get caught up in recipients’ spam filters. Google Apps is the first major email platform – including on-premises providers – to offer simple DKIM signing at no extra cost. Once again, the power of the cloud has made it possible for us to bring this feature to millions of customers quickly and affordably.


“We help the most-phished brands on the Internet manage their mail authentication programs, and the Google Apps solution is the simplest that we've encountered. Configuring DKIM for in-house systems requires plug-ins or additional gateway servers, making a company's mail environment more complex and difficult to manage. As a Google Apps customer, this feature took us only a few clicks in the control panel and an update of our DNS," said Kelly Wanser, CEO of eCert, an industry leader in providing critical protection against email fraud.

Starting today, all Google Apps administrators can enable DKIM signing in the “Advanced Tools” tab of the control panel. As more email providers around the world support DKIM signing, spam fighters will have an even more reliable signal to separate unwanted mail from good mail. We’re pleased to let millions more organizations use DKIM with this improvement.

Security First - A Chat with Google Apps Security and Privacy Experts

Google Apps customers experience both cost savings and productivity benefits, and more than 3 million of businesses have made the switch to Google Apps. To answer some of the questions businesses often ask about the security and privacy of data that is stored in Google Apps, we released the Google Apps Security Whitepaper in June. And to provide further visibility into how we protect the data in Google Apps, we are hosting a webcast on November 18th, 2010. Register today to attend this webcast.

In the webcast, Eran Feigenbaum, Director of Security for Google Apps, will describe some of the challenges of securing traditional on-premise IT infrastructure and explain how Google’s cloud computing architecture can offer an improved security model. John Collins, Google Enterprise Trust Product Manager, will then talk about how Google protects the privacy of the data that is stored in Google Apps.

We will take questions from the audience, so if your business or organization is considering a move to Google Apps, this session will be a great opportunity.

Register to attend this webcast, Thursday, November 18th at 11:00 AM PST / 2:00 PM EST / 19:00 GMT.

Bring Your Phone to Work Day: Managing Android Devices With Google Apps

Today in Tokyo, more than 600 IT leaders from across Japan are coming together with Google and 18 of our partners at Google Enterprise Day. It’s our annual event dedicated to discussing trends in enterprise technology and how businesses can use cloud technologies to increase productivity and innovate more quickly. This year, one of the hottest topics is mobile computing and how companies can allow employees to use their personal phones and tablets at work without compromising corporate security.

With over 200,000 devices activated each day, Android is seeing rapid adoption, and today we are launching new administrative controls that make it possible to securely manage these devices in the Google Apps environment. With this launch, Google Apps provides secure management and sync capabilities for all major mobile platforms. You can manage most mobile devices right from the browser, without having to deploy dedicated servers.

Many Android devices feature tight integration with Google Apps, including native applications for Gmail, Google Talk, and Google Calendar, as well as mobile access to Google Docs. Now any employee with an Android device running version 2.2 - personal or company-issued - can access their corporate information while allowing administrators to enforce data security policies such as:
  • Remotely wipe all data from lost or stolen mobile devices
  • Lock idle devices after a period of inactivity
  • Require a device password on each phone
  • Set minimum lengths for more secure passwords
  • Require passwords to include letters and numbers

When the employee leaves the company, the administrator can withdraw access to corporate info, which allows the employee to continue to use their device if it’s their own.

These policies can be enforced on devices that have installed the Google Apps Device Policy application, which will be available from Android Market in the next few days. They will be available free to all Google Apps Premier and Education Edition customers in the next few days, and can be accessed from the 'Mobile' tab under 'Service Settings' in the Google Apps control panel.



To learn more about these updates in mobile device management for Google Apps, join us for a live webcast with Mayur Kamat, Google Apps Product Manager, on November 10, 2010 at 9 a.m. PDT / 12 p.m. EDT / 6 p.m. GMT. Register now.

Security First: Google at the Cloud Security Institute Conference

The Google Enterprise team is excited to be participating in the Computer Security Institute Annual Conference, CSI 2010, taking place in National Harbor, Maryland, from Tuesday through Friday, October 26-29. CSI2010 brings together security and IT professionals from around the world to discuss and share best practices in computer security, risk management and compliance. The event features keynote presentations, workshops, panel discussions and customer case studies. Google’s Adam Swidler will be presenting a session entitled “Is Your Organization’s Data Safer in the Cloud?” at 11:15 AM EDT on Friday, October 29.

If you'll be at the conference, please join us for Adam’s presentation to hear about information security, privacy, and data protection in the cloud from Google’s perspective. If you can’t attend the conference, please visit our website for more information about about the security and privacy of data in Google Apps.

Posted by Ashley Chandler, Google Apps team

New OAuth support for Google Apps APIs

Google Apps is designed to provide a secure and reliable platform for your data. Until today, Google Apps administrators had to sign requests for calls to Google Apps APIs using their username and password (this is called ClientLogin Authorization).

Yet sharing passwords across sites can pose security risks. Furthering our commitment to make the cloud more secure for our users, today we are pleased to announce support for OAuth authorization on Google Apps APIs.

There are several advantages to using OAuth instead of the username/password model:
  • OAuth is more secure: OAuth tokens can be scoped and set to expire by a certain date, making them more secure than using the ClientLogin mechanism.
  • OAuth is customizable: Using OAuth, you can create tokens that scripts may only use to access data of a particular scope when calling Google Apps APIs. For instance, a token set to call the Email Migration API would not be able to use your login credentials to access the Google Apps Provisioning API.
  • OAuth is an open standard: OAuth is an open source standard, making it a familiar choice for developers to work with.
The Google Apps APIs that support the OAuth signing mechanism are:

1. Provisioning API
2. Email Migration API
3. Admin Settings API
4. Calendar Resource API
5. Email Settings API
6. Audit API

OAuth support for Google Apps APIs is another step towards making Google Apps the most secure, reliable cloud based computing environment for organizations. To learn more about OAuth support and other administrative capacities launched in Google Apps this quarter, join us for a live webinar on Wednesday, September 29th at 9am PT / 12pm EST / 5pm GMT.

Administrators for Google Apps Premier, Education, and Government Editions can use OAuth authorization for Google Apps APIs starting today.For more information about the OAuth standard, visit http://oauth.net.

Security First: Google at the ISSA International Conference

This week the Google Enterprise team is excited to be participating in the Information Systems Security Association’s (ISSA) International Conference in Atlanta, GA from September 15-17. The ISSA is a not-for-profit, international professional organization of information security professionals and practitioners. It promotes management practices that will ensure the confidentiality, integrity and availability of information resources. This year more than 500 IT and security professionals will gather under this year’s theme of “Connect and Collaborate”.

Eran Feigenbaum, Director Security for Google Enterprise wil be delivering a keynote presentation entitled “A New Security Model in the Cloud” on Thursday, September 16th, at 12:40 PM.

If you'll be at the conference, please join us for Eran’s session. If you’re not going to be at the conference, you can find more information on the security and privacy of data in Google Apps.

Security First: Google at the CompTIA Breakaway 2010 Conference

On Thursday, August 12th, the Google Enterprise team will be participating in the inaugural Cybersecurity Summit at the CompTIA Breakaway 2010 Conference in San Antonio, Texas. The summit brings together leaders from the IT industry and government to discuss how to work together to mitigate the frequency and impact of cyber threats in the private and public sectors. Google will be participating in the panel discussion “Security in the Cloud” at 11 AM CDT.

If you'll be at the conference, please join us for the panel discussion to hear about Google’s cloud security efforts. Additionally, you can find lots of information about the security of our solutions for enterprises here.


Posted by Adam Swidler, Sr. Manager – Google Enterprise

Google Apps adds more admin controls for mobile devices

Earlier this year we announced support for mobile device security policies in Google Apps to help administrators manage iPhone, Nokia, and Windows Mobile devices from the Google Apps control panel. These policies let employees access information from their phones while helping administrators keep corporate data more secure. Today, we are announcing new mobile device management options for Google Apps administrators.

  • Requiring devices to use data encryption
  • Auto-wiping device after specified number of failed password attempts
  • Disabling the phone’s camera
  • Ensuring old passwords are not reused
  • Requiring passwords to be changed after specified time interval
  • Disabling data synchronization when device is roaming to reduce wireless overage charges

    Starting this week, these policies will be available to all Google Apps Premier and Education customers. They can be accessed from the 'Mobile' tab under 'Service Settings' in the Google Apps control panel.


    It’s our mission to provide users with seamless access to their data while allowing enterprise administrators to centrally manage a diverse range of mobile devices. We’re working to enhance our device management options and to expand our list of supported devices – including Android later this year. If you have any questions, please check out our Help Center documentation.

  • Security First: Google at the Gartner Security & Risk Management Summit

    This week the Google Enterprise team is excited to be participating in the Gartner Security and Risk Management Summit. From today through Wednesday, IT and business executives responsible for information security, risk management, compliance, and business continuity management will gather to discuss new technologies and strategies to better secure their organizations and reduce risk.

    We're particularly excited to be joined by Chet Loveland of MWV and Brian Bolt from Boise State University for a panel on security and cloud computing. They discussed why their organizations chose Google Apps, and the steps Google takes to protect the security and privacy of their data.

    On Tuesday, we’ll be presenting a review of Google Apps security and reliability, building on the content in our recently published Apps security white paper.

    If you'll be at the conference, please join us for a session or stop by our booth to learn more about Google’s solutions for cloud security. If you’re not going to be at the conference, you can find lots of information on Google Apps here.

    Posted by Adam Swidler, Sr. Manager – Google Enterprise

    Security First: Protecting your data with Google Apps

    For most companies, trying to keep ahead of new security threats every day feels like gripping a handful of sand. No matter how hard you tighten and squeeze, some still manages to slip through your fingers. IT departments often face these challenges alone despite parallel responsibilities to support other core operational functions. As thousands of businesses discover every day, companies and organizations can depend on the technical expertise of Google to help them better manage their security needs when they sign up for Google Apps.

    Feeling comfortable storing data in the cloud involves trusting a cloud services provider and the practices and policies they have in place. In today's ultra-connected, web-capable world, understanding how data will be protected is ultimately more meaningful than knowing it is physically located in one data center or another. We know that our customers expect us to be transparent, and we work hard to do just that. For example, earlier this year we disclosed a cyber attack against Google and at least twenty other large companies from a variety of industries.

    As a next step toward increased transparency, today we're releasing a new Google Apps security white paper to help customers learn more about the security practices, policies, and technology that support Google Apps. We are always improving and evolving the security of our systems, and we work every day to help protect against new threats.

    Google Apps offers a strong and extensive security infrastructure to support these and other benefits:
    • Our data centers are protected by advanced physical security controls, and access to information is monitored at multiple levels.
    • We store customer data in fragments across multiple servers and across multiple data centers to both enhance reliability and provide greater security than can be achieved by storing all data on a single server. When only fragments are kept in any one place, the chance that a possible physical or computer-based compromise could result in the loss of meaningful information is greatly reduced.
    • We perform software patching rapidly across identical server stacks to help keep users updated with the latest patches. This significantly reduces the deployment workload for IT administrators.
    • Administrators can set fine-grained access controls for documents, calendars, and other types of information commonly stored in the cloud.
    • Operations at vast scale can help detect security threats across the web early and prepare appropriate defenses.
    • System redundancy involves data replication across disparate data centers for availability and disaster recovery.
    • We have strong teams of security professionals dedicated to protecting customer data.
    Visit this new page to learn more about security and privacy protections for schools.

    We appreciate feedback as we continue to work hard to earn and maintain the trust that is placed in us.

    Posted by: Eran Feigenbaum, Director of Security, Google Enterprise

    New reset cookie functionality on Google Apps

    Google Apps provides businesses with seamless, secure access to information regardless of device. You can check your email or consult your calendar, sites, and documents from any web-enabled device anywhere in the world with an Internet connection.

    The ability to access your data from virtually anywhere enables higher productivity, but just like traditional systems that don’t run in the cloud, security concerns can arise if a user loses a computer or mobile device that can access their sensitive information. Fortunately, when users store data in Google Apps, they do not need to keep it on the device itself. Starting today, administrators can also easily invalidate a user’s active connection to Google Apps services from the Google Apps control panel.

    More specifically, administrators can now reset a user’s sign-in cookies to help prevent unauthorized access to their account. This will log out that user from all current web browser sessions and require new authentication the next time that user tries to access Google Apps. Combined with the existing ability for administrators to reset user passwords, this new feature to reset users’ sign-in cookies improves security in the cloud in case of device theft or loss.

    If you have any questions about this feature, please check out our help page.

    The security and privacy of our customer’s data is paramount so stay tuned for more security features on Google Apps.

    Disaster Recovery by Google

    Will you be ready when disaster strikes? It's an uncomfortable question for many IT administrators, because answering it with confidence usually requires boatloads of money, immense complexity, and crossed fingers. Fortunately there's a better way.

    Taking email as an example, consider a few of the ways that companies protect their data from disruption. Ideally a typical small business backs up its email. They have a mail server, and copy the data to tape at regular daily or weekly intervals. If something goes wrong, they go to the tapes to restore the data that was saved before their last backup. But the information created after their most recent backup is lost forever.

    In larger businesses, companies will add a storage area network (SAN), which is a consolidated place for all storage. SANs are expensive, and even then, you're out of luck if your data center goes down. So the largest enterprises will build an entirely new data center somewhere else, with another set of identical mail servers, another SAN and more people to staff them.

    But if, heaven forbid, disaster strikes both your data centers, you're toast (check out this customer's experience with a fire). So big companies will often build the second data center far away, in a different 'threat zone', which creates even more management headaches. Next they need to ensure the primary SAN talks to the backup SAN, so they have to implement robust bandwidth to handle terabytes of data flying back and forth without crippling their network. There are other backup options as well, but the story's the same: as redundancy increases, cost and complexity multiplies.

    Google Apps customers don't need to worry about any of this for the data they create and store within Google Apps. They get best-in-class disaster recovery for free, no matter their size. Indeed, it's one of the many reasons why the City of Los Angeles decided to go Google.


    How do you know if your disaster recovery solution is as strong as you need it to be? It's usually measured in two ways: RPO (Recovery Point Objective) and RTO (Recovery Time Objective). RPO is how much data you're willing to lose when things go wrong, and RTO is how long you're willing to go without service after a disaster.

    For a large enterprise running SANs, the RTO and RPO targets are an hour or less: the more you pay, the lower the numbers. That can mean a large company spending the big bucks is willing to lose all the email sent to them for up to an hour after the system goes down, and go without access to email for an hour as well. Enterprises without SANs may be literally trucking tapes back and forth between data centers, so as you can imagine their RPOs and RTOs can stretch into days. As for small businesses, often they just have to start over.

    For Google Apps customers, our RPO design target is zero, and our RTO design target is instant failover. We do this through live or synchronous replication: every action you take in Gmail is simultaneously replicated in two data centers at once, so that if one data center fails, we nearly instantly transfer your data over to the other one that's also been reflecting your actions.

    Our goal is not to lose any data when it's transferred from one data center to another, and to transfer your data so quickly that you don't even know a data center experiences an interruption. Of course, no backup solution from us or anyone else is absolutely perfect, but we've invested a lot of effort to help make it second to none.

    And it's not just to preserve your Gmail accounts. You get the same level of data replication for all the other major applications in the Apps suite: Google Calendar, Google Docs, and Google Sites.

    Some companies have adopted synchronous replication as well, but it is even more expensive than everything else we've mentioned. To backup 25GB of data with synchronous replication a business may easily pay from $150 to $500+ in storage and maintenance costs- and that's per employee. That doesn't even include the cost of the applications. The exact price depends on a number of factors such as the number of times the data is replicated and the choice of service provider.

    At the low end a company might tier the number of times they replicate data, and at the high end they'll make several copies of the data for everyone. We also replicate all the data multiple times, and the 25GB per employee for Gmail is backed up for free. Plus you get even more disk space for storage-intensive applications like Google Docs, Google Sites and Google Video for business. Other companies may offer cloud computing solutions as well, but don't assume they backup your data in more than one data center.

    Here are a few of the reasons why we're able to offer you this level of service. First, we operate many large data centers simultaneously for millions of users, which helps reduce cost while increasing resiliency and redundancy. Second, we're not wasting money and resources by having a data center stand-by unused until something goes wrong – we can balance loads between data centers as needed.

    Finally, we have very high speed connections between data centers, so that we can transfer data very quickly from one set of servers to another. This let us replicate large amounts of data simultaneously.

    One of the most compelling advantages of cloud computing is its power to democratize technology. Whether it's a 25GB email inbox, Video for business, synchronous replication, or one of countless other advanced services, Google Apps gives companies of all sizes access to technology that until recently was available to only the largest enterprises. And it's available at a dramatically lower cost than the on-premises alternatives, without the usual hassles of upgrading, patching and maintaining the software.

    No one likes preparing for worst-case scenarios. When you use Google Apps, you have one less critical thing to worry about.

    Posted by Rajen Sheth, Senior Product Manager, Google Apps

    Google joins the Cloud Security Alliance

    Today we're happy to announce that Google has joined the Cloud Security Alliance, a non-profit organization of experts focused on best practices and education efforts around the security of cloud computing.

    Cloud computing continues to gain momentum, and organizations such as the CSA are an important part of an ecosystem that works to increase transparency, lower risks, and promote independent research. The CSA's focus on security best practices offers valuable information to organizations looking to move to the cloud, and as a member of the CSA, we look forward to providing ongoing education about cloud computing and its value to the organizations that use it.

    Google's activities with the CSA include sponsoring the Cloud Security Alliance Summit at RSA Conference 2010 on March 1, 2010 in San Francisco, California, and participating in a CSA panel discussion at SecureCloud 2010, held on March 16 and 17 in Barcelona, Spain.

    Learn more about Google's cloud computing solutions for organizations.

    Posted by Adam Swidler, Google Enterprise Marketing team