Researcher Creates Database of 35 Million Identifiable Google Profiles
A Dutch researcher has discovered that he could convert most of the data within Google Profiles into a single SQL statement and expose, among other data, the usernames and Gmail addresses of some 35,000,000 people.
The researcher, Matthijs R. Koot explained in a blogpost that there is an xml file known inside and outside of Google which points to more than 7000 sitemap-NNN(N).txt containing 5000 hyperlinks to Google profiles, with some 35,000,000 links in all. Koot spent roughly a month assembling this information into a database, and claims that in that time Google neither throttled, blocked, CAPTHCAd, or otherwise made his mass-downloading experience difficult in any way.
Koot claims that Google Profiles gives users the choice of using their username in their Google Profile URL, but warns that doing so could make an individual’s email address publicly accessible. The 35,000,000 profiles he assembled are those which chose to use their usernames to make a Google Profile URL easier to find and remember.
Editor's Pick
Other information he was able to access include in many cases, users’ professions, employers, education information, locations, links to their Twitter accounts, Picasa photo albums, LinkedIn accounts, and at times, various other information.
The researcher says this information is a spear-phishing attack just waiting to happen. In a second blog post, Koot claims his efforts are “directed at inciting, or poking up, debate about privacy – NOT to create DISTRUST but to achieve REALISTIC trust.” He goes on to claim this is another instance of Google, or any other tech company for that matter, equating "implied consent" with checking a box.
For more depth and information on this issue, you can find Matthijs R. Koot’s original blog posts here and here (in that order).
Commenting on this Article is closed.
Today's Most Popular
- Anatomy of a LulzSec Attack 'Singles Out' Web 2.0 Weakness
- Common Firewall Feature Enables TCP Hijacking Attacks
- Defense Contractor Northrop Grumman Hiring For Offensive Cyber Ops
- Facebook Cancellation Malware Disguised As Adobe Update Making Rounds
- OPINION: Are Anonymous Members Forged in the Crucible of IT Compliance?
Most Commented Stories
-
Forget 'Brogrammers,' Women Have The Edge In DEFCON Social Engineering Contest (9)
-
Defense Contractor Northrop Grumman Hiring For Offensive Cyber Ops (10)
-
The Internet Crime Complaint Center recently warned of malware targeting travelers connecting to Wi-Fi. When traveling, do you (1)
-
HULK DDoS Tool Smash Web Server, Server Fall Down (4)
-
Report: Diablo III Users Find Accounts Hacked, Gold Stolen And New 'Mystery' Friends (2)
Newsletter Sign-up
Take Our Poll
Listen to Latest Podcasts
-
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.



