Wednesday, June 4, 2008

Does your password pass the test?



This post is the latest in an ongoing series about online safety. - Ed.

One of the things I work on is password security. And because I'm someone who pays close attention to passwords and how people use them, I sometimes hear interesting stories. For example, a couple of my colleagues are so careful about the security of their passwords that they generate a random eight-character string, memorize it, and then use it as their password for two to three months. After that time elapses, they start the process over again and generate a new random password.

Do we all need to be that careful about our passwords? Probably not. But passwords are one of the web's most important security tools. Whether it's for your Google account, your banking center, or your favorite store, choosing a good password and keeping it safe can go a long way toward protecting your information online.

So how do you choose a good password, and then keep it safe? A few of these tips can help:
  • Avoid common elements when choosing your password. Specifically, you should avoid using words or phases from the dictionary, especially things that are easy to guess, like "password," "let me in," or the name of the site you're logging into. You should also avoid using keyboard patterns, such as "asdf1234" or "aqswdefr," or personal information, such as birthdays, addresses, or phone numbers.
  • Make your password as unique as possible. Once you've settled on a good base for your password, you should go a step further and add in numbers and non-alphanumerical characters, mix in upper-case letters, or use similar-looking substitutions for parts of the password, such as "$" for "s," "1" for "l," and "0" for "o."
  • Create different passwords for different sites. Doing so will help ensure that if one password is compromised, the others will remain secure. You may not be able to have a unique password for every place you visit on the web (for some of us, that would be a lot of passwords to manage), but alternating between a set of different passwords across the web and making sure all accounts that contain highly sensitive information (like email accounts or online banking accounts) have unique passwords is a good place to start.
  • Don't share your passwords with anyone. Not family, not friends, not anyone. This may seem a little strict, but the reality is the more people you share your password with, the greater your chances of having that password compromised will be. Also, if you need to write your passwords down, keep them away from your computer, and never send them in emails. And if you suspect someone might have discovered one of your passwords, change it immediately.
  • Be careful how you share your information online. Some online services -- such as social networking sites and gadgets that scrape information from other products -- may ask you for a password or an API key. If you choose to use these kinds of services, take a few minutes to learn more about what they do to keep your sensitive information secure. And just like sharing passwords with other people, you should be aware that sharing this information increases the chances that it could be compromised.
Another thing that can help keep your password secure is choosing a good security question and answer on the sites that offer that option. You've probably seen this before: When you're creating an account on many sites, you will be asked to choose a question to verify your identity if you forget your password.

Some sites will let you write in your own question; in these cases, you should make sure the Q&A you create isn't something that's easy to guess or something that your family and friends would know. Other sites will present you with a list of preset questions to choose from, such as "What is your mother's maiden name?" These kinds of questions are less secure, as they're easier for other people to guess the answer. In these cases, you should find a way to make your answer unique -- whether it's using the tips above, or by adding in other information -- so that even if someone guesses the answer, they won't know how to enter it properly.

Read more about choosing a good password and security question.

Tuesday, June 3, 2008

More on Robots Exclusion Protocol (REP)



Web publishers often ask us how they can maximize their visibility on the web. Much of this has to do with search engine optimization -- making sure a publisher's content shows up on all the search engines.

However, there are some cases in which publishers need to communicate more information to search engines -- like the fact that they don't want certain content to appear in search results. And for that they use something called the Robots Exclusion Protocol (REP), which lets publishers control how search engines access their site: whether it's controlling the visibility of their content across their site (via robots.txt) or down to a much more granular level for individual pages (via META tags).

Since it was introduced in the early '90s, REP has become the de facto standard by which web publishers specify which parts of their site they want public and which parts they want to keep private. Today, millions of publishers use REP as an easy and efficient way to communicate with search engines. Its strength lies in its flexibility to evolve in parallel with the web, its universal implementation across major search engines and all major robots, and in the way it works for any publisher, no matter how large or small.

While REP is observed by virtually all search engines, we've never come together to detail how we each interpret different tags. Over the last couple of years, we have worked with Microsoft and Yahoo! to bring forward standards such as Sitemaps and offer additional tools for webmasters. Since the original announcement, we have, and will continue to, deliver further improvements based on what we are hearing from the community.

Today, in that same spirit of making the lives of webmasters simpler, we're releasing detailed documentation about how we implement REP. This will provide a common implementation for webmasters and make it easier for any publisher to know how their REP directives will be handled by three major search providers -- making REP more intuitive and friendly to even more publishers on the web.

To see the major REP features currently implemented by Google, Microsoft, and Yahoo!, please see our detailed post on the Webmaster Central blog.

Google Site Search taps the power of the cloud



Search is never far from our minds -- not just on Google, but also for the millions of websites that don't yet have high-quality search. And since we've already built powerful search technologies into our computing infrastructure, site owners don't have to build it themselves. It's an aspect of something you might have heard about recently: "cloud computing".

Our ability to work in the cloud is one reason we've just announced Google Site Search with enhanced index coverage. Previously known as Custom Search Business Edition, this service gives any website the same relevance, ease of use and familiar search experience you get on Google.com. It takes just minutes to set up, and is hosted entirely by Google, so site owners can have great search capabilities with little or no maintenance and technical resources needed. We've also added enhanced index coverage and customization features that help us crawl and index all content (even pages deep within a site) -- and as a result, we can deliver comprehensive search results on any website.

It's not only webmasters who can take advantage of these features; so can site owners who want to maximize e-commerce opportunities and increase their conversions when they deliver a high-quality search experience to site visitors. Read more on the Google Enterprise blog to learn how you can offer better search on your site.

To see Google Site Search in action, watch this video featuring eHealthInsurance:

Monday, June 2, 2008

At long last, real-time stock quotes are here



We're very excited to tell you that real-time quotes on NASDAQ securities are now available on Google Finance. This is an important (and way overdue) development for everyone who consumes financial information. Historically, real-time stock data was not freely and widely accessible. Either buried behind subscription walls or brokerage sites, consumers typically had to live with 15 or 20 minute price delays. In the world of finance, time is indeed money, and it's critical to have timely and accurate data.

Providing free real-time stock quotes is consistent with our mission, and we'll continue to work hard to offer tools, features and more real-time data so investors can make informed and timely financial decisions.

Sunday, June 1, 2008

Treasure Hunt: the last leg of the journey



Over the last few weeks, we've been keeping you updated on our Treasure Hunt competition — a puzzle contest designed to test your knowledge of computer science, networking, and low-level UNIX trivia. And now it's coming to a close. The fourth and final puzzle will be released at 1212448500. With it, we'll also be highlighting Google Developer Day, which is coming up on June 18 at Wharf 8 in Sydney.

We'll be announcing the contest winners (and their handsome rewards) once the results are tabulated, so keep your spyglasses here over the next few weeks. And, of course, all the prior weeks' puzzles are still available on the main page.

You've come this far... be ye real treasure hunters or just landlubbers in disguise?
BLOG STAR © 2008. Design by :Yanku Templates Sponsored by: Tutorial87 Commentcute