Why spammers should thank Google?

Mohamed Ali Kaafar*, Pere Manils

*Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference proceeding contributionpeer-review

1 Citation (Scopus)

Abstract

Buzz, the new online social networking (OSN) service from Google has been introduced a few weeks ago. Even though it raised big concerns (and even complaints) about several privacy issues, Buzz has been already launched inside millions of Gmail accounts. In this paper, we show that one of the major concerns Buzz might have to deal with is that it is integrated into the Google email service. In fact, to use Buzz one has to sign up for a Google profile that will primarily be seen by other Google users. However this profile, as shown in this paper reveals for the vast majority of Buzz users their Gmail usernames, and so their Google email addresses. We exploit the notion of Followers/Follwing in Buzz to crawl Google for Gmail accounts, demonstrating how it is easy and practical to collect millions of valid Gmail accounts from a single machine, in a very short period of time and without being noticed. The collected email addresses have many desirable properties from a spammer's perspective. They are valid email addresses, that refer to active and individual Buzz users that participate in online social activities, increasing then the efficiency of spam campaigns targeting these users. We then show how spammers can even use the Google infrastructure to categorize the email accounts they collected based on specific area of interest of users. As a conclusion, this paper demonstrate that integrating Buzz to email accounts, and hence to Google profiles offers spammers with a valuable, yet not risky, way to build a giant Google emails-made spammers database.

Original languageEnglish
Title of host publicationProceedings of the 3rd Workshop on Social Network Systems, SNS'10
Place of PublicationNew York
PublisherAssociation for Computing Machinery
Number of pages6
ISBN (Print)9781450300803
DOIs
Publication statusPublished - 2010
Externally publishedYes
Event3rd Workshop on Social Network Systems, SNS'10 - Paris, France
Duration: 13 Apr 201013 Apr 2010

Conference

Conference3rd Workshop on Social Network Systems, SNS'10
CountryFrance
CityParis
Period13/04/1013/04/10

Keywords

  • online social networks
  • privacy
  • security
  • spam
  • web crawling

Fingerprint

Dive into the research topics of 'Why spammers should thank Google?'. Together they form a unique fingerprint.

Cite this