Showing posts with label Chrome Web Store. Show all posts
Showing posts with label Chrome Web Store. Show all posts

Wednesday, 5 September 2018

MEGA Warns Against An Infected Chrome Extension That Steals Data



The popular cloud storage service MEGA has warned users of an infected version of its own Chrome extension that was distributed through the official download channel and tried to steal all kinds of user data. According to MEGA, the cloud storage service of internet entrepreneur Kim Dotcom, an attacker has gained access to the official Chrome Web Store account of the company.

Then an infected version of the MEGA Chrome extension was placed in the Web Store and automatically offered to existing users. This version required permission to read data on all websites. As soon as users granted this permission, the extension tried to steal private keys for cryptocurrency wallets and user names and passwords for Amazon, GitHub, Google and Microsoft accounts.

After five hours, the infected Chrome extension was removed from the Chrome Web Store by Google. MEGA states that it has initiated an investigation to find out how the Web Store account could be taken over. The cloud storage service also gets to Google because it does not allow developers to sign their Chrome extensions. The extensions are now automatically signed after being uploaded to the Chrome Web Store. According to MEGA, this will remove an important measure that must protect against attackers.

Before MEGA gave the warning, Jeremy Nation of MetaCert already came up with an analysis of the infected extension. It is not the first time that attackers get access to the Web Store account of an extension developer and then distribute an infected update or version. At the end of last year, eight Chrome extensions were discovered that had been hacked and adware was installed by the 4.6 million users. The attackers had been able to trace the login data for the Web Store through these phishing attacks.

Tuesday, 10 October 2017

37,000 Chrome Users Downloaded Fake Version Of Adblock Plus



Over 37,000 Chrome users have downloaded a fake version of the popular Adblocker Adblock Plus. The extension was offered in the official Chrome Web Store, so the security investigator reports the "SwiftOnSecurity" alias on Twitter .

The extension used non-Latin characters so it seemed like it was about Adblock Plus. Over 37,000 Chrome users were deceived in this way. Once installed, the fake version shows all kinds of ads. The extension developer appears to be cloning more popular extensions and then offering it in the Chrome Web Store. Meanwhile, Google has removed the Chrome Web Store extension. The true version of Adblock Plus has more than 10 million users and over 158,000 reviews.

Tuesday, 3 November 2015

Research: PGP Tools Still Unsuitable For The Masses


PGP tools for encrypting e-mail messages have been around for years, but are still unsuitable for the masses to use. Researchers at Brigham Young University concluded on the basis of own research (pdf).


For their research they let subjects Mailvelope try a browser extension for encrypting webmail. The reason was for Mailvelope chosen was that it is the only solution that is named by the American civil rights movement EFF and existing webmail services can handle. Also gets positive reactions in the Chrome Web Store. At the trial, 20 participants took part, divided into 10 pairs. The participants were instructed to Mailvelope encrypted via e-mail each other within one hour. Only one pair of pressed herein.

"This shows that the encryption of e-mail using PGP, as implemented in Mailvelope still unsuitable for the masses," according to the researchers. The most common mistake during the study was to encrypt a message using the public key of the sender. Something happened seven couples, including the couple finally did manage to send an encrypted message.Furthermore, three pairs generated a key pair "with information from their friends, and then tried to use public key to encrypt their message.

Improvement

Despite the criticism, the researchers also show improvement. They advocated for integrated tutorials to guide new users.Furthermore, a simple explanation of cryptography via public keys help users to manage their own keys well and could offer PGP-based tools to automatically for unknown recipients to generate an e-mail with the request to install the PGP software, a generate public key and share it with the sender.

Saturday, 8 August 2015

Chrome Will Block Deceptive Inline Installations



To protect Chrome users from unwanted extensions, Google has announced a new measure. From September, the browser inline installations of extensions that originate block of misleading websites and advertisements.

Inline systems were introduced in 2011 as a way to easily install extensions from the website of a developer. The mechanism is now used by Web sites to trick users into installing unwanted extensions. So users can get a pop-up stating that they need to update their Flash Player to view the video. However, the pop-up does not point to Flash Player, but an inline installation of another extension.

According to Google unwanted extensions are a major annoyance for users and a major source of complaints. In recent years, the company decided to take several measures. Blocking of inline installations, there is one of them. The blockade starts on September 3rd. In this case, Chrome will block the installation and users can now send it to the Chrome Web Store, so they can decide as to whether or not to install the extension. The new measure would affect less than 0.2% of all extensions, but it is an important measure to keep the extension ecosystem healthy, says Andrew Kim from Google.

Wednesday, 25 March 2015

Oracle Provides Mac Version Of Java Again With "Adware"


Oracle has started with the delivery of the Java installation for Mac with the infamous Ask Toolbar. Also users get back to whether they have their home in Ask.com want to change. In early March showed that Oracle had the setup of Java for Mac bundled with the Ask Toolbar.

The software does this for some time for the Windows version, but it's the first time it does this for the Mac version. The Ask Toolbar is labeled as adware by different parties. The toolbar uses the Ask search engine, which would be full of bad classified ads. Advertisements that are not of the "organic" results would be distinguished in most cases.

There was considerable controversy because of bundling the Ask Toolbar and after a week seemed Oracle thus stopped to be. Several parties indicated they when installing Java to see the toolbar no longer received. Security firm Intego reports that Oracle now controls the location of users first before it is decided to activate the installation of the Ask Toolbar. Thus, French users will not see the toolbar, while US users will be asked if they want to install.

Regardless of the country of the user is always installed the "Sponsors.framework" when installing Java on the Mac, which again to install the Ask Toolbar is responsible. Intego suspects that the Ask Toolbar can be enabled with future updates , without the need for Java to be installed. The framework would say, if it is already installed, can be updated silently.

Friday, 6 March 2015

Oracle Adds "Adware" To Java Installation On Mac


For years, the installer for Java on Windows bundled with additional software, such as the Ask Toolbar, but now Oracle applies this practice also allows for the Java installer on Mac OS X. The Ask Toolbar is labeled by various parties as "adware." Under Windows Follower Ed Bott shows the Ask search engine bad results that are filled with advertisements that do not "organic" results can be distinguished in most cases.

In the case of Mac OS X is about 8 Java Update 40 whereby the Ask Toolbar is installed and the home page is changed. This version came out the week. The option to install the Ask Toolbar and change home is checked by default. Anyone who does not pay attention during installation has also a toolbar at. Bott discovered the new bundle of Oracle policy. He also discovered that the Ask developers in the Chrome Web Store does not use their own name, but "chromewebstore12".

Developers do when two other apps the same, allowing users might think that it is official Chrome apps. Oracle website now also makes mention that cooperation with certain parties that offer different products, but provides no further explanation or lets you know what people can do to remove Ask their system. Oracle's decision to join the toolbar follows the Lenovo Superfish debacle. Lenovo did this knowing that in the future cleaner machines will offer without much preinstalled software.