Showing posts with label Google Chrome. Show all posts
Showing posts with label Google Chrome. Show all posts

Wednesday, 5 September 2018

Google Chrome Will No Longer Show 'Protected' At HTTPS Sites



To celebrate the tenth anniversary of Google Chrome, a new version of the browser has appeared that does not show the word 'secured' at https sites, makes using Flash Player more difficult, introduces an improved password manager and fixes 40 security vulnerabilities.

On 2 September 2008 , Google launched its own browser, which has since become the dominant browser. According to StatCounter, Chrome has a market share of almost 68 percent on the desktop . In the Netherlands, around 54 percent of desktop users would browse with Chrome. Yesterday evening the 69th version of Chrome appeared that contains all kinds of new features and improvements.

This allows Chrome 69 to enter passwords, address details and credit card numbers more accurately. It is data stored in the user's Google account and accessible directly from the Chrome toolbar. The browser also has an improved password manager that can generate unique passwords for websites and accounts. Saved passwords are then available to users with a Google account on both the computer and mobile devices.

Furthermore, Chrome 69 does not show the word "secured" on websites with a secure connection. Only the lock icon indicates that a secure connection is being used. Eventually the lock icon will also disappear. Google decided in July to display the message "Unprotected" at all http sites. The internet giant wants https sites to be the norm and users will only see a notification at http sites.

Also, in the browser measures have been taken to make the use of Adobe Flash Player more difficult. Previously, users could whitelists websites that wanted to access the built-in Flash Player. That has now changed. Users must allow this separately each time a website wants to enable Flash content, regardless of whether they have done so in previous sessions.

In addition, Google has fixed 40 vulnerabilities in the browser that prevented an attacker from stealing or modifying data from other websites in the worst case scenario. Updating to Chrome 69.0.3497.81 will happen automatically on most systems. For Android users, Chrome 69.0.3497.76 has been made available.

Wednesday, 14 March 2018

Mozilla: Many Popular Websites With Symantec Certificates




There are still many popular websites with Symantec certificates that will soon no longer be trusted by Firefox and will cause an error message, as Mozilla has warned. It is about 1 percent of the Top 1 million most popular websites on the internet, which amounts to about 10,000 sites.

These websites use a tls certificate issued by Symantec to encrypt traffic to and from their visitors. Due to various incidents with tls certificates issued by Symantec, browser developers have decided to cancel the trust in Symantec certificates. This will take place in phases, with all Symantec certificates issued before 1 July 2016 no longer being trusted.

Google will implement this measure next month with the launch of Chrome 66. Mozilla will follow Firefox 9 on May 9. With the launch of Firefox 63 in October this year, trust in all Symantec certificates will be canceled regardless of issue date. Users who receive a certificate warning when visiting a website can ignore them and still reach the website, Mozilla explains, but security experts advise internet users never to ignore such warnings and not to visit the website in question.

Tuesday, 10 October 2017

37,000 Chrome Users Downloaded Fake Version Of Adblock Plus



Over 37,000 Chrome users have downloaded a fake version of the popular Adblocker Adblock Plus. The extension was offered in the official Chrome Web Store, so the security investigator reports the "SwiftOnSecurity" alias on Twitter .

The extension used non-Latin characters so it seemed like it was about Adblock Plus. Over 37,000 Chrome users were deceived in this way. Once installed, the fake version shows all kinds of ads. The extension developer appears to be cloning more popular extensions and then offering it in the Chrome Web Store. Meanwhile, Google has removed the Chrome Web Store extension. The true version of Adblock Plus has more than 10 million users and over 158,000 reviews.

Thursday, 11 February 2016

Google Stops From 2017 With Flash Ads


From January 2017 Google stops displaying Flash ads on their own ad networks, such as the Google Display Network and DoubleClick, as the Internet giant has over Google Plus disclosed. According to Google, it's important for advertisers to switch to HTML5 ads, so many people can be reached.

To accelerate this process will AdWords and DoubleClick Digital Marketing from June 30 to accept new Flash ads this year.From January 2, 2017 Flash ads will no longer be on the Google Display Network are displayed via DoubleClick. Google warns advertisers that they should have converted their ads to HTML5 for these dates. For now, the new measure does not affect video ads created in Flash.

Google has long been working to make Flash unnecessary. As YouTube videos are automatically played through HTML5. In the case of Flash ads that are distributed through AdWords, which are automatically converted to HTML5 since February last year. Since September 1st of last year, most Flash ads automatically in Google Chrome paused .

Last year, also called Alex Stamos, the new Chief Security Officer (CSO) of Facebook, which with Adobe Flash technology to stop , so that it can be switched completely on HTML5. HTML5 is natively supported by modern browsers and allows playback of videos and other "rich content" without installing additional plug-ins possible.

Monday, 16 November 2015

Google Chrome Now Also Protects Against Social Engineering


Google Chrome has the protection of its users expanded. Chrome previously protected its users against all phishing sites and websites with malware, social engineering is now also added. Social engineering attack websites posing as a trusted party and want to make the visitor believe that the web content is provided by the trusted party.

Warning

According to the Internet giant is going beyond traditional social engineering and phishing involves more instances of misleading web content. As an example, a website that uses the Google Chrome logo and offering a so-called update for the browser, or a page that occurs as Google support and the user requests a number to call. If Chrome detects such misleading websites let users now see a warning.

Friday, 13 November 2015

Google Closed Leak Of Information In PDF Reader Chrome


There is a new version of Google Chrome appeared where one vulnerability has been eliminated, as well as multiple vulnerabilities in embedded Flash Player. The vulnerability was an information leak in the PDF reader in Chrome. Besides Flash Player browser also has a built-in PDF reader.

Details on the vulnerability Google will not disclose if enough users have installed the new version. However, the leak has been labeled as 'high'. In this case, a malicious website could read confidential data from other websites or modify. The vulnerability was discovered by Rob Wu, who was awarded $ 4,000. It is also added the Flash Player to Chrome this week appeared. Update to Chrome 46.0.2490.86 happens on most systems automatically.

Thursday, 12 November 2015

Google Stops Support Chrome On XP And Vista In 2016


A little more than four months and then stop supporting Google Chrome on Windows XP, Vista and Mac OS X 10.6, 10.7 and 10.8, as Google has announced. The browser will still continue to work, but will not receive security updates and other fixes more.


The reason that Google discontinues the support is that the operating systems are no longer supported by Apple and Microsoft. Users of Windows XP, Vista and the older OS X versions get Google advised to upgrade to a newer operating system. According to the Internet giant walk unsupported platforms such as Windows XP, a greater risk of becoming infected by malware.

The Google story is remarkable. Support for Windows XP expired last April, but Vista until April 11, 2017 supported by Microsoft security updates, according to the Windows life cycle.

Wednesday, 4 November 2015

Google Chrome OS Will Not Phase Out


Google has no plans to phase out its own operating system Chrome OS, all went to recent reports in the media suggests otherwise. Sources left against the Wall Street Journal that the ultimate aim of Google Chrome OS and Android to combine a single platform.

Supporting and developing two different operating systems namely would be costly and confusing for manufacturers. Hiroshi Lockheimer, senior vice president of Android, Chrome OS and Chrome Cast, argues that Google is to combine "the best" of both operating systems, but there are no plans to phase out Chrome OS. Google has just plans to add new features to Chrome OS as a new media player, a visual refresh, improved performance and security. In addition, there will be next year dozens of new Chromebooks, said Lockheimer.

Sunday, 1 November 2015

Researcher Demonstrates Cheap Disposable Laptop


According to researcher Georg Wicherski has physical access to laptops and other devices at the border or in hotel rooms always been a way for intelligence services to gather information. With the introduction of full disk encryption, it was necessary for the service to apply firmware and hardware implants and to gain access.

The answer to this was the use of disposable data without hardware. Eg laptops that could be thrown away after the trip."Unfortunately, not everyone is a target which is a director and the budget for each trip to buy a new laptop," said Wicherski.The researcher works for security firm Crowd Strike and is co-author of the Android Hacker's Handbook.

Chromebook

This week demonstrated it at a conference in Finland solution, namely an inexpensive disposable laptop based on a Chromebook. Across Vice Magazine Wicherski says that he deliberately chose a Chromebook because they are relatively inexpensive. They are also compatible with Core Boot, opensource firmware. This gives the user more control over the booting process of the laptop, and can thus check that during charging no malware is active.

Every Chromebook itself better protect against attacks can be a pin of the SPI flash memory is removed, the chip containing the BIOS. By removing the pin, the chip 'read-only' and put an attacker can not easily make adjustments. "By using Core Boot, that really the first that runs on your processor, and then as slowly as possible to take control, then for every subsequent step to use cryptographic signatures, it becomes much harder for an implant develop."

Regarding ChromeOS that by default on the Chromebook runs chooses Wicherski sure to replace it by Arch Linux. Due to the tinkering and the required knowledge of the boot process to be disposable laptop is not suitable for everyone, give the researcher. It is also not a panacea. "It only protects against software and firmware implants that are added to the border, and it prevents some hardware implants." Yet users still need to encrypt their communications, otherwise they are vulnerable to software attacks, Wicherski decision.

IBM: Businesses Need Flash Apps Replaced By HTML5


Companies that offer Flash applications are wise to that HTML5 to convert, since the call for an internet browser without plug-ins is getting stronger, says David Strom IBM. Strom pointing to newer versions of Chrome and Firefox that no longer support the old NPAPI plug-sustaining nature. The main reasons for this are security and performance issues.

Recently, Mozilla announced that it is supporting the Java browser plug-in will cease altogether. However, there is a plug-in that is still supported, and that's Adobe Flash Player. Increasingly parties, however, are calling for an alternative, so that Internet users do not need more plug-ins to view online content or use. So pleaded Facebook CSO Alex Stamos before the end of the Flash technology.

According to Strom, this is not a new trend, since the appearance of the first Apple iPad without Flash support organizations have attempted to create websites with HTML5, the intended successor of Flash. This year, however, HTML5 can make its breakthrough, according to security evangelist at IBM. He argues that the time has come for organizations and companies for their Flash based apps to HTML5 to convert.

Friday, 30 October 2015

Copy-Pasting Google URL May Leak Past Searches


Who shares with Google search queries run the risk of seeing others get past searches. It discovered Jeremy Rubin. The problem is to reproduce in a few simple steps. As a first example, there must in Chrome or Firefox in the search bar something to be sought.

Then must make the Google search page to be searched for something else. The URL in the address bar will now include both searches. Users who do not see and pass the URL of their search so others can share unintentionally sensitive searches, says Rubin. He warned Google, but the Internet giant announced that it will not solve the problem.

Thursday, 22 October 2015

Google Gives More Details About Dangerous Blocked Sites


Every day protects via Google's Safe Browsing technology 1.1 billion people from dangerous Web sites, for example, want to install malware. Through Safe Browsing be users of both Google Chrome and Firefox and Safari warned of malware and phishing sites.

According to Google, the user is not always clear why a website is blocked. Therefore, the Internet giant has now added a special feature to the online Transparency Report which additional details can be retrieved. Through "Site Status" users can see exactly why a site is blocked by Google, such as website visitors to a malicious website which sends attempts to install malware or that forwarding dangerous websites visitors to the website visited.

Tuesday, 20 October 2015

Nearly One Million Websites With "Unsafe" SHA-1 Algorithm


Recently demonstrated researchers that it is much cheaper to attack SSL certificates with the SHA-1 algorithm than previously thought. The Centre for Mathematics and Computer Science (CWI) in Amsterdam pleaded therefore for the SHA-1 algorithm rather to phase out.

Google Chrome sees SSL certificates with the SHA-1 algorithm already unsafe. Research by internet company Netcraft shows that there are still nearly one million SSL certificates with this sensitive algorithm in use. The number of certificates is expected to decline from 2016. The CA / Browser Forum, a consortium of certificate authorities, the parties who issue SSL certificates, then do not allow new certificates with the SHA-1 algorithm.

Although SHA-1 by Google Chrome is now as weak or insecure is seen this year still spent more than 120,000 SHA-1 certificates. Some of these certificates are valid until 2020, but will need to be replaced sooner. From 2017 all browsers will display these certificates namely unsafe.

Monday, 19 October 2015

Microsoft Promotes Edge In Windows 10 To Adjust Browser


Windows 10 users that in the future the default browser will be able to customize Microsoft's request to Edge and try not to move. Even when adjusting the default music and photo app praises Microsoft's own apps.

According to a new Preview Build of Windows 10. WinBeta discovered the changes in the test version of the operating system. This is still an adjustment in a Preview Build of Windows 10, but Microsoft often conducts these adjustments in the final version of the OS.

For the launch of Windows 10 had notably Mozilla criticized the policies of the software giant. When upgrading from Windows 7 or 8.1, the browser is set previously been replaced by Microsoft Edge, which is the default browser in Windows 10. Figures show that many users after the upgrade, change the default browser, making Chrome become by far the most popular browser for Windows 10 users.

Friday, 16 October 2015

South Korea Seems To Wrest IE And ActiveX


By a legal obligation from the end of the last century, most South Koreans still use Internet Explorer, but the country seems slowly to Microsoft's browser and ActiveX technology to emerge. This week launched the Korea Trade Network (KTN), part of the Korea International Trade Organization, new authentication services in addition to IE also work in other browsers.

The KTN late announcement specifically that the new services are free and ActiveX standard Microsoft Edge, Chrome and Firefox work. ActiveX is an extension dating from 1996 model, making it possible to add extensions to Internet Explorer.Decided because of all kinds of stability and security vulnerabilities in Microsoft ActiveX Edge no longer support.

In South Korea ActiveX still plays an important role. To encourage online shopping and Internet banking and fears about insecurity to take away the Internet, the South Korean government developed its own system to authenticate the identity of online buyers. To order online buyers had their name and Social Security number to apply for a digital certificate from the government. This certificate could show people as a kind of identity card to the retailer. The whole process was designed so that it occupied just a few clicks.

The technology for these online identity was based on Microsoft's ActiveX technology, which works only in Internet Explorer. When the system was introduced in 1999, the South Korean government stated that it was mandatory for online purchases above 210 euros. For smaller purchases by South Korean retailers, however, applies a similar certification system developed by webshops and credit card companies. However, the law does not apply to foreign retailers.

Many South Koreans also use IE. In recent years, received the browser, as ActiveX, having to make many security problems. Nevertheless, the browser according to StatCounter in South Korea still has a market share of 67.8%. The announcement of the KTN is also noteworthy. In August it was announced that the Korean financial authorities want the authentication certificates within two to three years phasing.

Thursday, 15 October 2015

Chrome Removes The Lock Icon For HTTPS Sites 'Flaws'


Google has made changes to Chrome making HTTPS sites with 'mistakes' have no more lock icon in the browser. This is to ensure that users can more clearly see if they can trust a website, as Google has announced.

By "mistakes" the Internet giant meant especially websites served over HTTPS, but still contain content that is loaded through the unencrypted HTTP. This is referred to as "mixed content". Previously gave Chrome web sites with mixed content via a separate icon again, namely a lock with a warning triangle. To ensure that users need to recognize fewer different icons Google has now removed this icon in Chrome 46.

In addition, removing the icon should encourage the owners of the websites to fully HTTPS steps. There are still sites where the ads or images are provided via HTTP. This poses a security risk. Therefore, these websites are displayed as if they are completely unencrypted. This allows Chrome has only three instead of four different icons in the address bar.

"We have to find a balance: where the security of the website is as accurate as possible, while users are not too many possible security levels and details are overwhelmed," said Chris Palmer of the Chrome Security Team. According to Palmer found that many users found the warning triangle confusing. Ultimately, Google Chrome only display two icons, one for safety and one for unsafe.

Saturday, 12 September 2015

Google Receives Complaints About 300.000 Injected Ads


Since the beginning of this year, Google has received more than 300,000 complaints of Chrome users on injected ads. It is the largest source of annoyance for Chrome users. The injected ads come from so-called "ad injectors".

This relates to adware or browser extensions that inject additional ads on random websites or replace existing ads. According to Google ad injectors are a problem for advertisers and websites. Advertisers do not know that their ads be injected and so have no idea where their ads are displayed. Websites are not, however, paid for these ads because they are injected locally on the users' computers. The content sometimes dubious, it may involve malware, making the injected ads are a risk to visitors. This is negative for the image of the website, which can do nothing to the injected ads.

Filter

To have to tackle Google ad injectors for several measures taken. Since July, the Internet giant has also begun to filter injected ads of its own advertising platform DoubleClick. Google allows advertisers DoubleClick Bid Manager, which can be bid on ad space. To prevent injected advertisers buy ad space, there is now an automatic filter active.

This new system will detect injected ads and proactively establishes a blacklist that prevents advertisers to bid on ad space injected. Google expects that this measure will not immediately solve the problem, but it hopes that other parties in the advertising industry will take action against ad injectors. "Progress can be achieved only if we work together," said Vegard Johnsen, product manager of Google Ads.

Tuesday, 8 September 2015

Security Experts Swear By 20-Year-Old Mail Client Mutt


Regular Internet users are advised to use the latest software, but in the case of e-mail clients swear some security experts at the 20-year-old Mutt. Mutt is a small text-based mail client for Unix systems.The latest stable release dated June 9, 2007, although there last week released a new preview version.

Mutt is characterized by its simplicity. The software does not support HTML or emails with JavaScript. It is also for this reason that security for Mutt choose. "Simplicity is security," says Marek Tuszynski of the Tactical Technology Collective in front of Vice Magazine. Tools that run from the command line are characterized by a simpler design, fewer lines of code and the absence of vulnerable code such as Java or Flash. Therefore these types of programs will generally contain fewer bugs and be more stable.

Security researcher Christopher Soghoian says that he does not want his email client also contains the rendering engine of a web browser or JavaScript can handle. "The smaller the attack surface, the better," he tells. Mutt consists of "only" 100,000 lines code. Much less than the 14 million lines of Firefox and the 17.4 million of Chromium, the open source browser, which is the basis for Google Chrome. Due to the spartan look and feel is to use command line tools like Mutt mostly limited to technical users, even if they offer more safety than the programs in which the masses participate.

Monday, 7 September 2015

Microsoft Discourages Firefox And Chrome At Bing Users


Microsoft uses its own Bing search engine to prevent Internet users use Google Chrome or Mozilla Firefox. Who through Bing for 'firefox' or 'chrome' is looking for gets a big black bar on the screen stating that Microsoft Windows 10 recommends the use of Microsoft Edge.

This was discovered by VentureBeat. The bar also contains a button that a page opens with the advantages of Microsoft Edge. The page is available only for US users only, the message isn’t showing up in other countries.The black bar appears also to be shown once and does not appear in the search for 'opera'. Microsoft said in a statement that the notification is intended to give people information quickly and easily. In the past also Yahoo and Google to bring people in a similar way to have to adjust their browser or search engine.

Friday, 28 August 2015

Google Chrome Will Pause Flash Ads


From September 1, Google Chrome will automatically pause most Flash ads, so has Google via Google Plus disclosed. In June, Internet giant had already announced that it wanted to pause certain plug-ins, including Adobe Flash Player, in order to reduce power consumption and load times.

Google has long been trying to make Flash redundant. As YouTube videos are automatically played through HTML5. In the case of Flash ads that are distributed via AdWords, which are since February this year automatically converted to HTML5.Google argues that advertisers with Flash ads are working have several options to ensure that their ads are still shown to Chrome users, such as automatically to HTML5 to put out or to do it yourself.

Last month, also called Alex Stamos, the new Chief Security Officer (CSO) of Facebook, which with Adobe Flash technology to stop so completely on HTML5 can be switched. HTML5 is natively supported by modern browsers and allows playback of videos and other "rich content" without installing additional plug-ins.