Showing posts with label chromium. Show all posts
Showing posts with label chromium. Show all posts

Sunday, 8 November 2015

Rediscovered Adware That Replaces Full Browser


Warning for the second time in a short time researchers for browsers that have the display of advertisements as target and all installed browsers trying to replace. It involves two browsers called eFast and Cross Browser, which both are based on Chromium.

Chromium is an open source web browser developed by Google that is the basis for Google Chrome. Other parties can use Chromium as the basis for their browser, such as Comodo Dragon, Vivaldi, SRWare Iron and Opera. Also dubious parties seem now to deal with Chromium. Instead of infecting existing browsers with adware is chosen to develop its own browser that displays ads and replaces the existing browser. Once the browser is started and ads appear dubious domains are loaded.

Browse Cross is part of a notorious adware family called Cross Rider. Initially it went to "browser hijackers' and adware were only existing browsers hijacked. According to anti-malware company Malwarebytes does so still, but there is now also a fully functional browser appeared. Once active remove both cross Browse eFast as shortcuts to the default browser on the desktop, start menu and taskbar, and then add a shortcut to the native browser.

The rogue browsers via 'wrappers and bundled software distributed. A wrapper is an installer that besides a certain program can also install other software.

Thursday, 22 October 2015

Google Replaces OpenSSL By BoringSSL



Google recently decided in a wide range of products, including Chromium, M Android and Google's own production services, OpenSSL replace BoringSSL. OpenSSL is software that is used for setting up secure connections.

Google uses OpenSSL in their own software, but often in combination with specific patches. Some of these patches are approved by the OpenSSL developers, but many do not because they do not meet the stability guarantees of OpenSSL and are experimental. This created an awkward situation when Google decided to create an offshoot of OpenSSL called BoringSSL.

"For the first time, sharing many of Google's products a single TLS stack," says Google engineer Adam Langley. That makes it easy to make adjustments. Which previously could cost days. Google is now used in many places BoringSSL does not mean that everyone must OpenSSL dump and must change the demerger of Google, says Langley.

Modifications

The changes that Google has made, and especially the removal of code and components, ensuring that many programs on Linux no longer work as a Linux user OpenSSL replaces BoringSSL. The OpenSSL version where Google started it consisted of 468 000 lines of code. After removing all kinds of parts remained about 200,000 lines. Since BoringSSL not only used within Google, but also by third-party developers of Chromium and Android, Langley has now published a document on the changes to the demerger.

Tuesday, 17 February 2015

Microsoft Gives Details On HSTS Security In IE


Last month it was announced that Microsoft finally HTTP Strict Transport Security (HSTS) is added to Internet Explorer, which users must protect against man-in-the-middle attacks. Now the software giant has more details given about the security measure.

HSTS allows websites visited to visit over HTTPS only over HTTPS, even though HTTP is introduced into the address bar.The browser in this case captures the user's command and turns off automatically in HTTPS. Thus, no information is transmitted over unsecured HTTP there. HSTS websites offers two options to secure their connections with visitors.

The first option is to register the website on a table loaded by Internet Explorer and other browsers with HTTP traffic directly to HTTPS is put through. This makes IE using the Chromium HSTS list. Chromium is the open source browser on which Google Chrome is based. The second option is to offer a HSTS header. In this case, the browser after having visited the site for the first time over HTTPS, all future HTTP connections run over HTTPS.

Microsoft warns that HSTS can have two important effects on users. If there namely a certificate warning is displayed, the user can not ignore and must disconnect. Additionally supported by HSTS sites no mixed content. All content should be delivered over HTTPS. This can be a problem for websites where for example ads and images are loaded over HTTP. The HSTS-feature is already testing the Windows 10 Technical Preview and will later be added to the Project Spartan browser of the new OS.

Monday, 24 March 2014

White Hat Security company launches "secure browser" on Internet


An American security company claims to have the "most secure browser" launched on the Internet that users must protect. Against both malware and parties who want to violate the privacy Aviator, such as the browser is called, was published last year, the Mac version and now there is also a Windows version.

Aviator has been developed by white hat security and based on Chromium, the open-source browser that is used. Google Chrome The reason it was chosen Chromium is that it has several unique security features, such as a sandbox. White Hat found that Chromium is not safe enough and made ​​an adapted version with more security and privacy settings.

"Google and Microsoft make a lot of money on online ads. Unfortunately, very intrusive online advertising, because you basically follow anywhere on the Internet. Even Mozilla receives most of the revenue through advertisements. Implementing truly effective security and privacy could adversely for their business operations, " said the security company

For example, the default search engine DuckDuckGo instead of Google and integrates the browser Disconnect. An extension that ads and tracking on the Internet blocking. In addition, the browsing history, cache, cookies, auto-complete, and local storage after restarting the browser removed. Standard third party cookies are blocked, plug-ins require an additional mouse to work state Do-Not-Track is enabled by default and minimum data is sent to Google.

Earnings
Although there is little advertising for the Mac version was made, was downloaded thousands of times in recent months. The browser is free to download, but still is underway on a revenue model, allows product management director Robert Hansen know . He gives the guarantee that no money will be earned on the information provided by users, as do many other browsers.
Current users of the browser, however, would be no need to worry, because the browser can always use for free. "Once we have determined how we can make money on new users will only have to pay for a license." In the future, other operating systems are supported. Alongside Mac and Windows