Seven More Chrome Extensions Compromised

Discussion in 'other security issues & news' started by itman, Aug 15, 2017.

  1. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    https://threatpost.com/seven-more-chrome-extensions-compromised/127458/
     
  2. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    This is getting silly, now you can't even trust extensions anymore? I wonder what browser makers will do about this, since we can't count on extension developers to keep people safe.
     
  3. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
  4. guest

    guest Guest

    Phishing campaign targets developers of Chrome extensions
    October 1, 2018
    https://www.zdnet.com/article/phishing-campaign-targets-developers-of-chrome-extensions/
     
  5. guest

    guest Guest

    dev doesn't mean security expert, even those making security softs LOL
     
  6. cruelsister

    cruelsister Registered Member

    Joined:
    Nov 6, 2007
    Posts:
    1,649
    Location:
    Paris
    You should have NEVER trusted extensions.
     
  7. Socio

    Socio Registered Member

    Joined:
    Jun 29, 2004
    Posts:
    362
    Take ones that are most needed/wanted for security, privacy, spell checking etc... and build them into the browser this way the browser developer controls and updates them like in Brave Browser.
     
  8. 142395

    142395 Guest

    Indeed, especially when it comes to crypto. Everytime security researchers inspect AV's SSL filtering, they find problems (one of them). So it's no wonder that while many IS/TS started to incorporate VPN & pwdmgr there're many security problems (using known IPSec key, leaking IP, not using uniform CRNG, and more serious vuln such as TrendMicro & Kaspersky).
    It seems only sure way to be relatively secure is to install as fewer program (which you can trust to some extent) as possible, addon is no exception. Do not trust just because big company is in back.
     
  9. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    Exactly, it's a good idea. Another possibility is to put more restrictions on extensions.

    Actually, you don't have a choice if they offer functionality that you really need. I think most people trust extensions like uBlock and Privacy Badger to name a few.
     
  10. cruelsister

    cruelsister Registered Member

    Joined:
    Nov 6, 2007
    Posts:
    1,649
    Location:
    Paris
    R- I didn't say never use them, just don't install any and all with blind trust. One would never consider this with applications, but far too many will do this with extensions.

    An extension that has been out for years THAT HAS THE SAME PUBLISHER will no doubt be fine; but a new extension or an existing one bought by someone else must be viewed with suspicion.

    M
     
  11. Bertazzoni

    Bertazzoni Registered Member

    Joined:
    Apr 13, 2018
    Posts:
    657
    Location:
    Milan, Italia
    And use only the minimum necessary. Only 1 for me!.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.