Malicious code can wind up on your PC or phone by any number of roads. Companies do their best to guard the digital passes, but invariably, things get missed and the hackers find a way in. It’s a constant battle, and sadly, one that the good guys are losing.
Recently Google has stepped up its efforts, this time by focusing on Chrome browser extensions installed by third parties. By the end of the year, no extensions will be allowed on Chrome except for those acquired via the Web Store.
James Wagner, Google’s Product Manager for the Extensions Platform, had this to say on the topic:
“We continue to receive large volumes of complaints from users about unwanted extensions causing their Chrome experience to change unexpectedly – and the majority of these complaints are attributed to confusing or deceptive uses of inline installation on websites.”
It’s a thorny problem, but industry experts broadly agree that Google is taking the right approach here. Beginning in September, Google plans to disable the “inline installation” feature for all existing extensions. The user will instead be redirected to the Chrome Web Store where they’ll have the option to install the extension straight from the source.
Then, in December 2018, the company will remove the inline install API from Chrome 71, which should solve the problem decisively.
Of course, hackers being hackers will no doubt find a way around that, but kudos to Google for taking decisive action here. While browser extensions aren’t a major attack vector, it’s troublesome enough that Google’s attention is most welcome.
It should be noted that one of the indirect benefits of Google’s plan is that it further bolsters the importance of user ratings of extensions. They’re highly visible on the Web Store, so anyone who’s considering installing something has a good, “at-a-glance” way of telling whether the extension is good or a scam. That’s information they wouldn’t get had the extension been installed inline.
Again, kudos to Google!
President & CEO
I hope you enjoyed this article. My mission is to take your stress away from dealing with IT problems. Call (252) 565-1235 or send me a message at our contact us page if you have a question, comment or want help.
More bad news for Intel. Yet another security flaw has been identified in the processors the company makes. This one is so newly discovered that the full technical details have yet to be released. Here’s what we know so far, from a recent Intel announcement:
Change is coming, and not everyone is happy about it. Recently, Google redesigned its G-mail interface, and since then, they’ve allowed their free users to opt into the new changes. G-Suite users may or may not see the option to try the new interface, depending on whether their administrators have enabled the option and made it visible.
It’s the end of the line for Yahoo Messenger. As of July, it will be no more, marking the end of an era.
Facebook is in hot water again. Recently, the company admitted that while testing a new feature on the site, they inadvertently made public the posts of more than fourteen million users. The incident occurred between May 18th and May 22nd and occurred when Facebook was testing a new “Featured Posts” enhancement.
Another week, another new threat. This time, in the form of a new strain of malware that researchers are calling InvisiMole. The new threat was discovered by researchers at ESET, who found it on a number of hacked computers in Russia and the Ukraine.
Big changes are coming from Microsoft starting in July (exact date unknown), and it has potentially dire implications if you’re using some of the company’s older technology.
Cyber-criminals around the world are increasingly focusing their attention on job seekers. According to the security firm Flashpoint, there has been a notable uptick in ploys involving phony job listings that attempt to get job seekers to give up personal information.
Another week, another high-profile data breach, but this one can be filed under “Missed Opportunity.” The site in question is “TicketFly,” which is a web-based event ticket sales website owned by a company called Eventbrite. The TicketFly website was down since May 31st, and the normal homepage had been replaced by an image of Guy Fawkes with the message “Your Security Down I’m Not Sorry.”
A new study recently published by HPE Aruba called “The Right Technologies Unlock The Potential Of The Digital Workplace,” reveals some interesting details about technology in the workplace that’s worth paying attention to.