Showing posts sorted by relevance for query google chrome. Sort by date Show all posts
Showing posts sorted by relevance for query google chrome. Sort by date Show all posts

05 August 2021

Coming soon: Google Chrome to no longer show secure website indicators

 

Google Chrome will no longer show whether a site you are visiting is secure and only show when you visit an insecure website.

For years, Google has been making a concerted effort to push websites into using HTTPS to provide a more secure browsing experience.

To further push web developers into only using HTTPS on their sites, Google introduced the protocol as a ranking factor. Those not hosting a secure site got a potentially minor hit in their Google search results rankings.

It has appeared to have worked as according to the 'HTTPS encryption on the web' of Google's Transparency Report, over 90% of all browser connections in Google Chrome currently use an HTTPS connection.

Currently, when you visit a secure site, Google Chrome will display a little locked icon indicating that your communication with the site is encrypted, as shown below:


As most website communication is now secure, Google is testing a new feature that removes the lock icon for secure sites. This feature is available to test in Chrome 93 Beta, and Chrome 94 Canary builds by enabling the 'Omnibox Updated connection security indicators' flag. With this feature enabled, Google Chrome will only display security indicators when the site is not secure.

www.bleepingcomputer.com


06 May 2026

Google Chrome silently installs a 4 GB AI model on your device without consent

 

Alexander Hanff Writes: Google Chrome silently installs a 4 GB AI model on your device! Two weeks ago I wrote about Anthropic silently registering a Native Messaging bridge in seven Chromium-based browsers on every machine where Claude Desktop was installed. The pattern was: install on user launch of product A, write configuration into the user's installs of products B, C, D, E, F, G, H without asking. Reach across vendor trust boundaries. No consent dialog. No opt-out UI. Re-installs itself if the user removes it manually, every time Claude Desktop is launched.

This week I discovered the same pattern, executed by Google. Google Chrome is reaching into users' machines and writing a 4 GB on-device AI model file to disk without asking. The file is named weights.bin. It lives in OptGuideOnDeviceModel. It is the weights for Gemini Nano, Google's on-device LLM. Chrome did not ask. Chrome does not surface it. If the user deletes it, Chrome re-downloads it.

The legal analysis is the same one I gave for the Anthropic case. The environmental analysis is new. At Chrome's scale, the climate bill for one model push, paid in atmospheric CO2 by the entire planet, is between six thousand and sixty thousand tonnes of CO2-equivalent emissions, depending on how many devices receive the push. That is the environmental cost of one company unilaterally deciding that two billion peoples' default browser will mass-distribute a 4 GB binary they did not request.

Wow! Remember when the Internet blew up because Apple automatically downloaded a free U2 Album? I actually bought that album "Songs of Innocence" It's great - I'm listening to it now! It was a tiny download - which if you weren't a fan could simply delete. Still, loads of folks got in a mighty strop about that. ^^^ THIS is a big deal!!! Not cool Google, not cool! I'm waiting to see who is going to get their knickers in a knot over this huge download - which will affect most folks who have Google Chrome installed...

www.thatprivacyguy.com


28 May 2020

Threats to the security of Google Chrome - propagated by Google's own Web Store!


Efforts to manipulate installation counts in Chrome Web Store extension listings appear to be alive and well, despite a developer's personal crusade to call attention to the problem.

Julio Marin Torres has been highlighting suspiciously popular Chrome extensions since January in posts to the Chromium Extensions forum, trying to get Googler to enforce their store policies.

In an email to The Register, he said Google has taken some action since his initial posts on the subject, but the problem has only gotten worse since then. "Something has to change," he said. "I think this hurts the entire Chrome Store developer and user community."

There are still thousands of extensions in the Chrome Web Store that artificially inflate their user count statistics, to make store visitors more inclined to believe the extensions are widely used and trustworthy.

Google Chrome is a great Web browser, but there are a number of vectors out there that can turn chrome from a great tool, into a misery! Extensions & Notifications are the biggest threats that I have to deal with on behalf of my clients. Have problems with Chrome? Contact Donline.


23 August 2023

Google Chrome to warn when installed extensions are malware

Google is testing a new feature in the Chrome browser that will warn users when an installed extension has been removed from the Chrome Web Store, usually indicative of it being malwareAn unending supply of unwanted browser extensions is published on the Chrome Web Store and promoted through popup and redirect ads.

These extensions are made by scam companies and threat actors who use them to inject advertisements, track your search history, redirect you to affiliate pages, or in more severe cases, steal your Gmail emails and Facebook accounts.

The problem is that these extensions are churned out quickly, with the developers releasing new ones just as Google removes old ones from the Chrome Web Store.

Unfortunately, if you installed one of these extensions, they will still be installed in your browser, even after Google detects them as malware and removes them from the store.

Due to this, Google is now bringing its Safety Check feature to browser extensions, warning Chrome users when an extension has been detected as malware or removed from the store and that they should be uninstalled from the browser. This feature will go live in Chrome 117.

www.bleepingcomputer.com


17 October 2018

What's new in Google Chrome v70?


Google have launched Chrome 70 for Windows, Mac, and Linux

The release includes an option to disable linking Google site and Chrome sign-ins, Progressive Web Apps on Windows, the ability for users to restrict extensions’ access to a custom list of sites, an AV1 decoder, and plenty more. You can update to the latest version now using Chrome’s built-in updater or download it directly from google.com/chrome.

With over 1 billion users, Chrome is both a browser and a major platform that web developers must consider. In fact, with Chrome’s regular additions and changes, developers often must make an effort to stay on top of everything available — as well as what has been deprecated or removed.


06 September 2016

Google Chrome for Windows gets a battery performance boost



Google responds to Microsoft criticism that Chrome is a battery hog by introducing new power consumption enhancements.

Back in June, Microsoft hit out against Google by publishing test results which claimed that its Edge browser had the edge over Chrome when it came to power-saving on portable systems. Google has now responded by introducing new power consumption enhancements to the Windows version of its browser.



20 April 2018

Microsoft Ports Anti-Phishing Technology to Google Chrome Extension


Microsoft has released a Chrome extension named "Windows Defender Browser Protection" that ports Windows Defender's —and inherently Edge's— anti-phishing technology to Google Chrome.

The extension works by showing bright red-colored pages whenever users are tricked into accessing malicious links.

The warnings are similar to the ones that Chrome natively shows via the Safe Browsing API, but are powered by Microsoft's database of malicious links —also known as the SmartScreen API.

An NSS Labs benchmark revealed that Edge (with its SmartScreen API) caught 99 percent of all phishing URLs thrown at it during a test last year, while Chrome only detected 87 percent of the malicious links users accessed.

To download the Chrome extension (browser plugin), click here.


19 November 2024

Google is (finally) turning Chrome OS into Android to compete with the iPad

Google is a massive tech company with nearly two hundred thousand employees, so it definitely has the manpower and resources to develop two different operating systems in Android and Chrome OS. While both Android and Chrome OS have seen huge success in different markets, they’ve struggled to compete in one product category where they overlap: tablets. The high-end tablet market is dominated by the Apple iPad, and no matter what Google has tried, it has failed to change that. However, a source tells Android Authority that Google is working on a multi-year project to fully turn Chrome OS into Android, and the end result could be a platform that finally bests the iPad.

Android as an operating system is designed for smartphones, tablets, smartwatches, TVs, cars, and soon XR glasses, whereas Chrome OS is primarily designed for laptops. While the term Chromebooks encompasses tablets as well, it’s fair to say that Chrome OS isn’t as suited for tablet use as Android is, at least when it comes to media consumption. On the flip side, it’s also a fair assessment that Android isn’t as suited for tablet use as Chrome OS is, at least when it comes to productivity. Google has tried to add features to both operating systems to bridge that gap, but even after a bit of convergence, neither platform managed to really eat Apple’s lunch.

www.androidauthority.com


25 July 2022

Google Chrome security update fixes 'high risk' flaws

 

Google has released security updates for Google Chrome browser (updated to 103.0.5060.134) for Windows, Mac and Linux, addressing vulnerabilities that could allow a remote attacker to take control of systems. 

There are 11 fixes in total, including five that are classed as high-severity. As a result, CISA has issued an alert encouraging IT administrators and regular users to install the updates as soon as possible to ensure their systems are not vulnerable to the flaws. 

Among the most severe vulnerabilities that are patched by the Google Chrome update is CVE-2022-2477, a vulnerability caused by a use-after-free flaw in Guest View, which could allow a remote attacker to execute arbitrary code on systems or crash them. 

www.zdnet.com


07 July 2017

Padlock in the address bar is a good thing right? Not necessarily so...


Article 1 from The Register

Let's Encrypt plans to begin offering free wildcard certificates in January 2018, a move likely to make web security easier and a bit less costly for many organizations.

Announced in 2014 as an effort to enhance and accelerate online security, the public benefit certificate authority (CA) has been issuing free X.509 (TLS/SSL) certificates through an automated process that allows websites, given the technical requirements, to be accessed over encrypted HTTPS rather than the unprotected HTTP.

So: every site (including potentially scammers & crooks) can have a digital certificate: a padlock in the right hand side of the address bar.

Article 2 from the Google Chrome Help Forum:

QUESTION: When browsing to a secure site, I used to be able to click to the left of the URL where it shows the padlock and Secure icon and click 'details' which would bring a popout from the right side of my browser to view the certificate details.

Today it no longer provides this option and only says I'm on a secure connection and the only option is to select 'Learn More' which brings me to a page explaining the differences between Secure, Not Secure, etc.

ANSWER: To review the website's security certificate details, use: top-right Chrome Menu/three vertical dots ( ⋮ ) > More tools > Developer tools - Security panel  ( keyboard shortcut  Ctrl+Shift+I  or  F12 )

Now this has been bugging me for ages! I'm a big Google Evangelist, and don't moan about them often, but I have to criticise Google for this. Hiding this functionality away from users really doesn't help.

If you are using Google Chrome, on an HTTPS site, & would like to check who the CA (certificate authority) is: press the F12 button on your keyboard & a panel will appear in the right hand side of your browser window "Security Overview". 
Press the "View Certificate" button, to see who the CA is & then you can make a more informed decision as to  whether or not you TRUST the website.


UPDATE: Apparently this will be fixed (restored!) in Chrome v60. We are currently in v59, so coming soon folks! Stay safe out there!

17 October 2017

A cleaner, safer web with Google Chrome


Unwanted software impacts the browsing experience of millions of web users every day. Effects of this harmful software are often quite subtle—search results are modified to redirect users to other pages or additional ads are injected in the pages that users visit. But in some cases, the changes are so severe that they can make the web unusable—people are redirected to unwanted sites full of ads, and it can be next to impossible to navigate away from these pages.

Chrome already has tools to help people avoid unwanted software. For example, Safe Browsing prevents many infections from taking place by warning millions of users. But sometimes harmful software slips through.

Recently, we rolled out three changes to help Chrome for Windows users recover from unwanted software infections: Hijacked settings detection, a simpler Chrome Cleanup, & a more powerful Cleanup engine. 

We’ve begun to roll this out to Chrome for Windows users now. Over the next few days, it will help tens of millions of Chrome users get back to a cleaner, safer web.

 Donline has recommended Chrome for many years: as the go-to web browser for all. It's web standards compliant, fast & secure. Get it & enjoy the web as it's meant to be!


29 December 2019

Avast and AVG extensions pulled from Chrome - criticised for excessive data collection


Google Chrome is the latest browser to drop AVG and Avast extensions after reports of excessive data snooping.

Back in October, a blog post from Wladimir Palant, founder and CTO at AdBlock Plus, highlighted that browser extensions created by the two security firms were hoovering up more data than necessary to function, especially versus rivals such as Google Safe Browsing. That data, according to the post, included user ID, where you're located, and how you got to a specific page.

After that report, Mozilla and Opera both pulled the AVG and Avast extensions, though the former reinstated one set of add-ons after changes to data collection were made. Google has now reportedly also followed that lead, removing the questionable extensions.

"I didn't expect to publish this update any more, but Avast extensions are now gone from Chrome Web Store as well," Palant tweeted. "Only AVG Online Security remains for some reason. Way to go Google!" The latter has 3,582 users, according to the Google Web Store.

Avast, which bought AVG in 2016, had not replied to a request for comment at the time of publishing.


09 February 2018

From July, Google Chrome will name and shame "insecure" HTTP websites. Oh dear: read in conjunction with yesterday's post...


Three years ago, Google's search engine began favoring in its results websites that use encrypted HTTPS connections.

Sites that secure their content get a boost over websites that used plain-old boring insecure HTTP. In a "carrot and stick" model, that's the carrot: rewarding security with greater search visibility.

Later this year comes the stick. This summer, Google will mark non-HTTPS websites as insecure in its Chrome browser, fulfilling a plan rolled out in September 2016.

Starting with Chrome 68, due to hit the stable distribution channel on July 2018, visiting a website using an HTTP connection will prompt the message "Not secure" in the browser's omnibox – the display and input field that accepts both URLs and search queries.

Well that's just great: Google will stop trusting Symantec-issued SSL/TLS certs from this year. One option would be to drop the certificate - going from HTTPS back to good old HTTP. Unfortunately this will now flag that website as insecure! Good job Google - you can go off people, you know...


25 October 2022

Still using Windows 7, 8 or 8.1? Here's another reason to move to Win 10

With the release of Google Chrome 110 (tentatively scheduled for February 7th, 2023), Google will officially end support for Windows 7 and Windows 8.1. You’ll need to ensure your device is running Windows 10 or later to continue receiving future Chrome releases. This matches Microsoft's end of support for Windows 7 ESU and Windows 8.1 extended support on January 10th, 2023.

Older versions of Chrome will continue to work, but there will be no further updates released for users on these operating systems. If you are currently on Windows 7 or Windows 8.1, we encourage you to move to a supported Windows version before that date to ensure you continue to receive the latest security updates and Chrome features.

support.google.com


27 February 2017

Chrome malware masquerades as "missing font" files


New hack tricks users into downloading missing fonts loaded with malicious files
A security researcher has discovered a new hacking tactic on Google Chrome that manipulates websites into displaying missing font prompts, which then trick users into downloading malicious files.

The infection was first spotted on an unnamed WordPress website by Mahmoud Al-Qudsi, a researcher at cybersecurity firm NeoSmart Technologies, who detailed the process in a blog post.

The attack involves a hacker exploiting JavaScript to alter the rendering of content on a webpage, causing it to resemble mis-encoded text which appears as a jumble of symbols and shapes. The code then prompts the user to download the missing fonts through a Chrome language pack to decipher the text.

Clicking "Update" results in a file called "Chrome Font v7.5.1.exe" being downloaded and a second prompt encourages the user to run the file, all the while appearing as a perfectly safe Chrome download.

The attack is particularly well disguised and makes every attempt to appear a legitimate Chrome pop up, including the correct text formatting and right use of colours for the "Update" button.


24 July 2018

Google Chrome v68 users met with ‘Not secure’ warnings when visiting HTTP sites


If you’re still running a website that is using insecure HTTP then it’s probably too late. Some of your website’s visitors are going to be greeted with a message that tells them that they can’t trust your website to be secure.

That’s the message they’re going to get from Google Chrome which - in version 68 released on Tuesday 24 July 2018 - is changing its behaviour, and will start labelling all sites that continue to use unencrypted HTTP as “not secure”.

And as Chrome is the world’s most widely-used browser, that’s an awful lot of visitors who might feel unsettled visiting your website from Tuesday.


21 December 2018

If you still use Internet Explorer (really / why?) time to patch urgently, or better still: move to Google Chrome!


Microsoft has released an out-of-band (emergency) security update that fixes an actively exploited vulnerability in Internet Explorer.  This vulnerability has been assigned ID CVE-2018-8653 and was discovered by Google’s Threat Analysis Group when they saw the vulnerability being used in targeted attacks.

According to Microsoft's security bulletin this is vulnerability in how the Internet Explorer scripting engine handles objects in memory.  Attackers can use this vulnerability to corrupt memory in such a way that attackers could execute code under the security privileges of the logged in user.

Go to Windows Update: download the update & patch ASAP! BTW: don't use IE - use a modern safe Web Browser, like Google Chrome.


02 July 2018

Google shaming HTTP websites in Chrome - a lousy idea...


From Slashdot: Long-time software guru Dave Winer is criticizing Google's plans to deprecate HTTP (by, for example, penalizing sites that use HTTP instead of HTTPS in search results and flagging them as "insecure" in Chrome). 

Winer writes: A lot of the web consists of archives. Files put in places that no one maintains. They just work. There's no one there to do the work that Google wants all sites to do. And some people have large numbers of domains and sub-domains hosted on all kinds of software Google never thought about. Places where the work required to convert wouldn't be justified by the possible benefit. The reason there's so much diversity is that the web is an open thing, it was never owned....

If Google succeeds, it will make a lot of the web's history inaccessible. People put stuff on the web precisely so it would be preserved over time. That's why it's important that no one has the power to change what the web is. It's like a massive book burning, at a much bigger scale than ever done before.

"Many of these sites don't collect user data or provide user interaction," adds Slashdot reader saccade.com, "so the 'risks' of not using HTTPS are irrelevant." And Winer summarizes his position in three points:
The web is an open platform, not a corporate platform.
It is defined by its stability. 25-plus years and it's still going strong.
Google is a guest on the web, as we all are. Guests don't make the rules.

"The web is a social agreement not to break things," Winer writes. "It's served us for 25 years. I don't want to give it up because a bunch of nerds at Google think they know best."

HTTPS is great - it secures your connection to a web server: perfect for ecommerce, banking, data transfers, etc. HOWEVER: if a website is just supplying simple information, and there is no requirement for the visitor to input personal data or payment information - then what is the point of HTTPS?


25 January 2018

Google Chrome v64 kills pop-ups and redirects - available now!


Android is getting priority treatment again from Chrome as the stable version of Chrome 64 rolls out here ahead of Mac, Windows and Linux for the second release in a row. The version includes the usual bug fixes, plus a host of features designed to make browsing safer and easier. Malicious auto-redirects are out, with the browser blocking third-party iframes unless you've directly interacted with them, and an improved pop-up blocker will stop shady sites from opening new tabs or windows from accidentally-clicked play buttons and transparent overlays.

The release also brings site-wide audio muting, which should help put an end to frantic searching among tabs to quieten noisy pages. The addition is part of Google's drive for more streamlined media autoplay behavior, and can be activated from a new sound menu, accessed via Settings > Site settings. Android users can get Chrome 64 from the Play Store over the coming weeks.


21 April 2021

Google Chrome is under Zero-Day attack - make sure you are patched up to date!


Google late Tuesday shipped another urgent security patch for its dominant Chrome browser and warned that attackers are exploiting one of the zero-days in active attacks.

This is the fourth in-the-wild Chrome zero-day discovered so far in 2021 and the continued absence any meaningful information about the attacks continue to raise eyebrows among security experts.

The newest Chrome update - 90.0.4430.85 - is available for Windows, Mac and Linux users and is being rolled out via the browser’s automatic update mechanism.

www.securityweek.com