Welcome Guest ( Log In | Register )


This is NOT a Search Box
PRIVATE NOTICE FROM ladyhawk
--
bye hun
(Today, 12:38 PM) ladyhawk
--
bye hun
PRIVATE NOTICE FROM richmond
--
see you l8ter lh and all
(Today, 12:36 PM) richmond
--
see you l8ter lh and all
PRIVATE NOTICE FROM richmond
--
same here as am gona go shooting as well
(Today, 12:34 PM) richmond
--
same here as am gona go shooting as well
PRIVATE NOTICE FROM ladyhawk
--
its freezing i know i cant get a heat in me at all heating up full to
(Today, 12:33 PM) ladyhawk
--
its freezing i know i cant get a heat in me at all heating up full to
PRIVATE NOTICE FROM richmond
--
ok will do try and not flip it this time
(Today, 12:33 PM) richmond
--
ok will do try and not flip it this time
PRIVATE NOTICE FROM richmond
--
still cold tho
(Today, 12:33 PM) richmond
--
still cold tho
PRIVATE NOTICE FROM ladyhawk
--
be careful this time ok x
(Today, 12:32 PM) ladyhawk
--
be careful this time ok x
PRIVATE NOTICE FROM richmond
--
am just gona go out with quad to my m8s
(Today, 12:32 PM) richmond
--
am just gona go out with quad to my m8s
PRIVATE NOTICE FROM ladyhawk
--
and he was only 5 mins from the house to
(Today, 12:31 PM) ladyhawk
--
and he was only 5 mins from the house to
PRIVATE NOTICE FROM richmond
--
dam
(Today, 12:31 PM) richmond
--
dam
PRIVATE NOTICE FROM ladyhawk
--
40 mins in traffic another hour to get home
(Today, 12:30 PM) ladyhawk
--
40 mins in traffic another hour to get home
PRIVATE NOTICE FROM ladyhawk
--
hog was on his way home from work and was diverted via you know where cause someone was trying to jump of the bridge
(Today, 12:30 PM) ladyhawk
--
hog was on his way home from work and was diverted via you know where cause someone was trying to jump of the bridge
PRIVATE NOTICE FROM richmond
--
no what happend
(Today, 12:29 PM) richmond
--
no what happend
PRIVATE NOTICE FROM ladyhawk
--
did you hear what happened on the bridge last night
(Today, 12:28 PM) ladyhawk
--
did you hear what happened on the bridge last night
PRIVATE NOTICE FROM ladyhawk
--
hello
(Today, 12:27 PM) ladyhawk
--
hello
ShoutOut! © InvisionMint
Float shoutbox?

Chrome is a security nightmare,

This topic is about Chrome is a security nightmare,, the author, richmimi, wrote about: Can a browser’s search function work too well? After playing around with Google’s brand new Chrome browser, we’ve discovered that its history search ... To read more just scroll down

 
Reply to this topicStart new topic
> Chrome is a security nightmare,, indexes your bank accounts
richmimi
post Sep 4 2008, 05:15 PM
Post #1
Hexxagon Champion! Breakout Champion! Great Mahjong: Classic Champion! 501 Darts Champion! Galagon 2004 Champion! 9 Ball Pool Champion! Garage Door Tennis Champion! Blow Up: Arcade Champion! Prison Throw Champion! Homers Beer Run Champion! Poux Champion! Yeti Long Ass Shot 2 Champion! Yeti Sports 7 - Snowboard Freeride Champion! Extreme Pinball Champion!


Advanced Member
Group Icon

Group: Global Moderator
Received 616 Thanks
Posts: 2,521
Joined: 26-December 03
From: Wonderland
Member No.: 358





Can a browser’s search function work too well? After playing around with Google’s brand new Chrome browser, we’ve discovered that its history search box will fetch all types of data - even text from HTTPS-protected financial sites like Washington Mutual and Capital One. With a few utterly simple keywords like balance, account and Sept., everything from balance information, account numbers and even how much you spent at Costco can be pulled up.

To see all of this in action, just open up Chrome and log in to your favorite financial website. Like most important sites, it should be protected with HTTPS/SSL encryption and that should be evident in the address bar of the browser. Do the stuff you would normally do like look at your balances and gawk at your latest transactions and then open up a new tab in Chrome by clicking the “+” symbol. In the right-hand history search box, enter a few keywords and see what they get you. Surprised? I bet you are. No luck? Then try something simple like oh Visa, Mastercard, balance and account. Also try out the names and abbreviations of months like September, Sept and Sep.

If you’re like me, you probably saw account balances and some transaction details, but if you further refine your keywords you’d be able to see a lot more. We first discovered this “problem” by browsing the forensicfocus.com forums. “Problem” is in quotes because we’re not sure if this is a true vulnerability or Google Chrome’s search function working as intended – in this case, just too damn good. While playing around with the forensic implications of Chrome, “Jelle” on the forums posted that he and his partner noticed the browser was indexing information from HTTPS sites.

“One interesting finding is that in the regular browsing mode, Chrome creates a search index of the contents of a lot of the pages you visit. This allows you to do keyword searching in your own web history. On some of our tests, we found that content of https pages had been indexed as well, allowing us to retrieve our bank account details using a keyword search,” Jelle posted.

Of course after reading this I just had to give it a try and logged into my Washington Mutual and Capital One credit card accounts. I looked at my pathetically low bank account balances along with my insanely high outstanding credit card balances. Then I pulled up a recent list of transactions for the month (damn you gas prices) - on many financial websites this information is usually shown on the very first page after logging in. Then I opened up a new tab and started playing around with keywords.

Thinking like a hacker, my first plan of attack was to enumerate or list the financial services. After enumeration, I could drill down into the exact accounts and transactions. By simply typing in Visa, Mastercard, account and the names of popular banks you can find the types of accounts and which institution they belong to. In my case, Capital and Washington worked just fine. To get my account balance, I just typed in “balance” and to get transaction information I entered “transaction”. Typing in “costco” pulled up how much I spent on my last trip.

Is there a way to protect your financial information from being indexed? Google Chrome does have an incognito mode that promises to not cache anything. This can be accessed from the file menu in the upper-right corner of the window or by using the keyboard shortcut (Control Shift N). You can also clear your browser data after surfing to a financial website by going to the tools menu that’s also in the upper-right corner.

It was just yesterday that I wrote about Chrome’s security as being “not bad”, but I personally don’t get a warm and fuzzy feeling if Chrome is indexing all of my financial information. Search and indexing is what Google is good at and the company has made my life a whole lot easier in many ways, but indexing financial info is crossing the line.

On the programming level, I can’t really blame Google’s developers though because HTTPS was never meant to provide any protection anyways on the desktop itself. The protection was developed to protect traffic as it travelled through the “Wild West” Internet. But while this distinction is clear to most of our readers – the regular person probably believes HTTPS/SSL traffic is and should be protected on the desktop.

So is this all a big deal? Well anyone who wants to search your financial information would need local access to your machine and if a person is sitting at your computer, you have a lot more things to worry about than him/her using Chrome’s history search. Conceivably a hacker could develop an app to pull the cache and index files off your computer and examine them later on another machine – these files reside in the “C:\Documents and Settings\USERNAME\Local Settings\Application Data\Google\Chrome\User Data\Default” folder.

But on a simpler level, if ALL of the sites I visit are being keyworded and indexed locally, then how do I know that this information will stay local. I guess that depends on how much you trust Google.

Source.
Go to the top of the page
 
+
sg1efc
post Sep 8 2008, 06:03 AM
Post #2
Advanced Member
Group Icon

Group: Contributor
Received 13 Thanks
Posts: 277
Joined: 29-September 03
Member No.: 19,013





Wholly cow!!!! ohmy.gif That is simply Not funny. sad.gif

Awesome post, Thanks a lot! smile.gif
Go to the top of the page
 
+
arrgh
post Sep 8 2008, 11:42 PM
Post #3


Not bovvered!
Group Icon

Group: sVIP
Received 81 Thanks
Posts: 4,181
Joined: 28-December 03
From: Fraser Valley, BC, Canada
Member No.: 67





Well, I was not able to reproduce this with Chrome. No matter what I searched for my internet banking details including the log-in page remained hidden.
Go to the top of the page
 
+

Reply to this topicStart new topic
Tags
No Tag inserted yet

1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 







Indian television channel news | Free Advertising | Free Advertising | Internet Advertising | Links of Movies
RSS Lo-Fi Version | SEO by MinervaSEO © Icelabz.net Time is now: 9th January 2009 - 12:57 PM