{"id":4812,"date":"2018-12-03T10:00:31","date_gmt":"2018-12-03T16:00:31","guid":{"rendered":"http:\/\/blog.zoha-islands.com\/?p=4812"},"modified":"2018-12-03T10:00:31","modified_gmt":"2018-12-03T16:00:31","slug":"got-malicious-chrome-extensions","status":"publish","type":"post","link":"https:\/\/zoha-islands.com\/blog\/got-malicious-chrome-extensions\/","title":{"rendered":"Got Malicious Chrome Extensions?"},"content":{"rendered":"<table border=\"0\" width=\"100%\">\n<tbody>\n<tr>\n<td valign=\"top\">\n<div class=\"intro\">\n<p>If you are like most Chrome is a staple in our everyday internet lives as well as the extension in Second Life web browser.Your web browser is your first line of defense against all manner of cyber attacks. But some disturbing reports of malicious Chrome extensions that resist most manual removal efforts have led me to wonder just how good Google is at keeping malicious extensions out of the Play Store, and how committed Google is to doing so. Read on for the scoop\u2026<\/p>\n<\/div>\n<\/td>\n<td><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<div id=\"adsense-new\"><\/div>\n<div id=\"a005399more\">\n<div id=\"more\">\n<div class=\"KonaBody\">\n<h2>Is Google Doing All It Can To Protect Against Malicious Chrome Extensions?<\/h2>\n<p>Google puts a lot of effort into making the Chrome browser safe and secure. But when third-party extensions are added, your level of security may drop to zero. Browser extensions have nearly full access to the web pages you visit, so in addition to spying on your activity, a malicious extension can steal passwords, user your computer to mine cryptocurrency, and make you an unwitting participant in click fraud schemes.<\/p>\n<p><span id=\"ezoic-pub-ad-placeholder-116\" class=\"ezoic-adpicker-ad\"><\/span>The recent discovery of a uniquely stubborn rogue extension quickly led to revelations of others, and to the company\u2019s alarming admission that over a thousand malicious apps are uploaded to the Play Store every single month. Equally disturbing is Google\u2019s apparently lackadaisical response to the first extension; after being notified of its presence, Google took 19 days to remove it from the Play Store! <span id=\"ezoic-pub-ad-placeholder-111\" class=\"ezoic-adpicker-ad\"><\/span><span id=\"div-gpt-ad-askbobrankin_com-medrectangle-4-0\" class=\"ezoic-ad\"><\/span><\/p>\n<p>A company spokesperson stated that this extension and another user-resistant malicious app were \u201cautomatically removed\u2026 from the machines of affected users.\u201d Now, \u201cautomatic\u201d implies \u201cfast,\u201d but these removals did not happen until hours after Ars Technica published a post about them and the weeks-long delay in getting attention paid to the first one!<\/p>\n<p><img decoding=\"async\" class=\"imgmain\" src=\"https:\/\/askbobrankin.com\/malicious-chrome-extensions.jpg\" alt=\"Malicious chrome extensions\" \/><\/p>\n<p>The malicious apps in question were \u201cTiempo en Colombia en vivo\u201d (Weather in Columbia Live), a Chrome extension, and \u201cPlay Red Bull version 4,\u201d ostensibly a children\u2019s game that runs in Chrome. They are both gone, but the way they were handled has left a sour taste in many mouths.<\/p>\n<p><span id=\"ezoic-pub-ad-placeholder-112\" class=\"ezoic-adpicker-ad\"><\/span><span id=\"div-gpt-ad-askbobrankin_com-box-4-0\" class=\"ezoic-ad\"><\/span>James Oppenheim, who reviews children&#8217;s games professionally, is one of those whose lips are twisted bitterly. The rogue \u201cgame\u201d contained a logo that named his site, jamesgames.com, as the official home of the malware! James notes that he has never written an extension; he reviews games, he does not create them. appears that whoever published it knows enough about what I do reviewing kid&#8217;s software to think that my name would help make the malware more trustworthy,\u201d Oppenheim told Ars.<\/p>\n<p>Adding insult to that injury, he says that a week after he reported the offending app via the \u201cREPORT ABUSE\u201d button on its Play Store page, he had absolutely no response from Google and the malware remained available\u2026 and aimed at children, mind you!<\/p>\n<div id=\"quotebox\">You can protect yourself by installing only browser extensions to those that are well-established, with many thousands of positive reviews, and preferably millions of existing users. The <a href=\"https:\/\/chrome.google.com\/webstore\/category\/extensions\" target=\"_blank\" rel=\"noopener\">Chrome Web Store<\/a> displays star ratings, and the number of user reviews on the category pages. When you click to see the details of an extension, you can see how many users have installed it, and read the reviews. <img decoding=\"async\" loading=\"lazy\" class=\"wp-image-4835 alignright\" src=\"http:\/\/blog.zoha-islands.com\/wp-content\/uploads\/2018\/12\/Chrome-webstore-300x150.jpg\" alt=\"\" width=\"518\" height=\"259\" srcset=\"https:\/\/zoha-islands.com\/blog\/wp-content\/uploads\/2018\/12\/Chrome-webstore-300x150.jpg 300w, https:\/\/zoha-islands.com\/blog\/wp-content\/uploads\/2018\/12\/Chrome-webstore.jpg 474w\" sizes=\"(max-width: 518px) 100vw, 518px\" \/><\/div>\n<p>The \u201cgame\u2019s\u201d page said it had 27,781 users at the time Oppenheim investigated it. Many of them posted warnings that the thing was malware. \u201cMakes me wonder how seriously Google is taking this problem,\u201d he said in his email to Ars Technica\u2019s Security Editor, Dan Goodin.<\/p>\n<h2>Fumbling the Ball<\/h2>\n<p><span id=\"ezoic-pub-ad-placeholder-113\" class=\"ezoic-adpicker-ad\"><\/span>I wonder too. Google\u2019s spokesperson didn\u2019t even get the word \u201cBall\u201d right in the response that Goodin finally received, substituting \u201cBull.\u201d Funny, that\u2019s exactly what I think is Google\u2019s response to this security failure! There\u2019s <a href=\"https:\/\/goo.gl\/xuPb3b\" target=\"_blank\" rel=\"noopener\">a lot more to this story<\/a> as told by Oppenheim and Goodin, but I think we have the gist: Google didn\u2019t just fumble the ball, it was disgracefully late to the game.<\/p>\n<p>I mentioned earlier that 1000+ malicious apps are uploaded to the Play Store every month, and the great majority of those are automatically flagged and removed. So it&#8217;s not fair to say that Google isn&#8217;t trying to protect their users. But you can only do so much with automation. When you&#8217;re dealing with numbers of users in the tens or hundreds of millions, a success rate of 99.9% is not nearly good enough.<\/p>\n<p>I get it: Google Chrome is the world\u2019s most-used browser by several country miles; it\u2019s the first and often only target of every hacker. But Google knows that, and Google has plenty of money to throw at problems like this. If they don&#8217;t have enough people to handle problems like this, I refer you to the previous sentence. When problems are pro-actively reported by real humans who are saying &#8220;Hey, this is malware!&#8221; they should be acted on swiftly.<\/p>\n<p>This sort of failure to protect, and delay in remediation, and defense of indefensible obtuseness, is simply unacceptable. Google, you must do better here. If you want better security just DON&#8217;T Use Chrome or it&#8217;s apps! Its really that simple use Firefox or Windows built in browser and make damn sure you have <a href=\"https:\/\/www.malwarebytes.com\/\" target=\"_blank\" rel=\"noopener\">malwarebytes<\/a> and a good anti-virus program and know where your apps are coming from.<\/p>\n<p>Have a safe week from all of us on the ZI Staff<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>If you are like most Chrome is a staple in our everyday internet lives as well as the extension in Second Life web browser.Your web browser is your first line of defense against all manner of cyber attacks. But some disturbing reports of malicious Chrome extensions that resist most manual removal efforts have led me &hellip; <a href=\"https:\/\/zoha-islands.com\/blog\/got-malicious-chrome-extensions\/\" class=\"more-link\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":4834,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[2,3,4,5,6],"tags":[],"_links":{"self":[{"href":"https:\/\/zoha-islands.com\/blog\/wp-json\/wp\/v2\/posts\/4812"}],"collection":[{"href":"https:\/\/zoha-islands.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zoha-islands.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zoha-islands.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/zoha-islands.com\/blog\/wp-json\/wp\/v2\/comments?post=4812"}],"version-history":[{"count":0,"href":"https:\/\/zoha-islands.com\/blog\/wp-json\/wp\/v2\/posts\/4812\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/zoha-islands.com\/blog\/wp-json\/wp\/v2\/media\/4834"}],"wp:attachment":[{"href":"https:\/\/zoha-islands.com\/blog\/wp-json\/wp\/v2\/media?parent=4812"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zoha-islands.com\/blog\/wp-json\/wp\/v2\/categories?post=4812"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zoha-islands.com\/blog\/wp-json\/wp\/v2\/tags?post=4812"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}