Lupa Kata Sandi? Klik di Sini

atau Masuk melalui

Belum Memiliki Akun Daftar di Sini


atau Daftar melalui

Sudah Memiliki Akun Masuk di Sini

Konfirmasi Email

Kami telah mengirimkan link aktivasi melalui email ke rudihamdani@gmail.com.

Klik link aktivasi dan dapatkan akses membaca 2 artikel gratis non Laput di koran dan Majalah Tempo

Jika Anda tidak menerima email,
Kirimkan Lagi Sekarang

Spying on Users of Google's Chrome Shows New Security Weakness

Translator

Tempo.co

Editor

Laila Afifa

18 June 2020 16:16 WIB

TEMPO.COSan Francisco - A newly discovered spyware effort attacked users through 32 million downloads of extensions to Google’s market-leading Chrome web browser, researchers at Awake Security told Reuters, highlighting the tech industry’s failure to protect browsers as they are used more for email, payroll and other sensitive functions. 

Alphabet Inc’s Google said it removed more than 70 of the malicious add-ons from its official Chrome Web Store after being alerted by the researchers last month.

“When we are alerted of extensions in the Web Store that violate our policies, we take action and use those incidents as training material to improve our automated and manual analyses,” Google spokesman Scott Westover told Reuters.

Most of the free extensions purported to warn users about questionable websites or convert files from one format to another. Instead, they siphoned off browsing history and data that provided credentials for access to internal business tools.

Based on the number of downloads, it was the most far-reaching malicious Chrome store campaign to date, according to Awake co-founder and chief scientist Gary Golomb.

Google declined to discuss how the latest spyware compared with prior campaigns, the breadth of the damage, or why it did not detect and remove the bad extensions on its own despite past promises to supervise offerings more closely.

It is unclear who was behind the effort to distribute the malware. Awake said the developers supplied fake contact information when they submitted the extensions to Google.

“Anything that gets you into somebody’s browser or email or other sensitive areas would be a target for national espionage as well as organized crime,” said former National Security Agency engineer Ben Johnson, who founded security companies Carbon Black and Obsidian Security.

The extensions were designed to avoid detection by antivirus companies or security software that evaluates the reputations of web domains, Golomb said.

If someone used the browser to surf the web on a home computer, it would connect to a series of websites and transmit information, the researchers found. Anyone using a corporate network, which would include security services, would not transmit the sensitive information or even reach the malicious versions of the websites.

 

“This shows how attackers can use extremely simple methods to hide, in this case, thousands of malicious domains,” Golomb said.

All of the domains in question, more than 15,000 linked to each other in total, were purchased from a small registrar in Israel, Galcomm, known formally as CommuniGal Communication Ltd.

Awake said Galcomm should have known what was happening.

In an email exchange, Galcomm owner Moshe Fogel told Reuters that his company had done nothing wrong.

“Galcomm is not involved, and not in complicity with any malicious activity whatsoever,” Fogel wrote. “You can say exactly the opposite, we cooperate with law enforcement and security bodies to prevent as much as we can.”

Fogel said there was no record of the inquiries Golomb said he made in April and again in May to the company’s email address for reporting abusive behavior, and he asked for a list of suspect domains. Reuters sent him that list three times without getting a substantive response.

The Internet Corp for Assigned Names and Numbers, which oversees registrars, said it had received few complaints about Galcomm over the years, and none about malware.

While deceptive extensions have been a problem for years, they are getting worse. They initially spewed unwanted advertisements, and now are more likely to install additional malicious programs or track where users are and what they are doing for government or commercial spies.

 

Malicious developers have been using Google’s Chrome Store as a conduit for a long time. After one in 10 submissions was deemed malicious, Google said in 2018 here it would improve security, in part by increasing human review.

But in February, independent researcher Jamila Kaya and Cisco Systems’ Duo Security uncovered here a similar Chrome campaign that stole data from about 1.7 million users. Google joined the investigation and found 500 fraudulent extensions.

“We do regular sweeps to find extensions using similar techniques, code and behaviors,” Google’s Westover said, in identical language to what Google gave out after Duo’s report.

Read: Protect Your Personal Data; Tips for Your Online Security

REUTERS



27,162 Joint Personnel Secure Eid Travel in West Java

13 hari lalu

27,162 Joint Personnel Secure Eid Travel in West Java

The authorities have deployed a joint team of 27,162 personnel from police, military, and regional govt in West Java to secure Eid homecoming travel.


Ed Sheeran Concert in Jakarta Tonight, Police Deploy 2,000 Personnel for Security

48 hari lalu

Ed Sheeran Concert in Jakarta Tonight, Police Deploy 2,000 Personnel for Security

Jakarta Metro Police say the authority would deploy 2,025 personnel to secure the Ed Sheeran concert at JIS in North Jakarta.


Maintaining Neutrality of Security Forces in the Election

2 Desember 2023

Maintaining Neutrality of Security Forces in the Election

Many believe that the security forces will not be neutral in the 2024 elections. This is very dangerous for the nation.


BSSN Records 361 Million Cyber Attacks in Indonesia

17 November 2023

BSSN Records 361 Million Cyber Attacks in Indonesia

The National Cyber and Encryption Agency (BSSN) reported 361 million traffic anomalies or cyber attacks in Indonesia from Jan. 1 to Oct. 26, 2023.


Tax DG Ensures Taxpayers' Confidentiality over Prepopulated Scheme

27 Oktober 2023

Tax DG Ensures Taxpayers' Confidentiality over Prepopulated Scheme

Directorate General of Taxes will ensure the data confidentiality of taxpayers will remain secure when the prepopulated scheme is implemented.


Whoosh High-Speed Train Halted for 10 Minutes on Wednesday Evening

5 Oktober 2023

Whoosh High-Speed Train Halted for 10 Minutes on Wednesday Evening

KCJB detected a disruption on its track through Whoosh's remote censor.


Ancol Security Guards Assaulted Visitor to Death; No Proof of Theft

4 Agustus 2023

Ancol Security Guards Assaulted Visitor to Death; No Proof of Theft

There was no evidence of theft committed by Hasanuddin who died after being assaulted by the security guards of Ancol who suspected him of stealing.


Starvation in Central Papua Caused by Extreme Weather and Security Issues, Says Jokowi

31 Juli 2023

Starvation in Central Papua Caused by Extreme Weather and Security Issues, Says Jokowi

Jokowi said the famine suffered in two districts in Central Papua was caused by extreme cold weather and security factors.


AwanPintar Reveals Foreign Spam and Malware Attacks on Indonesia

21 Juli 2023

AwanPintar Reveals Foreign Spam and Malware Attacks on Indonesia

AwanPintar released its report on cyber threats such as spam and malware attacks in Indonesia in the first semester of 2023.


Indonesia vs Argentina Match; Jakarta Police Deploy 5,000 Personnel

17 Juni 2023

Indonesia vs Argentina Match; Jakarta Police Deploy 5,000 Personnel

Jakarta Metro Police preparing 5,596 personnel to guard the FIFA Matchday game of Indonesia vs Argentina national teams at GBK stadium.