Google purges Chrome extension store

08/04/2015 18:53

Google purges Chrome extension store


Tens of millions of users who visit Google sites use a browser loaded with malicious add-ons, research suggests.  reports.

Most rogue extensions bombard people with ads, but the most malicious steal login names and other valuable data.

Carried out by security experts and Google, the project analysed more than 100 million visits to the search giant's sites.

It led to Google purging almost 200 bad extensions from its online catalogues of browser add-ons.

Bad behaviour?

Extensions and add-ons for web browsers add all kinds of functions and features to the software.

Many of these extensions have hidden extras that cause trouble for people who install them, said UC Santa Barbara computer scientist Alexandros Kapravelos, who worked with Google on the rogue extensions project.

The research found that malicious extensions were available for every major browser.

The findings are due to be published in full in May at the IEEE Symposium on Security and Privacy.

Preliminary results revealed that 5% of people accessing Google every day have been caught out by at least one malicious extension.

Of these victims, about a third have four or more bad add-ons installed in their browser.

"It is a very hard problem to deal with," said Mr Kapravelos.

Some bad extensions were easy to spot, he said, because they were so obviously written to steal saleable data such as bitcoins, bank logins or personal data.

However, many used techniques seen in legitimate extensions, he said, and it took a lot of extra analysis to pin down the bad ones.

"Even when we have a complete understanding of what the extension is doing, sometimes it is not clear if that behaviour is malicious or not," he said.

"You would expect that an extension that injects or replaces advertisements is malicious, but then you have AdBlock that creates an ad-free browsing experience and is technically very similar."

Experts from Swedish security firm ScrapeSentry said it had found examples of extensions that gathered data in ways that could easily be abused.

ScrapeSentry's analysis of one extension, called Webpage Screenshot, revealed that it contained code that let it grab copies of all the browser traffic from the PC on which it was installed.

The gathered data was then sent to a server in the US. The extension has been downloaded about 1.2 million times.

"What happens to the personal data and the motives for sending it to the US server is anyone's guess, but we'd take an educated guess that it's not going to be good news," said Martin Zetterlund from ScrapeSentry.

A spokesman for Webpage Screenshot said there was nothing malicious about the data it gathered. Instead, said the spokesman, it was used to understand who the extension's users were and where they were located to help drive development of the code.

Users could opt out of sharing data, he said.

Deleting data

Mr Kapravelos said Google had acted on the early findings of the research by removing 192 actively malicious extensions from its Chrome catalogue. About 14 million people had been tricked into using these extensions, he said.

The UC Santa Barbara team was working with Google to develop tools that can automatically spot malicious extensions and flag them to the search giant's security staff.

In addition, said Mr Kapravelos, firms whose adverts were being injected onto webpages by the rogue extensions had been informed.

Unfortunately, he said, ad injection had become "entrenched" as a way for some unscrupulous developers to make money.

The research found that only a small number of developers were behind the majority of the rogue extensions that pepper people with ads, suggesting that targeted action could help tackle the problem.


In case you have found a mistake in the text, please send a message to the editor by selecting the mistake and pressing Ctrl-Enter.

Newsfeed

10/10/2024 17:45 Viva sees growing demand for cloud services 10/10/2024 10:30 Businessman and benefactor Mikayel Vardanyan was awarded the title of Honorary citizen of Masis community 03/10/2024 15:05 Trip to Dubai: Exciting new campaign for Byblos Bank Armenia premium cardholders 03/10/2024 13:40 The stamp dedicated to the 75th anniversary of Hrant Vardanyan, the founder of "Grand Holding", was issued 03/10/2024 10:35 Chat-Assistant in “My Viva”: new digital tool for online communication lovers 02/10/2024 19:27 Ameriabank’s Special Offer for New Mastercard Holders. 1% Cashback and Lots of Gifts 30/09/2024 16:17 Byblos Bank Armenia named General Sponsor of YSU Faculty of Economics and Management's 90th anniversary events 26/09/2024 10:45 Armenian confectionery production counts a century-long history. "Grand Candy" celebrates the 100th anniversary of creation of Armenian sweets 25/09/2024 12:32 Large-scale upgrade in Team Telecom Armenia's network 24/09/2024 18:24 Amundi-Acba Launches Academy to Enhance Financial Literacy and Professional Development 20/09/2024 16:53 Best startup ideas of “Get Started” revealed 19/09/2024 18:42 “Yandex Plus” and “Kinodaran” within Viva’s “START+” prepaid tariff plan 19/09/2024 13:57 Catalyst for growth and innovation: Viva presents new “Narrow Band-IoT” tariff plan 13/09/2024 12:24 5 more YSU students awarded AMD 1 million scholarship each: Byblos Bank Armenia continues to motivate young minds 11/09/2024 16:21 “Virtual PBX”: effective business management tool from Viva 11/09/2024 10:49 Barerar.am is a new platform that provides an opportunity to provide assistance to needy families directly and without any mediation 09/09/2024 14:11 Nokia and Team Telecom Armenia bring 25G PON commercial services to customers across Armenia 31/08/2024 12:03 “Remote hands” for any business from anywhere Viva offers a reliable and flexible server support service 30/08/2024 15:09 Achieving self-development with “Viva University” 30/08/2024 14:55 It pains me that those who fought for their nation and homeland have been consigned to oblivion. Mikayel Minasyan 29/08/2024 17:04 Kyiv Announces Plans to Transport Azerbaijani Gas to Europe Instead of Russian 29/08/2024 16:58 "Spayka" Threatens Our Livelihood: Export Truck Drivers Protest 29/08/2024 16:50 Russia Reaffirms Commitment to Armenia Partnership 29/08/2024 16:00 Armenia Plans to Amend the Constitution in 2027 25/08/2024 11:01 Theories of Conspiracy Among Armenians: Ambassador Mikael Minasyan's Analysis 23/08/2024 14:45 Around 100,000 households are making use of Team's Internet; 2nd quarter indicators 16/08/2024 14:34 Unlimited YouTube for AMD 3000 monthly 14/08/2024 15:27 Armenian Tax Authority Proposes Draconian Measures Against Businesses 14/08/2024 15:19 Massive Fire Engulfs Moscow’s RIO Shopping Center 14/08/2024 15:09 Azerbaijan Levels Mokhrenes Village in Artsakh 14/08/2024 15:01 Mikayel Minasyan, former ambassador and son-in-law of ex-President Serzh Sargsyan, is back in the spotlight 12/08/2024 15:15 First steps in establishing a startup with “Get Started” 12/08/2024 11:22 12-year-old Gabriela Harutyunyan aims for the European chess champion’s title 10/08/2024 13:56 VOYAGE 30 - 1000 MB of Internet, for only AMD 1500/Activation through “My Viva” application 02/08/2024 17:55 Unlimited Internet from Viva becomes even more affordable 29/07/2024 14:34 Wi-Fi Calling. calls and SMS abroad at the same rates as in Armenia 25/07/2024 17:51 Ameriabank Receives 3 Awards for Excellence by Euromoney: the Best Bank, the Best Digital Bank, and the Best Bank for SMEs in Armenia for 2024 23/07/2024 15:41 Byblos Digital Cards: Tailored for a generation opting for everything digital 22/07/2024 18:16 EBRD and Ameriabank to support Armenian businesses through stable trade finance funding 19/07/2024 13:38 Business Leadership in the Era of Internet of Things (IoT) and Digital Transformation 11/07/2024 19:41 “VOYAGE 30” Internet roaming: 1000 MB for just AMD 1500 03/07/2024 16:31 Ameriabank and COAF Pool Efforts to Develop Beekeeping in Lori Region 01/07/2024 18:11 Viva: Armenia's leading technology company introduces a new trademark 01/07/2024 13:05 Cumulative deposit on flexible terms. Byblos Bank Armenia's new offer 26/06/2024 12:15 Viva-MTS: Green technologies in Gomq 24/06/2024 18:20 “Viva University”: self-development and specialization platform for students․ About 300 graduates in 9 years 20/06/2024 12:15 “Dream big, start small”: Anna from Artsakh participates in “Get Started” 18/06/2024 11:00 Viva-MTS: Four families displaced from Artsakh have become beneficiaries of the "Individual Assistant" program 14/06/2024 19:08 EventHub.am is the official ticketing agent for the concert of the world renowned Black Eyed Peas in Tbilisi 04/06/2024 11:22 Byblos Bank Armenia puts children first: June 1 event celebrates childhood, imagination 31/05/2024 10:15 Karen Vardanyan donated 118 million drams to the National Center for Burns for the medical equipment 29/05/2024 16:56 EPIC Applauds EWC Armenia 2024 National Prizewinners Three Victorious Startups Advance to Global Competition 23/05/2024 18:05 Welcome to CaseKey 2024. Byblos Bank Armenia firmly stands by future innovators 23/05/2024 12:01 New technologies as guarantees for wildlife conservation and rural development 22/05/2024 16:06 Tariff plan “TOURIST UNLIM”: Unlimited Internet while travelling in Armenia 21/05/2024 15:45 Your home is in Armenia – Ameriabank offers mortgage loans for the Diaspora 20/05/2024 18:01 Ameriabank's Trade Finance portfolio enriched with four prestigious awards from EBRD and IFC 16/05/2024 17:03 “Get Started”: An educational platform for young startuppers 16/05/2024 15:40 Byblos Bank Armenia celebrates Students' Day with scholarship recipients 08/05/2024 15:42 Viva-MTS: modern technological solutions to modernize the infrastructure of the border village 25/04/2024 18:46 Solar photovoltaic station at the kindergarten of the border village Yeraskh 22/04/2024 13:06 Caring for nature, we have started with ourselves - Team Telecom Armenia 18/04/2024 11:27 New streets in Koti equipped with illumination operated via automatic and remote control 11/04/2024 10:30 Byblos Bank Armenia donates AMD 5 million to Health Fund for Children of Armenia 06/04/2024 14:34 Viva-MTS sums up the financial results for 2023 and confirms its leadership in the sector 02/04/2024 12:20 Success story resulting from continued support. From music therapy to the conservatory 29/03/2024 14:41 Ameriabank named the Best Bank in Armenia for 2024 by Global Finance magazine 28/03/2024 14:02 IoT Lab opens at National Polytechnic University of Armenia 26/03/2024 16:58 “START+”: “Kinodaran” without subscription fee, 10 GB internet, 1000 minutes and favorite apps without any limits 25/03/2024 16:14 Change in Viva-MTS company name and General Terms of Provisioning Services 22/03/2024 17:24 Marzes remain in the focus of attention of Viva-MTS: New service center opened in Tchambarak 21/03/2024 14:12 In 2023, the SME Loan Portfolio of Ameriabank Reported More Than 30% Growth 19/03/2024 10:20 Mikael Vardanyan donated 117 mln drams for garbage trucks and 230 waste bins for Masis community 14/03/2024 18:12 New technologies at the core of rural infrastructure development 13/03/2024 16:32 The number of Team mobile subscribers is over 1 million 13/03/2024 13:01 “RED”: fixed and mobile services in one package for customers valuing convenience and quality 11/03/2024 14:51 Global Finance Recognizes Ameriabank's Leadership in Sustainable Finance in Armenia 06/03/2024 14:07 Byblos Bank Armenia named CaseKey title sponsor again 05/03/2024 13:36 Doing Digital Forum Returns Featuring Brett King as Keynote Speaker 01/03/2024 18:42 "The Innovator's Dilemma": Byblos Bank Armenia supports publication of Armenian edition 29/02/2024 16:45 “Personal Assistant” program changes popular mindset in regions 27/02/2024 18:12 Viva-MTS: 30-day internet-package for the many destinations within “VOYAGE” service 22/02/2024 17:53 The kindergarten of Armavir village is already being supplied with solar photovoltaic panels 19/02/2024 16:53 Viva-MTS, a company cultivating reading traditions 19/02/2024 12:48 Ameriabank set to join BOGG, a London Stock Exchange (LSE) listed financial group as a standalone entity 14/02/2024 14:53 Years of hard work and a sustainable approach to infrastructure development in regions 07/02/2024 14:49 Virtual PBX: Smart tool for corporate clients 02/02/2024 18:26 Viva-MTS named one of the ten most attractive employers 26/01/2024 18:15 Ameriabank is the Largest Taxpayer Among Armenian Banks 25/01/2024 17:03 Viva-MTS and “SOURCE” Foundation's “Personal Assistant” program is achieving the desired result in Syunik 24/01/2024 19:14 The shareholder of Viva-MTS has changed: The company will reach new achievements 23/01/2024 12:56 Byblos Bank Armenia to sponsor CaseKey team’s participation in Budapest’s CUBE 2024 22/01/2024 14:27 53% increase in Internet traffic in the Viva-MTS network. New Year's Eve and the first day compared to the same period last year 18/01/2024 18:30 “Viva University”: a long-term investment in youth empowerment 29/12/2023 15:49 Viva-MTS: investments that ensure sustainable development using innovative solutions 28/12/2023 14:46 The Christmas Miracle in Shirak Region - Ameriabank Santas Visited Children from Artsakh 22/12/2023 11:43 12 participants of “Get Started” program will explore the startup ecosystem 20/12/2023 20:38 Byblos Bank Armenia donates New Year gift funds to Soldier's Home 14/12/2023 15:51 Daily solutions for Viva-MTS clients based on artificial intelligence and deep neural networks 13/12/2023 16:24 How Ameriabank continued to deliver success amid the volatility of the global markets