Researchers play cat and mouse with Google's anti-phishing Chrome extension

Security researchers found nine different ways to defeat Google's Password Alert extension for Chrome

For the past several days security researchers have raced to demonstrate that phishing protections added by a new Google Chrome extension can be bypassed with ease.

The Password Alert extension, developed by Google and released Wednesday, is designed to alert Chrome users when they input their Gmail passwords on websites that don't belong to Google and are therefore part of phishing attacks.

By Thursday, an information security consultant named Paul Moore had already devised a method that attackers could use to block the extension's alerts.

Google fixed that initial bypass in a new version released Friday, but since then it's been a cat and mouse game between Google's developers and security researchers who kept finding more and more ways to defeat the extension.

At the moment, the tally stands at nine bypasses, the latest of which was developed by Moore today. According to the researcher, only three of them have been patched by Google so far. The extension's latest version -- 1.6 -- was released Friday.

The majority of these exploits can be resolved easily, but a couple are difficult, if not impossible, to fix, Moore said Monday via email.

For example, an exploit developed by researchers from Dutch software security company Securify works by sandboxing an IFRAME.

"I can't see how Securify's sandbox exploit can be resolved without nullifying the sandbox completely," Moore said. "Likewise, my 'refresh on keypress' bypass works by exploiting a race condition which an extension probably cannot resolve."

In response to these exploits, the head of the webspam team at Google, Matt Cutts, commented on Twitter that: "A world in which every single phisher in the world has to play catchup/counterattack is a better world than today."

While that might be true, it's also a bit disingenuous, Moore said. "These exploits, some of which are downright comical, put the user at a disadvantage, not the attacker."

The extension will protect against the simplest phishing attacks and for that Google should be commended, but it arguably offers little protection against more sophisticated attacks and "no security is better than a false sense of security," the researcher said.

Join the newsletter!

Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection

Tags Securifyonline safetyGooglesecurityscamsExploits / vulnerabilities

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Lucian Constantin

IDG News Service
Show Comments

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Ben Ramsden

Sharp PN-40TC1 Huddle Board

Brainstorming, innovation, problem solving, and negotiation have all become much more productive and valuable if people can easily collaborate in real time with minimal friction.

Sarah Ieroianni

Brother QL-820NWB Professional Label Printer

The print quality also does not disappoint, it’s clear, bold, doesn’t smudge and the text is perfectly sized.

Ratchada Dunn

Sharp PN-40TC1 Huddle Board

The Huddle Board’s built in program; Sharp Touch Viewing software allows us to easily manipulate and edit our documents (jpegs and PDFs) all at the same time on the dashboard.

George Khoury

Sharp PN-40TC1 Huddle Board

The biggest perks for me would be that it comes with easy to use and comprehensive programs that make the collaboration process a whole lot more intuitive and organic

David Coyle

Brother PocketJet PJ-773 A4 Portable Thermal Printer

I rate the printer as a 5 out of 5 stars as it has been able to fit seamlessly into my busy and mobile lifestyle.

Kurt Hegetschweiler

Brother PocketJet PJ-773 A4 Portable Thermal Printer

It’s perfect for mobile workers. Just take it out — it’s small enough to sit anywhere — turn it on, load a sheet of paper, and start printing.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?