SOT Casino - SOT Amazon Store - SOT Arcade - FlashChat

Go Back   Super Off Topic Syndicate > Science & Technology > Computers and Software
Register gXboxLive FAQ Members List Search Today's Posts Mark Forums Read

Notices

Your Ad Here
Reply
 
Share LinkBack Thread Tools Display Modes
Old 09-04-2008, 09:40 AM   #1 (permalink)
SOT Moderator
 
Vertabreaker's Avatar
 
Join Date: Aug 2007
Location: The phone booth across the street
Posts: 16,121
Vertabreaker has a spectacular aura aboutVertabreaker has a spectacular aura about
Chrome is a security nightmare, indexes your bank accounts

Just an FYI to those who have already downloaded and tried Chrome

Quote:
Los Angeles (CA) – Can a browser’s search function work too well? After playing around with Google’s brand new Chrome browser, we’ve discovered that its history search box will fetch all types of data - even text from HTTPS-protected financial sites like Washington Mutual and Capital One. With a few utterly simple keywords like balance, account and Sept., everything from balance information, account numbers and even how much you spent at Costco can be pulled up.

To see all of this in action, just open up Chrome and log in to your favorite financial website. Like most important sites, it should be protected with HTTPS/SSL encryption and that should be evident in the address bar of the browser. Do the stuff you would normally do like look at your balances and gawk at your latest transactions and then open up a new tab in Chrome by clicking the “+” symbol. In the right-hand history search box, enter a few keywords and see what they get you. Surprised? I bet you are. No luck? Then try something simple like oh Visa, Mastercard, balance and account. Also try out the names and abbreviations of months like September, Sept and Sep.

If you’re like me, you probably saw account balances and some transaction details, but if you further refine your keywords you’d be able to see a lot more. We first discovered this “problem” by browsing the forensicfocus.com forums. “Problem” is in quotes because we’re not sure if this is a true vulnerability or Google Chrome’s search function working as intended – in this case, just too damn good. While playing around with the forensic implications of Chrome, “Jelle” on the forums posted that he and his partner noticed the browser was indexing information from HTTPS sites.

“One interesting finding is that in the regular browsing mode, Chrome creates a search index of the contents of a lot of the pages you visit. This allows you to do keyword searching in your own web history. On some of our tests, we found that content of https pages had been indexed as well, allowing us to retrieve our bank account details using a keyword search,” Jelle posted.

Of course after reading this I just had to give it a try and logged into my Washington Mutual and Capital One credit card accounts. I looked at my pathetically low bank account balances along with my insanely high outstanding credit card balances. Then I pulled up a recent list of transactions for the month (damn you gas prices) - on many financial websites this information is usually shown on the very first page after logging in. Then I opened up a new tab and started playing around with keywords.

Thinking like a hacker, my first plan of attack was to enumerate or list the financial services. After enumeration, I could drill down into the exact accounts and transactions. By simply typing in Visa, Mastercard, account and the names of popular banks you can find the types of accounts and which institution they belong to. In my case, Capital and Washington worked just fine. To get my account balance, I just typed in “balance” and to get transaction information I entered “transaction”. Typing in “costco” pulled up how much I spent on my last trip.

Is there a way to protect your financial information from being indexed? Google Chrome does have an incognito mode that promises to not cache anything. This can be accessed from the file menu in the upper-right corner of the window or by using the keyboard shortcut (Control Shift N). You can also clear your browser data after surfing to a financial website by going to the tools menu that’s also in the upper-right corner.

It was just yesterday that I wrote about Chrome’s security as being “not bad”, but I personally don’t get a warm and fuzzy feeling if Chrome is indexing all of my financial information. Search and indexing is what Google is good at and the company has made my life a whole lot easier in many ways, but indexing financial info is crossing the line.

On the programming level, I can’t really blame Google’s developers though because HTTPS was never meant to provide any protection anyways on the desktop itself. The protection was developed to protect traffic as it travelled through the “Wild West” Internet. But while this distinction is clear to most of our readers – the regular person probably believes HTTPS/SSL traffic is and should be protected on the desktop.

So is this all a big deal? Well anyone who wants to search your financial information would need local access to your machine and if a person is sitting at your computer, you have a lot more things to worry about than him/her using Chrome’s history search. Conceivably a hacker could develop an app to pull the cache and index files off your computer and examine them later on another machine – these files reside in the “C:\Documents and Settings\USERNAME\Local Settings\Application Data\Google\Chrome\User Data\Default” folder.

But on a simpler level, if ALL of the sites I visit are being keyworded and indexed locally, then how do I know that this information will stay local. I guess that depends on how much you trust Google.
I'm sure they'll fix some of the shit going wrong with it but this is a little ridiculous.
Vertabreaker is offline   Reply With Quote
Old 09-04-2008, 09:44 AM   #2 (permalink)
SOT Administrator
 
Cr@xheadMcgee's Avatar
 
Join Date: Jun 2006
Location: Miami
Posts: 31,351
Cr@xheadMcgee will become famous soon enoughCr@xheadMcgee will become famous soon enough
yep. It does it.

*Uninstalles Chrome*
__________________
SOT - When in doubt add more HerpDERP!
Cr@xheadMcgee is offline   Reply With Quote
Old 09-04-2008, 09:46 AM   #3 (permalink)

 
Awesome-0's Avatar
 
Join Date: Jan 2008
Posts: 10,611
Awesome-0 is on a distinguished road
well that didnt last long

soon

google>microsoft

when it comes to 'most evil'
__________________
SOT - Eat da poo poo
Awesome-0 is offline   Reply With Quote
Old 09-04-2008, 09:47 AM   #4 (permalink)
SOT Moderator
 
cpjay2003's Avatar
 
Join Date: Dec 2006
Location: Lakeland, FL.
Posts: 4,300
cpjay2003 is on a distinguished road
Glad I never DL'd it...
__________________
cpjay2003 is offline   Reply With Quote
Old 09-04-2008, 09:48 AM   #5 (permalink)
SOT Post Whore
 
Evil_Merlin's Avatar
 
Join Date: Jan 2008
Location: Medford, MA
Posts: 5,574
Evil_Merlin can only hope to improve
Uninstalling now. Woah.

WTF is up with the uninstall screen: "Is it something we said?"

If I wanted a joke when uninstalling a program, I'd read Awesome-O's posts.

Last edited by Evil_Merlin; 09-04-2008 at 09:51 AM.
Evil_Merlin is offline   Reply With Quote
Old 09-04-2008, 09:49 AM   #6 (permalink)
tjf
SOT Post Whore
 
Join Date: Jul 2007
Location: Soviet NJ
Posts: 7,145
tjf is on a distinguished road
i still use IE, i guess that finally paid off for something
tjf is offline   Reply With Quote
Old 09-04-2008, 09:53 AM   #7 (permalink)
angry an' shit mod
 
edgecrusher1120's Avatar
 
Join Date: Jul 2008
Location: new york, north kackalacka and compton
Posts: 7,396
edgecrusher1120 will become famous soon enough
Quote:
Originally Posted by Vertabreaker View Post
Just an FYI to those who have already downloaded and tried Chrome



I'm sure they'll fix some of the shit going wrong with it but this is a little ridiculous.

chrome needs to lock it up, its projecting
__________________
The average response time for a 911 call is over 4 minutes.
The average response time of a .357 magnum is 1400 FPS.

Photobucket

sot-just when my coils reachin the green line
edgecrusher1120 is offline   Reply With Quote
Old 09-04-2008, 09:54 AM   #8 (permalink)

 
Awesome-0's Avatar
 
Join Date: Jan 2008
Posts: 10,611
Awesome-0 is on a distinguished road
Henry, submit this on digg

Merlin, wanna hug?
__________________
SOT - Eat da poo poo
Awesome-0 is offline   Reply With Quote
Old 09-04-2008, 09:56 AM   #9 (permalink)
SOT Moderator
 
Vertabreaker's Avatar
 
Join Date: Aug 2007
Location: The phone booth across the street
Posts: 16,121
Vertabreaker has a spectacular aura aboutVertabreaker has a spectacular aura about
Quote:
Originally Posted by edgecrusher1120 View Post
chrome needs to lock it up, its projecting
Enjoy yourself while I go ice my balls and spit up blood.

"Team player"
Vertabreaker is offline   Reply With Quote
Old 09-04-2008, 09:57 AM   #10 (permalink)
SOT Post Whore
 
Evil_Merlin's Avatar
 
Join Date: Jan 2008
Location: Medford, MA
Posts: 5,574
Evil_Merlin can only hope to improve
Quote:
Originally Posted by Awesome-0 View Post
Merlin, wanna hug?
From you? You'll probably reach into my wallet and steal money from me and give it to some crack whore that cannot speak English and is milking society for everything.
Evil_Merlin is offline   Reply With Quote
Reply

Bookmarks

Tags
accounts, bank, chrome, indexes, nightmare, security

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT -5. The time now is 11:50 PM.

   

Powered by vBulletin® Version 3.7.0
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0
Forum Topsite