iEntry 10th Anniversary RSS Newsletter Advertising
Join the WebProWorld Forum!

Google Safe Browsing May Be Unsafe

Post to Twitter Post to Facebook

The new Firefox plug-in from Google that helps to thwart phishing schemes may itself pose a problem to uses due to a security flaw.

Dr. Szell: Is it safe?
-- Marathon Man, 1976

Maybe not, Christian. Nitesh Dhanjani posted some concerns he has about the Google Safe Browsing plug-in for Firefox.

Every request made while using the plug-in goes to Google. Dhanjani tested a legit site and a phishing site, intercepted the traffic, and observed that behavior. The first problem comes with the data being sent to Google:

Every request is transmitted to Google over HTTP, i.e. in clear-text.
Clear-text means plain, easy-to-read text. Dhanjani writes that if a web application is set up to send your information to a site with a GET request instead of a POST, and someone is sitting on the network between the user and Google with a packet sniffer, they can easily see your credit card number or any other personal information.

GET figures in Dhanjani's second issue with the plug-in:

The extension sends the entire GET request to Google. If a web application were to send private information via GET parameters, this will now be transmitted to Google.
So even if no malicious parties are camping out on the wire and sniffing that information, it's still traveling in the clear to Google. Typical uses won't know if their bank or credit card company uses GET or POST for web applications; Dhanjani believes a lot of web applications don't use POST.

Let's hope a few people in banking and financial IT pick up on this and check out their applications. Is it safe?

Add to document.write("Del.icio.us") | Yahoo My Web

David Utter is a staff writer for WebProNews covering technology and business.

News Tags: Google, Browsing, Web

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.
CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.
6 + 5 =
Solve this simple math problem and enter the result. E.g. for 1+3, enter 4.
Featured Headline
Fake Chrome OS Screenshots Punk Tech Media
Mystery Blogger Comes Clean
5 comments | 18 hours ago
 
Subscribe to WebProNews


Send me relevant info