Chrome, Firefox browser extensions leaked millions of users' data

Agencies
July 20, 2019

Popular browser extensions like ad blockers have been caught harvesting personal data of millions of consumers who use Chrome and Firefox -- not only their browsing histories but also exposing tax returns, medical records, credit card information and other sensitive data in the public domain.

According to an independent cyber security researcher Sam Jadali, the data has been leaked to a fee-based company called Nacho Analytics that gives unlimited access to any websites analytics data.

The data could be purchased for as little as $10 to $50, said Jadali whose report was first described in Ars Technica late on Friday.

"This non-stop flow of sensitive data over the past seven months has resulted in the publication of links to home and business surveillance videos hosted on Nest and other security services.

"Tax returns, billing invoices, business documents, and presentation slides posted to, or hosted on, Microsoft OneDrive, Intuit.com, and other online services" have been exposed, said the report.

The exposed data via eight browser extensions also include vehicle identification, numbers of recently bought automobiles, along with the names and addresses of the buyers.

Patient details, travel itineraries, Facebook Messenger attachments and Facebook photos, even private, are now available in the public domain.

Browser extensions - also known as plug-ins or add-ons - are apps that consumers can install to run alongside their browser for additional functionality.

The affected extensions were apps used by millions of people, including HoverZoom, SpeakIt!, and FairShare Unlock.

"The extensions have been remotely removed or disabled in consumers' browsers and are no longer available for download," said both Google and Firefox.

People who didn't download the extensions may also be affected.

"Nobody is immune to this. Even if you don't have any harmful extensions, the other people you interact with may have an extension on their computers that could be leaking the data you share with them," Jadali was quoted as saying.

Nacho Analytics, for example, promises to let people "see anyone's analytics account" and to provide "real-time web analytics for any website".

The company charges $49 per month, per domain, to monitor any of the top 5,000 most widely-trafficked websites.

The security expert has suggested users to delete all browser extensions they have installed in the past.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
March 18,2020

San Francisco, Mar 18: Facebook said a bug in its anti-spam system temporarily blocked the publication of links to news stories about the coronavirus. Guy Rosen, Facebook's vice president of integrity, said on Twitter Tuesday that the company was working on a fix for the problem.

Users complained that links to news stories about school closings and other information related to the virus outbreak were blocked by the company's automated system.

Later on Tuesday, Rosen tweeted that Facebook had restored all the incorrectly deleted posts, which also covered topics beyond the coronavirus.

Rosen said the problems were unrelated to any changes in Facebook's content-moderator workforce. The company reportedly sent its human moderators home this week because of the coronavirus outbreak.

A representative for Facebook did not immediately respond to questions on the status of Facebook's content moderators, many of whom do not work directly for the company and are not always able to work from home.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
June 3,2020

New Delhi, Jun 3: India registered its highest single-day spike in COVID-19 cases on Wednesday with 8,909 more cases reported in the last 24 hours, taking the country's tally to 2,07,615, while the death toll rose to 5,815 according to the Union Health and Family Welfare Ministry.

The number of active COVID-19 cases stood to 1,01,497 while 1,00,303 people have been cured/discharged/migrated.

According to the Union Health and Family Welfare Ministry, out of all the states, Maharashtra has recorded the highest number of coronavirus cases with 72,300 patients followed by Tamil Nadu with 24,586 cases.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
March 15,2020

New Delhi, Mar 15: The new rules for debit and credit cards to increase security and reduce frauds kick in from Monday. In January, the Reserve Bank of India (RBI) had issued new rules to improve user convenience and increase the security of card transactions. These rules will help in curbing the misuse of debit and credit cards.

RBI has directed banks to allow only domestic card transactions at ATMs and PoS terminals in India at the time of issuance/reissuance of card. For international transactions, online transactions, card-not-present transactions and contactless transactions, customers will have to separately set up services on their card.

These rules will be applicable for new cards from March 16. Those with old cards can decide whether to disable any of these features.

As per the existing rules, these services used to come automatically with the card, but now it will start at the request of the customer.

Debit or credit card customers who have not yet done any online transaction, contactless transaction or international transaction with the card, then these services on the card will automatically stop from March 16.

The Reserve Bank has asked all banks to provide mobile banking, net banking option to enable limit and enable and disable service 24 hours a day, seven days a week.

If the customer makes any change in the status of the card, the bank will alert the customer through SMS/email and send the information.

Issuers shall provide to all cardholders facility to switch on/off and set/modify transaction limits (within the overall card limit, if any, set by the issuer) for all types of transactions -- domestic and international, at PoS/ATMs/online transactions/contactless transactions, etc.,

The provisions, however, are not mandatory for prepaid gift cards and those used at mass transit systems.

The latest instructions come in the wake of rising instances of cyber frauds and the huge increase in the use of cards.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.