Chrome, Firefox browser extensions leaked millions of users' data

Agencies
July 20, 2019

Popular browser extensions like ad blockers have been caught harvesting personal data of millions of consumers who use Chrome and Firefox -- not only their browsing histories but also exposing tax returns, medical records, credit card information and other sensitive data in the public domain.

According to an independent cyber security researcher Sam Jadali, the data has been leaked to a fee-based company called Nacho Analytics that gives unlimited access to any websites analytics data.

The data could be purchased for as little as $10 to $50, said Jadali whose report was first described in Ars Technica late on Friday.

"This non-stop flow of sensitive data over the past seven months has resulted in the publication of links to home and business surveillance videos hosted on Nest and other security services.

"Tax returns, billing invoices, business documents, and presentation slides posted to, or hosted on, Microsoft OneDrive, Intuit.com, and other online services" have been exposed, said the report.

The exposed data via eight browser extensions also include vehicle identification, numbers of recently bought automobiles, along with the names and addresses of the buyers.

Patient details, travel itineraries, Facebook Messenger attachments and Facebook photos, even private, are now available in the public domain.

Browser extensions - also known as plug-ins or add-ons - are apps that consumers can install to run alongside their browser for additional functionality.

The affected extensions were apps used by millions of people, including HoverZoom, SpeakIt!, and FairShare Unlock.

"The extensions have been remotely removed or disabled in consumers' browsers and are no longer available for download," said both Google and Firefox.

People who didn't download the extensions may also be affected.

"Nobody is immune to this. Even if you don't have any harmful extensions, the other people you interact with may have an extension on their computers that could be leaking the data you share with them," Jadali was quoted as saying.

Nacho Analytics, for example, promises to let people "see anyone's analytics account" and to provide "real-time web analytics for any website".

The company charges $49 per month, per domain, to monitor any of the top 5,000 most widely-trafficked websites.

The security expert has suggested users to delete all browser extensions they have installed in the past.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
January 15,2020

New Delhi, Jan 15: The Delhi government Wednesday told the high court that execution of the death row convicts in the Nirbhaya gangrape and murder case will not take place on January 22 as a mercy plea has been filed by one of them.

The four convicts -- Vinay Sharma (26), Mukesh Kumar (32), Akshay Kumar Singh (31) and Pawan Gupta (25) -- are to be hanged on January 22 at 7 am in Tihar jail. A Delhi court had issued their death warrants on January 7.

Justices Manmohan and Sangita Dhingra Sehgal were told by the Delhi government and the Centre that the petition filed by convict Mukesh, challenging his death warrant, was premature.

The Delhi government and the prison authorities informed the court that under the rules, it will have to wait for the mercy plea to be decided before executing the death warrant.

They also said that none of the four convicts can be executed on January 22 unless the present mercy plea is decided.

The Supreme Court had on Tuesday dismissed the curative pleas of Mukesh and Vinay.

The mercy plea hearing began Wednesday morning and will continue in the afternoon.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
May 26,2020

UN, May 26: Countries could see a "second peak" of coronavirus cases during the first wave of the pandemic if lockdown restrictions were lifted too soon, the World Health Organization (WHO) has warned.

Mike Ryan, the WHO's head of emergencies, told a briefing on Monday that the world was "right in the middle of the first wave", the BBC reported.

He said because the disease was "still on the way up", countries need to be aware that "the disease can jump up at any time".

"We cannot make assumptions that just because the disease is on the way down now that it's going to keep going down," Ryan said.

There would be a number of months to prepare for a second peak, he added.

The stark warning comes as countries around the world start to gradually ease lockdown restrictions, allowing shops to reopen and larger groups of people to gather.

Experts have said that without a vaccine to give people immunity, infections could increase again when social-distancing measures are relaxed.

Ryan said countries where cases are declining should be using this time to develop effective trace-and-test regimes to "ensure that we continue on a downwards trajectory and we don't have an immediate second peak".

Also on Monday, Tedros Adhanom Ghebreyesus, WHO Director-General, said that a clinical trial of hydroxychloroquine (HCQ) on COVID-19 patients has come to "a temporary pause", while the safety data of the the anti-malaria drug was being reviewed.

According to the WHO chief, The Lancet medical journal on May 22 had published an observational study on HCQ and chloroquine and its effects on COVID-19 patients that have been hospitalized, reports Xinhua news agency.

The authors of the study reported that among patients receiving the drug, when used alone or with a macrolide, they estimated a higher mortality rate.

"The Executive Group of the Solidarity Trial, representing 10 of the participating countries, met on Saturday (May 23) and has agreed to review a comprehensive analysis and critical appraisal of all evidence available globally," Tedros said in a virtual press conference.

The developments come as the total number of global COVID-19 cases has increased to 5,508,904, with 346,508 deaths, according to the Johns Hopkins University.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
June 29,2020

New Delhi, Jun 29: A disturbing video of a Covid-19 patient, speaking his last words, after his oxygen supply was allegedly cut off, has surfaced on social media. The patient reportedly died after indicating that the oxygen supply to him was cut off despite his requests.

The video has a 35-year-old Covid-19 patient bidding good-bye to his family, from a government hospital bed in Hyderabad. The patient Ravi Kumar can be seen speaking out against the negligence of of the medical staff in providing ventilator support to him when he needed it the most.

The video has led to social media outrage as it attracted public attention towards plight of patients in government hospitals

"I am not able to breathe, I pleaded but they did not continue oxygen for the last three hours. I am not able to breathe anymore daddy, it's like my heart has stopped, Bye daddy. Bye to all, daddy," these were apparently the final words of the man, who spoke in his local dialect, and shared on social media.

Several reports have claimed that the man had been admitted to government Chest hospital, after several private hospitals refused to admit him. His ventilator support was allegedly taken off in the hospital, after which he recorded the video message.

The victim’s family shared the video message for the public to know of the negligence.

Reports have it that Ravi’s covid-19 report, which testes positive, was given to family a day after his death, when 30 of his family members performed the final rites, thus making all of them vulnerable to the virus. Ravi’s father has alleged that the test was done on June 24 and Ravi died on June 26, while the report was given to them on June 27.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.