Chrome, Firefox browser extensions leaked millions of users' data

Agencies
July 20, 2019

Popular browser extensions like ad blockers have been caught harvesting personal data of millions of consumers who use Chrome and Firefox -- not only their browsing histories but also exposing tax returns, medical records, credit card information and other sensitive data in the public domain.

According to an independent cyber security researcher Sam Jadali, the data has been leaked to a fee-based company called Nacho Analytics that gives unlimited access to any websites analytics data.

The data could be purchased for as little as $10 to $50, said Jadali whose report was first described in Ars Technica late on Friday.

"This non-stop flow of sensitive data over the past seven months has resulted in the publication of links to home and business surveillance videos hosted on Nest and other security services.

"Tax returns, billing invoices, business documents, and presentation slides posted to, or hosted on, Microsoft OneDrive, Intuit.com, and other online services" have been exposed, said the report.

The exposed data via eight browser extensions also include vehicle identification, numbers of recently bought automobiles, along with the names and addresses of the buyers.

Patient details, travel itineraries, Facebook Messenger attachments and Facebook photos, even private, are now available in the public domain.

Browser extensions - also known as plug-ins or add-ons - are apps that consumers can install to run alongside their browser for additional functionality.

The affected extensions were apps used by millions of people, including HoverZoom, SpeakIt!, and FairShare Unlock.

"The extensions have been remotely removed or disabled in consumers' browsers and are no longer available for download," said both Google and Firefox.

People who didn't download the extensions may also be affected.

"Nobody is immune to this. Even if you don't have any harmful extensions, the other people you interact with may have an extension on their computers that could be leaking the data you share with them," Jadali was quoted as saying.

Nacho Analytics, for example, promises to let people "see anyone's analytics account" and to provide "real-time web analytics for any website".

The company charges $49 per month, per domain, to monitor any of the top 5,000 most widely-trafficked websites.

The security expert has suggested users to delete all browser extensions they have installed in the past.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
June 17,2020

New Delhi, Jun 17: Prime Minister Narendra Modi on Wednesday called for an all-party meeting to be held on June 19 to discuss the situation at the border areas with China.

The virtual conference meeting, presided by PM Modi, will be attended by presidents of various political parties in the country.

"In order to discuss the situation in the India-China border areas, Prime Minister Narendra Modi has called for an all-party meeting at 5 PM on 19th June. Presidents of various political parties would take part in this virtual meeting," a tweet by the PMO India read.

At least 20 Indian Army personnel, including a Colonel rank officer, had lost their lives in the violent face-off in the Galwan valley area of Ladakh on June 15.

The violent face-off happened on late evening and the night of June 15 in Ladakh's Galwan Valley as a result of an attempt by the Chinese troops to "unilaterally change" the status quo during de-escalation in Eastern Ladakh and the situation could have been avoided if the agreement at the higher level been scrupulously followed by the Chinese side, India said on June 16.

The Chinese side also suffered casualties, including the death of the commanding officer of the Chinese Unit involved in the violent face-off with Indian troops, sources confirmed to news agency.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
February 5,2020

Chennai, Feb 5: The popular cine actor Rajinikanth has defended the Union Government on the Citizenship Amendment Act, saying it will not affect the Indian Muslims.

In a brief interaction with reporters this morning in Chennai, the matinee idol said if the Muslims are affected by the CAA, he would be at the forefront in their defence. He asked how will the legislation affect the Indian Muslims when they chose to stay back in the country to make it their motherland. Mr Rajinikanth also supported the National Population Register saying it has been in force even in the past.

On the NRC, Mr Rajinikanth said the Government has already made it clear that its nationwide rollout has not been even discussed so far. Mr Rajinikanth is nourishing political ambitions and has made it clear that he would plunge into politics ahead of the Tamil Nadu Assembly Elections in the state which is due in 2021.

Comments

Arif
 - 
Wednesday, 5 Feb 2020

This law violates the fundamentals of the Indian constitution. Whey they are seeing the Muslims angle first?

 

It looks that they are misinforming the public by diverting into a Muslim only issue. If that was the case, why so many non-Muslims are protesting? I looks like Rajini has back-end support to the center's CAA move.

 

Suresh SS
 - 
Wednesday, 5 Feb 2020

He is another crack, hamare desh main pagal logon ki kami nahi

Wellwisher
 - 
Wednesday, 5 Feb 2020

What can expect from ex KSRTC bus conductor

 

 
clear sign of ZERO knowedge with Indian constitution.

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
January 7,2020

Jan 7: Body of the senior Iranian military commander, Qasem Soleimani killed in a U.S. drone strike in Iraq last week, has arrived in his home town of Kerman in southeast Iran for burial, the official IRNA news agency said on Tuesday.

State TV broadcast live images of thousands of people in the streets of the town, many of them dressed in black, to mourn Soleimani's death.

Soleimani was widely seen as Iran’s second most powerful figure behind Supreme Leader Ayatollah Ali Khamenei, 80, who wept in grief along with hundreds of thousands of mourners who thronged the streets of Tehran for Soleimani’s funeral on Monday.

Khamenei led prayers at the funeral in the Iranian capital, pausing as his voice cracked with emotion. Soleimani, 62, was a national hero even to many who do not consider themselves supporters of Iran’s clerical rulers.

He was killed while leaving Baghdad airport last Friday. Mourners packed the streets, chanting: “Death to America!” - a show of national unity after anti-government protests in November in which many demonstrators were killed.

The crowd, which state media said numbered in the millions, recalled the masses gathered in 1989 for the funeral of the Islamic Republic’s founder, Ayatollah Ruhollah Khomeini.

The killing of Soleimani has prompted fears around the world of a broader regional conflict, as well as calls in the U.S. Congress for legislation to keep President Donald Trump from going to war against Iran.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.