Jump to content

Google needs to go back to the drawing board, as Password Alert is hacked in 24 hours

zappian

google_password.png

This is frankly hilarious , the monolith that is google tried to implement a chrome extension to protect peoples password from phishing attemps :

 

 

Well, that didn’t take very long.

Not even a day after its debut, a proof-of-concept exploit has been posted which fools Google’s push to protect people’s passwords from phishing attempts through a new extension in Chrome.

 

Well it was hacked in a day by a single individual. Paul Moore a white hat hacker and security consultant.

 

 

“It beggars belief,” said Paul Moore, an information security consultant at UK-based Urity Group who wrote the exploit. “The suggestion that it offers any real level of protection is laughable.”

The Password Alert extension was supposed to be able to keep an active eye on phishing attempts by scanning databases of known threats, and running them against any pages that asked for your Google account to login.

 

But, just by simply removing the Javascript block which controls the warning banner that pops up when a fraudulent site is detected, Moore was able to fool the extension into thinking his set-up phishing portal was a legitimate resource.

 

So google went back to the drawing board and fixed the exploit . Paul moore cracked their protection again:

 

 

Google responded to the problem by quickly updating its service to block that specific route of entry, but just a day after that, Moore returned with a second crack which circumvented both updates without fail.

This iteration works by refreshing the page after every character is typed in, which fools the warning system into thinking the full password was never entered in the first place.

 

It just shows how futile some of these protection measure are and are easily circumvented by someone with enough time and skill to put into it .
Google needs to find another way to implement this .

 

Original Article : http://www.digitaltrends.com/computing/google-needs-to-go-back-to-the-drawing-board-as-password-alert-is-hacked-in-24-hours/

Link to comment
Share on other sites

Link to post
Share on other sites

 

 

It just shows how futile most of these protection measure are and are easily circumvented by someone with enough time and skill to put into it , even google cant fight back against the internet.

 

Original Article : http://www.digitaltrends.com/computing/google-needs-to-go-back-to-the-drawing-board-as-password-alert-is-hacked-in-24-hours/

how you say it makes it sound like google should just give up on security. Yeah its hard as hell, but no reason to stop trying to protect password

Link to comment
Share on other sites

Link to post
Share on other sites

People being able to hack it means they just need to work on different ways of securing passwords, not give up entirely.

Specs: CPU - Intel i7 8700K @ 5GHz | GPU - Gigabyte GTX 970 G1 Gaming | Motherboard - ASUS Strix Z370-G WIFI AC | RAM - XPG Gammix DDR4-3000MHz 32GB (2x16GB) | Main Drive - Samsung 850 Evo 500GB M.2 | Other Drives - 7TB/3 Drives | CPU Cooler - Corsair H100i Pro | Case - Fractal Design Define C Mini TG | Power Supply - EVGA G3 850W

Link to comment
Share on other sites

Link to post
Share on other sites

Google can't fight back the internet ??? and we should stop trying to protect our passwords ??? 

  ﷲ   Muslim Member  ﷲ

KennyS and ScreaM are my role models in CSGO.

CPU: i3-4130 Motherboard: Gigabyte H81M-S2PH RAM: 8GB Kingston hyperx fury HDD: WD caviar black 1TB GPU: MSI 750TI twin frozr II Case: Aerocool Xpredator X3 PSU: Corsair RM650

Link to comment
Share on other sites

Link to post
Share on other sites

Snip

yes

this is one of the greatest thing that has happened to me recently, and it happened on this forum, those involved have my eternal gratitude http://linustechtips.com/main/topic/198850-update-alex-got-his-moto-g2-lets-get-a-moto-g-for-alexgoeshigh-unofficial/ :')

i use to have the second best link in the world here, but it died ;_; its a 404 now but it will always be here

 

Link to comment
Share on other sites

Link to post
Share on other sites

That's like a condom with a hole in it.

Link to comment
Share on other sites

Link to post
Share on other sites

Updated the OT thingie.

I don't think you have to as it's your opinion.

  ﷲ   Muslim Member  ﷲ

KennyS and ScreaM are my role models in CSGO.

CPU: i3-4130 Motherboard: Gigabyte H81M-S2PH RAM: 8GB Kingston hyperx fury HDD: WD caviar black 1TB GPU: MSI 750TI twin frozr II Case: Aerocool Xpredator X3 PSU: Corsair RM650

Link to comment
Share on other sites

Link to post
Share on other sites

that sounds so simple to be overlooked by google *_*

i9 11900k - NH-D15S - ASUS Z-590-F - 64GB 2400Mhz - 1080ti SC - 970evo 1TB - 960evo 250GB - 850evo 250GB - WDblack 1TB - WDblue 3TB - HX850i - 27GN850-B - PB278Q - VX229 - HP P224 - HP P224 - HannsG HT231 - 450D                                                         
Link to comment
Share on other sites

Link to post
Share on other sites

that sounds so simple to be overlooked by google *_*

well when until you actually try to make it, thats all its going to be for you, it sounds simple.

Google could have made it better and tested it more, but still these things are bound to happen. And OP makes it sound like security should be completely eliminated because its hard to accomplish.

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

well when until you actually try to make it, thats all its going to be for you, it sounds simple.

Google could have made it better and tested it more, but still these things are bound to happen. And OP makes it sound like security should be completely eliminated because its hard to accomplish.

 as i said, it sounds simple, just as simple sounding as splitting atoms sounds :P

i9 11900k - NH-D15S - ASUS Z-590-F - 64GB 2400Mhz - 1080ti SC - 970evo 1TB - 960evo 250GB - 850evo 250GB - WDblack 1TB - WDblue 3TB - HX850i - 27GN850-B - PB278Q - VX229 - HP P224 - HP P224 - HannsG HT231 - 450D                                                         
Link to comment
Share on other sites

Link to post
Share on other sites

Well at least they know they should try harder, and thank god for white hat hackers

Link to comment
Share on other sites

Link to post
Share on other sites

Google should just hire that guy. Gotta give him the respect for cracking it. The best security would come from the best hackers.

Link to comment
Share on other sites

Link to post
Share on other sites

Thanks zappian.

 

We're up to 9 exploits so far, with 2 being virtually impossible to resolve without breaking either the sandbox or fixing a race condition which has existed for years.

 

I'd expect Google to pull it quite soon.

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×