Forum Views ()
Forum Replies ()
Read more with google mobile :
Vulnerabilities found in Google Chrome PC security
|
Edition:
U.S.
Article
Comments (0)
Follow Reuters
Facebook
Twitter
RSS
YouTube
Read
UPDATE 1-Los Alamos scurries to protect nuclear lab from fire
28 Jun 2011
Violence flares before key Greek austerity vote
|
8:58am EDT
Instant view: Greek parliament votes for austerity plan
9:40am EDT
France airlifts arms to bolster Libyan rebels
|
4:42pm EDT
Honey, will you marry... Oh. Never mind...
14 Mar 2008
Discussed
221
Biden deficit-cut talks hit impasse: Rep. Cantor
114
Fragile economy pushed Obama to tap oil reserves
97
Top Republicans insist no taxes in debt deal
Watched
A Tokyo-Paris flight in under three hours on the horizon
Fri, Jun 24 2011
Hefner's revenge; Ryan Reynolds stops traffic
Fri, Jun 17 2011
China's luxury fast train debuts
Mon, Jun 27 2011
Vulnerabilities found in Google Chrome PC security
Tweet
Share this
Email
Print
Related News
HP to develop cloud products in China
6:38am EDT
Microsoft rolls out Office in the cloud
Tue, Jun 28 2011
Google targets Facebook with new social service
Tue, Jun 28 2011
LulzSec's ambition grows, targets secret government data
Tue, Jun 21 2011
Sega attacked, hacker group offers to take revenge
Sat, Jun 18 2011
Analysis & Opinion
Tech wrap: Microsoft reaches for the cloud
First Look at the Google Plus social network: The Top Secret Demo
Related Topics
Technology »
By Jim Finkle
BOSTON |
Wed Jun 29, 2011 4:54pm EDT
BOSTON (Reuters) - Google Inc brags that computers running its recently released Chrome operating system are a lot safer than traditional PCs, partly because user data is stored in the Internet cloud and not on the machine.
Yet researchers at an independent computer security firm warn that the Chrome PC's reliance on Web computing makes it vulnerable to the same attacks that hackers have been launching on websites and Web browsers for years.
Matt Johansen, a researcher with WhiteHat Security, said he identified a flaw in a Chrome OS note-taking application that he exploited to take control of a Google email account. He reported it to Google, which fixed the problem and gave him a $1,000 reward for pointing it out.
Johansen said he has since discovered other applications with the same security flaw.
"This is just the tip of the iceberg," he told Reuters. "This is just evolving around us. We can see this becoming a whole new field of malware."
Google is betting that the launch of its Web-centric Chrome OS PCs will help reshape the decades-old personal computer industry, challenging entrenched players such as Microsoft Corp and Apple Corp. The first Chrome PC laptop, from Samsung, went on sale earlier this month. Early reviews have been mixed, with some influential technology hands noting that the concept of an always-Internet-connected PC may be ahead of its time and not ideal for mainstream users.
One key to hacking Chrome OS is to capture data as it travels between the Chrome browser and the cloud, Johansen said. Hackers have until now mostly targeted data that sits on a machine's hard drive.
"I can get at your online banking or your FaceBook profile or your email as it is being loaded in the browser," he said. "If I can exploit some kind of Web application to access that data, then I couldn't care less what is on the hard drive."
Johansen declined to identify the applications with the security bugs. He and colleague Kyle Osborn are holding back that information for a presentation at Black Hat, a prestigious hacking conference to be held this August in Las Vegas.
Those applications belong to a class of software programs known as "extensions," which users download from the Google Chrome Web Store. Extensions are essentially applications that run inside browsers
The bulk of Chrome OS extensions are written by independent software developers, not by Google.
Johansen said the problem with the extensions is related to a design flaw in Google Chrome OS: the operating system gives extensions sweeping rights to access data stored on the cloud.
"Chrome is trusting these extensions more than it would be trusting just another website," he said.
Executives at Google said they are looking to improve procedures that screen extensions for vulnerabilities before clearing them for the Chrome Web Store.
Caesar Sengupta, director of Chrome OS, said the company was exploring "various ways" of trying to automatically tag questionable extensions. Yet he said that Google did not want to make it onerous for developers to get their extensions distributed through the marketplace.
"We are trying to create a system that -- like the Web -- is open," he said.
Alex Stamos, a security expert with iSec Partners who helped develop the security system for Chrome OS, said that it would be unfair to condemn the overall security of the new operating system just because of the issues cited by the WhiteHat researchers.
"While things might not be perfect, we are talking about a much more controlled and secure environment than you have on Windows and Mac PCs," he said.
For information on the Black Hat conference, see www.blackhat.com.
(Reporting by Jim Finkle; Additional reporting by Alexei Oreskovic; Editing by Gary Hill)
Technology
Related Quotes and News
Company
Price
Related News
Tweet this
Link this
Share this
Digg this
Email
Reprints
We welcome comments that advance the story through relevant opinion, anecdotes, links and data. If you see a comment that you believe is irrelevant or inappropriate, you can flag it to our editors by using the report abuse links. Views expressed in the comments do not represent those of Reuters. For more information on our comment policy, see http://blogs.reuters.com/fulldisclosure/2010/09/27/toward-a-more-thoughtful-conversation-on-stories/
Comments (0)
Be the first to comment on reuters.com.
Add yours using the box above.
Social Stream (What's this?)
© Copyright 2011 Thomson Reuters
Editorial Editions:
Africa
Arabic
Argentina
Brazil
Canada
China
France
Germany
India
Italy
Japan
Latin America
Mexico
Russia
Spain
United Kingdom
United States
Reuters
Contact Us
Advertise With Us
Help
Journalism Handbook
Archive
Site Index
Video Index
Reader Feedback
Mobile
Newsletters
RSS
Podcasts
Widgets
Your View
Analyst Research
Thomson Reuters
Copyright
Disclaimer
Privacy
Professional Products
Professional Products Support
Financial Products
About Thomson Reuters
Careers
Online Products
Acquisitions Monthly
Buyouts
Venture Capital Journal
International Financing Review
Project Finance International
PEhub.com
PE Week
FindLaw
Super Lawyers Attorney Rating Service
Reuters on Facebook
Thomson Reuters is the world's largest international multimedia news agency, providing investing news, world news, business news, technology news, headline news, small business news, news alerts, personal finance, stock market, and mutual funds information available on Reuters.com, video, mobile, and interactive television platforms. Thomson Reuters journalists are subject to an Editorial Handbook which requires fair presentation and disclosure of relevant interests.
NYSE and AMEX quotes delayed by at least 20 minutes. Nasdaq delayed by at least 15 minutes. For a complete list of exchanges and delays, please click here.
Other News on Thursday, 30 June 2011 Myanmar government warns Suu Kyi on planned tour
|
Greek police battle rioters as austerity bill passed
|
Trial Opens of New Orleans Police Officers Charged in the Danziger Bridge Shootings
California state lawmakers pass budget with deep cuts
North, south Sudan agree on demilitarized border zone
|
Toyota voluntarily recalling 2006, 2007 Highlander Hybrid and Lexus Rx 400h
North Irish militants forcing police from their homes
|
Lindsay Lohan finishes house arrest sentence
Pat Cantlay may be the most intriguing golfer in AT&T field
Obama welcomes same-sex marriage in New York
Online labor demand down nearly 100K in June
Obama asks Congress to cancel vacations, deal with challenges
Mexico appeals to Supreme Court to spare citizen from death penalty
Bangladesh plans moves to get off human trafficking watch list
News Corp to sell Myspace for $35 million: source
|
LivingSocial moving ahead with $1 billion IPO: report
|
Vulnerabilities found in Google Chrome PC security
|
Lindsay Lohan ends home detention after 35 days
|
Second Greek vote expected to pass amid protest anger
|
Egypt police clash with youths; over 1,000 hurt
|
Exclusive: U.S. to resume formal Muslim Brotherhood contacts
|
Hot-hitting Mets score 16 runs to survive slugfest with Tigers
Newsmaker: South Sudan president steers nation to independence
|
Chinese Mongolians protest again, herders beaten: rights group
|
Yunel Escobar comes through as Blue Jays rally past Pirates
Analysis: A Thaksinomics renaissance in Thailand
|
Kim cancelled Russia trip on security worry: report
|
Thunder extend veteran center Nazr Mohammed's deal
Magnitude 5.4 quake hits central Japan, 7 injured
|
Notre Dame wideout Floyd gets probation after guilty plea for drunk driving
Dave Hutsell wins 44th PGA club pro championship
New doubts raised on Saleh's return
|
Hot-hitting Mets storm to 8-2 fifth inning advantage over Tigers
Indians jump out to early lead, take rubber-game from Diamondbacks
Women's World Cup: Rosana's goal launches Brazilians over Aussies
Joe Rogan to return for "Fear Factor" re-boot
Scott Baker tossed 7 1-3 scoreless frames as Twins blank Dodgers
Amazon protests California Web-sales tax plan
|
Samsung asks U.S. to ban iPad, iPhone imports
|
Dell to keep up acquisitions, sustain margin growth
|
Transformers debut ticket sales top $13 million
|
David Duchovny and wife Tea Leoni separate again
|
Man gets two years for Paris Hilton burglary attempt
|
Author James Patterson eyes movies, kids reading
|
New Yorkers get fresh look at Ai Weiwei's art
|
NATO air strike kills fighter linked to Afghan hotel attack
|
Russia: arming Libya rebels is crude violation
|
U.N.-backed court delivers Hariri killing indictments
|
UK teachers, civil servants strike over pensions
|
College tuition data released for first time
Some states still leave low-income students behind; others make surprising gains
Brotherhood gets out Muslim message with movies
Denise Richards adopts baby girl
Sarkozy involved in scuffle during handshake tour
|
Firefighters hopeful about wild fire burning near Los Alamos lab
Myanmar's Suu Kyi to plans first trip since release
|
Moroccan voters asked to approve reforms
Still waiting for an anti-human trafficking law
Analysis:French opinion shifts but a nuclear exit would be tough
|
Javier Colon wins first season of 'The Voice'
Cultural mainstreaming leaves MSM at high HIV risk
Satellite data to help farmers with micro-climates
DealTalk: Private equity scours Hewlett-Packard for cracks
|
Skype introduces video calling for Android phones
|
LightSquared submits GPS report to FCC
|
HMV to refocus on gadgets as profits slump
|
Global tech spend to jump 7.1 percent in 2011: Gartner
|
Vodafone CFO sees $5.5 billion dividend from Verizon
|
Harry Potter to cast final spell with eighth, last film
|
Forgotten Chaplin film fails to find buyer at auction
|
Greece at new risk of being pushed off euro
Bodies of missing Tenn. mom, Jo Ann Bain, and daughter found
Female Breasts Are Bigger Than Ever
AMD Trinity Accelerated Processing Units Now in Volume Production
The Avengers (2012 film), made the second biggest opening- and single-day gross of all-time
AMD to Start Production of piledriver
Ivy Bridge Quad-Core, Four-Thread Desktop CPUs
Islamists Protest Lady Gaga's Concert in Indonesia
Japan Successfully Broadcasts an 8K Signal Over the Air
ECB boosts loans to 1 trillion Euro to stop credit crunch
Egypt : Mohammed Morsi won with 52 percent
What do you call 100,000 Frenchmen with their hands up
AMD Launches AMD Embedded R-Series APU Platform
Fed Should not Ignore Emerging Market Crisis
Fed casts shadow over India, emerging markets
Why are Chinese tourists so rude? A few insights