Chrome, Firefox browser extensions leaked millions of users' data

Agencies
July 20, 2019

Popular browser extensions like ad blockers have been caught harvesting personal data of millions of consumers who use Chrome and Firefox -- not only their browsing histories but also exposing tax returns, medical records, credit card information and other sensitive data in the public domain.

According to an independent cyber security researcher Sam Jadali, the data has been leaked to a fee-based company called Nacho Analytics that gives unlimited access to any websites analytics data.

The data could be purchased for as little as $10 to $50, said Jadali whose report was first described in Ars Technica late on Friday.

"This non-stop flow of sensitive data over the past seven months has resulted in the publication of links to home and business surveillance videos hosted on Nest and other security services.

"Tax returns, billing invoices, business documents, and presentation slides posted to, or hosted on, Microsoft OneDrive, Intuit.com, and other online services" have been exposed, said the report.

The exposed data via eight browser extensions also include vehicle identification, numbers of recently bought automobiles, along with the names and addresses of the buyers.

Patient details, travel itineraries, Facebook Messenger attachments and Facebook photos, even private, are now available in the public domain.

Browser extensions - also known as plug-ins or add-ons - are apps that consumers can install to run alongside their browser for additional functionality.

The affected extensions were apps used by millions of people, including HoverZoom, SpeakIt!, and FairShare Unlock.

"The extensions have been remotely removed or disabled in consumers' browsers and are no longer available for download," said both Google and Firefox.

People who didn't download the extensions may also be affected.

"Nobody is immune to this. Even if you don't have any harmful extensions, the other people you interact with may have an extension on their computers that could be leaking the data you share with them," Jadali was quoted as saying.

Nacho Analytics, for example, promises to let people "see anyone's analytics account" and to provide "real-time web analytics for any website".

The company charges $49 per month, per domain, to monitor any of the top 5,000 most widely-trafficked websites.

The security expert has suggested users to delete all browser extensions they have installed in the past.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
November 11,2024

Udupi, Nov 11: A traveller reportedly lost ₹4.1 lakh after attempting to book a cab online in Udupi. 

At around 1:30 PM on November 7, the man from West Bengal searched for car rentals on Google and selected a website named "Shakti Car Rentals." Shortly after, he was contacted by someone claiming to be "Rohit Sharma," who directed him to pay a registration fee of ₹150 on the site.

After unsuccessful payment attempts via both his Canara Bank debit card and SBI credit card (without receiving an OTP), "Rohit Sharma" instructed him to pay the driver directly. But at 1:47 PM, he received messages showing deductions of ₹3.3 lakh from his SBI credit card and ₹80,056 from his Canara Bank debit card, totaling ₹4.1 lakh.

The complainant alleges fraud through a deceptive link disguised as a booking token fee. A case has been registered at Udupi Town Police Station.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
November 18,2024

Advisors to US President-elect Donald Trump have instructed his allies and associates to refrain from using the inflammatory language they previously employed when discussing issues related to migrants and the deportation of asylum seekers, in a bid to avoid “looking like Nazis.”

US media reports said that Trump’s associates had been asked to stop using the word “camps” to describe potential facilities that would be used to accommodate migrants rounded up in deportation operations across the country.

The reports said the US president-elect’s allies had been ordered to stave off such charged terms as they would bring to mind “Nazis,” and be used against Trump.

“I have received some guidance to avoid terms, like ‘camps,’ that can be twisted and used against the president, yes,” one Trump ally told American monthly magazine Rolling Stone.

“Apparently, some people think it makes us look like Nazis.”

The presidential advisers also cautioned surrogates and allies to keep racist terms, which have dogged Trump’s campaign, out of their remarks.

They said with Trump’s heated rhetoric that used to compare undocumented immigrants to “animals” and his slight that they are “poisoning the blood of our country,” detractors did not need to reach too far to find parallels to Nazi Germany.

Stephen Miller, who Trump tapped to be his deputy chief of staff of policy, specifically used the word “camps” to describe holding facilities that he hoped the military could put together for immigrants.

Tom Homan, who served as the acting director of Immigration and Customs Enforcement and is chosen by Trump to be in charge of the US borders, was no stranger to such language.

“It’s not gonna be a mass sweep of neighborhoods,” he said in an interview earlier this week. “It’s not gonna be building concentration camps. I’ve read it all. It’s ridiculous.”

Becoming a little more forthright about the new government’s aggressive deportation plans, Homan likened the early days of the Trump administration to the initial invasion of Iraq in 2003.

“I got three words for them – shock and awe,” he said. “You’re going to see us take this country back.”

Trump made immigration a central element of his 2024 presidential campaign but unlike his first run, which was mainly focused on building a border wall, he has shifted his attention to interior enforcement and the removal of undocumented immigrants already in the United States.

People close to the US president and his aides are laying the groundwork for expanding detention facilities to fulfill his mass deportation campaign promise.

The businessman-turned-politician deported more than 1.5 million people during his first term.

The figure do not include the millions of people turned away at the border under a Covid-era policy enacted by Trump and used during most of Biden’s term.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
November 21,2024

palestainetragedy.jpg

Hamas says the Israeli regime’s sole objective lies in “erasing” the entirety of the Palestinian population from across the Palestinian territories.

Khalil al-Hayya, a ranking official with the Gaza Strip-based Palestinian resistance movement, made the remarks to the Palestinian al-Aqsa TV on Wednesday.

“The occupation targets everyone—it strikes hospitals, civil defense, women, children, and the elderly,” he said, adding that the regime sought to “empty Gaza of its residents, and displace the Palestinian people to fulfill its dreams of building a Zionist Jewish state across all of Palestine.”

The remarks came amid the regime’s October 2023-present war of genocide on the coastal sliver that has so far claimed the lives of nearly 44,000 Palestinians, mostly women and children.

“This unprecedented aggression in modern times evokes scenes from the dark ages of human history, having crossed all red lines and exceeded every expectation of brutality in the modern era,” the Palestinian official lamented.

He also regretted that the regime had added “systematic and dangerous starvation to its aggression, falsely claiming before the world that it allows 250 [aid] trucks into Gaza daily. In reality, the number of trucks is far fewer.”

Hayya, meanwhile, regretted that “scenes of children torn apart, women screaming over their children, and heart-wrenching destruction have failed to stir enough humanity to stop these crimes.”

He decried the United States for vetoing the United Nations Security Council’s resolutions that are aimed at bringing about a potential ceasefire in the war, saying this indicated Washington’s “partnership in the aggression” and a simultaneous siege that the Israeli regime has been enforcing on Gaza.

Addressing Israeli Prime Minister Benjamin Netanyahu, the official asserted that, despite what the Israeli official is after, Hamas would not hand over the regime’s captives “without [the regime’s] stopping the war.”

He called Netanyahu “the main obstacle” in the way of cessation of the aggression, saying the Israeli premier “blocks any progress for political reasons,” and citing his preventing conclusion of a ceasefire agreement in July.

Hayya also warned that the regime sought to expand the war beyond Gaza, but asserted that its goals are “impossible and will never happen.”

“Today, the enemy exposes its true intentions of extermination and displacement, but it will fail,” he stressed.

“The Palestinian people are resilient and will not surrender, as they believe in their humanitarian and political cause. The enemy and its allies will not succeed in achieving their goals. This steadfast people will endure, and the occupation will not prevail against them.”

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.