Stories
Slash Boxes
Comments

SoylentNews is people

posted by janrinok on Saturday April 20 2019, @05:59PM   Printer-friendly
from the javascript==security dept.

Submitted via IRC for ErkleLives

Phishing — schemes to nab personal data with disguised malicious webpages and emails — constituted more than 70% of all cyber attacks in 2016, according to a Verizon report. In an effort to combat them, Google last year announced it would require users to enable JavaScript during Google Account sign-in so that it could run attack-detecting risk assessments, and today, the company said it'll begin to block all sign-ins from embedded browser frameworks like Chromium Embedded Framework starting in June.

For the uninitiated, embedded browser frameworks enable developers to add basic web browsing functionality to their apps, and to use web languages like HTML, CSS, and JavaScript to create those apps' interface (or portions of it). They're typically cross-platform — Chromium Embedded Framework runs on Linux, Windows, and macOS — and they support a range of language bindings.

"We're constantly working to improve our phishing protections to keep your information secure," account security product manager Jonathan Skelker wrote in a blog post. "This is yet another layer of protection on top of existing safeguards like Safe Browsing warnings, Gmail spam filters, and account sign-in challenges."

[...] As an alternative to embedded browser frameworks, Google is suggesting that developers use browser-based OAuth authentication, which enables users to see the full address of the page where they're entering their credentials. "If you are a developer with an app that requires access to Google Account data, switch to using browser-based OAuth authentication today," Skelker said.

Source: https://venturebeat.com/2019/04/18/google-will-begin-to-block-sign-ins-from-embedded-browser-frameworks-in-june/


Original Submission

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 2) by fyngyrz on Sunday April 21 2019, @11:56AM (1 child)

    by fyngyrz (6567) on Sunday April 21 2019, @11:56AM (#832913) Journal

    There are no ads on the sign-in page.

    Fine. But you have to have javascript enabled. Unless there is a mechanism that only enables javascript on the sign-in page, the problem isn't limited to the sign-in page, it applies to every other page you visit.

    It's a bit much to expect the user to enable and disable javascript going into and out of the sign-in page, isn't it?

    --
    It's not really how I look that reveals my age.
    It's using complete sentences when I text.

    Starting Score:    1  point
    Karma-Bonus Modifier   +1  

    Total Score:   2  
  • (Score: 2) by darkfeline on Sunday April 21 2019, @09:28PM

    by darkfeline (1030) on Sunday April 21 2019, @09:28PM (#833121) Homepage

    If you have javascript globally disabled, why even bother logging in to Google? I don't think there's a single service you can use without javascript enabled. Maybe the legacy HTML Gmail view? But then you may as well use POP/IMAP and a local client.

    --
    Join the SDF Public Access UNIX System today!