Google Fixes Sandbox Escape in Chrome

Tuesday, May 19th, 2015

Google has patched a high-risk vulnerability in its Chrome browser that allows an attacker to escape the Chrome sandbox. That vulnerability is one of 37 bugs fixed in version 43 of Chrome. Six of those flaws are rated as high risks and Google paid out more than $38,000 in rewards to ...

Google Aims at Phishing with Password Alert

Wednesday, April 29th, 2015

Phishing pages are tricky by nature: they look like standard login pages, but are actually faux sites run by people looking to receive and steal passwords. Google is taking steps to thwart this common and dangerous trap with its Password Alert service. Password Alert is an open-source Chrome extension that ...

All Major Web Browsers Fall in Pwn2Own Hacking Contest

Friday, March 20th, 2015

Security researchers nabbed $552,500 in bounties at this year's Pwn2Own hacking contest, demonstrating exploits against the top four Web browsers, plus Adobe Reader and Flash Player. On Thursday, the second and final day of the competition, the star of the show was South Korean security researcher JungHoon Lee, aka "lokihardt," who ...

Strengthening 2-Step Verification with Security Key

Tuesday, October 21st, 2014

2-Step Verification offers a strong extra layer of protection for Google Accounts. Once enabled, you’re asked for a verification code from your phone in addition to your password, to prove that it’s really you signing in from an unfamiliar device. Hackers usually work from afar, so this second factor makes ...

Cleaning up after password dumps

Wednesday, September 10th, 2014

One of the unfortunate realities of the Internet today is a phenomenon known in security circles as “credential dumps”—the posting of lists of usernames and passwords on the web. We’re always monitoring for these dumps so we can respond quickly to protect our users. This week, we identified several lists ...