Google shuts off antiphishing feature in Firefox 2.0

Wednesday, January 21st, 2009

Although the two most-recent builds of Firefox 2.0, labeled 2.0.0.19 and 2.0.0.20, have omitted the defense, earlier editions of the browser were still able to query Google for a list of sites suspected of hosting identity theft scams. But Google is now shutting down the blacklist, said Mike Beltzner , ...

Symantec Gets Good Vibes From Virtualized Browser

Wednesday, January 14th, 2009

Security vendor Symantec is using new virtual machine technology to protect Web surfers from online attack. Called Vibes, the software bounces between three different virtual machine sessions, depending on what the user is doing on the Web. When Vibes spots the SSL (Secure Sockets Layer) protocol used for secure Web transactions, ...

Browser Bug Could Allow Phishing Without Email

Monday, January 12th, 2009

A bug found in all major browsers could make it easier for criminals to steal online banking credentials using a new type of attack called "in-session phishing," according to researchers at security vendor Trusteer. In-session phishing (pdf) gives the bad guys a solution to the biggest problem facing phishers these days: ...

Google’s Browser Security Handbook

Sunday, January 4th, 2009

This document is meant to provide web application developers, browser engineers, and information security researchers with a one-stop reference to key security properties of contemporary web browsers. Insufficient understanding of these often poorly-documented characteristics is a major contributing factor to the prevalence of several classes of security vulnerabilities. Although all browsers ...

All Major Browsers Vulnerable To Clickjacking

Monday, September 29th, 2008

Security research sites are buzzing about a new attack description called "clickjacking." The descriptions are still pretty vague, but they are scary enough that US Cert has weighed in and browser vendors are reported to have patches in the works. The basic description of the attack is that it allows the ...