Wednesday, August 7, 2013

Security Flaw In Chrome exposes Your saved Passwords

Google's Chrome browser has a security flaw that gives users easy access to see the saved passwords on the web browser. 


This will happens for passwords that you have told Chrome to save. 
How does it works?
1. Launch Chrome browser and login to google/gmail account
2. Copy below URL:
chrome://settings/passwords
3. Paste in Chrome's Address bar (Omnibox) and hit Enter

Open the Password Settings Page
password screen

Hover Mouse over one of the passwords
Chrome show

Click on Show button and your password is exposed!!!
password reveal

Google says it's not going to change anything. Justin Schuh, the head of the Chrome security team, says that the only real way to keep your Chrome account safe is to never give anyone you don't trust access to the account. 
"The only strong permission boundary for your password storage is the OS user account," he says, "So, Chrome uses whatever encrypted storage the system provides to keep your passwords safe for a locked account. Beyond that, however, we've found that boundaries within the OS user account just aren't reliable, and are mostly just theater."
This is sort of a crazy attitude. 
This was originally discovered by Elliott Kember who rightly points out:
"Today, go up to somebody non-technical. Ask to borrow their computer. Visit chrome://settings/passwords and click “show” on a few of the rows. See what they have to say."


So beware before you share your computer with anyone or rather say before saving any passwords in chrome ;)


Source: http://blog.elliottkember.com/chromes-insane-password-security-strategy

Monday, September 12, 2011

FREE Facebook T-shirt Scam - How to get rid of it

In last couple of weeks FREE Facebook T-shirt Scam has been seen circulating across posts & updates on FB:


This has been quite annoying and seems to be quite infectious. Below are simple steps to get rid from the same.


How to remove FREE Facebook T-shirt updates from my Facebook account ?


Steps:


1. Login to your Facebook Account. 
Go to https://www.facebook.com/mobile/

2. Search “Upload via Email”, underneath you get one email address. so these fake sites will send post on this email which will directly shows on your wall.
Refer Image-1 below 
3. Click on “Find out  more”
Refer Image-1 below 
4. Under Tips, you’ll get “refresh your upload email.” click on “refresh your upload email”, FB will ask to reset your fb secreat email address. Just reset.
Refer Image-2 below 
5. That's all! :).


Image-1


Image-2


Test:
http://tinyurl.com/74bnkpm

http://tinyurl.com/mdq9tb