Vendredi, 05 Août 2011 03:45
Security Researchers Demonstrate Hacking Google’s Chrome OS
When Google first mentioned its Google Chrome OS software several years ago, one of the selling points was the promise that it would come with better built-in security compared to other operating systems. The Chrome OS has commercially been available for a few months now and security researchers have already figured out how to hack it. Two researchers told a crowd that they had used web-based hacker tricks to compromise the security of the Chrome OS at today’s Black Hat security conference. The Chrome OS is the software that powers the recently launched Chromebooks from a variety of vendors. The hacks gave the researchers the ability to access a user’s email, Google Docs, contacts, and Google Voice messages. If Google doesn’t patch the variety of flaws or if the researchers uncover more flaws, then hackers could have a field day accessing data on Chromebooks everywhere. Two researchers at White Hat Security’s Threat Research Center, Matt Johanson and Kyle Osborn, said in their talk that they had spent months doing research on the Chrome OS. They ended up finding a flaw in ScratchPad, which is a preinstalled extension to the Chrome OS that lets people take notes and save them to cloud-based Google Docs. On stage at the Black Hat security conference, the researchers showed both videos of the hacked documents and live demos as well. “You basically grab and download someone’s contacts like this,” Osborn said, demonstrating the deed on a big screen. A Google spokesman said the following in a statement regarding the demonstration: “This conversation is about the web, not Chrome OS. Chromebooks raise security protections on computing hardware to new levels. They are also better equipped to handle the web attacks that can affect browsers on any computing device, thanks in part to a carefully designed extensions model and the advanced security available through Chrome that many users and experts have embraced.” Google also recently published information about writing more secure extensions to the Chrome OS, and it explained why it thinks the Chrome OS is more secure. With Chromebooks, there is no data stored on the device and everything takes place essentially in the cloud and is accessible via the Chrome web browser. By attacking browsers with known exploits such as cross-site scripting, cross-site requests, and “clickjacking,” hackers can get around the Chrome OS’s security protections and access sensitive data. The researchers say they can do high-speed scans of intranets via the hack and can view active host Internet Protocol addresses (which let them figure out what websites you’re looking at). They say they also have the ability to take over a user’s Google account by stealing session cookies, which can contain user password data. The Chrome OS isn’t unique in having these types of vulnerabilities either, other OSes are also subject to similar attacks. Google was informed about the vulnerabilities and addresses some of them including the ScratchPad flaw, but the researchers mentioned some of the underlying weaknesses still remain. The demonstration is just a reminder that the shift toward cloud computing won’t resolve all the common security problems that today’s computers have. Authors:
Read 2255 times
Published in
News Technologique-Tech News
More in this category:
« Peek Inside the Lamborghini Factory
Could An SSD Be The Best Upgrade For Your Old PC? »
Last WebBuzz
WebBuzz du 04/12/2015: Animation stroboscopique de Scultures: Blooms-Blooms Strobe-Animated Sculptures
Read 10619 times
WebBuzz du 03/12/2015: Le challenge mobil 1: 240cm avec Jenson button-Mobil 1 challenge 240 cm with Jenson button
Read 10827 times
WebBuzz du 02/12/2015: Carpes et poissons chat à Tchernobyl-Chernobyl catfishes and carps
Read 11580 times
WebBuzz du 01/12/2015: La porte des étoiles par le groupe playmid-The Playmid's star gate
Read 11831 times
WebBuzz du 30/11/2015: Vie sauvage en artique filmé par drone-Wild life in artic recorded by a drone
Read 11313 times
WebBuzz du 27/11/2015: Les migrants de Calais: la réalité-The truth about Calais emigrants
Read 8463 times
WebBuzz du 26/11/2015: Un batteur vole la veddette-Best drummer ever
Read 5927 times
WebBuzz du 25/11/2015: Une cheminée s'écroule sur une pelleteuse-A chimney collapsed on a excavator
Read 10256 times
WebBuzz du 24/11/2015: Un cargo perd son ancre-A freighter loose its anchor
Read 6047 times
WebBuzz du 23/11/2015: Destruction du super star destroyer en LEGO-Giant Star Wars LEGO Super Star Destroyer Shattered
Read 6299 times