cancel
Showing results for 
Search instead for 
Did you mean: 

Chrome Browser on Windows - New Threat

SpendLessTime
Aspiring Hero
Posts: 2,493
Thanks: 652
Fixes: 58
Registered: 21-09-2009

Chrome Browser on Windows - New Threat

This steals your username/password for the PC you are using.

From https://www.theregister.co.uk/2017/05/17/chrome_on_windows_has_credential_theft_bug/

Google's Chrome team is working to fix a credential theft bug that strikes if the browser is running on Microsoft Windows.The bug is exploited if a user is tricked into clicking a link that downloads a Windows .scf file (the ancient Shell Command File format, a shortcut to Show Desktop since Windows 9Cool.

..

Here's where the Windows flaw comes in: merely viewing the folder will trigger Windows to try and retrieve an icon associated with the .scf file.

To retrieve the icon, the user's machine will present credentials to a server – their user ID and hashed password on a corporate network, or the home group's credentials if it's a personal machine.

Solution until bug is fixed is

Chrome users should get to their Advanced settings, and make Chrome ask where downloaded files are to be saved: that way, the .scf extension will be revealed.

15 REPLIES
Community Veteran
Posts: 17,486
Thanks: 1,482
Fixes: 17
Registered: 06-11-2007

Re: Chrome Browser on Windows - New Threat

Didn`t someone flag up CHROME as a nosey parker anyway... just after it was released, as the latest and greates, all singing and all dancing, wallpapering, new kitchen and bathroom refurbishment of a browser ?

 

Well, that first, initial description, put me off it, and it has never been installed on my computer...

VileReynard
Seasoned Pro
Posts: 10,828
Thanks: 250
Fixes: 10
Registered: 01-09-2007

Re: Chrome Browser on Windows - New Threat

Well, I put Cromium on my PC, but only because it runs flash better than Fire Fox.

I virtually never have any use for it.

TheRoadCrew
Rising Star
Posts: 62
Thanks: 10
Fixes: 3
Registered: 14-05-2017

Re: Chrome Browser on Windows - New Threat

@shutter you may find Iridium is more to your liking than Chrome; you may even like its default search engine (Qwant)

Community Veteran
Posts: 17,486
Thanks: 1,482
Fixes: 17
Registered: 06-11-2007

Re: Chrome Browser on Windows - New Threat

Hmm.... thanks for the "Heads up"... never heard of it....but.... the first words of the description put me right off....

 

"The Iridium Browser is based on the Chromium code base."   sure it goes on about how secure it is... but then   so did Google with Chrome.... until someone found out otherwise.....

 

 

Community Veteran
Posts: 3,274
Thanks: 339
Fixes: 12
Registered: 24-10-2013

Re: Chrome Browser on Windows - New Threat

don't confuse Chromium with Chrome though.
not the same thing.
Community Veteran
Posts: 17,486
Thanks: 1,482
Fixes: 17
Registered: 06-11-2007

Re: Chrome Browser on Windows - New Threat

True... but how am I to know the difference ?   chrome is a short word for chromium... and maybe the promotors of the iridium site are trying to confuse people using the "posh" word  for the same thing...

 

 

Or... reverse that thought.... Google is using the short version to be more trendy... to be more acceptable to the younger element.. 

 

VileReynard
Seasoned Pro
Posts: 10,828
Thanks: 250
Fixes: 10
Registered: 01-09-2007

Re: Chrome Browser on Windows - New Threat

I did wonder... Cheesy

Community Veteran
Posts: 3,274
Thanks: 339
Fixes: 12
Registered: 24-10-2013

Re: Chrome Browser on Windows - New Threat


shutter wrote:

True... but how am I to know the difference ?   chrome is a short word for chromium... and maybe the promotors of the iridium site are trying to confuse people using the "posh" word  for the same thing...

 

 

Or... reverse that thought.... Google is using the short version to be more trendy... to be more acceptable to the younger element.. 

 


chromium is the open source project that various browsers are based on.
chrome uses (or did, i believe they are moving away from a chromium base) chromium as a base.

just to confuse matters, chromium was started by Google originally.

how to tell the difference?
one browser happens to be called Chrome and has google services built-in.
others aren't called chrome and may or may not use the chromium base (which doesn't have google services built-in).

Community Veteran
Posts: 17,486
Thanks: 1,482
Fixes: 17
Registered: 06-11-2007

Re: Chrome Browser on Windows - New Threat

@chenks76 so .... at the moment.... its "kinda" the same thing...... but .... not "kinda" the same thing...

 

As  in  ... I have a Chrome bumper on my car.........   but you have a Chromium bumper on your car   ..... ( metaphorically speaking of course ) ....  ! 

 

Yeah... not to be confused....

Community Veteran
Posts: 3,274
Thanks: 339
Fixes: 12
Registered: 24-10-2013

Re: Chrome Browser on Windows - New Threat

well no not really the same thing.

chrome is a browers that uses chromium open source code as a base, as do many other browers.
chrome then adds on stuff on top of that base code, as would other browsers that use the open source code.

the chromium browser is basically just that open source code with nothing added on.
Community Veteran
Posts: 17,486
Thanks: 1,482
Fixes: 17
Registered: 06-11-2007

Re: Chrome Browser on Windows - New Threat

Pot of black paint......    =   Really Black

 

Pot of black paint with 10% red  paint mixed in.... =   Not Really Black... ( but to the naked eye still looks black )..

Browni
Aspiring Hero
Posts: 2,178
Thanks: 746
Fixes: 45
Registered: 02-03-2016

Re: Chrome Browser on Windows - New Threat

Or pot of black paint with 10% red paint carefully poured on top (think of it as a skin.)

It looks red but is actually black underneath.
I must have been really bad in a previous life as this was my 3rd ISP in a row that used lithium.
Now you're stuck with me because my new ISP doesn't run a forum Cheesy
Community Veteran
Posts: 3,274
Thanks: 339
Fixes: 12
Registered: 24-10-2013

Re: Chrome Browser on Windows - New Threat

or

Audi Q3
Skoda Yeti
VW Tiguan

all made in the same factory with the same "core", but with different badges, skins and features.

but back to the original point chromium /= chrome.
chrome is chromium + added google "features"

St3
Aspiring Champion
Posts: 2,603
Thanks: 495
Fixes: 4
Registered: 13-07-2012

Re: Chrome Browser on Windows - New Threat

Nothing is safe on the internet these days, i dont ever have problems using chrome and who cares if it spys on you.... we are all being watched anyways.