If you're running a load of Chrome extensions, you may want to pay attention to a research study set to be presented at the Usenix Security Symposium in San Diego tomorrow. As PC World reports, researchers at the University of California at Berkeley discovered that many extensions engage in "a variety of affiliate fraud, credential theft, advertising fraud and social network abuse." These extensions don't behave badly right after being installed; instead, illicit activity is triggered by specific kinds of web content.
The study examined 48,000 Chrome extensions and found 130 to be "outright malicious." 4,712 extensions were classified as suspicious, but the PC World story doesn't call out any of the offenders by name. It does, however, note that millions of folks have downloaded some of the questionable extensions. More details will presumably be released during tomorrow's presentation.
Google worked with the researchers during the study, and it's already taking action based on the findings. The firm has reportedly made it more difficult to "sideload" applications that aren't available via the official Chrome Web Store. Extensions offered through the Web Store should be thoroughly vetted, and Google will presumably be paying closer attention to the behaviors uncovered by the study. Affiliate fraud is apparently being addressed with changes to Google's extension policies.
|1. Ryszard - $603||2. Hdfisise - $600||3. Andrew Lauritzen - $502|
|4. Redocbew - $350||5. the - $306||6. SomeOtherGeek - $300|
|7. chasp_0 - $251||8. Ryu Connor - $250||9. mbutrovich - $250|
|10. YetAnotherGeek2 - $200|
|In the lab: FLIR's One thermal camera||20|
|Black Friday deals: Dell's U3415 curved monitor for $650 and more||20|
|Abu Dhabi government fund may be shopping GlobalFoundries||38|
|Asus goes for the gold with its 20th Anniversary GTX 980 Ti||6|
|MSI's Eco motherboards let owners fine-tune power consumption||6|
|Gigabyte's Z170X-Gaming G1 motherboard reviewed||14|
|Star Wars Battlefront video review||38|
|Club 3D active adapters convert DisplayPort 1.2 to HDMI 2.0||22|
|Phanteks' Power Splitter lets two systems run on one PSU||45|
|This is the answer to SSK's question on the Firefox news post.||+33|