Google is Indonesiataking a big step to fight phishingattempts on its users.
In a poston the company’s security blog, Google’s Product Manager of Account Security Jonathan Skelker announced that the search giant will begin to block account sign-ins from embedded browsers within applications.
The problem with embedded browsers, as Skelker lays out, is that it leaves Google’s users susceptible to phishing attacks from bad actors.
Previously, third-party developers could add web browser instances, like the Chromium Embedded Framework, to their apps. This allowed users to log into a service with their existing Google account without having to sign-up for a fresh account on a brand new platform.
While embedded browsers may have made it easy for an app user to sign-up or login, it also made it just as simple for a hacker to carry out a man-in-the-middle phishing attack. Malicious actors could use embedded browser frameworks to essentially eavesdrop on an unsuspecting user and steal their login credentials.
Unfortunately, Google can’t differentiate between legitimate sign-ins and a phishing attack through embedded browser frameworks. Because of this, the company has decided to ban this login method outright.
The company is urging developers using embedded browsers to switch to browser-based OAuth authentication. Basically, when a user wants to login to a third-party app using their Google account, the app would open up the Google sign-in page through their mobile browser. This way users can view the URL of the site to ensure this is a legitimate Google page and not a phishing website imposter.
Google saysit will begin blocking sign-ins from embedded browser frameworks in June.
Topics Apps & Software Cybersecurity Google
Essex Girl by Zakia UddinDiego, Frida, and Me by Molly CrabappleStory Time! by Sadie SteinTennessee Williams, Through the Eyes of W. Eugene SmithSugar Rush: Letter from Cape Town by Anna HartfordHappy Birthday, Jack Kerouac by Sadie SteinDFW: the Trading Card, and Other News by Sadie SteinBlurring the Lines: An Interview with Michelle Orange by Michele FilgateFestival Guide: A List of Don’ts for the Lady Music Writer by Natalie ElliottBlurring the Lines: An Interview with Michelle Orange by Michele FilgateHouse of Poesy: At the Grolier Poetry Book Shop by Rhoda FengIndian Comics, Professor Nabokov, and Other News by Sadie SteinAlex Katz, Paris Review, 1991 by The Paris ReviewDating the Iliad, and Other News by Sadie SteinPainting More Animals on Rocks by Sadie SteinFestival Guide: A List of Don’ts for the Lady Music Writer by Natalie ElliottThere and Back Again by Sadie SteinFestival Guide: A List of Don’ts for the Lady Music Writer by Natalie ElliottElijah Returns by Max RossEliot’s Pen, Fabio’s Mane, and Other News by Sadie Stein 'Parks and Rec' predicted the Cubs' win Behold Chicago's joyous insanity after Cubs take the World Series You won't see a supermoon like this for decades People are heartbroken nobody wanted to pet this sad pit bull Aziz Ansari, Jimmy Fallon invest in Momofuku's delivery Scottish boy pulls the ultimate Facebook prank on unsuspecting mother Internet mourns as $265,000 McLaren car demolished in crash Watch David Ross hit a World Series home run in the last game of his career 'Doctor Strange' movie review: Film is a classic stoner movie Dorm neighbors exchange honest notes about too The ecstasy and the agony of World Series fandom, expressed at the game A prophetic Twitter user predicted this exact World Series Game 7 way back in 2014 Here are a bunch of grown men crying over the Cubs World Series win Dudes posing as pros in North Korean golf match could've played anyway Simon Pegg offered to drop pants for Weibo followers, changed his mind Twitter MD for South East Asia and MENA Parminder Singh quits Cat trying to catch baseball on TV screen should be World Series MVP The Chicago Cubs won the World Series and everyone is crying about it This one chart shows the impending doom that is holiday music Donald Trump has taken over the internet