{"id":13778,"date":"2018-11-07T09:10:11","date_gmt":"2018-11-07T17:10:11","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2018\/11\/07\/news-7545\/"},"modified":"2018-11-07T09:10:11","modified_gmt":"2018-11-07T17:10:11","slug":"news-7545","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2018\/11\/07\/news-7545\/","title":{"rendered":"Google logins: JavaScript now required"},"content":{"rendered":"<p><strong>Credit to Author: Christopher Boyd| Date: Wed, 07 Nov 2018 16:00:00 +0000<\/strong><\/p>\n<p>Google users: In news that may sound alarming, it is now a requirement for you to enable JavaScript.<\/p>\n<p>Why? When your username and password are entered on Google\u2019s sign-in page, Google runs a risk assessment and only allows the sign-in if nothing looks suspicious. Recently, Google went about improving this analysis and now requires JavaScript in order to run their assessment. Want to use some of those comprehensive security enhancements for your account? Then <a href=\"https:\/\/security.googleblog.com\/2018\/10\/announcing-some-security-treats-to.html\" target=\"_blank\" rel=\"noopener\">JavaScript must be enabled<\/a>, or you won\u2019t be able to log in.\u00a0JavaScript is now your forever friend.<\/p>\n<h3>What is JavaScript?<\/h3>\n<p>If you use websites such as portals or social media platforms, you likely run into JavaScript all the time. It\u2019s a <a href=\"https:\/\/www.makeuseof.com\/tag\/what-is-javascript\/\" target=\"_blank\" rel=\"noopener\">programming language<\/a> used for all sorts of interactive effects in games and basic operations like logins. It ticks away in the background alongside cascading style sheets and HTML for a solid browsing experience.<\/p>\n<p>It\u2019s now a core slice of the Google login pie, and you will absolutely have to try a slice.<\/p>\n<h3>What has changed?<\/h3>\n<p>When using the Google sign-in page, you won&#8217;t get any further if you have JavaScript disabled. This could be frustrating for some users, given how much important data can be stored in a Google account. Why has the drawbridge come up? In a nutshell, to keep you safe from the many scams and attacks aimed at Google users.<\/p>\n<p>Google accounts have a whole variety of safety measures to keep would-be compromisers out. If someone manages to obtain your password and tries to sign in as you, Google runs some checks. If they flag certain unusual activity, such as logins from another country, they\u2019ll request additional verification.<\/p>\n<p>Google can\u2019t do any of this without JavaScript up and running, so moving forward you\u2019ll have to <a href=\"https:\/\/support.google.com\/accounts\/answer\/7675428\" target=\"_blank\" rel=\"noopener\">switch it on<\/a>.<\/p>\n<h3>Is this a problem?<\/h3>\n<p>I mean\u2026no, I don\u2019t think it is. JavaScript shows up in <a href=\"https:\/\/blog.malwarebytes.com\/threat-analysis\/2018\/10\/scammers-use-old-browser-trick-to-create-fake-virus-download\/\" target=\"_blank\" rel=\"noopener\">a lot of attacks<\/a>, and we don&#8217;t want anybody becoming complacent. It is, however, possible to impede your own preferred browsing behaviour unnecessarily.<\/p>\n<p>There\u2019s one school of security thinking which is a little like security nihilism. Essentially, everything is a threat and we must reduce the attack surface. Okay, fine. The problem is, for some, this turns into a game of \u201cremove absolutely everything from the device.\u201d At what point do we stop and look in wonder at our expensive, utterly non-functional box?<\/p>\n<p>You probably have JavaScript enabled right now, unless you\u2019re highly security-centric or super keen on having the fastest loading times possible. It\u2019s usually one of the most common complaints related to script blocker extensions. \u201cI blocked them, and nothing works. Now what?\u201d<\/p>\n<p>The Sun has the blocker fired directly into its heart, that&#8217;s what. If you want to strip out the functionality of browsers, there is always going to be a price to pay. For example, the earliest ad blocker\/script blocker tools often made everything nigh on unusable. Thankfully, <a href=\"https:\/\/blog.malwarebytes.com\/security-world\/privacy-security-world\/2018\/07\/mother-is-blocking-ads-so-why-arent-you\/\" target=\"_blank\" rel=\"noopener\">ad blockers have stepped up their game<\/a> and are now part of a healthy, balanced cybersecurity hygiene routine.<\/p>\n<h3>Good news, the choice is easy<\/h3>\n<p>Google estimates the impact of their new JavaScript requirement is likely to be small\u2014supposedly only 0.1 percent of their users have it switched off. At this point, they\u2019re going to have to make a choice.<\/p>\n<p>This isn\u2019t a stark \u201cone thing or the other\u201d decision. There\u2019s absolutely nothing preventing someone from enabling JavaScript purely for logins, then switching off afterwards. Yes, there are JavaScript exploits out there, but there\u2019s an exploit for pretty much everything anyway. You are unlikely to hit any sort of trouble switching it on just to sign in.<\/p>\n<p>As was mentioned on the <a href=\"https:\/\/portswigger.net\/daily-swig\/google-begins-enforcing-javascript-for-logins\" target=\"_blank\" rel=\"noopener\">Daily Swig blog<\/a>, surfers such as those using TOR are likely to be the most impacted. If you\u2019re on TOR and trying to use Google services, you may have to force yourself to switch. If you still won\u2019t use an alternate browser for Googling, perhaps<span class=\"Apple-converted-space\">\u00a0ultimately, you may have to find\u00a0another provider.<\/span><\/p>\n<p>For everyone else, this is a good thing and will help keep your accounts more secure in the long run.<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/11\/google-logins-javascript-now-required\/\">Google logins: JavaScript now required<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/11\/google-logins-javascript-now-required\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Christopher Boyd| Date: Wed, 07 Nov 2018 16:00:00 +0000<\/strong><\/p>\n<table cellpadding='10'>\n<tr>\n<td valign='top' align='center'><a href='https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/11\/google-logins-javascript-now-required\/' title='Google logins: JavaScript now required'><img src='https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/11\/shutterstock_565063075.jpg' border='0'  width='300px'  \/><\/a><\/td>\n<\/tr>\n<tr>\n<td valign='top' align='left'>Google now requires users to enable JavaScript before logging in for extra security measures. But wait, hasn&#8217;t JavaScript been used in cyberattacks? We take a look at the impact of Google&#8217;s decision.<\/p>\n<p>Categories: <\/p>\n<ul class=\"post-categories\">\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/cybercrime\/\" rel=\"category tag\">Cybercrime<\/a><\/li>\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/cybercrime\/privacy\/\" rel=\"category tag\">Privacy<\/a><\/li>\n<\/ul>\n<p>Tags: <a href=\"https:\/\/blog.malwarebytes.com\/tag\/browsers\/\" rel=\"tag\">browsers<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/google\/\" rel=\"tag\">Google<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/google-logins\/\" rel=\"tag\">Google logins<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/javascript\/\" rel=\"tag\">JavaScript<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/login\/\" rel=\"tag\">login<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/logins\/\" rel=\"tag\">logins<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/phishing\/\" rel=\"tag\">phishing<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/security\/\" rel=\"tag\">security<\/a><\/p>\n<table width='100%'>\n<tr>\n<td align=right>\n<p><b>(<a href='https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/11\/google-logins-javascript-now-required\/' title='Google logins: JavaScript now required'>Read more&#8230;<\/a>)<\/b><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/11\/google-logins-javascript-now-required\/\">Google logins: JavaScript now required<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[12014,4503,1670,20076,10871,18313,20077,3924,5897,714],"class_list":["post-13778","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-browsers","tag-cybercrime","tag-google","tag-google-logins","tag-javascript","tag-login","tag-logins","tag-phishing","tag-privacy","tag-security"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/13778","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=13778"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/13778\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=13778"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=13778"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=13778"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}