{"id":6529,"date":"2017-02-06T20:30:32","date_gmt":"2017-02-07T04:30:32","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2017\/02\/06\/news-336\/"},"modified":"2017-02-06T20:30:32","modified_gmt":"2017-02-07T04:30:32","slug":"news-336","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2017\/02\/06\/news-336\/","title":{"rendered":"President Bannon Chrome Extension is a security problem, not a joke"},"content":{"rendered":"<p><strong>Credit to Author: Michael Horowitz | Date: Mon, 06 Feb 2017 20:05:00 -0800<\/strong><\/p>\n<p>Pretending that Steve Bannon is <em>really<\/em> the President was funny when Saturday Night Live did it on their opening bit. Then today, <a href=\"http:\/\/www.businessinsider.com\/google-chrome-extension-trump-steve-bannon-2017-2\">Business Insider wrote about a Google Chrome extension<\/a> that replaces every mention of &#8220;Trump&#8221; with &#8220;Steve Bannon&#8221; on all web pages. Funny? Not from a Defensive Computing perspective.<\/p>\n<p>Any extension that can change a specific word <strong>on every web page<\/strong> is inherently dangerous. Almost by definition, such an extension is spyware.<\/p>\n<p>Installing the President Bannon extension to the Chrome browser<\/p>\n<p>Sure enough, when you install the <a href=\"https:\/\/chrome.google.com\/webstore\/detail\/president-bannon\/ahbnplnaillhhmkglkgpcaeampaajakb\">President Bannon extension<\/a> (above) it needs permission to <em>&#8220;read and change all your data on the websites you visit.&#8221;<\/em> This is exactly what I wrote about last time (see <a href=\"http:\/\/www.computerworld.com\/article\/3161765\/chrome-os\/spyware-on-a-chromebook.html\">Spyware on a Chromebook<\/a>).<\/p>\n<p>I am not claiming that the President Bannon extension is malicious. I have not looked at the source code or sniffed any traffic it may be sending. It&#8217;s dangerous nonetheless.<\/p>\n<p>First off, no software should have this much power. And, even if its merely a <strong>joke today<\/strong>, since Chrome extensions are automatically and silently updated, nothing stops it from becoming <strong>spyware tomorrow<\/strong>.\u00a0<\/p>\n<p>You might as well have someone from American Bridge (&#8220;A major Democratic-aligned super PAC&#8221; according to Business Insider) standing over your shoulder watching everything you do in the Chrome browser.<\/p>\n<p>The President Bannon Chrome browser extension<\/p>\n<p>It doesn&#8217;t help that the <a href=\"http:\/\/bridgeproject.com\/\">website of the software developer<\/a> says nothing at all about the extension and appears to have been abandoned.\u00a0<\/p>\n<p>Or, that the description of the extension, shown below, says nothing about what it actually does.<\/p>\n<p>Exposing Steve Bannon&#8217;s role in some of the most dangerous and unconstitutional actions taken by Trump&#8217;s Administration. A white supremacist is calling the shots in Donald Trump&#8217;s White House. This extension exposes Steve Bannon&#8217;s role in some of the most dangerous and unconstitutional actions taken by Trump&#8217;s Administration.<\/p>\n<p>Business Insider should stick to business and leave computers to us nerds.\u00a0<\/p>\n<p><a href=\"http:\/\/www.computerworld.com\/article\/3166605\/internet\/president-bannon-chrome-extension-is-a-security-problem-not-a-joke.html#tk.rss_security\" target=\"bwo\" >http:\/\/www.computerworld.com\/category\/security\/index.rss<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<article>\n<section class=\"page\">\n<p>Pretending that Steve Bannon is <em>really<\/em> the President was funny when Saturday Night Live did it on their opening bit. Then today, <a href=\"http:\/\/www.businessinsider.com\/google-chrome-extension-trump-steve-bannon-2017-2\">Business Insider wrote about a Google Chrome extension<\/a> that replaces every mention of &#8220;Trump&#8221; with &#8220;Steve Bannon&#8221; on all web pages. Funny? Not from a Defensive Computing perspective.<\/p>\n<p>Any extension that can change a specific word <strong>on every web page<\/strong> is inherently dangerous. Almost by definition, such an extension is spyware.<\/p>\n<figure class=\"large \"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/images.techhive.com\/images\/article\/2017\/02\/presidentbannon.permissions-100707561-large.jpg\" border=\"0\" alt=\"presidentbannon.permissions\" width=\"700\" height=\"313\" data-imageid=\"100707561\"\/> <small class=\"credit\">Michael Horowitz<\/small><figcaption>\n<p>Installing the President Bannon extension to the Chrome browser<\/p>\n<p class=\"jumpTag\"><a href=\"\/article\/3166605\/internet\/president-bannon-chrome-extension-is-a-security-problem-not-a-joke.html#jump\">To read this article in full or to leave a comment, please click here<\/a><\/p>\n<\/section>\n<\/article>\n","protected":false},"author":4,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[11062,10643],"tags":[4314,714],"class_list":["post-6529","post","type-post","status-publish","format-standard","hentry","category-computerworld","category-independent","tag-internet","tag-security"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/6529","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=6529"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/6529\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=6529"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=6529"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=6529"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}