https://www.dailymail.co.uk/sciencetech/article-13693891/Update-Chrome-Google-critical-flaw.html
Google has rolled out a security update for Chrome, which
fixes flaws that allowed hackers to steal user data.
According to search giant, the new update includes three
significant patches, two deemed high severity and one
'critical.'
Users are urged to update their Chrome accounts immediately
by closing the browser and reopening it.
[end article quotes]
This MEANS that bad actors have been stealing all
your data and account numbers and bank numbers and
such for awhile already ...
Computers - esp Win computers - just seem to be going
all ROTTEN of late. Not only have criminal syndicates
dedicated to finding/exploiting weaknesses grown
exponentially and more and more of them are now funded
and advised by hostile governments.
I'm gonna say something you don't want to hear ...
that online biz/banking/industry will soon be
just too risky to use. The big providers will
lie to you for awhile, swear everything's good,
but very soon it will be impossible to hide.
Hey, GO to a store. VISIT your bank branch or
broker. Let them get to know your face, who
you are. We're quickly heading back to the
future here ... comp/online stuff simply
cannot be protected or safe under even the
current level of attacks.
I'd suggest LOCAL Amazon/etc storefronts where
you can peruse their catalog - and then hand
a list to a HUMAN using some much more secure,
likely non-Win, link with corporate central.
Remind you of the old Sears experience ? Well ...
As for Chrome ... there IS a non-commercial version
called Chromium which lacks most of the internal
spyware features (which can be exploited). Can be
a bit of a trial getting it for Win, but it's out
there for Linux/Unix no problem. Win users/fools
can also install a virtual-machine system like
VirtualBox and run a Linux/Unix distribution
inside it ... maybe where you'd go to do actual
online biz/banking. I'll suggest VMs that run
ON your box, not 'cloud' versions that send all
yer stuff through M$ links or such.
In comp.os.linux.misc 186282@ud0s4.net <186283@ud0s4.net> wrote:
https://www.dailymail.co.uk/sciencetech/article-13693891/Update-Chrome-Google-critical-flaw.html
Google has rolled out a security update for Chrome, which
fixes flaws that allowed hackers to steal user data.
Just a media beat-up, cashing in on a public that's temporarily
realised the implications of a software bug in the wrong place.
According to search giant, the new update includes three
significant patches, two deemed high severity and one
'critical.'
Which isn't anything that unusual, following the link to a
description of the vulnerabilities you get:
CVE-2024-6990: A critical vulnerability involving uninitialized use
in Dawn, reported on July 15, 2024. This flaw could
potentially allow attackers to exploit the browser,
leading to crashes or other malicious activities. CVE-2024-7255: A high-severity out-of-bounds read issue in
WebTransport, reported by Marten Richter on July 13,
2024. This vulnerability could enable attackers to
read sensitive information from other memory locations. CVE-2024-7256: Another high-severity issue involving insufficient
data validation in Dawn, reported on July 23, 2024.
This flaw could be exploited to inject malicious data
into the browser. https://cybersecuritynews.com/google-critical-security-update-chrome/
Google's announcement is here: https://chromereleases.googleblog.com/2024/07/stable-channel-update-for-desktop_30.html
It looks like the prevous "critical" vulnerability was in April: https://chromereleases.googleblog.com/2024/04/stable-channel-update-for-desktop_24.html
Firefox last had one in March: https://www.mozilla.org/en-US/security/advisories/mfsa2024-16/
I read about the Firefox vulnerabilites and discovery of these sort
of bugs, mainly memory access ones, is pretty routine: https://www.mozilla.org/en-US/security/known-vulnerabilities/firefox-esr/
Users are urged to update their Chrome accounts immediately
by closing the browser and reopening it.
"Update their Chrome accounts"? Journalists choose some strange
words at times.
[end article quotes]
This MEANS that bad actors have been stealing all
your data and account numbers and bank numbers and
such for awhile already ...
No, it just means they _could_ have been, if they put the work in
to exploit the vulnerability in a useful way.
Computers - esp Win computers - just seem to be going
all ROTTEN of late. Not only have criminal syndicates
dedicated to finding/exploiting weaknesses grown
exponentially and more and more of them are now funded
and advised by hostile governments.
That's been happening for a long time. Take a look at Wikileaks for
known examples from the government of the USA.
I'm gonna say something you don't want to hear ...
that online biz/banking/industry will soon be
just too risky to use. The big providers will
lie to you for awhile, swear everything's good,
but very soon it will be impossible to hide.
Hey, GO to a store. VISIT your bank branch or
broker. Let them get to know your face, who
you are. We're quickly heading back to the
future here ... comp/online stuff simply
cannot be protected or safe under even the
current level of attacks.
Sure, these things are why I never did switch to online banking, but everybody else did. Nothing's really changed now that hasn't been
happening for years, and ignored by almost everyone. Time before
last that I went to the bank I played dumb while the teller advised
me on the security of online banking if I chose to enable it. No
issue, so long as you keep your password safe, apparantly. No
thanks, if the computer at the bank gets hacked it's their problem,
if my computer/browser gets hacked (or they guess that it _could_
have been), I can be accused of fault, and I don't want to have
that argument.
I'd suggest LOCAL Amazon/etc storefronts where
you can peruse their catalog - and then hand
a list to a HUMAN using some much more secure,
likely non-Win, link with corporate central.
Remind you of the old Sears experience ? Well ...
I regularly print out product pages from a store's website and
take them into the store instead of ordering online. Some tell
me I needn't have bothered with the print-out, but otherwise you'll
ask and they'll say "You want what?... Nah mate, never heard of
that" (while it's sitting on the shelf behind them).
As for Chrome ... there IS a non-commercial version
called Chromium which lacks most of the internal
spyware features (which can be exploited). Can be
a bit of a trial getting it for Win, but it's out
there for Linux/Unix no problem. Win users/fools
can also install a virtual-machine system like
VirtualBox and run a Linux/Unix distribution
inside it ... maybe where you'd go to do actual
online biz/banking. I'll suggest VMs that run
ON your box, not 'cloud' versions that send all
yer stuff through M$ links or such.
VMs and container systems have their own history of known
vulnerabilites and past exploits.
| Sysop: | Gate Keeper |
|---|---|
| Location: | Shelby, NC |
| Users: | 926 |
| Nodes: | 20 (0 / 20) |
| Uptime: | 497227:30:08 |
| Calls: | 15,771 |
| Calls today: | 13 |
| Files: | 5,333 |
| D/L today: |
18 files (8,192P bytes) |
| Messages: | 678,482 |