On July 24, 2024, Google experienced a bug that affected Chrome Browser users around the world. The issue prevented users from accessing or saving passwords using the Chrome Password Manager for nearly 18 hours, and was was traced to the M127 version of the Chrome Browser on Windows platforms.
Google identified the problem as a change in product behaviour that lacked proper safety precautions. Engineers quickly rolled out a fix, advising users to restart their browsers to resolve the problem.
In response to these incidents, Google has reaffirmed its plans to protect user data and improving security measures, so this doesn鈥檛 happen again. The company is working closely with cybersecurity experts to analyse the incidents and refine its security protocols.
听
What Did This Teach Users On Password Safety?
听
Chelsea Hopkins, Social Media and PR Manager at Fasthosts commented, 鈥淭his Google error has been a lesson in proper password management, especially for smaller businesses who may have the vast majority if not all of their passwords saved exclusively in Google Password Manager.鈥
This bug comes not long after the global Crowdstrike/Microsoft outage. Whether or not they are linked, they both remind us that the digital world will also have setbacks, and that cybersecurity is more important than ever.
Hopkins commented, 鈥淭his 鈥渙utage鈥 is also a point in favour of passwordless accounts, something which Google themselves are promoting and are in fact already using as the default option for new personal Google accounts. This new method of authentication links your device to the account you鈥檙e trying to access, skipping the need for passwords entirely.
鈥淎 passkey is created for your device which is stored locally and heavily encrypted, making it extremely secure, and you鈥檒l only need to use your already existing pin, FaceID, or fingerprint scan to log in to all of your accounts. Businesses large and small should definitely be looking into switching to passwordless options, and this latest Google error should be your wake-up call to do so.鈥
听
Google Workspace Authentication Flaw
听
In a separate incident, Google Workspace faced a security flaw that allowed unauthorised account creation without email verification. This flaw let attackers impersonate legitimate domain owners and gain access to third-party services integrated with Google鈥檚 authentication system. The breach was identified after a user reported an unauthorised Workspace account creation. Google said, 鈥淚n the last few weeks, we identified a small-scale abuse campaign whereby bad actors circumvented the email verification step in our account creation flow for Email Verified (EV) Google Workspace accounts using a specially constructed request.
鈥淭hese EV users could then be used to gain access to third-party applications using 鈥淪ign In with Google鈥. Within 72 hours of discovery, Google fixed the issue. We have subsequently added additional detection to protect against such malicious activities.鈥
听
More from News
- How Does Google Intend On Producing 15 Million AI Chips Over The Next Two Years?
- TikTok Parent ByteDance Has Officially Passed The $4 Billion Mark In AI Revenue
- Russia鈥檚 Latest Move Against Pavel Durov Shows That Telegram Is No Longer Just A Messaging App
- Experts React To The UK鈥檚 Decision To Make Tech Subjects Compulsory In Schools
- Microsoft Has Confirmed Copilot鈥檚 Super App Will Launch Soon 鈥 But What Is It For?
- G2A.COM鈥檚 Autonomous AI Agent Dave Helps Sellers Resolve 14,400 Support Tickets In 63 Days
- Why One MedTech Company Chose a Computer Graphics Conference To Launch Its Next AI Platform
- 75% Of CEOs Don鈥檛 Think Marketing Drives Growth 鈥 What Are They Missing?
Password Managers For Safety
听
Google does have a password manager, so a further step to take is to refrain from storing all passwords in one place. Using 2 or 3 password managers, like 1Password and NordPass, help safely store passwords without having to rely on one manager.
Tim Hall, CTO at managed IT services provider Boxxe advised, 鈥淩emembering lots of passwords and making sure they鈥檙e strong is hard work, but using a Password Manager can cut the number of passwords you have to remember to just one.
鈥淭he Password Manager will handle the rest, from coming up with new passwords that are long and cryptic, to storing them securely online, and auto-filling them on forms when you need them.
鈥淓ven if a hacker does gain access to your password through a breach, two factor authentication will keep them out of your account by requiring a second form of identification.
鈥淭his can be in the form of SMS, email and app-generated codes, or biometric verification through fingerprint for example.
鈥淲hile it does make the sign-in process longer, this is a vital safeguard. You should always look to enable this feature on your most important online accounts, such as email, online banking and cloud backup services.鈥
听
How Can Startups Stay Protected?
听
Startups need to make sure their sensitive data is safe. Ev Kontsevoy, CEO at Teleport, on cybersecurity measures for startups鈥 passwords: 鈥淕enerally speaking, any startup wanting to protect the data in their applications and modern infrastructure should not use passwords, or really any outdated static credentials for identity authentication, including browser cookies, API keys, etc.
鈥淎 lot of attention gets paid to software vulnerabilities, but most successful data breaches still come from social engineering and phishing attacks. If one engineer makes a mistake and a password ends up in the wrong place, that鈥檚 an open door for a hacker to access a company鈥檚 infrastructure and pivot laterally across different parts without anyone knowing otherwise.鈥
鈥淎 more secure approach is to instead base employees鈥 identities on real world attributes. Effectively, this means an employee鈥檚 identity becomes based on the sum of their biometrics, the hardware identity of their machine, and a PIN code.
鈥淭hat should be the basis of what companies use for authentication and authorisation. There are already examples of this in some technology ecosystems. For example, to download an app on the iPhone, you need 1) facial recognition, 2) device recognition, and 3) your Apple ID code. The time has come to implement these principles in modern infrastructure in order to better protect sensitive data.鈥
