Skip to main content
  1. Home
  2. Computing
  3. News

Google needs to go back to the drawing board, as Password Alert is hacked in 24 hours

Add as a preferred source on Google

Well, that didn’t take very long.

Not even a day after its debut, a proof-of-concept exploit has been posted which fools Google’s push to protect people’s passwords from phishing attempts through a new extension in Chrome.

Recommended Videos

“It beggars belief,” said Paul Moore, an information security consultant at UK-based Urity Group who wrote the exploit. “The suggestion that it offers any real level of protection is laughable.”

The Password Alert extension was supposed to be able to keep an active eye on phishing attempts by scanning databases of known threats, and running them against any pages that asked for your Google account to login.

Some were hoping the extension could usher in a whole range of companies taking advantage of similar services, especially those like Facebook and Twitter which lease out their logins to destinations all across the web.

But, just by simply removing the Javascript block which controls the warning banner that pops up when a fraudulent site is detected, Moore was able to fool the extension into thinking his set-up phishing portal was a legitimate resource.

Google responded to the problem by quickly updating its service to block that specific route of entry, but just a day after that, Moore returned with a second crack which circumvented both updates without fail.

This iteration works by refreshing the page after every character is typed in, which fools the warning system into thinking the full password was never entered in the first place.

Luckily for the rest of us, Moore is on the good guys side of this fight, and was more than willing to rub Google’s noses in its mistakes before widely publishing the details of his work so the whitehat community could provide a temporary fix to compensate.

If you ask us, Google probably needs to hit the whiteboard a little harder before they roll out crucial services like this, lest all our passwords end up in the hands of the enemy first.

Chris Stobing
Former Digital Trends Contributor
Self-proclaimed geek and nerd extraordinaire, Chris Stobing is a writer and blogger from the heart of Silicon Valley. Raised…
AI slop stories are spoiling the childhood
Grandparents are gifting AI-generated story books to kids, and it's just gross.
A child reading a book.

AI slop, the colloquial term for low-effort AI-generated content, has emerged as a huge problem across different industries. Music labels are fighting streaming services to put an AI label on such tra/cks. Publishing houses are wary of AI-written drafts. Research journals are buried under a deluge of AI-generated papers. The software industry is reeling under the pressure of vibe-coded apps brimming with security flaws. Even Apple is struggling against a tide of bug reports created using AI. Of course, the disdain against AI is pretty obvious, but there's now a new dimension to it.

Boomers are gifting AI-generated books to their grandkids.

Read more
The MacBook Air is running in short supply, despite a price hike
The memory crunch is now disrupting MacBook Air supplies
MacBook Air M5

For months, Apple seemed better protected from the memory crisis than most laptop makers. It had long-term supplier agreements, enormous purchasing power, and enough margin to absorb rising component costs. The situation has now caught up with its most popular laptop.

According to Bloomberg’s Mark Gurman, MacBook Air availability has tightened considerably across Apple’s retail network. Several configurations are showing delivery estimates stretching into late August, while some customized models may not arrive until September.

Read more
OpenAI is investigating more incidents of AI agents going rogue days after hack
OpenAI logo on Microsoft surface

It appears that the "AI agents going rogue" tale has more to it than what AI giants have revealed publicly so far. Merely days after OpenAI announced that its AI agents went rogue and hacked Hugging Face, Anthropic dropped a similar bombshell. Soon, it was discovered that not just one, but multiple services were compromised. Well, it seems there are even more layers to it.

Reuters reports that OpenAI has found more incidents of AI agents escaping their software containment environment during research. Citing sources with knowledge of the incident, the outlet notes that the AI agents didn't go beyond OpenAI's software environment and affect any external service.

Read more