Security News

WordPress to automatically disable Google FLoC on websites
2021-04-18 19:12

WordPress announced today that they are treating Google's new FLoC tracking technology as a security concern and may block it by default on WordPress sites. After Google began testing FLoC this month in Google Chrome, there has been a consensus among privacy advocates that Google's FLoC implementation just replaces one privacy risk with another one.

Google is adding its Dinosaur Game as an iPhone widget
2021-04-17 17:34

Google is bringing its Dinosaur Game to Apple iPhones as an iOS widget that you can add to your home screen. When Google Chrome cannot access the Internet, it displays a Dinosaur Game where you jump and duck under obstacles while waiting for the Internet to be fixed.

Google Chrome's new feature lets you easily share selected text
2021-04-17 13:18

Google makes it easy to share text with friends and colleagues with a new Chrome 90 feature that lets you create links to selected text on a web page. This new feature is rolling out now in Chrome 90 and is built on top of Google's "Scroll-To-Text using a URL fragment" feature that they introduced earlier this year and is only available in Chrome.

Amex cards removed from Google Pay due to expired certificate
2021-04-16 13:49

An expired certificate has led to the repeated removal of linked American Express credit cards from user's Google Pay accounts. Starting yesterday, Google Pay users with linked American Express cards began receiving emails that Google removed their linked Amex card.

Google Project Zero Cuts Bug Disclosure Timeline to a 30-Day Grace Period
2021-04-16 12:57

Google Project Zero will now give organizations a 30-day grace period to patch zero-day flaws it discovers in a new disclosure policy revealed this week aimed at speeding up the time it takes for patches to be adopted. Now research group is changing this tactic slightly, saying it will delay disclosure of the technical details of the vulnerability until 30 days after a patch is issued if that patch is created within the 90-day period, according to a blog post by Project Zero's Tim Willis posted Thursday.

Watchdog thinks Google tricked Australians into giving up data, sues. Judge semi-agrees
2021-04-16 11:30

Australian federal court sent a message to Big Tech about its willingness to act on privacy violations when it ruled today that Google had "Partially" misled consumers about collecting mobile phone personal location data. For Google to not collect a device's location data, the user needed to let their wishes be known in both the "Location History" and the "Web & App Activity" setting segments.

Watchdog thinks Google tricked Australians into giving up data, sues. Judge semi-agrees
2021-04-16 11:30

Australian federal court sent a message to Big Tech about its willingness to act on privacy violations when it ruled today that Google had "Partially" misled consumers about collecting mobile phone personal location data. For Google to not collect a device's location data, the user needed to let their wishes be known in both the "Location History" and the "Web & App Activity" setting segments.

Google Project Zero Announces 2021 Updates to Vulnerability Disclosure Policy
2021-04-16 10:47

Google's Project Zero cybersecurity research unit on Thursday announced that it's making some changes to its vulnerability disclosure policies, giving users 30 days to install patches before disclosing the technical details of a flaw. Project Zero has announced three major changes to its vulnerability disclosure policy in 2021, compared to 2020.

Google Broke Australian Law Over Location Data Collection: Court
2021-04-16 08:28

Google violated Australian law by misleading users of Android mobile devices about the use of their location data, a court ruled Friday in a landmark decision against the global digital giant. The federal court found that in 2017 and 2018 Google misled some users of phones and tablets featuring its Android operating system by collecting their personally identifiable location information even when they had opted out of sharing "Location History" data.

Google Chrome 90 released with HTTPS as the default protocol
2021-04-14 22:10

Google has released Chrome 90 today, April 14th, 2021, to the Stable desktop channel, and it includes security improvements, a new AV1 encoder, and the default protocol changed to HTTPS. Chrome 90 fixes 37 security bugs, including a zero-day used at the Pwn2Own competition and publicly released Monday on Twitter. Today, Google promoted Chrome 90 to the Stable channel, Chrome 91 as the new Beta version, and Chrome 92 will be the Canary version.