Infostealers Already Cracking Chrome’s Latest Updates

Malware
(Image credit: Shutterstock)

Despite enthusiast media sources celebrating Google’s attempts to route hacking groups in last month’s updates to the Chrome browser, new posts on infostealer forums seem to show that malware peddlers are now keeping up with the tech giant’s latest encryption updates with minimal issue. 

Early last month, Google released Chrome 80, which added the AES-256 encryption algorithm to the browser in an attempt to prevent hackers from stealing user credentials. Prior to this, the browser had simply used the data protection API built into Windows to protect sensitive user data. AES-256 was meant to combine that data protection API with the AES standard to make information more secure, but even with a minor hacker panic shortly after release, it seems that the added security isn’t panning out quite as the tech giant had hoped.

Latest Videos FromTom's Hardware

Michelle Ehrhardt is an editor at Tom's Hardware. She's been following tech since her family got a Gateway running Windows 95, and is now on her third custom-built system. Her work has been published in publications like Paste, The Atlantic, and Kill Screen, just to name a few. She also holds a master's degree in game design from NYU.

  • bit_user
    It's a good article, but it'd be more compelling if you could make it more real. If you could give some examples of what sorts of attacks, exploits, and thefts are accomplished with these tools, I think it would help readers better understand their stake in the matter.

    Thanks.
    Reply
  • Math Geek
    my guess is like WEP cracking, the encryption itself is not the problem, but rather how it is handled that gives away the key needed to snoop.

    i tried to look into this more but so far not really found any technical explanation of how it's working.
    Reply
  • bit_user
    Math Geek said:
    i tried to look into this more but so far not really found any technical explanation of how it's working.
    Perhaps the exploits they're using are unpublished?
    Reply
  • Math Geek
    that's possible as well. could still be unpublished vulnerability being exploited.

    i emailed a guy i know to see what he has to say if he can. he works pretty high up in the dod cyber defense world. he'll point me in the right direction if he can.
    Reply