Chipp.in Tech News and Reviews

Windows, Security & Privacy, Open Source and more

Menu
  • Home
  • Windows
  • Security & Privacy
  • Gaming
  • Guides
  • Windows 11 Book
  • Contact
  • RSS Feed
Menu

Category: Security & Privacy

Security

Should you save passwords in a browser?

Posted on July 6, 2024July 6, 2024 by Martin Brinkmann

All modern web browsers include password management functionality. It makes sense on first glance to integrate the functionality; most users sign-in to services on the Internet regularly.

One of the main advantages of password managers in browsers is convenience. The browser recognizes new logins and prompts users to save the information. Similarly, it proposes to sign-in using saved data whenever a website is found in the password manager’s database.

It is handy and that is the reason why it is widely used.

Disadvantages exist as well:

  • Functionality is limited to a specific browser – Synchronization support may extend the reach, but it is still a limiting factor.
  • Automatic login functionality is limited to a browser – It cannot be used to sign-in to apps and other services that are not opened in the browser.
  • Protective features are limited — Usually to the device password or Pin.

Limited functionality

When you save a password in a browser, it is stored by it in a database on the local device.

If synchronization is enabled, the database will be synced across all devices on which the browser is installed and synchronization is enabled.

Still, it is limited to that browser. If you use multiple browsers, then you won’t be able to use the functionality there as well, unless you use import features.

The saving of passwords and automatic logins are also limited to the browser. If you need to log in to an application on the device, then you need to do so manually by copying the username and password from the browser’s password manager.

Security is limited

Security and protective features are another. Depending on the password manager, passwords may not be saved with a password. Some browsers support setting a primary password to protect the password database, but in many cases, it is not enabled by default.

Anyone with access to the PC may get access to the stored passwords of browsers. While that requires the account password for the PC in question, it may open up a can of worms in some cases.

The browser may prompt for a password or a pin when the password manager is opened and entries are inspected there. However, there is no such protection when visiting saved websites. Browsers like Chrome will fill out the passwords on the sites and sign-in users automatically.

It is even possible to show passwords in plain text by manipulating the HTML code of the website. This is not a problem if the account password is strong and you never leave the PC unattended.

Synchronization is convenient, but it moves the password database into the cloud. It is encrypted, but it adds another attack vector that would not exist if the database would be stored locally only.

How dedicated password managers compare

Here are the main differences:

  • A password is required to create a new password database — This means that it is protected by the device password and also the password the user selects during creation.
  • Additional protective features are available — This may include two-factor authentication for extra protection, customizing security features, such as the number of iterations.
  • Password managers run system-wide — You can use them to sign into apps or other services on the device, independent of any browser or program.
  • Self-hosting may be supported — Instead of relying on a server by a company, you can self-host the cloud space.
  • Open source and audits — Many browsers are not open source. Good password managers are audited regularly.

Some of the features depend on the password manager. My recommendation goes to Bitwarden and KeePass. There are numerous others that you can try.

Granted, password managers are not perfect. They cannot help you if you need to sign-in to a service on your Smart TV, but neither can browser password managers.

Closing Words

Using a password manager is highly recommended. If you use a browser password manager, make sure you configure extra security features, if needed. This may include setting up a primary password, enabling operating system protections, or using a strong device password or pin.

Standalone password managers offer more functionality. Good ones offer better security right away, more customization options, and a lot more that browser password managers do not support.

To answer the question of this article: a dedicated password manager is better in many regards, but it is still better using a browser password manager than none at all.

What about you? Do you use a password manager? If so, what is the program that you use currently and why?

Nord Security launches File Checker online tool

Posted on July 2, 2024July 2, 2024 by Martin Brinkmann

Nord Security, maker of the popular VPN service NordVPN, has published a new online tool. File Checker is a free online security tool to check files for malware.

Online virus scanners are useful to check a small number of files for viruses and other unwanted code. Google-owned Virustotal is probably the uncrowned king of these types of tools.

Here is what you need to know about the new File Checker tool:

  • It is free to use on the NordVPN website; an account is not required.
  • File Checker works on any platform.
  • Recommended file size is 50 megabytes or less, but it works with larger files. There is a limit though, as it would not scan a 160 megabytes file.

File Checker is also integrated into NordVPN’s Threat Protection feature. I did not give the feature a recommendation back then as it installed a certificate on the system that gave it a high level of control.

Threat Protection back then supported the scanning of files, but limited this to files of a size of up to 20 megabytes.

File Checker

The website provides little information on the File Checker technology. Most of the information is basic, explaining that you can get viruses through infected phishing emails or that PDF files can contain viruses.

In fact, the only information about File Checker is that it was created by NordVPN.

File Checker was developed by NordVPN, a global leader in cybersecurity with over 10 years of experience. Our experts curate a massive real-time database of threats and use advanced technologies, including artificial intelligence and machine learning, to continuously improve File Checker.

Nord Security maintains a list of threats and uses technology, including AI and machine learning, to improve it. This does not tell us anything about how good or bad the product is.

File Checker does have a few disadvantages when compared to Virustotal:

  • You can only scan individual files that are on the local device already and links. Virustotal supports this and it includes a Search for finding already scanned files.
  • Virustotal furthermore displays information about the scanned file, including details, behavioral information, and also community comments.
  • File Checker uses a single service, Nord Security’s own, to scan files for malware. Virustotal checks dozens of antivirus engines, which provides a clearer picture.

Should you use the standalone File Checker tool?

While it is commendable that File Checker is free, it is held back by the fact that it relies on a single threat database. Virustotal is the better option, as it provides results from dozens of antivirus services.

Furthermore, it is integrated in NordVPN, which means that all customers may enable this to get automatic file checking. Still, most antivirus applications support this as well.

What about you? Do you use online file scanning services to check downloaded files before you open them on your devices?

Facebook Instagram

Meta gives Europeans a pass – won’t use data for AI training

Posted on June 17, 2024June 17, 2024 by Martin Brinkmann

European Facebook and Instagram users may breathe a sigh of relief, as their public data won’t be used by Meta for AI training for the time being.

Meta published an update regarding the use of data from European users on Facebook.

Here are the highlights:

  • Meta will pause plans to train its large language models using publicly shared content from European users on Facebook or Instagram.
  • Data protection agencies from 11 countries from the EU have filed complaints against Meta.
  • Meta calls it a “step backwards for European innovation”.

The decision does not change the handling of data from users outside of the European Union. Meta will use public data from these users to train its AI systems.

Meta said that it hopes that the data protection authorities chance their stance on the issue. The company said previously that it would use public posts and comments from users over the age of 18 only for AI training. European users were the only ones to get an opt-out option.

While Meta said that it remains committed to bringing AI functionality to users from the European Union, it added that the lack of local information would make it a “second-rate experience”.

Here is an interesting idea: how about making the training opt-in? Giving Facebook and Instagram users the option to give Meta permission to use their data for AI training.

The main issue here, at least for Meta, is that it would gain access to a fraction of the data only. Opt-in systems are favored by users, as they give them full control over a feature. They are disliked by companies, as it limits the reach significantly.

Meta could counter this by giving users incentives to share their data. It will be interesting to see how this will turn out in the end. Meta said that it will “continue to work collaboratively” with the Irish Data Protection Commission.

Would you allow companies to use your public data for AI training?

AI

AI is now capable of exploiting 0-Day vulnerabilities without description

Posted on June 10, 2024June 10, 2024 by Martin Brinkmann

A team of security researchers at the University of Illinois published a study back in April 2024 that demonstrated the hacking capabilities of AI.

Using OpenAI’s GPT-4 model, they discovered that exploit code could be generated for 87% of the tested 0-day vulnerabilities.

This figure dropped to 7% if the CVE description was not provided.

Good to known: 0-day vulnerabilities refer to security issues that are very recent. Patches may not be available in all cases, and systems that are not updated are vulnerable to attacks that target these vulnerabilities.

The same research team has now published a new research document: Teams of LLM Agents can Exploit Zero-Day Vulnerabilities

It builds on the previous research. This time, the researchers wanted to find a way to improve the exploiting capabilities of AI if no description of 0-day vulnerabilities was provided.

They managed to create a system that bumped the success rate to 53% using real-world 0-day vulnerabilities that were discovered after the AI model’s data cut-off date.

Using GPT-4, the researchers switched to a team-based approach to compartmentalize attacks. Instead of relying on a single GPT-4 instance for attacks, they developed an architecture that assigned AI agents with different tasks.

The tasks are assigned by a planner AI and controlled by a manager AI. The planner AI launches other AI instances, including the manager AI and AIs for specific tasks.

This approach worked well, as it improved the the capabilities of the AI attacker. The chance of success rose from 7% when using a single AI instance to 53% under the new team-based approach.

Closing Words

AI research that focuses on security is important. Besides demonstrating the capabilities of different AI models, it may also highlight future dangers. Well-funded hackers and criminals may use AI models for illegal activities. These may range from finding new exploits to creating exploits for existing vulnerabilities.

Web-based and App-based AI interactions prevent certain activities, including hacking. This is not the case, however, for self-hosted or created AI models.

What is your take on this? Will we see more exploits that are more widely used in attacks in the future? Or will we see the rise of AI-based Anti-hacking solutions that try to counter their breathren?

Facebook

Facebook will use your data for AI training, unless you opt-out

Posted on June 2, 2024June 2, 2024 by Martin Brinkmann

Meta is notifying its users currently on Facebook about a privacy-impacting change that will to into effect on June 26, 2024.

The company says that it is expanding “AI at Meta experiences” to the user’s region. AI refers to the “collection of generative AI features and experiences” at Meta. It includes Meta AI and AI Creative Tools according to the notification.

All Facebook users are opted-in automatically. Those who do not want their data to be used for AI training need to opt-out. This opt-out is not straightforward and it appears to be a deliberate decision by Meta.

Meta Facebook AI use of data for AI training

A click on the right to object link in the notification opens the Object to Your Information Being Used for AI at Meta page.

The page offers information on the data that Meta plans to use for AI training and the data that it won’t use. In a nutshell, public data, for instance posts or photos, will be used. Private data, including private messages, won’t be used.

For the opt-out, it is necessary to provide the following information:

  • Country of residence.
  • Email address.
  • Writing an essay on “how this processing impacts you”.

There is also one optional text field that users can fill out to provide additional information.

Meta processes the information and the notification sounds as it if can accept or decline the request. Meta writes:

If your objection is honored, it will be applied going forward.

This is not the end of it though. Meta sends a confirmation code to the email address. This code needs to be entered into a form on the Facebook website to confirm the email address.

Meta then says that it will review the submission as soon as possible. It took less than a minute to receive the answer:

Hi Martin,

We’ve reviewed your request and will honor your objection. This means your request will be applied going forward.

If you want to learn more about generative AI, and our privacy work in this new space, please review the information we have in Privacy Center.

facebook.com/privacy/genai

This inbox cannot accept incoming messages. If you send us a reply, it won’t be received.

Thanks,
Privacy Operations

In case you are wondering what I wrote in the required text field. It was “I object to the use of my data for the training of AI at Meta”

Whether Meta is analyzing user requests with AI is unclear, but it seems very unlikely that a human processed the request in less than a minute after sending it.

If someone could try and write nonsense in the field, we’d know for sure.

What about you? Do you mind if your public data is used for AI training?

Google

Latest Chrome 125 security update fixes 11 unique issues

Posted on May 31, 2024May 31, 2024 by Martin Brinkmann

Google has released a new security update for its Chrome web browser for all supported platforms. The update patches 11 unique security issues in the browser. It comes days after an out-of-bounds security update for Chrome to address a 0-day security vulnerability.

While the issues do not appear to be exploited at the time of writing, it is recommended to update Chrome immediately.

This is done by loading chrome://settings/help in the browser’s address bar or selecting Menu > Help > About Google Chrome manually.

Chrome lists the installed version and will download a new version that it finds automatically on desktop systems.

Pro Tip: open a command prompt window on Windows and run winget upgrade google.chrome.exe to update Chrome without opening it.

Chrome should display one of the following versions after installation of the update:

  • Chrome for Mac or Windows: 125.0.6422.141 or 125.0.6422.142
  • Chrome for Linux: 125.0.6422.141
  • Chrome Extended Channel for Mac or Windows: 124.0.6367.243
  • Chrome for Android: 125.0.6422.146 or 125.0.6422.147

The security fixes

Google lists seven of the eleven security issues that it fixed in the Chrome update on the official releases site.

All seven have a severity rating of high. Google does not publish information about security issues that it discovered internally. The severity of the four unmentioned security issues is unknown as a consequence.

Here is what Google reveals about the listed security issues:

  • [$7000][339877165] High CVE-2024-5493: Heap buffer overflow in WebRTC. Reported by Cassidy Kim(@cassidy6564) on 2024-05-11
  • [TBD][338071106] High CVE-2024-5494: Use after free in Dawn. Reported by wgslfuzz on 2024-05-01
  • [TBD][338103465] High CVE-2024-5495: Use after free in Dawn. Reported by wgslfuzz on 2024-05-01
  • [TBD][338929744] High CVE-2024-5496: Use after free in Media Session. Reported by Cassidy Kim(@cassidy6564) on 2024-05-06
  • [TBD][339061099] High CVE-2024-5497: Out of bounds memory access in Keyboard Inputs. Reported by zh1x1an1221 of Ant Group Tianqiong Security Lab on 2024-05-07
  • [TBD][339588211] High CVE-2024-5498: Use after free in Presentation API. Reported by anymous on 2024-05-09
  • [TBD][339877167] High CVE-2024-5499: Out of bounds write in Streams API. Reported by anonymous on 2024-05-11

The security issues affect several components of the browser, including APIs, keyboard inputs, media session, WebRTC, and Dawn. Dawn is an “open-source and cross-platform implementation of the WebGPU standard” according to Google Source.

Google fixes another 0-day exploit in Google Chrome

Posted on May 24, 2024May 24, 2024 by Martin Brinkmann

Google has released quite a few security updates for its Chrome web browser in recent months. Besides the weekly scheduled security updates, Google has released updates to address 0-day vulnerabilities in Chrome.

Today, Google released another security update for Google Chrome to address a 0-day exploit. The issue affects all desktop versions of Chrome and Chrome for Android.

Chrome users may want to install the update immediately to fix the issue. Here is how that is done on desktop systems (there is no option to speed up the installation of Chrome updates on Android):

  • Load chrome://settings/help in the Chrome address bar.
  • Chrome displays the current version and runs a check for updates.

Updates will get installed automatically at this point, but you need to restart the browser manually to complete the update.

Chrome should return the following version after installation of the update:

  • Chrome for Windows and Mac: 125.0.6422.112 or 125.0.6422.113
  • Chrome Extended Stable for Windows or Mac: 124.0.6367.233
  • Chrome for Linux: 125.0.6422.112
  • Chrome for Android: 125.0.6422.112 or 125.0.6422.113

About the Chrome security vulnerability

The official release notes page lists basic information about the vulnerability only. It is CVE-2024-5274, a Type Confusion in V8 issue. Google has rated the vulnerability as high and notes that it is exploited in the wild.

V8 is the JavaScript and WebAssembly engine that Google Chrome uses.

In other words, systems with an outdated version of Chrome may be successfully attacked. It is unclear how the issue can be exploited, however.

The last update that fixed a 0-day vulnerability in Google Chrome was released just 2 weeks ago. It is the 8th 0-day exploit fix in Chrome in this year alone.

Chrome 124 0-day security update

Google fixes Chrome security issue that is exploited in the wild

Posted on May 10, 2024May 10, 2024 by Martin Brinkmann

Just days after the weekly Google Chrome security update comes another security update for the web browser. This one unscheduled, as it fixes a 0-day security issue in Google Chrome that is exploited in the wild.

Google Chrome users should update the browser immediately to protect the browser and their data. Here is how that is done:

  • Open Google Chrome on a desktop system.
  • Select Menu > Help > About Google Chrome.

The browser displays the current version and runs a check for updates. It should pick up the security update and install it automatically.

Windows users may also launch a command prompt window and run winget upgrade Google.Chrome.EXE to update the browser to the latest version.

One of the following versions should be displayed by Chrome after installation of the update:

  • Chrome for Windows or Mac: 124.0.6367.201 or 124.0.6367.202
  • Chrome for Linux: 124.0.6367.201
  • Chrome Extended for Windows or Mac: 124.0.6367.201

The Chrome 0-day security issue: what we know

Google reveals little about the security issue on the official Chrome Releases website.

[N/A][339266700] High CVE-2024-4671: Use after free in Visuals. Reported by Anonymous on 2024-05-07

Google is aware that an exploit for CVE-2024-4671 exists in the wild.

The security issue is rated high and it is a use after free in Visuals. It was reported to Google on May 7, 2024, which means that it could have been exploited at least since that date. It is unclear how this issue can be exploited.

Other Chromium-based web browsers are also affected by the issue. This means that browsers such as Microsoft Edge, Vivaldi, Brave, or Opera are all vulnerable until an update is released.

Expect updates for these browsers in the coming hours and days.

Chrome on Android does not seem to be affected by the issue, as Google has not published an update for the browser or made an announcement on the releases blog regarding the platform.

When do you update browsers?

AI

AI is capable of creating exploits from public CVEs

Posted on April 22, 2024April 22, 2024 by Martin Brinkmann

AI tools are capable of writing exploits for publicly disclosed security vulnerabilities.

A team of University of Illinois researchers analyzed the capabilities of different Large Language Models in this regard. It found out that OpenAI’s GPT-4 managed to create exploit code for 87% of the tested vulnerabilities.

The figure dropped to 7% without access to the CVE description. Other AI models, including GPT-3.5, could not create any exploits based on public CVEs.

The researchers note:

When given the CVE description, GPT-4 is capable of exploiting 87% of these vulnerabilities compared to 0% for every other model we test (GPT-3.5, open-source LLMs) and open-source vulnerability scanners (ZAP and Metasploit).

The researchers did not put other large language models to test. Google Gemini or Claude 3, for example, were not part of the test.

How the tests were conducted

The researchers selected 15 day one vulnerabilities from the Common Vulnerabilities and Exposures database for the test. All vulnerabilities were reproduced in “highly cited academic papers” according to the research paper.

The single large language model agent that the researchers created gave the AI access to tools, the CVE description, and the ReAct agent framework. Tools included capabilities to browse the Internet and activate elements, a code interpreter, and file creation.

Then agent consisted of a total of 91 lines of code according to the researchers.

AI is improving, but there are challenges

OpenAI’s GPT-4 large language model managed to create exploits for 87% of the 15 vulnerabilities. That’s a huge jump from GPT 3.5’s 0%.

The researchers have verified that — at least one — large language model is now capable of creating exploit code based on publicly available information.

While GPT-4 performed well in tests, it experienced its fair share of challenges as well. The detailed description of one vulnerability was provided in Chinese only, which the researches believe might have confused the AI, as the prompt given to it was provided in English.

The second vulnerability that GPT-4 could not crack required navigating a site using JavaScript navigation.

The researchers conclude that large language model providers and the cybersecurity community should take these capabilities into consideration, especially in regards to defensive measures.

Closing Words

The capabilities of large language models have increased significantly since the first release of ChatGPT last year. The capabilities will improve further in the coming months and years.

It is likely that threat actors will use large language models to automate processes. Exploits may be used sooner as a consequence by a wider pool of threat actors.

What is your take on this? Will we see an increase in exploit code in the coming years?

approve sign in request

You can now sign in to Microsoft accounts using Outlook

Posted on April 9, 2024April 9, 2024 by Martin Brinkmann

Microsoft’s Outlook app may now be used to sign in to Microsoft accounts and services. How useful is the new functionality?

Sign ins to accounts on the Web or locally on devices are still a major nuisance for users. If you follow security guidelines, you pick a secure unique password for each service, and preferably, enable two-factor authentication as well.

Passkeys promise an improvement, but most Internet services and operating systems do not support this yet fully.

Microsoft has now enabled authentication functionality in its Outlook app to improve the login flow and make it more secure for certain setups. Classic two-factor authentication options such as text messaging are insecure, as the code is submitted in clear text.

Using the Outlook app for authentication

The main idea here is to use Outlook to verify the sign in. It works similarly to Authenticator apps, including Microsoft Authenticator.

Here is the entire process:

  1. You submit your username and password to sign in to your Microsoft account. This can be in Microsoft 365, OneDrive, Teams, or even Microsoft Windows.
  2. Microsoft displays a number on the next screen and prompts you to check your Outlook app.
  3. You need to tap on the right number, out of three presented to you, in the Outlook app.
  4. You then need to allow this using biometric or PIN verification.

Why is Microsoft introducing the functionality?

Microsoft Authenticator offers this functionality already. Why then is Microsoft introducing it in Outlook? Microsoft does not say in the official announcement.

The most likely reason is reach. Microsoft Authenticator has over 100 million downloads on Google Play, which is impressive for such an app. Microsoft Outlook, however, has over 1 billion downloads on Google Play alone. While a good portion of these downloads are not active, it is still likely that the Outlook app has a bigger reach than the Authenticator app.

Microsoft can reach ten times as many users in Outlook. To make things even simpler, the company is enabling the new functionality automatically in the latest Outlook app.

Microsoft says:

This sign-in verification functionality will be automatically enabled when you use the latest version of the Outlook app.  

In other words, if you use the Outlook app on Android, it sounds as if you have two factor authentication enabled automatically for your account. I have the app installed, but cannot verify this at this point because of Microsoft’s rollout of the feature.

There is a chance that this functionality becomes available only to users who have two-factor authentication enabled already for their accounts. This would improve the process, if they use weaker verification options, such as text messages.

Closing Words

Microsoft’s Authenticator app offers advantages over the Outlook implementation. Microsoft notes that users of the Authenticator app can continue using it. The app supports adding different accounts as well, while the Outlook app is limited to securing Microsoft accounts.

Microsoft says that the functionality is rolling out to all Android users. An iOS update is in development already and will be launched in the future.

Do you use two-factor authentication to improve account security?

  • Previous
  • 1
  • …
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • Next

Support This Site

If you like what I do please support me!

Any tip is appreciated. Thanks!
  • August 29, 2026 by Martin Brinkmann Another Windows Issue: Microsoft Defender Antivirus is turned off notification, but it is actually enabled
  • August 28, 2026 by Martin Brinkmann Brave Accounts and Email Aliases launch
  • August 25, 2026 by Martin Brinkmann Microsoft confirms: Latest .NET updates may cause printing issues
  • August 24, 2026 by Martin Brinkmann The Chrome Web Store has a fake VPN extensions problem
  • August 23, 2026 by Martin Brinkmann Microsoft is worsening classic Media Player to get users to upgrade

About

We talk, write and dream about Technology 24/7 here at Chipp.in. The site, created by Martin Brinkmann in 2023, focuses on well-researched tech news, reviews, guides, help and more.

Legal Notice

Our commitment

Many websites write about tech, but chipp.in is special in several ways. All of our guides are unique, and we will never just rehash news that you find elsewhere.

Read the About page for additional information on the site and its founder and author.

Support Us

We don't run advertisement on this site that tracks users. If you see ads, they are static links. Ads, including affiliate links, never affect our writing on this site.

Here is a link to our privacy policy

©2026 Chipp.in Tech News and Reviews