Chipp.in Tech News and Reviews

Windows, Security & Privacy, Open Source and more

Menu
  • Home
  • Windows
  • Security & Privacy
  • Gaming
  • Guides
  • Windows 11 Book
  • Contact
  • RSS Feed
Menu

Category: Security & Privacy

Firefox 143.0.3 is out with security fixes and more

Posted on September 30, 2025September 30, 2025 by Martin Brinkmann

Mozilla released a new point update for its Firefox web browser today. Firefox 143.0.3 is a security update that fixes also some non-security issues in the open source browser.

The new update is available already via the browser’s automatic update feature. Existing users may speed up the installation of the update by selecting Menu > Help > About Firefox. This opens a small window in the browser that displays the current version and a check for updates.

Firefox should pick up the update automatically at this point, but you need to restart the browser once to complete the installation. Opening the page again after installation should reveal the new version.

The official security release notes reveal that Mozilla addressed two security vulnerabilities in the release. Both have a severity rating of high. They affect the JavaScript engine and the Canvas2D component of the browser. Mozilla makes no mention of exploits in the wild, but it is still recommended to update quickly.

The non-security release notes list six issues that Mozilla fixed or improved in the release. Probably the most noteworthy is a fix for extension not updating via the add-ons manager of the browser.

Another issue fixes a Firefox crash that could happen when certain extensions are installed. These caused a storage issue that could lead to Firefox crashing on start of the browser.

Firefox users who noticed long delays when opening certain websites may also see improvements after installing Firefox 143.0.3. Mozilla reduced the delays, which happen on certain websites if the network blocks UDP connections.

The three remaining fixes address minor problems in Firefox, such as Firefox View sections not collapsing or expanding as expected. You can check out the full release notes on Mozilla’s website.

Who would have thought? Customers of Samsung fridges are not happy about ads their smart fridges started to show

Posted on September 25, 2025September 25, 2025 by Martin Brinkmann

Do fridges, toasters and other household appliances may come with “smart functionality” or wireless connectivity these days. In the case of some, TVs for instance, the functionality may also be used to display advertisement to users and collect data about users.

Samsung recently announced that its smart fridges would start showing ads. A software update introduced the feature and first reactions of customers are not exactly glowing.

The company introduced the change for some of its Family Hub refrigerators in the United States. This turned the screen of the device into a vehicle for ads. And who does not love ads, especially for items that cost thousands of Dollars?

Techspot reports that the update introduced new Terms of Service and a Privacy Notice that covers the addition of advertisement. Samsung’s smart fridge displays the ads on the fridge’s screen. It appears when the screen is idle, which likely means most of the time and only if users have selected certain themes, including weather, daily board, or color.

Users may enable certain themes to avoid ads for now. If the cover screen is set to art mode, which displays photos, then no ads are shown. A setting to fully disable ads is not provided, but users may block certain ads from reappearing.

You could disconnect the fridge from the network, but might not be able to use most of its functions in that case.

Samsung says that the advertisements “are designed to enhance value for owners”. I’m pretty certain that most owners would beg to differ.

Maybe next time, it would be better to buy a “dumb” fridge or other items, especially if the provided functionality is not adding value or has the chance of being turned into something that is highly annoying or invasive.

Proton Emergency Contact

Proton launches Emergency Access feature for paid accounts

Posted on August 28, 2025August 28, 2025 by Martin Brinkmann

Proton AG has been quite busy lately. It launched Proton Authenticator, a free open-source two-factor authentication app, and the privacy-friendly AI Lumo in the past month.

Today, the company announced a new feature for paid members. Emergency Access is designed to provide a way into a user’s account under certain circumstances, such as injury or death.

Proton writes in a new blog post:

With our new Emergency Access feature, you can grant permission to trusted contacts to securely access your Proton Account after a set period of time, ensuring nothing important is lost if you’re unable to enter your account due to death or illness.

Proton users may select up to five trusted contacts who may access a user’s account either immediately or after a select wait time that they may set in advance. For this to work, the trusted contacts do need a Proton Account of their own.

When a trusted contact requests access, one of two things happens: if the user set up a wait time, they may approve or deny the request in that period. Once the wait time is over, the request is granted automatically and the trusted contact gains access to the entire account.

For instance, if you set the wait time to four weeks, you have four weeks to allow or deny the request.

Emergency access can be disabled at any time by the account owner. Furthermore, Proton notes that it is applying to the entire Proton account of the user and not just a single application.

Proton users may set up the feature under Recovery > Add emergency contact. There they may add email addresses of their trusted contacts. Proton notes that the emails need to be associated with a Proton account.

Trusted contacts may request emergency access under Settings > Recovery.

Now You: do you have set up emergency options for accounts that support it? Feel free to leave a comment down below.

Android

Starting next year, all Android apps need to be registered by verified developers, even sideloaded ones

Posted on August 26, 2025August 26, 2025 by Martin Brinkmann

Android users have two main options to install apps on their devices. Through Google Play, if the marketplace for apps is installed, or through sideloading. Up until now, releasing apps through Google Play required a verified developer account. This meant that the developer had to verify their identity before apps could be published.

Starting in 2026, developers who do not publish their apps through Google Play will also be required to verify their identity, if they want their apps to be installed on certified Android devices. A certified Android device, in a nutshell is any device with installed Google services.

Google says that it won’t check apps that are registered through the new program but not made available through Google Play. However, developers are required to use a new special Android Developer Console for sideloading.

Furthermore, the verification process requires that developers provide Google with personal information, including their name, address, email, and phone number, and verification of their identity, for instance by providing Google with documentation that confirms the identity.

Google plans to invite select developers of applications from October 2025 onward and enable free registrations from March 2026 on.

The sideloading of apps by unverified developers will be blocked in the countries Brazil, Indonesia, Singapore, and Thailand from September 2026 on. More countries are added to the list starting in 2027.

Google claims that the new process is designed to “better protect users from repeat bad actors”, as it will make it harder for malware actors to quickly release new malicious apps after Google has taken down an app from a developer.

The change will make it difficult for malware creators, as they need a certificate to distribute their malicious apps outside of Google Play. However, it is also giving Google access to additional data and ends the anonymous development and distribution of apps.

Now You: what is your take on this? Good decision by Google to stop malware and threat actors in their tracks, or a move to gain access to even more data and control?

KeePass 2.59 Password Manager supports Arm64 on Windows now

Posted on July 10, 2025July 10, 2025 by Martin Brinkmann

KeePass is one password manager that I’m using regularly on Windows machines for password-related activities. It is a well-designed app that runs locally, but you can extend it with all kinds of plugins and install compatible programs and apps for other operating systems.

A new version of the password manager is now available. KeePass 2.59 is the second release of the year 2025 and it introduces quite a few welcome improvements and changes. First and foremost, if you run Windows on an ARM64 device, like the latest Microsoft Surface Pro devices, then you may install and use the password manager on that device now as well. KeePass 2.59 is therefore the first version of the password manager that supports all architectures that Windows supports.

KeePass 2.59 interface

KeePass 2.59 introduces native implementations of AES-KDF and Argon2 on Windows systems, promising a breathtaking 30-50 times speed increase on systems on which the native support library was not available or disabled. Encrypting and decrypting databases that use the AES algorithm should now also be faster.

Another new feature is a new import and export module for the KeePass KDB-database on Arm64 and Unix-like systems. You find the new option under File > Export in the main KeePass interface. Exports support the default user name and database color now. The root group is now also exported, according to the release notes.

Other than that, support for opening URLs from within KeePass now supports the private modes of the browsers Maxton, SeaMonkey and Yandex, next to the already supported browsers. Also new is that some links are now clickable on Unix-like systems, which may improve handling of them, as you no longer have to use copy and paste for that anymore.

You can check out the remaining changes on the official website. They include several improvements and optimizations for the most part.

Existing users may run the installer to update KeePass to the latest version. A new KeePass 2.59 portable edition is also available for those who prefer it.

Now You: which password manager do you use and why? Feel free to share your thoughts on it in the comment section below.

Chrome

Security researchers discovered malicious Chrome extensions with more than 2.3 million combined installs

Posted on July 8, 2025July 8, 2025 by Martin Brinkmann

Browser extensions can be very useful. They may help you block ads and other unwanted content, download content from websites, enhance online services, or introduce AI features that you really want to use in the browser.

However, reports about malicious extensions for Google Chrome, and thus all other Chromium-based browsers, appear online in regular intervals. Security is not perfect and users may fall pray to malicious extensions not only on third-party sites but also when they browse the Chrome Web Store.

Security researchers at Koi Security discovered a coordinated malware campaign of 18 extensions for Google Chrome, Microsoft Edge, and other Chromium-based browsers that had over 2.3 million users.

The extensions, among them Color Picker, Eyedropper — Geco colorpick, Free Weather Forecast, or Unlock TikTok, were fully functional according to the developers. These were not “thrown together in a weekend” and obiously scam, but “carefully crafted trojan horses”.

Color Picker, for example, provided color picking functionality. It must have done an okay-job at that, as it had a rating of 4.2 of 5 on the Chrome Web Store, over 800 ratings, and more than 100,000 users.

Interestingly enough, several of the extensions were listed as “featured” on the store, which meant that Google promoted them to users who visited the Store. It is very likely that this gave the featured extensions a significant boost, more eyes on them, more downloads.

A Reddit developer observed an increase of impressions of almost 300 percent after the extension got the coveted featured badge on the Chrome Web Store. While the percentage may vary, it is without a doubt pushing installs.

Browser Hijacking

The extensions provide users with functionality that they claim, but they also run malicious tasks in the background according to Koi Security.

The malware monitors every page you visit, submits it to a remote server along with your unique tracking ID, and may receive redirect URLs from the server.

The malware group introduced the malicious code sometime after the extensions were launched on the Chrome Web Store. The fact that browser extensions are designed to update automatically most of the time helped them. Users did not have to click on anything or fall pray to a sophisticated phishing or social engineering attack to get the malware on their devices.

All they did in the beginning was install a perfectly harmless and working extension for the browser. The malware came later.

Koi Security reported the malware extensions to Google. At the time of writing, some are still available on the Store.

Here are the names and unique IDs, so that you can check them against the installed extensions:

Chrome:

kgmeffmlnkfnjpgmdndccklfigfhajen — [Emoji keyboard online — copy&past your emoji.]
dpdibkjjgbaadnnjhkmmnenkmbnhpobj — [Free Weather Forecast]
gaiceihehajjahakcglkhmdbbdclbnlf — [Video Speed Controller — Video manager]
mlgbkfnjdmaoldgagamcnommbbnhfnhf — [Unlock Discord — VPN Proxy to Unblock Discord Anywhere]
eckokfcjbjbgjifpcbdmengnabecdakp — [Dark Theme — Dark Reader for Chrome]
mgbhdehiapbjamfgekfpebmhmnmcmemg — [Volume Max — Ultimate Sound Booster]
cbajickflblmpjodnjoldpiicfmecmif — [Unblock TikTok — Seamless Access with One-Click Proxy]
pdbfcnhlobhoahcamoefbfodpmklgmjm — [Unlock YouTube VPN]
eokjikchkppnkdipbiggnmlkahcdkikp — [Color Picker, Eyedropper — Geco colorpick]
ihbiedpeaicgipncdnnkikeehnjiddck — [Weather]

Edge:

jjdajogomggcjifnjgkpghcijgkbcjdi — [Unlock TikTok]
mmcnmppeeghenglmidpmjkaiamcacmgm — [Volume Booster — Increase your sound]
ojdkklpgpacpicaobnhankbalkkgaafp — [Web Sound Equalizer]
lodeighbngipjjedfelnboplhgediclp — [Header Value]
hkjagicdaogfgdifaklcgajmgefjllmd — [Flash Player — games emulator]
gflkbgebojohihfnnplhbdakoipdbpdm — [Youtube Unblocked]
kpilmncnoafddjpnbhepaiilgkdcieaf — [SearchGPT — ChatGPT for Search Engine]
caibdnkmpnjhjdfnomfhijhmebigcelo — [Unlock Discord]

Google fixes another 0-day vulnerability in Chrome, advises to update asap

Posted on July 1, 2025July 1, 2025 by Martin Brinkmann

If you have installed Google Chrome on one of your devices, then you may want to start the browser’s update engine immediately to update it to the latest version.

Google released a new version of Chrome for desktop and Android to fix a 0-day vulnerability in the browser. This one is exploited in the wild, which means that there is a chance that the issue may be exploited when you run older versions of the Google browser.

The official release notes list CVE-2025-6554 as a type confusion issue in V8, the JavaScript engine that Google Chrome uses. A type confusion vulnerability exploits a flaw in software where a program mistakes a specific type of data for another. This can lead to unexpected behavior, which threat actors may exploit in attacks.

Google mentions that the issue was reported by Clément Lecigne of Google’s Threat Analysis Group on June 25th, 2025. Google says that it mitigated the issue a day later by pushing a configuration change to the stable channel of the browser across all platforms.

This suggests that most devices — all that received the configuration change — are protected from attacks targeting the vulnerability. Still, it is recommended to update the browser immediately.

Desktop users, those who run Google Chrome on Windows, Mac, or Linux devices may select Menu > Help > About Google Chrome to do so. Chrome runs a check for updates and will install the new version automatically. Note that a restart of the browser is necessary to complete the process.

Tip: Windows users may also run winget upgrade google.chrome.exe in Terminal to upgrade the browser to the new version without first starting it.

Android users are not so lucky. The update depends on Google Play in that case, and that may take a while. There is no option to speed up the installation of the mobile browser on Android, if installed via Google Play.

Windscribe: Google is blocking our extension update because of “too many privacy features”

Posted on June 30, 2025June 30, 2025 by Martin Brinkmann

Windscribe is a popular VPN solution thanks to its free version, privacy features, and interesting build a plan feature. Windscribe users may install the official extension to integrate the VPN better into Google Chrome and other Chromium-based browsers, and get several privacy features on top.

The extension adds features such as ad blocking, webRTC blocking, cookie-banner hiding, and much more.

This just happened: The developers confirmed on X that Google is blocking the latest extension update from its Chrome Web Store.

The provided screenshot shows that Google claims that the extension does not comply with the “Single Use” policy for Chrome extensions.

Good to know: The Single Purpose Policy requires that extensions focus on one specific function or theme. Google says that this improves the user experience.

The posted screenshot of the Google email shows that Google claims that the “extension is providing multiple unrelated functionalities”, such as “masking physical location”, “circumventing censorship”, and “blocking ads and trackers”.

Google is asking the developers of the extension to modify it, so that it offers a “narrowly-focused single functionality”.

Windscribe appealed Google’s objection to no avail. As it stands, Windscribe is blocked from updating its extension on the Chrome Web Store.

Tip: you can check out the Windscribe extension for Firefox, which does not have any of these issues.

This is not the first time that legitimate popular extensions have issues with the update process on the Chrome Web Store. Google’s Store is the default location for most Chromium-based browsers when it comes to extensions.

Several browsers, including Brave, do not operate their own extensions store. While some do, Microsoft with Edge or Opera with its Opera Web Browser, the majority relies on extensions from the Chrome Web Store. Even the two mentioned browsers have limited extensions listed in their respective stores.

As for Windscribe, it will be interesting to see how this works out for the company. Usually, public attention is required to get Google to look deeper into the matter and change its stance on a violation.

Firefox

Mozilla should test Firefox with best-in-class ad blocker and privacy

Posted on June 24, 2025June 24, 2025 by Martin Brinkmann

The future looks quite grim for Mozilla and its Firefox web browser. The average monthly user count continues to drop while the browser of its ex-CEO is reporting new heights regularly. Then there is the looming death of Google and its impact on Mozilla’s finances to consider.

Mozilla’s reaction came as a surprise. It started to add features that users requested for years. Firefox supports vertical tabs now, tab groups, and a lot more.

It also took a look at its assets to figure out what to keep and what to terminate. This resulted in the termination of recent acquisitions, such as Fakespot, and long-standing staples, such as Pocket.

While these help free up resources and reduce expenses, it is likely that they won’t prevent the Mozilla-ship from capsizing, if things take a turn for the worse.

What to do? Here is an idea!

Why is Brave gaining users and Firefox losing them? You could say that it is all because of the different underlying platforms that the browsers use. Brave, after all, uses the same core as Google Chrome. Firefox uses Mozilla’s own engine. It has advantages, as it gives Mozilla full control over the engine. However, all development weight is on Mozilla whereas Brave and others reap what (mostly) Google developers and others work on.

It would be shortsighted to focus solely on this. Brave includes a content blocker by default. It also includes lots of privacy enhancements. While some criticize the browser for its integration of crypto-stuff, the combination of Chromium with its integrated content blocker works really well most of the time.

Firefox users can install uBlock Origin or another content blocker, but they have to do so manually.

Why is not Mozilla integrating its own content blocker or establishing a partnership with Raymond Hill, the creator of uBlock Origin? Mozilla never revealed the answer, but the most likely answer is because of its search deal with Google.

An ad blocker would prevent Google ads from showing up. Google would rightfully so want to pay less to Mozilla, as it would not make enough revenue anymore to justify the price that it pays Mozilla each year.

But what about running a test? Create a special version of Firefox. Install an ad-blocker and enable it by default. Distribute it, maybe ask for donations in the same way that the Thunderbird team is asking for them.

See how it goes. Just make sure that privacy is excellent for users, that they won’t see any sponsored content or other paid content in Firefox, and that their privacy is always valued more than anything else.

It might work. Users might pick Firefox as it would keep them safe and private while using the browser. It might not work, but Mozilla would at least tried something.

Now You: do you use Firefox or another browser? Let me know in the comments below.

Reddit

Reddit is rolling out options to hide posts and comments on your profile page

Posted on June 10, 2025June 10, 2025 by Martin Brinkmann

Reddit users will soon have an option to keep their interactions on the social site private. The company is rolling out a new feature that enables users to hide posts and comments that they made on the site on their profile page.

Currently, all posts and comments show up when the page is opened. Anyone who opens the link to the profile, which always begins with https://www.reddit.com/user/ followed by the username, sees all posts and comments by that user in chronological order.

Some content on the page, including saved posts on Reddit or votes, are kept private.

Reddit users have the following options going forward:

  • Hide all posts and comments.
  • Hide posts and comments selectively per community.
  • Show all posts and comments (default).

Furthermore, there will be additional options. Users who interact with NSFW (Not Safe For Work) content on Reddit may block this content from showing up in their profile directly. Also, the follower count can be hidden as well.

This may look like a small change for Reddit users who do not post to the site. Those who do know that their profiles are in the open and so is their entire post and commenting history.

Giving users an option to lock this down is appreciated, as it blocks potential abuse, e.g., creation of profiles or harassment. It may be especially useful to users who interact with SFW (Safe For Work) and NSFW content on the site, and do not want the SFW crowd to know about their NSFW side, or the other way round.

Now You: do you have a Reddit account? What is your take on the direction the site is heading to since its IPO? Feel free to leave a comment down below.

  • Previous
  • 1
  • …
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • …
  • 14
  • Next

Support This Site

If you like what I do please support me!

Any tip is appreciated. Thanks!
  • August 29, 2026 by Martin Brinkmann Another Windows Issue: Microsoft Defender Antivirus is turned off notification, but it is actually enabled
  • August 28, 2026 by Martin Brinkmann Brave Accounts and Email Aliases launch
  • August 25, 2026 by Martin Brinkmann Microsoft confirms: Latest .NET updates may cause printing issues
  • August 24, 2026 by Martin Brinkmann The Chrome Web Store has a fake VPN extensions problem
  • August 23, 2026 by Martin Brinkmann Microsoft is worsening classic Media Player to get users to upgrade

About

We talk, write and dream about Technology 24/7 here at Chipp.in. The site, created by Martin Brinkmann in 2023, focuses on well-researched tech news, reviews, guides, help and more.

Legal Notice

Our commitment

Many websites write about tech, but chipp.in is special in several ways. All of our guides are unique, and we will never just rehash news that you find elsewhere.

Read the About page for additional information on the site and its founder and author.

Support Us

We don't run advertisement on this site that tracks users. If you see ads, they are static links. Ads, including affiliate links, never affect our writing on this site.

Here is a link to our privacy policy

©2026 Chipp.in Tech News and Reviews