Skip to main content

Chrome Canary’s anti-phishing beta feature fails its flight test, security company says

chrome canarys anti phishing beta feature fails to work as intended google

If you spend a considerable amount of time on the Web, then you likely already know that phishing is a fact of life. Google knows this too, so in an effort to help people sidestep such dangers, it has been working on a feature called Origin Chip. 

However, Web security firm PhishMe says that while Origin Chip is designed to strip out a URL down to its bare essentials to make it easier to determine whether you’re the target of a phishing attempt, it sometimes does the opposite.

“We’ve discovered that if a URL is long enough, Canary will not display any domain or URL at all, instead showing an empty text box with the ghost text Search Google or type URL,” Aaron Higbee and Shyaam Sundhar of PhishMe said. “This creates a golden opportunity for attackers to carry out data-entry phishing attacks.”

Instead of displaying, for instance, Amazon.com or Netflix.com, a flaw in Origin Chip could shroud the entire URL altogether, which makes it impossible for you to determine whether you’re on a legitimate site or not just by looking at the URL in your browser’s address bar. Google has incorporated the feature into Chrome Canary, a version of the tech giant’s web browser that’s geared towards developers. 

Higbee and Sundhar suggest that “a potential solution would be to keep the entire URL intact, but put a visual focus on the root domain.” Perhaps color-coding the root domain with hues like green for “safe” and red for “unsafe” could go a long way towards decreasing the likelihood that an average user falls victim to a phishing attempt.

With that in mind, it’ll be interesting to see how Google will tackle this problem in future releases of Chrome.

What do you think? Sound off in the comments below.

Konrad Krawczyk
Former Digital Trends Contributor
Konrad covers desktops, laptops, tablets, sports tech and subjects in between for Digital Trends. Prior to joining DT, he…
This new Google Chrome feature may boost your search history
A MacBook with Google Chrome loaded.

Google is adding a new feature to its Chrome web browser that’s intended to help you find previously browsed topics and pick up where you left off. Called Journeys, it’s rolling out now for Chrome’s desktop version.

The feature essentially works like an extension of browsing history. When you type a word into the search bar or head to the Chrome History Journeys page in your browser, you will see a list of previously visited sites linked to that topic. Chrome will know how much you’ve interacted with any particular site, and those it considers the most relevant to you will go to the top of the pile.

Read more
Google Chrome has a secret feature to make it match Windows 11’s new design
Google Chrome opened on a laptop.

One of the signature features of Windows 11 is the new rounded corners and glass-like mica effects. Usually only found in Microsoft and select third-party Windows apps, these design elements are now making their way into Google Chrome but are still hidden secret behind a flag in Chrome's settings.

Once the secret flag is enabled, Chrome on Windows 11 fits in better with the rest of the new operating system. Right-click menus in Chrome change from squared off to more rounded, and also pick up the modern mica effect. In addition, Chrome's pop-out settings menu changes to a more rounded shape, fitting better with native Windows elements like the Start Menu and Quick Actions pop-out.

Read more
5 easy ways to dramatically increase security in Google Chrome
A MacBook with Google Chrome loaded.

If you're one of many people who use Chrome as your default web browser, then you might want to take some steps to ensure that it's extra secure. This can help you in a world where hackers are always after passwords and can easily spoof websites to look like the real thing.

Well, Google has a lot of tools built right into Chrome that can help with that protection. From Safe Browsing to encrypting passwords and more, we got you covered with five easy ways to dramatically increase security in Google Chrome.
Change your Safe Browsing settings

Read more