Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Friday, July 13, 2018

How private browsing works



When you browse privately, other people who use the device won't see your activity.
Chrome doesn't save your browsing history or information entered in forms. Cookies and site data are remembered while you're browsing, but deleted when you exit Incognito mode.

Your activity might still be visible

Incognito mode stops Chrome from saving your browsing activity.
Your activity might still be visible to:
  • Websites you visit, including the ads and resources used on those sites
  • Your employer, school, or whoever runs the network you’re using
  • Your internet service provider
If you sign in to an account to use a web service, like Gmail, your browsing activity might be saved on sites that recognize that account.

Downloads and bookmarks are saved

Chrome won’t remember the files you download while browsing in private. But, they're still saved to your Downloads folder, even after you exit Incognito. You and anyone who uses your device can see and open the files.
All bookmarks you create are saved to Chrome.

You can switch between Incognito windows and regular Chrome windows. You'll only browse in private when you're using an Incognito window.

Stop private browsing

Incognito mode runs in a separate window from your normal Chrome windows.
If you have an Incognito window open and you open another one, your private browsing session will continue in the new window. To exit Incognito mode, close all Incognito windows.
  1. On your computer, go to your Incognito window.
  2. Close the window:
    • Windows or Chrome OS: At the top right, click Close Close.
    • Mac: At the top left, click Close Close.

How To Manage saved passwords



You can have Chrome remember your passwords for different sites. To use your passwords on different devices, sign in to Chrome.

If you enter a new password on a site, Chrome will ask to save it. To accept, click Save.
  • To see the password that will be saved, click Preview Preview.
  • If there are multiple passwords on the page, click the Down arrow Down Arrow. Choose the password you want remembered.
  • If your username is blank or incorrect, click the text box next to "Username." Enter the username you want remembered.

Sign in with a saved password

On some websites, if you save a password to Chrome or Smart Lock for Passwords, you'll be automatically signed in when you visit that website.
  1. On your computer, go to a site you've visited before.
  2. In a sign-in form, click the username field.
  3. From the list, choose the sign-in info you want to use.

See, delete, or export saved passwords

You can see or delete passwords at any time:
  1. On your computer, open Chrome.
  2. At the top right, click More More and then Settings.
  3. At the bottom, click Advanced.
  4. Under "Passwords and forms," click Manage passwords.
  5. See, delete, or export a password:
    • See: To the right of the website, click Preview Preview. If you lock your computer with a password, you'll be prompted to enter your computer password.
    • Delete: To the right of the website, click More More and then Remove.
    • Export: To the right of "Saved Passwords," click More More and then Export passwords.
To clear all your saved passwords, clear browsing data and select "Passwords."

Stop saving passwords

By default, Chrome offers to save your password. You can turn this option off or on at any time.
  1. On your computer, open Chrome.
  2. At the top right, click More More and then Settings.
  3. At the bottom, click Advanced.
  4. Under "Password and forms," click Manage passwords.
  5. Turn the setting off.

Fix problems with passwords

If Chrome isn't saving or offering to save passwords, learn how to fix issues with saved info.

How Chrome saves and syncs passwords

How Chrome saves your passwords depends on whether you want to store and use them across devices. When synced, passwords can be used on Chrome on all your devices, and across some apps on your Android device.
Your passwords are saved to your Google Account if either of the following are true:
Otherwise, your passwords are only stored on Chrome on your computer.

Remove unwanted ads, pop-ups & malware



If you're seeing some of these problems with Chrome, you might have unwanted software or malware installed on your computer:
  • Pop-up ads and new tabs that won't go away
  • Your Chrome homepage or search engine keeps changing without your permission
  • Unwanted Chrome extensions or toolbars keep coming back
  • Your browsing is hijacked, and redirects to unfamiliar pages or ads
  • Alerts about a virus or an infected device
In the future, avoid unwanted software by only downloading files or visiting sites that you know are secure.

Remove unwanted programs (Windows, Mac)

Check your computer for malware (Windows)

Chrome can help you find suspicious or unwanted programs on your computer. If Chrome finds an unwanted program, click Remove. Chrome will remove the software, change some settings to default, and turn off extensions.
You can also check for malware manually.
  1. Open Chrome.
  2. At the top right, click More More and then Settings.
  3. At the bottom, click Advanced.
  4. Under “Reset and clean up,” click Clean up computer.
  5. Click Find.
If you're asked to remove unwanted software, click Remove

You can remove malware and other programs on your computer that you don't remember installing.
  1. Open Finder.
  2. On the left, click Applications.
  3. Look for any programs you don't recognize.
  4. Right-click the name of any unwanted programs.
  5. Click Move to Trash.
  6. When you're done, at the bottom, right-click Trash.
  7. Click Empty Trash.

Reset your browser settings

  1. On your computer, open Chrome.
  2. At the top right, click More More and then Settings.
  3. At the bottom, click Advanced.
    • Windows: Under "Reset and cleanup,” click Reset Settings and then Reset Settings.
    • Mac or Chromebook: Under "Reset Settings," click Reset Settings and then Reset.
    • Linux: Under “Reset Settings,” click Restore settings to their original defaults and then Reset Settings.
If you removed unwanted programs or reset your browser settings, you might need to turn some extensions back on. To turn extensions on, at the top right, click More More and then More Tools and then Extensions. Only turn on extensions you trust.

Safe Browsing: malware and phishing




Safe Browsing is a service that Google's security team built to identify unsafe websites across the web and notify users and webmasters of potential harm. In this Transparency Report, we disclose details about the threats we detect and the warnings we show to users. We share this information to increase awareness about unsafe websites, and we hope to encourage progress toward a safer and more secure web.

How we identify unsafe websites

Google’s Safe Browsing service examines billions of URLs and software and content on those pages in its search for unsafe websites. Safe Browsing then warns users when they navigate to websites that could steal their personal information or install software designed to take over their computers. Every week, Safe Browsing protects billions of devices.

Unsafe websites detected per week

Every day, Safe Browsing discovers thousands of new unsafe sites. Many of these are legitimate websites that have been compromised by hackers. Unsafe sites fall into two categories that threaten users’ privacy and security: phishing and malware

Malware explained 

These websites contain code that installs malicious software onto visitors’ computers, either when a user thinks they are downloading legitimate software or without a user’s knowledge. Hackers can then use this software to capture and transmit users' private or sensitive information. Our Safe Browsing technology also scans and analyzes the web to identify potentially compromised websites

Phishing explained

These websites pretend to be legitimate so that they can trick users into typing in their usernames and passwords or sharing other private information. Web pages that impersonate legitimate bank websites or online stores are common examples of phishing sites. 

 

 


Manage warnings about unsafe sites


You'll see a warning if the content you're trying to see is dangerous or deceptive. These sites are often called "phishing" or "malware" sites.

Get warnings about dangerous & deceptive content

Phishing and malware detection is turned on by default. When it's turned on, you might see the following messages. If you see one of these messages, we recommend that you don't visit the site.
  • The site ahead contains malware: The site you're trying to visit might try to install bad software, called malware, on your computer.
  • Deceptive site ahead: The site you're trying to visit might be a phishing site.
  • The site ahead contains harmful programs: The site you're trying to visit might try to trick you into installing programs that cause problems when you’re browsing online.
  • This page is trying to load scripts from unauthenticated sources: The site you're visiting is not secure.
Download with caution: Some sites try to trick you into downloading harmful software by telling you that you have a virus. Be careful not to download any harmful software.

View unsafe sites, content & downloads

You can visit a page or access a downloaded file that is showing a warning. This is not recommended.

Visit an unsafe page

  1. On your computer, open Chrome.
  2. On the page where you see a warning, click Details.
  3. Click Visit this unsafe site.
  4. The page will load.
When you visit an unsafe site, Chrome will try to remove the unsafe content from the page.
To view the entire page:
  1. On your computer, open Chrome.
  2. On a deceptive site, to the right of the address bar, click Content blocked Content blocked.
  3. In the alert, click Load full site.
  4. The page will load.
If the error mentions scripts, you can view the entire page by clicking Load unsafe script.

Download an unsafe file

  1. On your computer, open Chrome.
  2. At the top right, click More More and then Downloads.
  3. Find the file you want to download.
  4. Click Recover malicious file.

Turn off warnings about dangerous & deceptive sites

If you don't want to be warned about unsafe content, you can turn off deceptive and dangerous site alerts. This also turns off download warnings.
We do not recommend turning off alerts.
  1. On your computer, open Chrome.
  2. At the top right, click More More and then Settings.
  3. At the bottom, click Advanced.
  4. Under "Privacy and security," turn off Protect you and your device from dangerous sites.

What warnings about dangerous & deceptive content mean

  • Deceptive sites (also known as "phishing" or "social engineering" sites) try to trick you into doing something dangerous online, such as revealing passwords or personal information, usually through a fake website.
  • Dangerous sites (also known as "malware" or "unwanted software" sites) can harm your computer, or can cause problems when you’re browsing online. Learn how to clean Chrome of unwanted ads, pop-ups & malware.
  • Google Safe Browsing: To protect you from dangerous websites, Google maintains a list of websites that might put you at risk for malware or phishing. Google also analyzes sites and warns you if a site seems dangerous. Learn more about Google Safe Browsing.
  • Using a Chromebook at work or school? Your network administrator might set up phishing and malware detection for you, in which case you can't change this setting yourself. Learn about using a Chromebook through work or school.

My site or software is marked dangerous

Secure your site with HTTPS

 

What is HTTPS?

HTTPS (Hypertext Transfer Protocol Secure) is an internet communication protocol that protects the integrity and confidentiality of data between the user's computer and the site. Users expect a secure and private online experience when using a website. We encourage you to adopt HTTPS in order to protect your users' connections to your website, regardless of the content on the site.
Data sent using HTTPS is secured via Transport Layer Security protocol (TLS), which provides three key layers of protection:
  1. Encryption—encrypting the exchanged data to keep it secure from eavesdroppers. That means that while the user is browsing a website, nobody can "listen" to their conversations, track their activities across multiple pages, or steal their information.
  2. Data integrity—data cannot be modified or corrupted during transfer, intentionally or otherwise, without being detected.
  3. Authentication—proves that your users communicate with the intended website. It protects against man-in-the-middle attacks and builds user trust, which translates into other business benefits.

Best practices when implementing HTTPS

Use robust security certificates

You must obtain a security certificate as a part of enabling HTTPS for your site. The certificate is issued by a certificate authority (CA), which takes steps to verify that your web address actually belongs to your organization, thus protecting your customers from man-in-the-middle attacks. When setting up your certificate, ensure a high level of security by choosing a 2048-bit key. If you already have a certificate with a weaker key (1024-bit), upgrade it to 2048 bits. When choosing your site certificate, keep in mind the following:
  • Get your certificate from a reliable CA that offers technical support.
  • Decide the kind of certificate you need:
    • Single certificate for single secure origin (e.g. www.example.com).
    • Multi-domain certificate for multiple well-known secure origins (e.g. www.example.com, cdn.example.com, example.co.uk).
    • Wildcard certificate for a secure origin with many dynamic subdomains (e.g. a.example.com, b.example.com).

Use server-side 301 redirects

Redirect your users and search engines to the HTTPS page or resource with server-side 301 HTTP redirects.

Verify that your HTTPS pages can be crawled and indexed by Google

  • Do not block your HTTPS pages by robots.txt files.
  • Do not include meta noindex tags in your HTTPS pages.
  • Use Fetch as Google to test that Googlebot can access your pages.

Support HSTS

We recommend that HTTPS sites support HSTS (HTTP Strict Transport Security). HSTS tells the browser to request HTTPS pages automatically, even if the user enters http in the browser location bar. It also tells Google to serve secure URLs in the search results. All this minimizes the risk of serving unsecured content to your users.
To support HSTS, use a web server that supports it and enable the functionality.
Although it is more secure, HSTS adds complexity to your rollback strategy. We recommend enabling HSTS this way:
  1. Roll out your HTTPS pages without HSTS first.
  2. Start sending HSTS headers with a short max-age. Monitor your traffic both from users and other clients, and also dependents' performance, such as ads.
  3. Slowly increase the HSTS max-age.
  4. If HSTS doesn't affect your users and search engines negatively, you can, if you wish, ask your site to be added to the HSTS preload list used by most major browsers.

Consider using HSTS preloading

If you enable HSTS, you can optionally support HSTS preloading for extra security and improved performance. To enable preloading, you must visit hstspreload.org and follow the submission requirements for your site.

Avoid these common pitfalls

Throughout the process of making your site secure with TLS, avoid the following mistakes:
Issue Action
Expired certificates Make sure your certificate is always up to date.
Certificate registered to incorrect website name Check that you have obtained a certificate for all host names that your site serves. For example, if your certificate only covers www.example.com, a visitor who loads your site using just example.com (without the "www." prefix) will be blocked by a certificate name mismatch error.
Missing Server name indication (SNI) support Make sure your web server supports SNI and that your audience uses supported browsers, generally. While SNI is supported by all modern browsers, you'll need a dedicated IP if you need to support older browsers.
Crawling issues Don't block your HTTPS site from crawling using robots.txt.
Indexing issues Allow indexing of your pages by search engines where possible. Avoid the noindex meta tag.
Old protocol versions Old protocol versions are vulnerable; make sure you have the latest and newest versions of TLS libraries and implement the newest protocol versions.
Mixed security elements Embed only HTTPS content on HTTPS pages.
Different content on HTTP and HTTPS Make sure the content on your HTTP site and your HTTPS is the same.
HTTP status code errors on HTTPS Check that your website returns the correct HTTP status code. For instance 200 OK for accessible pages, or 404 or 410 for pages that do not exist.

More tips

See the HTTPS migration FAQs for more tips about using HTTPS pages on your site.

Migrating from HTTP to HTTPS

If you migrate your site from HTTP to HTTPS, Google treats this as a site move with a URL change. This can temporarily affect some of your traffic numbers. See the site move overview page to learn more.
Add the HTTPS property to Search Console; Search Console treats HTTP and HTTPS separately; data for these properties is not shared in Search Console. So if you have pages in both protocols, you must have a separate Search Console property for each one.