Chrome ignores when it is configured to use an anonymous third-party proxy
A bug in Google Chrome has been identified that reveals the identity of the browsers’ users when they are using anonymous browsing services like Tor. The bug leaks the DNS data of the user.
Third-party anonymous browsing services mask the identity of a user by routing their DNS queries through a proxy server. But when Chrome is configured to use such a proxy, it is basically ignoring that request and routing DNS queries from the user’s local network, revealing the user’s network and location.
The advisory was published to the Full-Disclousre mailing list this week. The advisory blamed the DNS pre-fetching feature that Chrome touts. With pre-fetching, Chrome scans the links on the page you are reading and resolves the DNS addresses for them in advance. It is one of the ways that Chrome speeds Web surfing. Those who found the bug says that disabling that feature does not fix the problem.
A Google spokesperson said that Google is investigating the problem and offered the words of solace that it doesn’t affect many users.
As Google pushes its way ever deeper into the world of software development, will it do a better job of security than arch rival Microsoft? Right now, with so few people using and depending on Google’s client-side software, very few hackers or security researchers have focused on those products. And Google can easily fix its products by automating updates, pushing out new releases, confident that its forced refresh won’t break anything. If Google has the success it hopes for, will that change?
Like this post? Check out these others.
Plus, visit the Microsoft Subnet web site for more news, blogs, podcasts. Subscribe to all Microsoft Subnet bloggers. Sign up for the bi-weekly Microsoft newsletter. (Click on News/Microsoft News Alert.)
- Watch out Microsoft: GNOME is poised to have a killer 2010
- Microsoft Exchange/Outlook 2010 UC Mobile and Voicemail Features (Beta) Release!
- Windows 7 Remote Admin Tools: Controls Windows Server 2008 from your Windows 7 desktop
- Fake Microsoft security e-mail spreads malicious code
- Prevx apologizes, backtracks on claims that Microsoft patch causes black screen
- Secrets of Exchange Server 2010
- Unified Messaging (Voicemail) in Exchange 2010
- Microsoft’s data cache technology, code-named Velocity, speeds app performance
Follow All Microsoft Subnet bloggers on Twitter
Follow Julie Bort on Twitter




