
The Security Detail · 2024-10-02 · 18 min
Key moments - from our scoring
Substance score
32 / 100
Five dimensions, 20 points each
Browser security has become a critical attack vector for enterprises, particularly as remote and hybrid work blur the lines between managed and unmanaged devices. Fletcher Oliver walks through Chrome's multi-layered approach to protecting users: Safe Browsing (protecting 5 billion devices daily with malicious site and phishing detection), Enhanced Safe Browsing (adding real-time URL checking and additional extension scrutiny), and Chrome Enterprise Core (free policy management and reporting via Google Admin Console). The episode also covers recent Splunk Surge research analyzing 140,000 Chrome extensions from the Chrome Web Store, which revealed concerning patterns in free VPN extensions storing credentials and autofill extensions exfiltrating data to remote hosts. Oliver explains granular extension management strategies - blocking by permission type (proxy access, USB device access), by website context, or via allowlist/blocklist approaches - and introduces Chrome Enterprise Premium for comprehensive DLP, URL filtering, and context-aware access control. The conversation emphasizes visibility as the foundation of extension security, integrating Chrome event reporting directly into Splunk for breach detection and investigation.
Data loss (both malicious and unintentional, such as uploading sensitive data to file conversion sites) and lack of visibility into endpoint and browser-level activity are the primary challenges; remote and hybrid work have made VPN-based defenses less effective.
Safe Browsing scans for malicious websites, phishing sites, deceptive sites, and dangerous downloads across 5 billion devices daily; Enhanced Safe Browsing adds real-time URL checking as users type in the address bar and provides additional extension security vetting.
Chrome Enterprise Core is a free tool accessed via Google Admin Console that provides reporting, extension visibility and management, policy enforcement, and integration with Splunk for browser event logging.
By enrolling browsers in Chrome Enterprise Core to gain visibility into installed extensions and their permissions, then applying granular controls: blocking extensions by permission type (proxy, USB access), by website context, or via allowlist/blocklist strategies.
Analysis of 140,000 Chrome Web Store extensions revealed that free VPN extensions were storing credentials in documents and configuring proxies, while autofill extensions were sending user data to remote hosts.
Our reviewer’s read on each dimension, with quotes from the episode.
A handful of genuinely practical operational tips emerge (URL-specific extension blocking, free Chrome Enterprise Core enrollment, permission-based auto-disable rules), but they are buried in product marketing and generic advice. The ratio of novel-to-obvious is low for an 18-minute episode.
you could say, fine with these extensions running on third-party websites...you can actually enter in those URLs and the extension will continue to work on other sites, but won't work on the sites that you specify
if an extension tries to set a proxy or accesses USB, you can actually check a box and say, if an extension tries to or ever tries to access that specific right, you can automatically disable it
Almost entirely standard, vendor-authored browser security advice with no contrarian or first-principles thinking. The episode reads as a product walkthrough for Chrome Enterprise rather than any fresh analysis of the threat landscape.
I say the top tip that I would take out of this is definitely make sure via policy...enforce safe browsing within your environment
making sure that they are, you know, being aware of deceptive sites that are out there
Fletcher Oliver is a real, customer-facing practitioner at Google with genuine enterprise deployment experience, but he is a pre-sales customer engineer with a product to sell, not a CISO, security architect, or researcher who has built these programs from the buyer side at scale.
I am a Chrome Enterprise Customer Engineer at Google based outside of Chicago, and I'm on the enterprise team. So I work closely with our customers to be able to manage Chrome browser at scale
risk is relative right So what risky to a shoe company may not be as risky or maybe more risky to say a bank or something along those lines
The episode contains only one meaningful third-party data point ('5 billion devices') and one research figure from the hosts' own work; there are no customer case studies, breach metrics, timelines, or dollar figures to ground the claims.
built into Chrome is a tool called Safe Browsing, and it protects something like 5 billion devices every single day
they were able to scrape 140,000 Chrome extensions from the Chrome store
Questions are generic and templated ('How has the shift to hybrid and remote work impacted cybersecurity?'), no vendor claims are challenged, and the hosts openly express enthusiasm rather than scrutiny, turning the interview into an uncritical product showcase.
How has the shift to hybrid and remote work environments impacted cybersecurity strategies for businesses in your experience?
I had no idea that you could specify the URLs. I might go and audit my extensions now and try that out.
Computed from the transcript - who did the talking, and the words that came up most.
Browser security is crucial for protecting personal information and preventing malicious attacks, ensuring safe and private online experiences. In Episode 6 of The Security Detail, Chrome browser customer engineer Fletcher Oliver shares some of the top browser security risks and how to defend against them. We also discuss SURGe research that examines security risks associated with Chrome browser extensions. Links: - Chrome Safety: - Chrome Safe Browsing: - Chrome Enhanced Safe Browsing: - Chrome Enterprise Core: - SURGe research on Chrome browser extension security: - Google's Permission Risk whitepaper download: - Chrome Enterprise Premium: - Splunk integration in Chrome Enterprise Core: - Google Chrome App for Splunk:
Transcribed and scored by The B2B Podcast Index.
Welcome to the Security Detail, a cybersecurity podcast by Splunk Surge. I'm Audra Streepin. And I'm Madeline Tauber. In today's episode, we're taking a look at browser security.
And browsers are a common entry point for malware, and they can also collect and store a lot of personal data. So to learn more about some of the top browser security risks and how to defend against them, we spoke with Fletcher Oliver, who's a customer engineer at Google, and he's very knowledgeable about Google Chrome. We'll also touch on some research from Serge that actually looked at security risks associated with Chrome browser extensions. Take a listen.
My name's Fletcher Oliver. I am a Chrome Enterprise Customer Engineer at Google based outside of Chicago, and I'm on the enterprise team. So I work closely with our customers to be able to manage Chrome browser at scale. So that's setting policies, providing security controls, as well as, you know, helping them to be able to, you know, manage their extensions.
So lots of different conversations with many different customers. I have a more of a general security question. I'm just curious right now when you're working with enterprises, what you consider to be some of the top security challenges that they face today? I think a lot of them are the same as they've always been, right?
How they can protect their data with so much stuff moving online, whether it's, you know, SaaS applications or just general browsing over the Internet. But it's always going to be data loss, whether it's malicious data loss or more likely like unintentional, like, say, people utilizing file conversion sites because, hey, I have to have a PDF in order to submit my time card. And I need to convert to that. And that has sensitive data, right?
So it's not always malicious. And then also just lack of insights, being able to have visibility into what's happening on the endpoint, within the network layer, within the browser. And, you know, the big challenge is that everybody's being asked to do more with less. So that IT overhead, the amount of people or bodies that they have within the SOC is becoming more and more limited.
How has the shift to hybrid and remote work environments impacted cybersecurity strategies for businesses in your experience? I guess it's just made things more difficult, right? So many employees are infrequently connecting to the corporate VPN. They're having them jump on the network or even come into the office on a regular basis so that way they can get regular OS updates or updates on their applications.
It's just becoming more and more difficult. So moving to a browser-based strategy and providing a security baseline within the browser has become significantly more advantageous for customers to be able to protect their data and their employees. How do you think browser security fits into an organization's overall security strategy? It's pretty important.
Obviously, I'm a little biased when it comes to the importance of the browser. But when you think about it, it usually is the primary tech vector for cyber criminals, for intentional or unintentional data exfiltration. So aside from employees kind of picking up USB drives in the parking lot and plugging them into their machine, which I'm sure unfortunately probably still happens, a lot of data breaches, malware infections, and other security incidents can be sourced directly through the browser.
So having a security baseline through policy or through browser built-in security is becoming very, very important in this day and age. And what would you say that entails? So just browser security in general and then also the browser extension security in particular? When it comes to browser security, really being able to make sure that you have visibility into what's happening, right?
So being able to see and make sure and have controls in place that make sure that the browser is updated on a regular basis So from a Chrome browser perspective my wheelhouse is you know making sure that you have auto update turned on So that makes it so you get the latest and greatest features and functionality, but also the latest security fixes. And also built into Chrome is a tool called Safe Browsing, and it protects something like 5 billion devices every single day. And that's doing scanning for malicious websites and phishing sites, deceptive sites, dangerous downloads and uploads.
So I highly recommend, although it is on by default, browser security can be increased through applying a policy that makes sure that users can't turn safe browsing off. Or even you can go at a level above that and turn on enhanced safe browsing that not only provides the same level as standard, but also provides real-time URL checking. So as the users are entering in the address into the address bar or Omnibox, as we call it, it's going to check against the latest data within safe browsing.
Also provides a lot of additional security around extensions. So extension security within the Chrome Web Store, when developers submit their extensions to the Chrome Web Store, it goes through a combination of machine learning, AI, and human code review to make sure that the rights that those extensions are requiring to function are relative to the APIs or the rights that they're calling. And so it has its own kind of approval process, but Enhanced Safe Browsing has an additional layer of security above that to provide additional security within the browser.
And then beyond the extension safety that's offered through Enhanced Safe Browsing, you can also get additional visibility and configurations and capabilities through our tool called Chrome Enterprise Core, which is managing the browser from the Google Admin Console. So there's no cost associated with it. And it provides reporting as well as extension management, you know, block allow protecting extensions from running from specific websites. So it provides a really great capability as well as enabling you to integrate with great tools like Splunk.
Two of our colleagues on Surge recently released research looking at Chrome extension risk, and they were able to scrape 140,000 Chrome extensions from the Chrome store, of course, with permission from the Chrome team. So thank you for that. But mainly what they were looking at was just how these extensions interact with user data. They perform URL and domain analysis.
And then they also looked at the permissions and authentication scopes that the extensions were requesting. And so they led this project really with the goal of creating an open source software pipeline for evaluating extension risk and highlighting some of those best practices. And they also created a Splunk dashboard where you can input the Chrome extension ID to see the scoring results that we generated. And this was also informed by Google's permission risk white paper.
That's what we based our permission risk scores. So we can link to all of that in the show notes as well. We'll also link to our four-part blog series explaining some of our research methodology and our findings. And some of the findings that I thought were quite interesting, of course, we really zeroed in on outliers for potential malicious activity.
This is a very small subset of the extensions that we were looking at. We saw some of the free VPN offerings were actually configuring proxies and storing credentials in documents. And then we also saw some of those autofill form extensions where we're sending data to a remote host. Those were some interesting findings.
And then of course, analyzing JavaScript was a little bit difficult at times because of some of the obfuscation, but we outline all of that in our report. But I am curious, you know, Fletcher, based on your experience with customers, what are some of your top recommendations when it comes to evaluating extensions and making sure that they're securely managed? Yeah. So some of the most effective ones based on my experience with customers is being able to get visibility into what extensions are installed, where they're installed and what they have access to, right?
So a lot of the research that Splunk did, as well as the dashboards that are provided within Splunk are a great way to get those insights right Because when it comes down to it risk is relative right So what risky to a shoe company may not be as risky or maybe more risky to say a bank or something along those lines right So being able to have visibility is probably the first place to start. So what we usually recommend is that customers can enroll their browsers into Chrome Enterprise Core, as I mentioned before, Again, no cost associated with it.
And when I say enroll, it's really just setting a Chrome policy. So it's like a registry key on Windows at a file location on Mac and Linux. And then they could be able to turn on reporting. And then they'll be able to see what extensions are installed, where they're installed, and what they have access to.
As well as we have risk assessments, as well as we could be able to tie that into Splunk as well. So as they turn on that reporting, they can also get browser events that can get sent directly to Splunk through our reporting connector. So things like malicious site visits, malicious downloads, extension install events. So that way you can bring that into your cybersecurity playbook and really be able to get another layer of, you know, possible vulnerabilities within your environment, ongoing breaches that could be happening as you could kind of chain those events together and then be able to, you know, bring that information into Splunk.
As well as we do have the ability to have a variety of options for managing extensions based on your risk appetite. You can block all extensions and allow some. You can allow all and block the ones that you want to. You can also manage by permission.
So that's by the rights that permissions are the rights that extensions need in order to run. So website access or device-based access. So you could say, hey, if this extension tries to set a proxy or accesses USB, you can actually check a box and say, if an extension tries to or ever tries to access that specific right, you can automatically disable it. as well as being able to manage via website access.
You could say, fine with these extensions running on third-party websites, think of like a coupon extension. You don't really care if it runs on retail sites, but maybe on your HR site or on your GitHub or something like that. Maybe you don't want that extension to be able to read all your data. So you can actually enter in those URLs and the extension will continue to work on other sites, but won't work on the sites that you specify.
So those are probably the most effective strategies so that way you're able to really evaluate what you have and then set your security baseline from an extension perspective, as well as getting those additional insights into Splunk. I had no idea that you could specify the URLs. I might go and audit my extensions now and try that out. But earlier you mentioned data loss and data breaches still being kind of a constant concern for businesses.
So how do you think organizations can better protect their sensitive data, especially with remote work and BYOD policies being so prominent? It's difficult when you don't have the, especially for BYOD, if you don't have the ability to put a VPN on it or you don't have the ability to, you know, put an agent on it because you don't own the machine or it's a partner or a contractor or something like that. It can definitely be difficult. That's why we also have a solution called Chrome Enterprise Premium, which is our security solution offered through Google Cloud that provides the ability to implement a comprehensive data loss prevention or DLP solution, as well as URL filtering, URL categorization, watermarking, as well as being able to have like DLP rules for like Gen AI, context-aware access control, and advanced security insights.
So definitely being able to have a solution in place that's able to leverage an agent that's already there, which Chrome Enterprise Premium just uses Chrome, makes it a lot easier to not only support your managed devices, but also your BYOD devices and your partner ones that are unmanaged. Is there anything else you want to add that we didn ask you so far about browsers or extensions or anything that we haven touched on I say the top tip that I would take out of this is definitely make sure via policy and you can do a search for safe browsing policy.
Definitely enforce safe browsing within your environment. I highly recommend it. It's a great way to have a security baseline enforced. Again, it's on by default, but I always recommend for my customers to take that as a top tip to make sure that that's enforced.
Definitely consider using enhanced safe browsing because that's going to provide even more capabilities. If you want to get additional insights and reporting and kind of ease of use across multiple platforms, highly recommend taking a look at Chrome Enterprise core, which again, doesn't have any costs associated with it. And then if you do have a need for a secure enterprise browser, definitely consider Chrome Enterprise Premium because it does provide so many different capabilities directly within the browser, leveraging an agent that's already present on millions of enterprise devices, which is the Chrome browser.
welcome to i'm the cizzo and i say so this is a segment where we ask interview guests what they would recommend or even mandate if they were a chief information security officer we asked fletcher about his top priorities as a cizzo and here's his answer if i was the cizzo and i say so i i guess i would you know say like we need to make sure that auto update is on on the browser I would also try to default on a secure enterprise browser, obviously, given my background, and I would recommend Chrome as that particular secure enterprise browser.
And just making sure that not only that I'm enforcing policies to ensure that there's always going to be a security baseline, whether the user is on a managed or an unmanaged devices, but also just educating employees about browser security best practices, how to identify phishing emails, how to check links without actually clicking on them. making sure that they are, you know, being aware of deceptive sites that are out there, and being a little bit more stringent about, you know, what extensions I allow within my environment.
You know, this episode did make me feel like evaluating some of the extensions I use in my Chrome browser, because I use Chrome. And I did like that we discussed kind of the granularity of how you can manage the extensions. So I'm definitely going to take a look. And like I said, I want to audit them and see what I can do security-wise there.
What did you think, Audra? Yeah. And just thinking about browsers as a very common attack vector in terms of clicking on malicious links and phishing emails. I think it's important every time we open up a browser to consider that with what we're looking at and what we're downloading.
And I also really liked Fletcher's comment about the reporting available through Chrome Enterprise Core so that you can get visibility into those extensions that you install on your browser. And then you can also send that information to Splunk through Google's reporting connector. So we'll, of course, link to Google's Chrome add-on for Splunk in the show notes in case you're interested in logging some of that data, along with the surge research that we mentioned that looks into Chrome browser extension risk.
And you can also check out some of our other research that we're working on at Surge. Our website is splunk.com slash surge. For instance, we just released some research not too long ago looking at creating detections for some of the top LLM vulnerabilities according to the OWASP top 10 for LLM applications.
So highly recommend checking that out in case you're interested in learning more about prompt injection attacks and things like that, disclosing sensitive information and finding ways to create detections for that. but that is all the time we have for this episode of the security detail. If you like what we're doing, please share the security detail with your friends. You can look for us on Podbean, Apple, Spotify or wherever you find your podcasts.
Thanks for listening.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.