We use cookies to provide you with a better experience. If you continue to use this site, we'll assume you're happy with this. Alternatively, click here to find out how to manage these cookies

hide cookie message
78,230 News Articles

Chrome to flag dangerous Windows downloads

Google follows Microsoft's strategy with IE9

Google has revealed it will add malware download warnings to its Chrome browser.

The move has Google following the lead of rival Microsoft, whose Internet Explorer 9 (IE9) also alerts users of questionable downloads.

Google will use its Safe Browsing service to flag sketchy downloads, the company said in a blog. Chrome, Mozilla's Firefox and Apple's Safari already tap into Safe Browsing - which identifies suspicious or unsafe sites, then adds them to a 'blacklist' - to warn of dangerous sites before users actually reach those sites.

Safe Browsing will also provide the data for Chrome's download blocker, said Google.

When a Chrome user tries to download a Windows executable - a file with the '.exe' suffix - from a URL on the Safe Browsing blacklist, the browser will display a warning that reads, "This file appears to be malicious. Are you sure you want to continue?"

Extending Safe Browsing to downloads helps shut a malware door, Google argued.

"A separate attack vector exists, which is a social engineering mechanism that attempts to convince a user to download and run a file," Google said. "This new feature is designed to protect against that type of attack."

'The other half of the puzzle'

Chet Wisniewski, a security researcher with Sophos, agreed.

"This fills in the other half of the puzzle," said Wisniewski, explaining that while Chrome already alerts users of dodgy sites that launch drive-by attacks, that's not enough. "There are millions of [malicious sites], more than Safe Browsing can track, but they all point to a smaller number, still in the tens of thousands but smaller, that contain downloads."

Malware distributions site don't change at the same speed that sites redirecting to them do, and are much more likely to be tagged by Safe Browsing. "The number of sites at the bottom [that distribute malware] are small enough that it's a heck of lot easier to track them," Wisniewski said.

Google's anti-download approach differs from Microsoft's. IE9, which launched last month, includes a feature called 'SmartScreen Application Reputation' that uses a complex algorithm to rank the probability that a download is legitimate software.

Although Microsoft doesn't like to label Application Reputation, or 'App Rep', as a 'whitelist', it does resemble a pre-approved list. App Rep uses a file's hash - which identifies its contents - and the file's digital certificate to determine whether it's a known executable with an established reputation. If it's not, IE9 warns the user to beware.

Chrome's new warning will be tested with a small number of users running the 'dev' channel of Chrome before being added to the 'stable', or production-quality version, with Chrome 12, Google said.

Chrome's stable edition now stands at v. 10, which was released a month ago. Assuming Google keeps to its usual practice of rolling out a new version of Chrome every six to eight weeks, Chrome 12 should reach users between the end of May and the end of June 2011.

Other browsers will also be able to tap Safe Browsing for comparable features.

"This is a new project and we are still working out some of the finer details," Google said. "[But] our goal with Safe Browsing has always been to make the internet a safer place for all users, regardless of which browser they are using. We hope that others will be able to use this data shortly."

Mozilla did not reply to a request for comment on whether it would use Google's technology to add an anti-download alert to Firefox.

"I think this could have an impact," said Wisniewski. "More tracking of malicious sites and downloads only helps everyone."

See also: Google fights to make HTTPS browsing safe


IDG UK Sites

OnePlus Two release date rumours: Something's happening on 22 July

IDG UK Sites

13in MacBook Air review, Apple's MacBook Air 2014 reviewed

IDG UK Sites

5 reasons to buy an electric car and 5 reasons not to

IDG UK Sites

Evernote Skitch: the best way for creatives to doodle feedback