DEF CON 32 - Sneaky Extensions  The MV3 Escape Artists - Vivek Ramachandran, Shourya Pratap Singh

DEF CON 32 - Sneaky Extensions The MV3 Escape Artists - Vivek Ramachandran, Shourya Pratap Singh

Source: YouTube · DEFCONConference · published Oct 16, 2024 · 20:30

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Browser extensions pose significant security risks as they can bypass security measures, intercept sensitive data, and perform malicious actions without user knowledge 1:17-1:27.

Key Takeaways:
• Browser extensions have powerful capabilities including content script injection that can modify web pages without explicit permissions 7:30-8:17
• Malicious extensions can bypass Content Security Policy restrictions using JavaScript techniques to execute remote code 9:35-11:55
• Extensions can perform social engineering attacks like fake update prompts that appear to come from legitimate websites 12:14-13:15
• Malicious extensions can intercept live video calls from platforms like Google Meet without any indication to the user 14:19-16:03
• Extensions can silently hijack accounts by accessing HTTP-only cookies and performing actions on behalf of users 16:26-17:51

Users should be extremely cautious when installing browser extensions, as even those from official stores can pose significant security threats.

Sources:

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

morning everyone thank you so much for coming I mean I know this is the very first talk happening literally in every single screen out there so really appreciate you making it out to ours U I'm VI ramachandran I have sh with me and we're going to talk about something very interesting sneaky extensions the mv3 Escape artists little bit about me I've been in cyber security 20 years very first Defcon 2007 when I spoke found multiple Wonder abilities uh started multiple cyber security companies now we run squarex a browser native security company hello everyone uh I'm sh I work as a principal software engineer at squarex uh my work mainly involves researching extensions uh Malaysia extensions and working on uh methods to actually tackle them and we have Sasha from the speaker Ops Team okay so …