Chrome tips users to dangerous Windows downloads

Google follows Microsoft's lead, will warn users of unsafe downloads before they reach the PC

Google on Tuesday said it will add malware download warnings to its Chrome browser.

The move has Google following the lead of rival Microsoft, whose Internet Explorer 9 also alerts users about questionable software downloads.

Google will use its Safe Browsing service to flag sketchy downloads, the company said in a post on a company blog. Chrome, Mozilla's Firefox and Apple's Safari already tap into Safe Browsing -- which identifies suspicious or unsafe sites and then adds them to a blacklist -- to warn users of dangerous sites before they actually visit those sites.

Safe Browsing will also provide the data for Chrome's download blocker, said Google.

When a Chrome user tries to download a Windows executable -- a file with the ".exe" suffix -- from a URL on the Safe Browsing blacklist, the browser will display a warning that reads, "This file appears to be malicious. Are you sure you want to continue?"

Extending Safe Browsing to downloads helps shut a malware door, Google argued.

"A separate attack vector exists, which is a social engineering mechanism that attempts to convince a user to download and run a file," Google said in an email reply to questions Wednesday. "This new feature is designed to protect against that type of attack."

Chet Wisniewski, a security researcher at Sophos, a U.K.-based security vendor, agreed.

"This fills in the other half of the puzzle," said Wisniewski, explaining that while Chrome already alerts users of dodgy sites that launch drive-by attacks, that's not enough. "There are millions of [malicious sites], more than Safe Browsing can track, but they all point to a smaller number, still in the tens of thousands but smaller, that contain downloads."

Malware distribution sites don't change at the same speed that sites redirecting to them do, and they're much more likely to be tagged by Safe Browsing. "The number of sites at the bottom [that distribute malware] is small enough that it's a heck of lot easier to track them," Wisniewski said.

Google's anti-download approach differs from Microsoft's. IE9, which launched last month, includes a feature called "SmartScreen Application Reputation" that uses a complex algorithm to rank the probability that a download is legitimate software.

Although Microsoft doesn't like to label Application Reputation, or "App Rep," as a "whitelist," App Rep does resemble a list of pre-approved apps. App Rep uses a file's hash -- which identifies its contents -- and the file's digital certificate to determine whether it's a known executable with an established reputation. If it's not, IE9 warns the user to beware.

Chrome's new warning will be tested with a small number of users running the "dev" channel of Chrome before being added to the "stable," or production-quality version, of Chrome 12, Google said.

Chrome's stable edition now stands at Version 10, which was released a month ago. Assuming Google keeps to its usual practice of rolling out a new version of Chrome every six to eight weeks, Chrome 12 should reach users sometime between the end of May and the end of June 2011.

Other browsers will also be able to tap Safe Browsing for comparable features.

"This is a new project, and we are still working out some of the finer details," Google said in its email on Wednesday. "[But] our goal with Safe Browsing has always been to make the Internet a safer place for all users, regardless of which browser they are using. We hope that others will be able to use this data shortly."

Mozilla did not reply to a request for comment on whether it would use Google's technology to add an anti-download alert tool to Firefox.

"I think this could have an impact," said Wisniewski. "More tracking of malicious sites and downloads only helps everyone."

Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at Twitter@gkeizer, or subscribe to Gregg's RSS feed Keizer RSS. His e-mail address is

Join the CSO newsletter!

Error: Please check your email address.

Tags google web browserweb browserssecuritychrome

More about AppleGoogleMicrosoftMozillaSophos

Show Comments

Featured Whitepapers

Editor's Recommendations

Solution Centres

Stories by Gregg Keizer

Latest Videos

  • 150x50

    CSO Webinar: Will your data protection strategy be enough when disaster strikes?

    Speakers: - Paul O’Connor, Engagement leader - Performance Audit Group, Victorian Auditor-General’s Office (VAGO) - Nigel Phair, Managing Director, Centre for Internet Safety - Joshua Stenhouse, Technical Evangelist, Zerto - Anthony Caruana, CSO MC & Moderator

    Play Video

  • 150x50

    CSO Webinar: The Human Factor - Your people are your biggest security weakness

    ​Speakers: David Lacey, Researcher and former CISO Royal Mail David Turner - Global Risk Management Expert Mark Guntrip - Group Manager, Email Protection, Proofpoint

    Play Video

  • 150x50

    CSO Webinar: Current ransomware defences are failing – but machine learning can drive a more proactive solution

    Speakers • Ty Miller, Director, Threat Intelligence • Mark Gregory, Leader, Network Engineering Research Group, RMIT • Jeff Lanza, Retired FBI Agent (USA) • Andy Solterbeck, VP Asia Pacific, Cylance • David Braue, CSO MC/Moderator What to expect: ​Hear from industry experts on the local and global ransomware threat landscape. Explore a new approach to dealing with ransomware using machine-learning techniques and by thinking about the problem in a fundamentally different way. Apply techniques for gathering insight into ransomware behaviour and find out what elements must go into a truly effective ransomware defence. Get a first-hand look at how ransomware actually works in practice, and how machine-learning techniques can pick up on its activities long before your employees do.

    Play Video

  • 150x50

    CSO Webinar: Get real about metadata to avoid a false sense of security

    Speakers: • Anthony Caruana – CSO MC and moderator • Ian Farquhar, Worldwide Virtual Security Team Lead, Gigamon • John Lindsay, Former CTO, iiNet • Skeeve Stevens, Futurist, Future Sumo • David Vaile - Vice chair of APF, Co-Convenor of the Cyberspace Law And Policy Community, UNSW Law Faculty This webinar covers: - A 101 on metadata - what it is and how to use it - Insight into a typical attack, what happens and what we would find when looking into the metadata - How to collect metadata, use this to detect attacks and get greater insight into how you can use this to protect your organisation - Learn how much raw data and metadata to retain and how long for - Get a reality check on how you're using your metadata and if this is enough to secure your organisation

    Play Video

  • 150x50

    CSO Webinar: How banking trojans work and how you can stop them

    CSO Webinar: How banking trojans work and how you can stop them Featuring: • John Baird, Director of Global Technology Production, Deutsche Bank • Samantha Macleod, GM Cyber Security, ME Bank • Sherrod DeGrippo, Director of Emerging Threats, Proofpoint (USA)

    Play Video

More videos

Blog Posts

Market Place