Brave version of 1.54 for desktop and Android will include more powerful features for controlling which sites can access local network resources and for how long.
Malicious requests from websites to access local host resources act as a fingerprinting technique which concerns users’ privacy and security at risk.
The conventional desktop version of web browsers like Chrome, safari, firefox, Mozilla, etc., allows secure and nonsecure public sites to access your local host resources.
Local host resources are nothing but images and web pages that are hosted by other software on your local machine.
Browsers allow websites to access localhost resources for various reasons, but the main two reasons are historical legacy and backward compatibility.
Generally, browsers did not strictly enforce the distinctions between first-party resources (those hosted by the website you’re visiting), third-party resources (those hosted on other public websites), and local-host resources due to a decreased concern for user privacy.
Due to this vulnerability, a significant amount of software has been created to be freely accessible via websites that are invisible to users.
And many of these uses are acceptable. Examples include specific cryptocurrency wallets, security software offered by banks or security firms, and gear whose configuration uses specific Web interfaces.
Unfortunately, a large variety of harmful, user-harming software on the Internet makes use of access to local-host resources for illicit purposes.
To re-identify you, for instance, fingerprinting scripts look for specific patterns in the other software you have operating on your device.
Other scripts look for weak or susceptible software on the system and attempt to attack.
Unlike other browsers, Brave puts you in control of your data. The secure browser automatically blocks trackers and unwanted ads while also providing anti-phishing and anti-malware protection.
Brave is the only popular browser to ship multiple protections against sites maliciously accessing localhost resources. Brave currently uses filter list rules to:
Brave has developed a new approach for protecting users against sites abusing local network resources. This new system will have the following parts:
Furthermore, Brave enhances its protections deeper in the network stack, so that Brave can protect users against additional, less common methods of sites making localhost requests (including DNS records that refer to localhost).
“AI-based email security measures Protect your business From Email Threats!” – .
The U.S. government has offered a prize of up to $5 million for information that leads to the arrest and…
Russia leverages a mix of state-backed Advanced Persistent Threat (APT) groups and financially motivated cybercriminals to achieve its strategic goals,…
Researchers discovered four significant vulnerabilities in the ThroughTek Kalay Platform, which powers 100 million IoT-enabled devices. Notably, ThroughTek Kalay's influence…
The App Store will close over 370 million developer and customer accounts in 2023. Apple takes this move to fight…
VirusTotal has announced a major change to its Crowdsourced AI project: it has added a new AI model that can…
Multiple security flaws affecting VMware Workstation and Fusion have been addressed by upgrades published by VMware. If these vulnerabilities are…