<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" 
      xmlns:thr="http://purl.org/syndication/thread/1.0">
  <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php" />
  <link rel="self" type="application/atom+xml" href="http://www.readwriteweb.com/atom.xml" />
  <id>tag:www.readwriteweb.com,2011:/1/tag:www.readwriteweb.com,2008://1.7153-</id>
  <updated>2011-04-29T11:04:57Z</updated>
  <title>Comments for Serious Security Flaw in Google Chrome</title>
  
  <generator uri="http://www.sixapart.com/movabletype/">Movable Type 4.35-en</generator>
  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153</id>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php" />
    <link rel="service.edit" type="application/atom+xml" href="http://www.readwriteweb.com/cgi-bin/mt/mt-atom.cgi/weblog/blog_id=1/entry_id=7153" title="Serious Security Flaw in Google Chrome" />
    <published>2008-09-03T04:47:28Z</published>
    <updated>2008-09-03T21:45:57Z</updated>
    <title>Serious Security Flaw in Google Chrome</title>
    <summary>Google Chrome has quickly become one of our favorite browsers here at RWW, but as Ryan Narraine, a security evangelist at Kaspersky Lab, reports, Chrome has also inherited a potentially serious security flaw from the old version of WebKit it is based on. An attacker could easily trick users into launching an executable Java file...</summary>
    <author>
      <name>Frederic Lardinois</name>
      
    </author>
    
    <category term="Browsers" />
    
    <category term="Google" />
    
    <category term="News" />
    
    <content type="html" xml:lang="en" xml:base="http://www.readwriteweb.com/">
      <![CDATA[<p><img alt="chromologo2.jpg" src="http://www.readwriteweb.com/images/chromologo2.jpg" />Google Chrome has quickly become <a href="http://www.readwriteweb.com/archives/chrome_test_it_with_us_live.php">one of our favorite browsers</a> here at RWW, but as Ryan Narraine, a security evangelist at Kaspersky Lab, <a target="_blank" href="http://blogs.zdnet.com/security/?p=1843">reports</a>, Chrome has also inherited a potentially serious security flaw from the old version of WebKit it is based on. An attacker could easily trick users into launching an executable Java file by combining a flaw in WebKit with a known Java bug and some smart social engineering.</p>

<p><font style="float: right; margin-left: 10px;"><script type="text/javascript">digg_url = 'http://digg.com/tech_news/Serious_Security_Flaw_in_Google_Chrome';digg_bgcolor = '#ffffff';digg_skin = 'normal';</script><script src="http://digg.com/tools/diggthis.js" type="text/javascript"></script></font>Security expert <a target="_blank" href="http://aviv.raffon.net/">Aviv Raff</a>, who first discovered this flaw, set up a <a target="_blank" href="http://raffon.net/research/google/chrome/carpet.html">demo</a> of the exploit here. (<strong>Note</strong>: This page will automatically download a Java file onto your desktop). You can safely click on the download, as it only opens up a notepad application written in Java. </p>]]>
      <![CDATA[<h2>Carpet-Bombing</h2>

<p><img alt="chome_exploit.png" align="right" src="http://www.readwriteweb.com/images/chome_exploit.png" />The problem here is that, after a user double-clicks the download at the bottom of the screen, this application is opened without any warning, which would allow a malicious hacker to easily execute any Java program on a user's machine.</p>

<p>Two facts make this exploit especially embarrassing for Google. First of all, Google stressed the security of Chrome in both the <a href="http://www.google.com/intl/en/press/pressrel/20080902_chrome.html">official announcement</a> as well as in today's live video demo just before the launch. </p>

<h2>Apple Already Did It</h2>

<p>More importantly, as <a target="_blank" href="http://blogs.zdnet.com/security/?p=1843">ZDNet reports</a>, Apple already patched WebKit against this flaw when it released Safari 3.2.1 in July, though only after the flaw had been <a target="_blank" href="http://www.theregister.co.uk/2008/05/15/apple_safari_carpet_bombing_vuln/">known already</a> for more than two months. Google, however, is using an older version of WebKit as the basis for Chrome. </p>

<h2>Social Engineering</h2>

<p>Obviously, this exploit only works because of the social engineering behind it. Just like some pop-up ads trick users into clicking "OK" because the ad mimics a typical system message in Windows, this exploit would trick users who are not yet familiar with Chrome's interface into believing that the download is actually just part of the web page. </p>

<p>We assume that Google will patch this flaw a lot <a target="_blank" href="http://digg.com/security/Apple_OK_with_Safari_s_Carpet_Bombing_Vulnerability">faster</a> than Apple did, but this news definitely puts a bit of a damper on our enthusiasm for Chrome.</p>

<p><b>EDITOR'S UPDATE:</b> we've been all over the Chrome story for the past few days, so here is a summary of our coverage so far:</p>

<p>- <a href="http://www.readwriteweb.com/archives/video_of_google_chrome_announcement.php">Video of Google Chrome Announcement</a><br />
- <a href="http://www.readwriteweb.com/archives/chrome_test_it_with_us_live.php">Chrome: Test it With Us Live</a> (check out Sarah Perez's screencast, with input from all the RWW team)<br />
- <a href="http://www.readwriteweb.com/archives/does_google_have_rights_to_all.php">Does Google Have Rights to Everything You Send Through Chrome?</a> (great discussion happening in the comments of this one)<br />
- <a href="http://www.readwriteweb.com/archives/google_to_offer_its_own_browser_chrome.php">Google to Offer its Own Browser: Chrome</a> (our original post)</p>]]>
    </content>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:297113</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c297113" />
    <title>Comment from yuregininsesi on 2011-01-10</title>
    <author>
        <name>yuregininsesi</name>
        <uri>http://www.yuregininsesi.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.yuregininsesi.com">
        <![CDATA[<p>Come on guys, it&#39;s still in beta so let&#39;s just give them a break and wait for the final build.<br /><a href="http://www.seslisohbetevi.com" rel="nofollow">sesli chat</a> <a href="http://www.seslisohbetevi.com" rel="nofollow">sesli sohbet</a> <a href="http://www.seslisohbetevi.com" rel="nofollow">chat roulette</a> <a href="http://www.seslisohbetevi.com" rel="nofollow">omegle</a></p>]]>
    </content>
    <published>2011-01-10T23:49:30Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:112427</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c112427" />
    <title>Comment from chess tactics on 2008-09-30</title>
    <author>
        <name>chess tactics</name>
        <uri>http://www.chess-tactics.net/</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.chess-tactics.net/">
        <![CDATA[<p>Ok, so google chrome has become one of the favorite browsers. But I still feel that mozilla and internet explorer is far more better than chrome. <br />
Especially for the SEO's google chrome doesn't provide any help. Does it ?</p>]]>
    </content>
    <published>2008-10-01T05:35:06Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:67116</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c67116" />
    <title>Comment from Chromer on 2008-09-18</title>
    <author>
        <name>Chromer</name>
        <uri>http://chromeguru.info/index.php</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://chromeguru.info/index.php">
        <![CDATA[<p>Dont forget to visit <a href="http://chromeguru.info" rel="nofollow">http://chromeguru.info</a> for Google Chrome Themes.</p>

<p>Over 60 themes added to the filebase.</p>]]>
    </content>
    <published>2008-09-18T23:00:24Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:66922</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c66922" />
    <title>Comment from Junaid on 2008-09-16</title>
    <author>
        <name>Junaid</name>
        <uri>http://www.junaid.biz/</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.junaid.biz/">
        <![CDATA[<p>I really like Chrome. It is extremely fast and really easy to work with. The main feature i did like is "Type in the address bar and get suggestions for both search and web pages."</p>]]>
    </content>
    <published>2008-09-17T03:47:43Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:66691</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c66691" />
    <title>Comment from Ari Rigopoulos on 2008-09-14</title>
    <author>
        <name>Ari Rigopoulos</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>Since I installed Chrome I have lost use of my page scroll.</p>]]>
    </content>
    <published>2008-09-15T02:00:08Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:66640</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c66640" />
    <title>Comment from Chris Lees on 2008-09-13</title>
    <author>
        <name>Chris Lees</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>Google should be criticised if this security issue exists with Chrome. They made the decision to use a piece of Apple software for an untrusted-web-facing service when Apple is known to take a lax position on security. I'm also criticising KDE and Gnome for also jumping on board the Webkit dinghy; KDE from the excellent KHTML and Gnome from Gecko.</p>

<p>However, the people saying that Apple was quicker to fix the problem than Google are only telling half the story. Apple introduced the security flaw and knew about it for two months before fixing it. Apple left a "passwords being sent in cleartext" bug in OS X Server for six months after it had been fixed upstream. There is also a local root exploit in desktop OS X, that only requires a single line of Applescript to trigger, that has been around for years and has not even been fixed in development versions of Snow Leopard.</p>

<p>In addition, the original iPhone shipped with an old version of Webkit that contained a similar flaw, when the Mac version of Safari had fixed it. This was a flaw that had been fixed in Internet Explorer 6 literally years beforehand, and we all know that it's rare for IE 6 to rightly claim security superiority :-P</p>

<p>I infinitely trust Google more with web software than Apple, but not if they use Apple code in it.</p>]]>
    </content>
    <published>2008-09-14T03:46:46Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:66636</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c66636" />
    <title>Comment from jan niehaus on 2008-09-13</title>
    <author>
        <name>jan niehaus</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>Help get chrome out of my life. When I log on instead of connecting to firefox I get warnings chrome was not signed & firefox cannot see server. thank you </p>]]>
    </content>
    <published>2008-09-14T00:07:39Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:66537</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c66537" />
    <title>Comment from شات on 2008-09-12</title>
    <author>
        <name>شات</name>
        <uri>http://www.12allchat.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.12allchat.com">
        <![CDATA[<p>Well</p>

<p>I tried it my self, yes there is a security problem. i think google will fix it soon.</p>

<p><br />
thanx for info</p>]]>
    </content>
    <published>2008-09-12T18:10:19Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:66336</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c66336" />
    <title>Comment from hojjat on 2008-09-09</title>
    <author>
        <name>hojjat</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>only opera browser and nothing</p>]]>
    </content>
    <published>2008-09-10T01:40:41Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:66285</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c66285" />
    <title>Comment from SEO Blog on 2008-09-09</title>
    <author>
        <name>SEO Blog</name>
        <uri>http://www.bwdow.com/blog</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.bwdow.com/blog">
        <![CDATA[<p>Why did google announced it before finishing the software? Does anyone have opinion why did they released the beta directly to enduser?</p>]]>
    </content>
    <published>2008-09-09T18:18:42Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:66278</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c66278" />
    <title>Comment from mmanson on 2008-09-09</title>
    <author>
        <name>mmanson</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>chill down folks!</p>

<p>This "security flow" it have been already PATCHED. there is a new version 0.2.149.29</p>

<p>Well For apple took two month to fix his flaws.. for Google took about what...? two days ? </p>]]>
    </content>
    <published>2008-09-09T16:35:08Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:66127</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c66127" />
    <title>Comment from Glen LeBarr on 2008-09-08</title>
    <author>
        <name>Glen LeBarr</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>I downloaded the program and the very day it was released and I was exposed to a seriously nasty virus that totally hijacked my system. I don't know if it had anything to do with chrome or not, but after seemingly getting rid of it (or, so I thought) my computer has had numerous problems and I can't get Firefox or IE to work properly. Firefox won't even start and IE opens but when I do search on Google all the links in my search result open to totally unrelated sites. I believe the virus is called XP something or another. It's also caused my computer to freeze up whenever I do just about any function. I've tried numerous ways to get rid of this pest and just when I think I'm in the clear something else starts to go wrong. Like I said, I've never had a problem like this before when using IE or Firefox and I don't know if Chrome has allowed an unknown security flaw to screw up my computer or not. I hope not because otherwise I've been very impressed with this new browser, especially it's speed.</p>]]>
    </content>
    <published>2008-09-08T13:21:12Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:66069</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c66069" />
    <title>Comment from John Patton on 2008-09-07</title>
    <author>
        <name>John Patton</name>
        <uri>http://www.belgeci.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.belgeci.com">
        <![CDATA[<p>I just found a new security hole while im surfing the web, which causes Google Chrome stack-based buffer overflow. check it : </p>

<p><a href="http://www.computersake.com/2008/09/google-chrome-save-as-function-buffer-overflow-vulnerability/" rel="nofollow">http://www.computersake.com/2008/09/google-chrome-save-as-function-buffer-overflow-vulnerability/</a></p>]]>
    </content>
    <published>2008-09-07T21:44:21Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:66053</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c66053" />
    <title>Comment from jIMMAY on 2008-09-07</title>
    <author>
        <name>jIMMAY</name>
        <uri>http://dragonscanner.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://dragonscanner.com">
        <![CDATA[<p>this is not a serious security flaw in chrome.  and if you are so worried just scan files downloaded with DragonScanner: <a href="http://www.dragonscanner.com" rel="nofollow">http://www.dragonscanner.com</a></p>]]>
    </content>
    <published>2008-09-07T14:45:57Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:65945</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c65945" />
    <title>Comment from Andrew Heenan on 2008-09-06</title>
    <author>
        <name>Andrew Heenan</name>
        <uri>http://www.sick-site-syndrome.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.sick-site-syndrome.com">
        <![CDATA[<p>"Protect yourself - don't install Java."<br />
"Protect yourself - don't use Javascript"<br />
"Protect yourself - don't use cache"<br />
"Protect yourself - don't install Chrome"</p>

<p>Hey, why not go the whole hog? Turn off your computer and go live in a cave. So it ain't perfect? What is?</p>

<p>Live in total fear and total safety - or live a little, take a few minor risks, and get the benefit.</p>

<p>This 'flaw' requires not only the use of Chrome - but also a 'newbie level' of carelessness.</p>

<p>It need not be serious, it will be fixed, no need to knot the underwear.</p>]]>
    </content>
    <published>2008-09-06T12:27:06Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:65933</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c65933" />
    <title>Comment from Lightman on 2008-09-06</title>
    <author>
        <name>Lightman</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>People. There are two ways to counteract this "flaw".</p>

<p>1. As always, be smart about your browsing.</p>

<p>2. Go into your settings and disable auto-download (I did it as soon as I got the browser).</p>

<p>This may have been posted already, but I CBA to read everything :)</p>]]>
    </content>
    <published>2008-09-06T08:00:17Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:65914</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c65914" />
    <title>Comment from selin kare on 2008-09-05</title>
    <author>
        <name>selin kare</name>
        <uri>http://www.telefonfiyatlari.net</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.telefonfiyatlari.net">
        <![CDATA[<p>i think, Google will change again face of internet :)</p>]]>
    </content>
    <published>2008-09-06T01:07:34Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:65810</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c65810" />
    <title>Comment from zorex on 2008-09-05</title>
    <author>
        <name>zorex</name>
        <uri>http://blog.zorex.info</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://blog.zorex.info">
        <![CDATA[<p>I did report this using the feedback form. Auto download is very dangerous. </p>

<p>However, you can temporary overcome this prob in Chrome. Go to "Option > Minor Tweaks" and check the box "Ask where to save each file before downloading" under the "Download location" section. Like this, every time when you are downloading files (automated or you click on it), there will be a dialog box asking you where to save the file. You can click cancel if you found out the file is weird. </p>]]>
    </content>
    <published>2008-09-05T09:35:58Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:65801</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c65801" />
    <title>Comment from Google on 2008-09-04</title>
    <author>
        <name>Google</name>
        <uri>http://www.directorysearchin.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.directorysearchin.com">
        <![CDATA[<p>For moment Google Chrome is beta so in this case is normal to have bugs</p>]]>
    </content>
    <published>2008-09-05T06:10:29Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:65789</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c65789" />
    <title>Comment from Filip on 2008-09-04</title>
    <author>
        <name>Filip</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>Hey i've been using chrome for a day now and there's something that bothers me. Let's say when I want to download a word document it doesn't give me an option to open it, i can just save it and then manually open it. Can you change this somewhere in the options, cause i can't find it.</p>]]>
    </content>
    <published>2008-09-05T04:33:13Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:65750</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c65750" />
    <title>Comment from kameko on 2008-09-04</title>
    <author>
        <name>kameko</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>who cares if its still in 'beta'? gmail has been in BETA for years. that doesn't excuse anything.</p>]]>
    </content>
    <published>2008-09-04T20:04:53Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:65726</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c65726" />
    <title>Comment from Erol on 2008-09-04</title>
    <author>
        <name>Erol</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>That's a pretty nasty flaw, but it's not as serious compared to the GDI+ vulnerability a few years ago.</p>]]>
    </content>
    <published>2008-09-04T17:24:47Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:65710</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c65710" />
    <title>Comment from David Chudleigh on 2008-09-04</title>
    <author>
        <name>David Chudleigh</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>I think the loser here will be Opera's market share.  Firefox and Chrome are distinct enough but Opera and Chrome appear more familiar and Opear does not have the plug-ins quality Firefox and eventualy Google can bring.</p>]]>
    </content>
    <published>2008-09-04T14:27:40Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:65697</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c65697" />
    <title>Comment from Wogan May on 2008-09-04</title>
    <author>
        <name>Wogan May</name>
        <uri>http://woganmay.com/</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://woganmay.com/">
        <![CDATA[<p>Sweet - I got a free notepad app...</p>]]>
    </content>
    <published>2008-09-04T10:57:48Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:65694</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c65694" />
    <title>Comment from Michael on 2008-09-04</title>
    <author>
        <name>Michael</name>
        <uri>http://cybersurge.org</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://cybersurge.org">
        <![CDATA[<p>Can someone say beta?</p>]]>
    </content>
    <published>2008-09-04T10:45:07Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:65685</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c65685" />
    <title>Comment from truthsayerlol on 2008-09-04</title>
    <author>
        <name>truthsayerlol</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>ahhh another angry macfag getting pissy over new software<br />
guess theve never been in a world where software isnt child-proof, these "security flaws" are not security flaws if you know what you are doing when using the program,<br />
a) its in beta, <br />
heres a tip for you type into google - define:beta<br />
b) ffs its been released for all of what? a frakking day!<br />
well if you arnt a bunch of pissy whining want-it now nubs<br />
ITS OPEN SOURCE - dont like it? fix it yourself!<br />
if you cant, then learn, dont rip into anotherwise exceptional piece of new software that is going against the big leagues of IE and Mozilla, (Safari is not a good browser as much as you wish it is, it really is not).</p>

<p>and as a final point, lookup what a security flaw is, plenty of info on that for IE and Safari, then google define:dumbass and youll find a picture of yourself for not being able to tell the difference between what someone else is doing right and your doing wrong</p>

<p>tata</p>]]>
    </content>
    <published>2008-09-04T08:19:04Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:65678</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c65678" />
    <title>Comment from Kamal Mettananda on 2008-09-03</title>
    <author>
        <name>Kamal Mettananda</name>
        <uri>http://lkamal.blogspot.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://lkamal.blogspot.com">
        <![CDATA[<p>Another reason not to switch to Chrome from Firefox too early.</p>

<p>But for sure, they fix this much sooner.</p>]]>
    </content>
    <published>2008-09-04T06:40:27Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:65670</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c65670" />
    <title>Comment from mark on 2008-09-03</title>
    <author>
        <name>mark</name>
        <uri>http://free-xbox-360-premium.blogspot.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://free-xbox-360-premium.blogspot.com">
        <![CDATA[<p>It's only beta.</p>]]>
    </content>
    <published>2008-09-04T04:38:48Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:65654</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c65654" />
    <title>Comment from bcarter on 2008-09-03</title>
    <author>
        <name>bcarter</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>Who gives a sh*t.</p>]]>
    </content>
    <published>2008-09-04T02:54:54Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:65643</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c65643" />
    <title>Comment from sEwer on 2008-09-03</title>
    <author>
        <name>sEwer</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>It's not a security flaw, IMHO. It just the fact, that Chrome is for smart people, it doesn't need to be idiot-proof. Don't double-click the damn file if You don't know what it is. If You wan't someone to ask You if You know what You're doing, go buy a Vista System.</p>]]>
    </content>
    <published>2008-09-04T01:38:46Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:65636</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c65636" />
    <title>Comment from Anon on 2008-09-03</title>
    <author>
        <name>Anon</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>i tried the demo and Vista actually managed to help for once in its miserable existence. It comes up with the "allow or cancel" something i opened. For once Vista did something right. well thats not saying much at all is it?</p>]]>
    </content>
    <published>2008-09-04T00:38:06Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:65632</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c65632" />
    <title>Comment from Captain Obvious on 2008-09-03</title>
    <author>
        <name>Captain Obvious</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>Posting "security bugs" for beta software is kinda lame from an esthetic perspective, but tempting because it get's you in the news without real effort ...  </p>]]>
    </content>
    <published>2008-09-04T00:12:49Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:65616</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c65616" />
    <title>Comment from Groucho Marx on 2008-09-03</title>
    <author>
        <name>Groucho Marx</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>I have always learned that bread and butter tastes better than butter and bread....</p>

<p>Google claims to only employ the best of the best but it took a 9 to 5 journalist less than a few hours to find vulnerabilities in the Chrome product. Well it only gets to show you that Groucho was right after all...you never know who is blessed with common sense or not. </p>]]>
    </content>
    <published>2008-09-03T23:05:35Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:65615</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c65615" />
    <title>Comment from Question on 2008-09-03</title>
    <author>
        <name>Question</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>Somebody please kindly respond to this question: </p>

<p>Above, somebody said Chrome is self-updating. Does this mean it updates its versions automatically on the fly, behind the scenes, without prompting the user? </p>]]>
    </content>
    <published>2008-09-03T23:03:39Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:65610</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c65610" />
    <title>Comment from Sotek on 2008-09-03</title>
    <author>
        <name>Sotek</name>
        <uri>http://www.vault45.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.vault45.com">
        <![CDATA[<p>Come on guys, it's still in beta so let's just give them a break and wait for the final build.</p>]]>
    </content>
    <published>2008-09-03T22:49:03Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:65603</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c65603" />
    <title>Comment from jonny on 2008-09-03</title>
    <author>
        <name>jonny</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>I can't scroll down in Google Chrome God DAMMIT!  Will someone please fix it!</p>]]>
    </content>
    <published>2008-09-03T22:18:26Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:65595</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c65595" />
    <title>Comment from noname on 2008-09-03</title>
    <author>
        <name>noname</name>
        <uri>http://idonothaveasite.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://idonothaveasite.com">
        <![CDATA[<p>Remember, google chrome IS still in beta.</p>

<p>(posted via g. chrome)</p>]]>
    </content>
    <published>2008-09-03T21:37:27Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:65594</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c65594" />
    <title>Comment from Saint Germain on 2008-09-03</title>
    <author>
        <name>Saint Germain</name>
        <uri>http://www.saintger.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.saintger.com">
        <![CDATA[<p>I like google chrome, its very fast, but i will keep my firefox ;-)</p>]]>
    </content>
    <published>2008-09-03T21:23:54Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:65590</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c65590" />
    <title>Comment from Ryan Svoboda on 2008-09-03</title>
    <author>
        <name>Ryan Svoboda</name>
        <uri>http://duffsdevice.blogspot.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://duffsdevice.blogspot.com">
        <![CDATA[<p>I haven't seen anyone else mention it so far, but I wrote up a quick post complaining about a small security flaw with Chrome; there is no way to set a master password for your saved login information.<br />
<a href="http://duffsdevice.blogspot.com/2008/09/google-chrome-overlooks-one-small.html" rel="nofollow"><br />
Duff's Device: Google Chrome overlooks one small security flaw</a></p>

<p>I did notice earlier today that while I was browsing Facebook, Chrome automatically downloaded the file us-120other.html twice. Not sure what it is or why it was downloaded. </p>

<p>Looking into it I see (curlys to simulate html brackets):</p>

<pre>
{script 
type="text/javascript" src="http://Ads1.msn.com/library/dap.js" }
{/script}
{script 
type="text/javascript"}
dap('&PG=FBK600&AP=1113', 120, 600);
{/script}
{img src="http://ads.ak.facebook.com/ads/creative/1x1/msn/us-120other.gif" height="1" width="1" border="0"}
</pre>
Side note: <a href="http://Ads1.msn.com/" rel="nofollow">http://Ads1.msn.com/</a> redirects to <a href="http://advertising.microsoft.com/home/home" rel="nofollow">http://advertising.microsoft.com/home/home</a>
]]>
    </content>
    <published>2008-09-03T21:13:20Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:65588</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c65588" />
    <title>Comment from Mark on 2008-09-03</title>
    <author>
        <name>Mark</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>It doesn't download anything.  It brings up a window asking me to download something.  Just cancel it.  I don't see a security flaw at all.</p>

<p>Pretty soon people are going to think opening a web page is a flaw.</p>]]>
    </content>
    <published>2008-09-03T21:03:33Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:65587</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c65587" />
    <title>Comment from SSTRM on 2008-09-03</title>
    <author>
        <name>SSTRM</name>
        <uri>http://sstrmblog.blogspot.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://sstrmblog.blogspot.com">
        <![CDATA[<p>Pobody's Nerfect. Also Chrome its still in beta. Nothing else to see here.</p>]]>
    </content>
    <published>2008-09-03T20:58:44Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:65585</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c65585" />
    <title>Comment from Bob Foster on 2008-09-03</title>
    <author>
        <name>Bob Foster</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>What's the big deal? The page downloads a file. If you open the file you get the usual dialog warning you are about to run an executable file. If you're stupid enough to run it, you deserve what you get instead of your "Free Coupwn".</p>]]>
    </content>
    <published>2008-09-03T20:39:25Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:65584</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c65584" />
    <title>Comment from Jish Denson on 2008-09-03</title>
    <author>
        <name>Jish Denson</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>I guess with any new release there is ALWAYS going to be bugs. Comes with the territory. I have been playing with Chrome all day and so far still think Firefox 3 is the better browser. IMHO</p>

<p>Jish<br />
www.privacy.mx.tc</p>]]>
    </content>
    <published>2008-09-03T20:38:53Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:65579</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c65579" />
    <title>Comment from No Prompt on 2008-09-03</title>
    <author>
        <name>No Prompt</name>
        <uri>http://www.milw0rm.com/exploits/6355</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.milw0rm.com/exploits/6355">
        <![CDATA[<p>The exploit does not require any user interaction what so ever, but it does not execute this file. It would take a really retarded user to execute a file that just appeared one day.  And as other have said, it's a beta release, I would like to see how many exploits are found when Chrome goes GOLD.</p>

<p><br />
<a href="http://www.milw0rm.com/exploits/6355" rel="nofollow">http://www.milw0rm.com/exploits/6355</a></p>

<p><br />
</p>]]>
    </content>
    <published>2008-09-03T20:09:07Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:65577</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c65577" />
    <title>Comment from harry on 2008-09-03</title>
    <author>
        <name>harry</name>
        <uri>http://www.instantplay.org</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.instantplay.org">
        <![CDATA[<p>I really like chrome but im leaving for abit as to many reports of problems at the moment</p>]]>
    </content>
    <published>2008-09-03T20:05:00Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:65574</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c65574" />
    <title>Comment from ToastyMallows on 2008-09-03</title>
    <author>
        <name>ToastyMallows</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>It's the beta version and it's open-source, why not suggest that this be fixed or fix it yourself?</p>]]>
    </content>
    <published>2008-09-03T20:01:28Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:65573</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c65573" />
    <title>Comment from emerson on 2008-09-03</title>
    <author>
        <name>emerson</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>This isnt a security flaw at all, no more than any other "executable" file that a user can be made to launch.</p>

<p>If a user is stupid enough to click the download button in Chrome, they will surely be stupid enough to just double click the "executable" in their downloads folder too.</p>

<p>Its exactly the same as opening an email attachment.  I dont see how it has anything to do with Chrome at all, unless your suggesting Chrome should block running programs that have been downloaded ? - Thats just denial of responsibility though, not security.</p>

<p>On my system it does nothing, becuase the choice of what to do with an "executable" file is up to Windows, and i have the ".jar" extension registered to an archive program, since jars are just zip files anyway.</p>]]>
    </content>
    <published>2008-09-03T19:59:18Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:65571</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c65571" />
    <title>Comment from Sergiv Brin on 2008-09-03</title>
    <author>
        <name>Sergiv Brin</name>
        <uri>http://google.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://google.com">
        <![CDATA[<p>damper, fags.</p>]]>
    </content>
    <published>2008-09-03T19:54:34Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:65561</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c65561" />
    <title>Comment from dg on 2008-09-03</title>
    <author>
        <name>dg</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>I would not call this a security flaw.  The user must perform an action, clicking on a button, before any malicious activity can take place.</p>

<p>I configure my browsers to "Always ask where to save a downloaded file".  Thus in my case I get the save as dialog before any download actually occurs.</p>

<p>It actually took me a moment to even see what the big deal was, then I remembered that by default the file is just saved to your desktop.</p>

<p>Is this a usability issue?  YES. Google will need to add prompts and/or make it obvious that the download bar is not part of the window.</p>]]>
    </content>
    <published>2008-09-03T19:19:33Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:65554</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c65554" />
    <title>Comment from graeme on 2008-09-03</title>
    <author>
        <name>graeme</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>@all those getting the hump cos of a minor flaw in a free beta product:</p>

<p>1. if you're not prepared to take the risk then don't install it (it's not compulsory), and let those of us who do like it get on and enjoy it in peace.</p>

<p>2. it is open source. if you don't like it, patch it yourself.</p>]]>
    </content>
    <published>2008-09-03T18:54:34Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:65552</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c65552" />
    <title>Comment from please.... on 2008-09-03</title>
    <author>
        <name>please....</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>This is not a 'serious' flaw, a serious flaw requires nothing but a page load to work.  For this flaw to work a person needs to open an  executable file from their chrome downloads bar!  </p>]]>
    </content>
    <published>2008-09-03T18:47:43Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:65537</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c65537" />
    <title>Comment from F. Andy Seidl on 2008-09-03</title>
    <author>
        <name>F. Andy Seidl</name>
        <uri>http://faseidl.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://faseidl.com">
        <![CDATA[<p>The interesting questions to me are not if Chrome (beta) is ready for prime time (it is not) or which established browser will suffer most (they all will.)  What I find more interesting is that it appears to have all the trappings of a disruptive technology hiding in plain sight.</p>

<p>I wrote more about this idea here:</p>

<p>Google Chrome: Disruptive Technology<br />
<a href="http://faseidl.com/public/blog/212172" rel="nofollow">http://faseidl.com/public/blog/212172</a></p>]]>
    </content>
    <published>2008-09-03T17:24:21Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:65511</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c65511" />
    <title>Comment from Matt on 2008-09-03</title>
    <author>
        <name>Matt</name>
        <uri>http://mattwalters.net/</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://mattwalters.net/">
        <![CDATA[<p>Those of you claiming it's ok because it's a beta should really watch that argument when defending Google.  I agree, the product just came out, and they'll need a little bit to get a patch out.</p>

<p>But don't forget, lots of Google's products and services stay in "Beta" forever.  They can't continue to hide under that.  Google has effectively made "Beta" into "release/stable" for themselves.  They don't really deserve any extra slack because of the Beta label like an independent developer might.  They need to properly use the term if they want the slack from users it should provide.</p>]]>
    </content>
    <published>2008-09-03T15:07:26Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:65510</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c65510" />
    <title>Comment from Jordan Hofker on 2008-09-03</title>
    <author>
        <name>Jordan Hofker</name>
        <uri>http://friendfeed.com/jhofker</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://friendfeed.com/jhofker">
        <![CDATA[<p>Protect yourself - don't install Java.</p>]]>
    </content>
    <published>2008-09-03T14:57:18Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:65508</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c65508" />
    <title>Comment from NickC321 on 2008-09-03</title>
    <author>
        <name>NickC321</name>
        <uri>http://friendfeed.com/nickc321</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://friendfeed.com/nickc321">
        <![CDATA[<p>I guess this is one of those few times I should be happy that an app isn't available for Mac or Linux yet....</p>]]>
    </content>
    <published>2008-09-03T14:49:25Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:65491</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c65491" />
    <title>Comment from JulesLt on 2008-09-03</title>
    <author>
        <name>JulesLt</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>>Google has used a vulnerable version of webkit 4 months after this vulnerability is >discovered.</p>

<p>In a BETA piece of software. As in unfinished, use at your own risk, not ready for the primetime.</p>]]>
    </content>
    <published>2008-09-03T12:05:48Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:65488</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c65488" />
    <title>Comment from Carlos Alonso on 2008-09-03</title>
    <author>
        <name>Carlos Alonso</name>
        <uri>http://astillero.org</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://astillero.org">
        <![CDATA[<p>No, Google will not patch this bug faster than Apple. Apple already patched it (although it took them 2 months to do it), and Google don't. Google has used a vulnerable version of webkit 4 months after this vulnerability is discovered. Great!</p>]]>
    </content>
    <published>2008-09-03T10:43:57Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:65479</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c65479" />
    <title>Comment from The wedding on 2008-09-03</title>
    <author>
        <name>The wedding</name>
        <uri>http://www.eweddingphotographers.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.eweddingphotographers.com">
        <![CDATA[<p>A new services of google ?<br />
</p>]]>
    </content>
    <published>2008-09-03T07:46:07Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:65476</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c65476" />
    <title>Comment from Wolf on 2008-09-03</title>
    <author>
        <name>Wolf</name>
        <uri>http://www.wolfslittlestore.be</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.wolfslittlestore.be">
        <![CDATA[<p>Look, they needed to get a browser out of the door. Patching webkit up to the latest version is probably not as easy as it sounds. I'm sure they're pretty much aware that if they're using an older build of Webkit, all the security issues that have been discovered during when they took the build and now are real.</p>]]>
    </content>
    <published>2008-09-03T07:12:15Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:65474</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c65474" />
    <title>Comment from abacab on 2008-09-02</title>
    <author>
        <name>abacab</name>
        <uri>http://friendfeed.com/abacab</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://friendfeed.com/abacab">
        <![CDATA[<p>I seriously don't imagine Google not saying -something- each time, given people will always be watching and willing to bust their chops over even the tiniest little flaw or issue that arises. I wonder, though, if announcements will have people looking for downloads or update links to click on when none exist...</p>]]>
    </content>
    <published>2008-09-03T06:38:35Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:65472</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c65472" />
    <title>Comment from Steven Hodson on 2008-09-02</title>
    <author>
        <name>Steven Hodson</name>
        <uri>http://friendfeed.com/stevenhodson</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://friendfeed.com/stevenhodson">
        <![CDATA[<p>abacab I just wonder how vocal they are going to be about any updates made .. will they just slide them in place without any fanfare or will we be told about them</p>]]>
    </content>
    <published>2008-09-03T06:16:34Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:65471</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c65471" />
    <title>Comment from abacab on 2008-09-02</title>
    <author>
        <name>abacab</name>
        <uri>http://friendfeed.com/abacab</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://friendfeed.com/abacab">
        <![CDATA[<p>What almost makes this a non-issue is that Chrome's entirely self-updating, self-healing (barring nontrivial disabling of the software, lack of Internet connection, etc). You won't have to do anything. And... you know Google can and will patch (stuff like) this hella faster than Apple does (or did, this particular WebKit flaw instance).</p>]]>
    </content>
    <published>2008-09-03T06:13:57Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:65470</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c65470" />
    <title>Comment from Chris Baskind on 2008-09-02</title>
    <author>
        <name>Chris Baskind</name>
        <uri>http://friendfeed.com/chrisbaskind</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://friendfeed.com/chrisbaskind">
        <![CDATA[<p>Sweetchrome or Sweetcrap?</p>]]>
    </content>
    <published>2008-09-03T06:06:51Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:65469</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c65469" />
    <title>Comment from Steven Hodson on 2008-09-02</title>
    <author>
        <name>Steven Hodson</name>
        <uri>http://friendfeed.com/stevenhodson</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://friendfeed.com/stevenhodson">
        <![CDATA[<p>Bad Sarah - back to dungeon with you :)</p>]]>
    </content>
    <published>2008-09-03T06:06:05Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:65468</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c65468" />
    <title>Comment from Charlie Anzman on 2008-09-02</title>
    <author>
        <name>Charlie Anzman</name>
        <uri>http://friendfeed.com/charlieanzman</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://friendfeed.com/charlieanzman">
        <![CDATA[<p>Sure, you had to go and ruin the party :)</p>]]>
    </content>
    <published>2008-09-03T06:00:22Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:65467</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c65467" />
    <title>Comment from PC on 2008-09-02</title>
    <author>
        <name>PC</name>
        <uri>http://pcsplace.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://pcsplace.com">
        <![CDATA[<p>First flaw.. <br />
may be there are many more coz its just a beta version.. </p>

<p>These will be corrected in the final version I guess..</p>]]>
    </content>
    <published>2008-09-03T05:53:52Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.7153-comment:65466</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.7153" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php#c65466" />
    <title>Comment from Nag on 2008-09-02</title>
    <author>
        <name>Nag</name>
        <uri>http://littleswaps.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://littleswaps.com">
        <![CDATA[<p>This is kind of the First Security flaw on Chrome i guess.</p>

<p>Good and nice post</p>

<p>Cheers, Nag</p>]]>
    </content>
    <published>2008-09-03T05:43:50Z</published>
  </entry>

</feed>
