Last
Friday, Tavis Ormandy, a Google Project Zero researcher disclosed that there
was a vulnerability in the popular grammar checker, grammarly.com. The vulnerability allowed third-party
websites to access the authentication token of Grammarly accounts which in turn
allowed access to all the user’s documents, history, and website information.
An authentication token allows repeated entry to the same website without
entering credentials every time. This makes it convenient for users to leave
the site and come back at another time. However, in this exploit, Mr. Ormandy
shows that it was possible to use a script to create tokens that allow access
to Grammarly accounts.
The
security breach is devastating because there are 20 million users of the
Grammarly application on Chrome and 645,000 users on Firefox. (Kovacs, 2018).
However, after Grammarly was notified of the vulnerability, they patched it
within a few hours. They also go on to say that there was no evidence that user
information was compromised. The vulnerability affected only the text saved on
the website, but not the keyboard editor, Microsoft add-in, or text typed in
other sites.
If
you use Grammarly, you don’t have to take any actions. All components of the
software will be automatically updated. However, this is a warning to all users
of the software. Be cautious of what is being exposed to the grammar checker.
If the document or website is confidential, it is probably best to not use the
application. The tool is excellent for checking school documents and is a great
supplemental aid for writing. However, sensitive information should not be
exposed to Grammarly.
References
Armasu, L. (2018, February 6). Grammarly Bug Could Have Exposed User Data To Any Visited Website. Retrieved from http://www.tomshardware.com/news/grammarly-bug-exposes-user-data,36464.html
Kanaracus, C. (2018, February 5). Grammarly Patches Chrome Extension Bug that exposed users' Docs. Retrieved from https://threatpost.com/grammarly-patches-chrome-extension-bug-that-exposed-users-docs/129794/
Kovacs, E. (2018, February 6). Grammarly Rushes to Patch Flaw Exposing User Data. Retrieved from http://www.securityweek.com/grammarly-rushes-patch-flaw-exposing-user-data
No comments:
Post a Comment