Tuesday, February 6, 2018

Week 9 - Take Caution in the Use of Grammarly


Last Friday, Tavis Ormandy, a Google Project Zero researcher disclosed that there was a vulnerability in the popular grammar checker, grammarly.com.  The vulnerability allowed third-party websites to access the authentication token of Grammarly accounts which in turn allowed access to all the user’s documents, history, and website information. An authentication token allows repeated entry to the same website without entering credentials every time. This makes it convenient for users to leave the site and come back at another time. However, in this exploit, Mr. Ormandy shows that it was possible to use a script to create tokens that allow access to Grammarly accounts.

The security breach is devastating because there are 20 million users of the Grammarly application on Chrome and 645,000 users on Firefox. (Kovacs, 2018). However, after Grammarly was notified of the vulnerability, they patched it within a few hours. They also go on to say that there was no evidence that user information was compromised. The vulnerability affected only the text saved on the website, but not the keyboard editor, Microsoft add-in, or text typed in other sites.

If you use Grammarly, you don’t have to take any actions. All components of the software will be automatically updated. However, this is a warning to all users of the software. Be cautious of what is being exposed to the grammar checker. If the document or website is confidential, it is probably best to not use the application. The tool is excellent for checking school documents and is a great supplemental aid for writing. However, sensitive information should not be exposed to Grammarly.

References

Armasu, L. (2018, February 6). Grammarly Bug Could Have Exposed User Data To Any Visited Website. Retrieved from http://www.tomshardware.com/news/grammarly-bug-exposes-user-data,36464.html

Kanaracus, C. (2018, February 5). Grammarly Patches Chrome Extension Bug that exposed users' Docs. Retrieved from https://threatpost.com/grammarly-patches-chrome-extension-bug-that-exposed-users-docs/129794/

Kovacs, E. (2018, February 6). Grammarly Rushes to Patch Flaw Exposing User Data. Retrieved from http://www.securityweek.com/grammarly-rushes-patch-flaw-exposing-user-data

No comments:

Post a Comment