SlideShare a Scribd company logo
1 of 5
Download to read offline
NINE STEPS TO OPTIMIZE GOOGLE CHROME
FOR GOOGLE APPS SECURITY
BACKUPIFY – MARCH 2012
NINE STEPS TO OPTIMIZE GOOGLE CHROME FOR GOOGLE APPS SECURITY
Backupify, Inc. 2
INTRODUCTION
Google Chrome has been consistently rated as the safest consumer Web browser
available today, but, to paraphrase a famous military scholar, no security survives
contact with the user. Poor end-user habits and settings can compromise even the
most secure browser. Below are some basic steps to ensure that Chrome isn't the
weak link in your Google Apps security plan.
BROWSER SETTINGS
The first phase of improving Chrome's security profile is tweaking its native
settings to avoid storing sensitive data, and to ensure you never surf to the more
unsavory corners of the World Wide Web.
1. Make Sure Safe Browsing Is Enabled
Chrome has a number of automatic Safe Browsing defenses against phishing and
malware, most of which simply warn users against visiting pages with spoofed
URLs or woefully out of date security certificates. Safe Browsing is enabled by
default, but security begins by making sure it stays that way.
2. Block All Browser Cookies by Default
While this will make the browser mildly less convenient by forcing the user to log
in every time he or she reaches a site — including Google Apps — it will prevent
any session from persisting after a browser tab is closed. This blocks both
unwanted monitoring by third-party cookies and limits the possibility of tailgating
attacks.
3. Block Saved Passwords
Saved passwords are a risky convenience, as anyone with access to your browser
— which is only a stolen laptop away — can subsequently access all your online
accounts, Google Apps included. Moreover, hackers target the stored password file
as a treasure trove of identity theft or intrusion ammunition. Disabling the saved
NINE STEPS TO OPTIMIZE GOOGLE CHROME FOR GOOGLE APPS SECURITY
Backupify, Inc. 3
password function is perhaps the single most important step to take in protecting
not just your Google Apps domain, but every one of your online accounts.
4. Disable Autofill
Autofill data represents saved form data — addresses, phone numbers and email
addresses — designed to make online sign-ups easier. While far less dangerous
than saved passwords, autofill information is nonetheless a tempting target for
hackers and laptop thieves alike, as it contains vital clues to the login information
for your Google Apps domain (to say nothing of your online banking accounts).
Disabling autofill keeps this information out of the browser.
5. Lock SafeSearch to Strict
Chrome makes it trivially easy to employ Google Search, so those searches need
to be as safe and secure as possible. Locking Chrome's native search functionality
into SafeSearch mode ensures that no less-than-trustworthy sites are returned
from any query, keeping the application that accesses your Google Apps domain
that much further from any dangerous malware.
SECURITY EXTENSIONS
Chrome's native security measures are laudable, but you can double down on your
defenses with carefully selected browser extensions.
6. Secbrowsing Plugin Version Checker
The first step to safely using Chrome Extensions is to make sure those extensions
are up to date, which is to say that all known security flaws have been patched.
The Secbrowsing plugin ensures that any extension you're running is the latest,
and thus likely the safest, version.
7. KB SSL Enforcer
Secure Sockets Layer (HTTPS) browsing is fundamentally safer than standard web
surfing, and most websites offer an SSL access option — provided you can find it.
The KB SSL Enforcer defaults to the HTTPS address for every website that offers it,
NINE STEPS TO OPTIMIZE GOOGLE CHROME FOR GOOGLE APPS SECURITY
Backupify, Inc. 4
including every core and non-core Google Apps service. Never transmit a
password without SSL protection again.
8. View Thru URL Shortening Decoder
Popular URL shortening services like bit.ly and j.mp are often used to enable
phishing attacks and malware installations by disguising unsafe web addresses. The
View Thru extension allows you to verify the real, unshortened URL before you visit
it, sidestepping these camouflage attempts.
9. PasswordFail Cleartext Password Alarm
While virtually every web application requires you to create an account to use the
service, a shocking number of these apps send and receive password information
in dangerously insecure cleartext formats. While no Google Apps service makes
this mistake, another web app's carelessness could compromise your browser and
thus your Google Apps domain. The PasswordFail extension warns you off any web
application that employs cleartext passwords, ensuring you never put your browser
security in the hands of sloppy code.
Implement these nine steps and Google Chrome's already stalwart security profile
will be significantly stronger — and so will your Google Apps domain.
ABOUT BACKUPIFY
Backupify is the leading provider of backup and restore solutions for SaaS
applications including Google Apps, Salesforce, Facebook, Twitter, and more.
Backupify was founded in 2008 and is based in Cambridge, MA. Backupify has over
200,000 users trusting us with more than 500 million documents, two billion email
messages and 350 terabytes of data.
WHY BACKUP CLOUD DATA?
Your data is one of the most critical assets of your business. Like any important
asset, it should be insured. While most SaaS providers, including Google and
Salesforce, offer state-of-the-art disaster recovery capabilities that protect you
from some forms of data loss, you are still at risk for data loss due to user error,
NINE STEPS TO OPTIMIZE GOOGLE CHROME FOR GOOGLE APPS SECURITY
Backupify, Inc. 5
hacked accounts and third-party application bugs. To fully replicate your on-
premise backup capabilities in the cloud, you need the ability to perform granular
restores, and to retain the control that comes from having your own secure
second copy of the data in your SaaS applications.
FIND OUT MORE
If you're interested in the peace of mind you get from an automated Google Apps
backup solution, feel free to contact us directly at info@backupify.com.
 Web http://www.backupify.com
 Phone 1.800.571.4984
 Twitter http://twitter.com/backupify
Backupify logo is a registered trademark or registered trademarks of Backupify, Inc. All other names
may be the trademarks or registered trademarks of their respective owners.
© 2012 Backupify, Inc. Item: GAT-WP-EN-200110608

More Related Content

Viewers also liked

Using smart phones as part
Using smart phones as partUsing smart phones as part
Using smart phones as partcindy spaedy
 
Lean & Scrum at VietnamWorks
Lean & Scrum at VietnamWorksLean & Scrum at VietnamWorks
Lean & Scrum at VietnamWorksChris Shayan
 
Csp@scuola uav corso1_lez4
Csp@scuola uav corso1_lez4Csp@scuola uav corso1_lez4
Csp@scuola uav corso1_lez4CSP Scarl
 
Protecting Data in the Cloud: The Truth about SaaS Backup
Protecting Data in the Cloud: The Truth about SaaS BackupProtecting Data in the Cloud: The Truth about SaaS Backup
Protecting Data in the Cloud: The Truth about SaaS BackupDatto
 
Assignment5 Paper prototype
Assignment5 Paper prototypeAssignment5 Paper prototype
Assignment5 Paper prototypeInezAng
 
Todos los trabajos
Todos los trabajos Todos los trabajos
Todos los trabajos Juliiita
 
Living Labs ovvero il possibile contributo delle ICT ai Presidi Territoriali ...
Living Labs ovvero il possibile contributo delle ICT ai Presidi Territoriali ...Living Labs ovvero il possibile contributo delle ICT ai Presidi Territoriali ...
Living Labs ovvero il possibile contributo delle ICT ai Presidi Territoriali ...CSP Scarl
 
Agility at Vietnamworks
Agility at VietnamworksAgility at Vietnamworks
Agility at VietnamworksChris Shayan
 
Cauchuyendang xem
 Cauchuyendang xem Cauchuyendang xem
Cauchuyendang xemDamPhan
 
How to design for the web
How to design for the webHow to design for the web
How to design for the webCyber-Duck
 

Viewers also liked (19)

Using smart phones as part
Using smart phones as partUsing smart phones as part
Using smart phones as part
 
Arte óptico
Arte ópticoArte óptico
Arte óptico
 
Thewiseoldman
ThewiseoldmanThewiseoldman
Thewiseoldman
 
Lean & Scrum at VietnamWorks
Lean & Scrum at VietnamWorksLean & Scrum at VietnamWorks
Lean & Scrum at VietnamWorks
 
Rös
RösRös
Rös
 
Color theory
Color theoryColor theory
Color theory
 
Csp@scuola uav corso1_lez4
Csp@scuola uav corso1_lez4Csp@scuola uav corso1_lez4
Csp@scuola uav corso1_lez4
 
Multiprojects management
Multiprojects managementMultiprojects management
Multiprojects management
 
Protecting Data in the Cloud: The Truth about SaaS Backup
Protecting Data in the Cloud: The Truth about SaaS BackupProtecting Data in the Cloud: The Truth about SaaS Backup
Protecting Data in the Cloud: The Truth about SaaS Backup
 
Brain storming-rules
Brain storming-rulesBrain storming-rules
Brain storming-rules
 
Assignment5 Paper prototype
Assignment5 Paper prototypeAssignment5 Paper prototype
Assignment5 Paper prototype
 
Todos los trabajos
Todos los trabajos Todos los trabajos
Todos los trabajos
 
Living Labs ovvero il possibile contributo delle ICT ai Presidi Territoriali ...
Living Labs ovvero il possibile contributo delle ICT ai Presidi Territoriali ...Living Labs ovvero il possibile contributo delle ICT ai Presidi Territoriali ...
Living Labs ovvero il possibile contributo delle ICT ai Presidi Territoriali ...
 
Kotler01 mkt.crm
Kotler01 mkt.crmKotler01 mkt.crm
Kotler01 mkt.crm
 
NYATEP13CNRW_Presentation
NYATEP13CNRW_PresentationNYATEP13CNRW_Presentation
NYATEP13CNRW_Presentation
 
Sandro del petre
Sandro del petreSandro del petre
Sandro del petre
 
Agility at Vietnamworks
Agility at VietnamworksAgility at Vietnamworks
Agility at Vietnamworks
 
Cauchuyendang xem
 Cauchuyendang xem Cauchuyendang xem
Cauchuyendang xem
 
How to design for the web
How to design for the webHow to design for the web
How to design for the web
 

More from Datto

What is Network Continuity? Why Does it Matter for Small Businesses?
What is Network Continuity? Why Does it Matter for Small Businesses?What is Network Continuity? Why Does it Matter for Small Businesses?
What is Network Continuity? Why Does it Matter for Small Businesses?Datto
 
13 Ransomware Statistics That Will Make You Rethink Data Protection
13 Ransomware Statistics That Will Make You Rethink Data Protection13 Ransomware Statistics That Will Make You Rethink Data Protection
13 Ransomware Statistics That Will Make You Rethink Data ProtectionDatto
 
What is Ransomware?
What is Ransomware?What is Ransomware?
What is Ransomware?Datto
 
14 Ways to Increase Google Apps Adoption at Your School
14 Ways to Increase Google Apps Adoption at Your School14 Ways to Increase Google Apps Adoption at Your School
14 Ways to Increase Google Apps Adoption at Your SchoolDatto
 
What's In a Cloud? Purpose-Built vs. Public
What's In a Cloud?  Purpose-Built vs. PublicWhat's In a Cloud?  Purpose-Built vs. Public
What's In a Cloud? Purpose-Built vs. PublicDatto
 
Follow the Yellow Brick Road to Google Apps Setup & Security Success
Follow the Yellow Brick Road to Google Apps Setup & Security SuccessFollow the Yellow Brick Road to Google Apps Setup & Security Success
Follow the Yellow Brick Road to Google Apps Setup & Security SuccessDatto
 
The Wizards Behind Google Apps: 11 Google Apps Setup Tips for Admins by Admins
The Wizards Behind Google Apps: 11 Google Apps Setup Tips for Admins by Admins The Wizards Behind Google Apps: 11 Google Apps Setup Tips for Admins by Admins
The Wizards Behind Google Apps: 11 Google Apps Setup Tips for Admins by Admins Datto
 
15 Effective Tips for Schools Using Google Apps for Education
15 Effective Tips for Schools Using Google Apps for Education15 Effective Tips for Schools Using Google Apps for Education
15 Effective Tips for Schools Using Google Apps for EducationDatto
 
Midmarket CIO Forum Spring 2014
Midmarket CIO Forum Spring 2014Midmarket CIO Forum Spring 2014
Midmarket CIO Forum Spring 2014Datto
 
Midmarket CIO Forum 2013 Presentation
Midmarket CIO Forum 2013 PresentationMidmarket CIO Forum 2013 Presentation
Midmarket CIO Forum 2013 PresentationDatto
 
Salesforce Data Loss in the Wild Wild West
Salesforce Data Loss in the Wild Wild WestSalesforce Data Loss in the Wild Wild West
Salesforce Data Loss in the Wild Wild WestDatto
 
Growing Up Google - Google Apps for EDU Adoption [Infographic]
Growing Up Google - Google Apps for EDU Adoption [Infographic]Growing Up Google - Google Apps for EDU Adoption [Infographic]
Growing Up Google - Google Apps for EDU Adoption [Infographic]Datto
 
CIO Cloud Summit nyc_backupify
CIO Cloud Summit nyc_backupifyCIO Cloud Summit nyc_backupify
CIO Cloud Summit nyc_backupifyDatto
 
Google Apps Demographics Study [Infographic]
Google Apps Demographics Study [Infographic]Google Apps Demographics Study [Infographic]
Google Apps Demographics Study [Infographic]Datto
 
Google Apps Data Loss [Infographic]
Google Apps Data Loss [Infographic]Google Apps Data Loss [Infographic]
Google Apps Data Loss [Infographic]Datto
 
Data Liberation Awards [Infographic]
Data Liberation Awards [Infographic]Data Liberation Awards [Infographic]
Data Liberation Awards [Infographic]Datto
 
The Value of Gmail Accounts [Infographic]
The Value of Gmail Accounts [Infographic]The Value of Gmail Accounts [Infographic]
The Value of Gmail Accounts [Infographic]Datto
 
13 Steps to Safely Deprovision and Delete a Google Apps User
13 Steps to Safely Deprovision and Delete a Google Apps User13 Steps to Safely Deprovision and Delete a Google Apps User
13 Steps to Safely Deprovision and Delete a Google Apps UserDatto
 
10 Steps to Optimize Mozilla Firefox for Google Apps Security
10 Steps to Optimize Mozilla Firefox for Google Apps Security10 Steps to Optimize Mozilla Firefox for Google Apps Security
10 Steps to Optimize Mozilla Firefox for Google Apps SecurityDatto
 
5 Steps to Secure Google Drive
5 Steps to Secure Google Drive5 Steps to Secure Google Drive
5 Steps to Secure Google DriveDatto
 

More from Datto (20)

What is Network Continuity? Why Does it Matter for Small Businesses?
What is Network Continuity? Why Does it Matter for Small Businesses?What is Network Continuity? Why Does it Matter for Small Businesses?
What is Network Continuity? Why Does it Matter for Small Businesses?
 
13 Ransomware Statistics That Will Make You Rethink Data Protection
13 Ransomware Statistics That Will Make You Rethink Data Protection13 Ransomware Statistics That Will Make You Rethink Data Protection
13 Ransomware Statistics That Will Make You Rethink Data Protection
 
What is Ransomware?
What is Ransomware?What is Ransomware?
What is Ransomware?
 
14 Ways to Increase Google Apps Adoption at Your School
14 Ways to Increase Google Apps Adoption at Your School14 Ways to Increase Google Apps Adoption at Your School
14 Ways to Increase Google Apps Adoption at Your School
 
What's In a Cloud? Purpose-Built vs. Public
What's In a Cloud?  Purpose-Built vs. PublicWhat's In a Cloud?  Purpose-Built vs. Public
What's In a Cloud? Purpose-Built vs. Public
 
Follow the Yellow Brick Road to Google Apps Setup & Security Success
Follow the Yellow Brick Road to Google Apps Setup & Security SuccessFollow the Yellow Brick Road to Google Apps Setup & Security Success
Follow the Yellow Brick Road to Google Apps Setup & Security Success
 
The Wizards Behind Google Apps: 11 Google Apps Setup Tips for Admins by Admins
The Wizards Behind Google Apps: 11 Google Apps Setup Tips for Admins by Admins The Wizards Behind Google Apps: 11 Google Apps Setup Tips for Admins by Admins
The Wizards Behind Google Apps: 11 Google Apps Setup Tips for Admins by Admins
 
15 Effective Tips for Schools Using Google Apps for Education
15 Effective Tips for Schools Using Google Apps for Education15 Effective Tips for Schools Using Google Apps for Education
15 Effective Tips for Schools Using Google Apps for Education
 
Midmarket CIO Forum Spring 2014
Midmarket CIO Forum Spring 2014Midmarket CIO Forum Spring 2014
Midmarket CIO Forum Spring 2014
 
Midmarket CIO Forum 2013 Presentation
Midmarket CIO Forum 2013 PresentationMidmarket CIO Forum 2013 Presentation
Midmarket CIO Forum 2013 Presentation
 
Salesforce Data Loss in the Wild Wild West
Salesforce Data Loss in the Wild Wild WestSalesforce Data Loss in the Wild Wild West
Salesforce Data Loss in the Wild Wild West
 
Growing Up Google - Google Apps for EDU Adoption [Infographic]
Growing Up Google - Google Apps for EDU Adoption [Infographic]Growing Up Google - Google Apps for EDU Adoption [Infographic]
Growing Up Google - Google Apps for EDU Adoption [Infographic]
 
CIO Cloud Summit nyc_backupify
CIO Cloud Summit nyc_backupifyCIO Cloud Summit nyc_backupify
CIO Cloud Summit nyc_backupify
 
Google Apps Demographics Study [Infographic]
Google Apps Demographics Study [Infographic]Google Apps Demographics Study [Infographic]
Google Apps Demographics Study [Infographic]
 
Google Apps Data Loss [Infographic]
Google Apps Data Loss [Infographic]Google Apps Data Loss [Infographic]
Google Apps Data Loss [Infographic]
 
Data Liberation Awards [Infographic]
Data Liberation Awards [Infographic]Data Liberation Awards [Infographic]
Data Liberation Awards [Infographic]
 
The Value of Gmail Accounts [Infographic]
The Value of Gmail Accounts [Infographic]The Value of Gmail Accounts [Infographic]
The Value of Gmail Accounts [Infographic]
 
13 Steps to Safely Deprovision and Delete a Google Apps User
13 Steps to Safely Deprovision and Delete a Google Apps User13 Steps to Safely Deprovision and Delete a Google Apps User
13 Steps to Safely Deprovision and Delete a Google Apps User
 
10 Steps to Optimize Mozilla Firefox for Google Apps Security
10 Steps to Optimize Mozilla Firefox for Google Apps Security10 Steps to Optimize Mozilla Firefox for Google Apps Security
10 Steps to Optimize Mozilla Firefox for Google Apps Security
 
5 Steps to Secure Google Drive
5 Steps to Secure Google Drive5 Steps to Secure Google Drive
5 Steps to Secure Google Drive
 

Recently uploaded

Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupFlorian Wilhelm
 
Install Stable Diffusion in windows machine
Install Stable Diffusion in windows machineInstall Stable Diffusion in windows machine
Install Stable Diffusion in windows machinePadma Pradeep
 
Search Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdfSearch Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdfRankYa
 
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Mark Simos
 
WordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your BrandWordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your Brandgvaughan
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)Wonjun Hwang
 
Powerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time ClashPowerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time Clashcharlottematthew16
 
My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024The Digital Insurer
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfAddepto
 
DevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenDevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenHervé Boutemy
 
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticsKotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticscarlostorres15106
 
Artificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxArtificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxhariprasad279825
 
What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024Stephanie Beckett
 
Unleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubUnleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubKalema Edgar
 
My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationMy Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationRidwan Fadjar
 
Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Scott Keck-Warren
 
"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii SoldatenkoFwdays
 
DevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsDevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsSergiu Bodiu
 

Recently uploaded (20)

Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project Setup
 
Install Stable Diffusion in windows machine
Install Stable Diffusion in windows machineInstall Stable Diffusion in windows machine
Install Stable Diffusion in windows machine
 
Search Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdfSearch Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdf
 
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
 
WordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your BrandWordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your Brand
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
 
Powerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time ClashPowerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time Clash
 
My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdf
 
DevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenDevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache Maven
 
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticsKotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
 
Artificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxArtificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptx
 
What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024
 
Unleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubUnleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding Club
 
My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationMy Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 Presentation
 
Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024
 
"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko
 
DevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsDevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platforms
 

9 Steps to Optimize Google Chrome for Google Apps Security

  • 1. NINE STEPS TO OPTIMIZE GOOGLE CHROME FOR GOOGLE APPS SECURITY BACKUPIFY – MARCH 2012
  • 2. NINE STEPS TO OPTIMIZE GOOGLE CHROME FOR GOOGLE APPS SECURITY Backupify, Inc. 2 INTRODUCTION Google Chrome has been consistently rated as the safest consumer Web browser available today, but, to paraphrase a famous military scholar, no security survives contact with the user. Poor end-user habits and settings can compromise even the most secure browser. Below are some basic steps to ensure that Chrome isn't the weak link in your Google Apps security plan. BROWSER SETTINGS The first phase of improving Chrome's security profile is tweaking its native settings to avoid storing sensitive data, and to ensure you never surf to the more unsavory corners of the World Wide Web. 1. Make Sure Safe Browsing Is Enabled Chrome has a number of automatic Safe Browsing defenses against phishing and malware, most of which simply warn users against visiting pages with spoofed URLs or woefully out of date security certificates. Safe Browsing is enabled by default, but security begins by making sure it stays that way. 2. Block All Browser Cookies by Default While this will make the browser mildly less convenient by forcing the user to log in every time he or she reaches a site — including Google Apps — it will prevent any session from persisting after a browser tab is closed. This blocks both unwanted monitoring by third-party cookies and limits the possibility of tailgating attacks. 3. Block Saved Passwords Saved passwords are a risky convenience, as anyone with access to your browser — which is only a stolen laptop away — can subsequently access all your online accounts, Google Apps included. Moreover, hackers target the stored password file as a treasure trove of identity theft or intrusion ammunition. Disabling the saved
  • 3. NINE STEPS TO OPTIMIZE GOOGLE CHROME FOR GOOGLE APPS SECURITY Backupify, Inc. 3 password function is perhaps the single most important step to take in protecting not just your Google Apps domain, but every one of your online accounts. 4. Disable Autofill Autofill data represents saved form data — addresses, phone numbers and email addresses — designed to make online sign-ups easier. While far less dangerous than saved passwords, autofill information is nonetheless a tempting target for hackers and laptop thieves alike, as it contains vital clues to the login information for your Google Apps domain (to say nothing of your online banking accounts). Disabling autofill keeps this information out of the browser. 5. Lock SafeSearch to Strict Chrome makes it trivially easy to employ Google Search, so those searches need to be as safe and secure as possible. Locking Chrome's native search functionality into SafeSearch mode ensures that no less-than-trustworthy sites are returned from any query, keeping the application that accesses your Google Apps domain that much further from any dangerous malware. SECURITY EXTENSIONS Chrome's native security measures are laudable, but you can double down on your defenses with carefully selected browser extensions. 6. Secbrowsing Plugin Version Checker The first step to safely using Chrome Extensions is to make sure those extensions are up to date, which is to say that all known security flaws have been patched. The Secbrowsing plugin ensures that any extension you're running is the latest, and thus likely the safest, version. 7. KB SSL Enforcer Secure Sockets Layer (HTTPS) browsing is fundamentally safer than standard web surfing, and most websites offer an SSL access option — provided you can find it. The KB SSL Enforcer defaults to the HTTPS address for every website that offers it,
  • 4. NINE STEPS TO OPTIMIZE GOOGLE CHROME FOR GOOGLE APPS SECURITY Backupify, Inc. 4 including every core and non-core Google Apps service. Never transmit a password without SSL protection again. 8. View Thru URL Shortening Decoder Popular URL shortening services like bit.ly and j.mp are often used to enable phishing attacks and malware installations by disguising unsafe web addresses. The View Thru extension allows you to verify the real, unshortened URL before you visit it, sidestepping these camouflage attempts. 9. PasswordFail Cleartext Password Alarm While virtually every web application requires you to create an account to use the service, a shocking number of these apps send and receive password information in dangerously insecure cleartext formats. While no Google Apps service makes this mistake, another web app's carelessness could compromise your browser and thus your Google Apps domain. The PasswordFail extension warns you off any web application that employs cleartext passwords, ensuring you never put your browser security in the hands of sloppy code. Implement these nine steps and Google Chrome's already stalwart security profile will be significantly stronger — and so will your Google Apps domain. ABOUT BACKUPIFY Backupify is the leading provider of backup and restore solutions for SaaS applications including Google Apps, Salesforce, Facebook, Twitter, and more. Backupify was founded in 2008 and is based in Cambridge, MA. Backupify has over 200,000 users trusting us with more than 500 million documents, two billion email messages and 350 terabytes of data. WHY BACKUP CLOUD DATA? Your data is one of the most critical assets of your business. Like any important asset, it should be insured. While most SaaS providers, including Google and Salesforce, offer state-of-the-art disaster recovery capabilities that protect you from some forms of data loss, you are still at risk for data loss due to user error,
  • 5. NINE STEPS TO OPTIMIZE GOOGLE CHROME FOR GOOGLE APPS SECURITY Backupify, Inc. 5 hacked accounts and third-party application bugs. To fully replicate your on- premise backup capabilities in the cloud, you need the ability to perform granular restores, and to retain the control that comes from having your own secure second copy of the data in your SaaS applications. FIND OUT MORE If you're interested in the peace of mind you get from an automated Google Apps backup solution, feel free to contact us directly at info@backupify.com.  Web http://www.backupify.com  Phone 1.800.571.4984  Twitter http://twitter.com/backupify Backupify logo is a registered trademark or registered trademarks of Backupify, Inc. All other names may be the trademarks or registered trademarks of their respective owners. © 2012 Backupify, Inc. Item: GAT-WP-EN-200110608