Google Adds New Verification Feature to Prevent Phishing Attacks

Advertisement
By Sumit Chakraborty | Updated: 27 April 2018 18:50 IST
Highlights
  • New feature for Google account users who rely on Chrome
  • It prevents users from signing in to an account controlled by an attacker
  • The feature will appear only once per account per device

This week, Google announced a new security feature for Google account users who work on Chrome for browsing the Internet. The new sign-in feature asks users to verify that the account they are using is their own account. The search giant says that this is designed to prevent anyone from quietly signing into a Google account that may be owned by a malicious third party.

The move by Google is essentially meant to secure third-party logins, such as those performed by SAML single sign-on (SSO). From May 7, after signing in on a SAML provider's website, the users will see a new screen on the Google's site, to confirm their identity. Google says in a G Suite Updates blog, this screen will provide an additional layer of security and help prevent users from unknowingly signing in to an account created and controlled by an attacker.

Google stated that it will only show the feature once per account per device to minimise disruption for the user. It said, "We're working on ways to make the feature even more context-aware in the future, meaning your users should see the screen less and less over time."

Advertisement

For phishing attacks, the new screen will prevent would-be attackers from tricking a user into clicking a link that would sign them into a Google Account that the attacker controls. Google says, "Today, this can be done via SAML single sign-on (SSO), because it doesn't require a user interaction to complete a sign-in. To protect Chrome users, we've added this extra protection."

Advertisement

Google says that the new security feature is part of its plans to create a consistent identity for users across Google web services such as Gmail and native Chrome browser services such as Chrome Sync. It will make it easier for signed-in G Suite users to take advantage of native Chrome browser features, but with additional protection during authentication.

Notably, you can also disable the new screen. For that, you will have to use the 'X-GoogApps-AllowedDomains HTTP header' to identify specific domains whose users can access Google services. Then, the header can be set in Chrome via the 'AllowedDomainsForApps group policy'.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Son of Sardaar 2 OTT Release: Know When and Where to Watch it Online
  1. Astronomers Predict 90 Percent Chance of Spotting an Exploding Black Hole in Next Decade
  2. DNA Cassette Tapes Could Transform the Future of Digital Storage
  3. Researchers Create Metal That Resists Cracking in Deep Space Cold
  4. The Madras Mystery OTT Release: This Nazriya Nazim Thriller Will Soon Arrive on This Platform
  5. The Treasure Hunters OTT Release: Know When and Where to Watch Manisha Rani's Game Show Online
  6. Sarkeet OTT Release: This Is Where You Can Watch the Asif Ali-Starrer Later This Month
  7. Researchers Reconstruct 2,500-Year-Old Faces From Skulls Found in Tamil Nadu
  8. House Mates OTT Release: When and Where to Watch the Tamil Horror Comedy Online
  9. Black Hole Kicked Away? Gravitational Waves Reveal Einstein’s Ripples in Spacetime
  10. NASA’s Artemis II Astronauts Will Double as Test Subjects for Deep Space Health Research
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.