Since this information is readily available on a user’s web browser, cybercriminals can use a malicious extension to collect the data for their gain. At the same time, the data collected is sold without user consent or knowledge and used by third-party data brokers to send users tailor-made ads.
Although not all browser extensions are a security risk, some might be built to impersonate legitimate extensions, especially those from third-party resources. In other cases, legitimate extensions have been compromised or bought by a developer who uses them for malicious purposes.
Some browser add-ons are built to download malware onto your device, redirect search traffic to malicious websites or download ad ware and Trojan horse viruses.
The extensions can automatically update without requiring any action from a user. This means that if a legitimate extension is compromised, it can be used to install malware without user knowledge. Even secure extensions are prone to attacks or can be compromised, enabling attackers to gain access to data stored by browsers.
Additionally, malicious extensions can be built to bypass fraud detection by official Web stores. For instance, in 2020, Google removed over 500 extensions from its web store that violated policies, with some already having infected users and stolen their data. This followed the discovery of some malicious extensions that users had already downloaded.
A recent report released by Kaspersky, a cybersecurity firm, shows just how dangerous malicious add-ons are. After the firm analyzed data from January 2020 to June 2022, it discovered that over this time frame, 4.3 million users were attacked by adware hiding in browser extensions. This put adware as the highest representative of browser extension risks, with malware coming second. The report also indicates that Kaspersky products prevented more than 6 million users from downloading adware, malware or riskware disguised as browser extensions.
Such figures from just one cybersecurity firm are worrying, considering the study focused only on users that use their security solutions. This creates a need for users to be more vigilant when using browser extensions.
How to Make Sure Browser Extensions Are Safe
There are various ways to help reduce the risks posed by browser extensions:
Ensure the extension is from an official web store. Since these extensions can also be compromised, it is best to find out more information about the developer.
Check reviews as they help to know what other users think of the extension and if there have been any complaints. However, users should be cautious of identical comments or too many 5-star reviews, as these could be fake.
Check whether the extension is updated regularly. An extension last updated many years ago might not be reliable.
Review extension permissions for each extension.
Check that you are not installing clones of the original extension. For instance, if you search for an extension, you can find other similar ones that look legit.
Uninstall browser extensions that you don’t recognize or those you no longer need.
Use browsers that have the features you want.
Install reliable antivirus software that will help spot malicious activities or applications.
Conclusion
Browser extensions play an important role in the user browsing experience. Although not all extensions are dangerous, users must conduct due diligence to ensure they install legitimate extensions.
Powell CPA PLLC
Risk of Browser Extensions and How to Stay Safe
September 1, 2022 · Blog, What's New in Technology
⏱ 4 min read
Web browsers such as Google Chrome, Firefox, Safari and Edge, among others, play an essential role in enabling access to websites on the internet. Most browsers allow users to install extensions, also referred to as add-ons or plug-ins. These extensions are applications or small software modules that add functionality and other useful features to a browser.
By means of the extensions, users can carry out various tasks such as password management, cookie management, ad blocking, interface modification, productivity tracking, grammar and spell-checking, etc.
However, although the extensions offer different useful functionalities, cybercriminals have taken advantage of them, creating a security risk to users and their data.
The Need to Beware of Browser Extensions
Browsers enable websites to collect information such as viewing history, adding cookies, etc. Also, when installing the extensions, some require to be allowed various permissions, like the ability to read or change data. For instance, according to a recent study by Talon, a digital security company, most Chrome Web Store extensions (62.43 percent of extensions) require dangerous permissions, including permission to read or change user data and activity. This means that an extension can see the sites visited, keystrokes, login credentials and private data, such as payment card details.
Since this information is readily available on a user’s web browser, cybercriminals can use a malicious extension to collect the data for their gain. At the same time, the data collected is sold without user consent or knowledge and used by third-party data brokers to send users tailor-made ads.
Although not all browser extensions are a security risk, some might be built to impersonate legitimate extensions, especially those from third-party resources. In other cases, legitimate extensions have been compromised or bought by a developer who uses them for malicious purposes.
Some browser add-ons are built to download malware onto your device, redirect search traffic to malicious websites or download ad ware and Trojan horse viruses.
The extensions can automatically update without requiring any action from a user. This means that if a legitimate extension is compromised, it can be used to install malware without user knowledge. Even secure extensions are prone to attacks or can be compromised, enabling attackers to gain access to data stored by browsers.
Additionally, malicious extensions can be built to bypass fraud detection by official Web stores. For instance, in 2020, Google removed over 500 extensions from its web store that violated policies, with some already having infected users and stolen their data. This followed the discovery of some malicious extensions that users had already downloaded.
A recent report released by Kaspersky, a cybersecurity firm, shows just how dangerous malicious add-ons are. After the firm analyzed data from January 2020 to June 2022, it discovered that over this time frame, 4.3 million users were attacked by adware hiding in browser extensions. This put adware as the highest representative of browser extension risks, with malware coming second. The report also indicates that Kaspersky products prevented more than 6 million users from downloading adware, malware or riskware disguised as browser extensions.
Such figures from just one cybersecurity firm are worrying, considering the study focused only on users that use their security solutions. This creates a need for users to be more vigilant when using browser extensions.
How to Make Sure Browser Extensions Are Safe
There are various ways to help reduce the risks posed by browser extensions:
Ensure the extension is from an official web store. Since these extensions can also be compromised, it is best to find out more information about the developer.
Check reviews as they help to know what other users think of the extension and if there have been any complaints. However, users should be cautious of identical comments or too many 5-star reviews, as these could be fake.
Check whether the extension is updated regularly. An extension last updated many years ago might not be reliable.
Review extension permissions for each extension.
Check that you are not installing clones of the original extension. For instance, if you search for an extension, you can find other similar ones that look legit.
Uninstall browser extensions that you don’t recognize or those you no longer need.
Use browsers that have the features you want.
Install reliable antivirus software that will help spot malicious activities or applications.
Conclusion
Browser extensions play an important role in the user browsing experience. Although not all extensions are dangerous, users must conduct due diligence to ensure they install legitimate extensions.
Disclaimer
These articles are intended to provide general resources for the tax and accounting needs of small businesses and individuals. Service2Client LLC is the author, but is not engaged in rendering specific legal, accounting, financial or professional advice. Service2Client LLC makes no representation that the recommendations of Service2Client LLC will achieve any result. The NSAD has not reviewed any of the Service2Client LLC content. Readers are encouraged to contact a professional regarding the topics in these articles. The images linked to these articles are protected by copyright and should not be copied for any reason.
These articles are intended to provide general resources for the tax and accounting needs of small businesses and individuals. Service2Client LLC is the author, but is not engaged in rendering specific legal, accounting, financial or professional advice. Service2Client LLC makes no representation that the recommendations of Service2Client LLC will achieve any result. The NSAD has not reviewed any of the Service2Client LLC content. Readers are encouraged to contact a professional regarding the topics in these articles. The images linked to these articles are protected by copyright and should not be copied for any reason.
These articles are intended to provide general resources for the tax and accounting needs of small businesses and individuals. Service2Client LLC is the author, but is not engaged in rendering specific legal, accounting, financial or professional advice. Service2Client LLC makes no representation that the recommendations of Service2Client LLC will achieve any result. The NSAD has not reviewed any of the Service2Client LLC content. Readers are encouraged to contact a professional regarding the topics in these articles. The images linked to these articles are protected by copyright and should not be copied for any reason.
These articles are intended to provide general resources for the tax and accounting needs of small businesses and individuals. Service2Client LLC is the author, but is not engaged in rendering specific legal, accounting, financial or professional advice. Service2Client LLC makes no representation that the recommendations of Service2Client LLC will achieve any result. The NSAD has not reviewed any of the Service2Client LLC content. Readers are encouraged to contact a professional regarding the topics in these articles. The images linked to these articles are protected by copyright and should not be copied for any reason.
These articles are intended to provide general resources for the tax and accounting needs of small businesses and individuals. Service2Client LLC is the author, but is not engaged in rendering specific legal, accounting, financial or professional advice. Service2Client LLC makes no representation that the recommendations of Service2Client LLC will achieve any result. The NSAD has not reviewed any of the Service2Client LLC content. Readers are encouraged to contact a professional regarding the topics in these articles. The images linked to these articles are protected by copyright and should not be copied for any reason.
These articles are intended to provide general resources for the tax and accounting needs of small businesses and individuals. Service2Client LLC is the author, but is not engaged in rendering specific legal, accounting, financial or professional advice. Service2Client LLC makes no representation that the recommendations of Service2Client LLC will achieve any result. The NSAD has not reviewed any of the Service2Client LLC content. Readers are encouraged to contact a professional regarding the topics in these articles. The images linked to these articles are protected by copyright and should not be copied for any reason.
These articles are intended to provide general resources for the tax and accounting needs of small businesses and individuals. Service2Client LLC is the author, but is not engaged in rendering specific legal, accounting, financial or professional advice. Service2Client LLC makes no representation that the recommendations of Service2Client LLC will achieve any result. The NSAD has not reviewed any of the Service2Client LLC content. Readers are encouraged to contact a professional regarding the topics in these articles. The images linked to these articles are protected by copyright and should not be copied for any reason.
Another option for both stocks and mutual funds is to search by the stock symbol at Yahoofinance.com. On the stock’s performance chart, look for the Events tab and check the Stock Splits option. You may need to reduce the historical time frame to see splits marked clearly.
You also may be able to search for stock split history on the website of your online broker. Many outfits offer these types of research tools.
Powell CPA PLLC
Stock Splits, Explained
August 1, 2022 · Blog, Financial Planning
⏱ 5 min read
Imagine selling slices of a large pizza. You can cut it into four even slices and charge $2 a slice. Or, you can cut it into eight even slices and charge $1 per slice. Either way, the total value of the pizza will still be $8.
That’s what happens when a stock splits. Let’s say a stock’s market price is $100. With a 2-for-1 split, each current owner receives one additional share for each share he owns. Now, each share is worth $50. If you had one share to start, you now have two, but the total value of the investment remains $100.
A stock split differs from when a company decides to issue new shares, wherein new shares flooding the market can dilute the value of existing shares. With a stock split, the value of existing shares do not decrease. The total market value of a shareholder’s holdings will remain the same.
There are different forms of stock splits, such as the 2-for-1, 3-for-1, or 3-for-2 stock split. They all work the same way: You get two shares for everyone you hold, or three shares for everyone you hold, or three shares for every two shares you own.
Another, the less common form is called the reverse stock split. This is when a company decides to reduce the number of outstanding shares, which in turn will increase the stock price of shares held by stockholders. This strategy is generally used to boost the price of a stock that has lost value over time.
It is important to recognize that the stock split is a simple strategy designed to affect the stock price. It in no way changes the company’s market capitalization (i.e., total value of all outstanding shares) or other fundamental metrics. In order to issue a stock split, it must be approved by both company management and the board of directors. Furthermore, the company must publicly announce its intention to conduct a stock split within days or weeks of implementation.
The timing of the announcement is important because some investors try to take advantage of a stock split, believing that the value of the stock will increase as a result. This has more to do with market sentiment than any change in company fundamentals.
For example, in the past when a stock split its value often returned to its pre-split price within a year. This is not necessarily because the company has improved fundamentals, but rather because the investor market simply believes that stock is worth that price — it’s a form of confirmation bias. However, in recent years it is not as common for split stocks to climb back to their original price as it was in the past.
Why Conduct a Stock Split?
Again, the reason for a stock split is largely driven by market sentiment. For example, some investors may not have a lot of discretionary income to invest, so they look for a lower-priced stock. While they might not consider a stock valued at $100 per share, they may be interested in the company at $50 a share. In fact, following a recent stock split, investors may see it as getting a bargain price for that stock. As such, they might buy two shares. Now they’ve spent $100 on two shares whereas they were reluctant to buy one share for $100. The value is the same, but psychologically, that stock now seems like a great buy. This is referred to as unit bias. Psychologically, most people perceive lower per share prices to mean that a stock is “cheaper” and therefore may have more room to make gains.
In addition, now they can further diversify their portfolio with different stocks, whereas before those high-priced shares may have dominated their portfolios, exposing them to greater market risk.
A stock split also gives current shareholders the opportunity to increase their holdings at half price. While the value hasn’t changed when they make the buy if the stock increases in the future their portfolio will increase in value because they have more shares of that stock. For example, let’s say you have 10 shares of a stock priced at $10, for a total value of $100. The stock splits 2-for-1, so now you have 20 shares priced at $5, still valued at $100. In a few years, the stock price grows to $20 per share. Had the stock not split, your total value would grow to $200. But because you now own 20 shares, the total value of those shares would grow to $400.
Clearly, the true value of a stock split comes from holding those shares until the price increases substantially.
Mutual Fund Split
Some mutual funds also engage in the split strategy, but instead of splitting an individual stock, the fund company issues additional shares of the fund at a reduced price. In all other ways, a mutual fund share split works like an individual stock split.
If you’d like to learn the history of a company’s stock splits, consider the following resources:
Click on the investor relations tab on the company website, which often provides a history of the company, including dates of past stock split activity.
Another option for both stocks and mutual funds is to search by the stock symbol at Yahoofinance.com. On the stock’s performance chart, look for the Events tab and check the Stock Splits option. You may need to reduce the historical time frame to see splits marked clearly.
You also may be able to search for stock split history on the website of your online broker. Many outfits offer these types of research tools.
Disclaimer
These articles are intended to provide general resources for the tax and accounting needs of small businesses and individuals. Service2Client LLC is the author, but is not engaged in rendering specific legal, accounting, financial or professional advice. Service2Client LLC makes no representation that the recommendations of Service2Client LLC will achieve any result. The NSAD has not reviewed any of the Service2Client LLC content. Readers are encouraged to contact a professional regarding the topics in these articles. The images linked to these articles are protected by copyright and should not be copied for any reason.
These articles are intended to provide general resources for the tax and accounting needs of small businesses and individuals. Service2Client LLC is the author, but is not engaged in rendering specific legal, accounting, financial or professional advice. Service2Client LLC makes no representation that the recommendations of Service2Client LLC will achieve any result. The NSAD has not reviewed any of the Service2Client LLC content. Readers are encouraged to contact a professional regarding the topics in these articles. The images linked to these articles are protected by copyright and should not be copied for any reason.
These articles are intended to provide general resources for the tax and accounting needs of small businesses and individuals. Service2Client LLC is the author, but is not engaged in rendering specific legal, accounting, financial or professional advice. Service2Client LLC makes no representation that the recommendations of Service2Client LLC will achieve any result. The NSAD has not reviewed any of the Service2Client LLC content. Readers are encouraged to contact a professional regarding the topics in these articles. The images linked to these articles are protected by copyright and should not be copied for any reason.