Skip to content

Commit

Permalink
Merge pull request #14 from adhintz/master
Browse files Browse the repository at this point in the history
project rename & commits from the last week or two
  • Loading branch information
adhintz committed Apr 26, 2015
2 parents 6ef9dc4 + 4d3908a commit ec5badb
Show file tree
Hide file tree
Showing 104 changed files with 1,611 additions and 714 deletions.
2 changes: 1 addition & 1 deletion AUTHORS
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
# This is the official list of Password Catcher authors for copyright purposes.
# This is the official list of Password Alert authors for copyright purposes.
# This file is distinct from the CONTRIBUTORS files.
# See the latter for an explanation.

Expand Down
1 change: 1 addition & 0 deletions CONTRIBUTORS
Original file line number Diff line number Diff line change
Expand Up @@ -13,3 +13,4 @@ Drew Hintz <adhintz@google.com>
Henry Chang <henryc@google.com>
Richo Healey <richo@stripe.com>
Nick Semenkovich <semenko@alum.mit.edu>
Tom Fitzgerald <tomfitzgerald@google.com>
8 changes: 4 additions & 4 deletions README.md
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
Password Catcher
Password Alert
====================

Password Catcher helps protect against phishing attacks. If you enter your Google for Work password into anywhere other than accounts.google.com, you’ll receive an alert, so you can change your password if needed. Password Catcher works like a spellchecker, comparing your keystrokes within the Chrome browser to your password to help you avoid mistakes. It doesn’t store your password or actual keystrokes, or send either to any remote system beyond your computer -- instead, it locally saves a fingerprint of your password, and compares that fingerprint to the fingerprint of what you’re typing.
Password Alert helps protect against phishing attacks. If you enter your Google for Work password into anywhere other than accounts.google.com, you’ll receive an alert, so you can change your password if needed. Password Alert works like a spellchecker, comparing your keystrokes within the Chrome browser to your password to help you avoid mistakes. It doesn’t store your password or actual keystrokes, or send either to any remote system beyond your computer -- instead, it locally saves a fingerprint of your password, and compares that fingerprint to the fingerprint of what you’re typing.

Separately, Password Catcher also tries to detect fake Google login pages to alert you before you’ve typed in your password. To do so, Password Catcher checks the HTML of each page you visit to ascertain whether it appears to be impersonating a Google login page.
Separately, Password Alert also tries to detect fake Google login pages to alert you before you’ve typed in your password. To do so, Password Alert checks the HTML of each page you visit to ascertain whether it appears to be impersonating a Google login page.

The Chrome extension is only intended for Google for Work accounts; other account passwords are not affected because the extension only compares your keystrokes to the stored fingerprint of your Google account password. The extension also does not operate in Incognito windows. When Google for Work administrators deploy Password Catcher across all Chrome clients in their domains, the administrators can receive alerts when Password Catcher triggers.
The Chrome extension is only intended for Google for Work accounts; other account passwords are not affected because the extension only compares your keystrokes to the stored fingerprint of your Google account password. The extension also does not operate in Incognito windows. When Google for Work administrators deploy Password Alert across all Chrome clients in their domains, the administrators can receive alerts when Password Alert triggers.
4 changes: 2 additions & 2 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
Password Catcher is covered by Google's bug bounty program as
Password Alert is covered by Google's bug bounty program as
described here: https://www.google.com/about/appsecurity/reward-program/

For Password Catcher specifically, vulnerabilities that would be
For Password Alert specifically, vulnerabilities that would be
in-scope for the bug bounty program would be things such as:
- unauthenticated access to user data on the server
- a way for a malicious web page to get the password hash from the
Expand Down
2 changes: 1 addition & 1 deletion chrome/README.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
# To install the extension
The extension is available [in the Chrome Web Store here](https://chrome.google.com/webstore/detail/password-catcher/noondiphcddnnabmjcihcjfbhfklnnep).
The extension is available [in the Chrome Web Store here](https://chrome.google.com/webstore/detail/password-alert/noondiphcddnnabmjcihcjfbhfklnnep).

Most users and organizations should
be able to use the version in the Chrome Web Store without needing to compile
Expand Down
2 changes: 1 addition & 1 deletion chrome/_locales/af/messages.json
Original file line number Diff line number Diff line change
@@ -1 +1 @@
{"always_ignore":{"message":"Ignoreer altyd vir hierdie webwerf"},"always_ignore_confirmation":{"message":"Wil jy h\u00ea Wagwoordvanger moet hierdie webwerf altyd ignoreer?"},"back":{"message":"Terug"},"contact_security":{"message":"Kontak sekuriteit"},"extension_description":{"message":"Wagwoordvanger help om jou teen uitvissingaanvalle te beskerm."},"extension_detailed_description":{"message":"As jy jou Gmail- of Google for Work-wagwoord by enige ander plek as accounts.google.com invoer, sal jy 'n opletberig ontvang sodat jy jou wagwoord kan verander indien nodig.\n\nWagwoordvanger probeer ook om bedrieglike Google-aanmeldbladsye te bespeur om jou te waarsku voordat jy jou wagwoord intik. Om dit te doen, gaan Wagwoordvanger die HTML van elke bladsy wat jy besoek, na om te sien of dit 'n Google-aanmeldbladsy naboots.\n\nGEREELDE VRAE\n-- Wanneer sal Wagwoordvanger in werking tree?\nWagwoordvanger sal homself inisieer die volgende keer wanneer jy jou wagwoord by accounts.google.com invoer.\n\n-- Berg Wagwoordvanger my wagwoord of sleuteldrukke?\nNee. Wagwoordvanger berg nie jou wagwoord of sleuteldrukke nie -\u2013 dit berg eerder 'n beveiligde skermkiekie van jou wagwoord, wat dit met 'n skermkiekie van jou mees onlangse sleuteldrukke in Chrome vergelyk.\n\n-- Waarheen stuur Wagwoordvanger data?\nAs jy Wagwoordvanger in 'n Gmail-rekening gebruik, sal Wagwoordvanger nie enige data van jou plaaslike rekenaar af stuur nie. As jou Google for Work-administrateur kies om Wagwoordvanger oor jou domein heen te ontplooi, sal die administrateur opletberigte ontvang wanneer Wagwoordvanger inskop.\n\n-- Wat is Wagwoordvanger se beperkings?\nWagwoordvanger beskerm nie incognito-vensters, Chrome-programme of Chrome-uitbreidings nie. Dit beskerm ook nie wagwoorde vir nie-Google-dienste nie. Wagwoordvanger werk slegs binne die Chrome-webblaaier wanneer Javascript geaktiveer is.\n\n-- Waar kan ek meer besonderhede vind?\nBesoek die volledige GEREELDE VRAE by LINK_TBD, of jy kan die hele oopbronkodebasis sien by https://github.com/google/password- catcher.\n\nDeur hierdie item te installeer, stem jy in tot Google se diensbepalings en privaatheidsbeleid by www.google.com/policies/\n"},"extension_name":{"message":"Wagwoordvanger"},"ignore":{"message":"Ignoreer hierdie keer"},"initialization_message":{"message":"Meld asseblief by jou rekening aan sodat Wagwoordvanger in werking kan tree."},"initialization_thank_you_message":{"message":"Dankie. Wagwoordvanger is nou in werking."},"learn_more":{"message":"Kom meer te wete"},"password_warning_banner_body":{"message":"Jou Gmail-wagwoord is pas aan 'n nie-Gmail-aanmeldbladsy blootgestel. Jy moet jou wagwoord onmiddellik terugstel om jou Gmail-rekening veilig te hou. Maak asseblief ook seker dat jou Gmail-wagwoord nie ook in ander dienste gebruik word nie."},"password_warning_banner_header":{"message":"Stel jou Gmail-wagwoord terug"},"phishing_warning_banner_body":{"message":"Dit kom voor of hierdie werf 'n bedrieglike weergawe van die Google-aanmeldbladsy gebruik om jou wagwoord te steel, en daarom is dit geblokkeer. As jy verstaan dat hierdie werf jou rekenaar kan beskadig, kan jy dit besoek, maar wees asseblief versigtig oor die inligting wat jy intik."},"phishing_warning_banner_header":{"message":"Hierdie werf is geblokkeer."},"report_phishing":{"message":"Gee hierdie werf aan"},"reset_password":{"message":"Stel wagwoord terug"},"sign_in":{"message":"Meld aan"},"visit_this_site":{"message":"Besoek hierdie werf"}}
{"always_ignore":{"message":"Ignoreer altyd vir hierdie webwerf"},"always_ignore_confirmation":{"message":"Wil jy h\u00ea Wagwoordwaarsku moet altyd hierdie webwerf ignoreer?"},"back":{"message":"Terug"},"contact_security":{"message":"Kontak sekuriteit"},"extension_description":{"message":"Wagwoordwaarsku help beskerm teen uitvissingsaanvalle."},"extension_detailed_description":{"message":"If you enter your Gmail or Google for Work password into anywhere other than accounts.google.com, you\u2019ll receive an alert, so you can change your password if needed.\n\nPassword Alert also tries to detect fake Google login pages to alert you before you\u2019ve typed in your password. To do so, Password Alert checks the HTML of each page you visit to see if it\u2019s impersonating a Google login page.\n\nFAQ\n-- When will Password Alert take effect?\nPassword Alert will initialize itself the next time you enter your password into accounts.google.com.\n\n-- Does Password Alert store my password or keystrokes?\nNo. Password Alert doesn\u2019t store your password or keystrokes -- instead, it stores a secure thumbnail of your password, which it compares against a thumbnail of your most recent keystrokes within Chrome.\n\n-- Where does Password Alert send data?\nIf you are using Password Alert in a Gmail account, Password Alert does not send any data from your local computer. If your Google for Work administrator chooses to deploy Password Alert across your domain, the administrator will receive alerts when Password Alert triggers.\n\n-- What are Password Alert's limits?\nPassword Alert doesn't protect incognito windows, Chrome Apps, or Chrome Extensions. It also does not protect passwords for non-Google services. Password Alert only operates inside the Chrome web browser when Javascript is enabled.\n\n-- Where can I find more details?\nVisit the full FAQ at LINK_TBD, or you can see the entire open-source codebase at https://github.com/google/password-alert\n\nBy installing this item, you agree to the Google Terms of Service and Privacy Policy at www.google.com/policies/\n"},"extension_name":{"message":"Wagwoordwaarsku"},"ignore":{"message":"Ignoreer hierdie keer"},"initialization_message":{"message":"Vir Wagwoordwaarsku om te werk, meld asseblief aan."},"initialization_thank_you_message":{"message":"Dankie. Wagwoordwaarsku werk nou."},"learn_more":{"message":"Kom meer te wete"},"password_warning_banner_body":{"message":"Jou Gmail-wagwoord is pas aan 'n nie-Gmail-aanmeldbladsy blootgestel. Jy moet jou wagwoord onmiddellik terugstel om jou Gmail-rekening veilig te hou. Maak asseblief ook seker dat jou Gmail-wagwoord nie ook in ander dienste gebruik word nie."},"password_warning_banner_header":{"message":"Stel jou Gmail-wagwoord terug"},"phishing_warning_banner_body":{"message":"Dit kom voor of hierdie werf 'n bedrieglike weergawe van die Google-aanmeldbladsy gebruik om jou wagwoord te steel, en daarom is dit geblokkeer. As jy verstaan dat hierdie werf jou rekenaar kan beskadig, kan jy dit besoek, maar wees asseblief versigtig oor die inligting wat jy intik."},"phishing_warning_banner_header":{"message":"Hierdie werf is geblokkeer."},"report_phishing":{"message":"Gee hierdie werf aan"},"reset_password":{"message":"Stel wagwoord terug"},"sign_in":{"message":"Meld aan"},"visit_this_site":{"message":"Besoek hierdie werf"}}
Loading

0 comments on commit ec5badb

Please sign in to comment.