Google has decided to ban logins from "embedded browsers" starting in June 2019. But why did the company make this decision? For security. Specifically, to reduce the chances of man-in-the-middle attacks, which have increased recently.
When someone connects to applications through an “embedded browser,” they are more likely to fall victim to a man-in-the-middle attack. For example, the Chromium embedded framework, or CEF, is such a browser and is used by many people to connect to the Steam client, Evernote, and Amazon music.
Unfortunately, detecting a MITM attack, when users connect via an embedded browser, is not possible.
For this reason, Google has decided to completely ban connections made from such a browser. In fact, it will add OAuth authentication. Every time users want to connect somewhere, they will be transferred to another browser, such as Safari, Chrome and others.
With this process Google will be sure that there is no risk of attack. Also, the user will be able to have more information, as the full URL of the login page will be revealed.
In OAuth authentication, there are three parties involved. The first party is the OAuth Client, i.e. the application you want to connect to. The second party is the OAuth provider, e.g. Facebook, Twitter, Instagram. Finally, the third party is the owner himself.
This control system allows OAuth clients to gain access to user data securely, without the risk of password leakage.
Given that many people do not use two-factor authentication, Google proposed this method to have greater security and protection.
Google had to act, as man-in-the-middle attacks have increased. The company has been trying to combat them for some time. Recently, it made an update to Gmail, adding the MTA-STS standard. With this update, hackers cannot gain access to emails sent to and from Gmail.
Man-in-the-middle attacks can cause a lot of problems. A hacker can steal credentials, which is the most common, but also install malware and illegal certificates on victims' computers.
The installation of fake certificates is done in order to «deceive» the anti-virus and allow the installation of malicious software, considering it harmless.
Anyway, whether the risk of an attack is large or small, everyone should take as many measures as possible to stay safe on the internet.
