Omnibox: The real security danger in Chrome

September 28th, 2008 by Lars Ottesen Henriksen

On my home laptop (Thinkpad X40), I use Google Chrome for browsing to see what it’s like. The speed is obviously very nice and I am really happy with the Omnibox – the address bar in Chrome. The suggestions and auto completions are very good and seem to be spot on every time.
Now, there has been a lot of talk about the security of Chrome. I haven’t had any issues in that area – the most dangerous part of Chrome is actually: The Omnibox…

As you may know, the Omnibox suggests sites based on what you type in, just as any other browser. But while the other browsers only look at your history, Chrome also suggests sites that contain the letters you’ve written. An example:

Omnibox suggestions for NYTimes

Omnibox suggestions for NYTimes

Excellent feature! But… These suggestions need to be filtered or you need to explain the Omnibox to your spouse to avoid confusion. Here’s what happened when I was planning on going to Picasa: I entered the first three letters and…

Omnibox suggestions for Picasa

Omnibox suggestions for Picasa

I started laughing and unfortunately my girlfriend was sitting next to me… So to defend myself and explain how the Omnibox works, I thought I’d go to Engadget. Now this was also a bad idea:

Omnibox suggestions for Engadget

Omnibox suggestions for Engadget

The suggested site name means one night stand in Danish… So do yourself the favour of explaining the Omnibox to your spouse before you end up in the same mess as me…

Posted in Random

Related posts...

Related posts



Leave a Comment

Please note: Comment moderation is enabled and may delay your comment. There is no need to resubmit your comment.

About Lars Ottesen Henriksen

Lars Ottesen Henriksen is a Civil Engineer in Computer Systems Engineering from the University of Southern Denmark. He currently works in Copenhagen, but still lives in Odense which means he spends 4 hours on the train each day. Sometimes this time is used for writing, which is what you see above. > More

RSS