Yahoo messes up Axis browser launch with major security flaw

Yahoo messes up Axis browser launch with major security flaw
Axis-dental muck ups

Yahoo launched a new search-laden mobile browser this morning, but appeared to have forgotten a couple of teensy-weensy but ever so crucial little tiny details like, you know, robust security and terms of service.

Whoops! Yahoo Axis, which is available as an iOS browser as well as a Chrome extension, intends to cut out the usual search engine middle man by taking users straight from search query to web page.

It's an interesting one, and requires quite specific search terms to really work – for example, if we search 'bears' we're not really interested in the Chicago Bears American football team, we're rather more interested in the actual creatures of the ursine persuasion.

But because the Chicago Bears have significantly better SEO, they come top and we have to flick past them to get to Pooh and friends.

Trying

Anyway, it's worth giving it a go – and you'll be pleased to hear that those security issues have been addressed.

One developer found that the Axis Chrome extension leaks its private certificate file, making it child's play for forgers and cloners to create fake extensions that phish for users' passwords, session cookies and the rest.

As a result, Yahoo disabled the Chrome extension for a time, although it is now back up and running. Yahoo says it has "blacklisted the exposed cert key with Google which has resolved the vulnerability".

The slightly panicked statement also reads, "We take issues like this very seriously and are dedicated to working around the clock to ensure resolution."

And the terms of service, which were once just a placeholder reading "Terms will go here", are now in place so you can merrily go on not reading them safe in the knowledge that they are actually there.

So it could be a case of all's well that ends well, although the fumbled launch doesn't make the already-troubled company look particularly good.

Via The Next Web

News Editor (UK)

Former UK News Editor for TechRadar, it was a perpetual challenge among the TechRadar staff to send Kate (Twitter, Google+) a link to something interesting on the internet that she hasn't already seen. As TechRadar's News Editor (UK), she was constantly on the hunt for top news and intriguing stories to feed your gadget lust. Kate now enjoys life as a renowned music critic – her words can be found in the i Paper, Guardian, GQ, Metro, Evening Standard and Time Out, and she's also the author of 'Amy Winehouse', a biography of the soul star.

Latest in Browsers
Woman using a Windows computer with Microsoft Edge
Don’t panic – Microsoft’s Edge browser isn’t about to subject you to a flood of unblocked adverts (not yet, anyway)
Google Chrome browser icon
A new split-screen feature is coming to Google Chrome, and it's surprisingly powerful
The Microsoft Edge logo on a black background displayed on a laptop screen.
Microsoft just gave Edge a great new feature to ensure the browser doesn’t slow down the PC, and it’s tempting me to switch from Google Chrome
Google Chrome with Christmas theme in Windows 11
I've used Edge, Firefox, and Opera, and yet after ten years in tech journalism, I still come back to Chrome
Woman using a Windows computer with Microsoft Edge
Microsoft gets rid of ‘Edge uninstall’ advice page after facing criticism over it having nothing to do with removing the app, and just promoting the browser instead
Microsoft Edge
Sorry, you're not getting Microsoft Edge off of your PC, at least according to its new 'uninstall' document
Latest in News
An Nvidia GeForce RTX 5080 resting on an RTX 5090 on a gray crafting mat.
Corsair tells us only one of its prebuilt PCs with an RTX 5000 GPU has suffered from chip-level fault, suggesting it’s as rare as Nvidia claimed
A hunter holds up a Grav Bowfin and smiles
How to catch a Gravid Bowfin in Monster Hunter Wilds
Fujfilm GFX 50R
First Fujifilm GFX100RF images leaked in build-up to expected reveal – here’s what they tell us about the unique premium compact camera
Samsung Galaxy Z Flip 6 in blue
The Samsung Galaxy Z Flip 7 could have a Motorola Razr-style full-sized cover screen – and I think it’s about time
Spotify logo on a mobile device
Had Spotify problems recently? It's clamped down on Premium APK 'modded' apps – here's what's happening
The DJI Mavic 3 Pro in flight over some mountains
Upcoming DJI Mavic 4 Pro premium drone could deliver new camera skills and LiDAR – here’s what the latest leaks tell us