New Update Guardio - Guard.io | Creating a Secure Digital World, for Everyone.

Add-on/Extension Page
https://guard.io/

Kongo

Level 35
Thread author
Verified
Top Poster
Well-known
Feb 25, 2017
2,492
Long ago (XP-era) I used a heavily tweaked Interet Explorer for daily browsing (and Opera for downloads). IE could be prevented to download programs (and all risky file types). IE in default configuration had many risky features to facilitate corporate web-applications which could all be disabled to make it a safer browser. Also something I learned after purchasing Windows XP 64 bits on which browser containers did not work like Sandboxie, GesWall, DefenseWall, etc, so I had to improvise.

Why don't browser developers offer an easy safe mode in which risky features are disabled (e.g. many site permissions can be set to block/disable without any loss of functionality in Edge). Browsers nowadays offer profiles, so I have two profiles (one in which nearly everything is set to strict/block/disallow and one in default settings), but why don't the browsers themselves offer something similar (in stead of every security aware user discovering these hardened settings in a trial-and-error way).
Cause only few people would actually use those features. Most users apart from us geeks would probably just use the default settings anyway...
 

Zero Knowledge

Level 20
Verified
Top Poster
Content Creator
Dec 2, 2016
841
Why don't browser developers offer an easy safe mode in which risky features are disabled

Simple. You stop risky features and introduce a safe mode or a lockdown mode then you probably stop telemetry and data collection. All browsers except privacy focus ones rely heavily on spying to create revenue and they earn vast amounts of money from the data they collect in the browser. You stop risky behaviours then you stop the money, not going to happen!
 

GuardioLabs

From Guardio
Verified
Developer
Jan 8, 2023
2
Hey everyone! I'm Nati, head of Guardio Labs - Guardio's research group. I was very glad to see this thread and your relevant comments and ideas! Will do my best to answer all your questions here:

- Guardio is not an Anti-Virus - That is kind of our motto here. We realize that the most abused attack vector these days is our browser - we do everything with it from work, gaming, shopping, social, emails... and meanwhile get tons of phishing, malvertising, and other scam attempts. This is why we focus our current efforts on a solution that is a browser extension (chromium based - Chrome and Edge, no firefox/safari at least for now). This is how we can be first to block those attempts - not only bad advertisements (e.g. adblockers) but also phishing links, tech support scams (that start as a phone call/email), bad files download, malicious chrome extensions, browser hijackers... basically stop any malicious activity that is focused or starts in your browser. So, for example, we stop malware before it was even downloaded...

- Smartscreen / Safe Browsing vs. Guardio - Indeed there are built-in solutions, yet those are unfortunately not enough. Our group of analysts and researchers are working hard to find more and more ways to block new scams and malicious activities, way before standard solutions are able to. We've seen many high-volume as well as targeted attacks that for days and even weeks were ignored by those methods. Also, malware loaders being tagged as safe in virustotal and other EDRs. Our approach managed to capture those right on start and of course block those attempts for our users. We share some of those research details and conclusions in our blog so feel free to visit us and read more about it at: Guardio – Medium

- Downloads Block - we block bad downloads at several checkpoints along the way. Blocking the original serving domains, blocking websites that link or manipulate you to download it, and also blocking the download itself after scanning attributes of the file (before releasing it for the user to execute). We make the max out of what the extension context allows us + using our backend data stream to make real-time decisions.

Hope those answer your questions! Please feel free to ask any other questions, we will be happy to hear your suggestions as well!

Nati,
Guardio Labs - https://labs.guard.io
Guardio - https://www.guard.io
 

Kongo

Level 35
Thread author
Verified
Top Poster
Well-known
Feb 25, 2017
2,492
Hey everyone! I'm Nati, head of Guardio Labs - Guardio's research group. I was very glad to see this thread and your relevant comments and ideas! Will do my best to answer all your questions here:

- Guardio is not an Anti-Virus - That is kind of our motto here. We realize that the most abused attack vector these days is our browser - we do everything with it from work, gaming, shopping, social, emails... and meanwhile get tons of phishing, malvertising, and other scam attempts. This is why we focus our current efforts on a solution that is a browser extension (chromium based - Chrome and Edge, no firefox/safari at least for now). This is how we can be first to block those attempts - not only bad advertisements (e.g. adblockers) but also phishing links, tech support scams (that start as a phone call/email), bad files download, malicious chrome extensions, browser hijackers... basically stop any malicious activity that is focused or starts in your browser. So, for example, we stop malware before it was even downloaded...

- Smartscreen / Safe Browsing vs. Guardio - Indeed there are built-in solutions, yet those are unfortunately not enough. Our group of analysts and researchers are working hard to find more and more ways to block new scams and malicious activities, way before standard solutions are able to. We've seen many high-volume as well as targeted attacks that for days and even weeks were ignored by those methods. Also, malware loaders being tagged as safe in virustotal and other EDRs. Our approach managed to capture those right on start and of course block those attempts for our users. We share some of those research details and conclusions in our blog so feel free to visit us and read more about it at: Guardio – Medium

- Downloads Block - we block bad downloads at several checkpoints along the way. Blocking the original serving domains, blocking websites that link or manipulate you to download it, and also blocking the download itself after scanning attributes of the file (before releasing it for the user to execute). We make the max out of what the extension context allows us + using our backend data stream to make real-time decisions.

Hope those answer your questions! Please feel free to ask any other questions, we will be happy to hear your suggestions as well!

Nati,
Guardio Labs - https://labs.guard.io
Guardio - https://www.guard.io
Really appreciate the detailed explanation. Is there any planned date when Guardio will be available for Gecko-based browsers? (Firefox for example)

We make the max out of what the extension context allows us + using our backend data stream to make real-time decisions.
As your extension heavily relies on its permissions in the browser I see a hard future for you once Manifest v3 is being pushed out. Do you already have a backup plan?
 

GuardioLabs

From Guardio
Verified
Developer
Jan 8, 2023
2
Really appreciate the detailed explanation. Is there any planned date when Guardio will be available for Gecko-based browsers? (Firefox for example)


As your extension heavily relies on its permissions in the browser I see a hard future for you once Manifest v3 is being pushed out. Do you already have a backup plan?
We plan to release our v3 soon with all features working just the same as on v2. So no worries here (y)
 
F

ForgottenSeer 97327

You mean Malwarebytes Browser Guard? Then no. The only extension that does this as far as I know is the one from ZoneAlarm. And it was a mess.
Just checked and MBAM Browser Guard blocks downloads, nothing was downloaded. On same URL's with for instance McFee SiteAdvisor, Microsodt Defender pops up telling me it neutralized malware.
1673258583705.png
 
Last edited by a moderator:

Kongo

Level 35
Thread author
Verified
Top Poster
Well-known
Feb 25, 2017
2,492
Just checked and MBAM Browser Guard blocks downloads, nothing was downloaded. On same URL's with for instance McFee SiteAdvisor, Microsodt Defender pops up telling me it neutralized malware.
That's not what I meant tbh. I meant that Guardio might be able to scan the file once it is already downloaded.
 

Kongo

Level 35
Thread author
Verified
Top Poster
Well-known
Feb 25, 2017
2,492

CyberDevil

Level 6
Verified
Well-known
Apr 4, 2021
262
Please feel free to ask any other questions, we will be happy to hear your suggestions as well!
Do you know about the problem with working in Opera? For some reason in Opera, after installation, when I log in through the extension I can open only my profile, even direct links to the scanner give a redirect to the profile and nothing else. In Edge everything works for me.
 

oldschool

Level 82
Verified
Top Poster
Well-known
Mar 29, 2018
7,100
Sounds like snake oil. Secure everything at no cost! Clean everything! What on earth could go wrong?
Indeed, there is a cost to everything and service-by-subscription is the new normal. By default Guardio knows everything about your browsing experience.

@GuardioLabs have you developed the extension for future MV3 compatibility?
 

Kongo

Level 35
Thread author
Verified
Top Poster
Well-known
Feb 25, 2017
2,492
Indeed, there is a cost to everything and service-by-subscription is the new normal. By default Guardio knows everything about your browsing experience.

@GuardioLabs have you developed the extension for future MV3 compatibility?
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top