Chrome "Did you mean...." Safety warning

Status
Not open for further replies.

SeanT

Customer
Joined
Oct 7, 2019
Messages
4
Reaction score
2
Hi,

Some users of Google Chrome are getting a safety warning that the link they click to join a web meeting is fake. The message says:

Did you mean DOMAIN.com?
The site you just tried to visit looks fake. Attackers sometimes mimic sites by making small, hard-to-see changes to the URL.


I've replaced our actual domain with DOMAIN in the message above.

There's a button to ignore which loads into the meeting thereafter however it doesn't look good that we have to instruct participants to click ignore on a security message.

Is there anything that can be done?

Thanks,
 
Hi Sean,

This may happen if they mistyped something and it is remembered in their history every time they try to use the url and Chrome serves up the mistype from history. Please empty their history to ensure this is not the case.

If it continues, there may also be something hijacking your URLs. So far I have not experienced it on any of our machines here, running Chrome Version 84.0.4147.125 (Official Build) (64-bit)
 
Hi Sean,

This may happen if they mistyped something and it is remembered in their history every time they try to use the url and Chrome serves up the mistype from history. Please empty their history to ensure this is not the case.

If it continues, there may also be something hijacking your URLs. So far I have not experienced it on any of our machines here, running Chrome Version 84.0.4147.125 (Official Build) (64-bit)
I use the webmeetings often and this also happened to me for the first time for me today. 3CX might want to reach out to google with it's list of webmeeting domains to clear them as safe.

Seems to happen when the pbx subdomain name is similar to an otherwise known fqdn
 
Just saw this today. Must have been the latest Chrome update.

3CX and Google will need to work this out. There may be a way in the Chrome ADMX templates, that won't help conferences with people outside the company though. It's not very professional to tell a customer to hit ignore on a security warning....
 
Any update on this? Still seeing it today.

For example,

Local PBX is: pbx.company.com
3CX Webmeeting: pbx-company-com.3cx.net

Chrome sees pbx-company-com in the URL and is flagging it because it looks like a fake pbx.company.com.
 
We are having this issue as well
 
To add some clarity when you invite someone to a webmeeting from the people page your are taken to a new link. This means you go from something like 3cx.domain.com to 3cx site which changes the URL to 3cx-domain-com.3cx.net.

This is on Chrome Version 84.0.4147.125.

In response to JohnS_3CX reply there is no mistyping because you are just click on the create webmeeting link in the persons record in the 3cx web page. If support reaches out I can provide a video of the issue.
 
To add some clarity when you invite someone to a webmeeting from the people page your are taken to a new link. This means you go from something like 3cx.domain.com to 3cx site which changes the URL to 3cx-domain-com.3cx.net.

This is on Chrome Version 84.0.4147.125.

In response to JohnS_3CX reply there is no mistyping because you are just click on the create webmeeting link in the persons record in the 3cx web page. If support reaches out I can provide a video of the issue.
From Chrome you can paste "chrome://flags/#enable-lookalike-url-navigation-suggestions" into the browser and change the setting to disabled to resolve. Don't see anything in the ADMX template to manage via GPO for this setting still looking into it more
 
Same here,

Because the web meeting url contains something like abc-com.3cx.net, chrome thinks that this url was crafted by some sort of hacker trying to hijack the end user session. Thanks @akjrabe21 for the chrome setting. @JohnS_3CX there needs to be a more scalable solution. On a 50 users deployment, we can't ask every end users to change a flag in their Chrome software. Is that setting will still be disabled after the next Chrome update, or Chrome will return that setting to its default value on every updates?
 
Hi all,

Let me start by saying that obviously we can neither tell nor dictate what settings and features Google adds/removes from Chrome. Disabling that feature is entirely up to you in this case, we cannot do it for you nor bypass it.

As a general purpose browser, and from Google's perspective, Chrome is agnostic to what that the webmeeting URL is, so we cannot really blame them for showing you that notification.

On the other hand, it's only a minor annoyance at this stage, compared to the major undertaking of changing 1000s of webmeeting URLs to something that no longer triggers that setting, only to find out that the setting is gone at a later chrome revision, or kept and made more aggressive.

So at least for now, you will either have to allow it or look into ways to manage your browsers across your network (ie. via Google Admin's Chrome Policies or other means). Given that tomorrow Google may add other features that pose problems or become an annoyance, you will need a way to manage your organization's machines anyway, I think this is something that none of us can avoid when we are talking about companies with more than a handful of users (we already use Chrome Policies internally at our offices).
 
Respectfully, you will forever be at Google's mercy when it comes to WebMeeting, especially as the competition dwindles with Chromium Edge. While Chrome .admx files are great internally, no organization can control external invitees. This isn't going away.
 
We have run Chrome ADMX templates for years and can generally manage what we want that way. However, even after getting the latest templates I could find a setting to fix this issue via GPO. I tried adding our 3cx.net URL to the safe browsing list and it had no effect. It's not practical to go around and manually do every machine.

What concerns me more are people outside our organization. It is very unprofessional to ask a customer to click ignore on a security warning to get to a webmeeting. There needs to be a resolution here other than just live with it. Surely Google has a way to apply to be whitelisted.

Unless this feature creates a huge fuss I don't see it going anywhere. I have yet to find another site that triggers it, so I'm not sure what the chances of removal are. It is a valid security feature, many scammers use like-URL's to get their targets.
 
Last edited:
I can second that the Chrome .admx files don't have a setting to prevent this and Safe Browsing exemptions do not apply.
 
Chrome 85 was released today and this issue no longer exists. It appears as though Google removed the like-URL security feature, I'll happily eat my words. Not sure if it will come back or not, time will tell.
 
Status
Not open for further replies.

Forum statistics

Threads
111,973
Messages
590,078
Members
164,896
Latest member
sameage