Avatar of Tom Knowlton
Tom Knowlton
Flag for United States of America asked on

google privacy error - HSTS?

I am trying to get to the bottom of this error that I get (it seems) like once a day.  

What is HSTS?



Here is a screenshot:

google privacy error
Google Chrome OSNetwork SecurityRouters

Avatar of undefined
Last Comment
Oleksiy Gayda

8/22/2022 - Mon
DarinTCH

so this has actually been around for 5-6 but has recently been gaining traction
it has also been renamed as HTTP Strict Transport Security
a secure version of HTTP
which serves to thwart man in the mddle attacks

the HSTS informs the browser that this should be connected to as a secure site either http over ssl or tls
Tom Knowlton

ASKER
the HSTS informs the browser that this should be connected to as a secure site either http over ssl or tls


And in my case -- is failing to do so?  Can I fix this?
DarinTCH

yes you can install the certificate for said site into your PC -- into trusted certs
....caveat - usually works -
still having occasional issues - especially with firefox
Experts Exchange has (a) saved my job multiple times, (b) saved me hours, days, and even weeks of work, and often (c) makes me look like a superhero! This place is MAGIC!
Walt Forbes
Tom Knowlton

ASKER
Still looking at this.
Tom Knowlton

ASKER
I don't see how to make the certificates "trusted"
DarinTCH

which browser

IE is tools - internet options-trusted sites
and the certificate is on content - certificates - then import

the problem is the browser is now maintin a list of what should be a cert and which is trusted so it folks some security measures and legitimately blocks things like man-in-the-middle
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
Tom Knowlton

ASKER
All my troubles are in Chrome.
Oleksiy Gayda

You must have some extension in Chrome that hijacks HTTPS traffic to inspect it for advertising purposes. See that *.betrad.com "subject" on the bottom of the screenshot - you are going to google.com but the certificate being used for it is issued to betrad.com (which is actually a domain for "Ghostery Enterprises", formerly Evidon, a very well-known marketing analytics provider. Remove any Chrome extensions that you don't trust (especially any extensions associated with Betrad or Ghostery) and your browser will stop exhibiting MITM attack behaviors that Google's HSTS mechanisms are detecting and alerting on.

If removing all Chrome extensions doesn't work, you might have some other spyware installed on your computer (likely came along with some freeware game or utility). You should be able to get rid of those by running a scan with Malwarebytes.
ASKER CERTIFIED SOLUTION
DarinTCH

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
Tom Knowlton

ASKER
I've removed all of my extensions, and it still happens.  For example in Google Docs if i try to edit a document the pop-up window gets hijacked by an advertisement.

When I go to settings / extensions in Chrome:

extensions remvoed
This is the best money I have ever spent. I cannot not tell you how many times these folks have saved my bacon. I learn so much from the contributors.
rwheeler23
Tom Knowlton

ASKER
Scanning with malware bytes 2 detected objects so far:

malware scan so far
Tom Knowlton

ASKER
It's a PC, not a Mac.
Tom Knowlton

ASKER
Here is one that popped-up during the Malwarebytes scan:

iispace
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
SOLUTION
Oleksiy Gayda

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.