According to Russian security firm Doctor Web, there are an increasing number of Mac-focused Trojans that install extensions for Safari, Chrome, and Firefox. These extensions are designed to embed third-party ad code into otherwise unrelated Web pages, funneling the clickthrough revenue back to the malware authors. The Trojans use a variety of techniques to fool users into installation, including masquerading as video plug-ins, media players, download accelerators, and more. To be safe, avoid installing software from sites that prompt you to do so — always get software from trusted sources. follow link
Copy Before Submitting Web Forms
Filling in Web forms (like the one used to submit this tip) can be a bit of a gamble - you put in your pearls of wisdom, perhaps only to lose them all if the Web page flakes out or the browser crashes. Instead of losing all your text, "save" it by pressing Command-A to select all and then Command-C to copy the selected text to the clipboard. Do this periodically as you type and before you click Submit, and you may "save" yourself from a lot of frustration. It takes just a second to do, and the first time you need to rely on it to paste back in lost text, you'll feel smart.
Beware Trojans Bearing Ads
Does this mean one should turn off AutoUpdate or use it strictly as a notice that one should go the original vendor's web site to get the latest update?
The main thing is, if a Web page pops up a dialog saying "You need the IMGOINGTOSTEALYOURFACE plugin to view this content." click Cancel and close the page as quickly as possible. And even if a site says, "You need the Microsoft Silverlight plugin to view this content." go to the Microsoft site manually to download and install it, rather than getting it from the prompt.
Does this mean extensions from other sources are suspect? How does one go about determining their safety? (Crap, and I thought Mac users didn't have to fuss about this stuff.)
This is actually a big deal, and I believe Google has changed Chrome so that you can download Chrome extensions only from the Chrome Web Store rather than from developer sites for just the same reason.