6 ms·
but as soon as you allow any communication at all, there's no automated way to prevent data theft. I think you missed the point of the article, which proposes
by moe 11y ago
but as soon as you allow any communication at all, there's no automated way to prevent data theft.
I think you missed the point of the article, which proposes exactly that.
All I/O functions would tag all variables populated by them with the source of the data.
When a tagged ("tainted") variable is used in an I/O function again, we can compare origin/destination and apply firewall-style filtering or prompt the user.
.----------------------------------------.
| Add-On "Evernote" has read data from: |
| Chrome Clipboard |
| |
| and wants to send it to: |
| http://evernote.com |
+----------------------------------------+
| [Deny] [Allow] ( ) Remember |
`----------------------------------------'
- Perseids 11y agoAfaict, to not be unuseable restrictive, the extension has to at least have access to the originating site by default. Thus the security of the data depends on the originating site to be secure against leakage – a property no site is designed to accomplish. Just follow through with the first example of Gmail: An extension can write emails to arbitrary third parties (and erase it immediately after to cover its tracks) by using only the intentionally provided functionality of the site.
- ajuc 11y agoWill this show a warning? for (int i=0;i<LEN; i++) { for (char c=0; c<255;c++) { if (tainted[i] == c) { untainted[i] = c; } } } send(untainted); If no - protection doesn't work obviously. If yes - almost all variables are tainted (you don't usually read stuff that doesn't influence codepaths or global state in your application). In the promiscuous world of imperative programming there's millions of ways to introduce dependency that can't be automaticaly checked. For more complex - you can have workers/threads doing while() { sleep(), next_letter; } and other workers killing them after calculated time. Or you can get different number of pseudorandom numbers from generator with known seed in one loop depending on tainted data, and after the loop untainted data is set depending on the current random number from the same generator. Calling rand() taints the generator. I thought they would just mark the whole etension as tainted once it reads tainted data. And then any communication with other sites show the warning.
- moe 11y agoWill this show a warning? Yes, because the assignment happens inside a conditional that references a tainted variable. In the promiscuous world of imperative programming there's millions of ways to introduce dependency that can't be automaticaly checked. That is not true. workers/threads doing while() { sleep(), next_letter; } What is that supposed to achieve? known seed in one loop depending on tainted data Every variable assigned to within a "loop depending on tainted data" becomes tainted. Calling rand() doesn't taint the generator. Seeding it within a tainted scope does. Edit: I was wrong (see below), of course rand() also taints the generator.
- ajuc 11y ago> Yes, because the assignment happens inside a conditional that references a tainted variable. What if it was if (!tainted[i]==c) { continue; } untainted[i]=c; ? If your checker is smart enough to catch this - your whole program is tainted by your password once you check it in the login screen. > What is that supposed to achieve? Global state is incramented by another worker every second to the next value. My thread kills the other worker after N seconds. global state = N and I haven't touched it. If you don't want to call kill from if depending on tainted data - sleep in that if, and call kill immediately after it. > Calling rand() doesn't taint the generator. Seeding it within a tainted scope does. It does: set_seed(1337); for(int i=0; i<tainted[0]; i++) { rand(); } int tmp = rand()); // now I know what tainted[i] was // because I know how many times // rand() was called, because I know // the whole sequence because I know // (untainted) seed.
- moe 11y agoWhat if it was To clarify, tainting "scope" doesn't refer to variable scope but is commonly implemented as a (thread-local) global dict that tracks tainted access in execution order. In your example the variable 'c' would be tainted from the moment the conditional evaluates until it is either re-assigned (from a non-tainted source) or until the program ends. If your checker is smart enough to catch this - your whole program is tainted by your password once you check it in the login screen. Not sure what you mean by "your password" in this context. Which password, from what source? Calling rand() taints the generator Pardon, you are of course right. Yes it does.