8 ms·
Comodo “Chromodo” Browser disables same origin policy
- __jal 11y agoTheir PKI infrastructure was compromised a few years back, too. Obviously a very different corner of the security landscape, but it doesn't seem like they've gotten any more careful. Avoid.
- steckerbrett 11y agoAh the old, break the PoC to make the researcher stop complaining move but don't fix the underlying insanity. Classic.
- david_shaw 11y agoMy background's in application security assessments. I've seen this hundreds (or more) times, from developers that should really know better. "Hey, there's SQLi in this input form! Better make sure ' OR 1=1;-- is blacklisted," but don't properly parameterize their queries or sanitize input.
- dsacco 11y ago"Hey, they reported cross-site scripting! Let's blacklist angle brackets, that'll do the trick!" In case this is not clear to anyone in 2016, blacklisting known-dangerous characters is not an adequate bug fix. It's a rabbit hole, you will burn hours trying to blacklist every character or character combination that can cause a vulnerability just to have someone own you anyway.
- TTPrograms 11y agoWhat's current best practice?
- sarciszewski 11y agoThe proper fixes for common web application vulnerabilities are as follows: Session Hijacking/Fixation/etc.: Use TLS. SQL Injection: Prepared statements that AREN'T emulated; PHP's defaults are bad here. EDIT: If you're writing in another language, make sure it's not providing string escaping masquerading as prepared statements, but actual prepared statements. (My earlier comment was too broad; some forms of emulated prepared statements might be OK, but PHP's is dangerous.) Cross-Site Scripting: Context-aware escaping (templating libraries) + Security Headers Cross-Site Request Forgery: CSRF tokens Password storage: bcrypt, scrypt, PBKDF2-SHA2, Argon2 Encryption, Digital Signatures, Authenticated Key Exchanges, etc.: Hire an expert, don't do it yourself based on the advice contained within HN comments. File Inclusion / Directory Traversal: Don't write your applications in a dumb way that makes these vulnerabilities possible. But if you must, use something like realpath() with a sanity check based on the expected parent directory (in PHP). XML External Entities: Make sure you disable the entity loader: libxml_disable_entity_loader(true); PHP Object Injection in PHP 5: don't ever pass user input to unserialize(); use json_decode() instead. PHP Object Injection in PHP 7: either disable object loading or whitelist the allowed types; i.e. unserialize($var, false); or unserialize($var, ['DateTime']); These are just some of the common problems I frequently find, of course. There are more basic ways to mess up an application ("not even checking that you're authenticated" being at the top of that list). https://paragonie.com/blog/2015/08/gentle-introduction-application-security https://paragonie.com/blog/2015/08/gentle-introduction-appli... Further reading and resources: * https://securityheaders.io https://securityheaders.io * https://github.com/paragonie/awesome-appsec https://github.com/paragonie/awesome-appsec And if anyone wants their code reviewed: https://paragonie.com/services https://paragonie.com/services
- derefr 11y agoDo prepared statements count as emulated if the DB doesn't support prepared statements, but the DB adapter is doing replacement during the encoding-to-typed-binary-wire-protocol step (i.e. replacement of typed tokens with other typed tokens) rather than by just concatenating strings?
- 11y ago
- deleted 11y ago[deleted]
- AdmiralAsshat 11y agoWow, that's disconcerting. Different product, but I'm almost tempted to uninstall the Comodo Firewall that's running on my Windows laptop out of fear that there's some other blatant security blunder waiting to be exploited. Anyone have any suggestions for a free firewall alternative?
- jrcii 11y ago> Anyone have any suggestions for a free firewall alternative? pf on OpenBSD. Strong firewall, highly configurable, the syntax isn't bad, and there are even some decent books out on it.
- Splines 11y agoI've heard people running pf in a vm which their main OS talks to the rest of the world through. Sounds interesting but personally I'm sure I would get it wrong.
- atemerev 11y ago*BSD (especially OpenBSD) is hard to get right in general, but configuring firewall there is a pure joy for some reason.
- steckerbrett 11y ago> I noticed their scan process is not using ASLR You can be pretty sure that none of their software is fit for purpose if they're not using basic protections for a process which runs as a super user and parses every file it can find.
- jessaustin 11y agoI think you have an extra "not" in there; it's hard to parse anyway.
- jve 11y agoAre you using Windows? What's wrong with the Built-in Advanced Firewall?
- sarciszewski 11y agoComodo should have crashed and burned years ago. https://www.youtube.com/watch?v=Z7Wl2FW2TcA https://www.youtube.com/watch?v=Z7Wl2FW2TcA
- jakub_g 11y agoInteresting video, thanks for sharing. One question about it if you don't mind: with the Moxie's proposed client-based solution, how do I know that the communication with notaries is safe? If there's an (active) MITM in the network, they could hijack the connections to all the notaries as well, and whatever the query from client, they'd respond "yeah that cert is totally valid". I guess I'd have to manually install notaries and somehow verify their certs myself upon installation. Edit: well I could rely on Firefox/Chrome to prebundle some "trusted" notaries' certs, like they do with CA certs now, but then I would be able to delete all but a few, contrary to the current situation where deleting some CA certs is breaking the internet.
- sarciszewski 11y agoI don't even know if Convergence is being maintained anymore, but pinning the public key of the notaries would make an active MITM nigh-impossible.
- scandox 11y agoFantastic speech. Thanks for the link.
- jameslk 11y agoI just uninstalled this "Internet Security" piece of software recently and had only kept it on my media PC because it was more of a burden to remove it. Once upon a time, they used to receive high marks for their antivirus software, but as of late, their antivirus software has done nothing but plague me with ads that popup over the taskbar and rob me of my computational resources. It isn't surprising that it is also riddled with security issues like this. This seems to be the trend in antivirus software (like the other gangbuster revelation with Trend Micro). They've slowly turned their software into the crapware they used to defend against in response to their increasing irrelevance.
- Cartwright2 11y agoWasn't there a similar issue in another browser here on HN recently? How does this actually happen - two different security companies both push out "secure" browsers that are fundamentally insecure. I'm not even in the security business and I know it would be fatal to publish a Chrome build without cors. What I can't understand is why would they ever disable it? Seems almost like an act of malice.
- jameslk 11y ago> Wasn't there a similar issue in another browser here on HN recently? This one?: https://news.ycombinator.com/item?id=10882563 https://news.ycombinator.com/item?id=10882563
- wepple 11y agoI'd argue Comodo isn't a security company. It's a software company that markets software which intends to have a positive effect on one aspect of your security (namely, malware). They're using 20 yearold ineffective techniques to do attempt to have a positive effect on your security, and whether there is a positive, negative, or neutral net effect is to be debated. They continue to make hundreds of millions of dollars, so they keep going. Edit: are you talking about this: https://news.ycombinator.com/item?id=8866784 https://news.ycombinator.com/item?id=8866784 ? I'd have thought a company like whitehatsec would be able to do a better job with a browser.
- deleted 11y ago[deleted]
- derFunk 11y agoComodo, TrendMicro, AVG... A lot of security suites made it into headlines the past couple of months, because of their incredible questionable practices. What's the reason for this?
- thekos 11y agoTaviso has been on a rampage.
- jeremycw 11y agoTo quote Harvey Dent in The Dark Knight: "You either die a hero or you live long enough to see yourself become the villain."
- ploxiln 11y agoNo one bothered to watch the watchers (most of us just uninstalled commercial anti-virus/anti-malware crap, or moved to other OSes). Until now, when Tavis Ormandy decides to do this frustrating unpleasant work as a service to humanity.
- ossreality 11y ago... it's been an internet meme that AV solutions are worse than a lot of viruses... for over a decade. This isn't anything new. In fact, this stuff happens regularly on an ongoing basis.
- forgotAgain 11y agoImprovements in the security of Microsoft desktop operating systems is sucking all of the oxygen out of the desktop security marketplace. 3rd party browsers have also had an equal impact on the desktop security marketplace by competing with (and replacing) IE.
- deleted 11y ago[deleted]
- JukEboX 11y agoI can't find any information as to how you would contract this.
- cjbprime 11y agoWhat do you mean by contract? You download it from https://www.comodo.com/home/browsers-toolbars/chromodo-private-internet-browser.php https://www.comodo.com/home/browsers-toolbars/chromodo-priva....
- JohnTHaller 11y agoComodo's "secure" browsers have a tendency to lag rather badly behind Chrome. So a major security fix will land in Chrome and be pushed to stable along with the relevant security bug being made public but Comodo's Chrome-based browser won't land the patch for weeks or months.
- mschuster91 11y agoGuess the reason is because some site failed to implement CORS. But, on the other side, it's a TRUE PITA to debug.
- twiss 11y agoI don't understand the testcase they provide. It opens a window at https://ssl.comodo.com/ https://ssl.comodo.com/ and sends a message to it with `postMessage`. However, the whole point of postMessage is to provide cross-origin communication. Continuing, the message they send is: { command: "execCode", code: "alert(document.cookie)", } Apparently https://ssl.comodo.com/ https://ssl.comodo.com/ used to then proceed to execute that code. However, this is not a vulnerability in the browser, but in that website. Am I missing something? Was Chromodo breaking the `messageEvent.origin` property, breaking same-origin checks in JavaScript? Seems far-fetched.
- lolc 11y agoWhat postMessage() does is immaterial. This is where it should fail, referencing into another domain: obj.postMessage
- twiss 11y agoNo, that shouldn't fail. `postMessage` is not a random function defined inside the window at ssl.comodo.com. It's a function defined by the browser, available on every Window object, including ones returned by window.open(): https://developer.mozilla.org/docs/Web/API/Window/postMessage https://developer.mozilla.org/docs/Web/API/Window/postMessag...
- lolc 11y agoThanks for the correction. I didn't know postMessage() was special. Now I too am confused as to why the browser should be to blame here.
- snakebitten101 11y agoComodo's browsers should not be trusted. They have jumped the shark and do not value their users security or privacy in the slightest. Why do I say so? For things like this: http://forums.comodo.com/help-cd-b206.0/-t108748.0.html http://forums.comodo.com/help-cd-b206.0/-t108748.0.html
- vetrom 11y agoEmpowering Honest Achmed worldwide since 2011!