7 ms·
I dont understand why they are doing this. .exe files are known to be dangerous so usually when one downloads it you make sure its from a safe website. How is
by grezql 8y ago
I dont understand why they are doing this.
.exe files are known to be dangerous so usually when one downloads it you make sure its from a safe website.
How is blocking non-https .exe downloads making this any safer for end-user?
I am getting fed up with Google trying to steer how the web should be. Already changed to Firefox.
Also when I think about this, this only hurts legacy windows applications which probably is hosted on a non-http site. I dont like this move at all.
- deleted 8y ago[deleted]
- jmathai 8y agoNot saying this is the right solution but the vast majority of Chrome users likely do not know exe files can be dangerous.
- Ajedi32 8y agoIt doesn't matter if the website is "safe" if the download happens over plaintext HTTP. Any middleman could replace the executable with anything, or worse: just inject malicious code into the executable so you don't notice anything is amiss.
- RKearney 8y agoAnd break the code signature in the process, thus causing Windows to display a large nasty warning about the exe being unverified.
- Ajedi32 8y agoWhat, you mean this warning? https://files.brightside.me/files/news/part_46/468060/20593810-UAC_PROMPT-1516629223-1517845099-650-cf6d3a4568-1520921909.jpg https://files.brightside.me/files/news/part_46/468060/205938... I don't know any normal user who would think twice about clicking "Yes" on a prompt like that when they're trying to install a program they just downloaded. There are plenty of legitimate programs that don't have a signature, and plenty of malicious programs that do.
- everfree 8y agoA big problem is that it's so difficult (and expensive) to get a code signing certificate that's valid under Windows that many developers just don't bother: https://docs.microsoft.com/en-us/windows-hardware/drivers/dashboard/get-a-code-signing-certificate https://docs.microsoft.com/en-us/windows-hardware/drivers/da... Here's hoping that something like LetsEncrypt comes along for code signing or EV certificates, or that Microsoft makes the process easier somehow.
- gruez 8y ago>A big problem is that it's so difficult (and expensive) to get a code signing certificate that's valid under Windows that many developers just don't bother: That's for EV certificates. Regular certificates are a lot more affordable: https://comodosslstore.com/ca/code-signing https://comodosslstore.com/ca/code-signing (~$100/yr). For comparison, apple developer program is also around $100/yr. Certum also provides discounted certificates for open source projects (around $30). >Here's hoping that something like LetsEncrypt comes along for code signing or EV certificates, or that Microsoft makes the process easier somehow. The only reason that letsencrypt can be free is that domains can be validated at 0 marginal cost. Code signing certificates are issued to persons or corporations, not domains. Because of that, the issuer has to do a bunch of manual checks that drives up the marginal cost of each certificate. Also, letsencrypt has many corporate sponsors who directly benefit from https adoption. Who benefits from microsoft code signing certificate adoption? Only microsoft.
- justinclift 8y ago> Certum also provides discounted certificates for open source projects (around $30). The Certum ones turn out to be about 135 Euro, after the mandatory super expensive (and super slow) postage for the key fob to store the key on is included. They do have "Cloud hosted" ones available too, which don't need the electronic fob. But I don't know anyone who'd trust their electronic signing keys to "the cloud". ;)
- 8y ago
- PretzelFisch 8y agoIf you download an exe from a nonsecure connection. You cannot be sure the exe is the one offered by the site or one provided by a man in the middle. I know there are CRC checks but, this protection is not for user that understand that.
- archgoon 8y agoAs a PSA, CRC checks are insufficient to prevent tampering. CRC checks are designed to detect accidental corruption, not deliberate. Cryptographic hashes, provided over a secure connection (not http), are the basic minimum. Do note that even then, there have been demonstrated exploits of package managers downloading over http, where the parsers were demonstrated to be compromised. https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3462 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3462 (nice summary of the above CVE https://www.securityweek.com/code-execution-vulnerability-impacts-linux-package-manager https://www.securityweek.com/code-execution-vulnerability-im...)
- deleted 8y ago[deleted]
- floatingatoll 8y agoGoogle found a threat model where attackers inject http:// http:// .exe links into https:// https:// web pages. This exposes a flaw in mixed-content handling, where web pages don’t allow http:// http:// resources to be loaded - but DO allow resources to be downloaded. Addressing that flaw for all file types would probably break a lot of the internet, but not for .exe (in their apparent estimation). I look forward to hearing what the Firefox and Edge teams think of this. TLDR: In this approach, http:// http:// sites can link http:// http:// executables, but https:// https:// sites cannot.
- deleted 8y ago[deleted]
- mfoy_ 8y agoI don't see why a https:// https:// site would serve up a http:// http:// download link to an .exe in the first place. Mixed-content rules would block even loading http:// http:// images on a https:// https:// page, so wouldn't you think that blocking .exe downloads from http:// http:// sources on an https:// https:// location would also be blocked? I don't love Google, but this doesn't seem like a bad idea.
- floatingatoll 8y agoA properly behaving site would not. One hacked by malware distributors could.
- CydeWeys 8y agoMalice is certainly possible, but someone simply making a mistake is another easily plausible cause. Many sites don't correctly redirect all URLs to from http to https.
- kemitche 8y agoMistakes will be fixed pretty quickly if this policy gets implemented, so I don't see it as a problem.
- zelon88 8y ago> I am getting fed up with Google trying to steer how the web should be. Already changed to Firefox. I second this. Their market share affords them far too much luxury with not nearly enough impartial oversight. > I dont understand why they are doing this. I do understand why they're doing this. Me and you are smart enough to know to only trust a download from a secure connection. Others don't. I've fixed two computers THIS MONTH from people who opened email attachments and then proceeded to click past all of the Office security warnings. Both of them were Kovter droppers. The average user doesn't know what the padlock means, and if you hid a non secure download behind an https redirect they wouldn't even know. Another story, just last week, my town of 9k people has a "social network" based on dotNetNuke on some sketchy shared/co-hosted server without HTTPS. They tried to spam their network on a local FB group recently and they don't even have an SSL cert. Still, the sheer volume of idiots who visited and posted comments like "there's a bug, I can't create an account" or "just signed up!" was disgusting. I posted a stark warning and chewed out the spammer for not taking the 10 minutes to get a free SSL cert, which was when I learned of their sketchy hosting situation. So you see, not only do regular users not know what their looking at on the internet; other web developers also have no idea and don't really care. They insisted to me they have their own security measures which negate the liablity of not encrypting traffic; to which I responded that I could setup a fake AP at the local coffee shop and start stealing passwords if he didn't beleive me. The post was deleted after that, but most of the country bumpkins in my town stood BEHIND HIM!!! They thought I was being mean to a local business. The boogey-man can't sneak up on us, but many people are just going through life and need someone to watch their back digitally. Besides, the only time you initiate a non-secure download of an application from a secure connection is when you've injected payload fetching code into an XSS vulnerability. I can see literally no other use-case unless the developer is an idiot (see paragraph 3).
- d0ugie 8y agoYou are baffled that they reacted this way, that you became the villain? It's hard sometimes, but I've found it helpful to try to perceive both myself and the digital obstacles from the shoes of users I'm trying to help (calibrating more as I proceed), and adjust myself accordingly. Affording someone the ability to save face is among the reasons to consider making a private approach. And when irritated, slighted or indignant, when amped up somehow, not disengaging to cool down is the sort of thing I tend to regret. It's a tall order to expect people to interpret an offer to steal passwords in a coffee shop to assert their need of your acumen as a beneficent act.
- Crinus 8y ago> I dont understand why they are doing this. They want people to fear the desktop since they have no control over it nor way to monetize it and move them to the web where the only way to monetize software is through ads and subscriptions and they provide solutions for both (as well as the hosting/infrastructure for implementing those applications).
- gambler 8y ago>I am getting fed up with Google trying to steer how the web should be. Already changed to Firefox. Here is a reply from Mozilla representative in that very thread: "I would be very happy to push in this direction, limited by the amount of breakage and user-pushback we can expect." http://lists.w3.org/Archives/Public/public-webappsec/2019Apr/0012.html http://lists.w3.org/Archives/Public/public-webappsec/2019Apr...