4 ms·
> The Hover Zoom extension can be seen downloading the 156KB payload I have tried to find out from the article or the original report[1] how the extensions cou
by gorhill 7y ago
> The Hover Zoom extension can be seen downloading the 156KB payload
I have tried to find out from the article or the original report[1] how the extensions could execute the payload from remote servers. I could find no details about this -- I consider this one of the key point.
I could download and unzip one of the extension hosted on the owner's server, "SaveFrom.net Helper".
As expected, the manifest.json contained an entry which allows the extension to execute code not part of the package, in the context of the extension (i.e. can access extensions API):
"content_security_policy": "script-src 'self' 'unsafe-eval'; object-src 'self'"
I have often pointed out that one of the key issue with the Chrome store is that it allows extensions with ability to execute remote code in extension context[2], this makes it impossible to code review such extension, as it can at any time download and execute code not part of the package.
If privacy and security were a genuine concern, all extensions which ask for `unsafe-eval` should be removed from the Chrome store -- they are essentially un-reviewable.
Firefox's AMO does not allow extensions with such ability.[3]
* * *
[1] https://securitywithsam.com/2019/07/dataspii-leak-via-browser-extensions/ https://securitywithsam.com/2019/07/dataspii-leak-via-browse...
[2] https://twitter.com/gorhill/status/1139306139072507906 https://twitter.com/gorhill/status/1139306139072507906
[3] https://twitter.com/gorhill/status/1139308498825732096 https://twitter.com/gorhill/status/1139308498825732096
- itcrowd 7y ago> one of the key issue with the Chrome store is that it allows extensions with ability to execute remote code in extension context I agree. It is also "strongly recommended against" by the dev page [1]. Do you know a strong argument to allow usafe-eval? (i.e. what would be the rationale of continuing to allow it?) [1] https://developer.chrome.com/extensions/contentSecurityPolicy#relaxing https://developer.chrome.com/extensions/contentSecurityPolic...
- vengefulduck 7y agoI bet it’s for user script extensions like tamper monkey.
- itcrowd 7y agoTamper monkey is also available for Firefox, which doesn't allow unsafe-eval .. [edit]: just checked, tamper monkey on chrome has the following policy: "content_security_policy": "script-src 'self' https://ssl.google-analytics.com; https://ssl.google-analytics.com; object-src 'self'"
- heavenlyblue 7y agoFirefox doesn’t allow plugins with unsafe-eval to their store.
- smilliken 7y agoIs it possible to prevent an extension from downloading a javascript payload and interpreting it? Eval isn't required.
- gorhill 7y agoThe default `script-src` policy in extensions is 'self', no JavaScript code outside the package will be allowed to execute.