6 ms·
ChromeGalvanizer – Harden your browser against extension backdoors and exploits
- dsun179 6y agoThis sounds great, I will try. Is it somehow possible to restrict the internet access of a single extension? For example I have an add-http-header extension that has no reason to create connection to an outside server.
- gnicholas 6y agoNot sure if this answers your specific question, but you can limit the sites that an extension can run on. I recently discovered that Chrome offers this feature (right click the extension icon and select Manage Extension to access), and it saved me from having to build a site whitelist feature for my extension. [1] It already has a blacklist feature, and I was going to build a whitelist feature due to user requests. Then I discovered that this functionality is built into all Chrome extensions. Unfortunately it doesn’t seem to exist on Firefox. 1: https://chrome.google.com/webstore/detail/beeline-reader/ifjafammaookpiajfbedmacfldaiamgg https://chrome.google.com/webstore/detail/beeline-reader/ifj...
- Thorrez 6y agoIf it can modify the DOM or even display its own HTML-based UI, that might be hard because it can embed an external image, and the loading of that image would contact an external website.
- 1cvmask 6y agoWho uses this?
- tchaffee 6y agoI open Chrome once in while for testing or on the rare occasion something only works there, so maybe this is useful for those occasions. But if you're serious about security and privacy shouldn't you be avoiding Chrome as your regular browser?
- cl3misch 6y agoOn malicious extensions and stealing login credentials specifically, what's bad about Chrome?
- judge2020 6y agoSince it's the more popular browser for non-tech people (i'd imagine firefox leans more towards tech/privacy-conscious people than 'normal' users), it's probably the first one targeted for auto-extension installation by malware.
- jamieweb 6y agoI can see where you're coming from on the privacy bit, but from a security point of view, Chrome/Chromium is generally a well-secured browser. Yes it's not written in a memory-safe language, but drive-by exploits and attacks that escape the sandbox are exceedingly rare in Chrome, even if you're running an older version. Of course if you add extensions and Flash to the mix, the security is degraded, but with a normal Chrome install it's fairly hard to do something bad in one tab that will negatively impact another.
- miles 6y agoJust tested in Windows with a registry file generated via the linked web interface[0]. Dark Reader was not prevented from accessing sites that should have been excluded based on the imported policy, even after a reboot. Has anyone successfully tested Chrome Galvanizer? [0] https://thehackerblog.com/galvanizer/ https://thehackerblog.com/galvanizer/
- szhu 6y agoI tested the following on Mac: 1. Block "(star)" from accessing "(star)://mail.google.com" 2. Install the config 3. Go to chrome://policy/ and click "Reload policies" 4. Open Gmail. Dark Reader doesn't work anymore.
- miles 6y agoThanks very much - will test on macOS next. EDIT: It must be me, as I am still not having any luck. I just tested in a slightly older macOS VM (10.12) with Google Chrome 81; even after installing the profile, Dark Reader continues to work on sites that should be excluded.
- mandatory 6y agoAuthor here, can you provide the generated policy for me to take a look at?
- miles 6y agoThanks very much for replying. Here is the generated reg file: Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\Software\Policies\Google\Chrome] "ExtensionSettings"="{\"*\":{\"runtime_blocked_hosts\":[\"*://ycombinator.com\",\"*://boh.com\"]}}" Tested in a new Windows 10 x64 (2004) VM with a new install of Google Chrome 81.
- mandatory 6y agoHow strange, it works for me (although it took a second to propagate) - testing with a Win10 x64 VM as well: https://i.imgur.com/jr534JN.png https://i.imgur.com/jr534JN.png If you click "Reload policies" under the chrome://policy page does it kick in after ~15 seconds?
- PappaPatat 6y ago> Using Chrome Galvanizer, you can protect yourself from attacks like this by specifying specific sites that one or all of your extensions can no longer access. For the MEGA case, if users had created a policy restricting access for the MEGA extension to access amazon.com, live.com, github.com, google.com, myetherwallet.com, mymonero.com, and idex.market then they'd be protected from the attack. You might as well turn off the internet for some.
- jamieweb 6y agoIt's a challenge to weigh up the risk of not using an adblocker versus the risk of the extension getting compromised. I guess that solutions like DNS-level blocking or custom hosts files are a fair balance, but I still like the DOM-based per-element control found within adblock extensions. And then I see people with like 20 extensions installed...
- ocdtrekkie 6y agoUltimately it's a trust tradeoff. Extensions should only be installed from incredibly trusted "I'd give this entity my passwords and my bank info for safekeeping" level trust. Because that's essentially the access a lot of browser extensions have. The easiest way to protect your browser from exploits is to disable or whitelist extensions. At the office we block all but a small handful of extensions we've vetted, and we're very hesitant to add more without very good cause. Do this at home too.
- sitkack 6y agoEven for extensions you trust, if their domain expires, it can be minutes later that it is pushing an update. Actually ... Chrome extensions should have a trust policy wrt domain age, meaning a newly refreshed domain (via expiration) shouldn't be able to push an update for X days. edit, forgot to mention that this applies to all plugin systems, many which provide vectors of attack against programmers, many of whom can affect global infrastructure. So VSCode, IntelliJ, etc can be used to inject code into the client as well.
- dogma1138 6y agoChrome extensions should be signed and should prevent updates of extensions if the new version was signed by a different from the one signed the current one until the user manually approves it.
- jamieweb 6y agoMost users will click straight through the approval though, like when they granted it full permissions at install. And is the signing actually effective anyway? There's very little mention of it online, and as far as I can see it isn't covered in the official guide for publishing extensions. Is it even possible to have proper signing keys stored locally or air-gapped?
- squarefoot 6y agoBeing a FF user I can't use it, but it made me think about the dangers of extensions being hijacked. It would be nice to have as a browser builtin feature a domain based whitelist that enables access to extensions according to a trust level, so that for example any new encountered domain can be accessed by all extensions by default, but if I assign say my bank domain a level of N, only extensions whose trust level exceed that N number would be able to access its data while others would be bypassed, then a fixed maximum value of say 10 would mean all extension bypassed for the paranoid. Probably even a trusted/not tusted flag would suffice, but just in case one wants to differentiate between locally written and installed extensions that can't self update, then official and non official ones. Doable?
- namibj 6y agoConsider filing an enhancement request: https://bugzilla.mozilla.org/enter_bug.cgi?product=DevTools https://bugzilla.mozilla.org/enter_bug.cgi?product=DevTools You'd not want to simplify it too much in it's core, though. That'd exclude advanced configurations outright.
- gnicholas 6y agoOne way to accomplish this is to just use private windows for your banking or other critical sites, and then don't let extensions run in private windows. You can configure this per extension in Firefox and Chrome.
- deleted 6y ago[deleted]
- throwaway_pdp09 6y agoA simpler, if perhaps unnecessarily heavyweight way of doing this is to have separate accounts on the same computer. My email has its own account, and allows cookies there (it's gmail). I have to switch accounts to do mail but that's not so bothersome, perhaps even an advantage for some as it might help not jumping every time a mail arrives. Using private X in the browser requires trusting the browser, this way you can have the OS isolate processes which has to be stronger.
- superasn 6y agoI've made it a rule to right click all chrome extensions icons and then set them to "This can read and change data > On www.example.com" on sites I really intend to use them. This prevents them from reading all sites but also prevents the annoyance of reloading the page every-time you need to use the extension. Also some extensions like Likepass inject some really ugly HTML into form fields (it also takes care of that) It's a pretty useful feature that many people miss.
- tjbiddle 6y agoPhenomenal! Thank you! I've personally just switched from Chrome to Brave. Funnily enough, Chrome was causing my computer to seize all the time while Brave does not, even though it's still built on Chromium. But I took the opportunity to go ahead and clear out a number of extensions. Feels so much better. Your browser can really get cluttered over the years!
- miles 6y agoThis. Is. Epic. Completely missed it. Thank you so much.
- tobylane 6y agoThat's a good feature, but not applicable to my setup. What I'd like is more limitations, say Grammarly can only run on pages with textareas.