8 ms·
I am one of the few people that inspects the source-code of extensions. It's easy to do, for Firefox for example, just right-click and save-as in the extensions
by blindm 6y ago
I am one of the few people that inspects the source-code of extensions. It's easy to do, for Firefox for example, just right-click and save-as in the extensions site, then rename your extension to a .zip file and extract e.g:
addon.xpi --> addon.zip
Then manually sift through the code looking for obvious malicious intent (or not so obvious malicious intent if the author is doing obfuscation). Note: obfuscation is a red flag! A simple scan for `https:// https://` / 'http:// http://' would usually yield interesting URLs where data is sent. I have actually spotted malicious addons in the wild this way and reported them to Mozilla. They were thankfully removed.
Note: Obfuscation is NOT the same as minification, and I don't mean minification when using the word obfuscation!
- Triv888 6y agoMaybe Mozilla could list on the Addon's page a list of domains/IP addresses where data is being sent. A Bit like a table of Nutritional Facts for food, but for extensions.
- blindm 6y ago> A Bit like a table of Nutritional Facts for food, but for extensions. Great idea!
- gruez 6y agoSo bad guys will route all traffic through a proxy instead? eg. this addon connects to: * https://484044b296.execute-api.us-east-1.amazonaws.com
- Triv888 6y agoI always considered proxies, url shorteners, etc to be suspicious in the first place. Some more investigation would be required in some cases.
- gruez 6y ago>I always considered proxies, url shorteners, etc to be suspicious in the first place It doesn't have to be as overt making it look like a proxy (eg. a endpoint that makes arbitrary http requests on behalf of the caller). It can be as simple as changing the endpoint for the spying service from https://evil.example.com/api/ https://evil.example.com/api/ to https://484044b296.execute-api.us-east-1.amazonaws.com/evil/api/ https://484044b296.execute-api.us-east-1.amazonaws.com/evil/... > Some more investigation would be required in some cases. The point is that the "nutrition facts label" doesn't really do anything because it's trivial to bypass. If it becomes widespread I guarantee every malicious addon maker would adopt this tactic.
- Triv888 6y agoOf course it would not be the only element in the table. But either way, it would at least tell you that an extension is leaking data when it isn't supposed to leak data (for extensions that should not require an Internet connection).
- ashtonkem 6y agoI personally would find such an inscrutable name suspicious.
- gruez 6y agoWhy? Would connecting to "api.example.com" be less suspicious? The same issue would still be present (namely, smuggling requests to "shady" domains using a mundane domain), and the only difference would be that it demonstrates the author paid $10/yr for the domain.
- ashtonkem 6y agoI should be able to clearly determine the intention of any domain that an extension is going to call. Anything that tries to obsfucate the actual underlying purpose is a red flag. One might not like Google analytics, but at least you know exactly what you’re going to get when someone calls analytics.google.com.
- 542458 6y agoWouldn’t that be impossible to do as you’d have to somehow execute every code path in the plugin? The domains don’t have to exist as strings - there are lots of ways to obfuscate network requests.
- gruez 6y agoDepending on how you approach it you either end up having to solve the halting problem (spoiler: it's impossible), or restricting what domains an addon can connect to (also impossible given the way addons work. they can inject arbitrary scripts into pages to make requests for them).
- Triv888 6y agoBut you have all the code and you know which functions/methods/etc that can do requests so it should be trivial... either way, if it is not a solvable problem, there is a major problem in the design.
- gruez 6y ago>But you have all the code and you know which functions/methods/etc that can do requests so it should be trivial but you can't. See the last part of my comment: "they can inject arbitrary scripts into pages to make requests for them". >either way, if it is not a solvable problem, there is a major problem in the design. Not really. It's like complaining that debuggers can impersonate programs they attach themselves to.
- Triv888 6y ago> they can inject arbitrary scripts into pages to make requests for them disallow that behavior? You could also just pull that code but it might change based on request origin...
- fennecfoxen 6y agoLots of the best extensions are basically "change this webpage when it loads to make it work better." You can't "disallow this behavior" without crippling them.
- Abishek_Muthian 6y agoPerhaps even a need gap for 'little snitch for browser extensions' as a browser extension(Considering OS LS or similar usually gets whitelisted for 80/433 with browsers). Is it even possible or would the sandbox prevent such an extension from functioning?
- Triv888 6y agoYes, there is probably many extensions that make outside connections that don't add benefit to the user by doing so. I wish I could block per-app connections on Linux like Little Snitch appear to allow on Mac.
- dylan604 6y agoIsn't Little Snitch essentially an interactive firewall? Rather than silently denying/allowing traffic, it needs the user's decision until a connection is white/black listed? Why would this not be allowed on Linux? (other than the app doesn't exist, yet)
- gus_ 6y agohttps://github.com/evilsocket/opensnitch https://github.com/evilsocket/opensnitch However, if you allow everything to 80/443, the extensions would still be able to connect to their servers. Maybe the browsers should add the ability to allow/deny connections per extension. https://github.com/gustavo-iniguez-goya/opensnitch/issues/21 https://github.com/gustavo-iniguez-goya/opensnitch/issues/21
- the8472 6y agoThis is entirely possible. Either by isolating the application into a network namespace (e.g. via firejail or systemd units), with selinux labels, running the process under a custom gid and various other mechanisms.
- Triv888 6y agoAnything is possible, but is it relatively easy to block all apps and keep a whitelist of allowed apps?
- gnaman 6y ago> Note: obfuscation is a red flag And why is this? Unless the extension source is already public, I don't see any reason why anyone would not use obfuscation
- unethical_ban 6y agoThere is no reason /to/ use obfuscation in good faith if the code is open source.
- megous 6y agoI've found extensions doing malicious things that were not obfuscated, by inspecting the code. Obfuscated code is just not worth installing at all. Too much work, for little benefit, to review it, when alternatives exist.
- tobylane 6y agoThen it’s a sign that they haven’t open sourced their extension, which is a red flag. Minification may be acceptable though pointless.
- blindm 6y agoNote: Obfuscation is NOT the same as minification, and I don't mean minification when using the word obfuscation!
- eyelidlessness 6y agoMinification isn’t necessarily pointless, depending on the tooling used. While the JS doesn’t have a wire cost, it does have a parsing and execution cost. Optimizing compilers like (say) Google Closure Compiler can significantly improve runtime cost, which is definitely a benefit for extension users. That said, any extension using those tools without source code available and build verification should definitely be viewed with suspicion.
- blindm 6y ago> And why is this? I'm not saying all obfuscation is necessarily bad, just something to look out for if you're trying to sleuth around for malicious intent by the addon's author. Typically if you want to hide the fact you are collecting the browsing secrets of the addon's user, you would use some form of obfuscation (in order to have the addon in good standing by Mozilla and to stop a simple sweep by people like myself who first look for things like http:/https: in the source). Note: Obfuscation is NOT the same as minification, and I don't mean minification when using the word obfuscation!
- superkuh 6y agoUnfortunately if you modify the extension at all the Mozilla will not allow you to use it in Firefox branded browsers. So while it is nice you can look, you cannot change if you use Firefox. This has been the case since Firefox 37. I assume Chrome jumped the shark even earlier.
- mmis1000 6y agoIf you are not going to list it on the store page. Mozilla has a process thst allow you to sign add-on automatically unlisted without review(you do still need a free account).
- superkuh 6y agoIt just highlights that the whole process is awkward security theater. The only security is Moz being able to revoke access.
- mmis1000 6y agoThat is basically the whole purpose of that. A kill switch used when everything is on fire. Allows them to deactivate wide spread malwares when they discovered it. Although I have no idea whether it works or it is ever being used. On the other side. The chrome store starts to behave badly and ban extensions they don't like for random reason after they implement that. About mozilla, i don't know. will they eventually be like that, or they won't?
- alternatetwo 6y agoOr just use the developer edition and enable unsigned extensions.
- superkuh 6y agoDeveloper edition is a beta (or alpha since it derived from aurora line which came from alpha). You can say it doesn't have bugs but it has more than release editions. In my experience many more. Using a beta as a daily driver is not something to recommend. Now, some distros like Debian have enough political power to get Mozilla to allow them to put Firefox branding on their altered user-freedoms-respecting repo editions of FF release. But most don't. So the only way to use actual release FF is to go outside your repos and use the unbranded version. Possible, of course, but tedious.
- loeg 6y agoHow do you distinguish minification from obfuscation? I mean, minified JS is essentially illegible to me.
- alternatetwo 6y agoYou can run it through a beautifier and get it readable again.
- loeg 6y agoI don't think that's true. I don't think any tool can automatically recreate meaningful symbol names once they have been destroyed (absent things like debuginfo, which is irrelevant in the javascript context).
- szaroubi 6y agoTo me, minifaction will rename reallyClearFunctionName("string param") to a("string param"). While obfuscation would also encrypt the "string param" and then decrypt it at runtime. Minification's main purpose is to reduce the size, obfuscation will go one step futher and make it difficult to understand what is going on. Side note, it can be obfuscated but "maxified" (if that is a thing). Side note: the joke goes that Perl is a write only language as it is difficult to read it and understand it. Some twisted souls decided to create the obfuscated perl content: https://en.wikipedia.org/wiki/Obfuscated_Perl_Contest https://en.wikipedia.org/wiki/Obfuscated_Perl_Contest For a list of some of the winners: https://www.foo.be/docs/tpj/issues/vol4_3/tpj0403-0017.html https://www.foo.be/docs/tpj/issues/vol4_3/tpj0403-0017.html
- the8472 6y agoAdvanced minification might do more optimizations than just shortening names though. In the extreme case you might have a sort of optimizing compiler that performs the equivalent of `-Os` which can make code quite unreadable. But yes, even that shouldn't be encrypting strings.
- loeg 6y agoSure. You could also imagine a better minifier compressing string constants to save even more size.
- llacb47 6y agoYou don't even need to do all that, just use https://robwu.nl/crxviewer/ https://robwu.nl/crxviewer/ and insert the URL of the extension, for example https://addons.mozilla.org/en-US/firefox/addon/decentraleyes/ https://addons.mozilla.org/en-US/firefox/addon/decentraleyes... .
- wool_gather 6y agoThis may be fine, but do note that you're inserting an extra layer that you have to trust compared to inspecting the source that you know is on your local disk. Should they choose to, nothing stops the site you've linked from masking malicious tidbits in code you request.