3 ms·
Interesting - the attack relies on a compromised rule list, but that doesn't seem super hard. I have no idea what goes into building one of those, where they're
by staticassertion 5y ago
Interesting - the attack relies on a compromised rule list, but that doesn't seem super hard. I have no idea what goes into building one of those, where they're sourced from, etc.
- dewey 5y agoYou can select which "lists" you want to subscribe to when setting up the extension. One of the popular ones would be EasyList: https://github.com/easylist https://github.com/easylist Compromising one of these would be as "simple" as getting a PR merged that wasn't reviewed carefully.
- shadytrees 5y ago> Compromising one of these would be as "simple" as getting a PR merged that wasn't reviewed carefully. I think it's less scary than this. A hypothetical PR would have to contain all the keylogger rules. The person who approves the PR would have to be in cahoots. I hope the filter-list repository owners have 2FA turned on...
- dewey 5y ago> The person who approves the PR would have to be in cahoots. Not really unfortunately: https://www.theverge.com/2021/4/30/22410164/linux-kernel-university-of-minnesota-banned-open-source https://www.theverge.com/2021/4/30/22410164/linux-kernel-uni...
- staticassertion 5y agoI wouldn't be surprised if, given the volume of new domains to be blocked (like for a malware list), there's some automation involved. And since malicious domains can be absolutely nutty it seems particularly hard to manually review for an attack like this. Ultimately I suspect that getting fuzzing integrated, lots of testing, etc, would be wise. It would also make sense to limit the lists you subscribe to - there's not really a ton of reason, in my opinion, to subscribe to more than a basic list.