12 ms·
Netflix disables use of the Chrome developer console
- jebblue 13y agoDoesn't affect me on Ubuntu, they can't even play a movie in the browser which is something Crackle does a great job at.
- tomrod 13y agoSilverlight still the protocol?
- nolok 13y agoSilverlight is a browser plugin, not a protocol.
- rcfox 13y agoThere is a way to get Silverlight as a plugin in your standard Linux browsers. It's called Pipelight[0]. Yes, it uses Wine, but not for the rendering, so it's not a horrible experience. [0] http://www.webupd8.org/2013/08/pipelight-use-silverlight-in-your-linux.html http://www.webupd8.org/2013/08/pipelight-use-silverlight-in-...
- ToastyMallows 13y agoPipelight is awesome, I recommend using it to anyone reading this. It just works.
- lern_too_spel 13y agoThe NSA ranting around here is out of control. Not only did the poster somehow tie this bit of javascript to the NSA, but he claimed that the NSA records our phone conversations too. There is no evidence that it does unless you're a head of state or somebody the FBI has a warrant to tap.
- nnnnni 13y agoNice try, NSA Agent Lern Too Spel
- ephemeralgomi 13y agoThe poster did not "tie this bit of javascript to the NSA". She/he argues that blindly acquiescing to removal of rights in the name of security is a bad idea, using the NSA phone tapping deal as a point of comparison.
- lern_too_spel 13y agoRemoval of rights? Saying that either this JavaScript or the NSA's actions amount to a removal of rights is a huge stretch. You might as well compare the the sealed battery on the iPhone to the NSA's data gathering.
- ephemeralgomi 13y agoI half-disagree with you: the NSA's actions, IMHO, certainly do amount to a violation of the right to privacy. However, calling the ability to run the javascript development console on a page a 'right' is a stretch, I agree. Please feel free to read the actual article and quote it and find fault with its conclusions. As it is now you're seizing on individual words, not ideas. If this were a Turing test you wouldn't be doing so well.
- lern_too_spel 13y ago
- BadassFractal 13y agoGuess it's time to recompile the browser (Chromium in this case?) with some extra switches to remove that chunk of JS code before it's executed?
- gizmo686 13y agoThat seems like overkill. Just write an extension to unblock the console.
- arg01 13y agoFrom the article: // But if you're feeling up to it, you can run the following line via an extension to prevent // this abuse: // Object.defineProperty(window, 'console', {configurable: false, value: window.console});
- aboodman 13y agoActually that alone won't work in a Chrome extension because of isolated worlds. You have to do a bit more gymnastics.
- deleted 13y ago[deleted]
- redbmk 13y agoA really simple fix for this in Chrome is to type "javascript: delete console" into the omnibox. This will bring back the built-in console.
- staunch 13y agoIts just a bug in Chrome that you can disable it. A cat and mouse game that Chrome should easily win, given that it holds all the cards.
- georgemcbay 13y agoChrome can easily fix this, but it wouldn't actually be a bad idea for them to show a message to the user warning them of social-engineering based self-XSS attacks when devtools are first brought up. Either that or "hide" the developer tools a bit like they do in modern Android so that it is really obvious to the user if they are directed to mess with things that they shouldn't be messing with without understanding them.
- rosswilson 13y ago"so that it is really obvious to the user if they are directed to mess with things that they shouldn't be messing with" I think that as soon as an attacker tempts the user with: "follow these steps to access American/UK (substitute a locale that has content your account shouldn't have access to) only films that Netflix don't want you to know!" that the apparent gain for the user will lead them to ignore any warnings. In fact, warning might actually encourage these kinds of attacks since the user could think "that's just Netflix trying to hide something, I'm gonna following [the attackers] guide"
- syntern 13y agoYou can't protect the users this way: the attacker will create a custom Chromium build and lure the user to download and execute it. At that point the user will be pawned either way.
- chrisrhoden 13y agoIf you're getting a user to download and execute a piece of software, why bother going beyond that?
- 13y ago
- yeukhon 13y agoI didn't read the whole thing, but I think the actual motivation is to prevent self-XSS which is in the first line. http://stackoverflow.com/questions/21692646/how-does-facebook-disable-the-browsers-integrated-developer-tools http://stackoverflow.com/questions/21692646/how-does-faceboo... Anyhow, I will just quickly dismiss this has anything to do with NSA. If I may, be an ignorant once, called this pastebin a bullshit.
- yeukhon 13y agoWow, I can't even modify my post. Which unfair HN mod locked my post? How on earth could anyone connect this to NSA?
- ephemeralgomi 13y agoThe poster did not "connect this to the NSA". She/he argues that blindly acquiescing to removal of rights in the name of security is a bad idea, using the NSA phone tapping deal as a point of comparison.
- krapp 13y agoBut access to a dev console isn't a right - it's just a feature modern browsers happen to include. I agree that disabling it is pointless and futile but it's hardly violating anyone's rights.
- ephemeralgomi 13y agoYup, that is a completely legitimate argument to raise.
- MichaelGG 13y agoCalling it a "right" instead of a permission doesn't change much. "Digital Rights Management" doesn't manage rights under your definition (unless pause or fastforward is a right).
- icambron 13y ago
- Artemis2 13y agoI really like the comparison with right click deactivation. Anyway, people who use social engineering will still win; you can put JS code in the browser bar with the good old javascript: "protocol" if you want somebody to execute something.
- adamnemecek 13y agoI think that executing JS in the URL bar is disabled in all browsers now.
- RandallBrown 13y agoWow, that really sucks. Bookmarklets can be really useful.
- pmh 13y agoBookmarklets still work fine (at least in Firefox and Chrome). It's just copy/pasting something with "javascript:" into the URL box that won't work.
- noblethrasher 13y agoStill works on Chrome 32/Win as of a minute ago.
- polarix 13y agoAbled in chrome 33.
- mrb 13y agoIf you (are tricked to) paste "javascript:..." it won't work. You have to manually type "javascript:" for it to work.
- brianshumate 13y agoActually, you can just type the "j" and then paste the rest.
- arg01 13y agoThings like this always annoy me. It's a marginal annoyance to people who know what they're doing. For those less knowledgeable, who were using something they learnt by rote to improve their experience, they'll either google and find another way to do it (thanks to a blog post/youtube video by someone with a bit of nouse) / download some virus / wait until they see the person who originally showed them what to do. It just seems like a bit of grief for a temporary gain.
- cge 13y agoThere are legitimate security reasons why various major sites want to do this, and the changes do appear to be in response to actual, self-XSS attacks that have been seen. While I am no fan of the NSA, I don't see how this has anything to do with them. I also think this is very distinct from the right-click-disabling that used to be so popular: that was not in response to actual attacks, and also, to my knowledge, never happened on reputable sites. Additionally, I don't recall it being justified as being for "security" reasons: websites were usually rather honest about having it to prevent saving or copying and pasting. This is, in my view, a poor solution to the problem, but as a temporary measure, it makes some sense. A change to Chrome to make a warning message appear the first time the developer console is opened, or javascript is used in the location bar, could be a good idea. And, as the pastebin notes, there are likely better, if more complex, technical solutions from the website side. All of these, however, will take considerably more time and effort, and the attacks are already happening.
- dgrant 13y agoIt doesn't have anything to do with the NSA. He was just saying that "for security reasons" is a stupid excuse that, he says, seems to be frequently used to excuse any nefarious behaviour.
- couchand 13y agoIf you expect me to run your code on my computer I expect to be able to see it first. The comparison to right-click jacking is quite apt. Some people will keep on exploiting others no matter the format, nerfing things for everyone else is not a tenable solution.
- seba_dos1 13y agoFacebook at least allows an easy opt-out.
- dan15 13y agoThat and Facebook's one shows a huge message saying why they do it.
- zobzu 13y agoi would have called that "for security reasons" :)
- userbinator 13y agoI've noticed a rather disturbing trend of thought in technology that's been showing up more and more recently with things like this: "Make it harder for users to know how things really work. Make it harder for users to explore, make mistakes, and learn. Make it harder for users to become developers. The less the users know, the easier it'll seem to them, and the easier it'll be for us to stay in control. Keep them ignorant and consuming. Lock them in a walled garden and tell them it's all 'for your security/safety'. Because knowledge is power, and we don't want that in the hands of the users." Netflix doing this is one of the more obvious manifestations, but they are not alone - many other companies and even open-source, free-software projects are taking this approach, Google included.
- chris_mahan 13y agoI don't have netflix. If everybody does the same, they'll go out of business. Or are you all addicted to TV?
- mindrag 13y agoI think you totally missed the point. We don't want Netflix to go away. (Actually, Netflix is one of the most important technology companies in existence at the moment). We want better behavior.
- quasque 13y agoWhy is it one of the most important?
- ThoreauAway 13y agoit's providing a service that will hopefully lead to a more open future. instead of being forced into buying bundled cable packages, maybe one day we'll be able to have more specified choices. i'd say services like Netflix, Hulu, etc. are all things that push towards that. at least i hope
- deleted 13y ago[deleted]
- syncerr 13y agoJust enter this in the address bar (may have to manually re-type "javascript:") > javascript:void(delete window.console);
- dav- 13y agoWatch out, this guy's obviously a slimy social engineer. Don't fall for his tricks.
- userbinator 13y agoIntuitively, I would expect that to FUBAR the console completely but it's actually deleting the overridden version so it restores the real console's properties (which thankfully cannot be deleted.) Cute way of fixing it.
- deleted 13y ago[deleted]
- matt_heimer 13y agoYou can defeat this without any extensions, here is how: Since this only applies to Chrome, so do the instructions: 1) Open netflix.com 2) Open developer tools. 3) Go to Sources tab. 4) Click on the tiny icon for "Show Navigator" on the left. 5) Find the JavaScript file that has: (function(){try{var $_console$$=console;Object.defineProperty(window,"console",{get:function(){if($_console$$._commandLineAPI)throw"Sorry, for security reasons, the script console is deactivated on netflix.com";return $_console$$},set:function($val$$){$_console$$=$val$$}})}catch($ignore$$){}})(); For me this is cdn1.nflxext.com/FilePackageGetter/sharedSystem/pkg-nflxsrc-* 6) For me the offending line is line 3. Click on the line number, this will set a breakpoint. 7) Reload the page, now the Script will pause before running line 3. 8) Switch to the Console tab. 9) Run: Object.defineProperty(window, "console", {configurable: false}); 10) Switch back to the Sources tab and press the resume script button or F8. 11) Enjoy console access again.
- javajosh 13y agoYes, or if this becomes common one could easily write a little Chrome plugin that stashes a reference to the console and checks to see if it has been disabled (onload and on an interval) and simply puts it back. The only thing Netflix's 'security' measure does is make me respect the company a bit less. Who, precisely is this going to hurt? A serious "attacker" is going to be stopped for about 15 seconds. It might stymie some kid trying to learn about front-end web dev. Good job Netflix!
- skybrian 13y agoThe most benign explanation I can think of is to prevent an attacker from using social engineering where they give the victim a command to run in the JavaScript console. Sites with a large number of inexperienced users (including children) have to think about these things.
- camus2 13y agovery good point.but maybe console access should be included in parental control.
- sergiotapia 13y agoGoogle please fix this bug in Chrome. Websites SHOULD NOT be able to override the console.
- cbsmith 13y agoLet the websites do whatever they want. You can always work around it. The point of such measures is inconvenience.
- iLoch 13y agoI dunno, I kinda like this. Of course it's not blocking serious hackers, that's not the point. I'm guessing this feature is disabled for the same reason Facebook is disabling it - to prevent self XSS (people copy/pasting scripts that'll "give them free/more/better X")
- pippy 13y agoInstead of developers throwing their toys out the cot, try to imagine a conversion along the lines of: MPAA executive: we need to lobby W3C more to get DRM! Netflix: why? MPAA executive: because they'll steal our content! Netflix: no need! we've disabled the developer console so they can't steal your content! MPAA executive: That sounds good! It's nice having a "yeah but you can do X" retort to the people making these decisions. The ideologically driven 'but the web should be oooopen' argument won't go far.
- hayksaakian 13y agothe alternative is "don't negotiate with terrorists" but given that Netflix got where it is today on the back of our broken copyright system, I don't for see that happening anytime soon.
- nilved 13y ago> The ideologically driven 'but the web should be oooopen' argument won't go far. lmao, which site am i on again?
- higherpurpose 13y agoInteresting that this happens soon after Google restricted extensions to developer mode, isn't it? Back then I said the "security reason" is definitely BS, because they already took a "strong enough" measure to only allow extensions to be installed with drag and drop into the Extensions page. Plus, when you have the company that lives by data, not show you the data that made them make this move, you know something is up. I asked then, and I actually asked when they moved to drag and drop, too: show me the data that proves this is so necessary! Even before any of this, Chrome was far better than IE and even Firefox at staving off bad extensions. So to me both of those moves seemed unnecessary, and most likely with another "agenda" behind. Now we begin to see that that agenda could be. I've also connected stuff like this with MPAA taking board membership at W3C. Expect stuff that's much worse than this, and the MPAA-influenced W3C to start keeping features away from browsers that MPAA freaks out about, while Google will increasingly start to ban various extensions from the store for various "ToS reasons". And people still think W3C's DRM extension won't be used to close down the Internet? It took Netflix weeks to take advantage of Google's recent move. Watch what happens when DRM can be enabled in the browser by anyone, just as easily, Then we'll see if the "convenience" of not playing Netflix through a plugin was worth it.
- madrox 13y agoI don't think the goal of this is to hide legitimate uses of the dev tools. As many have mentioned, it's really easy to circumvent. It's to shut down an attack vector.
- gergles 13y ago"self-XSS" (the thing this malfeature is purportedly protecting people from) is a made-up concept. It's basically "don't run your own scripts to interfere with our site, and we'll use scary-sounding security words in an attempt to discourage you from doing it." I don't believe for a second this is about helping the user - more likely is that FB and Netflix want to prevent users running scripts that add features or do functions they find inconvenient, like exporting your address book or movie rating info. I get to run code just as much as you do - it's MY computer, MY browser, and MY bandwidth. Making up a scare word (that just means "users running code I don't like") in an attempt to legitimize disabling access to development and exploration tools is beyond the pale. There is absolutely no reason to permit this kind of behavior, and I'm frankly a little appalled a community of startup founders and hackers would ever defend this kind of behavior, as some of the comments here have done. If you want to protect users from themselves and limit and restrict what they can do, write a mobile app. Don't try and put your shit on the web if you want it to be a walled garden.
- FiloSottile 13y agoI don't see exactly how it is a concern for Netflix, but sadly "self-XSS" is real on Facebook. Not among us tech-savvy people obviously, so consider how much you look from inside a bubble. If people read of a "h4x0r trick to read their bf/gf private messages", they will execute it. And hey, "it has this l33t keyboard shortcut that will make a strange window pop up, it must be what the hackers in the movies use!!". And then "Oh well, thanks to this friend of mine for sharing this cool trick that gives me the stuff to paste there, I would not know how to use it!". And finally "Booooo, Facebook sucks, my account got hacked". I remember of the internet making fun of a girl that believed to be enrolled in some secret police because she popped up the Dev console. Well, that is just normal people, not uncommon. I trust that actual developer can find their way around blocks and warnings, that however raise the bar for social engineering.
- gcb0 13y agoright, because patching one of 1000 is the right solution? please give back your engineer card. - just download this file to see your gf private messages. ok, lets remove download from the browser (actually, ios did this) - just run this long string in the address bar to see whatever. ok, let prevent javascript: schema in url bar (actually, android stock browser did this) anyway you go at it, is ineffective. the only solution is to educate. trying to prevent idiots from harming themselves will just lead to annoyance to the non-idiots and more sophisticated attacks until you cant prevent them. people who implement those dumb thing disgusts me. your comment disgusted me.
- nilved 13y agoWhy can websites disable use of the developer console? That seems like a critical security bug,.
- deleted 13y ago[deleted]
- banterability 13y agoAnyone filed this on http://crbug.com/ http://crbug.com/ yet?
- comex 13y agoI was going to, but the developer console works on the landing page and I don't have an account, so I can't verify Netflix is actually doing that. If someone can verify, I highly recommend filing it. ed: Looks like there is a bug already: https://code.google.com/p/chromium/issues/detail?id=345205 https://code.google.com/p/chromium/issues/detail?id=345205
- meowface 13y agoThis mentions that there are ways to secure CSRF tokens so that they can't be stolen via self-XSS (or any kind of XSS) attacks. How exactly could this be implemented, not including adding a captcha or requiring the user to retype their password for every action?
- artellectual 13y agonever trust the client. no matter what kind of hacks you come up with to protect yourself. you have to assume the client side is always compromised. always protect yourself in the parts you have full control.
- subleq 13y ago> API requests can be made inaccessible from XSS (and that includes self-XSS) by means of a CSRF token that is properly secured How can self-XSS be prevented with a CSRF token? Can't the script included via self-XSS get the token out of the page and use it to make requests that appear as if they originate from the app itself? Can't a script injected through self-XSS do absolutely anything the page can do in the first place?
- just2n 13y agoNo, but it's not easy (in fact it's quite hard to do well) because of how insecure the browser is. You can take advantage of the fact that you can store private information in closures. To prevent malicious code from overwriting a native function to which you pass sensitive information (like the CSRF token in this case) you need to Object.freeze the prototype of things like XMLHttpRequest or take your own references of the native functions. Naturally all of this assumes the user doesn't do something like set a breakpoint and then inject a script with access to scope variables. But if social engineering gets you that far, you could probably just have the user run any arbitrary code on their machine.
- deleted 13y ago[deleted]
- bambax 13y ago> Google should really patch this. The command line API should be privileged so that third parties can't modify how the browser behaves without explicit authorization (i.e. an extension) Absolutely agree. Why don't they do that, or at least make it an option?
- gchfjfjfj 13y agobut, you get to sit in your chair, get fat eating fried chips, and consume content! Good consumer droid!
- josteink 13y agoFirst Netflix attempts to subvert web-standards with WebDRM. And now they attempt to lock down the regular HTML as well by disabling legit inspection tools. I can't wait to see what's up next! It should be clear by now that if you care about the open web, Netflix is not a company you can trust, much less fund with your money. Cancel Netflix if you already haven't.
- shultays 13y agoThank you facebook
- blueskin_ 13y agoIt's a major WTF that Chrome even allows this. Still, I suppose it is google...
- brownbat 13y agoWhat are some things everyone's using the dev console on Netflix for?
- decad 13y agoI threw together an extension during my lunch that should work against these types console disables [0], using the method the poster suggested. [0] https://github.com/Decad/ConsoleDefender https://github.com/Decad/ConsoleDefender
- dieulot 13y ago“And interestingly, Chrome (even Canary) still allows the user to run javascript from the omnibar.” Worth noting that they remove the "javascript:" part when you paste from clipboard. My guess is that it protects against people telling others to "copy this in the address bar to steal your friends' Facebook accounts", much like why Facebook disabled the console previously.