Fake ad blockers in Chrome Web Store
palant.de
palant.de
This was one of the interesting use cases I thought about when I dug into crypto.
As evinced by the article, the web store isn't perfectly trustworthy but this kind of validation could be done automatically and I do trust their ability to automate.
but that's just a roundabout way of doing reproducible builds.
... sorry had to post this. Quite tired of Blockchain.
Why would you need a blockchain for this?
Evil insiders.There are two threat models:
1. Evil Foreign Spy infiltrates the Tor project and makes a backdoored, signed release.
Evil Foreign Government uses MITM or something similar to serve this backdoored version to one or two journalists they know aren't technical enough to inspect the source code themselves.
The journalists think "This will be safe, as it will have been code reviewed by people who know how to do that" but no such people ever saw the backdoored version.
Hence, you don't just need a signed build - you also need a globally-agreed list of builds, so the user (and the auto-update mechanism) can be sure everyone else in the world knows this release exists. If a build is ever repudiated, sound the alarm!
2. Evil Foreign Spy infiltrates the Tor project, and intentionally triggers the alarm in a way that doesn't lead back to them.
The alarm going off and the fact the infiltrator hasn't been found means people don't trust Tor, or they start ignoring the alarm rendering it useless.
Hence, you don't just need a globally-agreed list of builds - you need an indestructible, globally-agreed copy of each build's source code and who changed each line.
Now granted, a blockchain isn't the only way to achieve these things - indeed, it'd cost a fortune to put the entire Tor source code into the Bitcoin blockchain - but you need some similar mechanism.
Having one homogeneous decentralized way to read this data is neat. You could make entire package managing solution out of this. Even attach torrent magnet links for each lib in the chain, and make the whole store distributed.
It would be a fair point to say that if you don't trust any specific person or entity to verify that a given source compiles to the binary signed by the author that maybe some sort of blockchain would be useful. I think you'd get a lot more bang for your buck by using trusted authorities in something closer to a CA model.
And you do need trust for distributing software.
You can't use git, it's hard to sync automatically. Torrent is a nice transport, not a db, and can be use to sync blockchains anyway, why make them exlusive ? And using any distributed db would exclude the field tested solution on millions of wallet that prove to work, and the api that is alreay well supported.
My own strategy is just to limit the number of extensions I use to a small number of ones from established/trusted entities, but it pains me because I publish a couple extensions and I am not an established entity.
Everyone takes it for granted that the github link on an npmjs.com project page describes the code you get when you `npm install`.
Both npmjs.com and the Chrome app store should have an in-line file browser to make it as easy to vet the code as possible.
I have a browser plugin[0] that lets you view a Chrome plugin's source code, but I've also noticed how many of them obfuscate their code. For example, the Super Netflix plugin is heavily obfuscated: https://chrome.google.com/webstore/detail/super-netflix/aioe...
I can certainly imagine why. It would take me a non-trivial amount of time to figure out how to interact with Netflix's client/server. I gave up when I couldn't even figure out how to programmatically pause/unpause the client. And that's now the plugin's secret sauce, especially in a hostile app store where everyone is chomping at the bit to clone your plugin.
I don't know of any easy solutions here.
Even large scale manual review like Apple's approach has issues with clones.
[0]: https://chrome.google.com/webstore/detail/chrome-extension-s...
Eclipse and PyPy has a problem with it too[0][1].
Apple with their walled garden also isn't a panacea. They let a very glitchy and broken version of cuphead onto the app store (so much for manual review and flawless experience) and there apparently is a known repeated offender whose MO is to port popular indie desktop games (maybe because it's Unity3D games it's easy?) to iOS hastily and sell them[2]. They also only last year banned the fake anti-viruses (the "speed your phone up by clicking this red button in this free app and paying us $10 to remove 1337 north korean backdoors, viruses and unneeded programs!1" clickbait kind, the one that targets low tech people).
I also wonder how far you could maybe get with some really great game in a native executable for Windows on itchio or Game Jolt (or maybe even on Steam, they are really bad with catching broken, bad, etc. games and have a very hands off approach to everything on there) that was also packed with covert viruses/trojans, people download and run those very willy nilly on their computers, don't keep themselves up to date (thanks to Microsoft making updates obnoxious and doing crap like installing Candy Crush 325254th time, I know I removed one from my laptop like twice or thrice now) and I wonder if there is any security scanning on those sites to try detect viruses in uploaded files (I wanted to try with EICAR but it kept getting nuked by Windows Defender and I don't have the patience to try make it leave my EICAR file alone).
[0] - https://eclipse.org/org/press-release/20170814_security_bull...
[1] - https://news.ycombinator.com/item?id=15256121
[2] - https://www.polygon.com/2017/12/18/16790052/cuphead-fake-ios...
[3] - https://www.theverge.com/2017/9/15/16314034/apple-developer-...
I also meant Chrome extensions of course, not plugins, but plugins are so rare (except the default Flash) and sidelined (even chrome://plguins no longer works) that I call extensions plugins very often.
A diff with an X or a check mark if it's overall different in any way would be awesome too.
Unfortunately, in reality you quickly run into problems with different compiler versions, optimisation settings and other issues that make builds unreplicable. At least with chrome extensions you can look at the JS source. With ethereum, all you have to go on is the compiled bytecode.
The worst of the spyware / download guys are now the best of the "legit" extension affiliates.
I don't get why googles verification team is asleep at the wheel on this, I feel the exact same way about amazon and their counterfeiters abusing the shit out of fake reviews and buy counts.
This thing clicks ads for you so that parasites can't use data for anything meaningful. Check it out!
It could really be 'malware' of course, but my money's on the other possibility.
I wish there at least seemed to be some degree of review or reasonable sandboxing here. The closest they come is disabling eval-style behavior in 'background' scripts, but there's nothing stopping you from running command & control scripts from a remote origin in a non-privileged context and then getting up to your evil mischief anyway. Or injecting malicious code directly into gmail tabs.
Then just completely ignore said guidelines while not doing anything close to a review. Seriously, do none of these rules can checked at all?
https://developer.chrome.com/webstore/program_policies?csw=1...
It's no better on the iOS store, Play Store, Steam, Windows Marketplace or anything else of a similar kind. Poor quality, scam apps and programs seem to waltz right through 'quality control' like it's non existent.
Honestly, at this point the best 'walled garden' marketplace would probably be the fan game and mod equivalents. At least on the likes of MFGG and SMW Central you have human moderators physically test every single submission , then give detailed feedback on every single aspect of said submission (down to actual game design and mechanical implementations). Plus a perma ban system for anyone continually trying to submit crap.
Makes me wonder what the Chrome Store or the Play Store or Steam would be like if they did that. Probably better, and with less questionable extensions like this in it.
You clearly don't remember when Valve Corporation required contractual agreements outside of the Steam Store to get sold on Steam. Greenlight, and its incarnations are all public options for selling on the digital distribution store.
Most games sold then were by bonafide studios who had to reach out to Valve's sales contacts, and not children operating out of their parent's bedrooms making mods or "games" on Unity.
At some point the people behind sneaking ads or tracking into extensions are going to pivot into higher-value scams, like harvesting account credentials or important data.
As Chrome is constructed now, there's almost nothing stopping any extension with the 'Read and change all your data on the websites you visit' permission from stealing literally any piece of data that moves through your browser if the person in control of it is determined enough. With the push towards running all your apps in the browser for "sandboxing", the risk this poses keeps going up. Companies use Slack, Gmail, etc to collaborate and all of those things are built to run in a browser tab (even if they have native apps) - and basically any extension a user installs has the potential to silently exfiltrate sensitive information, disguised as regular user traffic. Worse still, if the user signs into their Google account, the malicious extension can be synced to other machines. "Don't install stuff on your work PC" is pretty easy to understand, but "don't sign in to Google" is a bit harder of a policy to enforce, especially with the fuzzy boundary between Google-the-platform, Google-the-website, and Google-the-browser, all of which use the same login flow.
Native and mobile app development spaces have solutions for most of these issues already via sandboxes and permissions (though there remains work to be done), and these threats are non-existent when dealing with regular websites and web apps. Extensions need a lot more scrutiny due to just how much of a threat they pose.
Sandboxing cannot be relied upon a primary security feature; at best it's only an additional roadblock that provides defense in depth. Isolating potentially malicious code in a sandbox is useless if you also run the the rest of your software in that same sandbox.
The browser sandbox was useful for isolating transient Javascript the current page/window. Your primary apps and always-running utilities were protected because they were outside the sandbox.
The problem here isn't the shared sandbox, though, but that an adblocker needs access to every site to block their ads.
A top rated chrome extension was inserting porn Ads in Youtube's companion renderer element. Google removed it after I tweeted about it though.
If you get hit with a DMCA claim (fraudulent or otherwise) that'll put a manual review flag on your account for a while. You can tell because pushing an update or new extension takes over a day vs the standard ~20-60 minutes. The manual review can and will just reject you for no reason without much explanation, but it seems to be easy to just bypass the review.
Good thing I like ads.
https://www.linux-noob.com/forums/uploads/post-12-1098049148...
Oh wait. I guess forcing everyone to use HTTPS and signing everywhere means HTTPS and signing can no longer be used to distinguish serious actors from even plain malware-vendors.
Thanks Google.