Malware in open-source web extensions
lwn.net
lwn.net
It's a bit ironic that this security issue doesn't exist in Firefox [1] when they actually implement features promoted by Google in the Manifest V3. Why doesn't Chrome already block remote scripts?
[1] https://blog.mozilla.org/addons/2019/12/12/test-the-new-csp-...
Capability, sure.
But more often than not, it is Electron-based applications which are happy to include remote scripts... Because that's often as easy or easier than vendoring your dependencies and bundling them.
In practice, Electron apps probably poses a bigger security risk, at least for that threat-vector.
I think all 3 have been patched to prevent that particular attack, but it's astonishing to me that electron apps don't seem to use any form of code signing.
my HackerOne reports were all Out Of Scope, naturally, until parts of the attack got assigned CVEs later and someone else got the bug bounty :) At least it's fixed!
They did eventually try to shut the barn door after the horse bolted by changing the wildcard permissions system to have manual domain filtering but I never saw them actually shut it off by default (doing so would break existing extensions). Maybe they will in Manifest v3 since they're perfectly happy breaking ad blockers.
https://github.com/andreicristianpetcu/google_translate_this
eval() is one of those things.
I like gardening my small personal home server, services and backups but there is no reason debian packages could not be subject to the same supply chain "evil maid" or upstream "evil new maintainer". Everything being done in the open and reviewed makes it less probable, but not impossible. Sigh.
As a company, "risk" is mostly insurance. As an individual, it’s anxiety.
Aren’t they very easy to exploit, for a mildly dedicated actor? I don’t see any decent solution to this. Any line could contain a wget | bash...
Or you can not, and work to control your supply chain. Host the artifacts yourself and choose carefully which ones you use.
There is no magic bullet, just boring and painful risk-control processes. But they do help.
Wayland, SELinux, Flatpak, PipeWire. These will save us or at least reduce the problem of evil maintainers.
This model has been tried and proven for over a decade on mobile. What we call malware on mobile is simply the app doing bad things with what you enter in to the app itself and not the desktop class "steals all your data and then encrypts it"
If the sandbox is configured by the same person or organization that writes the code there's no improvement in trust.
That's why package maintainers have a role in Linux distributions.
Maintainers do not have the time or ability to check for even intentional malware let alone security bugs.
There is no way around having to trust somebody else.
Debian does very extensive vetting of the contents of packages - and of the volunteers who get to become Debian Developers.
I'm always suspicious of the number of blogspam generic linux help advice sites that get you to install some random ppa complete with a nifty little code snippet that automatically installs certs and updates your sources.list! How handy!
I love using sites like that for my personal computer/projects, but I never copy and paste code snippets or install PPAs on work machines or computers with magic internet money on them
https://www.idontplaydarts.com/2016/04/detecting-curl-pipe-b...
You can make it so that the server returns benevolent looking code when auditing it with just "curl URL", but return malware when curl is directly piped to bash.
What this means is that the package maintainer is unable to alter the binary/package outside of the publicly available sources.
In the case of the web extension, the maintainer could build whatever software they wanted, not necessarily the source you see on github or elsewhere. A reproducible build system would prevent this type of attack (that I'm talking about here).
"Of course, as the vast majority of the users of The Great Suspender were not interested in its open-source nature, few of them noticed until October, when the new maintainer made a perfectly ordinary release on the Chrome Web Store. Well, perfectly ordinary except for the minor details that the release did not match the contents of the Git repository, was not tagged on GitHub, and lacked a changelog."
> Raymond Hill, after (you guessed it) he transferred ownership of uBlock to a new, untrustworthy maintainer
Only the GitHub repo was transferred, I never transferred the extension in the Chrome Store, and Opera Store.[1]
The Firefox version was published by a contributor, and he chose to stay with the new maintainer, and as a result I created a new publication for uBlock Origin in Firefox store.
All this was nearly 6 years ago.
> Aljoudi began reducing blocking features, eventually choosing to permit certain ads via the "acceptable ads" program
"Acceptable Ads" was added to "uBlock" in February 2019 by the new owner, BetaFish Inc. (maker of AdBlock).[2]
BetaFish Inc. was itself sold circa October 2015 to an (still) anonymous buyer.[3]
> Hill created a fork, now called uBlock Origin, which reverted the changes
I didn't revert any change, I forked while I was still controlling the GitHub repo.[4] If you look at the project timeline, it shows that I have been in charge since the first commit in June 2014.[5]
> Nano Defender and its 200,000+ users, upon their recent acquisition, immediately began having their personal data mined.
Note that the malware did not require the blocking ability of the webRequest API to collect the data, it needed only the observational ability, which is not deprecated by Manifest v3.[6]
**
[1] https://github.com/gorhill/uBlock/issues/57
[2] https://github.com/uBlock-LLC/uBlock/releases/tag/0.9.5.13
[3] https://news.ycombinator.com/item?id=10318200
[4] This was the first release following the split, nothing had to be reverted: https://github.com/gorhill/uBlock/releases/tag/0.9.3.0
[5] https://github.com/gorhill/uBlock/graphs/contributors
[6] https://github.com/NanoAdblocker/NanoCore/issues/362#issueco...
No other software that has contributed so much to my overall happiness, productivity and well-being.
I just double checked the repo but couldn’t find a way to support your work. Is there any way I can donate or send something your way?
I wasn't aware that you hadn't transferred the rights to the Web Store. I suppose the article wasn't clear enough on the timeline for the uBlock Origin swap: it was included because it was another case of maintainership change gone wrong, and it was closely related to the Nano Defender situation that was virtually identical to The Great Suspender.
I was aware that acceptable ads were added much later than the change in ownership: however, I thought the removal of per-site switches would be less relevant to the modern situation. On review, it does seem to imply that the impetus for the fork is that change: my apologies.
I trust that you didn't revert any changes, but Git doesn't necessarily preserve that information properly. Some git commands ('git reset --hard') remove any changes from history, as well as not creating a log of such changes. Much of what I could find around the change seemed to imply that you had reverted them, as opposed to simply never getting them: the difference is mostly academic, in my opinion.
Thanks for putting that clarification here: it wouldn't have fit well in the article, but it is worth mentioning. Manifest V3's new restriction on remote code is the main relevant security addition, and I am not a fan of how they bundle that in with the other changes. That restriction would make it a lot harder for these sorts of changes to fly under the radar. Nano Defender's malicious changes were quickly discovered: The Great Suspender flew under the radar for months..
No worry. I forked the repo at the same time I transferred ownership. The reason was simply that I wanted to get back at being able to mostly work on the code base, as the issue tracker had become a burden taking most of the time I allocated to the project, and I found that @chrisaljoudi was good at handling opened issues.
I wanted to ask whether you tried to go against the uBlock maintainer through legal actions?
DMCA takedown comes to mind as well as registering the uBlock trademark and force him to change the name...or revoking rights to him specifically for new updates/changes of the codebase.
uBlock meanwhile is just as scammy as AdBlock and AdBlock Plus, which both are owned by eyeo GmbH (and their acceptable ads program which they abuse to force websites to enter their program, while getting 30% of ad revenue for the "allowance").
And I would hate to see uBlock pulling uB0 through the mud with its name.
The international patents and trademarks database doesn't confirm this, because the trademark application of Betafish was cancelled.
The only thing that's actually registered is the uBlock "graphical trademark" (don't know the US term for it) so it's not the word itself that's registered, but only the combination of word and picture with its exact form that's protected.
This graphical trademark #017822487 is registered by uBlock, LLC, 30309, Atlanta, US and it was registered on 19.02.2018 - almost 4 years later.
So, technically, @gorhill could still register the term "uBlock" as a trademark and probably win a case against uBlock, LLC because their trademark is bound with its graphical representation and not the word itself.
(Also, I am not a lawyer - because I heard people assume this all the time on the internet for whatever reason.)
This reminds me of why GitHub should create it’s own App Store (yup, I’m gonna beat this drum):
I can navigate the source ask questions about parts that make me suspicious, and then install a prebuilt binary with confidence that the binary was the sum of what I reviewed.
this is fundamentally impossible to do because you can smuggle data out by injecting content scripts to a given page and make requests in that context.
With money on the line, you have to be either unaware of the risks or lack conscience.
Wow, this is clearly the fault of the maintainer. Too much power in one hands. He literally had the lives of so many people at stake and he sold them out for whatever it was worth. I feel that although there's another angle of maintainers getting paid for their work, this is totally not in line with ethics of how open source should be done.
I should note that the manifest can specify an 'update url' that would enable auto-updating behavior: and it does, in fact, appear that this extension does. If you remove that line from the manifest, that behavior will cease.
Kinda off-topic: with enough eyes all bugs are shallow, but does that really help when Google prefers playing whack-a-mole to doing the right thing?
A man can dream, I guess.
Alert people that they should rotate their passwords?
The last one is so crucial. Had I not read that LWN post, I would never have noticed that the extension didn't just run adware fraud but also snooped passwords. Seriously, fuck Google and their disgusting zero communication attitude.
It can't be fixed without crippling the system. You can't sandbox permissions because the most basic and useful tools require full access to every website.
The only way I can think of is having all extension developers required to have their identity verified and from a country that follows some common law so that google can take legal action against malware developers.
I shouldn't be forced to run someone else's code to look at a publication. That's the entire point behind using something as ugly as XML (or it's simplified child, HTML) to begin with: this is supposed to be a document markup language. A method of annotating what an author would _like_ to have happen when rendering the data.
I seriously loath the fetish of creating pixel perfect displays which treat the end user as an actively hostile element; a passive consumer, rather than someone empowered to use the data for their own enlightenment in the manor their preferences prefer. (Font size, screen reader, dark / light mode, etc)
It's not really the same issue.
If you are visiting a site that uses its own JavaScript, you can probably assume that if it's run by someone trustworthy, the script isn't going to try stealing your passwords or credit card number. There shouldn't be any reason for the web page to have access to anything that you're not providing it with anyway.
A browser extension (like an ad blocker) can access the content on every page you visit. That could be your bank, email account, social media - anything. If you have a malicious browser extension, it can see everything you do.
Gentoo has a nice system, "Gentoo Linux Security Advisories", where you can periodically run a program called glsa-check which lets you know if you have packages installed that have security problems, what the problems are, and points to more info (like CVEs). You can even have it upgrade stuff on its own if you don't want to think about it. Something like this would be a nice feature for browser extensions.