Enterprise-level Chromium removes view-source to prevent students from cheating
theregister.com
theregister.com
Perhaps if the creators of the web service had spent more time with the view-source tool during their own schooling they would have designed a better quiz system, one that was less vulnerable to this “exploit”.
The layers of incompetence are hilarious. Incompetent web developers restrict access to a valuable resource, which will inevitably lead to more incompetent web developers.
Vs
> Woah it worked, this is so fucking cool, what else can I make the computer do?
It's probably not critical for someone who's decided to be a web developer. It's the foundation that's created every self taught hacker ever.
While yes, theses tests are broken. The problem isn't the test, the issue is breaking something useful, so that we can have something that might get better some day. No, it won't get better. More people will depend on putting answers in the html source code delivered to clients, and everything will keep being shit.
I'm perfectly happy to die on this hill. But the hill isn't "subpar solutions can never be used, everything must be perfect from commit 0" The hill I'm willing to die on is "Don't break something that's currently good, to fix something that's already horribly broken and bad." Which I' argue is a good hill to die on.
LOL. Teachers will never be able to prevent students from cheating. This will only help against a very easily accessible way of cheating that would otherwise render Google Forms Quiz useless for teachers.
They don't remove your precious feature. I would fight against this too, if they would. They just allow admins to restrict it on workstations they manage. Just having a shitty electron app in Windows kiosk mode is the alternative... which I thinks is definitely worse.
You seem to unknowingly argue against straw men!
If Google Forms Quiz embeds the test answers into the html, then is it is already worse than useless.
> They don't remove your precious feature. I would fight against this too, if they would.
I've already said this to you in another thread, but my sister is a school teacher. I do tech support for her all the time. This *is* something that *WILL* make my life harder. Now that you know it's a feature I need and use to be able to help her, will you actually argue against this with me?
> They just allow admins to restrict it on workstations they manage. Just having a shitty electron app in Windows kiosk mode is the alternative... which I thinks is definitely worse.
I think electron is worse, but if that's the only other option, then I'd rather they break the test specific electron app instead of the chromium browser that I have to use for everything. This is where I also point out that just because the feature does allow for a small list of websites to block view-source on. There's nothing preventing a stupid or lazy admin who sets it up from blocking it on every computer the school uses.
> You seem to unknowingly argue against straw men!
No, I'm not. I feel as if you're trying to insult me.. But I think it might be I'm not explaining myself well enough.
Lol, my mom was a teacher, my wife is a teacher, my sister is a teacher, my sister in law will be a teacher. For all I did tech support. Now what?
Actually I think this is a very nice simple solution. Under the circumstances that teachers like to use Google Forms and Google seems to shit on teachers with this use case, let the admin simply deactivate view source for Google Forms URLs and no problem any more. This will only affect student accounts, maybe even only student exam accounts and the problem is solved, especially in primary education.
> They don't remove your precious feature. I would fight against this too, if they would.
They are removing a feature I use.
But you didn't answer any of my other questions. And ignored my comments about how a lazy or stupid admin will just block view source on every computer and every website. You said taking tests on computers is supposed to make things faster, and more accessible. How does giving admins the ability to disable features that kids can use to learn about computers and the web make things more accessible to students who's school computer is their only computer?
IMO a stupid admin you can ask to enable view source for teacher accounts is far better than a proprietary test application that you are not even able to understand nor debug in any way.
Just activate the group policy for exam workstations only and students will not encounter this on any other school computer. Or even better provide special exam accounts.
I sincerely hope your nephew's computer is not managed by his school's admins.
Honest question here, why is this worse? Why wouldn't you want a kiosk mode for taking tests?
Blocking URLs is kind of a half-baked answer anyway, you don't really want people to have access to most browser features for the embedded page, including dev tools, including the URL bar, you don't want them to be able to Ctrl-S the page, you don't want them to be able to access bookmarklets that can reveal source, etc, etc. If you're using Google Forms to give tests, there are probably other issues there beyond whether or not kids can look at the source code, and the reality is you probably do not want to actually use a full-featured browser to give that test.
So there's very little downside I can see to having a single-purpose Electron app that's installed on school computers. I mean, hopefully you're not using kids own computers for this anyway if you care about security, because you have no way to verify that they haven't messed with the browser or bypassed your restriction then. So if they're school machines, because this is a policy for work machines that are managed... yeah, of course you should install a testing app, and of course you should put machines into a kiosk mode. Why wouldn't you?
I would think "put school-owned machines into kiosk mode" would be the first step to take as an admin if someone is trying to administer secure tests on those machines.
An app has to be developed and this development costs money and somebody has to pay this money.
Doesn't Chrome already have a kiosk mode built into it?
> but still want to preserve some browser functionality. E.g. allow access to more exam material not embedded into the quiz or an Encyclopedia for research during exams.
Open Internet access seems like a really bad way to provide that. There are maybe 5 different ways I can think of off the top of my head that are quick to do that circumvent a view-source restriction if the rest of the browser is enabled.
Sure, an enterprise admin might know to disable (some of) those methods, but if they're smart enough to do that, aren't they also smart enough to set up a kiosk display? Kiosk apps aren't some kind of new technology, these get used all over the place.
I'm curious about the intersection between teachers/admins who are not well-equipped enough to avoid using anything other than Google Forms to deliver tests, but that are well equipped enough to build a network policy that blocks students from just sending each other test answers during the test.
I don't know, I don't want to be cynical here, but this kind of thing is literally the job of a network admin, isn't it? It's why you hire them, to set up stuff like this.
I would question whether a computerized test with these problems is actually better than a paper test. But more than that, I would question whether people have an obligation to make other products worse just to accommodate bad coding.
I don't think anyone is demanding perfection by (correctly) pointing out that not designing a product to deliberately leak secure information is kind of the bare minimum bar in a secure testing environment.
Are paper tests a bad thing? Why do intelligent state voting systems depend on paper, or backups? Why do ultra high security computer systems still log to paper?
Please note that this feature is part of managed Chrome which can be restricted in many other ways. The exam workstation itself of course too.
Then what is the kid? And who is *using* the computer to take the test? And who is *using* the browser? And who is *using* Chromium that would like to learn something about the source, that now has view-source disabled? Are they not users, just because someone else wrote the test?
> Man, do they really have to deploy iPads in kiosk mode for shitty tests so you don't shit on them? Teachers do their best to optimize and digitize teaching under the worst circumstances. If this litte bugfix helps them I am happy.
I'm happy to help teachers too, but this helps them by hurting others. That's *not* ok!
> Please note that this feature is part of managed Chrome which can be restricted in many other ways. The exam workstation itself of course too.
Sure, but that's still wrong. Just because bad thing is bad, or closer to how you put it, there's other things you can't do with this software. Doesn't mean that adding more restrictions is a good thing.
So server side security is in this case better because it's a more clean solution? In this case the cleanliness of the solution is irrelevant as long as it works. Students can always sneak in attach a keylogger to the teacher's keyboard and read out the password for accessing all tests. It's about erecting a barrier that is good enough.
Yes, absolutely. There's nothing a client can do if the server doesn't send it the answers.
> In this case the cleanliness of the solution is irrelevant as long as it works.
*NO!!* How good a solution is always matters! Another solution to students cheating is for an older student to stand over them as the take the test, and beat them with a stick if they try to view the source of the test. That' would be a solution to this problem, but it's so obviously bad. But hey, it'd work. It'd actually work better than this because it would work on every test, on every site, in every browser, for every computer... Because how clean a solution is doesn't matter, who cares if there's a little blood on the screen?
> Students can always sneak in attach a keylogger to the teacher's keyboard and read out the password for accessing all tests. It's about erecting a barrier that is good enough.
If a student is able to sneak a keylogger onto the computer of a teacher without getting caught, they're smart enough that the test is pointless to them.
> If a student is able to sneak a keylogger onto the computer of a teacher without getting caught, they're smart enough that the test is pointless to them.
Attaching keyloggers is stupidly simple. Security is always a trade off. This was my actual point. In case of keyloggers it's more a matter of lacking risk awareness since it would probably bring criminal charges.
The kid is an excuse for a "teacher" and "assistants" to get paid and get benefits and for Google to start collecting data on them from a very young age.
And besides, if everyone knew for that second test then that's a lot of seeds right there alone.
I don't see a point where making this kind of stuff secure in another more targeted way (e.g. central exam server) is helping in any way.
You can still held hacker competitions in computer science classes anyway (hopefully mandatory for all).
What "computer" class is these days is "MS Office" class. Except actually it's "MS Word and Excel class, except the teacher only ever calls it "the typing thing".
And even if there were sanctioned hacker competitions, they would become classwork and therefore boring. The fact that it is against the rules is part of the draw.
For what it's worth, I think there's something to be said for leaving a situation like this inherently insecure. Yes it's manipulative, but somebody learning something from their own drive is a lot better than standardized testing beating it into the infodump section of the brain.
Your "inspirations" sound quite enjoyable! You were definitely much more skilled than me or anyone I knew.
I just see the intentionally insecure quiz working in the current setting, and there being no way to implement the wargames in an effective way in this setting.
One man's exploit is another mans feature. But more directly, no I'm not saying either of those things. I'm saying that user hostile design, like preventing the user from being able to do something they otherwise could is what causes people to hate computers. In this case, it's better to fix the problem [someone including answers within the test they're sending to the client] instead of breaking a feature so that someone can keep doing something stupid.
This is beyond ridiculous and seriously diminishes my overall faith in humanity.
https://www.techdirt.com/articles/20211021/23033847793/misso...
I was involved in a lot of crappy testing software people wanted to sell our university. That was the first criterion I insisted on these publishers satisfied.
By the mid-aughts, everyone seemed to have understood it. ... WTF happened that now we are talking about disabling view-source in browsers as a security measure?!
I wasn't even aware that was a thing (even though I've had to use Chrome in many enterprise settings). Is this just the `npm install` automatons not understanding the distinction between the client and server in client/server applications?
Idiocracy is here.
This is only acceptable is the purpose is to provide practice questions that do not count for credit. Just like it is a good idea to provide answers to practice questions at the end of the book (sometimes printed upside down).
Of course, to be useful as a learning tool, the answers to such practice question must include an explanation of why, say, (c) is a better answer than (a), (b), and (d).
So, set up practice questions in Google forms, put actual answers/explanations on a web page for students to learn.
You can still do exams in Google forms ... Just don't leave the grading to Google forms. Instead, grade asynchronously.
Again, that would be actual work, so, no leave everything to Google, and accuse students of cheating and take away `view-source`. Right. That's what things have come to.
Unacceptable capitulation to poor educational quality.
See https://support.google.com/docs/thread/39605334/google-forms... to verify.
Meanwhile, the code complexity and unintuitive behavior (who would ever expect 'view-source' to have a blacklist or be controllable by the web page?!) will get externalized onto all Chrome users forevermore.
This is about enterprise policy in a managed environment. It was already able to block a URL - like https://google.com - but not view-source:https://google.com.
Blocking devtools was already possible.
javascript:let $code=document.createElement('textarea');let source=document.body.outerHTML;$code.innerHTML = source;document.body.appendChild($code);
For those who don't feel like reading a js oneliner, it reads the page source and adds an element to the page that displays all of it. javascript:alert('hello world');
Do note that some browsers remove the `javascript:` part when you paste it into the url bar because it could easily be used maliciously so you might have to type that yourself.You've patched one hole. How many more are possible? We know where this game goes...
i would expect that when a browser displays source code at a url that looks like view-source://the-url-of-the-page, and gives me a pattern-matching blacklist feature, then blocking view-source://* would block urls matching that pattern. having a blacklist feature that selectively doesn't work on certain types of URLs seems like a bug to me.
removing a special-case exclusion is hardly unintuitive behaviour, unless you're using the definition of "unintuitive" that means "something i don't like"
Great move /s
Google Forms
Chromium: Permit blocking of view-source: with URLBlocklist - https://news.ycombinator.com/item?id=29170886 - Nov 2021 (126 comments)
View-Source in Chromium - https://news.ycombinator.com/item?id=29193561 - Nov 2021 (1 comment)
I honestly don't get why so many commentators are upset. They are using Google Forms for tests. And these tests leak answers through the source code. Schools are not well funded and this setup itself is not very professional. When you can fix this by giving admins such possibilities, why not?
It's not like your Chrome will prevent you from viewing any sources. As you can also read in the article the restriction can be limited to certain URLs. IT ONLY AFFECTS MANAGED ENVIRONMENTS WHERE ADMINS CAN DO MUCH MORE RESTRICITNG THINGS ANYWAY.
However, there are legit environments where people might want to prevent users from accessing devtools and view-source functionality, like when using it as a kiosk software.
From security standpoint, it might be also reasonable to disable at least devtools in enterprise environments, since users can not necessarily be trusted with such access (which is the reason why many sites, such as Facebook, display warning to not enter anything in the console, especially if someone instructed them or they found it online).
> Microsoft engineer fixes enterprise-level Chromium bug students could exploit to cheat in online tests
> Ability to block 'view source' for specific URLs hasn't actually worked for years
The post title is a decent summary.
[0] I hate throwing out this word, as it's always used wrong - including my usage here - and tends to carry a lot of other connotations with it which I don't want to affiliate myself with. Is there a better word to use here?