Code Verify: An open source browser extension for verifying code authenticity
engineering.fb.com
engineering.fb.com
I refuse to believe that rouge browser extensions and userscripts are such a big problem that Meta decides to invest in security against those attack vectors.
But if anyone else mentioned this tech, I would assume it was benign. Subresource Integrity (https://developer.mozilla.org/en-US/docs/Web/Security/Subres...) is primarily aimed at servers proving to clients that their code is unaltered, not the other way around. I haven't personally tried it before, but I can't imagine why extensions wouldn't be able to override integrity strings or remove them from script elements.
For WhatsApp I'm not sure I see the point necessarily, but it's an understandable goal for Open Source and offline webapps or for apps that use 3rd-party CDNs. The main problem for personally hosted code is that the integrity string is also getting served from the server, so there's no reason it can't also be altered if the server that gives the HTML is compromised.
In theory with some tweaking and a way to pin integrity strings in a user-controlled way (which an extension could do I suppose) it could be a step towards allowing users to know when a PWA is being updated, which would be helpful for some security models. In its current state it's fairly niche and I'm not sure how useful the standard is outside of securing CDN requests.
Although why that would matter to WhatsApp, :shrug: It does feel weird that Facebook would be leading that push.
Here's what ChatGPT says:
Most ad blocker browser extensions primarily work by intercepting and blocking network requests made by web pages to known advertising servers or domains. When a web page loads, it typically requests various resources such as images, scripts, and stylesheets from different servers. Ad blockers analyze these requests and compare them against a list of known ad servers or patterns commonly associated with advertising content. If a match is found, the ad blocker prevents the resource from loading, effectively blocking the ad from appearing on the page.
Some ad blockers also employ additional techniques such as element hiding, where they modify the Document Object Model (DOM) of the webpage to hide elements that are recognized as ads. This can include hiding divs, iframes, or other HTML elements that contain advertising content.
Overall, while there are variations in implementation, most ad blockers primarily rely on blocking network requests to known ad servers or domains, with some employing additional techniques to hide or remove ad content from web pages.
https://github.com/facebookincubator/meta-code-verify is the goods, and is MIT
https://github.com/facebookincubator/meta-code-verify#instal... says Safari support is "coming soon" (from 2022) so I guess they think those users don't need to "verify[..] the integrity of a web page."
I haven't ripped apart the extension yet, but there is no mention of cryptographically verifying the response from Cloudflare.
Edit: looks like they are checking for a number of ad blocking extensions and mark it as "At Risk" if detected.
Edit 2: Oh boy, I hope this is covered by their bug bounty program.
Not surprised at all. As with a lot of things these days, the "security" they are talking about is to secure their ability to shove whatever shit they want down your throat without you being able to resist.
They are 100% using "open source" as a distraction here. The fact that you can see the source is irrelevant for the purpose they are trying to use this for.
For the second use case, isn't that what digital signatures are for?
That adversary could be a government trying to compel the web application developer to serve a compromised version to a particular user or group of users.
At least, this is a threat model that I talked about with people who were working on similar tools a few years ago.
Edit: for example, you could imagine a messenger application that has end-to-end encryption with a web version of the client. With traditional web applications, the developer could trivially substitute a backdoored version at any time in the future, and users couldn't plausibly detect that.
> With Code Verify, you can confirm that your Instagram Web code hasn’t been tampered with or altered, and that your Instagram Web experience is the same as everyone else’s.
If a website is compromised, no extension will fix this.
Only a rollback to a specific known-to-be-legit hash in IPFS.
And meta won't embrace IPFS, ever.
Also, do you really think meta's products will have static assets for eternity from the point of installing an extension? Absurdly unlikely.