Why Do Chrome Extensions Need to Access All My Data?
lifehacker.com
lifehacker.com
1. I'm really surprised legit vendors like LastPass don't become verified authors on the Chrome webstore; it's trivial to setup. We were able to do this for Meldium easily.
2. Joe's comments that it's hard to write an extension that steals data does not seem very true. Someone who is dedicated can do a lot with Javascript.
3. The author doesn't mention the model Mozilla follows with its addons: actual humans code review extensions to determine trustworthiness. They reject extensions containing obfuscated code for example.
http://developer.chrome.com/beta/extensions/activeTab.html
> The activeTab permission gives an extension temporary access to the currently active tab when the user invokes the extension - for example by clicking its browser action. Access to the tab lasts until the tab is navigated or closed.
> The main benefit of the activeTab permission is that it displays no warning message during installation.
Doesn't the very same problem exist with Firefox extensions / add-ons? After a quick online search, it seems that this problem is far from being a Chrome thing... [1] http://www.computerworld.com/s/article/9152578/Mozilla_confi... [2] http://www.networkworld.com/columnists/2009/020309antonopoul...
They ask for permissions that are very hard to figure out as a user.
When the user is faced with two options:
1. Click Ok and get started with this app that looks cool.
2. Click No, and go back to the previous screen without the app.
The choice becomes pretty obvious.
My wife simply ignores it and clicks ok. I'm sure most users do the same after the first or second app they install and from then on it becomes a reflex response. Install. Ok. Ok.
I mean, their is obviously no other solution. We should just quit complaining about it.
Or go the route of free without ads and hope that the goodwill leads to recognition and donations.
Deleted comment
If I'm running AdBlock it needs to be able to modify the HTML of any page and occasionally update its lists using the Internet. But AdBlock Extra Evil Edition might also be paid by someone to not block their ads or to leave beacons in place.
A form filling application could potentially push evil information into a form and submit it before I could do anything. Or it may work the way I expect and only fill in data that I want to be filled. How do you allow the good stuff without also allowing the bad stuff?
At the same time, all of them have no issue at all to install a regular Windows application from, say, Download.com. They are surprised when I tell them that any Windows application can not only access all their data but could also format their hard drive...
To cut a long story short: Google does a good job of educating users. Microsoft should follow (and innovate with a more fine grained security system).
Deleted comment
There's no need to patch binaries -- you can hook just about everything you want. Whether you want to intercept networking, file IO, or just about anything else, it's trivial with tools like Easyhook. A binary running under your account has complete control of everything happening under your account, in essence, and exercising that control is never hard.
Does not compute. I don't see the logic in this statement.
If you just need to know when a tab is visible for your content scripts to do things, use the Page Visibility API[1].
If you want your Extensions background scripts to notify all content scripts of something, you can rely on `chrome.storage.onChanged` event. The storage API does not warn users about permissions[2]
If anyone's interested in code samples, I could through some snippets in a gist.
[1] http://www.w3.org/TR/2011/WD-page-visibility-20110602/#sec-p... [2] http://developer.chrome.com/extensions/permission_warnings.h...
Instead of requiring all web access just so an app can perform an action on any page (when you decide for it to) - what if a specific user action could grant temporary/permanent access to a domain? E.g. Clicking an icon if the app is in the toolbar, or selecting a certain action from a menu.
Chrome has a way to prompt for temporary permissions - but this brings up an alert box, and that is never ideal, it would be nice if the user interaction could be taken for permission.
edit: apparently its in beta (https://news.ycombinator.com/item?id=5383011)
Soft permissions would be where an app can function without permission, but has feature(s) that require it. For example, if I install a game, I should be able to play it without giving it internet access. However, if they want to have a online high-score system they must require that I give them internet access in order to install the app;
Pseudo permissions would be where the app thinks it has permission to use something, but it is really receiving bogus data. For example, say an app 'requires' access to my phones GPS system (when such access is not critical to the function of the app), it would appear to the app that it has access, but the data it receives would not corralate to the actually data.
I think I recall seeing a project to implement both of these features in Android, but I do not recall what it is called.
At the least, it would let everyone know that their extension's activities are being watched. And laymen knowing that extension authors know that this activity is watched would be reassuring to the laymen.
Could such logging be done by a separate extension?
It also installs (silently, without permission, and for reasons unspecified) a Firefox plug-in, and it reinstalls/reactivates that plug-in even if the user has explicitly chosen to disable it.
It amazes me that Google seem to get such a free ride with Chrome. A lot of the things it does are either indistinguishable from a lot of the things that malware does or leaving itself wide open to compromise if malware gets onto a system by some other mechanism.
> [Chrome] also installs (silently, without permission,
> and for reasons unspecified) a Firefox plug-in, and it
> reinstalls/reactivates that plug-in even if the user has
> explicitly chosen to disable it.
Could you elaborate more on this? Most of my machines have both Chrome and Firefox installed, but I don't see any unexpected or Chrome-related plugins in Firefox. A web search for [chrome installs firefox plugin] also turns up no relevant hits.[Edit] Here's a link describing the plug-in: http://superuser.com/questions/156913/what-is-the-google-upd...
Of course it does: it means any malware that manages to get onto the machine running as a non-administrator can arbitrarily compromise Chrome.
If Chrome were installed properly as an application under Program Files, the Windows UAC mechanism would intercept attempts to modify it by unprivileged code.
Installing a general executable platform like Chrome under the users directory effectively creates a privilege escalation vulnerability.
No. The malware would need to be run under an account with write access to Chrome. Because Chrome is in a user directory, the only accounts that should have write access to it are administrator, and that same user. If malware is running as the normal user account, then it can compromise the Chrome executable, and be able to run on that same user account when Chrome gets re-run. However, this at best allows malware to turn a 1 time compromise into a persistent compromise, and even then it is an ability that the malware has anyway. Assuming that Windows has no mechanism for a user to execute arbitrary code at login (which I doubt), the malware can always replace one of the shortcuts on the desktop with a shortcut to a malicious executable, that then loads the original executable, and maintains the same icon. Granted it is harder to detect a compromised executable, but if you do not know to look, how often to you check shortcuts/login programs?
The malware cannot use this for privledge escalation because the only user who should ever run the Chrome executable is the user in whom's directory the executable is installed. And this is also the only non-administrator who could have compromised it in the first place.
Installing to a user directory does however prevent another type of privledge escalation, because you do not ever need the give the executable (or installer) administrative access.
EDIT: I completely re-wrote this while Silhouette wrote a responce.
Exactly.
There's an old notion in computer security that as long as you can stop someone getting root, you're doing fairly well. In an age where data leakage, privacy invasion and phishing are probably more serious threats than causing "real damage" that can be fixed by simply (relatively speaking) reinstalling and/or restoring from back-ups, I find the emphasis on not being admin by default rather quaint. Of course it's a step in the right direction, but it's nowhere near sufficient.
Any user probably has access to their own e-mail, files, and so on. Often, that data will be far more valuable to an attacker or disclosing it will be far more costly to the victim than merely installing a virus that makes old-school letters drop down the screen or even than turning the machine into part of a botnet.
Ideally, we'd have an OS-level access control model that restricted access by application and data type, not just by user. There are practical challenges to implementing such a model without unacceptably compromising usability, but at least ensuring that only the intended applications are running is a significant step in the right direction. By avoiding that level of explicit check on changing code you're going to run, Chrome is stepping in the opposite and exactly wrong direction.
With regards to your OS-level access control, I think we have examples of how to do it without usability problems. For example, in smartphones, when apps get installed they define what permissions they need. If we assume the publisher of an app is not malicous, then their is no need for a typical user to need to know about this, and we can view it as the app saying "these are the things I am going to access, if I try to access anything else, then I have probably been compromised".
The smartphone implementation seems a bit to crude to be very effective in stopping malware, however there is no reason why we should not be able to make a more fine grained system.
For example, in the Linux world, we have apparmor, which does effectively the same, but is much more configurable. Still, this only requires the program to be honest at install time, and to not have write access to the apparmor configuration file; the user does not need to be aware of its existence.
The problem with these systems is that programs need to do things that we do not want malware to be able to do. For example, Chrome has an auto-update feature. If it gets compromised, then the malware can overwrite the executable just as easily (unless the OS enforces code signing). Say that the program wants to be able to create shortcuts on the desktop, and save data to the harddrive. Now, if it gets compromised, the malware can save itself to the harddrive, and create a shortcut on the desktop labeled "Chrome.exe".
It's not that Firefox is so much better. But Mozilla doesn't have Google's motive or ability to cross-correlate data-streams.
Google makes it extremely hard for an enterprise security team to set reasonable restrictions. Our support response from Google is usually "we don't support locking that down" or "we don't have a way to let people access feature X without also allowing feature Y". Make no mistake, Google Apps for Enterprise exists in name only.
I'm not saying that the issue only came from IT. A well prepared plan that went wrong should be considered a necessary evil.
Plus they will make users hate you.
Policy is what you're talking about, and solid enforcement. If you don't have a way to ensure people are adhering to the policy, you're in a world of hurt because yes, they will do whatever they can to get the features they want.
But the bottom line is that the machines are there for work, and a single security problem caused by a single careless/uneducated user can cause devastating consequences for the organisation as a whole, so I find myself increasingly taking the IT guys' side on this one.
Put it this way: the employee who wants to install Chrome because it's their favourite browser or to bring their own device because they don't want to carry a second company one probably isn't the employee who's going to get paged at 3am and then spend all weekend reinstalling clean images on compromised machines if there's a security breach, nor the one who is going to have to explain to senior management why the company has lost $6M this week due to downtime because the recovery had to happen during business hours.
So unless the user wanting to break the rules is willing and able to underwrite all potential losses to the employer, which they aren't, it is perfectly reasonable to not only restrict what they can do with the employer's systems but also to penalise them severely if they try to circumvent those rules.
However, you need an awful lot of indirect benefit to make up for one screw-up that breaches corporate security, particularly if you work in a regulated industry like healthcare or finance. Lawyers and industry regulators don't care about any goodwill you got from letting Bob bring his own laptop to work if Bob's laptop was subsequently left on a train opening access to thousands of customers' medical records or credit card details. You could probably have fired Bob and hired an entire team of other people who didn't care about using their own laptop with the money you're instead paying as a fine for that one, though perhaps not so much if the business collapses due to the adverse PR and an executive or two gets thrown in jail for negligence.
http://www.chromium.org/administrators/policy-list-3
You can whitelist and blacklist extensions, whitelist sources, force install extensions and block them by type only.
It shouldn't be hard to prevent all extensions from running.