Google apps whitelist hardcoded into Chromium open source project
code.google.com
code.google.com
The original commit includes the comment 'We should remove this code when PNaCl ships' which got removed somewhere along the way.
[1] http://src.chromium.org/viewvc/chrome/trunk/src/chrome/rende...
[2] https://codereview.chromium.org/9368046
[3] https://code.google.com/p/chromium/issues/detail?id=113668
The comment seems perfectly valid so I can't figure out why that would happen...
"We don't enable NaCl on the web at large because we don't want to see a particular instruction set baked into the web. We enable it for apps that are in the Chrome Web Store (even hosted apps which are in the web) because it's a place where over time we can get developers to migrate to PNaCl. For this whitelist, we have similar controls to what we have on the Chrome Web Store, and our goal is to eventually remove the need for it altogether."
https://code.google.com/p/chromium/codesearch#chromium/src/c...
bool ChromeContentRendererClient::IsAdblockInstalled() {
return g_current_client->extension_dispatcher_->extensions()->Contains(
"gighmmpiobklfepjocnamgkkbiglidom");
}
bool ChromeContentRendererClient::IsAdblockPlusInstalled() {
return g_current_client->extension_dispatcher_->extensions()->Contains(
"cfhdojbkjhnklbpkdaibdccddilifddb");
} // TODO(mpcomplete): remove the extension-related histograms after we collect
// enough data. http://crbug.com/100411
const bool use_adblock_histogram =
ChromeContentRendererClient::IsAdblockInstalled();
https://code.google.com/p/chromium/issues/detail?id=100411Also, with >10,000 engineers (even assuming they are the best 10k in the world), mistakes will be made which is why vulnerabilities exist in the real world.
I guess what I'm trying to say is. Don't act surprised. We've seen it before and we will see it again.
JS Execution? No popup blocking? Something else?
// Temporarily allow these whitelisted apps and WebUIs to use NaCl.
And it's in a function called "IsNaClAllowed"
[EDIT] answered by https://news.ycombinator.com/item?id=6723930
// Temporarily allow these whitelisted apps and WebUIs to use NaCl.
For NaCl, presumably. // Temporarily allow these whitelisted apps and WebUIs to use NaCl.
> Google Native Client (NaCl) is a sandboxing technology for running a subset of Intel x86 or ARM native code in a sandbox. It is proposed for safely running native code from a web browser, allowing web-based applications to run at near-native speeds,[2] which aligns well with Google's plans with Chrome OS. It may also be used for securing browser plugins, and in the future parts of other applications or full applications. [2]In effect, this gives Google remote code execution rights from their domains on anybody running Chromium.
Aren't they just the APIs in https://code.google.com/p/chromium/codesearch#chromium/src/p...? By the looks of it they're just things that aren't ready for primetime, not things that are special dev-only debug tools or whatever.
https://code.google.com/p/chromium/codesearch#chromium/src/p...
and
https://src.chromium.org/chrome/trunk/src/ppapi/c/extensions...
I haven't looked deeply, but both seem to allow for access outside the sandbox. Maybe a chromium committer could give more detail on the safety of the dev interfaces. They are blocked from public usage for a reason though.
PPB_Testing_Dev is a set of helpers for writing tests: querying status of the plugin; running nested message loop to wait for results of async operations; simulate input events which are received only by the plugin itself.
PPB_Ext_Events_Dev is for registering/unregistering events provided by Chrome apps apis (http://developer.chrome.com/apps/api_index.html). It will only be accessible when the NaCl module is included in a Chrome app. This interface hasn't been implemented yet.
If you're running Chrome, you've already given them code execution rights – the only thing this does is make it slightly harder to detect.
bool is_whitelisted_url = false;
(If one should be so inclined). — Ron Jeffries // Whitelisted apps must be served over https.Google is saying that everyone on the internet has to dump plugins, dump Flash and create pure HTML solutions. HTML should be good enough for everyone! Everyone except themselves, apparently.
They can just jump to native code on their websites whenever they like. So much for their credibility when it comes to web-standards, eh?
That's a big part of getting the end-user experience to work well and can't just be "tacked on" later.
For instance graceful fallback is a 'nice to have' but not necessary. If you deny flash or javascript, essentially most sites simply break. I imagine a native client plugin would have the same results if you don't enable it.
As for white listing, why can't it simply be handled with the same dialogs used for whitelisting all the other existing extensions per site?