Netflix disables use of the Chrome developer console
pastebin.com
pastebin.com
I get to run code just as much as you do - it's MY computer, MY browser, and MY bandwidth. Making up a scare word (that just means "users running code I don't like") in an attempt to legitimize disabling access to development and exploration tools is beyond the pale. There is absolutely no reason to permit this kind of behavior, and I'm frankly a little appalled a community of startup founders and hackers would ever defend this kind of behavior, as some of the comments here have done. If you want to protect users from themselves and limit and restrict what they can do, write a mobile app. Don't try and put your shit on the web if you want it to be a walled garden.
If people read of a "h4x0r trick to read their bf/gf private messages", they will execute it. And hey, "it has this l33t keyboard shortcut that will make a strange window pop up, it must be what the hackers in the movies use!!". And then "Oh well, thanks to this friend of mine for sharing this cool trick that gives me the stuff to paste there, I would not know how to use it!". And finally "Booooo, Facebook sucks, my account got hacked".
I remember of the internet making fun of a girl that believed to be enrolled in some secret police because she popped up the Dev console. Well, that is just normal people, not uncommon.
I trust that actual developer can find their way around blocks and warnings, that however raise the bar for social engineering.
- just download this file to see your gf private messages. ok, lets remove download from the browser (actually, ios did this)
- just run this long string in the address bar to see whatever. ok, let prevent javascript: schema in url bar (actually, android stock browser did this)
anyway you go at it, is ineffective. the only solution is to educate. trying to prevent idiots from harming themselves will just lead to annoyance to the non-idiots and more sophisticated attacks until you cant prevent them.
people who implement those dumb thing disgusts me. your comment disgusted me.
Also if you want to learn how to do it right, look at Mozilla. They mostly do the right thing. E.g. telling user and in extreme cases making him wait a very short time before accepting something that may be dangerous.
In Comments
Be civil.
http://ycombinator.com/newsguidelines.htmlExactly. The more things you do to restrict users so "it's safer for them", the more reckless and stupid they'll become - "because $security_feature will protect me" - and they won't ever learn anything. On the other hand, if we give them the freedom to make mistakes, those that do will learn from them. Instead of trying to block "self-XSS" or telling everyone "don't listen to anyone telling you to paste something into the URL bar", we should be encouraging them with "if you don't know what it does or don't trust the one who told you to do that, then don't do it - or find out what it really does." That last part is particularly important, since it encourages curiosity and that motivates learning.
I understand that many people would just want to use something and not want to learn all that much, but I feel we should also not be encouraging this "lack of thought" mentality either.
There's no way to make a system really secure and as you point out there is no way to "prevent idiots from harming themselves". What you do is stopping common/easy vectors and raising the effort bar/reducing conversions for the attacker.
If we require that a guy to use his computer learns how its threat model works, we failed as a industry.
And to address your points: users know that downloaded files are evil and Chrome warns about that. The javascript schema is mitigated by Chrome - if you copy-paste the initial "javascript:" is cut out. I'd love to know the other 998 to open discussions about them.
Note about the use of the word idiots: more of people who are not tech-savvy; you might be an idiot in this meaning for one or more of: electricians, mechanics, doctors...
document.getElementsByTagName('script')[0].innerText > fn = function(){ var key = "shhhhh" }
> fn.toString()
'function (){ var key = "shhhhh" }'
Nothing is sacred in JS.But it requires that the value is hardcoded inside the function. If it was given to an unreachable scope by some async action (like an ajax request) this trick wouldn't work.
One could possibly also wrap the function in an native .bind call to change the output of toString() to [native code]
It's better to assume the console has 100% root (client-side) privileges.
Rather, it makes more sense for them to add it so that if someone does debug their site, it gives Netflix a legal precedent to press charges against them for hacking their site by bypassing a security system.
It's like those tacky trailers at the start of a movie "pirating movies is illegal". First question the judge asks - what steps did you do to prevent pirating and when did you notify your customers.
These companies lose more money to fraud in a quarter than they have ever lost due to people exporting their movie ratings, or whatever other non-criminal acts people have been committing at the console. I don't understand why we need to posit a 2nd (more sinister) motivation.
How does that even make sense given that Facebook clearly gives the opt-out link which is easy to use, and works? I don't believe for a second that you aren't being completely cynical.
The opt-out is there to boil the frog until they can remove it in the guise of "security". I also agree with bsamuels that it provides a convenient CFAA lever to hit in the event you do run a script they don't like. ("They had to deliberately bypass our 'protection' to paste the javascript into the console!")
Asking targets to first go to the account->security settings to disable the option named "Allow my account to be hijacked if I paste malicious JavaScript", and then to paste this JavaScript, seems to me to be quite clearly less effective than the simpler "paste this JavaScript".
Furthermore I strongly suspect that compromised accounts cause more harm to Facebook's bottom line than users who are exporting their address books. Millions lost every quarter due to fraud vs... what, exactly?
It seems that users were being duped in to running malicious scripts that gave attackers control of their accounts. Sure, Facebook could be evil and not offer the option to re-enable the console and I'm sure other sites will do exactly that until browser makers prevent it, but at this time, Facebook is not being evil. I'm not sure about Netflix.
If people are being successfully duped in to running malicious scripts this way, perhaps browser developers should put a first-run warning on the dev tools saying that running code there supplied by a third-party is dangerous.
Since this only applies to Chrome, so do the instructions:
1) Open netflix.com
2) Open developer tools.
3) Go to Sources tab.
4) Click on the tiny icon for "Show Navigator" on the left.
5) Find the JavaScript file that has: (function(){try{var $_console$$=console;Object.defineProperty(window,"console",{get:function(){if($_console$$._commandLineAPI)throw"Sorry, for security reasons, the script console is deactivated on netflix.com";return $_console$$},set:function($val$$){$_console$$=$val$$}})}catch($ignore$$){}})();
For me this is cdn1.nflxext.com/FilePackageGetter/sharedSystem/pkg-nflxsrc-*
6) For me the offending line is line 3. Click on the line number, this will set a breakpoint.
7) Reload the page, now the Script will pause before running line 3.
8) Switch to the Console tab.
9) Run: Object.defineProperty(window, "console", {configurable: false});
10) Switch back to the Sources tab and press the resume script button or F8.
11) Enjoy console access again.
The only thing Netflix's 'security' measure does is make me respect the company a bit less. Who, precisely is this going to hurt? A serious "attacker" is going to be stopped for about 15 seconds. It might stymie some kid trying to learn about front-end web dev. Good job Netflix!
Sites with a large number of inexperienced users (including children) have to think about these things.
They're not trying to lock out web-developers, but normal users that would otherwise never open the developer tools.
I just tried it now on my FB account and it looks like they didn't touch my console. My guess is that I've been developing apps on FB since 2007 and maybe i already disabled that via something long ago.
Just look at those "Forward this email or Bill Gates will kill MSN/sell your children/make the moon landing fake!" things that used to go around. People fell for them.
If you haven't heard of it before, prepare for a journey through Wikipedia as fascinating as it is pitiful.
This is, in my view, a poor solution to the problem, but as a temporary measure, it makes some sense. A change to Chrome to make a warning message appear the first time the developer console is opened, or javascript is used in the location bar, could be a good idea. And, as the pastebin notes, there are likely better, if more complex, technical solutions from the website side. All of these, however, will take considerably more time and effort, and the attacks are already happening.
Some people will keep on exploiting others no matter the format, nerfing things for everyone else is not a tenable solution.
Either that or "hide" the developer tools a bit like they do in modern Android so that it is really obvious to the user if they are directed to mess with things that they shouldn't be messing with without understanding them.
I think that as soon as an attacker tempts the user with: "follow these steps to access American/UK (substitute a locale that has content your account shouldn't have access to) only films that Netflix don't want you to know!" that the apparent gain for the user will lead them to ignore any warnings. In fact, warning might actually encourage these kinds of attacks since the user could think "that's just Netflix trying to hide something, I'm gonna following [the attackers] guide"
The warning won't be fool proof because the world is constantly evolving greater fools, but if well implemented it'll stop at least some of the fools without really impacting legitimate uses of the dev tools.
What the proposed dialog would do is inform users that the console is someplace that they probably do not want to be.
Anyway, people who use social engineering will still win; you can put JS code in the browser bar with the good old javascript: "protocol" if you want somebody to execute something.
You have to manually type "javascript:" for it to work.
> javascript:void(delete window.console);
It just seems like a bit of grief for a temporary gain.
It should be clear by now that if you care about the open web, Netflix is not a company you can trust, much less fund with your money.
Cancel Netflix if you already haven't.
// But if you're feeling up to it, you can run the following line via an extension to prevent // this abuse:
// Object.defineProperty(window, 'console', {configurable: false, value: window.console});
Plus, when you have the company that lives by data, not show you the data that made them make this move, you know something is up. I asked then, and I actually asked when they moved to drag and drop, too: show me the data that proves this is so necessary!
Even before any of this, Chrome was far better than IE and even Firefox at staving off bad extensions. So to me both of those moves seemed unnecessary, and most likely with another "agenda" behind. Now we begin to see that that agenda could be.
I've also connected stuff like this with MPAA taking board membership at W3C. Expect stuff that's much worse than this, and the MPAA-influenced W3C to start keeping features away from browsers that MPAA freaks out about, while Google will increasingly start to ban various extensions from the store for various "ToS reasons".
And people still think W3C's DRM extension won't be used to close down the Internet? It took Netflix weeks to take advantage of Google's recent move. Watch what happens when DRM can be enabled in the browser by anyone, just as easily, Then we'll see if the "convenience" of not playing Netflix through a plugin was worth it.
MPAA executive: we need to lobby W3C more to get DRM!
Netflix: why?
MPAA executive: because they'll steal our content!
Netflix: no need! we've disabled the developer console so they can't steal your content!
MPAA executive: That sounds good!
It's nice having a "yeah but you can do X" retort to the people making these decisions.
The ideologically driven 'but the web should be oooopen' argument won't go far.
but given that Netflix got where it is today on the back of our broken copyright system, I don't for see that happening anytime soon.
lmao, which site am i on again?
[0] http://www.webupd8.org/2013/08/pipelight-use-silverlight-in-...
How can self-XSS be prevented with a CSRF token? Can't the script included via self-XSS get the token out of the page and use it to make requests that appear as if they originate from the app itself? Can't a script injected through self-XSS do absolutely anything the page can do in the first place?
You can take advantage of the fact that you can store private information in closures. To prevent malicious code from overwriting a native function to which you pass sensitive information (like the CSRF token in this case) you need to Object.freeze the prototype of things like XMLHttpRequest or take your own references of the native functions.
Naturally all of this assumes the user doesn't do something like set a breakpoint and then inject a script with access to scope variables. But if social engineering gets you that far, you could probably just have the user run any arbitrary code on their machine.
Worth noting that they remove the "javascript:" part when you paste from clipboard.
My guess is that it protects against people telling others to "copy this in the address bar to steal your friends' Facebook accounts", much like why Facebook disabled the console previously.
Netflix doing this is one of the more obvious manifestations, but they are not alone - many other companies and even open-source, free-software projects are taking this approach, Google included.
And the importance is the presence of competition where there otherwise wouldn't be any
It's partly responsible for bringing options to people with regard to what they see.
I watched a little bit of the Olympics (my wife made me) and while the ladies figure skating was ok, the rest, and especially the commercials, made me feel dumb.
I had to go read a good book (Storm of Steel by Ernst Junger) to boost my mental processes back to normal.
Stupid TV.
In technology, the excuse is usually either "security" or "better user experience".
Like preventing child pornography, these are both worthwhile goals, but they are often used to cover up goals far less noble, as you note.
Netflix may claim they're doing it for "security reasons" but I could see other companies hopping on the bandwagon "to protect their intellectual property" and that'd be a sad day for the internet. Hopefully this doesn't turn into the crazy right-click-blocking craze as another poster mentioned.
Basic literacy and ability to search the web is not that high a bar. There are lots of other gotchas you'll have to overcome to be an Android developer; it's not really a nice programming environment for beginners.
This is part of a larger trend where programming environments are getting increasingly creaky and complicated. Java started out simple, but it's not anymore. The web started out simple, but it's not anymore. Every so often, development environments need a reboot and I think we're long overdue.
There's also the question of whether all this increasing complexity is actually needed - not everyone needs enterprise solution platforms or scalable web application architecture frameworks. Some people just want to write a few webpages to share information with others, and browsers made it easy to get started. Just because we have some really idiotic users and the page source might contain "exploitable" things like cookie values and session IDs doesn't mean we should remove "View Source" and make it a developer-only option. (If the trend continues, I can actually see this happening in the not-so-distant future...)
Disabling a feature of the user's browser is absolutely absurd. If you want to hide from the user whats going on then that code needs to run on the server.
Can you imagine opening an image in Photoshop and because of some flag half the tools disappear? Yeah, me either, and images don't even run code.
The same kind of mindset that thinks that the world would operate better if everyone used Bitcoin and trusted no-one.
I took one glance at the code, and it confirmed what we'd learned during the interview (he was turned down).
Yet he was terribly concerned with getting the disk back to ensure we wouldn't steal his mail client code. The interview was at Yahoo - it's not like we didn't run a vastly more complicated and advanced e-mail system. And not like there weren't dozens of open source mail clients that were far superior to what he brought in if we for some bizarre reasons should have wanted to "steal" code for a desktop mail client.
If someone can verify, I highly recommend filing it.
ed: Looks like there is a bug already: https://code.google.com/p/chromium/issues/detail?id=345205
Absolutely agree. Why don't they do that, or at least make it an option?
How exactly could this be implemented, not including adding a captcha or requiring the user to retype their password for every action?
Still, I suppose it is google...
http://stackoverflow.com/questions/21692646/how-does-faceboo...
Anyhow, I will just quickly dismiss this has anything to do with NSA. If I may, be an ignorant once, called this pastebin a bullshit.
I agree that disabling it is pointless and futile but it's hardly violating anyone's rights.
May I suggest you read the whole thing next time? You can certainly disagree with the author's assertion that companies and governments abuse "for your security" to do awful things (or that it's what happened here), but it's far from ridiculous. I think you just misunderstood the point about the NSA--not reading will do that to you--and it makes you look silly.
Netflix is not abusing "for your security" to do awful things. How? I just don't see it. I see that as an accusation, putting Netflix and Facebook's temporary solution in the same category as NSA's excuse is bad. I might be unfair to the author for not reading the entire post (well technically I read most of it, except Crockford and afterward I gave a quick glance), I will admit that's my failure, but that argument doesn't appeal to me at all.
Details: https://www.facebook.com/selfxss
Note that they have a checkbox on the above page where you agree to the downside, and the console is turned back on (and it appears to work just fine)
Please feel free to read the actual article and quote it and find fault with its conclusions. As it is now you're seizing on individual words, not ideas. If this were a Turing test you wouldn't be doing so well.