Live data from Hacker News

Google apps whitelist hardcoded into Chromium open source project

code.google.com

31–40 of 61 posts

Re: Google apps whitelist hardcoded into Chromium open source project

#31
post #11

Throwing some more info here, this is the NaCl whitelist, looks like it was originally added Feb last year [1]. There's a discussion on Chromium Code Reviews here [2], and an issue on the project itself here [3] The original commit includes the comment 'We should remove this code when PNaCl ships' which got removed somewhere along the way. [1] http://src.chromium.org/viewvc/chrome/trunk/src/chrome/rende... [2] https:…

[deleted]

Re: Google apps whitelist hardcoded into Chromium open source project

#32
post #12

What whitelist? JS Execution? No popup blocking? Something else?

Did a bit of digging - it lets NACL apps downloaded from those whitelisted Google apis have access to "dev interfaces". Brief search shows that these dev interfaces would have the ability to access the user's PC outside of the Chrome sandbox. In effect, this gives Google remote code execution rights from their domains on anybody running Chromium.

I only use Chrome to access Google apps/docs/gmail, since it seems to work better than other browsers for this. Looking like it might be worth setting up a VM appliance for this now.

Re: Google apps whitelist hardcoded into Chromium open source project

#33
post #11

Throwing some more info here, this is the NaCl whitelist, looks like it was originally added Feb last year [1]. There's a discussion on Chromium Code Reviews here [2], and an issue on the project itself here [3] The original commit includes the comment 'We should remove this code when PNaCl ships' which got removed somewhere along the way. [1] http://src.chromium.org/viewvc/chrome/trunk/src/chrome/rende... [2] https:…

[deleted]

Re: Google apps whitelist hardcoded into Chromium open source project

#34
post #11

Throwing some more info here, this is the NaCl whitelist, looks like it was originally added Feb last year [1]. There's a discussion on Chromium Code Reviews here [2], and an issue on the project itself here [3] The original commit includes the comment 'We should remove this code when PNaCl ships' which got removed somewhere along the way. [1] http://src.chromium.org/viewvc/chrome/trunk/src/chrome/rende... [2] https:…

[deleted]

Re: Google apps whitelist hardcoded into Chromium open source project

#35
post #11

Throwing some more info here, this is the NaCl whitelist, looks like it was originally added Feb last year [1]. There's a discussion on Chromium Code Reviews here [2], and an issue on the project itself here [3] The original commit includes the comment 'We should remove this code when PNaCl ships' which got removed somewhere along the way. [1] http://src.chromium.org/viewvc/chrome/trunk/src/chrome/rende... [2] https:…

Does anybody know why (variations on copies of) leokun's comment are automatically marked as dead?

The comment seems perfectly valid so I can't figure out why that would happen...

Re: Google apps whitelist hardcoded into Chromium open source project

#36
post #35
post #11

Throwing some more info here, this is the NaCl whitelist, looks like it was originally added Feb last year [1]. There's a discussion on Chromium Code Reviews here [2], and an issue on the project itself here [3] The original commit includes the comment 'We should remove this code when PNaCl ships' which got removed somewhere along the way. [1] http://src.chromium.org/viewvc/chrome/trunk/src/chrome/rende... [2] https:…

Does anybody know why (variations on copies of) leokun's comment are automatically marked as dead? The comment seems perfectly valid so I can't figure out why that would happen...

The shortened link seems to do it.

Re: Google apps whitelist hardcoded into Chromium open source project

#37
post #35
post #11

Throwing some more info here, this is the NaCl whitelist, looks like it was originally added Feb last year [1]. There's a discussion on Chromium Code Reviews here [2], and an issue on the project itself here [3] The original commit includes the comment 'We should remove this code when PNaCl ships' which got removed somewhere along the way. [1] http://src.chromium.org/viewvc/chrome/trunk/src/chrome/rende... [2] https:…

Does anybody know why (variations on copies of) leokun's comment are automatically marked as dead? The comment seems perfectly valid so I can't figure out why that would happen...

[deleted]

Re: Google apps whitelist hardcoded into Chromium open source project

#38
post #35

Earlier quoted context omitted.

Does anybody know why (variations on copies of) leokun's comment are automatically marked as dead? The comment seems perfectly valid so I can't figure out why that would happen...

The shortened link seems to do it.

[deleted]

Re: Google apps whitelist hardcoded into Chromium open source project

#39
post #11

Throwing some more info here, this is the NaCl whitelist, looks like it was originally added Feb last year [1]. There's a discussion on Chromium Code Reviews here [2], and an issue on the project itself here [3] The original commit includes the comment 'We should remove this code when PNaCl ships' which got removed somewhere along the way. [1] http://src.chromium.org/viewvc/chrome/trunk/src/chrome/rende... [2] https:…

There was a brief discussion about this code on Twitter a few weeks back and I asked for extra clarification from engineering. Erik Kay explained on that bug ticket [3] a bit more:

"We don't enable NaCl on the web at large because we don't want to see a particular instruction set baked into the web. We enable it for apps that are in the Chrome Web Store (even hosted apps which are in the web) because it's a place where over time we can get developers to migrate to PNaCl. For this whitelist, we have similar controls to what we have on the Chrome Web Store, and our goal is to eventually remove the need for it altogether."

Re: Google apps whitelist hardcoded into Chromium open source project

#40
post #35
post #11

Throwing some more info here, this is the NaCl whitelist, looks like it was originally added Feb last year [1]. There's a discussion on Chromium Code Reviews here [2], and an issue on the project itself here [3] The original commit includes the comment 'We should remove this code when PNaCl ships' which got removed somewhere along the way. [1] http://src.chromium.org/viewvc/chrome/trunk/src/chrome/rende... [2] https:…

Does anybody know why (variations on copies of) leokun's comment are automatically marked as dead? The comment seems perfectly valid so I can't figure out why that would happen...

I believe it means his account has been banned, for some reason.
Post reply on HN