Live data from Hacker News

Malware in the browser: how you might get hacked by a Chrome extension

kjaer.io

21–30 of 64 posts

Re: Malware in the browser: how you might get hacked by a Chrome extension

#21
post #4

If you like to tweak your Chrome install, check out: chrome://flags/#extension-active-script-permission It adds an extra level of permission where each extension that doesn't ask for a specific website is, by default, locked out of every website, and you have to enable it manually by either clicking on it, whitelisting the websites where it can run or globally (example pic, sorry for not being in english: http://puu.…

I wish this was the default.

Re: Malware in the browser: how you might get hacked by a Chrome extension

#22
post #7

Extensions like this are just the same as .exe adware downloaded and installed by user (not automatically). More serious problem is legitimate extensions that are trusted by lots of users then being sold to some rogue company, then lots of users receive malware with update.

or the author is simply paid to add it to their extension. With the auto updating its basically impossible to stop.

Re: Malware in the browser: how you might get hacked by a Chrome extension

#23
This example is hilarious, granted, but not even the one I truly worry about.

I work in a lax multi-national corporate environment, to be vague. These extensions, especially with religiously conservative adults, is of limited concern.

I am far more concerned about the semi-professional extensions.

I doubt this is malicious, but someone installed this in my environment and inquried why the quality of output went down (in terms of pixelation).

https://chrome.google.com/webstore/search/screenshot?hl=en-U...

The problem here is it raises fewer eyebrows. It does a purpose-filled operation professionals would need, and they are far less discerning than me.

This person had Adobe Acrobat Pro, and forgot. Such extensions have real potential to IOC (indicators of compromise), but only very expensive next-generation malware detection knows that when it sees traffic out.

But what if there is no traffic out? Or it does a more professional job with exfil?

Most modern software inventory has no intelligence into plugins. That is terrifying. Per-user javascript directories? Enumerating just the obvious ones can be a full-time job?

What about dupes? I am the only one I know in my department who uses uBlock ... Origin. And I know there is a fork. Others are intended to have a similar logo and fool busy professionals.

I love FF, but also use Chromium. I am worried that the freedom afforded to me by the beauty of things like Keysnail, like the generally abstracted trend of vendor lockdown, forces me to voluntarily suck it up and deal with crap software defaults and workflows, and doubly recommend the same to people in my environment. I will increasingly have to part with each of the limited extensions I like, all while people here push Electron apps. I like them (who am I to be arrogant and judge the work of these people half my age; at least they put out code while I bitch all day), but the browser base is not discernibly updated or managed unless some developers coordinate. I am sure that came or is coming down the line, but currently populars apps will play catch up while people like me are forced to preemptively yet again restrict use of likeable tech because security was an afterthought.

Qubes increasingly looks like the future. It is sad, but I must every few years consume more resources of my computer for useful, but wasteful, separation of software from its self, because, well, queue the recently retracted Theo de Raadt "x86 virtualization being secure is a waste of time" trope rescinded because even his OpenBSD crew will bite the bullet and work on OpenBSD virt technology.

I just depressed myself.

Sincerely, Guy running multiple browsers in Firejail in a VM

EDIT: I do not the difference between have and half apparently; probably a sign of my age, haha!

Re: Malware in the browser: how you might get hacked by a Chrome extension

#24
post #2

The issue with Chrome extensions, just like with android apps, is that people never check the permissions and just click OK. Extensions make it even easier to install them, though, just need to redirect a user. I've also come upon some spam sites that try to get you to install extensions with annoying alerts that prevent you from closing the page, playing a recorded message "To close the page, just install the XX ext…

I was under the impression all chrome extensions had to go through the chrome web store now. I don't think you can manually install them anymore (outside of installing in developer mode). I could be wrong though.

They do, but Google's policing of the web store is an absolute joke. Tell it at parties, people will laugh.

I've reported malicious extensions and a year later they're still there racking up installs.

Re: Malware in the browser: how you might get hacked by a Chrome extension

#25
post #21
post #4

If you like to tweak your Chrome install, check out: chrome://flags/#extension-active-script-permission It adds an extra level of permission where each extension that doesn't ask for a specific website is, by default, locked out of every website, and you have to enable it manually by either clicking on it, whitelisting the websites where it can run or globally (example pic, sorry for not being in english: http://puu.…

I wish this was the default.

If it was, it would make Chrome all but unusable to a very large portion of its users. Once they realized Flash didn't work on any websites, they'd switch back to Internet Explorer or Firefox or Safari, rather than trying to figure out why it does that.

Re: Malware in the browser: how you might get hacked by a Chrome extension

#26
post #20

Earlier quoted context omitted.

I was under the impression all chrome extensions had to go through the chrome web store now. I don't think you can manually install them anymore (outside of installing in developer mode). I could be wrong though.

This is true. They've actually made it difficult to do even with Developer Mode active, which is probably a net win.

Obviously there's no net win, given that TFA is talking about extensions distributed on Chrome's Web Store, infecting over 130000 users before it was banned.

That kind of proves the walled garden is pretty ineffective, the only accomplishment being the lock-in of users to Google's Web Store as the sole distribution mechanism, thus keeping Chrome a proprietary platform, in spite of the open-source nature of its code.

The only real advantage of the web store is the ability to uninstall banned extensions. But that could have been accomplished just as well by digital signing of the distributed packages.

Re: Malware in the browser: how you might get hacked by a Chrome extension

#27
post #20

Earlier quoted context omitted.

This is true. They've actually made it difficult to do even with Developer Mode active, which is probably a net win.

Obviously there's no net win, given that TFA is talking about extensions distributed on Chrome's Web Store, infecting over 130000 users before it was banned. That kind of proves the walled garden is pretty ineffective, the only accomplishment being the lock-in of users to Google's Web Store as the sole distribution mechanism, thus keeping Chrome a proprietary platform, in spite of the open-source nature of its code.…

Yes, and Web Store only has problems if you want to keep stuff internal ('enterprise' distribution).

This does seem like a total mess.

Re: Malware in the browser: how you might get hacked by a Chrome extension

#28
post #21

Earlier quoted context omitted.

I wish this was the default.

If it was, it would make Chrome all but unusable to a very large portion of its users. Once they realized Flash didn't work on any websites, they'd switch back to Internet Explorer or Firefox or Safari, rather than trying to figure out why it does that.

I don't think this would be that big of an issue really, because Flash is built into the Google build of Chrome. It's the one "extension" that would be really easy to give a free pass on this policy. This would probably be more of a nuisance on Chromium builds.

Re: Malware in the browser: how you might get hacked by a Chrome extension

#29
post #2

The issue with Chrome extensions, just like with android apps, is that people never check the permissions and just click OK. Extensions make it even easier to install them, though, just need to redirect a user. I've also come upon some spam sites that try to get you to install extensions with annoying alerts that prevent you from closing the page, playing a recorded message "To close the page, just install the XX ext…

I remain baffled that alerts in modern browsers are still handled with an OS-level modal dialog that prevents interaction with the browser's interface elements.

Couldn't the alert instead be rendered as an overlay to the page itself, be modal to just that tab, and not disable the browser Chrome? This would make it much harder for pages to "trap" users with alert spam. The existing policies (don't allow this page to create more dialogs -> page instantly redirects to itself to reset the flag) aren't doing a good enough job.

Re: Malware in the browser: how you might get hacked by a Chrome extension

#30
post #21

Earlier quoted context omitted.

I wish this was the default.

If it was, it would make Chrome all but unusable to a very large portion of its users. Once they realized Flash didn't work on any websites, they'd switch back to Internet Explorer or Firefox or Safari, rather than trying to figure out why it does that.

Flash is built-in to Chrome. You'll have to invent another straw man.

In fact, I recommend Chrome to unsophisticated users (hi Mom!) who need access to flash content. I tell Mom to never install anything ever. (She's managed to get malware on her Mac, even though I keep reminding her not to ever click on anything that says "your computer needs updates", etc.)

Post reply on HN