Following the same rationale, downloading of executables via Chrome should be restricted to those from Google approved publishers only.
Google enforcing Web store only extensions for Chrome
21–30 of 84 posts
Re: Google enforcing Web store only extensions for Chrome
#22> Why couldn’t this problem be solved by having a setting/option to load extensions that are not hosted in the Chrome Web Store? Unlike modern mobile operating systems, Windows does not sandbox applications. Hence we wouldn’t be able to differentiate between a user opting in to this setting versus a malicious native app overriding the user’s setting. Sounds a bit BS to me. In what reasonable threat model the attacker…
Extracting banking information? Session intercept, credentials theft - you need some form of cooperation with the user and the browser to get them.
Re: Google enforcing Web store only extensions for Chrome
#23Note that they're only doing this for Windows. As someone who occasionally is roped in to providing tech support for a sibling who keeps installing malware - someone who is going to fall for those repackaged versions of VLC, or one of those 'your computer has viruses, click here to install Super Security 3000' or whatever* - I can tell you that malware for Chrome along the lines of browser toolbars and ad injectors are real and out there in the wild and being installed automatically by these kinds of things.
The computer has Norton Internet Security, of course. Which does sweet FA as far as I can tell.
* Note to self: Install AdBlock on that computer.
Re: Google enforcing Web store only extensions for Chrome
#24> Why couldn’t this problem be solved by having a setting/option to load extensions that are not hosted in the Chrome Web Store? Unlike modern mobile operating systems, Windows does not sandbox applications. Hence we wouldn’t be able to differentiate between a user opting in to this setting versus a malicious native app overriding the user’s setting. Sounds a bit BS to me. In what reasonable threat model the attacker…
This is defense-in-depth. Sometimes, the goal is to get a chrome extension installed. (One that, for example, creates pop-up advertisements at random intervals to generate grey-market PPM revenue for the extension author.) Windows (and it's inevitably Windows) knows enough to realize "hey, this Chrome isn't the Chrome that was here yesterday." Signed binaries and SmartScreen work together well enough that even when C…
I think it is obvious what their real motivation is.
Re: Google enforcing Web store only extensions for Chrome
#25If you want to keep any extensions that you didn't install from Web Store, use the dev channel[1] of Chrome and they will work just fine. I use an extension and they warned me one month back to either install their Web Store version will fewer functionality or move to dev channel. [1] http://www.chromium.org/getting-involved/dev-channel
Why don't they simply give me a config flag to change the behaviour? I understand what they are trying to do but it annoys me to have to use non-stable releases just so that I can use a couple of useful extensions not available from the store.
Re: Google enforcing Web store only extensions for Chrome
#26Re: Google enforcing Web store only extensions for Chrome
#27Yet again Google try to prevent users from gaining the same hacker mentality that created Google in the first place.
Re: Google enforcing Web store only extensions for Chrome
#28If you want to keep any extensions that you didn't install from Web Store, use the dev channel[1] of Chrome and they will work just fine. I use an extension and they warned me one month back to either install their Web Store version will fewer functionality or move to dev channel. [1] http://www.chromium.org/getting-involved/dev-channel
Re: Google enforcing Web store only extensions for Chrome
#29I use both Chrome and Firefox interchangeably anyway so not using Chrome won't be a hardship.
Re: Google enforcing Web store only extensions for Chrome
#30> Why couldn’t this problem be solved by having a setting/option to load extensions that are not hosted in the Chrome Web Store? Unlike modern mobile operating systems, Windows does not sandbox applications. Hence we wouldn’t be able to differentiate between a user opting in to this setting versus a malicious native app overriding the user’s setting. Sounds a bit BS to me. In what reasonable threat model the attacker…
This is defense-in-depth. Sometimes, the goal is to get a chrome extension installed. (One that, for example, creates pop-up advertisements at random intervals to generate grey-market PPM revenue for the extension author.) Windows (and it's inevitably Windows) knows enough to realize "hey, this Chrome isn't the Chrome that was here yesterday." Signed binaries and SmartScreen work together well enough that even when C…
What if the virus just installs the binary somewhere else, then updates the shortcut? There are hundreds of possible ways, it just seems futile to plug a particular leak.