New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 621336 link

Starred by 2 users

Issue metadata

Status: Available
Owner: ----
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Mac
Pri: 2
Type: Feature



Sign in to add a comment

Measuring cross-origin modal dialog usage and block them if feasible

Project Member Reported by bi...@google.com, Jun 19 2016

Issue description

UserAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.63 Safari/537.36

Steps to reproduce the problem:
It's listed at bit.ly/proposed-interventions, and discussed internally at https://groups.google.com/a/google.com/forum/#!topic/safebrowsing-ads/CXL4W-qrrns. 

What is the expected behavior?

What went wrong?
Modal dialogs ('alert()', 'confirm()', 'prompt()', 'print()'), are being abused by unsafe third-party content (eg., ads), and we'd like to measure their usage in cross-origin context and see the possibility of blocking them. If blocking all cross-domain modal dialogs breaks too many pages, we could just block those w/o user gestures.

Did this work before? No 

Chrome version: 51.0.2704.63  Channel: n/a
OS Version: OS X 10.11.5
Flash Version: Shockwave Flash 22.0 r0
 
Project Member

Comment 1 by sheriffbot@chromium.org, Jun 19 2016

Labels: Hotlist-Google
Components: Blink
Status: Untriaged (was: Unconfirmed)
As the issue is of type feature marking it as Untriaged to get it addressed.

Thanks,
Components: -Blink Blink>HTML

Comment 5 by tkent@chromium.org, Jun 24 2016

Components: -Blink>HTML Blink>SecurityFeature Blink>HTML>IFrame
Status: Available (was: Untriaged)

Comment 6 by mkwst@chromium.org, Sep 12 2016

Cc: japhet@chromium.org ojan@chromium.org
The metrics here just hit stable, so we should have pretty reasonable data to work with in a few days. Bin, will you be following up on this bug? Or do we need to find someone to poke at things?

Comment 7 by bi...@google.com, Sep 12 2016

@Mike, Could you cc avi@chromium.org and emilyschechter@chromium.org on this bug?

They are investigating other potential avenues of solving alert, and maybe this could be part of their plan. If they can take care of this, I will focus on vibrate. Thanks.
Cc: a...@chromium.org emilyschechter@chromium.org
Cc: kenjibaheux@chromium.org
Cc: rsch...@chromium.org
Project Member

Comment 11 by sheriffbot@chromium.org, Sep 13 2017

Labels: Hotlist-Recharge-Cold
Status: Untriaged (was: Available)
This issue has been Available for over a year. If it's no longer important or seems unlikely to be fixed, please consider closing it out. If it is important, please re-triage the issue.

Sorry for the inconvenience if the bug really should have been left as Available. If you change it back, also remove the "Hotlist-Recharge-Cold" label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Comment 12 by tkent@chromium.org, Sep 15 2017

Components: Blink>WindowDialog
Labels: -Hotlist-Recharge-Cold
Status: Available (was: Untriaged)
Labels: Hotlist-EnamelAndFriendsFixIt
Labels: -Hotlist-EnamelAndFriendsFixIt

Comment 15 by ojan@chromium.org, May 8 2018

Cc: -ojan@chromium.org
Cc: -rsch...@chromium.org

Sign in to add a comment