New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 621397 link

Starred by 2 users

Issue metadata

Status: Fixed
Owner:
Last visit > 30 days ago
Closed: Aug 2016
Cc:
EstimatedDays: ----
NextAction: ----
OS: All
Pri: 2
Type: Feature



Sign in to add a comment

Measuring cross-origin vibrate usage and block them if feasible

Project Member Reported by bi...@google.com, Jun 20 2016

Issue description

UserAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.63 Safari/537.36

Steps to reproduce the problem:
It's listed at bit.ly/proposed-interventions, and discussed internally at https://groups.google.com/a/google.com/forum/#!topic/safebrowsing-ads/CXL4W-qrrns. 

What is the expected behavior?

What went wrong?
Vibrate is being abused by unsafe third-party content (eg., ads), and we'd like to measure its usage in cross-origin context and see the possibility of blocking them. If blocking all cross-origin vibrate breaks too many pages, we could just block it if there is no user gestures.

Did this work before? N/A 

Chrome version: 51.0.2704.63  Channel: n/a
OS Version: OS X 10.11.5
Flash Version: Shockwave Flash 22.0 r0
 
Project Member

Comment 1 by sheriffbot@chromium.org, Jun 20 2016

Labels: Hotlist-Google
Labels: Te-NeedsFurtherTriage
Labels: Security
Status: Untriaged (was: Unconfirmed)
Cc: rsesek@chromium.org
[mac triage] I'm not too familiar with security issues like this. Do you have any insight on this, rsesek? Thanks!

Comment 6 by rsesek@chromium.org, Jun 22 2016

Cc: -rsesek@chromium.org
Components: Security>UX
Labels: -OS-Mac OS-All
Cc: bi...@google.com
Status: Available (was: Untriaged)
Hi binlu@, Is this bug already fixed?

Comment 10 by bi...@google.com, Jul 20 2016

I'm working on it, and here is the intent to ship: https://groups.google.com/a/chromium.org/forum/#!topic/blink-dev/7iVcwNcO3xw

Could you please help assign me as the owner? Thanks.
Labels: -Te-NeedsFurtherTriage TE-NeedsfurtherTriage
Owner: kenjibaheux@chromium.org
We can't assign you because you are not a project member but don't worry, I'll close this one on your behalf.

Let's used  issue 625044  to track the actual change.
Status: Fixed (was: Available)
Components: -Security>UX
Labels: Team-Security-UX
Security>UX component is deprecated in favor of the Team-Security-UX label

Sign in to add a comment