New issue
Advanced search Search tips

Issue 632975 link

Starred by 3 users

Issue metadata

Status: Untriaged
Owner: ----
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Feature



Sign in to add a comment

Chrome doesnt inform the user about failed update attemps

Reported by mollyraz...@gmail.com, Jul 30 2016

Issue description

VULNERABILITY DETAILS
After your browser/computer gets hacked, the first thing an adversary/hacker does in order to keep persistence is crippling the browser's update process. Chrome does check updates, does it in the background, but never tells when an update failed. When Chrome cannot get information regarding updates it just keeps silent. This is problematic in so many levels. The user doesn't know when will a new update is coming, the user only gets a notice, when a new update is applied, but NEVER gets any indication that an update fetch failed... because ksfetch gets terminated or because some domains point to localhost or Little Snitch blocked some domains... and the list goes on.

It would be much safer that whenever an update check or update fails for any reason, or after 2-3 consecutive failures the user would get a message balloon or some kind of icon indicating that the update is failing and the browser is not up to date, therefore cannot be considered "secure" anymore.

The only place a user gets a notification about update problems are in the about/help section, but general users rarely if ever go there to update the browser themselves.

VERSION
Chrome Version: [52.0.2743.82] + [stable]
Operating System: [OSX 10.11.6]

REPRODUCTION CASE
Cripple KSFETCH's net connection attempts via Little Snitch or any preferred way
Use Chrome for a few weeks (do restarts too) and observe that no indication ever given to the user about failed update checks/updates.
 

Comment 1 by rickyz@chromium.org, Jul 31 2016

Components: Internals>Installer
Labels: -Type-Bug-Security -Restrict-View-SecurityTeam Type-Feature
Status: Untriaged (was: Unconfirmed)
Summary: Chrome doesnt inform the user about failed update attemps (was: Security: Chrome doesnt inform the user about failed update attemps)
Changing this to a feature request, since it is not a vulnerability. While there's nothing that Chrome can do about a machine being compromised (at that point, the attacker could fully replace Chrome with whatever they wanted), perhaps it could be worth surfacing info about failed updates to the user somehow.

Hopefully folks that work on the update system are more familiar with the constraints and issues around doing this.

Comment 2 by grt@chromium.org, Aug 1 2016

FWIW, the upgrade detector notifies users when Chrome is far out of date via the outdated upgrade bubble on Windows (and possibly all views-based desktop platforms). I'm not sure about the Mac.

Sign in to add a comment