New issue
Advanced search Search tips

Issue 679304 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
Closed: Jan 2017
Cc:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: Pushbullet bypasses Google's SMS auth verification

Reported by tiagober...@gmail.com, Jan 9 2017

Issue description

I am reporting this bug here, because this issue concerns almost all chrome extensions.


I use my google account in several browsers. My chrome extensions session is being kept regardless of my google login. 
Whenever i am asked to confirm the SMS token provided during Google login, Pushbullet promptly sends it to all my devices, regardless of my browser authentication state.


Even though this is a Pushbullet issue i think Chrome has some responsibilities here.

My suggestion would be to purge all extensions sessions on browser logout or expiration. 
 
Cc: kerrnel@chromium.org
Owner: rdevlin....@chromium.org
If I understand this correctly, the problem you are describing is that you use Pushbullet, which looks like it it forwards text messages around between devices, and you are wondering if the Pushbullet extension should remain logged in if you are being prompted to log back into your google account. For example, if you were to visit passwords.google.com and be asked for your password? 

I'm going to ask rdevlin.cronin@ to confirm this, but I don't think extension sessions are going to be tied to google.com login. Please clarify I didn't understand the issue correctly.
Project Member

Comment 2 by sheriffbot@chromium.org, Jan 17 2017

Status: Assigned (was: Unconfirmed)
Status: WontFix (was: Assigned)
We're probably not going to change anything in this respect.  There are a lot of ways that users can tweak settings in order to get extensions where they want them (and make sure they don't have them when they don't want them).  For instance, extensions are tied to a chrome profile, so you can make multiple profiles with different extension configurations.  You also have the choice of whether or not to sync extensions, so you can choose if you want extensions only on a certain machine or across all devices with the signed-in profile.  You can toggle whether or not the extension is allowed to run incognito, and use incognito mode when you don't certain extensions running (as a sort of light-weight second profile).  And, of course, if you don't want a given extension, you can always remove it from chrome://extensions or the extensions action bar.

Of course, these tools can't solve every use case, but trying to do that would result in too much complexity for Chromium and users. :)
I am using different extensions with several profiles. Anyone that uses my pc can swap the the browser profile and use different extensions. That is quite nice. 


My problem is that Chrome correctly asks me to login every now and then and my extensions do not purge sessions accordingly. Sometimes, my grandpa uses my browser or a browser where i was on and gets to see messages that were not meant for him.


I removed Pushbullet, i really think they screwed up really hard with this but i still think chrome extension authentication should be tied to browser login or else profiles won't ever work as safe user spaces.
Project Member

Comment 5 by sheriffbot@chromium.org, Apr 26 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment