Issue metadata
Sign in to add a comment
|
Security: Pushbullet bypasses Google's SMS auth verification
Reported by
tiagober...@gmail.com,
Jan 9 2017
|
||||||||||||||||||||
Issue descriptionI am reporting this bug here, because this issue concerns almost all chrome extensions. I use my google account in several browsers. My chrome extensions session is being kept regardless of my google login. Whenever i am asked to confirm the SMS token provided during Google login, Pushbullet promptly sends it to all my devices, regardless of my browser authentication state. Even though this is a Pushbullet issue i think Chrome has some responsibilities here. My suggestion would be to purge all extensions sessions on browser logout or expiration.
,
Jan 17 2017
,
Jan 17 2017
We're probably not going to change anything in this respect. There are a lot of ways that users can tweak settings in order to get extensions where they want them (and make sure they don't have them when they don't want them). For instance, extensions are tied to a chrome profile, so you can make multiple profiles with different extension configurations. You also have the choice of whether or not to sync extensions, so you can choose if you want extensions only on a certain machine or across all devices with the signed-in profile. You can toggle whether or not the extension is allowed to run incognito, and use incognito mode when you don't certain extensions running (as a sort of light-weight second profile). And, of course, if you don't want a given extension, you can always remove it from chrome://extensions or the extensions action bar. Of course, these tools can't solve every use case, but trying to do that would result in too much complexity for Chromium and users. :)
,
Jan 17 2017
I am using different extensions with several profiles. Anyone that uses my pc can swap the the browser profile and use different extensions. That is quite nice. My problem is that Chrome correctly asks me to login every now and then and my extensions do not purge sessions accordingly. Sometimes, my grandpa uses my browser or a browser where i was on and gets to see messages that were not meant for him. I removed Pushbullet, i really think they screwed up really hard with this but i still think chrome extension authentication should be tied to browser login or else profiles won't ever work as safe user spaces.
,
Apr 26 2017
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||
Comment 1 by kerrnel@chromium.org
, Jan 17 2017Owner: rdevlin....@chromium.org