New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 679839 link

Starred by 2 users

Issue metadata

Status: Duplicate
Merged: issue 651055
Owner: ----
Closed: Jan 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Mac
Pri: 2
Type: Bug
Team-Security-UX



Sign in to add a comment

Security Chip shows "Dangerous" for https://google.co.in after using Google Image Search

Reported by mr.mites...@gmail.com, Jan 10 2017

Issue description

Chrome Version       : Version 55.0.2883.95 (64-bit)
URLs (if applicable) : https://www.google.co.in/search?q=funny+single+status&espv=2&biw=1280&bih=700&tbm=isch&imgil=swNkL0D7Jw6x2M%253A%253Bci9aq_Ur_G0gwM%253Bhttp%25253A%25252F%25252Fwww.jokeswale.com%25252Ftag%25252Ffunny-single-status-jokes-in-hindi&source=iu&pf=m&fir=swNkL0D7Jw6x2M%253A%252Cci9aq_Ur_G0gwM%252C_&usg=__eoZz_DhU2c1BCSbdLyHqzOo3rk8%3D&dpr=2&ved=0ahUKEwjN-OSVtLjRAhUEOo8KHY7dBNQQyjcIJA&ei=z0J1WI3VOIT0vASOu5OgDQ#imgrc=vSBv1FRS01VU8M%3A

OS version               : 10.12.2
Behavior in Safari (if applicable): Working as expected
Behavior in Firefox (if applicable): Working as expected

What steps will reproduce the problem?
(1) Open https://www.google.co.in/search?q=funny+single+status&espv=2&biw=1280&bih=700&tbm=isch&imgil=swNkL0D7Jw6x2M%253A%253Bci9aq_Ur_G0gwM%253Bhttp%25253A%25252F%25252Fwww.jokeswale.com%25252Ftag%25252Ffunny-single-status-jokes-in-hindi&source=iu&pf=m&fir=swNkL0D7Jw6x2M%253A%252Cci9aq_Ur_G0gwM%252C_&usg=__eoZz_DhU2c1BCSbdLyHqzOo3rk8%3D&dpr=2&ved=0ahUKEwjN-OSVtLjRAhUEOo8KHY7dBNQQyjcIJA&ei=z0J1WI3VOIT0vASOu5OgDQ#imgrc=vSBv1FRS01VU8M%3A 
(2) After chrome warning replace urls with https://www.google.co.in 
(3) Now you will see the Dangerous red flag for google.co.in

What is the expected result?

The https://www.google.co.in/ should display Secure instead of Dangerous

What happens instead?

Instead of secure flag for https://www.google.co.in/ its display Dangerous.

For graphics-related bugs, please copy/paste the contents of the about:gpu
page at the end of this report.


 
Screen Shot 2017-01-11 at 2.05.27 AM.png
220 KB View Download
Screen Shot 2017-01-11 at 1.55.08 AM.png
112 KB View Download
Screen Shot 2017-01-11 at 2.16.50 AM.png
420 KB View Download
Video Demo of bug:
Chrome Bug.webm
4.4 MB View Download
Cc: elawrence@chromium.org durga.behera@chromium.org
Components: Internals>PageSecurityState
Labels: M-55 OS-Linux
Owner: zhaobin@chromium.org
Status: Assigned (was: Unconfirmed)
Able to reproduce the issue on Mac 10.12.2 and Ubuntu 14.04 using 55.0.2883.95/87.
Its working fine on beta 56.0.2924.51 and canary 57.0.2977.0.

Tried reverse bisecting and got all good builds only even increasing the bad revisions.
Good:56.0.2902.0
Bad :56.0.2901.0  
OMahaproxy UI CL:
https://chromium.googlesource.com/chromium/src/+log/56.0.2901.0..56.0.2902.0?pretty=fuller&n=10000
possible suspect from above CL:Review-Url: https://codereview.chromium.org/2435243002
zhaobin@: Could you please have a look into it if its related to your change.
Cc: nparker@chromium.org
Components: UI>Browser>SafeBrowsing
Labels: -Pri-3 Pri-2
Summary: Security Chip shows "Dangerous" for https://google.co.in after using Google Image Search (was: Dangerous for https://google.co.in)
Based on the repro video, it looks like what happens here is that the user visits Google, performs a Google Image search and selects an image to examine. That image (or something that comes down with it) triggers SafeBrowsing to complain that content from the target origin is deceptive, causing to the blocking interstitial page and the "Dangerous" marking.

I believe it is considered "Working as Intended" that, after an origin is marked Dangerous, that marking sticks around even if you navigate to other pages.
Hey

So for example: Google safe browsing blocked xyz.net site for malicious activity.
Now user1 is try to search some images and its end-up with xyz.net malicious website image and google chrome display its in FULL RED page its a good things.

But when user try to open Google.com or Google.co.in in the same tab chrome still think Google is Dangerous its not acceptable. 

The Dangerous is for xyz.net malicious site not for Google.
Re: Comment #5: Yes, your concern is understood. The problem is that there's no solid way to tell whether the outer domain is also malicious (and we only noticed that one one page that had a malicious resource from a known-dangerous domain) or a (somewhat) innocent bystander that just happened to reference a known-dangerous domain incidentally. 

Currently, the UI favors the more secure/paranoid approach.

This is basically the same as  Issue 651055 
What's use of then display SECURE/INFO/DANGEROUS?

If good domains like Google.com & Google.co.in Chrome display as Dangerous then who will trust chrome security state labels?

If we don't have a solid plan then we have to find a way to hack it and fix this behavior.


Mergedinto: 651055
Owner: ----
Status: Duplicate (was: Assigned)
We've reached out to the Google Images team on potentially integrating SafeBrowsing checks before serving image references.
Hey All,

This issue was merged into 651055 - which was Wont Fix.

So its that mean Google Chrome does not fix fake Dangerous Security state for valid good domain Google.com & Google.co.in ?
Cc: jialiul@chromium.org
The state is not "fake". 

As noted in  Issue 651055 , Chrome's policy is that sites that serve references to resources from Dangerous sites (as determined by Safe Browsing) will be marked as Dangerous for the lifetime of the browser instance. This helps ensure that malicious sites are not able to circumvent the protections of Safe Browsing.
Sorry but little confused here.

Chrome's policy is that sites that serve references to resources from Dangerous sites (as determined by Safe Browsing) will be marked as Dangerous for the lifetime of the browser instance

If google images serve the images from Dangerous sites then why not chrome mark Google as a Dangerous when we open the first time?

Why chrome wait for load image from Dangerous sites and then mark as a Dangerous?
You can learn more about Google Safe Browsing here: https://www.google.com/transparencyreport/safebrowsing/faq/?hl=en

Sign in to add a comment