New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 707061 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Feb 2018
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Android
Pri: 2
Type: Bug-Security
Team-Security-UX


Show other hotlists

Hotlists containing this issue:
EnamelAndFriendsFixIt


Sign in to add a comment

Chrome Home displays Page Info entirely in a spoofable viewport region.

Project Member Reported by lgar...@chromium.org, Mar 30 2017

Issue description

Chrome Version: 59.0.3055.0
OS: Android 7.1.1
Device: Nexus 5X

What steps will reproduce the problem?
(1) Visit google.com with chrome://flags/#enable-chrome-home
(2) Click on the lock icon.

What is the expected result?
Page Info appears over the URL bar. In particular, the URL in Page Info appears directly over where the omnibox URL used to be.

What happens instead?
Page Info appears in the viewport.
This is trivial to spoof. Spoofing Page Info can allow a site/URL to pretend to be another, or to pretend it's using fewer permissions than it actually is.
(We darken the rest of the screen, but no one would notice if only a page darkens itself.)

Now, a page can't intercept a tap on the lock icon, and probably can't easily guess when you're about to. However, the old UI anchored at the top made the location of trusted UI unmistakable.

 
Components: UI>Browser>Bubbles>PageInfo
Cc: emilyschechter@chromium.org f...@chromium.org
I'm struggling to think of alternatives other than:
- Cover the whole page
- Put it at the bottom (with variable height)

Neither puts the popup's URL over the original URL bar without significant rethinking, and I don't think there's time to spec and implement a flipped Page Info.

felt@, emilyschechter@: Any thoughts? Or maybe just WontFix, because graying everything behind the Page Info popup is good enough?

Comment 3 by ta...@google.com, Mar 31 2017

Labels: Security_Impact-Stable Security_Severity-Low
Project Member

Comment 4 by sheriffbot@chromium.org, Mar 31 2017

Labels: -Pri-3 Pri-2

Comment 5 by ta...@google.com, Apr 3 2017

Status: Available (was: Untriaged)
Idea: if we anchor/epxand Page Info to to the top of the omnibox, we can point at it, similar to  Issue 709224  (Add a triangle pointing to the security indicator for Android permissions prompts in Chrome Home)

Comment 7 by est...@chromium.org, Nov 10 2017

Labels: Hotlist-EnamelAndFriendsFixIt
Cc: carlosil@chromium.org
Similar to  crbug.com/707056 , is this interface still being experimented with? Otherwise this also seems like a Won'tFix.

Status: WontFix (was: Available)

Sign in to add a comment