New issue
Advanced search Search tips

Issue 750998 link

Starred by 2 users

Issue metadata

Status: Duplicate
Merged: issue 74987
Owner: ----
Closed: Aug 2017
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: 2
Type: Bug-Security



Sign in to add a comment

Security: browser history sniffing via timing attack

Reported by jackwill...@gmail.com, Aug 1 2017

Issue description

I see the fix was incomplete for issue  bug 625945 . Please follow the steps listed below.

Chrome Version: Stable 60.0.3112.78 
Operating System: Windows 

REPRODUCTION CASE
1: Download the attached file. 
2: Then open http://www.chase.com/.
3: You should see that http://www.chase.com is visited.
 
csp probing.html
3.7 KB View Download
Components: Internals>Network>DomainSecurityPolicy Privacy
Labels: Security_Severity-Low Security_Impact-Stable
Similar to Issue 626931.
Project Member

Comment 2 by sheriffbot@chromium.org, Aug 1 2017

Labels: Pri-2
Components: -Internals>Network>DomainSecurityPolicy Blink>SecurityFeature>SameOriginPolicy
Mergedinto: 74987
Status: Duplicate (was: Unconfirmed)
Summary: Security: browser history sniffing via timing attack (was: Security: browser history sniffing via HSTS + CSP )
This repros, albeit somewhat unreliably.

The fix in  Issue 544765  was to ensure that CSP requiring HTTP could not block HTTPS requests (https://www.chromestatus.com/feature/6653486812889088). That change remains effective and you can see by running this repro that no requests are blocked by CSP. Removing the "Step 1" section of the code (which attempts to use CSP), shows the same rate of repro. The repro is thus just using a cache timing attack to try to infer whether the target page happens to be in the cache.

As noted in comment #19 on that issue, "This won't fix variants of the attack that rely on cache timing, but it removes the trivial DOM event that the PoC relied on for 100% accuracy."

Unfortunately, breaking cache timing attacks is not generally practical without severely impairing the performance of the web platform.

Project Member

Comment 4 by sheriffbot@chromium.org, Nov 15 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment