There is no built-in MD5 or SHASUM checker for downloads
Reported by
vidyasag...@gmail.com,
Sep 22 2017
|
|||||||
Issue descriptionUserAgent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 Steps to reproduce the problem: 1. Download any file What is the expected behavior? Get a default "verify" button that a user can enter the source MD5 into and let chrome tell them it is signature verified What went wrong? This option is a no-brainer for a modern browser Did this work before? No Chrome version: 60.0.3112.113 Channel: stable OS Version: 10.0 Flash Version:
,
Sep 25 2017
Adding TE-NeedsTriageHelp label for moving this Unconfirmed bug out of TE unconfirmed triaging bucket.
,
Sep 25 2017
Chrome does not have this feature today. Whether it should is an open question.
,
Sep 26 2017
Maybe MD5 is broken. SHA256 isn't. The secure delivery of the hash value can be left up to the user to enter upon the download completion. There's no way of catching every file's signature as they are sometimes not published. Unless chrome makes it mandatory for them to or calculates it at source when download is requested. Whether this feature is an open question or not, I feel the community needs this. If you guys are not able to do it, point me in the right direction and I will learn to do it I guess.
,
Sep 28 2017
This is the first I have seen this request. To be honest, I struggle to think that this feature is going to be sufficiently used to justify the investment and/or UX overhead. However, I am going to leave the bug open for a while to see if there is more interest.
,
Oct 6 2017
Hmmm... I don't think there's much we're likely to do here, on the extensions side. Right now, this is pretty doable: an extension can use the HTML5 file APIs to read the contents of the file and verify it against an expected hash. The clunky part is that the extension needs to be provided the file by the user (it can't just read it without permission), but I think that's largely a desirable feature. I don't think we want extensions to be able to read arbitrary contents off disk. Since there's not likely going to be extension changes to support this, removing the extensions label.
,
Oct 10 2017
dah...@chromium.org - we're talking about security here. UX and UI overhead must be secondary to this surely?
,
Oct 12 2017
Perhaps, If the UI is not intuitive and users don't know how to use it, then it doesn't help security. I will mark this as available in case someone has time to look at it.
,
Oct 14 2017
I'm not much of a coder, but I doubt the best way to approach a coding challenge is fashion over function???? I think we make the feature available and then break our heads about making the UI more intuitive. Thank you, I really hope someone takes more interest in this. I mean, it is after all about making chrome more secure and people more secure. Especially considering the number of man in the middle attacks on the internet today.
,
Oct 14 2017
The mitigation for MiTM attacks is HTTPS, not asking humans to manually compare inscrutable sets of hexidecimal digits. Users who wish to compare SHA256 sums have many options available to them, none of which require changes to the browser.
,
Oct 14 2017
Well, how about having site owners maintain say a .htaccess file with the downloadable file's correct signature and making that a spec which chrome can then use to automatically verify that the source is what it says it is! I mean, this is where the ball starts rolling for the internet with chrome right, so if you guys can't make that paradigm shift to a safer browsing experience, who will?
,
Oct 14 2017
Your proposal requires HTTPS to protect access to the hashes, and after you turn on HTTPS, the proposal offers no additional security benefit.
,
Oct 15
This issue has been Available for over a year. If it's no longer important or seems unlikely to be fixed, please consider closing it out. If it is important, please re-triage the issue. Sorry for the inconvenience if the bug really should have been left as Available. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||
►
Sign in to add a comment |
|||||||
Comment 1 by elawrence@chromium.org
, Sep 22 2017Labels: -Type-Bug-Security -Restrict-View-SecurityTeam Type-Feature
Summary: There is no built-in MD5 or SHASUM checker for downloads (was: There is no built-in MD5 or SHASUM checker)