Security: prevent WebUSB from accessing all Yubico devices
Reported by
c...@yubico.com,
Mar 5 2018
|
|||||||||||||
Issue descriptionSee issue 818592 for vulnerability information. Until we gain comfort with any potential solutions to those issues, we'd like all of our devices not to be accessible via WebUSB. Please prevent all devices with USB VID 0x1050 (Yubico) with any PID from being accessed via WebUSB.
,
Mar 5 2018
Labels to match issue 818592
,
Mar 5 2018
,
Mar 5 2018
Pls add applicable OSs. Thank you.
,
Mar 5 2018
,
Mar 5 2018
,
Mar 5 2018
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/19ef9b1996b53c5a03abe3166ebc08294d840f69 commit 19ef9b1996b53c5a03abe3166ebc08294d840f69 Author: Reilly Grant <reillyg@chromium.org> Date: Mon Mar 05 23:54:18 2018 Add remaining Yubikey devices to WebUSB blocklist As requested by Yubico this change adds the rest of their Yubikey devices to the WebUSB blocklist. Bug: 818807 Change-Id: I4755ca0a2558e7efb2449e6b439c2abcc2440611 Reviewed-on: https://chromium-review.googlesource.com/949389 Reviewed-by: Adam Langley <agl@chromium.org> Commit-Queue: Reilly Grant <reillyg@chromium.org> Cr-Commit-Position: refs/heads/master@{#540992} [modify] https://crrev.com/19ef9b1996b53c5a03abe3166ebc08294d840f69/chrome/browser/usb/usb_blocklist.cc [modify] https://crrev.com/19ef9b1996b53c5a03abe3166ebc08294d840f69/chrome/browser/usb/usb_blocklist_unittest.cc
,
Mar 6 2018
In addition to the change above (which will be in Chrome 67.0.3363.0) this list is also being rolled out via Finch to Chrome 65 and above.
,
Mar 6 2018
,
Mar 6 2018
,
Mar 6 2018
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/967d11212c9f2547f7cc27eb96bee08618d4f143 commit 967d11212c9f2547f7cc27eb96bee08618d4f143 Author: Reilly Grant <reillyg@chromium.org> Date: Tue Mar 06 23:17:54 2018 Add additional U2F tokens to WebUSB blocklist Additional U2F tokens from other manufacturers. Bug: 818807 Change-Id: Ieb20c0b433b00bb3a0b4f65519d9b978b8c81b80 Reviewed-on: https://chromium-review.googlesource.com/952071 Reviewed-by: Adam Langley <agl@chromium.org> Commit-Queue: Reilly Grant <reillyg@chromium.org> Cr-Commit-Position: refs/heads/master@{#541235} [modify] https://crrev.com/967d11212c9f2547f7cc27eb96bee08618d4f143/chrome/browser/usb/usb_blocklist.cc
,
Mar 16 2018
,
Mar 16 2018
This bug requires manual review: M66 has already been promoted to the beta branch, so this requires manual review Please contact the milestone owner if you have questions. Owners: cmasso@(Android), cmasso@(iOS), josafat@(ChromeOS), abdulsyed@(Desktop) For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Mar 16 2018
Given that these IDs have been rolled out via Finch no merge to M-66 is necessary.
,
Mar 16 2018
Is this need a merge to M65?
,
Mar 16 2018
The Finch trial covers M-65 as well. No need for a merge.
,
Jun 12 2018
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||
►
Sign in to add a comment |
|||||||||||||
Comment 1 by c...@yubico.com
, Mar 5 2018