Issue metadata
Sign in to add a comment
|
Protected settings aren't getting update in "Secure Preferene" which in turn results in no invoke of "proteus settings hardening" |
||||||||||||||||||||||
Issue descriptionChrome Version: M65, M66 and M67 OS: Windows 10 What steps will reproduce the problem? 1. Clean install chrome 2. Launch chrome and set couple of Protected Preferences uner chrome:settings like homepage, Homebutton, onstartup settings etc., 3. Exit chrome 4. Navigate to ""C:\Users\machinename\AppData\Local\Google\Chrome\User Data\Default\Secured Preferences"" and change any settings or couple of settings(Make sure chrome is not up and running) 5. Launch chrome What is the expected result? Step2 and 3 : We should see the entries for protected preferences in Secured preferences Step 5 : All settings should be revert back to factory default and there should be an banner on top of chrome:settings page. What happens instead? Step2 and 3 : There is no entry of protected preferences in Secured preferences. Please correct me if I missed any steps which would lead to the settings hardening to invoke.
,
Apr 3 2018
@pbommana was this test on a corp machine? The proteus settings hardening feature is not enabled on enterprise domain-joined Windows.
,
Apr 3 2018
,
Apr 3 2018
Ahh, Yes this was on Corp machine. I just tried the same on non corp machine and below are my observations want to double check the behavior : Scenario 1 : 1. Launch Chrome and from Chrome settings --> Enable Show home button --> Set it as "https://play.google.com" 2. Exit Chrome 3. Navigate to "C:\Users\pbommana\AppData\Local\Google\Chrome\User Data\Default\Secure preferences" 4. Change Home page from "https://play.google.com" to "https://www.dell.com" 5. relaunch Chrome Observed behavior : 1. Under Chrome Settings I still see homepage set to "https://play.google.com" and there wasn't any bubble stating that settings were changed. Scenario 2 : 1. Launch Chrome and from Chrome settings --> Enable Show home button --> Set it as "https://play.google.com" 2. Exit Chrome 3. Navigate to "C:\Users\pbommana\AppData\Local\Google\Chrome\User Data\Default\Secure preferences" 4. Change Home page from "https://play.google.com" to "https://www.dell.com" 5. Navigate to "C:\Users\pbommana\AppData\Local\Google\Chrome\User Data\Default\Preferences" 6. Change Home page from "https://play.google.com" to "https://www.dell.com" 7. Relaunch Chrome Observed behavior : 1. There wasn't any bubble on the page stating that my homepage or Chromesettings were compromised. 2. Once navigate to "Chrome://settings" I see the dialog "Some Settings were reset"( I was expecting the bubble right after launch of Chrome from hotdog menu instead of going into Chrome://settings" please correct me if the feature has been changed)
,
Apr 3 2018
,
Apr 3 2018
Tried reproducing on Chrome M65 (65.0.3325.181) on a VM. For Scenario #2 Step #5-6, I did not see the home button URL in the regular Preferences file - only in the Secure Preferences file. For Scenario 1, I observed the same behavior as you did for Scenario 2: 1. There wasn't any bubble on the page stating that my homepage or Chrome settings were compromised. 2. Once navigate to "Chrome://settings" I see the dialog "Some Settings were reset" Note to self: maybe related to https://chromium-review.googlesource.com/c/chromium/src/+/985110?
,
Apr 4 2018
I can't seem to find the code responsible for showing the bubble right after the launch of Chrome. It's possible it was removed some time ago (@gab do you know if this was done during the mojo-ification?). @pbommana Can you link me to the test case which documents the expected behavior? I might be able to find it easier with the expected strings.
,
Apr 4 2018
Apologize for the confusion where I mixed with CRX validation with Settings hardening bubble. There shouldn't be any bubble on launch it's only when user navigates to "Chrome://settings".
,
Apr 4 2018
No problem. This only leaves the unexplained Scenario 1 from Comment #4. Could you try it again if you have the time? It's weird that the homepage stayed at the good value before the modification. Maybe the secure preferences file wasn't saved properly after the modification? Thanks!
,
Apr 4 2018
Tested this on multiple machines and can confirm that I was able to see "Some settings were reset" dialog when homepage is modified under "Secure Preferences" file. proberge@ you are right this might be the file wasn't saved properly. Thank you again.
,
Apr 5 2018
Thanks for the update. Marking as WontFix - intended behavior. |
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by csharp@chromium.org
, Apr 3 2018