[HN Gopher] New Google Chrome feature blocks attacks against hom...
___________________________________________________________________
New Google Chrome feature blocks attacks against home networks
Author : Wasserpuncher
Score : 37 points
Date : 2024-02-17 18:27 UTC (4 hours ago)
(HTM) web link (www.bleepingcomputer.com)
(TXT) w3m dump (www.bleepingcomputer.com)
| Despegar wrote:
| New Google Chrome feature blocks attacks from something websites
| shouldn't be able to access in the first place.
| redder23 wrote:
| Well have you looked at the example? Browsers should be able to
| a access anY IP on the LAN. If that url is not password
| protected and let you just change settings via URL its really
| not the browsers fault for supposedly "giving access". Well
| thinking about it, it should probably not be possible in an
| iframe but they would just trick you clicking a link instead.
| People to not secure their routers and have default passes that
| is the big issue here. So of course them mitigating that makes
| sense.
|
| Simple never giving access would mean people can not open their
| router interfaces, self hosted stuff on SBCs ... so you make no
| sense.
| betaby wrote:
| > People to not secure their routers and have default passes
| that is the big issue here.
|
| Is it really? ISPs in USA/Canada/France/etc give customers
| WiFi routers with random passwords for many years.
| rnmmrnm wrote:
| It's easy to be smart about it after the fact. Back then it was
| hard to tell WWW is gonna be the the standard protocol for most
| people to interact with the internet.
| blacksmith_tb wrote:
| And it doesn't even block, it preflights the requests, and if
| the device exists and responds, it will only block if the
| device sets a special header? Which of course no existing
| devices will, so it's going to do very little good - nothing
| for existing IoT gear, and likely not much more for new
| devices, unless all those manufacturers rapidly embrace setting
| the new header. To me it seems like it'd be a far more obvious
| approach to just throw up a dialog that says "the current page
| wants to connect to things on your home network, does that seem
| reasonable to you, or should I continue to block that?"
| ublocker wrote:
| 1. Force uBlock Origin out.
|
| 2. Reimplement its features selectively.
|
| uBlock Origin comes with a filter called 'Block Outsider
| Intrusion into LAN'[0].
|
| [0]
| https://github.com/uBlockOrigin/uAssets/blob/master/filters/...
|
| Migrate to Firefox and install uBlock Origin, you will have this
| feature and more.
| charcircuit wrote:
| Chrome has had a builtin ad blocker for years.
| ssss11 wrote:
| I know nothing of this Chrome ad blocker, but you have to ask
| yourself, is it really an ad blocker if it's owned and
| maintained by the largest adtech company on earth hellbent on
| maximising profits from ads?
| charcircuit wrote:
| Yes, it's in Google's best interest to maximize the amount
| of time they spend on the web, doing searches, to go to
| different websites. Websites with spammy ads can cause
| people to use the web less, causing them to search less,
| causing Google to be able to show less advertisements.
| cqqxo4zV46cp wrote:
| I'd probably base my determination more on its actual
| functionality in practice, rather than soapboxing by a
| drive-by commenter that themselves admits that they haven't
| used it.
|
| I'm not even a Chrome user, but come on...
| not_really wrote:
| No, you come on. Chrome's "ad blocker" is objectively
| laughable, and the person you are responding to is
| pointing out that additionally there is a conflict of
| interest. Wouldn't matter even if the functionality was
| at parity with Ublock.
___________________________________________________________________
(page generated 2024-02-17 23:01 UTC)