Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 451514 - remove chromium unsafe port feature
Summary: remove chromium unsafe port feature
Status: RESOLVED WONTFIX
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: New packages (show other bugs)
Hardware: All Linux
: Normal normal
Assignee: Chromium Project
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2013-01-12 11:42 UTC by Tomáš Chvátal (RETIRED)
Modified: 2013-01-15 03:44 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Tomáš Chvátal (RETIRED) gentoo-dev 2013-01-12 11:42:20 UTC
Hi guys,

As already discussed bit back on irc chromium has idiotic feature which bans you from connecting to "ports that they deemed unsafe".

This creative idea can be overriden with on-launch argument passing where you can tell your explicit port is in reality safe, but still you have to do it prior launching the chromium. Which makes me every time close all the stuff i have open and start over :/

Easiest approach would be just disabling the feature as whole.
Comment 1 Mike Gilbert gentoo-dev 2013-01-14 18:56:22 UTC
I have mixed feelings on this. On the surface, it certainly seems like a stupid feature to me. If I were affected by it, I would probably have patched it out already.

Can we dig up some history as to why it was implemented in the first place?
Comment 2 Tomáš Chvátal (RETIRED) gentoo-dev 2013-01-14 20:47:42 UTC
Can't find it, but someone from the herd once showed me the bug.
Comment 3 Mike Gilbert gentoo-dev 2013-01-14 21:21:36 UTC
It probably originates from Firefox, which implemented it as a workaround for a "cross-protocol scripting" vulnerability.

http://www-archive.mozilla.org/projects/netlib/PortBanning.html

So, unless you know that Chromium has some other safeguard in place for this, I don't think disabling the blacklist entirely would be a good idea.

You could always whitelist the ports you need by using the explicitly-allowed-ports command line option in /etc/chromium/default. Just set it and forget it.
Comment 4 Mike Gilbert gentoo-dev 2013-01-14 21:25:54 UTC
Given the date, I guess it was probably first implemented in Mozilla; Firefox did not yet exist.
Comment 5 Paweł Hajdan, Jr. (RETIRED) gentoo-dev 2013-01-15 03:44:05 UTC
(In reply to comment #0)
> As already discussed bit back on irc chromium has idiotic feature which bans
> you from connecting to "ports that they deemed unsafe".

This is definitely not something we should do as distro maintainers. And this is just asking for someone calling us idiots for disabling security features (I'm putting aside whether they work, and whether the general security model of the web is broken or not).

Feel free to raise that as an upstream issue though. Feel free to contact me (or the herd maintainers) off-bugzilla about this.