|
|
Subscribe / Log in / New account

Chromium suddenly starts downloading a binary blob

Chromium suddenly starts downloading a binary blob

Posted Jun 18, 2015 22:14 UTC (Thu) by josh (subscriber, #17465)
Parent article: Chromium suddenly starts downloading a binary blob

While this is definitely a Free Software issue, in that a Free Software browser should not be silently downloading and installing a proprietary blob (*especially* when the user isn't actually using that functionality), it isn't a security issue at all.

Unlike Flash and other plugins, Native Client is sandboxed. Barring a sandbox-escape bug in NaCl (which would be a critical security bug in Chrome), the extension in question could not run arbitrary code on the system.


to post comments

Chromium suddenly starts downloading a binary blob

Posted Jun 23, 2015 11:03 UTC (Tue) by nix (subscriber, #2304) [Link]

It can't run arbitrary code, but the browser explicitly grants it permission to listen to the microphone and talk to the network! I'd call that a pretty big permission. (One that it obviously needs in order to do its job, but still.)


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds