Wilders Security Forums  

Go Back   Wilders Security Forums > Privacy Related Topics > privacy technology
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old August 15th, 2012, 02:48 PM
Gnikf Gnikf is offline
Infrequent Poster
 
Join Date: Aug 2012
Posts: 40
Default Chrome - security/privacy extension

Since there is a thread about Firefox lets see what analogs we've got for Chrome.

I would start with
Use HTTPs - even if right now it works just for facebook and twitter out of the box
  #2  
Old August 15th, 2012, 04:35 PM
Pinga's Avatar
Pinga Pinga is offline
Frequent Poster
 
Join Date: Aug 2006
Location: Europe
Posts: 941
Default Re: Chrome - security/privacy extension

I thought you'd never ask!

http://www.wilderssecurity.com/showthread.php?t=263095
__________________
The really important kind of freedom involves attention, and awareness, and discipline, and effort, and being able truly to care about other people and to sacrifice for them, over and over, in myriad petty little unsexy ways, every day.
- David Foster Wallace
  #3  
Old August 15th, 2012, 05:26 PM
Ring0's Avatar
Ring0 Ring0 is offline
Regular Poster
 
Join Date: Aug 2010
Posts: 66
Default Re: Chrome - security/privacy extension

HSTS is HTTPS Strict Transport Security: a way for sites to elect to always use HTTPS.

Typing chrome://net-internals/ into your address bar, and then include HSTS menu item.

Add domain (example.com) paypal.com, google.com, ......

To delete: Delete domain (example.com) paypal.com, google.com,......
__________________
We secure the world ;-)
  #4  
Old August 15th, 2012, 05:39 PM
Kees1958's Avatar
Kees1958 Kees1958 is offline
Massive Poster
 
Join Date: Jul 2006
Posts: 5,857
Default Re: Chrome - security/privacy extension

Quote:
Originally Posted by Ring0
HSTS is HTTPS Strict Transport Security: a way for sites to elect to always use HTTPS.

Typing chrome://net-internals/ into your address bar, and then include HSTS menu item.

Add domain (example.com) paypal.com, google.com, ......

To delete: Delete domain (example.com) paypal.com, google.com,......

Simply brilliant find thx to one who searchers
  #5  
Old August 15th, 2012, 07:11 PM
m00nbl00d m00nbl00d is offline
Incredibly Massive Poster
 
Join Date: Jan 2009
Posts: 6,550
Default Re: Chrome - security/privacy extension

Quote:
Originally Posted by Ring0
HSTS is HTTPS Strict Transport Security: a way for sites to elect to always use HTTPS.

Typing chrome://net-internals/ into your address bar, and then include HSTS menu item.

Add domain (example.com) paypal.com, google.com, ......

To delete: Delete domain (example.com) paypal.com, google.com,......

That built-in function isn't that useful. First, for security reasons what ever you add to it, will only be valid for as long as the session lasts. Second, if you add a *.domain to it, then it will force every sub-domain. Many domain's sub-domains do not have a working HTTPS version, hence it will result in error.

We're better off with something like HTTPS Everywhere/similar.
  #6  
Old August 16th, 2012, 05:06 AM
Gnikf Gnikf is offline
Infrequent Poster
 
Join Date: Aug 2012
Posts: 40
Default Re: Chrome - security/privacy extension

Quote:
Originally Posted by Pinga


this thread seems to be for all kinds of plug-ins an is from 2010
lets focus on security/privacy ones here
  #7  
Old August 16th, 2012, 10:08 AM
Ring0's Avatar
Ring0 Ring0 is offline
Regular Poster
 
Join Date: Aug 2010
Posts: 66
Default Re: Chrome - security/privacy extension

Quote:
First, for security reasons what ever you add to it, will only be valid for as long as the session lasts.

I'm sorry, I thought you knew, you can make your *.json file, or download this and add your *.domain manually.
http://code.ohloh.net/file?fid=CL0Ms...rowser=Default

Quote:
Second, if you add a *.domain to it, then it will force every sub-domain. Many domain's sub-domains do not have a working HTTPS version, hence it will result in error.

No, If Include subdomains: not checked = include_subdomains:false
__________________
We secure the world ;-)
  #8  
Old August 16th, 2012, 11:19 AM
m00nbl00d m00nbl00d is offline
Incredibly Massive Poster
 
Join Date: Jan 2009
Posts: 6,550
Default Re: Chrome - security/privacy extension

Quote:
Originally Posted by Ring0
I'm sorry, I thought you knew, you can make your *.json file, or download this and add your *.domain manually.
http://code.ohloh.net/file?fid=CL0Ms...rowser=Default


Yeah, I think I came across an example like that before. But, I believe the security principle behind it is the same. There's a good reason why HSTS doesn't keep entries beyond Chrome's session. I've read a thread over Chromium's own forum sometime ago; will have to see if I can find it again.

I don't think having a JSon file would change that security risk?


Quote:
No, If Include subdomains: not checked = include_subdomains:false

You're right, but if we do check the Include subdomains: option, then it will force all subdomains to default to HTTPS, and many website's subdomains do not have an HTTPS version, and the user will have to manually remove each entry that may be necessary.

To have all this trouble, I rather - and I do use - use HTTPS Everywhere, and add any additional rules to the settings file, by creating regexes.

Another good extension, for those not wanting to edit HTTPS Everywhere rules settings file, is Redirector.
  #9  
Old August 19th, 2012, 12:59 AM
ComputerSaysNo ComputerSaysNo is offline
Very Frequent Poster
 
Join Date: Aug 2012
Posts: 1,086
Default Re: Chrome - security/privacy extension

HTTPS Everywhere (still in alpha stage)
ScriptNo
Adblock Plus + Adblock Element Hider
Ghostery
Do not Track Plus
User Agent Changer (About 10 different ones available if you search)
VirusTotal uploader
Dr Web Link Checker
AVG Link Checker
  #10  
Old August 19th, 2012, 12:38 PM
Ring0's Avatar
Ring0 Ring0 is offline
Regular Poster
 
Join Date: Aug 2010
Posts: 66
Default Re: Chrome - security/privacy extension

Quote:
Originally Posted by m00nbl00d
Another good extension ......

Configuring hsts data, I find this way sexier.

When using private browsing mode, hsts won't record any new hsts data.
When you choose "Clear browsing data" and "Empty the cache" is checked, hsts data will be erased (TransportSecurity-file) from your profile.

To prevent this, find > profile > "TransportSecurity" file and set attributes: read only, after you have imported all desired *.domain.
__________________
We secure the world ;-)
 

Wilders Security Forums > Privacy Related Topics > privacy technology « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 01:47 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums