New Update Chrome Galvanizer - Harden your Chrome browser via enterprise policy against extension backdoors and exploits

9724anon7537

Level 2
Thread author
Verified
Jun 12, 2018
65
Summary
Chrome Galvanizer is a tool to generate Chrome enterprise policies to help users harden their browser security. Currently, the main support is for generating policies to restrict extension access from sites explicitly marked as sensitive (e.g. your email, bank, cryptocurency, and other sites). This allows you to prevent extensions from accessing these specific sites even if you've already granted them permission to do so when first installing them.

What does this protect against?
This protects from hijacked extensions with backdoored updates and against extensions that have been exploited due to a security vulnerability in their code.

One good example of the former type of attack this protects against is the case of the MEGA Chrome extension getting hacked. Basically, the account which publishes the MEGA extension likely was phished, the result being that a backdoored extension update was pushed out to all extension users (millions). Per MEGA's statement the extension keylogged and stole “credentials for sites including amazon.com, live.com, github.com, google.com (for webstore login), myetherwallet.com, mymonero.com, [and] idex.market.”

Using Chrome Galvanizer, you can protect yourself from attacks like this by specifying specific sites that one or all of your extensions can no longer access. For the MEGA case, if users had created a policy restricting access for the MEGA extension to access amazon.com, live.com, github.com, google.com, myetherwallet.com, mymonero.com, and idex.market then they'd be protected from the attack.

You can even configure policies that only allow an extension to access a specific whitelist of sites instead of just blacklisting sensitive ones. This is useful if you have an extension you want to use for a set of sites but not the rest of the web. Of course, you can also layer these policies to get even better results.


 

Lenny_Fox

Level 22
Verified
Top Poster
Well-known
Oct 1, 2019
1,120
It is useful extension, This extension (Galvaniser) adds the option for tweaking the policies for people not daring or knowing how to set these policies with regedit.exe in the Registry

Another idea is to use two profiles (as I use for Edge-Chromium)
  • Default settings profile which I use for banking and (Microsoft) team meetings with (panda bear icon)
    a) default site settings (allow or ask)
    b) anti-tracking on BASIC and smartscreen ON
    c) no extensions

  • Hardened settings profile, which I use for surfing the with (astronaut icon)
    a) hardened site settings (block or ask)
    b) anti-tracking OFF and smartscreen OFF
    c) Adguard extension (with Phishing and Malware protection) and Blank Tab

Edge://flags and Edge://policy always apply to all profiles, so be carefull not to tweak to much to loose compatibility.

In Edge you can choose which profile to use for links, see picture
1589698602463.png


For edge, type edge://policy to display policies enabled (see Microsoft documentation for registry keys -> link)

1589704672360.png
 
Last edited:

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top