Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

BrowserAudit - 3 critical problems #4504

Closed
CHEF-KOCH opened this issue May 20, 2019 · 5 comments
Closed

BrowserAudit - 3 critical problems #4504

CHEF-KOCH opened this issue May 20, 2019 · 5 comments

Comments

@CHEF-KOCH
Copy link

@CHEF-KOCH CHEF-KOCH commented May 20, 2019

Description

Brave Browser is the only Browser (I tested) which has 3 critical security errors/hits. I tested Firefox, Opera, Chrome, Edge & Chromium Edge (Beta) and all of them pass the test.

Steps to reproduce the issue:

  1. Visit https://browseraudit.com/test
  2. Run the test, which takes a while.
  3. You'll see 3 critical hits in the red box, after the test is finished you can review it which says that there are DOM related security problems.
  4. Brave Shields settings are set to block ads, block third-party cookies & fingerprinting, HTTPSE is enabled (script blocking is disabled to avoid getting "strange" results).

Actual result:

Audit
sffsfsd

Expected result:

Brave should not get any critical hit on the test, however I'm not sure how reliable the test page is but since no other of my tested Browser shows a critical hit I think that should be fixed.

Reproduces how often:

Each time you run the test you will see 3 critical flaws.

Brave version (brave://version info)

  • Version 0.64.76 Chromium: 74.0.3729.157 (Official Build) (64-bit)
  • The issue did not appeared on a build which I tested earlier this year, 12. April - dunno which one it was (sorry).

Version/Channel Information:

  • Windows 10 1903 Ent.
  • I did not reproduce the issue in any non stable build but I assume the result will be the same.
@diracdeltas
Copy link
Member

@diracdeltas diracdeltas commented May 20, 2019

I tried it on the same version (same shield settings too) but with MacOS instead of windows and got 0 critical issues. do you happen to have any extensions installed?
Screen Shot 2019-05-20 at 11 41 52 AM

@yrliou
Copy link
Member

@yrliou yrliou commented May 20, 2019

Tried on Windows 10 but couldn't reproduce on my end on the same version.
Screen Shot 2019-05-20 at 12 00 08 PM

@CHEF-KOCH
Copy link
Author

@CHEF-KOCH CHEF-KOCH commented May 20, 2019

Thanks for the confirmation. Apparently some flags triggering critical problems in the Browser Audit test. E.g. setting #allow-sxg-certs-without-extension to disabled causes one critical error. There are bunch of other settings which might caused my other two critical errors. I already reset all flags now (just in case) and do some further tests.

I was not aware that disabling these flags which are marked with "Enabling this may pose a security risk" are "critical", because that was the reason in the first place why I disabled them.

Theoretically such flags should be removed in order to avoid such problems but I understand that for test reasons etc they are maybe necessary.

@CHEF-KOCH CHEF-KOCH closed this May 20, 2019
@srirambv
Copy link
Collaborator

@srirambv srirambv commented May 20, 2019

Cant reproduce on Windows

With default shields
image

With all fingerprint disabled
image (1)

@diracdeltas
Copy link
Member

@diracdeltas diracdeltas commented May 20, 2019

I was not aware that disabling these flags which are marked with "Enabling this may pose a security risk" are "critical", because that was the reason in the first place why I disabled them.

I wonder if this should be reworded to "setting a non-default setting may pose a security risk." Not sure since we inherited this wording from Chrome

@NejcZdovc NejcZdovc added this to the Dupe / Invalid / Not actionable milestone Jun 3, 2019
@bbondy bbondy removed this from the Dupe / Invalid / Not actionable milestone May 30, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Linked pull requests

Successfully merging a pull request may close this issue.

None yet
7 participants
You can’t perform that action at this time.