Skip to content

I'm confused about why SetInternetZoneIdentifier was removed #491

@delhi2050

Description

@delhi2050

On Windows, when using Edge or Chrome, after downloading an executable you cannot run it directly. Instead a security warning pops up, and in the file's Properties you can see a line saying "This file came from another computer and might be blocked to help protect this computer."

With Chromium, that security warning does not appear. I noticed that in disable-download-quarantine.patch the part that sets the Zone.Identifier was removed.

When a malicious executable is downloaded without the user explicitly initiating it, there is often a popup in the top-right corner. It's very easy to accidentally click that download entry and thereby run the malicious program directly.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions