Proposal to extend the chrome.enterprise.deviceAttributes API

62 views
Skip to first unread message

Pavol Marko

unread,
Jan 19, 2018, 5:16:03 PM1/19/18
to apps-dev, Security Enamel, R.Devlin Cronin, Kush Sinha, Julian Pastarmov, Maksim Ivanov, David Karam
Hi all,

We're proposing to extend the Chrome OS-only enterpise API chrome.enterprise.deviceAttributes.
In short: We'd like to add read-only access to the device Serial Number and administrator-set Asset ID to policy force-installed extensions on affiliated user sessions.

The full proposal is here:

Please let me know what you think!

Thanks,
Pavol 

Devlin Cronin

unread,
Jan 31, 2018, 10:58:29 AM1/31/18
to Pavol Marko, Emily Stark, Mustafa Emre Acer, apps-dev, Security Enamel, Kush Sinha, Julian Pastarmov, Maksim Ivanov, David Karam
This LGTM (and is in review here: https://chromium-review.googlesource.com/c/chromium/src/+/876365).

+meacer@ or +estark@, mind giving this a quick once-over from a security perspective?  (I don't see anything worrisome, but just to be sure)

Pavol Marko

unread,
Feb 2, 2018, 4:54:56 AM2/2/18
to Devlin Cronin, Emily Stark, Mustafa Emre Acer, apps-dev, Security Enamel, Kush Sinha, Julian Pastarmov, Maksim Ivanov, David Karam
Friendly ping :-)

Pavol Marko

unread,
Feb 6, 2018, 3:47:59 AM2/6/18
to Devlin Cronin, Emily Stark, Mustafa Emre Acer, apps-dev, Security Enamel, Kush Sinha, Julian Pastarmov, Maksim Ivanov, David Karam
Hey all, I'd like to proceed with this extension of the deviceAttributes API tomorrow if there's no pushback.

Thanks!

Mustafa Emre Acer

unread,
Feb 6, 2018, 2:11:55 PM2/6/18
to Pavol Marko, Devlin Cronin, Emily Stark, apps-dev, Security Enamel, Kush Sinha, Julian Pastarmov, Maksim Ivanov, David Karam
Apologies for the delay.

From a security point of view the changes (adding getters for serial number and asset ID) look okay as this will be restricted to enterprise enrolled devices.

However, you might want to get an opinion from the privacy team as well, since the serial number is a unique identifier.

--
You received this message because you are subscribed to the Google Groups "apps-dev" group.
To unsubscribe from this group and stop receiving emails from it, send an email to apps-dev+unsubscribe@chromium.org.

Pavol Marko

unread,
Feb 19, 2018, 9:43:19 AM2/19/18
to Mustafa Emre Acer, Devlin Cronin, Emily Stark, apps-dev, Security Enamel, Kush Sinha, Julian Pastarmov, Maksim Ivanov, David Karam
Hi Mustafa,

One of the results from the privacy review was that we now have an extension api modifcation tracking bug (!= launch bug) for this.

Thanks!

Pavol Marko

unread,
Feb 20, 2018, 5:41:14 AM2/20/18
to Mustafa Emre Acer, Devlin Cronin, Emily Stark, apps-dev, Security Enamel, Kush Sinha, Julian Pastarmov, Maksim Ivanov, David Karam, extension-...@chromium.org, Thiemo Nagel
Reply all
Reply to author
Forward
0 new messages