Jump to content

Recommended Posts

Posted (edited)

I was wondering if anyone knows why users can download and install google chrome on our machines?

 

For a start, why is smoothwall allowing this through?

 

I have found out that it is installing chrome to C:\users\{username}\appdata\google\chrome. Why would google allow this to happen?

 

Does anyone have a way to stop this?

Edited by timbo343
Posted

It installs into the profile not onto the program files etc

 

My old hack around it was to setup in the AV software to auto delete anything called chrome.exe :)

  • Thanks 1
Posted
I was wondering if anyone knows why users can download and install google chrome on our machines?

 

For a start, why is smoothwall allowing this through?

 

I have found out that it is installing chrome to C:\users\{username}\appdata\google\chrome. Why would google allow this to happen?

 

Does anyone have a way to stop this?

 

Google actually designed it this way to get around locked down accounts so that users could bypass the wishes of the business that they were emploied by. This I find massivly smarmy to start with. Almost worse is that because it sits in the profile and updates every 26 seconds it can end up using lots of bandwidth and expanding user profile size, users then start wineing that it is slow - their own fault etc.

 

There is applocker or program restrictions that you can run through GPO which can prevent programs from running from certain locations or with certain names. This could be a goo way to stop the dirty thing.

  • Thanks 1
Posted
Why not just install it if your users want it?

 

I agree with this - technically as it uses IE proxy they shouldn't be able to change this and it shouldn't affect them although compatibility issues could be had.

Posted
Google actually designed it this way to get around locked down accounts so that users could bypass the wishes of the business that they were emploied by.

 

Allowing users to install stuff in /home/user is pretty standard practice on anything non-windows. It's not a conspiracy.

Posted
download the msi from chrome - they also have adms you can download to control it in active directory - we give users chrome and internet explorer
Posted (edited)
Why not just install it if your users want it?

 

Im not sure impero works with it? @russdev

 

We tried blocking the internet with impero as a group and they could still access the net.

 

I personally think they are looking at trying to get around our filtering. I have also blocked dl.google.com for users too.

Edited by timbo343
Posted
I agree with this - technically as it uses IE proxy they shouldn't be able to change this and it shouldn't affect them although compatibility issues could be had.

 

We do for some individuals but it frankly is a pain compatibility wise, persists in its mental update cycle, tries to build in everything including the kitchen sink. Funny how to make the web browser the answer they have to copy and build in every single answer into it (PDF, Flash, new protocols). It also persists in trying to get you to sign it into google, there is a corporate version but from all accounts it is a pain to get it to push out without it choking over updates or similar.

Posted
Im not sure impero works with it? @russdev

 

We tried blocking the internet with impero as a group and they could still access the net.

 

I personally think they are looking at trying to get around our filtering. I have also blocked dl.google.com for users too.

 

You should block internet access at the network level - on the firewall - client based security isn't such a good plan.

Posted
Allowing users to install stuff in /home/user is pretty standard practice on anything non-windows. It's not a conspiracy.

 

But it is against the way Windows was intended to handle such things, it behaves like malware and why should Windows be Linux. For the environment it is targeted at it is skirting the rules and the mere fact they targeted it to get around the wishes of the organsations that own the computers in the first place is a tad less than ethical.

Posted
Software Restriction Policy -> New Hash Policy -> Chrome.exe ?

 

Rename to MyCoolNotAWebBrowser.exe and run, done. Block the whole temp folder (for limited users), it is a security risk anyway as it is where half of the malware nests.

Posted
Why not just install it if your users want it?

 

That's fine but with the managed MSI installer, ADMs and internal update source rather than hundreds (or thousands) of machines hammering the Internet connection for auto updates. Skype used to be another culprit of this.

Posted
But it is against the way Windows was intended to handle such things, it behaves like malware and why should Windows be Linux. For the environment it is targeted at it is skirting the rules and the mere fact they targeted it to get around the wishes of the organsations that own the computers in the first place is a tad less than ethical.

 

Its for home users. There's an MSI and group policy for organisations

 

Block the whole temp folder (for limited users), it is a security risk anyway as it is where half of the malware nests.

That would be against how windows is intended to handle things.

Posted
Rename to MyCoolNotAWebBrowser.exe and run, done. Block the whole temp folder (for limited users), it is a security risk anyway as it is where half of the malware nests.

 

 

Not with a hash policy - you can name it anything you want - but it wont change the hash value, so will still be blocked!

Posted (edited)
That would be against how windows is intended to handle things.

 

But nessisary for limited users when programs blatently abuse the privilage, just restoring the natural order and making sure that users don't stuff their profiles full of malware and cack then come complaining that they can't use CoolSmileyFaceBrowserX to do their rolls and complaining that their email has been hacked.

 

If the goal is to have a standard working system that people can actually use to get their work done you want to exert at least some control. If you just want to provide your users with whatever baubels they can be tricked into installing then that is your perogative.

 

Not with a hash policy - you can name it anything you want - but it wont change the hash value, so will still be blocked!

 

As above chrome updates every few days so the hash will change each time, you'll spend your whole life chasing file hashes for their latest capitilisation or logo change.

Edited by SYNACK
Posted

not had problem with updates - though it is supposed to update automatically.

It does work with impero - on workstation settings on groups - take tick out of only filter internet explorer traffic.

  • Thanks 1
Posted
Im not sure impero works with it? @russdev

 

We tried blocking the internet with impero as a group and they could still access the net.

 

I personally think they are looking at trying to get around our filtering. I have also blocked dl.google.com for users too.

 

Impero will work with chrome have to in group settings turn offf Filter Only Internet Explorer.

 

Russ

  • Thanks 1
Posted

Setting the SRP to white list and allow things like %program files% and %windir% only, blocking everything else will do what you want. This will block anything in their profiles, flash drives, and temp folders. This way your not chasing a hash or wondering if the user renamed it.

 

We are a Google apps school so chrome is recommended. I push out the MSI and use the adm files to set the homepage and block automatic updates.

 

All these settings have worked well for me.

Posted

We have installed the network MSI version, for everyone to use.

 

Don't worry about it they can't use it to bypass any web filtering, as it uses IE proxy.

Posted

We set up a software restriction policy to prevent any executable running from C:\Users\%USERNAME%\ so even if they do manage to install Chrome, they cannot run it.

 

We do have the networked version already installed on our image with gpos controlling some parts of it, so I am not too sure why some of users try to download it again!

Posted

I dislike Google Chrome for this, I have been trying for a while to stop Students from installing other Browsers..

 

I have added all the executables like Chrome.exe to the 'Don't run specified Applications' GPO.. This works most of the time unless they rename it..

 

Now we have quick computers with Windows 7 and IE9 in the majority of the school, students don't bother as much to install 'quicker' browsers. Plus everything we have in school like OWA and Frog etc is designed to run on Internet Explorer so this puts them off too.

 

It still really annoys me when they install any software that isn't something we put on and I don't want to install alternative browsers on the computers because it conflicts with IE and causes problems (I've tried).

 

Grrr.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...