However, there are instances where you need to allow a plugin full access. Say, for instance, when a plugin needs to install a necessary piece of software so that a website can function properly. If said plugin is fully sandboxed, that installation won’t be allowed.
Out of the box Chrome OS is set to ask you when a site wants to use a plugin to access your computer. That’s a fairly safe setting. You certainly don’t want to disable that and allow every site to run all plugins unsandboxed, as that would cause a serious security issue.
However, thanks to the Chrome OS developers, you can blacklist and whitelist sites. As you might expect, a blacklist site can’t use unsandboxed plugins, whereas a whitelist site can. This is especially helpful when you know of a particular site that must use a plugin to gain full access to your computer.
SEE: Cybersecurity strategy research: Common tactics, issues with implementation, and effectiveness (Tech Pro Research)
How do you do this? It’s actually quite simple.
How to find the setting
Finding the location in the Chrome OS settings is pretty straightforward. Do the following:
- Click on the system tray.
- Click on the gear icon.
- When the Settings window opens, scroll to the bottom and click Advanced.
- Locate Content settings, and then click on the right-pointing arrow (Figure A).
- Scroll down and click Unsandboxed plugin access.
How to blacklist a site
Because of the way Chrome OS is set up, every time a site wants to allow an unsandboxed plugin to gain access to your system, it will ask if you want to okay that. Such behavior can get pretty annoying, especially when you already know which sites you want to deny access. For that, you can blacklist sites. To do this, click the Add button associated with Block (Figure B).
In the resulting pop-up (Figure C), add the site address. If you want to block an entire domain, you cannot use wildcards, such as *.baddomain.com (where baddomain.com is the domain address to be blocked).
Instead, you can either enter baddomain.com (which will be seen as a domain) or enter each URL separately, such as www.baddomain.com, mail.baddomain.com, ftp.baddomain.com, etc.
Once you’ve added the URL (or domain), click Add and you’re finished. Repeat this process for every URL/domain you want to block.
How to whitelist a site
To whitelist a site use the same process, only click the Add button associated with Allow. Add the sites in similar fashion. Click Add when you done. Rinse, wash, repeat until you have all of the necessary sites whitelisted.
At this point, every site/domain you’ve blacklisted will no longer allow (or ask you if you want to allow) unsandboxed plugins, whereas every site/domain you’ve whitelisted will allow (without asking) unsandboxed plugins.
It is important that you use this feature wisely. Do not whitelist any site/domain unless you know (without a doubt) that it can be trusted.