Spectroscope

Search for endpoints potentially vulnerable to Spectre.

What is Spectroscope?

Spectroscope is a Chrome extension developed by Lukas Weichselbaum, and its main feature is "Search for endpoints potentially vulnerable to Spectre.".

Extension Screenshots

screenshot
screenshot
screenshot
screenshot
screenshot

Download Spectroscope Extension CRX File

Download Spectroscope extension files in crx format, manually install Chrome extensions in the browser, or share the crx files with friends to easily install Chrome extensions.

Extension Usage Instructions

                        Spectroscope is a prototype extension for security engineers and web developers to help track down application resources which aren't protected from being embedded by other websites. Such resources can, in some cases, be exfiltrated by malicious sites making use of CPU-level information leaks on users' devices, such as the Spectre vulnerability.

The tool identifies resources which are exempt from default protections enabled in Google Chrome (Cross-Origin Read Blocking, SameSite cookies) and which can be embedded cross-site. The results are added to Chrome's DevTools "Spectroscope" panel and include security recommendations to help protect your resources from Spectre and other cross-site attacks.

Note: This is a prototype extension which is meant to be used only as a convenience tool to help you protect your site; it is not an official Google product. Testing your site with Spectroscope is not a substitute for careful deployment of recommended web security features. See https://w3c.github.io/webappsec-post-spectre-webdev/ for a complete list of best practices.

Authors (alphabetically): Roberto Clapis, Santiago Diaz, Aleksandr Dobkin, David Dworken, Artur Janc, Aaron Shim, Lukas Weichselbaum                    

Extension Basic Information

Name Spectroscope Spectroscope
ID idppnaadbabknjeaifkegolcciafchpp
Official URL https://chromewebstore.google.com/detail/spectroscope/idppnaadbabknjeaifkegolcciafchpp
Description Search for endpoints potentially vulnerable to Spectre.
File Size 5.5 MB
Installation Count 232
Current Version 0.1.0
Last Updated 2021-08-19
Publish Date 2021-03-07
Rating 5.00/5 Total 2 Ratings
Developer Lukas Weichselbaum
Email [email protected]
Payment Type free
Supported Languages en
manifest.json
{
    "update_url": "https:\/\/clients2.google.com\/service\/update2\/crx",
    "name": "Spectroscope",
    "version": "0.1.0",
    "description": "Search for endpoints potentially vulnerable to Spectre.",
    "icons": {
        "128": "icon128.png"
    },
    "manifest_version": 2,
    "devtools_page": "devtools.html",
    "permissions": [
        "cookies",
        "http:\/\/*\/*",
        "https:\/\/*\/*",
        "storage"
    ],
    "background": {
        "persistent": false,
        "scripts": [
            "background.js"
        ]
    }
}