← Back to release summary

Block ports 989 and 990

Category
Network / Connectivity
Type
No developer-visible change
Status
Enabled by default (Chrome 93)
Intent stage
Shipped

Summary

Connections to HTTP, HTTPS or FTP servers of ports 989 and 990 will fail. These ports are used by the FTPS protocol, which has never been implemented in Chrome. However, FTPS servers can be attacked in a cross-protocol attack by malicious web pages using carefully-crafted HTTPS requests. This is a mitigation for the ALPACA attack. See https://alpaca-attack.com/.

Standards & signals

View on chromestatus.com