Live data from Hacker News

Ask HN: Is Google Chrome's autotranslate feature a huge vulnerability?

news.ycombinator.com

11–18 of 18 posts

Re: Ask HN: Is Google Chrome's autotranslate feature a huge vulnerability?

#11
post #8

Google translate refuses to work on private pages. It's actually kind of annoying, but yeah, anything past a login it refuses to do. At least for my bank and anything bill related.

As another data point, Google happily translates my bank account.

Re: Ask HN: Is Google Chrome's autotranslate feature a huge vulnerability?

#12
If you ask a person or a service to translate things that person can of course see these things.

If your connection to that service is not secured others may be able to intercept it. Chances are that it is though. Google Translate uses secure connections.

Re: Ask HN: Is Google Chrome's autotranslate feature a huge vulnerability?

#14
End to end encryption seems to be less understood by many people, even some professionals I know. HTTPS is completely secure, check this out, it's a fun read: https://en.m.wikipedia.org/wiki/Public-key_cryptography

The real question is perhaps, are we okay with Google having their eyes on everything?

Re: Ask HN: Is Google Chrome's autotranslate feature a huge vulnerability?

#15

End to end encryption seems to be less understood by many people, even some professionals I know. HTTPS is completely secure, check this out, it's a fun read: https://en.m.wikipedia.org/wiki/Public-key_cryptography The real question is perhaps, are we okay with Google having their eyes on everything?

Is that even the real question? If you are using chrome to visit your bank you are already assuming that Google isn't behaving badly. Your threat model changes very little when sending page contents to be translated.

Re: Ask HN: Is Google Chrome's autotranslate feature a huge vulnerability?

#16

End to end encryption seems to be less understood by many people, even some professionals I know. HTTPS is completely secure, check this out, it's a fun read: https://en.m.wikipedia.org/wiki/Public-key_cryptography The real question is perhaps, are we okay with Google having their eyes on everything?

Is that even the real question? If you are using chrome to visit your bank you are already assuming that Google isn't behaving badly. Your threat model changes very little when sending page contents to be translated.

You can track what comes and goes on your network, if chrome sends information about random pages back snoop on, then I think that quite certainly would have been whistleblown by now.

Sending a webpage ourselves directly to google is a completely different story. We have no idea what goes on with your data behind their servers. But we can monitor what goes on in our own machines.

Also, funny how we've come to the point that we're using the term threat model to describe our relationship with the beloved Google.

Re: Ask HN: Is Google Chrome's autotranslate feature a huge vulnerability?

#17
Not directly answering your question but stil relevant. At a fairly big company I worked at as a student I was able to circumvent the website blocker of the company by just applying google translate to the site. Formatting and images etc. were lost but it enabled me to browse reddit.

Re: Ask HN: Is Google Chrome's autotranslate feature a huge vulnerability?

#18
1.) I don't know, but that's fucking cool.

2.) You should follow rahimmathwani's advice and set up a man in the middle attack. You'll learn a lot.

3.) Have I mentioned that is fucking cool???

Good work! This is the exact kind of question that everyone should ask.

PS - That is fucking cool!

Post reply on HN