Live data from Hacker News

An iframe from googlesyndication.com tries to access the camera and microphone

techsparx.com

71–80 of 280 posts

Re: An iframe from googlesyndication.com tries to access the camera and microphone

#71
post #63
post #41

The author is concerned that an ad might be able to surreptitiously turn on the camera or microphone, but these are not accessible by default. In this case, it isn't even getting as far as a permissions prompt because the default Feature Policy doesn't allow camera or mic access in cross-origin iframes. (Ex, for Chrome: https://sites.google.com/a/chromium.org/dev/Home/chromium-se... ) Instead, I think the most likely…

Curiously no explanation why this sort of malicious behavior is accepted by "Google Ad Manager" in the first place. If you haven't already installed: https://addons.mozilla.org/en-US/firefox/addon/ublock-origin... https://chrome.google.com/webstore/detail/ublock-origin/cjpa...

I'm not sure it is allowed; that's not a part of the business I know much about. Since ads can run arbitrary JS it's hard to enforce policy programmatically.

On the other hand, it's not clear to me that whatever this advertiser is trying to do is having any real effect, aside from causing a console message that it is being blocked. Access to the mic and camera from cross-origin iframes is blocked by default, and you can't even trigger a permissions prompt.

As for installing an ad blocker, even with all the messiness of advertising, I still prefer it to paywalls.

Re: An iframe from googlesyndication.com tries to access the camera and microphone

#72
post #40

Earlier quoted context omitted.

Allowing an ads customer to "just" slip a request for camera and mic access into an ad script is malicious.

Negligent, I wouldn't call it malicious but I would call it negligent.

The first time google served malicious JS on behalf of a customer was negligent. Maybe the second and third and fourth and fiftieth times too.

It's not 2003 anymore, we're far past negligence at this point.

Re: An iframe from googlesyndication.com tries to access the camera and microphone

#73

I think this sounds more like some sort of fingerprinting attempt. It good to see that random access to these kind of resources fails due to new(er) browser controls. However, this does not mean that the fingerprinting actually failed. There is probably some way to determine if the request was denied automatically by the browser or manually by the user (e.g., time to get "response"), which is definitely something whi…

In my experience, with tools like Cover Your Tracks (apparently this is the new name for Panopticlick), the more you try and thwart fingerprinting, the more unique you appear. Although I still do everything I can to block and filter everything conceivable, I've given up on trying to figure out how identifiable I am on the web because it seems useless. If you don't try then you're identifiable, and if you do then you…

Those anti-fingerprinting tools should make you appear as the most common iPhone as much as possible.

Re: An iframe from googlesyndication.com tries to access the camera and microphone

#74
post #71
post #63

Earlier quoted context omitted.

Curiously no explanation why this sort of malicious behavior is accepted by "Google Ad Manager" in the first place. If you haven't already installed: https://addons.mozilla.org/en-US/firefox/addon/ublock-origin... https://chrome.google.com/webstore/detail/ublock-origin/cjpa...

I'm not sure it is allowed; that's not a part of the business I know much about. Since ads can run arbitrary JS it's hard to enforce policy programmatically. On the other hand, it's not clear to me that whatever this advertiser is trying to do is having any real effect, aside from causing a console message that it is being blocked. Access to the mic and camera from cross-origin iframes is blocked by default, and you…

> Since ads can run arbitrary JS it's hard to enforce policy programmatically.

Letting ads run arbitrary JS is the policy, right? It's not like that's a requirement to make the internet work, that's just a Google policy that trades money for user experience.

Re: An iframe from googlesyndication.com tries to access the camera and microphone

#75
post #71
post #63

Earlier quoted context omitted.

Curiously no explanation why this sort of malicious behavior is accepted by "Google Ad Manager" in the first place. If you haven't already installed: https://addons.mozilla.org/en-US/firefox/addon/ublock-origin... https://chrome.google.com/webstore/detail/ublock-origin/cjpa...

I'm not sure it is allowed; that's not a part of the business I know much about. Since ads can run arbitrary JS it's hard to enforce policy programmatically. On the other hand, it's not clear to me that whatever this advertiser is trying to do is having any real effect, aside from causing a console message that it is being blocked. Access to the mic and camera from cross-origin iframes is blocked by default, and you…

How about the company you work for disallow arbitrary JS in the ads they serve? We already know the answer though. Bottom line over doing what is right.

Re: An iframe from googlesyndication.com tries to access the camera and microphone

#76
post #67

Earlier quoted context omitted.

The author is concerned that an ad might be able to surreptitiously turn on the camera or microphone You are correct, that is the author's concern. The reason the rest of us are concerned is because the general public has been conditioned by Google and others to just press "Accept" any prompt that pops up, no matter how dangerous.

This is a catch-22 though. If something dangerous to privacy is being widely used in the world, then putting it behind a prompt creates an avalanche of prompts, and results in user apathy. But not prompting requires you to choose a default, which either default to block and breaks things (if it was actually required) or defaults to allow.

I would happily set all browsers to always deny all ads and untrusted domains the ability to use microphone and camera at all times. So there's no need for an avalanche of alerts, it just shouldn't be permissible for a resource from an untrusted source.

It may be widely used, but for a highly concentrated set of sites. I can't think of an occasion I've used it beyond Google, Microsoft, and Zoom properties. Perhaps Slack and Discord too? So there must be a better way.

Re: An iframe from googlesyndication.com tries to access the camera and microphone

#77
post #71
post #63

Earlier quoted context omitted.

Curiously no explanation why this sort of malicious behavior is accepted by "Google Ad Manager" in the first place. If you haven't already installed: https://addons.mozilla.org/en-US/firefox/addon/ublock-origin... https://chrome.google.com/webstore/detail/ublock-origin/cjpa...

I'm not sure it is allowed; that's not a part of the business I know much about. Since ads can run arbitrary JS it's hard to enforce policy programmatically. On the other hand, it's not clear to me that whatever this advertiser is trying to do is having any real effect, aside from causing a console message that it is being blocked. Access to the mic and camera from cross-origin iframes is blocked by default, and you…

> Since ads can run arbitrary JS

What a fantastic idea to create a platform where anyone can pay to have code ran on millions of end-user machines, embedded in random websites. What could possibly go wrong?

Re: An iframe from googlesyndication.com tries to access the camera and microphone

#78
post #4

Earlier quoted context omitted.

Has anyone seen any well done research showing these effects?

Not a study but I've heard explanations that big companies have so much data their models are just that good. For instance they know who you're friends with, both your search histories, and location data. Knowing you friend searched for lawnmowers recently and now y'all are physically close it's possible that brand was discussed. Although I wouldn't be shocked at all if mics were being used. I just feel like that wou…

no, they have so much data because their models are so bad. the vast data is used to give the illusion of good models by sheer volume, so little random matches are made more likely. that’s why google and the like want to hoover up our data, they’re desperate to keep the gravy train rolling long enough to create the good models and keep it going some more.

Re: An iframe from googlesyndication.com tries to access the camera and microphone

#79

I think this sounds more like some sort of fingerprinting attempt. It good to see that random access to these kind of resources fails due to new(er) browser controls. However, this does not mean that the fingerprinting actually failed. There is probably some way to determine if the request was denied automatically by the browser or manually by the user (e.g., time to get "response"), which is definitely something whi…

In my experience, with tools like Cover Your Tracks (apparently this is the new name for Panopticlick), the more you try and thwart fingerprinting, the more unique you appear. Although I still do everything I can to block and filter everything conceivable, I've given up on trying to figure out how identifiable I am on the web because it seems useless. If you don't try then you're identifiable, and if you do then you…

I think this can also be a good thing, as long as you also use software which makes sure you have a distinct 'unique' fingerprint for each session.

Not that I am a huge fan of Brave, but I think they have implemented something like this for certain (or all) APIs. You will still have a unique fingerprint, but it should not match to any previous fingerprints you had in the past.

Edit: see https://brave.com/privacy-updates/3-fingerprint-randomizatio...

Re: An iframe from googlesyndication.com tries to access the camera and microphone

#80
post #73

Earlier quoted context omitted.

In my experience, with tools like Cover Your Tracks (apparently this is the new name for Panopticlick), the more you try and thwart fingerprinting, the more unique you appear. Although I still do everything I can to block and filter everything conceivable, I've given up on trying to figure out how identifiable I am on the web because it seems useless. If you don't try then you're identifiable, and if you do then you…

Those anti-fingerprinting tools should make you appear as the most common iPhone as much as possible.

What is the most common iPhone? Should the common iPhone browser experience be scaled up to a desktop resolution, or should the desktop browser limit itself to the common iPhone resolution? What about mobile Safari bugs or misfeatures, such as webRTC shortcomings, or CSS bugs, or viewport resizing/scaling/zoom bugs?

There are so many possible variations that it seems like preventing fingerprinting by pretending you're something you're not would be an impossible task and makes you even more unique, not less.

Post reply on HN