Live data from Hacker News

An iframe from googlesyndication.com tries to access the camera and microphone

techsparx.com

151–160 of 280 posts

Re: An iframe from googlesyndication.com tries to access the camera and microphone

#151
post #97
post #94

This is not google, but a third party ad network serving ads through google. Google tries to sandbox the creatives in an attempt to prevent issues exactly like this, and develops browser features to prevent issues exactly like this. This is likely a script that somehow avoided google's malware scanning pipelines. This is definitely not google's malintent. Disclaimer: Ex googler, worked in ads, dealed with problems li…

> This is likely a script that somehow avoided google's malware scanning pipelines. I can't think of a good reason for scripts through google ad syndication to be asking for camera and microphone permissions. I'd assume Google runs these scripts in something like a lab environment to see what's ultimately invoked before deploying them to production? If so, would this be indicative of both a deliberate controls bypass…

"In a lab environment" -> Certainly happens, but what if the script targets "specific devices" like "samsung galaxy s10" which google won't be able list exhaustively?

What if bad actors figured out a way to identify google's emulators and avoid doing bad stuff in that situation?

The part i said "google develops browser solutions to prevent issues like this" is exactly what features policy will end up doing. But google's ad systems and chrome features don't always move at the same speed, but you can be sure that whatever ad malware team is finding will help chrome team to strengthen their defense.

Re: An iframe from googlesyndication.com tries to access the camera and microphone

#152
post #97
post #94

This is not google, but a third party ad network serving ads through google. Google tries to sandbox the creatives in an attempt to prevent issues exactly like this, and develops browser features to prevent issues exactly like this. This is likely a script that somehow avoided google's malware scanning pipelines. This is definitely not google's malintent. Disclaimer: Ex googler, worked in ads, dealed with problems li…

> This is likely a script that somehow avoided google's malware scanning pipelines. I can't think of a good reason for scripts through google ad syndication to be asking for camera and microphone permissions. I'd assume Google runs these scripts in something like a lab environment to see what's ultimately invoked before deploying them to production? If so, would this be indicative of both a deliberate controls bypass…

Javascript is Turing complete so it is impossible to determine what the script is going to do in all environments without running it in all environments.

The script could just detect the test environment and avoid triggering its malicious behavior.

Re: An iframe from googlesyndication.com tries to access the camera and microphone

#153

Earlier quoted context omitted.

I care a lot less about whether or not I see an ad than I do about the shadow dossier being compiled about me based on my browsing habits. So no, I don't think all the fingerprinting is moot. I'd rather see untargeted advertising than have my personal profile bought and sold.

Do you have ads blocked on google.com then? Because all ads there are contextual, not personalized.

That is wrong. Not sure where you got that idea from.

Re: An iframe from googlesyndication.com tries to access the camera and microphone

#154
post #6

The Exhibit A why no one will ever convince me to turn off my ad blocker or switch away from Firefox. It's a great feeling to just not have to worry about this entire class of exploits.

Or use a computer without a mic/webcam permanently embedded or attached. I'm glad I'm constantly reminded that not having such peripherals can be a good thing.

Re: An iframe from googlesyndication.com tries to access the camera and microphone

#155
post #94

This is not google, but a third party ad network serving ads through google. Google tries to sandbox the creatives in an attempt to prevent issues exactly like this, and develops browser features to prevent issues exactly like this. This is likely a script that somehow avoided google's malware scanning pipelines. This is definitely not google's malintent. Disclaimer: Ex googler, worked in ads, dealed with problems li…

Why allow anything in an ad besides text or images? Why allow others to run arbitrary code through your network. Inexcusable by Google imo.

Re: An iframe from googlesyndication.com tries to access the camera and microphone

#156
post #153

Earlier quoted context omitted.

Do you have ads blocked on google.com then? Because all ads there are contextual, not personalized.

That is wrong. Not sure where you got that idea from.

Search 'hr platform' and you only get ads for HR platforms. At no point will you see totally unrelated ads for stuff you didn't search for, since those will do much worse than contextual ones in the search context.

Re: An iframe from googlesyndication.com tries to access the camera and microphone

#157
I have to wonder if anti-fingerprinting is the wrong approach to privacy invading advertising. There’s an inherent asymmetry between the resources available to those who build these systems and those who try to stop them.

I’d love to see more stuff like CCPA. As a California resident I can simply tell Google that my data is not for sale, and they’re obligated to respect that regardless of what fingerprinting happens.

This isn’t an ideal solution, but the whole issue of privacy seems like a people/politics problem we keep trying to solve with technology.

Re: An iframe from googlesyndication.com tries to access the camera and microphone

#158

I think this sounds more like some sort of fingerprinting attempt. It good to see that random access to these kind of resources fails due to new(er) browser controls. However, this does not mean that the fingerprinting actually failed. There is probably some way to determine if the request was denied automatically by the browser or manually by the user (e.g., time to get "response"), which is definitely something whi…

In my experience, with tools like Cover Your Tracks (apparently this is the new name for Panopticlick), the more you try and thwart fingerprinting, the more unique you appear. Although I still do everything I can to block and filter everything conceivable, I've given up on trying to figure out how identifiable I am on the web because it seems useless. If you don't try then you're identifiable, and if you do then you…

One thing you can do is use different computers for different purposes.

Re: An iframe from googlesyndication.com tries to access the camera and microphone

#159
post #97

Earlier quoted context omitted.

> This is likely a script that somehow avoided google's malware scanning pipelines. I can't think of a good reason for scripts through google ad syndication to be asking for camera and microphone permissions. I'd assume Google runs these scripts in something like a lab environment to see what's ultimately invoked before deploying them to production? If so, would this be indicative of both a deliberate controls bypass…

"In a lab environment" -> Certainly happens, but what if the script targets "specific devices" like "samsung galaxy s10" which google won't be able list exhaustively? What if bad actors figured out a way to identify google's emulators and avoid doing bad stuff in that situation? The part i said "google develops browser solutions to prevent issues like this" is exactly what features policy will end up doing. But googl…

I thought they meant more like sandbox environment. Why would the API to access those things exist at all?

Re: An iframe from googlesyndication.com tries to access the camera and microphone

#160

Earlier quoted context omitted.

Who said anything about blaming google for users clicking “ok” without thinking about it?

The person to whom I replied!

To be fair, he said Google and others. I still don't know how much Google is responsible though.
Post reply on HN