Live data from Hacker News

Google has a secret browser hidden inside the settings

matan-h.com

21–30 of 327 posts

Re: Google has a secret browser hidden inside the settings

#21
post #5
post #4

Parental control bypass is the bigger issue here, kids will do anything to get around parental controls and Google made a promise when they set up parental controls that it was secure and would prevent your children from accessing things you didn’t want them to. This breaks that promise.

When a child is powerful enough to start taking control from you it might be time to start giving it away.

It should be noted that once this technique makes it to the playground, every kid will learn about the magic taps that make the web available, including kids that aren't ready yet.

Obviously, parents using parental control will have questions what their kids are doing for hours in the Google Settings app every day, but every kid will probably get that day or week of free browsing until their parents get suspicious.

That assumes parents bother to check on the statistics made available by parental controls, of course; if nobody checks, then the kid will access the web unrestricted for years.

Re: Google has a secret browser hidden inside the settings

#22

Is this different than any other embedded webview? Doesn't nearly every app somewhere have an embedded webview somewhere for things like "view privacy policy", where it is often much easier to display html than sending the whole privacy policy to your app developer?

> Is this different than any other embedded webview?

Yes - it exposes an API to set device encryption keys to the websites that you visit with it- At least that's how I interpret the last section "The dangerous functions".

Re: Google has a secret browser hidden inside the settings

#23

Is this different than any other embedded webview? Doesn't nearly every app somewhere have an embedded webview somewhere for things like "view privacy policy", where it is often much easier to display html than sending the whole privacy policy to your app developer?

Do normal embedded webviews also bypass parental controls? If so, that seems like a massive issue.

Re: Google has a secret browser hidden inside the settings

#24

Is this different than any other embedded webview? Doesn't nearly every app somewhere have an embedded webview somewhere for things like "view privacy policy", where it is often much easier to display html than sending the whole privacy policy to your app developer?

If any app that has an embedded webview allows to bypass parental control, then this is an even bigger bug in Android…

(without even talking about this key management stuff, because at this point it's merely speculation as the author didn't test what they actually do: “you have two methods which I don’t know what they do, but they sound scary”)

Re: Google has a secret browser hidden inside the settings

#25
post #19

Is this different than any other embedded webview? Doesn't nearly every app somewhere have an embedded webview somewhere for things like "view privacy policy", where it is often much easier to display html than sending the whole privacy policy to your app developer?

The webview appears to have privileged JS functions for password manager key management and recovery.

> appears

Until someone confirms that they are what the name and what the speculation is about.

Re: Google has a secret browser hidden inside the settings

#26
post #10

Google's increasingly cavalier attitude towards security is concerning: 1) Kids WILL use this to bypass parental / school controls as soon as they learn about it 2) In some contexts (especially as high-stakes test settings, but also some military/prison/finance/medical/legal/etc. settings) this IS a direct security risk 3) Given the embedded browser is not secure, if a lot of kids do this, it WILL lead to someone exp…

This is a pretty standard kiosk breakout technique, which have been super common since the 90s. They have always existed, and will continue to exist. The impact and use cases for issues like this are pretty negligible, so they don't get addressed as quickly as bugs that can actually be used for real crime.

Also, you say the embedded browser is "not secure", yet the going rate for browser bugs on Android are in the multi-million dollar range, especially if it leads to root.

Re: Google has a secret browser hidden inside the settings

#27
post #14

This brings back memories of older Windows versions, where you could push F1 and trigger various run commands through Windows Help

My first thought too - this feels like that "F1 -> Open Help File -> Other... -> right-click on explorer.exe and select Run" method of bypassing login screen circa Windows 95/98.

Re: Google has a secret browser hidden inside the settings

#29
post #10

Google's increasingly cavalier attitude towards security is concerning: 1) Kids WILL use this to bypass parental / school controls as soon as they learn about it 2) In some contexts (especially as high-stakes test settings, but also some military/prison/finance/medical/legal/etc. settings) this IS a direct security risk 3) Given the embedded browser is not secure, if a lot of kids do this, it WILL lead to someone exp…

At least Mozilla is still around to find all their bugs for them.

Re: Google has a secret browser hidden inside the settings

#30
post #10

Google's increasingly cavalier attitude towards security is concerning: 1) Kids WILL use this to bypass parental / school controls as soon as they learn about it 2) In some contexts (especially as high-stakes test settings, but also some military/prison/finance/medical/legal/etc. settings) this IS a direct security risk 3) Given the embedded browser is not secure, if a lot of kids do this, it WILL lead to someone exp…

> 1) Kids WILL use this to bypass parental / school controls as soon as they learn about it

Good. Parental/school controls don't belong on the device. They belong on whatever the device connects to.

That would be parental/school networks.

If you don't want your kids to connect to things then don't let your kids have devices that connect to things.

> 2) In some contexts (especially as high-stakes test settings, but also some military/prison/finance/medical/legal/etc. settings) this IS a direct security risk

The direct security risk is using Google in the first place.

> 3) Given the embedded browser is not secure, if a lot of kids do this, it WILL lead to someone exploiting this, and machines being compromised and escalations

There's nothing in that statement that relates specifically to kids.

Post reply on HN