Live data from Hacker News

Google has a secret browser hidden inside the settings

matan-h.com

41–50 of 327 posts

Re: Google has a secret browser hidden inside the settings

#41

Is this different than any other embedded webview? Doesn't nearly every app somewhere have an embedded webview somewhere for things like "view privacy policy", where it is often much easier to display html than sending the whole privacy policy to your app developer?

Do normal embedded webviews also bypass parental controls? If so, that seems like a massive issue.

Embedded webviews were the easiest parental control bypass on Windows since about Windows 98. I've played so many flash games through the documentation for Microsoft Word!

I can't find any information anywhere that either confirms or denies the possibility to bypass Google's restrictions with web views. I assume it's possible, because it's possible on most platforms, but I suppose it depends on the implementation.

I've seen parental controls that employ an (on-device) MitM proxy and DNS filtering to ensure safety, and those apps will prevent almost any app from displaying unwanted content.

Re: Google has a secret browser hidden inside the settings

#42
post #10

Google's increasingly cavalier attitude towards security is concerning: 1) Kids WILL use this to bypass parental / school controls as soon as they learn about it 2) In some contexts (especially as high-stakes test settings, but also some military/prison/finance/medical/legal/etc. settings) this IS a direct security risk 3) Given the embedded browser is not secure, if a lot of kids do this, it WILL lead to someone exp…

> Google's increasingly cavalier attitude towards security is concerning: > [3 bullet points unrelated to security] Security is a field related to protecting device-users from malicious actors. Your 3 examples all fall broadly under parental-controls, which are about controlling & monitoring a user's use & access of their device - a scenario within whichc the user is the adversary, not external actors. That may be an…

[dead]

Re: Google has a secret browser hidden inside the settings

#43
post #5

Earlier quoted context omitted.

When a child is powerful enough to start taking control from you it might be time to start giving it away.

It should be noted that once this technique makes it to the playground, every kid will learn about the magic taps that make the web available, including kids that aren't ready yet. Obviously, parents using parental control will have questions what their kids are doing for hours in the Google Settings app every day, but every kid will probably get that day or week of free browsing until their parents get suspicious. T…

Or even decades

Re: Google has a secret browser hidden inside the settings

#44
post #31

Is this different than any other embedded webview? Doesn't nearly every app somewhere have an embedded webview somewhere for things like "view privacy policy", where it is often much easier to display html than sending the whole privacy policy to your app developer?

Can you visit arbitrary websites using such webviews? I never managed to. And IIRC it's rather difficult to set up a webview that allows multiple domains or URLs (but I'm no android dev, and the last time I had to fiddle with this, was years ago)

The reason it works here is that this particular webview opens a Google page that links to Google.com. There is no address bar so any safe browsing enforcement will make it at least two steps harder to access most had content.

Blocking external domains shouldn't be that hard, but I also don't think parental controls are of any interest or priority for most app developers.

Re: Google has a secret browser hidden inside the settings

#46

Earlier quoted context omitted.

> Google's increasingly cavalier attitude towards security is concerning: > [3 bullet points unrelated to security] Security is a field related to protecting device-users from malicious actors. Your 3 examples all fall broadly under parental-controls, which are about controlling & monitoring a user's use & access of their device - a scenario within whichc the user is the adversary, not external actors. That may be an…

> Security is a field related to protecting device-users from malicious actors. You know - sometimes, just sometimes - it is also to do with protecting organisations from careless or malicious users. The three points are related to security, even it couched in terms of parents/children

There are lot of much easier ways to compromise security both for careless or malicious users. This is the fundamental difference between ios and android. If you want you could ruin the security of android, however it is harder to do it in ios. Definitely not impossible, you could sideload dangerous apps easily in ios as well.

Re: Google has a secret browser hidden inside the settings

#47
post #10

Google's increasingly cavalier attitude towards security is concerning: 1) Kids WILL use this to bypass parental / school controls as soon as they learn about it 2) In some contexts (especially as high-stakes test settings, but also some military/prison/finance/medical/legal/etc. settings) this IS a direct security risk 3) Given the embedded browser is not secure, if a lot of kids do this, it WILL lead to someone exp…

>1) Kids WILL use this to bypass parental / school controls as soon as they learn about it

Doesn't sound concerning, especially the latter.

Re: Google has a secret browser hidden inside the settings

#48

Earlier quoted context omitted.

> Google's increasingly cavalier attitude towards security is concerning: > [3 bullet points unrelated to security] Security is a field related to protecting device-users from malicious actors. Your 3 examples all fall broadly under parental-controls, which are about controlling & monitoring a user's use & access of their device - a scenario within whichc the user is the adversary, not external actors. That may be an…

> Security is a field related to protecting device-users from malicious actors. You know - sometimes, just sometimes - it is also to do with protecting organisations from careless or malicious users. The three points are related to security, even it couched in terms of parents/children

> sometimes, just sometimes - it is also to do with protecting organisations from careless or malicious users.

There are two cases where this is true: a user intentionally sharing internal access with external malicious actors, or a user unintentionally sharing internal access with external malicious actors (e.g. social engineering / general incompetence). Neither apply to kiosk breakouts.

Re: Google has a secret browser hidden inside the settings

#50

A similar workaround has been available in the 'about' licenses pages. Just follow a link to a license and then you have a browser. It's useful for getting a browser on car head units, Peloton bikes, etc.

Ha! I just went to the "Third-party licenses" page on my Pixel 6, and it loads a never-ending list of links. Looks like a list of all files in the filesystem.
Post reply on HN