Live data from Hacker News

Google has a secret browser hidden inside the settings

matan-h.com

91–100 of 327 posts

Re: Google has a secret browser hidden inside the settings

#91

Earlier quoted context omitted.

> sometimes, just sometimes - it is also to do with protecting organisations from careless or malicious users. There are two cases where this is true: a user intentionally sharing internal access with external malicious actors, or a user unintentionally sharing internal access with external malicious actors (e.g. social engineering / general incompetence). Neither apply to kiosk breakouts.

You seem very sure that those are the only two security risks to an expected browser being available on an otherwise managed device. I'm pretty certain there may be other risks.

One can absolutely make an argument for a great many risks to be classified under security concern: there are certainly more than just these two. Doing so is simply reductio ad absurdum.

To expand on this, we can if we choose classify all parental controls under general access control, and within a principle of least privilege further classify the following as legitimate security risks: - access to the internet - access to a keyboard - read access to a disk

There are absolutely scenarios one can contoct where these are real concerns. The settings panel of a general-purpose consumer device doesn't fit that venn diagram for me. Is it a bug: yes. Is it a security bug: no.

Re: Google has a secret browser hidden inside the settings

#93
post #56

Earlier quoted context omitted.

Google outsourced work to low cost bidders and now they get low quality results.

Says the person whose last comment is upset that their engineers have a $300k salary?

Truth must have really hurt you, if you even went through my post history.

My earlier comment is guy earning 300k shouldnt say that things are cheap.

My current comment is that Google does not hire the best anymore, but outsources to lowest cost bidders and results are visible -> quality suffers.

Re: Google has a secret browser hidden inside the settings

#94
post #10

Google's increasingly cavalier attitude towards security is concerning: 1) Kids WILL use this to bypass parental / school controls as soon as they learn about it 2) In some contexts (especially as high-stakes test settings, but also some military/prison/finance/medical/legal/etc. settings) this IS a direct security risk 3) Given the embedded browser is not secure, if a lot of kids do this, it WILL lead to someone exp…

> Google's increasingly cavalier attitude towards security is concerning: > [3 bullet points unrelated to security] Security is a field related to protecting device-users from malicious actors. Your 3 examples all fall broadly under parental-controls, which are about controlling & monitoring a user's use & access of their device - a scenario within whichc the user is the adversary, not external actors. That may be an…

Defining your way out of giving secure, as in safe, devices to kids is frustrating. And sadly reflective of exactly why the original comment is correct.

Re: Google has a secret browser hidden inside the settings

#95
post #71

Earlier quoted context omitted.

As a parent, it’s concerning to me. It’s funny how I never thought it would be an issue but kids have real impulse control issues and devices are super easy to spend too much time on and contribute to negative mental health. Screen time controls don’t solve this, but they help a little bit as part of many other things to help people learn about how to self regulate.

When I was a kid we managed to hack into my school's lab's computers to install Doom and Warcraft II. Good times.

I vividly remember cracking the admin PWs with ophcrack or the school WEP wifi with aircrack-ng.

Re: Google has a secret browser hidden inside the settings

#96

Earlier quoted context omitted.

> which are about controlling & monitoring a user's use & access of their device - a scenario within whichc the user is the adversary, not external actors Access control falls squarely under security. Also, the user should be considered the adversary, because they or programs that run on their behalf might be malicious, either knowingly or unknowingly. Not accounting for this is one of UNIX's biggest blunders.

The user is generally never the adversary in any legitimate security situation. Ignorance might be but that’s not something inherent to the user and an area for improvement.

In this case the “user” is in part the person granting controlled access. The person moving the mouse is not the user in total.

Take a easier example an atm machine. If a person touching it can access accounts/remove money, there is no question about it being a security problem.

Re: Google has a secret browser hidden inside the settings

#97

Earlier quoted context omitted.

The user is generally never the adversary in any legitimate security situation. Ignorance might be but that’s not something inherent to the user and an area for improvement.

> The user is generally never the adversary in any legitimate security situation. First, this isn't correct, for instance, DRM and TPM. Second, "the user" does not have direct access to the computer internals, which means all such access is mediated by programs that are supposed to act on the user's behalf. But because software is not formally verified, we have no guarantee that they do so, and so we must assume that…

> > The user is generally never the adversary in any legitimate security situation.

> First, this isn't correct, for instance, DRM and TPM.

You must have missed the word "legitimate". DRM and TPM are two of the best examples of illegitimate "security".

Re: Google has a secret browser hidden inside the settings

#98
post #26
post #10

Google's increasingly cavalier attitude towards security is concerning: 1) Kids WILL use this to bypass parental / school controls as soon as they learn about it 2) In some contexts (especially as high-stakes test settings, but also some military/prison/finance/medical/legal/etc. settings) this IS a direct security risk 3) Given the embedded browser is not secure, if a lot of kids do this, it WILL lead to someone exp…

This is a pretty standard kiosk breakout technique, which have been super common since the 90s. They have always existed, and will continue to exist. The impact and use cases for issues like this are pretty negligible, so they don't get addressed as quickly as bugs that can actually be used for real crime. Also, you say the embedded browser is "not secure", yet the going rate for browser bugs on Android are in the mu…

There are plenty of ways to invade someone’s privacy without being root. Stealing a Google Account would still be a prize.

Re: Google has a secret browser hidden inside the settings

#99

Earlier quoted context omitted.

> 1) Kids WILL use this to bypass parental / school controls as soon as they learn about it Good. Parental/school controls don't belong on the device. They belong on whatever the device connects to. That would be parental/school networks. If you don't want your kids to connect to things then don't let your kids have devices that connect to things. > 2) In some contexts (especially as high-stakes test settings, but al…

How would network restrictions help, there is WiFi at friends houses / everywhere. > There's nothing in that statement that relates specifically to kids. Most adults probably don't have parental controls on their phone...

> How would network restrictions help, there is WiFi at friends houses / everywhere.

Aren't there other Internet-connected devices at friends' houses too?

Re: Google has a secret browser hidden inside the settings

#100

Earlier quoted context omitted.

How would network restrictions help, there is WiFi at friends houses / everywhere. > There's nothing in that statement that relates specifically to kids. Most adults probably don't have parental controls on their phone...

> How would network restrictions help, there is WiFi at friends houses / everywhere. > > If you don't want your kids to connect to things then don't let your kids have devices that connect to things.

Comment said the restrictions belong on the network being connected to, which is useless when you can connect else where.

Yes not giving your kids access to a device is one option; parental controls are another.

I'm not sure either will work entirely, but that's another point.

Post reply on HN