Live data from Hacker News

Google has a secret browser hidden inside the settings

matan-h.com

211–220 of 327 posts

Re: Google has a secret browser hidden inside the settings

#211
post #50

A similar workaround has been available in the 'about' licenses pages. Just follow a link to a license and then you have a browser. It's useful for getting a browser on car head units, Peloton bikes, etc.

Ha! I just went to the "Third-party licenses" page on my Pixel 6, and it loads a never-ending list of links. Looks like a list of all files in the filesystem.

Can you enlighten me where the "Third-party licenses" link is?

Re: Google has a secret browser hidden inside the settings

#212

Earlier quoted context omitted.

The user is generally never the adversary in any legitimate security situation. Ignorance might be but that’s not something inherent to the user and an area for improvement.

In this case the “user” is in part the person granting controlled access. The person moving the mouse is not the user in total. Take a easier example an atm machine. If a person touching it can access accounts/remove money, there is no question about it being a security problem.

Someone on an ATM accessing accounts other than their own is a security problem. Someone on an ATM accessing youtube is not a security problem.

Re: Google has a secret browser hidden inside the settings

#213
post #50

Earlier quoted context omitted.

Ha! I just went to the "Third-party licenses" page on my Pixel 6, and it loads a never-ending list of links. Looks like a list of all files in the filesystem.

Can you enlighten me where the "Third-party licenses" link is?

In Settings -> About phone -> Legal information

Re: Google has a secret browser hidden inside the settings

#214
post #162

Earlier quoted context omitted.

How is this supposed to work? Opening the bookmarks page navigates away from the current page. Even then, selecting the bookmark does nothing.

Works in Firefox, not Chrome. Android. 1. Bookmark any page, making a dummy 2. Menu > Bookmarks > edit 3. Change URL of dummy bookmark to the js bookmarklet code. 4. Visit any site. 5. Menu > Bookmarks > tap on the bookmarklet 6. Widget appears on bottom right of page It doesn't work on HN(?) But does work on other sites.

Step 5 onwards don't work on private tabs for some reason. For private tabs you can do all steps up to 4 and then:

5. Tap on the URL bar

6. Type part of the name of the bookmark you chose until it appears in search (in my case eruda works)

7. Tap the bookmarlet

For this to work you need to have bookmark search enabled in settings: Settings -> Search -> Search bookmarks

Also, there seem to be many sites where the widget doesn't appear, but you can try it at google.com.

Re: Google has a secret browser hidden inside the settings

#215

Reminds me of the Switch, which has a built in fully functional web browser, but it’s only surfaced when connecting to a DNS server that requires a password as far as I am aware.

In order to login through some captive portals on restricted networks you need a browser. Presumably you sometimes even need JavaScript, or else Nintendo likely wouldn't have included a JS engine since that greatly increases the attack vector.

It would have been possible to design a system of letting users read the ToS of a network and enter login information without needing an entire browser. Granted, it's probably safe to assume most captive portals aren't trying to exploit your non-traditional computing device (such as a Nintendo Switch), and if a user is changing the DNS to evade a captive portal and go to some other site, then any exploits that occur on their device are kind of their own fault, but it still seems like a suboptimal system. Either you're going to have a bunch of exploitable devices that otherwise would in practice be secure since they need to have a web browser, or you're going to have devices that straight up can't access many networks (since they don't have a built-in browser.) I'd argue the latter problem is even greater than the former: web browsers are incredibly complex! If your device is capable of running an already existing browser (e.g. Linux or BSD based systems), then it's not that big of a deal. But if it isn't (e.g. certain embedded systems), then it sucks, though there are sometimes workarounds to accessing captive networks without an on-device browser (e.g. AppleTV lets you login through captive portals on iPhone or iPad — works for people in the Apple ecosystem, but that integration isn't as easy with devices from unaffiliated companies.)

Re: Google has a secret browser hidden inside the settings

#217

Earlier quoted context omitted.

> Google's increasingly cavalier attitude towards security is concerning: > [3 bullet points unrelated to security] Security is a field related to protecting device-users from malicious actors. Your 3 examples all fall broadly under parental-controls, which are about controlling & monitoring a user's use & access of their device - a scenario within whichc the user is the adversary, not external actors. That may be an…

This is literally a privilege-escalation attack: i.e. the user escapes from controls that are imposed on them by the device manager (which may well not be the user, but a corporate MDM platform). Are you suggesting that privilege-escalation attacks are not security risks?

I wouldn't say that escaping a control is always a privilege escalation. Browsing like this doesn't access any data, privileged or not, and you already had internet access. You're still in a very tight sandbox.

Re: Google has a secret browser hidden inside the settings

#218
post #201

Earlier quoted context omitted.

https://news.ycombinator.com/newsguidelines.html > Please don't post insinuations about astroturfing, shilling, brigading, foreign agents, and the like. It degrades discussion and is usually mistaken. If you're worried about abuse, email hn@ycombinator.com and we'll look at the data.

Are you pretending to be a moderator? Referencing widely documented news isn’t an insinuation. If you want to see the links yourself you can just ask - not every post here has citations linked even when already widely available/known (I see several people have provided several references already)

> You’re apparently an employee shareholder with a bias.

Re: Google has a secret browser hidden inside the settings

#219
post #184
post #166

Earlier quoted context omitted.

Are you sure about biggest Android exploit? Tests conducted by Project Zero confirm that those four vulnerabilities allow an attacker to remotely compromise a phone at the baseband level with no user interaction, and require only that the attacker know the victim's phone number. [1] [1] https://googleprojectzero.blogspot.com/2023/03/multiple-inte...

To be exact, those aren't exploits of android itself, just the device it's running on. Not much of a difference in the outcome, but i guess it doesn't defeat the argument of google having good platform

This is a recent one. Whatsapp bug [1] exposed both Android and iOS few years back. And then there was MMS exploit [2] that affected close to 95% of android phones

[1] https://www.ft.com/content/4da1117e-756c-11e9-be7d-6d846537a...

[2] https://en.wikipedia.org/wiki/Stagefright_(bug)

Re: Google has a secret browser hidden inside the settings

#220

Earlier quoted context omitted.

> Doom and Warcraft II If that's all today's kids had access to, I wouldn't be worried about it either. I work with "average" kids today that have access to far more developmentally-damaging media, and I want the few kids that have parents that care enough to set up controls, to have a fighting chance.

Oh, I am absolutely sure of that. I didn't mean my silly recollections there to be a way to handwave the concerns of people with parental controls nowadays. Those are important. I just miss those simpler times. The most risque thing we got our hands on back then were low resolution porn clips. Perhaps some odd hentai AVI with mangled translation. People used to be up in arms about something silly as Carmageddon being…

For 90's kids it was video games that were gonna rot your brain and make you a bad person. That turned out to be false.

For 00's kids the new boogeyman is "social media". Likely will turn out false too.

Just sounds like a cop-out way to blame anything other than poor parenting.

Post reply on HN