Live data from Hacker News

Google has a secret browser hidden inside the settings

matan-h.com

251–260 of 327 posts

Re: Google has a secret browser hidden inside the settings

#251

Reminds me of the Switch, which has a built in fully functional web browser, but it’s only surfaced when connecting to a DNS server that requires a password as far as I am aware.

The Switch not only has a web browser, but a web server! (afaik its only used when downloading from the Switch's media browser app to your phone)

Re: Google has a secret browser hidden inside the settings

#252

Earlier quoted context omitted.

In this case the “user” is in part the person granting controlled access. The person moving the mouse is not the user in total. Take a easier example an atm machine. If a person touching it can access accounts/remove money, there is no question about it being a security problem.

Someone on an ATM accessing accounts other than their own is a security problem. Someone on an ATM accessing youtube is not a security problem.

I'm not so sure. It could be considered a DoS if nothing else, and throwing porn up on an ATM screen could certainly cause a company enough problems that they would consider it a security problem, and if you can load youtube on an ATM you could probably also load a different site with a fake ATM screen that collects pins and/or other personal information (account numbers would be more difficult unless you have a way to access the card reader) but any full featured browser in an ATM capable of being instructed by an attacker to load the attacker's JS is very likely a major security issue waiting to happen.

Re: Google has a secret browser hidden inside the settings

#253
post #76

Did some investigation. So when you click on "Manage my account" you actually get taken out of the settings app and into an Activity (name for the "screen" God object on Android) embedded inside of Google Play Services. Eventually, following this the browser is com.google.android.gms/.auth.folsom.ui.GenericActivity. This doesn't seem to be using the default system webview implementation, as on my phone that would be…

> gaiaId (Google Accounts and ID Administration ID)

Wow, someone at Google is undoubtedly proud of coming up with that for what I assume is essentially a Google world wide unique ID, and for good reason.

Re: Google has a secret browser hidden inside the settings

#254

Earlier quoted context omitted.

On the other hand, what kid wants to talk to their parents about what music they listen to?

What kid _doesn't_ want to talk to their parents about the stuff they're interested in? My kids have introduced me to some really interesting music, and vice verse.

I shared my dad's love of like Jethro Tull and Talking Heads, but uh there was also plenty of music I wouldn't want to talk with my parents about. There are endless examples in any era of popular music.

Re: Google has a secret browser hidden inside the settings

#255
post #10

Google's increasingly cavalier attitude towards security is concerning: 1) Kids WILL use this to bypass parental / school controls as soon as they learn about it 2) In some contexts (especially as high-stakes test settings, but also some military/prison/finance/medical/legal/etc. settings) this IS a direct security risk 3) Given the embedded browser is not secure, if a lot of kids do this, it WILL lead to someone exp…

> Google's increasingly cavalier attitude towards security is concerning: > [3 bullet points unrelated to security] Security is a field related to protecting device-users from malicious actors. Your 3 examples all fall broadly under parental-controls, which are about controlling & monitoring a user's use & access of their device - a scenario within whichc the user is the adversary, not external actors. That may be an…

The third bullet point explicitly mentions the device being compromised, so I think it’s unfair to paint that as unrelated to security or just a parental-control issue.

Re: Google has a secret browser hidden inside the settings

#256
post #177

Earlier quoted context omitted.

Please take this as critical feedback, and not as a personal attack: The comments which you are making here suggest that you shouldn't develop any software which in any way touches personal data without significant upskilling on IT security. You're making false comments with complete confidence. Most security scenarios came about as a result of attackers being able to bring systems into absurd situations, and moving…

Seems like an argument about system-driven and component-driven risk analyses - they both have their place, and they're not mutually exclusive. Risk-based approaches aren't about either removing all risk or paying attention to only the highest priority ones. Instead, they are about managing and tracking risk at acceptable levels based on threat models and the risk appetites of stakeholders, and implementing appropria…

It's a slightly different argument. The level of "reasonable risk" depends on the attacker in both situations.

The odds of any individual crafting a special packet to crash my system are absurdly low.

However, "absurdly low" is good enough. All it took was one individual to come up with the ping-of-death and one more to write a script to automate it, and systems worldwide were being taken down by random teenagers in the late nineties.

As a result of these and other absurd attacks, any modern IP stack is hardened to extreme levels.

In contrast, my house lock is pretty easy to pick (much easier than crafting the ping-of-death), and I sometimes don't even remember to lock it. That's okay, since the threat profile isn't "anyone on the internet," but is rather limited (to people in my community who happen to be trying to break into my house).

I don't need to protect my home against the world's most elite criminals trying to break in, since they're not likely to be in that very limited set of people. I do any software I build.

That applies both to system threats and to component threats. Digital systems need to be incredibly hard.

Google used to know that too. I'm not sure when they unlearned that lesson.

Re: Google has a secret browser hidden inside the settings

#257
post #220

Earlier quoted context omitted.

For 90's kids it was video games that were gonna rot your brain and make you a bad person. That turned out to be false. For 00's kids the new boogeyman is "social media". Likely will turn out false too. Just sounds like a cop-out way to blame anything other than poor parenting.

There is definitely poor parenting at play here, and there are also way more, easier access, brain rotters today. 100 years ago, parents weren't giving their babies electronic pacifiers (tablets with YouTube playing).

I mean 100yrs none of that crap existed so yea no shit they weren't doing that. But I'm sure there were things of a similar nature that existed then as well.

Re: Google has a secret browser hidden inside the settings

#258
post #113
post #10

Google's increasingly cavalier attitude towards security is concerning: 1) Kids WILL use this to bypass parental / school controls as soon as they learn about it 2) In some contexts (especially as high-stakes test settings, but also some military/prison/finance/medical/legal/etc. settings) this IS a direct security risk 3) Given the embedded browser is not secure, if a lot of kids do this, it WILL lead to someone exp…

As a security researcher, I have to disagree - there's many things to criticize Google for, but "cavalier attitude to security" isn't one of them. Their security teams are industry-leading and they have done a lot of important work over the past decade (Project Zero, a very well-done bug bounty program, Advanced Protection, FIDO/hardware security keys, large-scale fuzzing and AFL, tons of behind the scenes sandboxing…

> Their security teams are industry-leading and they have done a lot of important work over the past decade (Project Zero, a very well-done bug bounty program, Advanced Protection, FIDO/hardware security keys, large-scale fuzzing and AFL, tons of behind the scenes sandboxing work, Linux kernel hardening...).

I have to agree. Google has O(200k) employees, and included among those, are some of the best security people in the world. Indeed, many are left over from historic Google.

However, there's a huge difference between having high-calibre employees and having those employees impact the security of the huge numbers of products Google develops. Most of those employees do fine research, but have no influence on the typical Google product.

> They have a fine track record keeping their users safe ... [citation needed]

Let me tell you a story. I use Google Workspace Free. My account was compromised, not through much fault of anyone involved (long story, involving being targeted by a criminal actor who gained physical access to a device).

I wanted to collect records, go to the police, and have the criminal arrested. Google had clear logs of what happened. I found out that security was a value-added product. I'd need to switch from my version to a paid version, and could never switch back. The cost was going to be $6/user/month for the rest of my life, times a dozen family members, times 12 months, times another 60 years of life, which is around 50 thousand dollars.

$50 grand.

To get audit logs.

You can guess what I decided.

There was no way to prevent this retrospectively, but it'd be very easy to prevent prospectively. It just wasn't worth doing for $50k. The criminal is still out there. They might be targeting your home or business!

Thanks Google!

Another good story -- impacting a significant fraction of low-income individuals in the world -- is withholding security updates for Android after a few years to keep people on the upgrade treadmill. New devices have frequent updates. Older ones have slower updates, until at some point, the updates stop. Phones get compromised, and attackers do ransomware, identity theft, and other sorts of nasty things.

Thanks Google!

Security should not be a paid value-add. Everyone deserves security.

I could tell many more stories too.

Re: Google has a secret browser hidden inside the settings

#260
post #220

Earlier quoted context omitted.

Oh, I am absolutely sure of that. I didn't mean my silly recollections there to be a way to handwave the concerns of people with parental controls nowadays. Those are important. I just miss those simpler times. The most risque thing we got our hands on back then were low resolution porn clips. Perhaps some odd hentai AVI with mangled translation. People used to be up in arms about something silly as Carmageddon being…

For 90's kids it was video games that were gonna rot your brain and make you a bad person. That turned out to be false. For 00's kids the new boogeyman is "social media". Likely will turn out false too. Just sounds like a cop-out way to blame anything other than poor parenting.

Seeing some pretty concerning NEET "battlestations" online I'd think the parents of the 90s were right for at least some of those kids. Doing anything all day to excess to the detriment of everything else is bad, whether it be TV or video games or social media or whatever distraction comes next.
Post reply on HN