Earlier quoted context omitted.
Works in Firefox, not Chrome. Android. 1. Bookmark any page, making a dummy 2. Menu > Bookmarks > edit 3. Change URL of dummy bookmark to the js bookmarklet code. 4. Visit any site. 5. Menu > Bookmarks > tap on the bookmarklet 6. Widget appears on bottom right of page It doesn't work on HN(?) But does work on other sites.
If you're on Android and want eruda, I've got a userscript to load it on every site here: https://github.com/Efreak/UserScripts/tree/master/Eruda-Mobi... It helps with things like removing elements because you can see the DOM and it's fewer clicks away and easier to use than ublock, which doesn't show the DOM in the little box provided for element removal and only allows removing one item say a time (you can use mult…
Google has a secret browser hidden inside the settings
271–280 of 327 posts
Re: Google has a secret browser hidden inside the settings
#272Earlier quoted context omitted.
Sorry, but how is this news then? The Google settings have never felt native and therefore were almost certainly a browser for a very long time now
Why does it have to be news? Someone wanted to share what they found, that’s what personal blogs are for. Nothing more.
Re: Google has a secret browser hidden inside the settings
#273Earlier quoted context omitted.
Sure but that's like discovering how to make pizza vs discovering how to put a frozen pizza into a microwave. You'd be generally more proud from the first one
Depends on how much you cook and how good you are at it, right? When I was a kid, I was damn proud of "discovering" Sub7 and using it to fuck with all of my friends, teaching them to do the same. Years later, I would "discover" how to read assembly by reading a book on it and then "discover" pirated copies of various disassemblers online and use them to reverse engineer games, write keygens, etc. Years later, I would…
Re: Google has a secret browser hidden inside the settings
#274Earlier quoted context omitted.
Depends on how much you cook and how good you are at it, right? When I was a kid, I was damn proud of "discovering" Sub7 and using it to fuck with all of my friends, teaching them to do the same. Years later, I would "discover" how to read assembly by reading a book on it and then "discover" pirated copies of various disassemblers online and use them to reverse engineer games, write keygens, etc. Years later, I would…
idk what sub7 is, but this is a great post. i like it a lot. sometimes i find it easy to forget what learning is and how it can take place and that we learn from each other and each other's work and sometimes we discover something that no one has discovered before -- it is all learning. thanks.
Re: Google has a secret browser hidden inside the settings
#275Earlier quoted context omitted.
Sorry, but how is this news then? The Google settings have never felt native and therefore were almost certainly a browser for a very long time now
Why does it have to be news? Someone wanted to share what they found, that’s what personal blogs are for. Nothing more.
Re: Google has a secret browser hidden inside the settings
#276This is a bit like accessing the internet from chm (help) files when the browser was blocked. Damn. I revealed my age!
Re: Google has a secret browser hidden inside the settings
#277Earlier quoted context omitted.
> Google's increasingly cavalier attitude towards security is concerning: > [3 bullet points unrelated to security] Security is a field related to protecting device-users from malicious actors. Your 3 examples all fall broadly under parental-controls, which are about controlling & monitoring a user's use & access of their device - a scenario within whichc the user is the adversary, not external actors. That may be an…
Well said. Spoken like a true Google engineer! However, I think you understand both security as a field, at least one of my three points, as well as children and parenting. =================== Security as a field =================== You wrote: "Security is a field related to protecting device-users from malicious actors." This is a very narrow and incorrect definition. Security as a field relates to many things, incl…
You (and many many of the replies in thread) have taken the initial topic (kiosk escape -vs- parental controls) and are defending their definition as a serious security threat by likening them to social engineering attacks on medical staff. These are separate scenarios with separate threat models. If your child is sending confidential corporate data to malicious third parties through the Android settings app you may have a separate set of problems beyond software controls.
Overall, much of the finer details of yours & others' replies amount to an extreme level of theoretical pedantry around technical classification of threats, completely removed from any kind of real-world analysis of their severity.
Re: Google has a secret browser hidden inside the settings
#278Earlier quoted context omitted.
The reason it works here is that this particular webview opens a Google page that links to Google.com. There is no address bar so any safe browsing enforcement will make it at least two steps harder to access most had content. Blocking external domains shouldn't be that hard, but I also don't think parental controls are of any interest or priority for most app developers.
It'd be pretty simple to enforce sandbox/parental controls for the integrated webview browser. 1. Just limit the webview browser location to the same list as allowed by the parental control. 2. By default limit the webview browser location to the domain first opened by the app i.e locked to a single domain by default. 3. Allow webview browser to be expanded via a regex/pattern list of domains. 4. Limit the number of…
Re: Google has a secret browser hidden inside the settings
#279Earlier quoted context omitted.
It's a slightly different argument. The level of "reasonable risk" depends on the attacker in both situations. The odds of any individual crafting a special packet to crash my system are absurdly low. However, "absurdly low" is good enough. All it took was one individual to come up with the ping-of-death and one more to write a script to automate it, and systems worldwide were being taken down by random teenagers in…
Do you think there’s a standard for “incredibly hard” that all applications need to follow? Or that it varies from one application to another depending on context?
1) Cost of compromise.
- For example, medical data, military secrets, and highly-personal data need a high level of security.
- Something like Sudoku high scores, perhaps not so much.
2) Benefit of compromise. Some compromises net $0, and some $1M.
- Something used by 4B users (like Google) has much higher potential upside than something used by 1 user. If someone can scam-at-scale, that's a lot of money.
- Something managing $4B of bitcoin or with designs for the F35 has much higher upside than something with Sudoku high scores.
3) Exposure.
- A script I wrote which I run on my local computer doesn't need any security. It's like my bedroom door.
- A one-off home, school, or business-internal system is only exposed to those communities, and doesn't need to be excessively hardened. It's more-or-less the same as physical security.
- Something on the public internet needs a lot more.
This, again, speaks to number of potential attackers (0, dozens/hundreds, or 7B).
#1 and #2 are obvious. #3 is the one where I see people screw up with arguments. Threats which seem absurdly unlikely are exploited all the time on the public internet, and intuition from the real world doesn't translate at all.
Re: Google has a secret browser hidden inside the settings
#280This is a bit like accessing the internet from chm (help) files when the browser was blocked. Damn. I revealed my age!
Are we revealing our age through exploits now? How about "using gopher on a university library terminal to access a site that launched a telnet session so you can check your out-of-state college email over the summer"?
Allowed free shell accounts and the college board in GA offered free local dialup access to a Gopher server (Peachnet).
I had a terminal script that navigated through the Gopher menu until I could get to Nyx.