Showing posts with label Google. Show all posts
Showing posts with label Google. Show all posts

Wednesday, May 31, 2017

Google Chrome "feature" allows recording audio and video without indicator

Slashdot writes about it here - Google Chrome Bug Lets Sites Record Audio and Video Without a Visual Indicator

"Ran Bar-Zik, a web developer at AOL, has discovered and reported a bug in Google Chrome that allows websites to record audio and video without showing a visual indicator," reports BleepingComputer. "The bug is not as bad as it sounds, as the malicious website still needs to get the user's permission to access audio and video components, but there are various ways in which this issue could be weaponized to record audio or video without the user's knowledge. The bug's central element is a 'red circle and dot' icon that Chrome usually shows when recording audio or video streams." Bar-Zik discovered that if the JavaScript code that does the actual audio and video recording is launched inside a small popup, the icon is not shown anymore. This opens the door for various types of scenarios, where an attacker that has tricked a user into granting him permission to record audio and video records user data but when the user doesn't expect this (no visual indicator). For example, an attacker could disguise audio/video recording code inside popup ads. If the user doesn't close the popup, the popup continues to stream audio and video from the victim's house. Google declined to consider this a security bug.

Google bug site at first treats it as a feature not a bug,


Components: UI>Browser>Permissions>Indicators Labels: -Type-Bug-Security -Restrict-View-SecurityTeam Team-Security-UX OS-Chrome OS-Linux OS-Mac OS-Windows Type-Bug Status: Available
Thanks for the report. This isn't really a security vulnerability - for example,
WebRTC on a mobile device shows no indicator at all in the browser.  
The dot is a best-first effort that only works on desktop when we have chrome UI space available. That being said, we are looking at ways to improve this situation. I'll put this in our general permissions indicator pool.
 but  I expect they'll come around quickly

Tuesday, March 25, 2014

Google: Another update, Pando shows that Google joined a cartel forcing down IT workers wages

According to Pando Daily, Google, Apple  and a host of other companies got together, and made a list of companies that wouldn't call each other for tech workers.  How nice.  There is even (email) evidence of at least 1 recruiter who lost his job for being overly aggressive in, umm, recruiting, at a company he wasn't supposed to touch, but wasn't told until, well, he might've got the hint at the same time he was walked out.

The whole list (from Pando again) is:
 • Apple, Inc
• Comcast Corporation
• DoubleClick
• Genentech
• IBM Corporation (Junior hires okay—also applies to subsidiaries)
• Illumita
• Intel Corporation
• Intuit
• Microsoft
• Oglivy
• WPP 
And might have gotten as far as a million workers.  There's an antitrust lawsuit in the works, scheduled for May, but things are settling out of court.  Seeing as some of this is serious, of course there are out of court settlements.

Monday, March 17, 2014

Google: That whole "don't be evil" thing is so last century!

According to Edweek.org, The latest thing in Google slide to become the great evil empire is the "Google Apps for Education".  

Apparently Google has these free applications that schools can sign up for, and then require their students to use.  Then Google scans the content learning all kinds of things about the students.

Why do I think that's a problem? Well, let's see what happens in a class action lawsuit in San Jose, which Judge Lucy H Koh denied Googles motion to dismiss the case and is not deciding whether to certify it as a class. (Google Inc. Gmail Litigation, 13-md-02430.)

 Also, there's FERPA, the "Family Educational Rights and Privacy Act", which is meant to protect students privacy, and gives the following example:
EXAMPLE 4: A district contracts under the school official exception with a provider for basic productivity applications to help educate students: email, calendaring, web-search, and document-collaboration software. The district sets up the user accounts, using basic enrollment information (name, grade, etc.) from student records. Under FERPA, the provider may not use data about individual student preferences gleaned from scanning student content to target ads to individual students for clothing or toys, because using the data for these purposes was not authorized by the district and does not constitute a legitimate educational interest as specified in the district’s annual notification of FERPA rights.
Yes, right, which is exactly what Google does with Gmail, and they state they make no secret of.  Except they're not contracting with adult users of the services, they're contracting with schools that require minor students to use the applications.

How about Microsoft Office 365?
The privacy policy for Microsoft’s Office 365, the company’s competitor product for Google Apps for Education, states “We do not mine your data for advertising purposes. It is our policy to not use your data for purposes other than providing you productivity services.” 
Score 1 for Microsoft