Skip to content
DevMeme
5560 of 7590
Security Post #6102 · source on Telegram

Google Chrome's Alleged Private API for Google Sites

Description

A screenshot of a tweet from developer Luca Casonato (@lcasdev) that makes a serious allegation against Google Chrome. The tweet, posted on July 9, 2024, claims that the Chrome browser provides all '*.google.com' domains with special, privileged access to sensitive system information, including CPU, GPU, and memory usage, detailed processor info, and a 'logging backchannel'. Casonato explicitly states, 'This API is not exposed to other sites - only to *.google.com.' The image captures a viral moment in the tech community, sparking a significant conversation about browser security, user privacy, and potential antitrust behavior. For developers, this raises concerns about the web's level playing field and whether a browser vendor is giving its own services an unfair, hidden advantage

Comments

44
Anonymous ★ Top Pick It's not a 'logging backchannel,' it's a 'proactive performance telemetry service' that just happens to pipe directly into the ads division's revenue dashboard
  1. Anonymous ★ Top Pick

    It's not a 'logging backchannel,' it's a 'proactive performance telemetry service' that just happens to pipe directly into the ads division's revenue dashboard

  2. Anonymous

    SOP apparently now stands for 'Special Origin Privilege' - as long as your CNAME resolves to google.com

  3. Anonymous

    Ah yes, the classic 'it's not a backdoor, it's a feature' - except this time Google didn't even bother with the pretense. Nothing says 'Don't be evil' quite like giving your own domains the kind of system access that would make a rootkit jealous, while telling everyone else they need to respect the sandbox for 'security reasons.'

  4. Anonymous

    Ah yes, the classic 'do as I say, not as I do' approach to web standards. Google Chrome essentially gave itself root access to the browser while everyone else is stuck in userland. It's like being the only developer with production SSH keys because you also happen to own the data center. Nothing says 'open web' quite like a hardcoded whitelist of your own domains getting privileged system APIs. At least when Microsoft did this with IE and ActiveX, they had the decency to make it exploitable by everyone equally

  5. Anonymous

    Chrome's genius: Your tabs' CPU confessions go straight to Google, but only if the site's wearing the right domain badge

  6. Anonymous

    Chrome’s idea of origin privacy: google.com gets /proc; everyone else gets navigator.hardwareConcurrency and hope

  7. Anonymous

    New web primitive: navigator.syscalls() - works when eTLD+1 === 'google.com'; everyone else gets NotAllowedError and a lecture about the open web

  8. @Sp1cyP3pp3r 2y

    That's a Firefox propaganda

    1. @maximilionus 2y

      Except that Mozilla slowly becomes what it "fights" with

      1. @Hollow_Arigo 2y

        examples plz

        1. @Infinitelineman 2y

          Anonymous advertisement using "anonymous identifier"

          1. @Hollow_Arigo 2y

            You mean in thr anonys tabs?

            1. @Infinitelineman 2y

              No, i mean literally "mozilla" adsense

              1. @Bitals 2y

                They fight privacy violations. So far this ad method was not proven privacy-invasive. WTF are you talking about?

                1. @Infinitelineman 2y

                  so far

                  1. @Bitals 2y

                    Everything is so far. Innocent until proven guilty, you know? If it will be at some time, I will gladly join you with pitchforks.

                    1. @Infinitelineman 2y

                      you have missed the part with words "slowly becomes"

            2. @Infinitelineman 2y

              https://blog.mozilla.org/en/mozilla/mozilla-anonym-raising-the-bar-for-privacy-preserving-digital-advertising/

              1. dev_meme 2y

                But you know, they have to pay those bills somehow

                1. @Infinitelineman 2y

                  (c) CEO i am perfectly fine with buying subscription for this browser, can't find one

        2. @maximilionus 2y

          - The latest one was the removal of censorship circumventing extensions regionally from Russia. I do highly believe stuff like this also happens in other places, where actually fighting for freedom may lead you to some undesirable situations with a big fist up your arse. This was resolved with extension access restored, but only because the community started the fire. - Firefox client on every platform is filled with various telemetry features, that only can be disabled with editing values in about:config. Opting out from the main GUI doesn't disable them all. - Mozilla does everything it can, instead of actually improving the browser stability and performance (especially on Android). A good example of that will be the acquisition of Anonym, "privacy preserving" ad tracking company. And guess what? It's already opt-out integrated in 128.0 release. Mozilla points their fingers at any easy target to gain "respect", but completely ignores their own actions.

          1. dev_meme 2y

            Now this is a bit better finger pointing

          2. @qtsmolcat 2y

            People choose Firefox because at least it's not Google

            1. @maximilionus 2y

              Yet they should not consider Mozilla the messiah of internet privacy and freedom. Or this will end up with yet another addition to Alphabet.

      2. @Bitals 2y

        When did Mozilla fight adds?

    2. @plusdanshi69 2y

      Sure, no other browser would do the same

  9. @theodolu 2y

    Попался

    1. @timopheym 2y

      Ага)))

  10. @trainzman 2y

    Никогда такого не было и вот опять Literally what this posts text says

  11. @timopheym 2y

    Колись админ, куришь?) (с)

  12. @RustyOtter 2y

    https://fxtwitter.com/simonw/status/1810731216796324080

    1. @Danich 2y

      Wait wait wait! Did he just used chatgpt answer as a solid proof?

    2. @qtsmolcat 2y

      So let me get this straight - people are freaking out because Google has an extension preinstalled to enhance certain first party sites in their own browser and said extension uses a standard API to get CPU info?

      1. @maximilionus 2y

        Yes. And this feature has been in the source code for the last ~10 years.

        1. @qtsmolcat 2y

          Wait til they hear how Vivaldi and brave implement a lot of their features

          1. @Agent1378 2y

            You mean that essentially it all is just JS?

            1. @qtsmolcat 2y

              That and a background page. Some UI customization can't be done that way but a lot of other customization they do with extensions

              1. @Agent1378 2y

                Knowing that gnome desktop devs use JS as main language for gnome client apps....info that a browser uses JS to render all it "outside the page" interface is less scandalous

                1. @qtsmolcat 2y

                  Also it's easier to maintain across chromium upgrades

                  1. @Agent1378 2y

                    Yes. So we are going to allow it. Especially for a browser that retained iconic Opera 12 interface and functions

      2. @ZgGPuo8dZef58K6hxxGVj3Z2 2y

        Imo it's more about browser fingerprinting which only google is allowed to do, nobody else. And yeah ff has lots of things I dont like like DRM plugin by Google, and other crap I can't remember rn. But who knows how much more hidden gems the 80GB google source code has that benefits only threm...

  13. @Aqualon 2y

    there are actually some rather eery permissions that, if i inderstand correctly, are given by default, without asking the user

  14. @ZgGPuo8dZef58K6hxxGVj3Z2 2y

    You forgot to mention; its built into chromium, and accidentally edge left the cade in there too.

    1. @ZgGPuo8dZef58K6hxxGVj3Z2 2y

      POV Microsoft: "let's avoid getting another anti trust lawsuit and help google this time"

Use J and K for navigation