Google Chrome's Alleged Private API for Google Sites
Description
A screenshot of a tweet from developer Luca Casonato (@lcasdev) that makes a serious allegation against Google Chrome. The tweet, posted on July 9, 2024, claims that the Chrome browser provides all '*.google.com' domains with special, privileged access to sensitive system information, including CPU, GPU, and memory usage, detailed processor info, and a 'logging backchannel'. Casonato explicitly states, 'This API is not exposed to other sites - only to *.google.com.' The image captures a viral moment in the tech community, sparking a significant conversation about browser security, user privacy, and potential antitrust behavior. For developers, this raises concerns about the web's level playing field and whether a browser vendor is giving its own services an unfair, hidden advantage
Comments
44Comment deleted
It's not a 'logging backchannel,' it's a 'proactive performance telemetry service' that just happens to pipe directly into the ads division's revenue dashboard
SOP apparently now stands for 'Special Origin Privilege' - as long as your CNAME resolves to google.com
Ah yes, the classic 'it's not a backdoor, it's a feature' - except this time Google didn't even bother with the pretense. Nothing says 'Don't be evil' quite like giving your own domains the kind of system access that would make a rootkit jealous, while telling everyone else they need to respect the sandbox for 'security reasons.'
Ah yes, the classic 'do as I say, not as I do' approach to web standards. Google Chrome essentially gave itself root access to the browser while everyone else is stuck in userland. It's like being the only developer with production SSH keys because you also happen to own the data center. Nothing says 'open web' quite like a hardcoded whitelist of your own domains getting privileged system APIs. At least when Microsoft did this with IE and ActiveX, they had the decency to make it exploitable by everyone equally
Chrome's genius: Your tabs' CPU confessions go straight to Google, but only if the site's wearing the right domain badge
Chrome’s idea of origin privacy: google.com gets /proc; everyone else gets navigator.hardwareConcurrency and hope
New web primitive: navigator.syscalls() - works when eTLD+1 === 'google.com'; everyone else gets NotAllowedError and a lecture about the open web
That's a Firefox propaganda Comment deleted
Except that Mozilla slowly becomes what it "fights" with Comment deleted
examples plz Comment deleted
Anonymous advertisement using "anonymous identifier" Comment deleted
You mean in thr anonys tabs? Comment deleted
No, i mean literally "mozilla" adsense Comment deleted
They fight privacy violations. So far this ad method was not proven privacy-invasive. WTF are you talking about? Comment deleted
so far Comment deleted
Everything is so far. Innocent until proven guilty, you know? If it will be at some time, I will gladly join you with pitchforks. Comment deleted
you have missed the part with words "slowly becomes" Comment deleted
https://blog.mozilla.org/en/mozilla/mozilla-anonym-raising-the-bar-for-privacy-preserving-digital-advertising/ Comment deleted
But you know, they have to pay those bills somehow Comment deleted
(c) CEO i am perfectly fine with buying subscription for this browser, can't find one Comment deleted
- The latest one was the removal of censorship circumventing extensions regionally from Russia. I do highly believe stuff like this also happens in other places, where actually fighting for freedom may lead you to some undesirable situations with a big fist up your arse. This was resolved with extension access restored, but only because the community started the fire. - Firefox client on every platform is filled with various telemetry features, that only can be disabled with editing values in about:config. Opting out from the main GUI doesn't disable them all. - Mozilla does everything it can, instead of actually improving the browser stability and performance (especially on Android). A good example of that will be the acquisition of Anonym, "privacy preserving" ad tracking company. And guess what? It's already opt-out integrated in 128.0 release. Mozilla points their fingers at any easy target to gain "respect", but completely ignores their own actions. Comment deleted
Now this is a bit better finger pointing Comment deleted
People choose Firefox because at least it's not Google Comment deleted
Yet they should not consider Mozilla the messiah of internet privacy and freedom. Or this will end up with yet another addition to Alphabet. Comment deleted
When did Mozilla fight adds? Comment deleted
Sure, no other browser would do the same Comment deleted
Попался Comment deleted
Ага))) Comment deleted
Никогда такого не было и вот опять Literally what this posts text says Comment deleted
Колись админ, куришь?) (с) Comment deleted
https://fxtwitter.com/simonw/status/1810731216796324080 Comment deleted
Wait wait wait! Did he just used chatgpt answer as a solid proof? Comment deleted
So let me get this straight - people are freaking out because Google has an extension preinstalled to enhance certain first party sites in their own browser and said extension uses a standard API to get CPU info? Comment deleted
Yes. And this feature has been in the source code for the last ~10 years. Comment deleted
Wait til they hear how Vivaldi and brave implement a lot of their features Comment deleted
You mean that essentially it all is just JS? Comment deleted
That and a background page. Some UI customization can't be done that way but a lot of other customization they do with extensions Comment deleted
Knowing that gnome desktop devs use JS as main language for gnome client apps....info that a browser uses JS to render all it "outside the page" interface is less scandalous Comment deleted
Also it's easier to maintain across chromium upgrades Comment deleted
Yes. So we are going to allow it. Especially for a browser that retained iconic Opera 12 interface and functions Comment deleted
Imo it's more about browser fingerprinting which only google is allowed to do, nobody else. And yeah ff has lots of things I dont like like DRM plugin by Google, and other crap I can't remember rn. But who knows how much more hidden gems the 80GB google source code has that benefits only threm... Comment deleted
there are actually some rather eery permissions that, if i inderstand correctly, are given by default, without asking the user Comment deleted
You forgot to mention; its built into chromium, and accidentally edge left the cade in there too. Comment deleted
POV Microsoft: "let's avoid getting another anti trust lawsuit and help google this time" Comment deleted