15 ms·
Google has another secret browser
- andybak 3y agoA team that handles security vulnerability reports should never say "oh - that's another internal team. Go ask them...". In fact almost any staff member inside an organisation that receives a plausible vulnerability report should ensure it reaches the right people. It's not something you should shrug off.
- gear54rus 3y agoI assume that's the reason he just made a writeup about it instead.
- extheat 3y agoIt’s not really a vulnerability in the sense that it leads to any sort of system compromise. It’s definitely a design flaw in whatever features they added to the OS, but not necessarily something that warrants a huge investigation.
- andybak 3y agoI think anyone expecting these security-related features to work as expected would regard it as a vulnerability.
- dcow 3y agoThere are also just normal bugs and known limitations and acceptable risks.
- kllrnohj 3y agoIs parental lock really "security-related" ? Like it's a frustrating response to this valid bug report, but it's not really a security risk here, either. You don't actually bypass the lock screen or anything.
- andybak 3y agoI think it really is and could have serious safeguarding issues. Also other features are effected like kiosk mode etc. The implications are unclear but could conceivably be quite serious in some scenarios.
- kllrnohj 3y ago> Also other features are effected like kiosk mode etc Is it? That's not demonstrated nor claimed in the linked article. > I think it really is and could have serious safeguarding issues. Elaborate. What's the security risk from your child using a browser after the parental control timeout expired? It's annoying that the automatic limits didn't fully happen, but data isn't compromised as a result, either.
- ramses0 3y agoBrowse the open internet (or internal network?!) from a McDonalds ordering kiosk? No skin in the game, but this is very similar to the old Win95 "About... Help... $BROWSER" style bypasses.
- tigerBL00D 3y agoIf I read that correctly, in the second case someone can bypass the pinning feature to access your personal information via the default browser's active sessions. That would be a compromise if that's the case.
- JoshuaRogers 3y agoSure, it's not arbitrary code execution, but it's certainly privilege escalation.
- xuhu 3y agoThey have these exact phrases in their best practices list, but with no instead of any, and always instead of never.
- TeMPOraL 3y agoThe "that's another internal team" reply was presumably more about bounty than vulnerability itself. Still, my contrarian take: support - whether external customers or internal stakeholders - is a game of hot potato: first person that fails to forward it to someone else will get burned. It would be great if everyone was happy to drop whatever they're doing and lead resolution of customer's complaint, regardless of who the actual empowered/responsible person/team is. Alas, we live in the world where most people subscribe to Copenhagen Interpretation of Ethics. In this world, even forwarding a request to those responsible is dangerous. Anything more than that entangles you with the problem, meaning you'll be held responsible for it, no matter your actual connection to it. We can call it "principal-agent problem", or just "survival in the world where requesters are hunting for anyone willing to engage with their requests". (Source: I used to be the one willing to handle any internal request even tangentially related to my work, until my line manager told me to ask requesters for project ID or billing code before giving any help that requires more than 1 minute, because otherwise I'll end up doing none of the work we're actually being paid for.)
- smallmancontrov 3y agoYes, and the worst part is I don't think it's even a side effect of organizational structure because I've seen it in so many places. There is just a quirk of human psychology where "if you touch a problem it belongs to you now," and the result is a situation where everyone would be genuinely happy and eager to help but nobody (except the newbie) dares try because the consequences for trying are immediate and dire.
- skybrian 3y agoThis seems related to what I think of as the “jurisdictional hack.” Nobody can solve every problem, so you define a realm that’s your responsibility and anything outside it is someone else’s problem. Keeping your jurisdiction small means you can do more within that jurisdiction, by ignoring even important problems that are outside it. But the alternative is ineffective doomscrolling because all the world’s problems are yours.
- Xeamek 3y agoThey said 'go ask them' a out why they decided to close the issue (which also implies that someone went over this already), not 'go ask them because we simply don't care to look', as your comment seem to imply...
- andybak 3y agoThe result was the same. Someone was reporting a bad thing. The bad thing never got fixed.
- Xeamek 3y agoThis is too reductive. The 'we analyzed the issue and decided it won't be fix' Is NOT the same as 'we don't cate about this, go talk to some other team and maybe they'll fix it'. Deciding something is not a bug is not the same as just ignoring the bug and not fixing it
- andybak 3y agoIn this case it is - because someone outside the org - who has no responsibility for your company fixing it's stuff - is being asked to make sure the issue isn't lost. Google lost out in this case - because an employee pushed responsibility onto an outside party.
- dcow 3y agoWhat did they lose out on?
- qingcharles 3y agoGoogle is the king of "not my department." "No, I don't have contact with any other department within Google." "No, I don't have the email address of anyone on any other team in Google." WTF, Google?
- skirmish 3y agoIt's most likely because when you forward any internal information to any outsiders, you will get a stern dressing-down by your manager.
- r00fus 3y agoThat's the ultimate cop-out. There is a way you can expose coordination with internal teams and colleagues without "I've reached out to a colleague who has provided me with some additional context" or "this work requires some additional input from another team - I'm working to establish this and will get back to you with more details" Neither of the above examples provide any more context on internal teammates or their organizations. However they do require additional work and a culture of customer support (which Larry Page was infamously against for years).
- acdha 3y agoThat’s an explanation, not a cop out. It’s saying it’s a problem with management’s incentives and presumably not easily corrected before they have a good CEO.
- crdrost 3y agoSo having worked there, this was absolutely true, and the parent complaint about hot-potato is also absolutely true. The problem as I see it is that Google came to be dominated by an egalitarizing culture which at first wasn't necessarily a problem. This was an explicit choice by Larry and Sergey, that your manager should not be able to unilaterally fire you just because of a personal disagreement, nor stiff you out of financial rewards, none of that. So, your manager lacks any formal authority over your day-to-day work: they have to use politics and soft power. Instead, performance is reviewed by a committee of your manager’s peers, who can “calibrate” that manager’s opinion of you against others and against empirical data. The result of being judged by a faceless committee is that implicitly, some things generate the empirical data that they look at, and other things don't. It's helpful to oversimplify this to a common currency of “perfcoin” Ⓟ even though that was never explicit at Google. Some activities generate Ⓟ, some don't. Google has built dozens of new chat apps because whenever you can have a good excuse for how this aligns with your business priorities, they generate lots of Ⓟ. The design documents are rich in Ⓟ, the tracking issues for each feature are rich in Ⓟ, getting the thing privacy-analyzed and internationalized can get you some Ⓟ, the inevitable work to merge it into another chat app is also worth Ⓟ. But please understand that the existence of Ⓟ is a result of semi-hierarchy. The manager exists (hierarchy) but has to point to an objective measure (Ⓟ) to say that you're not doing what you're supposed to (semi-), it is almost a mathematical deduction that this has to exist given that structure. Now networking with people outside of your team, will never get you any Ⓟ. And this is not for lack of trying! When I was there it was a job responsibility to do some things that were not your job responsibility (“community contributions”) to try and associate Ⓟ with some form of networking! And everyone hated it, and it didn't work anyways. Manager-committees immediately decided that Ⓟ would not be awarded for excessive networking, just that you had to prove a little bit of networking or else Ⓟ would be deducted. Furthermore the most reliable community contributions were noncommunal—conducting hiring interviews being the easiest: probably this person will not be hired, but even if they are, you will never interact with this person ever again. But, you conducted N interviews in the quarter and that is just barely enough to not get docked some Ⓟ for being a shut-in. I am giving somewhat of a negative portrait and it is not all negative, see Laszlo Bock’s Work Rules for the better parts. I'm just saying that the culture of not-my-department has been created by, and is sustained by, incentivization.
- irrational 3y agoHow do you even find the right people? I have no idea how I’d do that at my company.
- dylan604 3y agoSend it to the CTO, the receptionist, or even HR. hell, CC them all with a note saying that it is unknown where to send it to so hoping someone will know where to forward it. It also sounds like your company needs better internal communication about communications within the company.
- irrational 3y agoMy company has 80,000+ people. I doubt those people have any clue either.
- dylan604 3y agoRegardless of the number of employees, if the CTO can't figure out where it needs to go, then WTF does that CTO have a job?
- throwaway11460 3y agoTry contacting the CTO in a company of 100k+ people. Your email probably goes to their junk folder. I worked in a similarly sized company and I didn't even know the name of the CTO, nor if there even was one.
- dmazzoni 3y agoI worked at Google for many years. Google is so huge that it's extremely common to know you have an important bug for another team, but not to be able to route it to them because you can't find their team name. Most teams have "code names" that have nothing to do with the public name of the project. For example, the parental controls team might be named "pigglewiggle-team" and the Android contacts team might be named "katniss-team" and their bug components might have similarly obscure code names. If you don't work with those teams frequently it can be really daunting to find. Even when the bug components have hints that get you close to the right place, it's not unusual to learn that most of the engineers are busy working on the new version of the app that isn't released yet, and the old version of the app (the one with the bug) has been destaffed and bugs are supposed to be routed to some other random team that's literally never touched the code.
- curt15 3y agoI read that Google Play Services can even grant itself new permissions[1]. How does that work? Does it have root? [1]https://developers.google.com/android/guides/permissions https://developers.google.com/android/guides/permissions
- ignoramous 3y ago> Does it have root? Not really, but it is a privileged System app, which pretty much means it can do a factory load of things that installed apps cannot without root.
- matan-h 3y agoyes. (It's not really the 'root' user, but it trusts blindly and can do things such as installing apps without user confirmation.). In my other blog post about gms, the JS bridges would be running in the privileged scope. You agreed to this in Google's privacy policy when installing Android.
- Xeamek 3y agoSystems (or vendor) apps also have to predefine permissions in their manifest, so not every system app can do everything. But the list of permissions accessible by those apps is so broad they can effectively have root, as long as you define enough of them as developer
- ranger_danger 3y agothis is called a back door, not to mention it can already install (and uninstall!) apps without your permission. and yes they have already gotten in trouble for it in the past, but not enough happened to them.
- sureglymop 3y agoLuckily it can be installed sandboxed and not privileged. (E.g. with GrapheneOS).
- Lutzb 3y agoThe Googles parental controls leave so much to be desired. There is a long running requests for disabling the Play Store app. Still this is not possible without using adb (which is not a good solution, it leads to other problems). It feels like no real kids are testing the parental controls: For a long time it was trivially easy to circumvent a set YouTube time limit restriction by just opening Play Store, browsing to an app with a video in the screenshot list and head over to YouTube from there. My son actually showed me this when he discovered it.
- AtlasBarfed 3y agoIf Google care in the least for kids they would scrub all of those games that are predatory, introduce gambling addiction mechanics, use annoying and confusing in-game ads, and gateway to older even more addiction focused apps. Notice I didn't even mention all of the information hoovering. And of course the Play store is desperate for you to provide a credit card at every single opportunity so you can maximize the potential of kids doing accidental buying. It is a complete scam. I honestly don't know how television got such strict laws and regulations on children's programming, when viewed in comparison to the complete wild west, that is the modern app store.
- AndrewDucker 3y agoThe sheer fact that I can't differentiate between "Has ads, and you can pay to get rid of them" and "Has 15 different currencies that make the game no fun unless you pay a fortune" in the Play store is proof that Google don't want to promote good business practices.
- willsmith72 3y ago> I honestly don't know how television got such strict laws and regulations on children's programming, when viewed in comparison to the complete wild west, that is the modern app store. With time and pressure. Right now you have a fun new technology which people are still infatuated with, bought by one of the biggest companies to ever exist, in a country which openly permits business-to-politician payments through lobbying. The wild west won't look anything like it does 50 years from now
- Xeamek 3y agoEh, calling an embedded web-view a 'screet google browser' smells a bit clickbait'ish. In situations where it bypasses things like parental control its fair to bring it up as an issue, but it's not exactly a 'vulnerability' in the way a vulnerability is commonly understood
- make3 3y agothe pinning thing looks like other applications could assume it's safe when it's not actually, which is a normal recipe for a vulnerability. worth investigating at least
- mrweasel 3y agoPerhaps not, unless there is a security vulnerability in the web-view. I think it shows that there's a problem with the usage, and implementation of web-view and it's permissions. I can see why Google wouldn't want to apply the permissions and parental contracts from the browser to the web-view, that would break a bunch of stuff and it would be hard to explain to the user that a link in the Contacts app doesn't work, because Chrome is locked down. Others would argue that is exactly what they expect to happen. In this case I fail to see why Contacts embeds its own webview, rather than just triggering the browser to open the link. Not every app needs a web-view.
- disintegore 3y agoI expected Google Ultron
- deleted 3y ago[deleted]
- thiago_fm 3y agoI have a faint memory of having seen an HN article about this hidden browser before. In any case, the Google response you've seen shows how the company is messed up. Google became Microsoft in the 90s.
- dartharva 3y agoI remember using something similar to bypass the lock of an old phone my collegue had forgotten the password of in my teens. It involved downloading an apk from some shady site with this "in-built browser" that did something to unlock the phone, then factory-resetting it.
- deleted 3y ago[deleted]
- prymitive 3y agoReminds me of this classic gem: https://imgur.com/BULPmCI?r https://imgur.com/BULPmCI?r
- k8svet 3y agoExactly what I thought of. I've used a technique similar to the OP for bypassing FRP on a Pixel 2 that I bought used on Craigslist. Also provoked a similar thought of how my entire life was set in motion staring at this screen for hours as a bored little kid, finally breaking in and experiencing my first "hit".
- dang 3y agoRelated. Others? Google has a secret browser hidden inside the settings - https://news.ycombinator.com/item?id=36478206 https://news.ycombinator.com/item?id=36478206 - June 2023 (312 comments)
- zelon88 3y agoIs this the same Google that pours millions of dollars into its Project Zero securi-tainment blog where they specifically use hamfisted disclosure policies to discredit competing products? Oh, well color me shocked!
- dr_kiszonka 3y agoIn case anyone is interested in an earlier discussion from 2023 (312 comments): https://news.ycombinator.com/item?id=36478206 https://news.ycombinator.com/item?id=36478206
- jwithington 3y agowhat's the consequence of this? kids can bypass parental controls? just making sure i understand
- cynicalsecurity 3y agoThis is some Windows 98 login screen bypass hack trick. https://i.imgur.com/BULPmCI.gif https://i.imgur.com/BULPmCI.gif Honestly, I would have never expected Google to become Microsoft Windows 98 level bad at designing their systems.
- eigenvalue 3y agoSuch a great exploit because it doesn’t require you to know about arcane stuff like buffer overflows. Even a casual user could follow the process. So much of security seems to be just minimizing the attack surface so you have less to think about. Why does someone need to be able to print a tooltip in the sign in dialog? It’s absurd. Once you involve printing, you are letting in all kinds of third party stuff that isn’t secure at all. Even if you want to permit printing of tooltips or help in general, they should have had a “secure context” where such features are disabled. Similar stuff in PDFs too, where 99% of the use of random features in PDFs like 3D models or scripting was for security exploits. Keep it simple by default and avoid that stuff!
- zvmaz 3y ago> Why does someone need to be able to print a tooltip in the sign in dialog? It’s absurd. I doubt that it was intentional. Although careful deploying systems, I have often a feeling that we must have forgotten something that is trivially exploitable by someone. I wonder if there are provably secure systems in use somewhere...
- user3939382 3y ago> provably secure systems in use somewhere... There are. Check out sel4 and dependent type systems.
- zvmaz 3y agoYes, I've heard of those. What I wanted to write is "widely used" even at the user level (GUI programs, web applications, etc.). You prompted me to read more about seL4; the white paper is nice [1]. [1] https://sel4.systems/About/seL4-whitepaper.pdf https://sel4.systems/About/seL4-whitepaper.pdf
- mustacheemperor 3y agoThis takes me back to my own first experiences 'hacking' and tinkering with the guts of a computer system, which put me on the path to a career in IT and engineering: - Breaking the family computer with a trojan pirating Halo PC, which I then had to figure out how to fix before my dad got home - Circumventing the NetNanny, etc parental controls my parents randomly decided to install on our personal computers several years after us kids had already been using the internet (edit: okay, there may have been a letter from Comcast re: the above sloppy piracy). Restoring my netbook to useful functionality without leaving a trace of modification introduced me to Linux Live CDs, and Linux! Good to know tomorrow's hackers are still getting that education today!
- cpcallen 3y agoSimilarly: I remember spending quite a lot of time exploring [National Capital Feenet](https://www.ncf.ca/en/)'s https://www.ncf.ca/en/)'s Gopher pages in an attempt to find a link-to-a-link-to-a-page that would let me make arbitrary telnet connections, thereby bypassing their efforts to ensure that their free dialup service was only used to access their own services, rather than, say, to play Nethack on a public server at tamu.edu (whose exact domain name I can, alas, no longer recall).
- datadrivenangel 3y agoCircumventing NetNanny definitely forced me to level up my computer skills. Classic.
- devit 3y agoGrapheneOS with sandboxed Play Services seems unaffected. The Phone app doesn't seem to be able to view or open web URLs in contacts, and the Contacts app fails to open the two URLs given in the article in pinned mode.
- steveruizok 3y agotoad pond
- djmips 3y agoDidn't work for me. Fixed? Or did I fail or is it different on different Android phones?
- bsimpson 3y agoWhen I was a kid, banks and similar institutions would have computer terminals in the lobby, loaded up with the company website in a special browser that would only let you view that site. This was also the age of Best Viewed In badges. Whenever my parents would take me with them to run errands, I would find one of these computers and click around until I got a Best Viewed In badge. (It was often on the Help page.) That would bypass the restrictions of the single-site browser and take you to e.g. netscape.com, where you could find a link to a search engine and browse wherever you wanted.
- notyourwork 3y agoI remember in university, our computers in the rec center had restrictions like this. Our email could be opened via web, I would email myself a link to search engine, open email, right click and open in the same frame. At that point you could go anywhere you could find a search result for. Good times.
- TheKarateKid 3y agoReminds me of when the PCs on display at Sears, CompUSA, etc. would have their demo software running which didn't let you do the one thing you should do when buying a PC.. actually use it. So I used to CTRL+ALT+DEL and kill the demo software with the task manager. For the more stubborn demo software that would instantly relaunch, I'd then open msconfig, uncheck the demo software from running on startup, and reboot. I remember the amazement and joy of other people nearby watching, who would then ask me to do it on their PC so they too could click around and play Minesweeper or Pinball :-) Sounds so amateur now, but it's hard to remember that CTRL+ALT+DEL in the mid-90's was -- dare I say it? -- sort of a power tool that only more experienced users knew about.
- int_19h 3y agoI would actually say that Ctrl+Alt+Del was better known in mid-90s simply because so many people were still on DOS, and that was the proper and documented way to reboot it. Which was not uncommon to do especially since if a DOS app locked up, your entire OS was unusable.
- germandiago 3y agoWas not Google's slogan "Don't be evil" years ago?
- kccqzy 3y agoI'm pretty sure these parental control holes are left on purpose to train the next generation of enterprising hackers.
- bookofjoe 3y agoIf everyone here knows about it, is it still secret?