An iframe from googlesyndication.com tries to access the camera and microphone
techsparx.com
techsparx.com
There is probably some way to determine if the request was denied automatically by the browser or manually by the user (e.g., time to get "response"), which is definitely something which can be used for fingerprinting.
Which reminds me of fingerprinting by tiny differences in the audio API provided by browsers [0]. Super interesting, but also a bit depressing. Also works for things like canvases and WebGL.
EFF allows you to check how fingerprintable your browser is [1]. Do note that the results may not be very accurate.
<iframe src="https://\*.safeframe.googlesyndication.com/safeframe/1-0-38/html/container.html" title="3rd party ad content" sandbox="allow-forms allow-popups allow-popups-to-escape-sandbox allow-same-origin allow-scripts allow-top-navigation-by-user-activation" allow="attribution-reporting"></iframe>
As you can see, it has both sandbox[1] and allow[2] attributes.
The former restricts certain behaviors of the embedded code (most notably, navigating the top window without user activation), and the latter restricts it from accessing certain APIs - this why the author saw errors in the console.The script at https://cdn.js7k.com/ix/talon-1.0.37.js is an ad verification library developed by Verizon Media (formerly Oath), and it does, among other things,, fingerprinting for bot detection purposes (because they want to prevent ad fraud). It was served together with the actual ad media (so called "creative") into the safeframe.
This a relativity begin case. Iv'e seen much more terrible stuff, from fingerprinting for user taking to straight out malware being served in ads. It's a wild west (or web).
[0]: https://www.iab.com/guidelines/safeframe/
[1]: https://developer.mozilla.org/en-US/docs/Web/HTML/Element/if...
[2]: https://developer.mozilla.org/en-US/docs/Web/HTML/Element/if...
That verizon JS is surprisingly not very obfuscated so if anyone is interested or just curious to hack around this is a great one to look at!
It looks like they are checking notificationPermission for notifications. stores (this.permissionStatus = "") & (this.notificationPermission = "")
I don't see any requestPermission() in the verizon js. So it's probably not the culprit?
I also don't think that would make sense for them to do it. it's probably a bad faith advertiser.
I'm not sure if cross origin permissions requests can be blocked by the parent safe frame yet? It looks like Chrome is proposing but I can't find any info on if it has been implanted? [1] [2]
-------
I really enjoy fingerprinting. Just feels like 'hacking' in the basic sense of poking around with things. Since I don't know enough to make actual complicated real vulnerability hacking. I've built a pretty big js file for our own ads analytics & tracking.
The verizon js has most basic common things but one that sticks out as cool is cssSelectorCheck & cssRuleCheck checks a few like div:dir(ltr) probably for eastern languages, and stuff like -moz-osx-font-smoothing: grayscale.
I also like the idea of adding HONEYPOT_TAGS looks like they are adding a button to check for auto click publisher fraud. But man they should have obfuscated that name....
One interesting idea to expand on the css testing they have started to use a small amount.
I've played with is placing actual unique CSS features and @supports in styles and then measuring them. Maybe use variables pass to js. Also a couple @media sizes to see if it's lying about size. Can also measure if css/svg animation is paused for view ability.
There are a ton of new css features that are implemented in different browser versions so likely high entropy. Also would love to learn paintWorklet just to know it for design and also seems like a big surface area (svg too).
I'm kind of surprised they aren't doing a RTCPeerConnection to try and get any IPs and it doesn't look like they are doing actual webgl / audio prints.
seeing the mime type checks is validating to me. that's the latest check I added it's pretty fast to execute i have something like 150 different codes/mime types loop through lol. Verizon is more sensible in checking only a couple lmfao
[1] https://docs.google.com/document/d/1iaocsSuVrU11FFzZwy7EnJNO... [2] https://dev.chromium.org/Home/chromium-security/deprecating-...
Not that I am a huge fan of Brave, but I think they have implemented something like this for certain (or all) APIs. You will still have a unique fingerprint, but it should not match to any previous fingerprints you had in the past.
Edit: see https://brave.com/privacy-updates/3-fingerprint-randomizatio...
This was fairly secure because even the same employee was unlikely to get the same fingerprint twice - it was only occasionally more convenient than generating a random hash everytime they opened the browser. It became a huge pain for managers to be called constantly on the weekend to remotely reauthorize the devices they'd just authorized a few hours ago, or when chrome suddenly updated itself for half the employees, so eventually we switched to a looser hybrid of fingerprints and local storage.
That's my rather naive opinion, idk am I just being naive?
There are so many possible variations that it seems like preventing fingerprinting by pretending you're something you're not would be an impossible task and makes you even more unique, not less.
live laugh love as the user-agent
If your fingerprint is unique and doesn't change then yes, you stand out. But if your fingerprint changes on every page load, then you become indistinguishable from other users.
This is presumably because most people don't attempt to thwart fingerprinting.
If a particular feature behaves differently between the three most common browsers, it can be used to distinguish them. If you disable it, now you don't look like any of the most common browsers, which puts you in a category with a smaller number of people in it.
Solution: Get more people in it by having more people install anti-fingerprinting extensions etc.
Not if you use Tor Browser.
In the interest of fair balance, I have had the opposite experience.
"I've given up..."
That's probably what "tech" companies are hoping you will do. I see this response repeatedly on HN when the fingerprinting topic comes up. I am wondering if the persons submitting these replies want others to "give up".
Is there a difference between users wanting to appear "the same" and a desire by users to stop supplying maximum amounts of free data/information to "tech" companies and exacerbating the problem of online advertising and associated surveillance.
If a user sends no fingerprinting data/information, then she might be "unique" because most users are sending excessive amounts of fingerprinting data/information. However, IMO, that is hardly a sound argument for continuing to send excessive amounts of fingerprinting data/information. I subscribe to the general principle of sending the least amount of information possible to successfully retrieve a page. This might be "unique" user behaviour, but I am confident it is the correct approach. The big picture IMHO is that "tech" companies, generally, are trying to collect data/information about users to inform online advertising. Uniquely identifying users is only a part of what they are trying to do.
It is a bit like telling a user to use/not use an ad blocker based on what other users are doing, so as to avoid being "unique". This might help with avoiding "uniqueness" but clearly there are gains to be had from using an ad blocker that are greater than the value of trying to appear "the same" as every other user.
Imagine users are all trying to appear exactly the same, so they embark upon coordinating with each other to make the exact same choices. It stands to reason that the number of choices each user has to make is going to be a factor in whether this is successful.
If every user is choosing to send large amounts of data/information (e.g., using browser defaults), then every user has to coordinate their choices on every single data point or bit of information. The higher the number of "correct" choices each user has to make, the less likely that all users succeed in being uniform. There are more chances for error. Whereas if we reduce the number of data points and bits of information so that every user is only sending one or two headers, with no Javascript, CSS, etc.,^1 then that is far easier for users to coordinate.
1. This has been tested heavily by yours truly for decades. One does not need a graphics layer or graphical browser features to make successful HTTP requests. I am not interested in being "invisible", I am interested in reducing the amount of free data/information I give to "tech" companies. Perhaps there is a difference between wanting to "blend in" and wanting to stop "feeding the beast".
"We do not know anything about User A. It looks like she is using TOPS-20 to browse the internet."
Is User A less or more likely to be unique. Probably more. Is User A a more or less viable target for online advertising. To me, it is the second question that matters the most.
You don't have "googlesyndication.com" blocked?
That phenomenon is called the Streissand effect
> It is particularly useful to identify malicious visitors attempting to circumvent tracking
Ah yes, the visitor trying to not be tracked is the malicious one. Barf.
<iframe src="https://*.safeframe.googlesyndication.com/safeframe/1-0-38/html/container.html" title="3rd party ad content" sandbox="allow-forms allow-popups allow-popups-to-escape-sandbox allow-same-origin allow-scripts allow-top-navigation-by-user-activation" allow="attribution-reporting"></iframe>
As you can see, it has both sandbox[1] and allow[2] attributes.
The former restricts certain behaviors of the embedded code (most notably, navigating the top window without user activation), and the latter restricts it from accessing certain APIs - this why the author saw errors in the console.The script at https://cdn.js7k.com/ix/talon-1.0.37.js is an ad verification library developed by Verizon Media (formerly Oath), and it does, among other things,, fingerprinting for bot detection purposes (because they want to prevent ad fraud). It was served together with the actual ad media (so called "creative") into the safeframe.
This a relativity begin case. Iv'e seen much more terrible stuff, from fingerprinting for user taking to straight out malware being served in ads. It's a wild west (or web).
[0]: https://www.iab.com/guidelines/safeframe/
[1]: https://developer.mozilla.org/en-US/docs/Web/HTML/Element/if...
[2]: https://developer.mozilla.org/en-US/docs/Web/HTML/Element/if...
That setting is exactly the sort of reason I'm locked in a war to block ads from Google and others. What good is an escapable sandbox, other than for Google?
"Allows a sandboxed document to open new windows without forcing the sandboxing flags upon them".
If it was absent, when user clicks the ad and it opens a new tab of the advertiser website, it would inherit the sandbox directives from the safeframe, which might break it. To be clear "sandbox" in this context refers to the iframe sandbox[0], not to be confused with the renderer process sandbox[1].
[0]: https://developer.mozilla.org/en-US/docs/Web/HTML/Element/if...
[1]: https://chromium.googlesource.com/chromium/src/+/refs/heads/...
But since there is absolutely no consideration for privacy from corporations like Google or Facebook, I don't see the need to support their perverse business model.
If enough users participated in such schemes, maybe these privacy invasions would stop.
Hopefully The Browser doesn't pester the user each time, either.
How does it work? What value does it provide? Who are the major players?
I work in marketing but feel like it’s a completely other world.
When does fingerprinting ever fail? Maybe in Brave and/or Tor, but I wouldn’t bet on it.
Google tries to sandbox the creatives in an attempt to prevent issues exactly like this, and develops browser features to prevent issues exactly like this.
This is likely a script that somehow avoided google's malware scanning pipelines.
This is definitely not google's malintent.
Disclaimer: Ex googler, worked in ads, dealed with problems like this all the time.
I can't think of a good reason for scripts through google ad syndication to be asking for camera and microphone permissions. I'd assume Google runs these scripts in something like a lab environment to see what's ultimately invoked before deploying them to production? If so, would this be indicative of both a deliberate controls bypass and a ToS violation by the ad network?
Sounds like Google Syndication may have taken care of this by enabling Permissions Policies(1) across its domains? I can't tell because the article references Feature Policy (a predecessor to Permissions Policies(2)) "in Safari" even though Feature and Permissions Policies, as best as I understand them, are delivered from the origin for implementation by the browser. So I'm kinda confused.
And if they don't implement it, it tells me they're totally fine with this kind of fingerprinting.
(1)https://developer.mozilla.org/en-US/docs/Web/HTTP/Feature_Po... (2)https://www.w3.org/TR/permissions-policy-1/
---
A prior version of this comment suggested Google should add permissions policies. I since edited it to clarify that I'm quite confused over whether it's something Google already implemented or something Safari overlaid on top of Google syndication origins since I can't verify using the origins themselves. The article seems to suggest it's something Safari specific even though the spec for both FP and PP involves receiving a set of permissions from the origin as a header and implementing them in the browser.
See vendors like “the media trust”
The NSO group iMessage exploit is a more interesting example, essentially turning a poorly bounded JBIG2 decompressor into a virtual machine.
It's a huge bummer that I HAVE TO block all ads as a security measure, though, and that people accept "Download advertisement.exe and run it in a half-assed sandbox or you're stealing that clickbait article" as the way things should be
After the initial investment in developing the exploit and before the vulnerability was patched, there would have been a near zero cost to hack any one user in particular.
What if bad actors figured out a way to identify google's emulators and avoid doing bad stuff in that situation?
The part i said "google develops browser solutions to prevent issues like this" is exactly what features policy will end up doing. But google's ad systems and chrome features don't always move at the same speed, but you can be sure that whatever ad malware team is finding will help chrome team to strengthen their defense.
The script could just detect the test environment and avoid triggering its malicious behavior.
No, it just means that it is impossible to do for every program. Google could just make it reject scripts it is unable to handle.
And this doesn't apply just to the ad network, it also applies to the publisher. I'd really like the publishers to be held liable for malvertising they serve.
There is nothing inherently hard about serving safe ads, we've gotten pretty good at separating code from content nowadays. There is no reason why a "classic adsense" three-blue-links ad should be able to inject malware. Even images can be served safely. The only reason why this happens is because in pursuit of a few percent more profit (and more tracking) everyone allows everyone to include arbitrary scripts.
Why wouldn't google just block access to those API's? I mean I guess that's what this sandbox did.
A static analysis is often relatively easy to circumvent, something like base64Decode(encodedMaliciousScript) can by-pass them.
Google does various runtime/dynamic analysis to figure out issues, but scripts can do interesting things to circumvent those too (like targeting specific devices through user agent and so on).
It's an arms race, often, where google catches up pretty fast, but bad actors move faster.
Feature Policy check addresses these but ad system and chrome features don't always move at the same speed, and often time there are trade offs that needs to be addressed first before it can be widely deployed.
Note: I also work in adtech, and my daily job is to maintain a library that has to load inside google's safe frame...
Why allow any thing on any advertisement, regardless of network, that is not image or text? Anything else opens up security issues.
"Ad networks need to be able to do their own attribution and click spam detection."
Step outside technical approach mode and look at it from the highest level possible -- why are end users ever given more than images and text, or, why are ads anything more than a very simple a href tag.
Spam detection and other protection of the ad platform should be done long before this information ever goes to the eyeball product owners.
You will have headless browsers simulating clicks and so on. This gets extremely hard over time fake, and the more signals there are, the easier it's to spot anomalies.
In a way, the thinking is - a malicious actor will get at least a few of those signals inorganic and ML can detect them...
"Long before the information ever goes to the eyeball" => wish it was true.
(That it's an iframe running on https://[random].safeframe.googlesyndication.com tells us it's an ad served through Google Ad Manager, and the contents of the iframe are supplied by the advertiser.)
Disclosure: I work for Google, speaking only for myself
If you haven't already installed: https://addons.mozilla.org/en-US/firefox/addon/ublock-origin... https://chrome.google.com/webstore/detail/ublock-origin/cjpa...
On the other hand, it's not clear to me that whatever this advertiser is trying to do is having any real effect, aside from causing a console message that it is being blocked. Access to the mic and camera from cross-origin iframes is blocked by default, and you can't even trigger a permissions prompt.
As for installing an ad blocker, even with all the messiness of advertising, I still prefer it to paywalls.
Letting ads run arbitrary JS is the policy, right? It's not like that's a requirement to make the internet work, that's just a Google policy that trades money for user experience.
I mean, anything on the Web can run arbitrary JS. The entire point is that it's a sandbox environment where arbitrary JS can't do any harm (excluding cases where vulnerabilities are found).
If you're not comfortable with arbitrary JS running on your computer, you'd have to either (a) not use the Web, (b) disable JavaScript, or (c) only visit sites which you have vetted and deem to be trustworthy. None of those are particularly practicable.
Most of us operate on the generally-reasonable assumption that the sandbox is effective, and therefore that we're OK to [click on that random link from HN like you did just now / open that news site which pulls in a bunch of tracking scripts / etc].
Either way, this is not somehow a problem that's specific to Google Ad Manager in any way at all. I don't know what else you could really expect of them.
> I don't know what else you could really expect of them.
Your option C is basically how it must work, and mostly does. To be safe online we go to sites we trust. When Google delivers malicious JS through ads, the site operator probably doesn't know Google has harmed the user on their behalf, so their trustworthiness becomes moot. Is there some "safe ads" codeless option for site operators who want to protect their users while still showing ads? Has Google made site operators aware they occasionally deliver malicious JS to users?
I'm fairly confident in saying that nobody, but nobody, only goes to sites they trust. Come on. You're on HN: do you mean to tell me that you never click to open a link from a post unless you've pre-vetted the website and know it to be trustworthy? That's simply not a practicable model.
And every site pulls in JavaScript which, to you, is arbitrary. You don't know that they won't add a new third-party script, and you don't know that any given third-party script won't change. You don't know that transitively for the scripts loaded by the scripts. Etc etc etc. Nobody can practise the approach you are setting out here, not both diligently and honestly.
Your complaint here is just about how the internet works. It's absurd to expect Google to vet the JavaScript that all of its users host, as much as it's absurd to expect Squarespace or Weebly or even AWS or Cloudflare to do the same. The model of the internet does not and cannot rely on any and all JavaScript being vetted for 'malice' by a trusted party before being loaded. It relies on the JavaScript runtime being a safely isolated sandbox where malice or the lack thereof doesn't matter either way.
A bunch of us were working on a project where ads would be fully declarative, and so no longer able to run arbitrary JavaScript, but this received very little interest outside of Google (advertisers didn't want to move to a new format, publishers didn't care) and we moved on.
(Still speaking only for myself)
Twitch shows that people are very willing to pay for content. I'd very much be happy to if that removed all of the spam.
And for sure, I appreciate being able to buy stuff online. But I seem to be able to do that without viewing ads! Amazing!
No offense but I've heard people who work at ad companies repeat this like a mantra, and it's a false dichotomy, akin to a coal company who dumps slag in rivers saying, "Well we think it's better than letting everyone freeze to death." We're not asking Google to stop advertising altogether and close up shop, just to make the internet ad ecosystem a little less awful and Orwellian.
I think my parent was: "No one needs ads. Not arbitrary JS ads, not declarative ads, not personalised ads, not any ads."
I agree with you. I spent a large part of 2018-2019 trying to make ads declarative, and am now working on (among other things) increasing the isolation of conventional ads [1] and implementing cross-site advertising without cross-site identity leakage [2].
But it sounds like you and my parent have very different views: there's a lot of space between "ads should be a lot better" and "ads should not exist".
Not my money. Why should I care about lawsuits between advertising networks and their advertisers, regulators and so on?
You don't need to. But the person is asking why Google is or is not doing a particular thing. So it is their interests that are relevant to the current discussion, not yours.
What a fantastic idea to create a platform where anyone can pay to have code ran on millions of end-user machines, embedded in random websites. What could possibly go wrong?
In addition, why is it hard to enforce a policy that disallows any ad to reach out to the camera and microphone? I don't understand why that is hard to enforce.
Are you talking about crypto mining? That's a good example of something which is against policy but difficult to fully prevent technically. The core problem from someone trying to exploit this, however, is that crypto mining in the browser is minimally profitable, so you need to do a huge amount before seeing noticeable returns. The more you try to do the more likely you are to get caught, so while it does take some scrutiny from publishers and ad networks, it doesn't take very much.
(still speaking only for myself; this isn't something I know very much about)
And given that we are talking about sometimes eight figures worth of ad buying... no network will want to risk offending such clients.
EDIT: I am wrong to think that serving and interacting with a sqlite database goes without javascript.
Making use of the SQLite database is entirely client side and requires JavaScript or WASM (the distinction is unimportant) - it requires running code on the frontend. This is not a great way to state your case.
This was the main thing I worked on in 2018-2019, along with many other engineers. I wrote about it some in https://www.jefftk.com/p/value-of-working-in-ads If this is something that users were demanding I could see picking it up again, but as far as we could tell us a time there was minimal interest externally.
It's not that hard, at least not at my end. I just don't run ads.
Why on earth does goo think that running arbitrary JS on their visitors' computers is OK? I mean, I know this is the policy, and I assume the policy of other ad networks is at least as "liberal". So I'm sorry, chaps, but no ads run on this screen.
I wonder if this is a race to the bottom? I've noticed that TV ads these days are all for animal charities, equity release schemes, and incontinence pads. I don't know what they're running in web ads, but I'm pretty sure that the TV ads are so dire because everyone but old fogeys and poor people skip the ads. I'd assume the same old/poor people are the ones that have to see web ads.
Advertising to poor people has traditionally been a pretty bad pitch. So why isn't the online/TV ad industry crumbling? And how do I bet against their shares?
Is that true? It seems like poor people spend, in aggregate, more than rich people and they tend to buy the cheaper, more mass-produced stuff. The grocery business alone must be build on the commerce of poor people, right?
How often do you see grocers advertising own-brand baked beans? If you see baked beans advertised at all, they're drawing attention to the fact that their Heinz beans are 1p cheaper than $COMPETITOR's Heinz beans.
I'm not convinced that advertisers spend much money on pitching to poor people. Most of the ad pitches that I see are for high-end products like cars, holidays, and household appliances. There's not much point in advertising to people whose weekly budget doesn't stretch to luxuries. They will buy only what they need; they don't have choices.
That's the problem!
You are correct, that is the author's concern.
The reason the rest of us are concerned is because the general public has been conditioned by Google and others to just press "Accept" any prompt that pops up, no matter how dangerous.
I auto-press [Accept]. I use an ad-blocker. I reject 3rd-party cookies. I disable JS by default, and re-enable it selectively for sites that refuse to work without JS. If that re-enablement involves more than a few clicks, I'll close the site - there are other fish in the sea.
What am I doing wrong?
If something dangerous to privacy is being widely used in the world, then putting it behind a prompt creates an avalanche of prompts, and results in user apathy.
But not prompting requires you to choose a default, which either default to block and breaks things (if it was actually required) or defaults to allow.
It may be widely used, but for a highly concentrated set of sites. I can't think of an occasion I've used it beyond Google, Microsoft, and Zoom properties. Perhaps Slack and Discord too? So there must be a better way.
I believe this is the default for most browsers now, right? (Or have I been spoiled by Firefox?) This is the best way, where the camera is always inaccessible, unless you enable it for a domain which needs it. Since I rarely ever see the camera/mic request option, I don’t think we’ve been conditioned to allow this type of request. (Compared to cookies, which show up on nearly every site.)
If you want to disable permissions dialogues altogether, then what’s a trusted domain? Just zoom and a handful of others? If you write yourself a nice app which uses the mic, do you have to email Google to get yourself added to the list of trusted domains? That would be pretty bad for the open web, so permissions dialogues are the alternative
This is how Firefox tracker protection, uMatrix, noscript, and a plethora of ad blockers and other privacy tools work.
The extension you're linking allows someone to opt out of Google Analytics across all sites. That pretty much has to be a browser extension, because GA by default doesn't use any third-party cookies (and third party cookies are going away anyway).
(Disclosure: I work at Google, speaking only for myself)
My understanding is that I have an advertisement ID attached to my user, and that enables Google to infer who I am and what my persona is about, to match me with personalized ads.
Wherever possible I disallow Google and all others to stop tracking me, having done so in my account. I find it odd I also need to disallow the tracking from Google, through a third party site (e.g. anyone's blog) even though I have already done so through every direct means possible. What do the consent settings in Google even mean then if I need to allow/disallow consent of tracking per seperate website in addition?
People may be visiting a trusted site and then are asked to allow audio and video, not realising that it is an iframe asking for the permission.
https://m.media-amazon.com/images/I/61l+gnZORVL._AC_SY355_.j...
They're pretty convenient and look nice
I'm not 100% certain that was the cause. But the guy at the Apple store seemed to think it was, which meant they wouldn't pay for it. And a quick google shows others who are convinced.
The bezel on that laptop was really tiny and I can easily see it might have contributed to the crack. I now have a 2021 model and the bezel is much thicker. But I'm not taking the chance.
I'll leave this,
https://support.apple.com/en-us/HT211148
>Make sure the camera cover is not thicker than an average piece of printer paper (0.1mm).
>If you install a camera cover that is thicker than 0.1mm, remove the camera cover before closing your computer.
And ripping out your microphone doesn't stop evildoers from viewing the camera. What's your point?
plug in an un-wired connector, cut of the wiring post, smooth with a nail-file or put on a crowning drop of glue so it won't rip your bag and you're done.
Take that, Apple fanboys.
I can’t remember the last time I used the built-in mic on a laptop, much less the last time I bought a laptop with a mic that was actually worth using.
OK, I destroyed it (carefully). Now it won't boot. What do I do next?
I don't know if this looks any better if Google is negligent/incompetent instead of malicious.
It's not 2003 anymore, we're far past negligence at this point.
It is not. It sounds like something that should have been taken care of by Google at least 10 years ago.
Aren’t they? They’re quite literally distributing malware.
"Please don't sneer, including at the rest of the community."
Not saying it's a great situation, just explaining why there's not an easy solution.
The solution is easy on Google's side. Just don't do it and accept the reduction in revenue. But I guess the economic incentives are just too big, like you say.
Code that makes your system appear infected with malware is indistinguishable from actual malware.
I think I found the problem.
The problem is that letting advertisers write their own JS means advertisers are willing to pay more for the ad. If Google banned that practice, or put in a lot of oversight, people would pay less for ads through Google. But some other ad networks would still allow the bad practices, and thus be able to pay higher rates. So sites would just move more ads to those other networks.
That doesn't absolve Google of responsibility, but it does mean that we can't actually solve the problem just by being mad at Google.
It is profoundly strange that we extol the virtues of succeeding in society and yet also act like said success doesn’t come with heavy responsibility.
Serving javascript from a well-connected CDN isn't something that sets anyone apart, you can just sign up with cloudflare and have that working in a few minutes.
Why can't they do the same with their ad networks? Transpile any JS code served from their network into a safe execution environment/api that only permits the resources allowed safely?
Yeah he noticed it... on his own website.
I’d love to see more stuff like CCPA. As a California resident I can simply tell Google that my data is not for sale, and they’re obligated to respect that regardless of what fingerprinting happens.
This isn’t an ideal solution, but the whole issue of privacy seems like a people/politics problem we keep trying to solve with technology.
After you enable that, a settings button will appear when you pull down your notification/settings menu for "Sensors Off". This disables the microphone, camera, fingerprint reader, accelerometer and other sensors.
Keywords (i.e. "perfume", "car", "phone", "notebook", "flowers", whatever) would probably be enough to "improve" targeted ads.
However, this would be a huge scandal if true, so your first suggestion, fingerprinting gone wrong, is more likely.
It would have been nice to see the author address that possibility, but it seems fingerprinting is not mentioned.
[1] https://developer.mozilla.org/en-US/docs/Web/API/MediaDevice...
What is your logic? My company uses Meet and it's "mandated" in the sense that it is used for all company meetings. I'm in a position that I might get us to switch if I pushed it, but Teams and Zoom aren't much better. I assure you I work at my company.
I'm not sure about Teams, but Zoom lets you use a standard SIP client to join meetings.
<mode style="grumpy-old-man"> I simply won't have it. At the moment, with FF, an adblocker and a JS blocker, I think I'm hard to track (but certainly not impossible). If my blockers get blocked, I can live without the WWW. Be careful, Goo! You may own the web, but the web doesn't own us.
As someone once said, "It's just a fad". </mode>
I first considered this when a friend told me about a brand of lawnmower of which I had never heard let alone searched (mowing lawns is the least interesting activity I can imagine), and one minute later a podcast app had a big banner at the top by which I could purchase a lawnmower of that exact brand. I don't have important conversations in the vicinity of mobile phones anymore.
Do you think the apps on your phone real-time stream all mic audio or that they run speech-to-text on your device?
Yes. Say no to tracking, regardless of if it listens to your voice. Even if it does not leak this way it's probable that one of the major ad brokers will leak data in the future.
This is why data privacy is so important even if you feel like you have nothing to hide.
0: as you note, they technically have the ability to do so and random apps could be but the amount of effort it would take to record, transcribe, and evaluate that much data just isn’t worth it when most users voluntarily give their info anyway. This is why I don’t use a phone, browser, or email service created by an ad tech company though and it boggles my mind how many people are ok with that.
Is it so unlikely that an ad network sketchy enough to pay its way onto random Android apps would also be sketchy enough to monitor conversations for keywords that can get it paid? I don't think that's unlikely at all.
Although I wouldn't be shocked at all if mics were being used. I just feel like that would have been leaked by someone by now.
Nobody is saying that. It's simply a quirk of human psychology. We are pattern matching machines with a poor intuitive grasp of probability.
In this case, having the ad in a cross-origin iframe is what keeps it from being able to read the content of the page, which is definitely something you'd want from a privacy/security perspective.
(Disclosure: I work on ads at Google, speaking only for myself)
There are also many different types of clickjacking:
Atleast some (eg. lenovo), have physical shutters to cover the webcam lens, so even if the cam turns on, it records only a piece of black plastic.
HTTP contains JavaScript, and theoretically anything can be executed within the browser (I've seen people mining bitcoins!).
Google can't monitor an execute every HTML snippet, but they doing pretty great job sampling responses and evaluating some of them. Fraudsters are smart, and trying to understand if the code is executed on Google's servers, but overall they are loosing.
It seems like a case where google's system didn't work.
By they way, all google partners are listed here: https://developers.google.com/third-party-ads/adx-vendors. Usually, it's possible to track down who's exactly responsible by looking at dev console
Of course it is. It's their ad network.
> Google can't monitor an execute every HTML snippet
Of course they can. There's no excuse for allowing this nonsense on their network.
The problem is bad actors are really good at evading detection through obfuscation and dynamically serving different code depending on the IP address so the creative behaves normally if it thinks you're a server Chrome instance and does bad stuff for real people.
To make matters worse bad actors have automated their process, so when they discover they're blocked everywhere, they rotate to a new account, domain, change their obfuscated code to look different, and are back up in a few hours. This leaves everyone else playing whack-a-mole.
And even if Google sees through all of that, the code might never actually touch Google, but come from one of the many marketplaces or resellers being rendered through Google's Ad Server. For any given site, the list of what markets they work with is usually public. This site, https://techsparx.com/ads.txt, is doing business with way too many markets - 680 of which are resellers of other markets' inventory.
This means if you're a bad actor, you can evade anyone capable of seeing through your obfuscation entirely, select for marketplaces that have extremely poor quality control (I see a few), and wind up on this website.
If I serve any content to my users, then I'm responsible for any malware it contains.