It also seems pretty silly to mix in interesting findings in a big PDF sprinkled among other items that are, speaking generously, debatable matters of opinion, like whether programs should be stripped or not.
It also seems pretty silly to mix in interesting findings in a big PDF sprinkled among other items that are, speaking generously, debatable matters of opinion, like whether programs should be stripped or not.
This is one of their medium findings. This report smells like "Guys, we MUST find something, give me something, anything!"... :P
We laugh and argue that this makes pentests a joke (which plenty are!), but at the end of the day that "admin" note resulted in a material improvement, however tiny, in the system. Google reacted by removing the need for escalation from the application and now an attacker needs one more exploit to build a full chain.
You work through a checklist for arse covering, which generates a lot of meaningless/low value findings.
If you omit a lot of those issues, the client thinks you didn't do the work sufficiently.
If you put in too many of those findings, the report gets made fun of for containing "filler".
However, this "privacy" goal is something that a huge number of VPN providers, including Google, claim as a goal and market heavily against, so it's fair to assess against it IHMO.
As for the second part, yeah, that's pentest reports in a nutshell. A few nuggets of information combined with checklist-satisfying irrelevant findings from automated tooling.
At another level a vpn provider that doesn't operate in country can reliably refuse orders to surveil you in the future wherein orders don't rise to the level of obtaining international cooperation AND don't meet standards higher than the nonsensically low standards in say the US.
This wont be enough to protect your international criminal empire but might well provide reasonable assurance of privacy to concerned individuals. I'm sure the google one is good for something....
Perhaps keeping your ISP from chiding or blocking you for pirating music until that hole is plugged...or keeping people who access http websites over coffee shop wifi safe?
https://www.datacenterdynamics.com/en/news/google-handed-ove...
https://www.forbes.com/sites/andygreenberg/2011/06/27/google...
https://www.theguardian.com/technology/2020/aug/17/google-gi...
https://www.dailystar.co.uk/tech/news/google-hand-over-video...