Google has another secret browser
matan-h.com
matan-h.com
In fact almost any staff member inside an organisation that receives a plausible vulnerability report should ensure it reaches the right people. It's not something you should shrug off.
Is bypassing the lock screen a security bug?
Like it's a frustrating response to this valid bug report, but it's not really a security risk here, either. You don't actually bypass the lock screen or anything.
Also other features are effected like kiosk mode etc. The implications are unclear but could conceivably be quite serious in some scenarios.
Is it? That's not demonstrated nor claimed in the linked article.
> I think it really is and could have serious safeguarding issues.
Elaborate. What's the security risk from your child using a browser after the parental control timeout expired? It's annoying that the automatic limits didn't fully happen, but data isn't compromised as a result, either.
No skin in the game, but this is very similar to the old Win95 "About... Help... $BROWSER" style bypasses.
Could you tell me more about this?
And being educated != being in jail.
But honestly, maybe re-read the HN guidelines: https://news.ycombinator.com/newsguidelines.html
> Please respond to the strongest plausible interpretation of what someone says, not a weaker one that's easier to criticize. Assume good faith.
These are parental controls. They aren't working in this one specific way. That's. The. Scope.
It would be great if everyone was happy to drop whatever they're doing and lead resolution of customer's complaint, regardless of who the actual empowered/responsible person/team is. Alas, we live in the world where most people subscribe to Copenhagen Interpretation of Ethics. In this world, even forwarding a request to those responsible is dangerous. Anything more than that entangles you with the problem, meaning you'll be held responsible for it, no matter your actual connection to it.
We can call it "principal-agent problem", or just "survival in the world where requesters are hunting for anyone willing to engage with their requests".
(Source: I used to be the one willing to handle any internal request even tangentially related to my work, until my line manager told me to ask requesters for project ID or billing code before giving any help that requires more than 1 minute, because otherwise I'll end up doing none of the work we're actually being paid for.)
Keeping your jurisdiction small means you can do more within that jurisdiction, by ignoring even important problems that are outside it.
But the alternative is ineffective doomscrolling because all the world’s problems are yours.
It's just that practically nobody in the world can credibly demand Google's board, or even just upper middle management, to make a decision on small matters.
When a ticket reaches your average IT guy, they can't usually delegate it to a lower tier employee unless there are formal support tiers, like L1 and L2, and the ticket was sent to one of the upper layer techs (which usually doesn't happen straight away, because of how L1 and L2 support teams work).
If this is not the case, the only way out is forwarding the issue to another team.
Sorry guys, that’s another team. They’re extremely reluctant to deploy even very important things. Separation of responsibilities means we have no other choice.
Yeah, that's my read. Basically the first line of support said "parental controls and screen pinning don't count as security boundaries", and the author is upset not because of an abstract argument about impact but because they want to get paid.
Should they be security boundaries? Honestly I'm mixed on this. First because the threat mode is totally different when the attacker is your teenager (i.e. who exactly is the harmed victim? The parent?).
But mostly because the whole idea behind bug bounties is to encourage disclosure of vulnerabilities that would otherwise be sold and deployed against the public at large. That is, the bugs have "value", and we're all better off if the purchase price is borne by the software developer than the criminal. There's no market for parental controls bypasses in that sense.
Will be used in scenarios with much more at stake than someone's belligerent teenager.
Think of these features in the broadest sense you possibly can.
(Edit: <sigh> than the bug bounty that the linked author desires. Really?)
Remember that both of these technologies don't allow the device to do anything it isn't able to do in its default configuration. They're essentially a form of DRM: disallowing otherwise useful activities because of the desires of the owner (and not the user). Would you demand, say, Apple pay a bug bounty for a DRM bypass that let people rip Netflix videos? Probably not, right?
Since the bug bounty is zero. All the time?
I’d like to shift this a little:
Support who’s primary metric is handle time is in a game of hot potato.
From a business perspective the managers and leaders always feel like there’s too many fires which inevitably leads to either pressure on front-lines to “go faster” and “stop doing unnecessary work” (aka “taking time away from the fires”) or some level of management that’s intentionally blocking higher-ups from seeing those fires so that they look like they are managing the department well (and in this case not only is there the same pressure on the front-lines, but there’s additional pressure about not reaching out to anyone except through that manager.
When the primary metric is handle time, the issues pile up, there’s never enough people to handle it, and the business slowly sinks as no one with a budget sees the “ounce of prevention [that can prevent a pound of cure]”.
However: If the metric is minimum number of departments an issue touches before it’s resolved it’s a whole different thing. Suddenly playing hot potato is a problem and “problem ownership” is praised. There are other metrics too that produce different support cultures (and sometimes different games), but the reason hot potato is so popular is that those other metrics all require top-level execs to be comfortable with spending now to save down the road.
Distributed prioritization seems like a problem; you can get priority inversion if you’re not careful.
Something like reducing staff ticket time by 20%, then using that 20% for feedback, strategy, and structure. Some (maybe even most if you’re lucky) of the front-line staff will have enough experience and insight to be invaluable here (though it is likely they won’t have the language yet to express it in ways that make sense to management). As the company goes through the process of communication, discovery, awareness, planning, and execution (preferably with a tight feedback loop) some of the underlying causes will be addressed, the front-line pressure will ease off, the cascade effect will see ease-off in other departments as well, and that 20% can go down to 5% or even 0 (not recommended lol) which will further reduce the workload to give longer-lasting relief.
Then with staff time “out of the red” the company can start thinking about what they will do in a fire-free future.
Could you elaborate?
It also meant that some people had "forever tickets", that were a continuous series of tacked-on asks by the same faculty member. HigherEd IT can be crazy (and crazily-laid back).
The stubbornness of large organization can be maintained for several hundred years, assuming it exists for that long, so this isn't quite true.
Parental controls is essentially maintenance mode and has 1 dev nominally responsible for it, maybe their workload is divided between that and a bunch of other stuff that they deem their "real" work. The way the component works means that bugs typically get assigned elsewhere in the system very far away from parental controls; you, the owner of Contacts, land a bug like "Your feature XXX has the following failure in parental controls mode." The team responsible is like ... "Why do I care about this? Why should I take a code change for this? Isn't that your problem?" Whoever is responsible for parental controls might not care, but if they do, they don't have political leverage over the owner of the Contacts app or whatever. Therefore, won't fix.
The 'we analyzed the issue and decided it won't be fix' Is NOT the same as 'we don't cate about this, go talk to some other team and maybe they'll fix it'.
Deciding something is not a bug is not the same as just ignoring the bug and not fixing it
Google lost out in this case - because an employee pushed responsibility onto an outside party.
2. The flaw was publicly exposed which cause reputational damage.
"I've reached out to a colleague who has provided me with some additional context" or "this work requires some additional input from another team - I'm working to establish this and will get back to you with more details"
Neither of the above examples provide any more context on internal teammates or their organizations. However they do require additional work and a culture of customer support (which Larry Page was infamously against for years).
The problem as I see it is that Google came to be dominated by an egalitarizing culture which at first wasn't necessarily a problem. This was an explicit choice by Larry and Sergey, that your manager should not be able to unilaterally fire you just because of a personal disagreement, nor stiff you out of financial rewards, none of that. So, your manager lacks any formal authority over your day-to-day work: they have to use politics and soft power. Instead, performance is reviewed by a committee of your manager’s peers, who can “calibrate” that manager’s opinion of you against others and against empirical data.
The result of being judged by a faceless committee is that implicitly, some things generate the empirical data that they look at, and other things don't. It's helpful to oversimplify this to a common currency of “perfcoin” Ⓟ even though that was never explicit at Google. Some activities generate Ⓟ, some don't. Google has built dozens of new chat apps because whenever you can have a good excuse for how this aligns with your business priorities, they generate lots of Ⓟ. The design documents are rich in Ⓟ, the tracking issues for each feature are rich in Ⓟ, getting the thing privacy-analyzed and internationalized can get you some Ⓟ, the inevitable work to merge it into another chat app is also worth Ⓟ. But please understand that the existence of Ⓟ is a result of semi-hierarchy. The manager exists (hierarchy) but has to point to an objective measure (Ⓟ) to say that you're not doing what you're supposed to (semi-), it is almost a mathematical deduction that this has to exist given that structure.
Now networking with people outside of your team, will never get you any Ⓟ. And this is not for lack of trying! When I was there it was a job responsibility to do some things that were not your job responsibility (“community contributions”) to try and associate Ⓟ with some form of networking! And everyone hated it, and it didn't work anyways. Manager-committees immediately decided that Ⓟ would not be awarded for excessive networking, just that you had to prove a little bit of networking or else Ⓟ would be deducted. Furthermore the most reliable community contributions were noncommunal—conducting hiring interviews being the easiest: probably this person will not be hired, but even if they are, you will never interact with this person ever again. But, you conducted N interviews in the quarter and that is just barely enough to not get docked some Ⓟ for being a shut-in.
I am giving somewhat of a negative portrait and it is not all negative, see Laszlo Bock’s Work Rules for the better parts. I'm just saying that the culture of not-my-department has been created by, and is sustained by, incentivization.
Google is so huge that it's extremely common to know you have an important bug for another team, but not to be able to route it to them because you can't find their team name.
Most teams have "code names" that have nothing to do with the public name of the project. For example, the parental controls team might be named "pigglewiggle-team" and the Android contacts team might be named "katniss-team" and their bug components might have similarly obscure code names. If you don't work with those teams frequently it can be really daunting to find.
Even when the bug components have hints that get you close to the right place, it's not unusual to learn that most of the engineers are busy working on the new version of the app that isn't released yet, and the old version of the app (the one with the bug) has been destaffed and bugs are supposed to be routed to some other random team that's literally never touched the code.
If your infosec team does not have a contact email (or preferably, several, e.g. "incident@", "security@", etc), slack/teams/webex channel, or escalation process for reporting security issues, that is decently well-known to employees, they are not doing their jobs well.
Quarterly infosec bulletins? Infosec day? "Cool incidents" annual recaps?
I cannot imagine working on an infosec team that doesn't make itself very visible, and very *available*, to other groups, and always position themselves as the 'catch-all' place for any security issues (which these bugs clearly are).
Whenever my parents would take me with them to run errands, I would find one of these computers and click around until I got a Best Viewed In badge. (It was often on the Help page.) That would bypass the restrictions of the single-site browser and take you to e.g. netscape.com, where you could find a link to a search engine and browse wherever you wanted.
I remember the amazement and joy of other people nearby watching, who would then ask me to do it on their PC so they too could click around and play Minesweeper or Pinball :-)
Sounds so amateur now, but it's hard to remember that CTRL+ALT+DEL in the mid-90's was -- dare I say it? -- sort of a power tool that only more experienced users knew about.
I had to hunt for servers that had gopher/lynx on them which didn’t have any login. I vaguely remember having to do something similar to this post to navigate somewhere that would allow me to bring up search or enter a URL.
This was all done on a C64 and a 1200 baud modem, along with this incredible software I was able to find on local BBSes called NovaTerm - an 80 column terminal on a Commodore 64 was black magic at the time. That disk was my prized possession and I almost wore it out.
Owned ;)
The VPN is one of the few reasons why I pay $5 for proton unlimited and I could make do without it.
My only alternative is to set up my own wireguard exit node at home with a raspberry
I’m not familiar with a “Best Viewed In” badge and I am intrigued as to how this bypass worked (based on my own 2000s high school experiences of working around restrictions). Would appreciate if any passersby could elaborate.
So if you tried to go to example.com, you would be redirected to bank.com. But if a link on bank.com got you to example.com, you could visit it that way.
Obviously address bars are one of the restricted things. I feel like there might have been others, but I don't recall the specifics.
Wikipedia explains the context in whoch these were born a bit more: https://en.m.wikipedia.org/wiki/Browser_wars
Except when they slapped on that badge, it linked to netscape.com which had a search engine.
It feels like no real kids are testing the parental controls: For a long time it was trivially easy to circumvent a set YouTube time limit restriction by just opening Play Store, browsing to an app with a video in the screenshot list and head over to YouTube from there. My son actually showed me this when he discovered it.
And of course the Play store is desperate for you to provide a credit card at every single opportunity so you can maximize the potential of kids doing accidental buying.
It is a complete scam.
I honestly don't know how television got such strict laws and regulations on children's programming, when viewed in comparison to the complete wild west, that is the modern app store.
With time and pressure.
Right now you have a fun new technology which people are still infatuated with, bought by one of the biggest companies to ever exist, in a country which openly permits business-to-politician payments through lobbying.
The wild west won't look anything like it does 50 years from now
> in a country which openly permits business-to-politician payments through lobbying.
It's actually amazing how good of a tell this is. Nobody who says this ever knows anything about politics. I'm sorry, but politicians actually genuinely believe in most of the stuff they do you don't like, and so do their voters.
If you don't, you could let them know and save them billions of USD per year.
But yes, that too, because even when they try it doesn't work.
Here's today's election results in SC where the billionaire-backed* candidate got 1.4%.
https://x.com/armanddoma/status/1753947901972418952
* morally, not financially, since you can't really do that unlike what people think
e.g. amazon in 2023, 19.8m USD https://www.opensecrets.org/federal-lobbying/top-spenders
it's not like america is alone in this, they just have gigantic dollar figures. australia is a country which really struggles to move away from fossil fuels, and it also has gigantic coal-mining companies paying huge amounts to keep it that way
https://www.bbc.com/news/world-europe-16797862
https://www.cnbc.com/2023/01/23/apple-ramped-up-lobbying-spe...
https://www.theguardian.com/environment/2023/dec/09/big-meat...
Companies also spend billions on marketing. But there's no reason to believe either of these things actually /work/. And lobbying is not giving money to politicians.
Just like Meta/Instagram, they're playing lip-service to the concept, but not really taking action.
Frustratingly, out of all the platforms & BigCorps, Microsoft's parental controls and support for child accounts seems the best.
For many parents this might be no big deal. But there are genuinely children who've ventured into self-harm, eating disorder, etc. content on account of the wild-westness of the Internet combined with weakness of this crap. And it's absolutely maddening to see how pathetic they all (including Apple) are treating this.
Over the air broadcasts do. The broadcast spectrum is considered publicly owned and is leased to television operators.
I guess you could say the same about the cellular spectrum. But how deep do you want government regulation to go since Google operates over the internet? Do you really want the government controlling internet content “for the children”?
And if they regulate app stores, especially on Android, do they also regulate what you can distribute from your own website?
So yes, I do expect strict child regulation in it, especially since there isn't the open internet issue of a) who pays for it and b) who is the central regulatory nexus point. It is google/apple in both cases.
If the US does something like the EU DMA, do you regulate all app stores for content?
Exactly how do you do either in a way that the government doesn’t come in an regulate content that they don’t like?
You are obviously arguing for zero-regulation, or you think you are in the libertarian sense. I always like to ask libertarians if they think murder should be illegal, which they usually do. Well, guess what, you are in favor of government regulation, it simply comes down to what line in the sand you are drawing that obviously is convenient to your own self interest.
I feel the same can be said about accessibility service: Once you get the accessibility permission, you have FULL control over the user's device. They could just split those permissions and expose a more fine-grained control api, but they (I suspect) have some one, verry extreme use case in mind and design the service around it (like ie. phone user being completly blind and requiring the accessiblity app to be an interface for literally all interactions with the device).
Which means that whenever you want to use some feature of that api, you have to trust an app completely and give it a carte-blanche to do whatever it wants on your device.
Which ultimately leads to gigantic whole in platforms security, for no other reason then 'this is the way and scenarios we intend people to be using it, and we give no compromises for anyone who has any other usege in mind'
Which could very likely go undetected, therefore unpunished. It's not like it's a family-room computer that's easily monitored.
> After all, they're parental controls, not NSA-proof security. Making them technically bulletproof would arguably be worse for everyone.
It sounds like they're about as bulletproof as as screen door. I would be much better to have them as strong as an locked exterior door, maybe not "NSA-proof" (the door is vulnerable to locksmiths and battering rams) but strong enough to keep a kid out.
I think that tells me something about the actual priorities of the people building all those systems.
Most of my frustrations come from the challenge of having 2 older (not toddler) kids, plus multiple Google devices (phones, tablets, Google TV's, PCs signed into Google Accounts). Google imagines parental control to be in the context of supervision, ie. this is Billy's phone and I'm going to physically hand it to him to use until he's done. And it's fundamentally device-level rather than account level, making it very cumbersome and easily circumvented -- let's say Jill has access via her account to 3 different Google TV's in the house. Family Link makes you say how much time she's allowed to spend on each TV per day. But to Jill, TV is TV, so if you leave her home alone unsupervised she'll just watch her quota on the first TV and then move on to the next.
My prevailing theories, mind you I have no evidence at all for this:
- These disparate product teams don't actually work closely together (and are probably incentivized to NOT work together)
- These are dead-end teams at Google. If you end up on one, your goal is to nominally ship something so you can go somewhere else.
- The product and engineering people who end up on the Family Link team don't actually have kids (they're too young), or if they do, they have like, one young kid.
> Most of us had full control of our devices growing up, right?
Devices, yes. Internet connection: not at first. With the AOL app (not a separate appliance or OS feature) responsible for establishing the dialup connection, it only bridged internet access to the OS when the current AOL user had no parental controls. As a 10-14 year old whose AOL account was set to "young teen" (DNS allow list) and then "mature teen" (DNS deny list), I was free to use non-AOL apps but they had no internet access. Solution: download a keylogger* and subsequently use a parent's AOL account for the next few years until they removed controls from mine, giving full Internet access to the whole computer, without being found out.
*The free version had a "pay for this" nag popup every few minutes. I opened the exe in a hex editor, typed over that nag string, and managed to corrupt it just enough that it would crash (with a totally generic fatal error) instead of nag. Launched it right before finding mom or dad to help me do some safe but blocked activity, which they were always happy to do, with increased supervision.
Here are things you cannot do:
- Create a global screen time limit across all devices regardless of how that time is used.
- Create a PIN for Google TV that prevents kids from switching to an adult account in order to access more apps. Right now it's the other way around, you can set a PIN that prevents a kid from accessing their own account (again, because supervision!) but that kid can easily switch over to the adult account if they want.
- Require that when an idle Google TV exit to the 'user selection' screen after a timeout. Right now a kid can just walk up to the TV and start using my profile and apps because I was the last one to use it.
As for nostalgia, I think that's overthinking it.
(Although they do have different fine grained features, like time limits and web site approval specifically aren't enterprise things.)
Yes, but the devices could do a lot less.
Like, I had full control over my bike too. But not an automobile.
I dunno about you but we had one computer, one TV, and one phone line. If by "full control" you mean "constant negotiations" then yeah we had that. By the time I was able to drive and earn enough coin to build my own computer, I was practically an adult.
What? Apple's successfully made it very hard for adults to get into their own devices. This claim is absurd.
Microsoft has e.g. actual child Hotmail accounts, where the parent can whitelist who they can email and who can contact them. Gmail does not and has no intention adding such a thing. They did eventually add child accounts as part of the Family Link effort, but there's really no controls at that level. I recall seeing internally at Google that instead of adding such facilities to Gmail, they just preferred to a) cover their eyes and pretend that <13 year olds didn't have accounts by tossing that into the agreement and asking for a birthday b) proposing some blue sky alternative communication system for children (I forget the name of this effort, but it was I think 2016ish time frame?), but it had mock-ups and hand waving and big discussions and PRDs etc but was guaranteed to go nowhere because it was a giant vision parallel to y'know... actual-reality...
Microsoft also has global time limits across all devices. And far more granular control.
Anyways, you're substantially right about all this. It drove me nuts that we struggled to deal with access to harmful content and had no control over it, and the worst part of it was working at Google at the time and seeing just how not--seriously this is taken or at least the level of organizational paralysis that was preventing action.
Apple's system isn't much better than Google's FWIW.
The moral here is all parental controls are crap because they don’t directly drive revenue. (Yes, you can say “but I would prefer to use a service with better controls, which drives adoption”, but let’s be honest - we are a minority there). Nobody’s getting promoted for making the best parental control suite.
That, and parents only have kids of the age that this is of relevance for, for maybe 4, 5, 6 years. So you're targeting a feature not only for a small segment, but one that is transient.
And if you screw it up, there's all sorts of potential for liability. You have to be careful about what you promise, etc. etc.
All the more reason why the answer probably comes down to: gov't regulation instead of expecting them to do this voluntarily.
Well, I was thinking of buying an XBox but now...
90% of the time product lays out a minimal rushed vision, engineering huffs and puffs that it might be impossible, then people work about 20-30 hours a week complaining that the designers didn't tell them exactly what to do and the teams they need to integrate with won't help, and you deliver 80-90% of the original minimal "vision" and slap eachother on the back.
And that was _before_: A) spent 18 months firing people, while some managers took advantage of that situation to punch down. B) they nuked the performance review system, 80% are exactly the same with their Significant Impact, another 10-15% have scarlet letters, and 5-10% get rewards.
Any deviation from that and someone perceives you as being on their turf and finds a way to punch down.
And good luck getting management to care, just like the real world, no one wants to get within 100 feet of trouble.
Then you're faced with the invitation to appeal to a VP, a coin flip where you have to guess at if they're going to back you, and even if they do, facing the fact you nuked your career anyway because you broke omerta.
It's hard to quantify the difference but Kagi really feels like it's working with me instead of just trying to sell me garbage.
It was absolutely bananas that a search engine could be SO GOOD the first result would probably be the right one.
Now the first link (and second and third) are never the right one. Usually something different entirely.
I know it seemed unthinkable for most of Google's history. For the longest time Search was Google. But now...
We must consider the fact that Google is essentially a user data broker. All their products are in various proportions collecting user data and/or serving ads.
If Search quality and features keep reducing then its usage and relevance will drop too, reducing its effectiveness at both data collecting and ad serving.
I don't think Google's DNA allows them to consider radical alternatives. They were born in an era when data automation was in its infancy and they rode it all the way to the top. They abhor the human touch, the manual intervention. Their services are set to function automatically, set and forget.
But AI is changing the automation landscape, it's bringing a transformative paradigm shift. It's irresistible bait for Google but it will ruin Search. They'll deal with it the only way they know how, drop it.
Small example: On iOS 'Screen Time' you can restrict websites to a whitelist, which seems useful. But so many things break if you do that - all kinds of login screens for different apps - and you dont get given clues to as to what urls need to be whitelisted to un-break things.
Sometimes with modern tech you're using a feature and you think "this is incredibly complicated and broken, there can't be many people actually using this" and I tend to get that feeling with parental controls.
Or... hear me out... they don't really want adequate controls to be put in place in the first place?
And, yeah, I have many many beefs to pick with Family Link.
In the end it is surrogate of a parent. Either you care about your child and you know what it is doing, or not.
If you think that your child would be vunlerable to anything in the web, then most likely you should not give the phone to your kid.
If the kid is old enough to understand things, then it does not require software parental control, but a parent. A good parent does not need parental control in apps of their children.
Parental controls also disables ability to install apps from other sources and I prefer fdroid apps from play store apps.
The last thing is that it teaches that we are controlled by some software company, and 'kept safe from harm'. It gives that illusion. It trains that illusion. It enforces it.
Every parent can use a little help. There's so much that your child sees and hears, you want to be there to help explain it to them when they have questions.
Hand them a device that shows anything happening anywhere in the world? Maybe a little help there, limiting what they can easily stumble upon, is a good thing.
I do not say that everybody can now safely remove their safeguards.
phone has many utilities I want kids to use: make calls, check mail, maps, weather etc.
The issue is that they are using it for secretly watching tiktok for example.
Have your child hand you their phone at 10PM before they go to bed? Why do they need a phone on their person 24/7?
Because they use it as an alarm?
Because you have a late date night and won't be there in person?
There are solutions.
E.g. parental controls.
Or "you need to put the phone down at 10pm, if I come home and see you on it you will be grounded"
Why must we use technology to enforce parenting choices
Humans predate computers.
But technology can come in handy, don't you think?
(also, we're in a thread complaining about how technology doesn't properly support paraental controls)
The Apple ones seem to have a hundred holes kids can break to extend screen time or download apps, and sometimes it takes awhile for a change to take effect. Windows was completely broken last time I checked on my son’s gaming machine. And Sony PlayStation - oh, so so painful.
So it isn’t just Android. It’s everyone.
Regarding YouTube, the YouTube Kids app lets me block videos and whole channels, and it's great. But there is no equivalent functionality in the main YouTube app. On various devices (e.g., Roku, Google Nest) the kid sometimes manages to find some YouTube channels I'd rather they didn't watch. But I have to manually intervene each time, I can't just block those channels from being watched or recommended in the future. YouTube/Google obviously know that it's valuable to block videos/channels, since that feature exists in the kids app, yet they omit the feature from the main app, even for a paying customer like me. It is obnoxious.
I have a legacy Google Workspaces account that all my family is on and now that it's considered a "business" product, I can't enable parental controls on my kids' Google accounts.
https://i.imgur.com/BULPmCI.gif
Honestly, I would have never expected Google to become Microsoft Windows 98 level bad at designing their systems.
I doubt that it was intentional. Although careful deploying systems, I have often a feeling that we must have forgotten something that is trivially exploitable by someone. I wonder if there are provably secure systems in use somewhere...
There are. Check out sel4 and dependent type systems.
You prompted me to read more about seL4; the white paper is nice [1].
- Breaking the family computer with a trojan pirating Halo PC, which I then had to figure out how to fix before my dad got home
- Circumventing the NetNanny, etc parental controls my parents randomly decided to install on our personal computers several years after us kids had already been using the internet (edit: okay, there may have been a letter from Comcast re: the above sloppy piracy). Restoring my netbook to useful functionality without leaving a trace of modification introduced me to Linux Live CDs, and Linux!
Good to know tomorrow's hackers are still getting that education today!
Google has a secret browser hidden inside the settings - https://news.ycombinator.com/item?id=36478206 - June 2023 (312 comments)
Not really, but it is a privileged System app, which pretty much means it can do a factory load of things that installed apps cannot without root.
You agreed to this in Google's privacy policy when installing Android.
The Phone app doesn't seem to be able to view or open web URLs in contacts, and the Contacts app fails to open the two URLs given in the article in pinned mode.
In any case, the Google response you've seen shows how the company is messed up. Google became Microsoft in the 90s.
In situations where it bypasses things like parental control its fair to bring it up as an issue, but it's not exactly a 'vulnerability' in the way a vulnerability is commonly understood
I can see why Google wouldn't want to apply the permissions and parental contracts from the browser to the web-view, that would break a bunch of stuff and it would be hard to explain to the user that a link in the Contacts app doesn't work, because Chrome is locked down. Others would argue that is exactly what they expect to happen.
In this case I fail to see why Contacts embeds its own webview, rather than just triggering the browser to open the link. Not every app needs a web-view.
Oh, well color me shocked!