Chrome Bugs Allow Sites to Listen to Your Private Conversations
talater.com
talater.com
"To minimize the chance of users unwittingly allowing web pages to record speech without their knowledge, implementations must abort an active speech input session if the web page lost input focus to another window or to another tab within the same user agent."
Given this the actual Chrome implementation is wrong.
I'm not entirely sure this spec creates a useful environment for webapp developers; in fact this limitation would encourage non-standardized implementations so they could actually be used by normal people.
Interesting to think about, either way.
One interesting thing is that web specs don't usually go into that much detail about UI, or at least that used to be the case. It was generally considered outside of the spec's purview, and it boxes in future browser interfaces that could be something very different than tabs and windows.
If you needed something, I would think something like there must be a visible notice to the user that their sound is being recorded, and if that notice becomes obscured, cease recording. But I'm not entirely sure it should be enforced on the spec level; instead it could have a non-normative security section and leave it up to the browsers to implement it well.
But it looks like all four points of the security model (including #4 that you've quoted) were retained. Luckily, Chrome is more aggressive on popups than ever, so there's less likelihood, but it's not yet bulletproof.
I agree it looks like Chrome's implementation is not matching this spec. I'll look into if we can tighten this up.
In it, a Chrome representative said: "The security of our users is a top priority, and this feature was designed with security and privacy in mind. We've re-investigated and still believe there is no immediate threat, since a user must first enable speech recognition for each site that requests it. The feature is in compliance with the current W3C standard, and we continue to work on improvements."
Check the informationweek article for more, specifically around the errata to remove that sentence from the spec.
Right now in Chrome permissions are enabled or disabled globally with exceptions based on hostname patterns. Adding a new option like "Allow popup window to inherit permissions" will solve the issue.
A well-hidden popup window can track your position all day using the geolocation API?
Browser --> Sandbox (within browser) --> "Operating system" (within browser)
Pages --> (Dynamic) Ads, "tracking", "web apps" --> Pervasive, intrusive monitoring via exploitation
If you are going to turn your browser into an operating system, you'd better get the security right -- and spend some time reflecting on the ongoing Java fiasco.
And maybe stop calling it a "browser" -- unless you mean that I'm now the one being browsed.
http://userscripts.org/scripts/show/110566
And TamperMonkey to enable the script:
https://chrome.google.com/webstore/detail/tampermonkey/dhdgf...
No need for 3rd party scripts to do the same, especially all the fiasco going around with adware folks getting into extensions.
He is misrepresenting his personal disagreements about UI/UX decisions as exploits or bugs in chrome which is disingenuous, especially as he edits his video to hide the safeguards (mainly the popup blocker).
Also the speech API does not send audio to authorized site only machine transcription of the audio which is not as pertinent, which also speaks to the misrepresentation of the author.
https://github.com/tuki/js-popunder
Another serious security issue is when the popunder waits for a while as the parent frame navigates itself to e.g. "java.com", then the child navigates the parent to a malicious drive-by download. This can make it appear to "spoof" a drive-by download. This attack vector has been known and ignored forever (I think Zalewski published about this years back). IE9 and 10 actually do a good job preventing this, but I know it works in most modern browsers.
1. the video presented this in a very biased light the popup was already open and behind as the main window.
2. chrome should provide an indicator in a more global way to indicate a recording is taking place...
additionally, just like the camera on your computer lights up when it's on, it would make sense for your computer to have a similar light indicator for when the mic is on?
It's the Google answer that is suspect: 'there was an ongoing discussion within the Standards group, to agree on the correct behaviour - "Nothing is decided yet."' What, what?