Chromium will no longer download/install the Hotword Shared Module
code.google.com
code.google.com
I'm sorry, what?! So I still have to trust that it's not doing anything malicious for 10-15 seconds?
> Chromium builds from r335874 (version 45) onwards will have hotwording disabled by default and will not download the module. There is no way to enable this feature at runtime.
So as long as you compile from source or trust your package maintainer to not enable the compile-time flag you should be good.
Sorry to raise undue alarm.
Microphone No
Audio Capture Allowed Yes
Does audio capture has admin privileges over the microphone, or the speakers for that matter?
https://code.google.com/p/chromium/issues/detail?id=500922#c...
>Microphone: Is a microphone detected? (Does not mean it is being used.)
>Audio Capture Allowed: Can Chromium use the mic? (This is there for historical reasons, it's always "Yes".)
Additionally, it's fairly ironic this is about a browser. If you don't trust packages maintainers, yet you want to use a browser, which the whole point of is to download and interpret text, code and binaries which you have little in the way of actually controlling after pointing it at a site, then I think you've made some interesting security trade-offs in your mind.
http://wccftech.com/intel-possibly-amd-chips-permanent-backd...
Really, this is what everything in life is like. Every time you cross a bridge, you are implicitly trusting the builders who built it, the engineers who designed it, the mechanical engineering processes they used, and the mathematical disciplines that they rely on, all the way down to their fundamental axioms. You have to extend trust at some point there as well, otherwise you can start by proving there exists a class of numbers we will call integers...
In the end you will always arrive at a chicken and egg situation, you will ultimately need to trust the engineers who designed your CPU and chipset, the VLSI design software which they used, the developers who wrote the compiler and toolchain, the tools used to bootstrap it, external libraries, etc.
The world ultimately runs on trust, no matter how you slice it.
But of course nothing beats compiling from source.
Did you assemble a bootstrap compiler yourself? Your binary compiler could be backdoored! [1]
[1] https://en.wikipedia.org/wiki/Backdoor_(computing)#Compiler_...
Google open sources far more than most companies. They've also contributed greatly to building new open source projects, and they actually keep them open and are a generally benevolent maintainer. They're probably one of the best corporate citizens of the open source community.
> Not sell our information to advertisers?
It's their entire business model; if you don't like it, don't use their products.
> Not collaborate with the government to spy on us?
Google never willingly collaborated with the government. They were either hacked by the NSA (this isn't a mark of shame -- just read up on the Equation Group virus that went undetected for the better part of a decade) or they cooperated under a sealed court order. Corporations don't have the agency that individuals do in refusing to cooperate with a court order -- it's literally not possible for a company to refuse to comply with a court order because the feds can just keep arresting people until someone complies. Most companies refuse to put their employees in this position, so they comply under protest (which is exactly what Google did).
> Not use their monopoly money to buy all of the smart people in the world?
So they shouldn't hire under capitalist principles? Also note that this is beneficial for the smart people of the world, because it forces other companies to pay more as well.
http://www.google.com/policies/privacy/#nosharing
Rather, its business model is using this data on behalf of advertisers. That is a highly significant distinction, in my personal opinion.
I'm willing to trust this one, specific company with my data because I know their privacy policy and their practices. Handing that data off to arbitrary other companies for a buck is another matter entirely, I wouldn't be comfortable with that; that's what "selling your data" means, that phrase has a specific meaning, and claiming that's what Google does is a misrepresentation.
What you're saying is that if I tell my friend Sean a secret in confidence, it's all the same whether or not he proceeds to share it with all his friends. In my mind, and in most people's minds, it isn't.
Yes, basically I'm asking for non-capitalism (sorry, I'm a relentless anti-capitalist). It's too much for a HN thread. But I'm sick of this world - Google is a company BUILT on free software. They only exist because of public largesse. Without Linus Torvalds and Stallman (and a million others), Google would not exist, period. Without the Internet, Google would not exist.
This sort of thing is rampant - github has a billion-dollar valuation based on the fact that Linus Torvalds wrote and open-sourced git, and pretty much for no other reason.
I want a word that acknowledges that we exist together, dammit, that the wealth we've made - all of it - is produced in common, and that we don't use every single scrap of advantage we get to arrogate more power to ourselves.
Google is a company that is built on taking a public good, perhaps the greatest public good we have ever made, and turning it into an engine for generating wealth and power for a few individuals.
It's the 21st century, dammit. Let's do better. We have the fucking model for how to do this. Let's build on it. Let's share what we produce instead of taking the collective bounty and using it for our own personal gain.
No, github has a billion-dollar valuation based on the fact that they took a pretty empty market (source code hosting) and created a developer ecosystem around it. Whether they used git, or mercurial, or svn, or any other version control system really doesn't make a big difference. They happened to pick up on the fact that git was picking up steam and went all-in on that bet, but you can replace git with practically any other VCS and it still could have worked. In fact, I'd say it brought more younger developers and enterprise companies to git than git bringing the developers to them.
If Linus was interested in turning git into cash, there are a variety of ways he could make that happen, but it doesn't seem like that's his goal.
Then we don't really have much to argue about on this. Google operates under a capitalist system, so to expect them to operate in a non-capitalist way is not realistic.
And if you want to get pedantic about it, the roads were actually built by a private, for-profit construction company that was contracted by some level of government. Those workers didn't show up and pour asphalt because they felt like it; they did it because they were paid to do it. In a capitalist society, even non-capitalist activities have to abide by the rules of capitalism.
Alternately, they're giving things away for free to discourage non-Google innovation and generally devalue the labor of other companies and developers.
Tomato, tomato.
Fortunately open alternatives such as Firefox still exist.
If they sold that information directly, they'd make a load of money today, but then none tomorrow. User information is the 'goose that lays the golden egg'.
From selling ad space and not the information?
Deleted comment
Seriously, the idea of open source projects downloading close sourced code "on your behalf" is bad in and of itself, regardless of the purpose.
Less evolution than things back to normal.
To paraphrase a Jurassic Park character, they are testing the waters, checking for weaknesses. They remember...
Thanks to William Shatner for lots of things; least of all demonstrating how to deliver a line of dialogue without it sounding like you're reading off the back of a cereal packet and left your glasses at home.
His cover of Common People (Pulp) is an immense example of this. https://www.youtube.com/watch?v=ainyK6fXku0
Yes Doctor Who, I'm staring you out whilst shaking a fist at you....
But something that started happening in the latest versions of Chromium is driving me nuts. Every time I talk to my mother in my native language in front of the laptop, the "Ok, Google" functionality activates and starts the search of the "parsed" English sentence in Google.
I tried to disable it but failed to find how.
apt-get install chromium-browser
well, that was easy.
uh, you were worried about your binary blob running a binary blob?
Would you be more likely to run a checksummed binary blob from your trusted Debian mirror, or one I send you via email?
It's all about acountability.
I'd have someone to beat the shit out of if anything went wrong with that.
Remind me the accountability on that one? vs a company you can sue for billions?
My point was more "i don't think trusted debian mirror buys you much either" if your goal is to not ship binary blobs not "billion dollar company is great".
Usually the interests of corporations and users align, so you can't be sure with them. You can be with the maintainers of Debian.
Why do you believe this? How do you know they aren't on various forums selling ways to exploit users by inserting bugs, or whatever?
Most open source developers do not in fact, make a lot of money from their programs alone. What stops them from being just as greedy as corporations?
Note also this already happens, where open source maintainers sell access to their installers or whatever to malware companies.
Why would one believe it won't happen to debian maintainers?
Also, i'll also point out a lot of them are employed by corporations you distrust so much, and history shows most people will do what they are told, so if their corporations told them to do something, they'd probably do it.
So again, i don't get it. There seems to be no actual reason to trust them more or less. I just see misplaced trust in "the good of people". (Which study after study after study has shown, often goes out the window for very low prices :P)
Google broke the trust the open source community had in them, by silently flipping a switch that surreptitiously downloads a binary blob. They have now gone on record saying that was wrong and have reversed the change going forward. Good on them for that, but as far as I'm concerned that trust is irrevocably broken.
Edit: To clarify, I'm only talking about the sandbox here, I'm aware that there is opt-in stuff and that there is open source code guarding the activation of that specific module, i'd argue that this isn't part of the sandbox though.
My phrasing of "anytime" was perhaps misleading, I'm aware that the module is guarded by open source code that activates it under specific conditions.
However I was talking about the sandbox, and when the module is running it does have access to the microphone without asking. The code guarding the activation of the module isn't relevant in this context.
> The hotword module has the same privileges as any website (except that it automatically has access to the microphone).
My original post was perhaps misleading, I'm only talking about the sandbox here, I'm aware that there is opt-in stuff and that there is open source code guarding the activation of that specific module, i'd argue that this isn't part of the sandbox though.
It makes me think of how Windows with it's very comprehensive mandatory access control remained vulnerable to simple attacks because the ACLs were too complicated. Thus application developers would request overly broad permissions, defeating the usefulness of the security model.
Seems to me that having too many difficult to use security features can be as bad as or worse than too little security.