23 ms·
An iframe from googlesyndication.com tries to access the camera and microphone
- EastSmith 5y agoSerious question - why do we need iframes? Can't we disable them?
- jefftk 5y agoAn iframe allows one party to securely embed something from another party. Ads are one example of this, but so are embedded videos, tweets, etc. In this case, having the ad in a cross-origin iframe is what keeps it from being able to read the content of the page, which is definitely something you'd want from a privacy/security perspective. (Disclosure: I work on ads at Google, speaking only for myself)
- jessaustin 5y agoWe have a chance to notice this when it's mediated by a browser. Native apps don't barf all over the console and thus escape such scrutiny. I first considered this when a friend told me about a brand of lawnmower of which I had never heard let alone searched (mowing lawns is the least interesting activity I can imagine), and one minute later a podcast app had a big banner at the top by which I could purchase a lawnmower of that exact brand. I don't have important conversations in the vicinity of mobile phones anymore.
- avsteele 5y agoHas anyone seen any well done research showing these effects?
- goldenkey 5y agoI've heard it from more folks than I'd like to. And counting them all as crazy or paranoid is less believable than the alternative.
- ricardobayes 5y agoI've only experienced it first-hand on youtube. After trying to learn spanish and talking spanish on the phone (but searched nothing on youtube in Spanish) Youtube offers recommendations in Spanish. Also after I sneezed a couple of times it recommends something related to hay fever. Lots more. I find these way more than circumstancial.
- andybak 5y ago> And counting them all as crazy or paranoid Nobody is saying that. It's simply a quirk of human psychology. We are pattern matching machines with a poor intuitive grasp of probability.
- pumnikol 5y agoA while ago, out of the blue, I've been diagnosed with a very rare medical condition. Online ads and recommended videos then started showing relevant and very specific drugs, treatments, therapies, self-help groups etc. for me. I had not performed any online or offline research about the topic, had not talked to anyone about it at all, except the MD, and had bought all drugs with cash. What are the odds? Then at work, in a web meeting, I made a completely spontaneous pun about having a divorce. Minutes later, my social media were completely plastered with ads for divorce lawyers, which they had never been before. I've never been married, don't want to be, and I don't even know anyone who has gotten a divorce in the last five years. And more, and more. If social media companies are selling health and other personal data to advertisers, what's stopping them from selling it to insurances and recruiters? Maybe I am all wrong about this, and maybe many others are also. Or maybe we'll start seeing a big wave of whisteblowing and revelation books once the current crop of software engineers, managers and directors retire and/ or are sufficiently strapped for cash.
- keanebean86 5y agoNot a study but I've heard explanations that big companies have so much data their models are just that good. For instance they know who you're friends with, both your search histories, and location data. Knowing you friend searched for lawnmowers recently and now y'all are physically close it's possible that brand was discussed. Although I wouldn't be shocked at all if mics were being used. I just feel like that would have been leaked by someone by now.
- clairity 5y agono, they have so much data because their models are so bad. the vast data is used to give the illusion of good models by sheer volume, so little random matches are made more likely. that’s why google and the like want to hoover up our data, they’re desperate to keep the gravy train rolling long enough to create the good models and keep it going some more.
- SahAssar 5y agoI've heard similar stories many times but every time it seems to be baader-meinhof effect/frequency illusion or that the linking is not via audio but something else. People have man-in-the-middle checked advertising traffic to see if they either stream audio or send spoken keywords to ad servers and they do not seem to do that. It's more likely that it saw your phone and your friends at similar locations and your friend had searched for the brand before, therefore linking your ad profile to the brand. Do you think the apps on your phone real-time stream all mic audio or that they run speech-to-text on your device?
- colordrops 5y agoWould it have to be audio? It could do TTS on the phone then send the text back.
- SahAssar 5y agoI said "run speech-to-text on your device". Also TTS would be the other way around as it means text to speech.
- colordrops 5y agoSorry I meant STT
- eloisius 5y agoThat's almost scarier. Seems like it could leak embarrassing information about what you've been searching or buying to your friends.
- SahAssar 5y ago> it could leak embarrassing information about what you've been searching or buying to your friends. Yes. Say no to tracking, regardless of if it listens to your voice. Even if it does not leak this way it's probable that one of the major ad brokers will leak data in the future.
- marcellus23 5y agoBut mobile apps are required to ask for mic/camera permissions.
- kzrdude 5y agoThere are exploits that circumvent this, of course.
- andybak 5y agoI don't think you'd waste an exploit like that to server a lawnmower ad.
- marcellus23 5y agoSure, but those exist for the web too…
- guptaneil 5y agoThis is a common belief that phones must be listening to us because ads are so targeted, but the scary truth is they aren’t[0] because they don’t need to. They have far more effective ways of targeting ads. For example, the reason you probably saw the lawnmower ad is because your friend searched for lawnmowers, and google knows they are friends with you, so they showed you targeted ads too because you might recommend that brand if you talk or you might subconsciously register that brand and reaffirm their decision to buy with something like “oh yeah I’ve heard of X, they’re supposed to be the best” without remembering where you saw that. It’s even possible you got the ad before your chat but didn’t notice because you had no reason to pay attention to a lawnmower ad. This is why data privacy is so important even if you feel like you have nothing to hide. 0: as you note, they technically have the ability to do so and random apps could be but the amount of effort it would take to record, transcribe, and evaluate that much data just isn’t worth it when most users voluntarily give their info anyway. This is why I don’t use a phone, browser, or email service created by an ad tech company though and it boggles my mind how many people are ok with that.
- jessaustin 5y agoIn this case, the conservative explanation seemed unlikely for several reasons. This friend would be more precisely described as the elderly friend of my elderly parents. Neither of us are on social media, she doesn't know what podcasts are, and neither of us had even used a web browser in the preceding several hours. Neither of us was in the market for a new riding mower nor had been in the preceding decade. I was on her (remote, inconsistent-cell-reception) farm to help with some cattle. I had never heard of this brand before, and now over a year later I can't think of it. Is it so unlikely that an ad network sketchy enough to pay its way onto random Android apps would also be sketchy enough to monitor conversations for keywords that can get it paid? I don't think that's unlikely at all.
- 1cvmask 5y agoInjecting malware into ads is as old as ad networks. There are even ad networks that hijack the ads of other networks and replace the original ads with their own. There are also many different types of clickjacking: https://en.m.wikipedia.org/wiki/Clickjacking https://en.m.wikipedia.org/wiki/Clickjacking
- foota 5y agoIs this just click bait? I don't know the intricacies of Google's ad serving, but is this not just someone (e.g., an ads customer) slipping a request for camera and mic access into an ad script? But the title seems to suggest Google is doing something malicious here.
- smt88 5y agoWhy does it matter whether Google did it or Google spread it around the world? It is equally repulsive behavior on their part.
- oblak 5y agoYou're right. Google would never compromise anyone to make some money. Never
- kadoban 5y agoWhy the _hell_ should a Google ads customer be able to "slip" in a request for camera and mic? That that is even possible is a large problem.
- hyperman1 5y agoIsn't Google supposed to vet whatever ads they send into the world? I don't know if this looks any better if Google is negligent/incompetent instead of malicious.
- dubbelboer 5y agoThey don't vet anything, anyone can execute any code on tpc.googlesyndicatio.com. See: https://blog.dubbelboer.com/2016/06/10/embed-into-tpc-googlesyndication-com.html https://blog.dubbelboer.com/2016/06/10/embed-into-tpc-google...
- CrazyStat 5y agoAllowing an ads customer to "just" slip a request for camera and mic access into an ad script is malicious.
- Nextgrid 5y agoI wonder if it's a fingerprinting attempt gone wrong? I can't see a reasonable even malicious reason for eavesdropping on mic/camera at scale like that, you'll be capturing a ton of data you need to manually process/clean up which takes time/resources, most people won't stay on the page long enough to capture enough sensitive info and even then, eavesdropped conversations seem pretty useless unless you also have the whole context and information on the person you're targeting to be able to effectively misuse that data.
- drclau 5y ago> eavesdropped conversations seem pretty useless unless you also have the whole context and information on the person you're targeting to be able to effectively misuse that data Keywords (i.e. "perfume", "car", "phone", "notebook", "flowers", whatever) would probably be enough to "improve" targeted ads. However, this would be a huge scandal if true, so your first suggestion, fingerprinting gone wrong, is more likely.
- akersten 5y agoThe Exhibit A why no one will ever convince me to turn off my ad blocker or switch away from Firefox. It's a great feeling to just not have to worry about this entire class of exploits.
- underscore_ku 5y agoalso tape your laptop's camera
- jdavis703 5y agoMy laptop is mostly closed and plugged in to an external monitor. The mic is so muffled by then, it would take expert audio recovery to understand what was being said. (In other words, it would be hard to scale it for ad purposes, but obviously a targeted attack could still be devastating).
- tmsbrg 5y agoThat doesn't protect your microphone from being exposed though.
- newbamboo 5y agoDon’t talk to your computer. When you do talk, talk about stuff that you want them to look into.
- beeboop 5y agothis is why we need hardware switches for microphones
- michael-ax 5y agofwiw, there's a switch in every ext. mic. jack. plug in an un-wired connector, cut of the wiring post, smooth with a nail-file or put on a crowning drop of glue so it won't rip your bag and you're done.
- zinekeller 5y agoWell, at least that requires clicking (not to diminish this report) but five years ago it's a zero-click proposition (like Forbes: https://www.networkworld.com/article/3021113/forbes-malware-ad-blocker-advertisements.html https://www.networkworld.com/article/3021113/forbes-malware-...). While I don't want to diminish their revenue, the fact that blocking online ads significantly strengthens your security posture is not lost to private companies and governments (like US CISA: https://www.cisa.gov/sites/default/files/publications/Capacity_Enhancement_Guide-Securing_Web_Browsers_and_Defending_Against_Malvertising_for_Federal_Agencies.pdf https://www.cisa.gov/sites/default/files/publications/Capaci...) alike.
- htunnicliff 5y agoThis sounds like one small piece of common fingerprinting techniques. It would have been nice to see the author address that possibility, but it seems fingerprinting is not mentioned.
- masswerk 5y agoIMHO, fingerprinting would explain the enumeration attempt, but not the attempt to access these devices.
- kingcharles 5y agoDoes accessing them give you extra fingerprinting data though? I would imagine that you can then enumerate at least the resolution of the camera.
- masswerk 5y agoThis only allows you to specify a preferred resolution, but doesn't return the resolution actually available. Any device info is returned in the MediaDeviceInfo object [1] on enumeration (which doesn't include resolution or similar data). [1] https://developer.mozilla.org/en-US/docs/Web/API/MediaDeviceInfo https://developer.mozilla.org/en-US/docs/Web/API/MediaDevice...
- lemoncookiechip 5y agoQuite ironic that the website posting the article actually has googlesyndication.com.
- bibinou 5y ago> These messages appeared in the JavaScript console on Safari while browsing multiple pages on techsparx.com. At first I saw it on one page, then checked other pages and got the same messages. This site is using Ezoic's advertising system, which in turn uses Google Ad Manager for some advertising. Yeah he noticed it... on his own website.
- Tepix 5y agoWhy, did you expect their techs to turn it off just for the one article?
- streptomycin 5y agoShitty ad code barfing errors onto the console is typical, unfortunately. The JS is not written by Google, it's written by the individual advertiser, with very limited oversight.
- kadoban 5y ago> "with very limited oversight" I think I found the problem.
- streptomycin 5y agoIt's a problem, but it's not "the" problem. The problem is that letting advertisers write their own JS means advertisers are willing to pay more for the ad. If Google banned that practice, or put in a lot of oversight, people would pay less for ads through Google. But some other ad networks would still allow the bad practices, and thus be able to pay higher rates. So sites would just move more ads to those other networks. That doesn't absolve Google of responsibility, but it does mean that we can't actually solve the problem just by being mad at Google.
- mattgreenrocks 5y agoI don’t think expecting Google to take responsibility for the ads they serve is unreasonable. It is profoundly strange that we extol the virtues of succeeding in society and yet also act like said success doesn’t come with heavy responsibility.
- luckylion 5y agoThe value in adsense is absolutely not in the ability to run unvetted javascript served from a google-hosted domain. The value is in the tracking and retargeting. Serving javascript from a well-connected CDN isn't something that sets anyone apart, you can just sign up with cloudflare and have that working in a few minutes.
- jasonjayr 5y agoThose other networks would start getting blocked hard with adblock/DNS block/public shaming of sites using them.
- vklmn 5y agoI don't think that it's google's fault. Google sometimes trade ads on auctions, meaning they issue and HTTP request to partners asking "Hey, you want to show an ad here", and partner respond with price and HTML code, the highest bidder wins and HTTP code is inserted. HTTP contains JavaScript, and theoretically anything can be executed within the browser (I've seen people mining bitcoins!). Google can't monitor an execute every HTML snippet, but they doing pretty great job sampling responses and evaluating some of them. Fraudsters are smart, and trying to understand if the code is executed on Google's servers, but overall they are loosing. It seems like a case where google's system didn't work. By they way, all google partners are listed here: https://developers.google.com/third-party-ads/adx-vendors https://developers.google.com/third-party-ads/adx-vendors. Usually, it's possible to track down who's exactly responsible by looking at dev console
- andybak 5y agoIf Google can't guarantee no malicious javascript then they should strip all javascript. If I serve any content to my users, then I'm responsible for any malware it contains.
- driverdan 5y ago> I don't think that it's google's fault Of course it is. It's their ad network. > Google can't monitor an execute every HTML snippet Of course they can. There's no excuse for allowing this nonsense on their network.
- coffeefirst 5y agoWell, they do monitor snippets. There's a lot more going on here than meets the eye. The problem is bad actors are really good at evading detection through obfuscation and dynamically serving different code depending on the IP address so the creative behaves normally if it thinks you're a server Chrome instance and does bad stuff for real people. To make matters worse bad actors have automated their process, so when they discover they're blocked everywhere, they rotate to a new account, domain, change their obfuscated code to look different, and are back up in a few hours. This leaves everyone else playing whack-a-mole. And even if Google sees through all of that, the code might never actually touch Google, but come from one of the many marketplaces or resellers being rendered through Google's Ad Server. For any given site, the list of what markets they work with is usually public. This site, https://techsparx.com/ads.txt https://techsparx.com/ads.txt, is doing business with way too many markets - 680 of which are resellers of other markets' inventory. This means if you're a bad actor, you can evade anyone capable of seeing through your obfuscation entirely, select for marketplaces that have extremely poor quality control (I see a few), and wind up on this website.
- tomudding 5y agoI think this sounds more like some sort of fingerprinting attempt. It good to see that random access to these kind of resources fails due to new(er) browser controls. However, this does not mean that the fingerprinting actually failed. There is probably some way to determine if the request was denied automatically by the browser or manually by the user (e.g., time to get "response"), which is definitely something which can be used for fingerprinting. Which reminds me of fingerprinting by tiny differences in the audio API provided by browsers [0]. Super interesting, but also a bit depressing. Also works for things like canvases and WebGL. EFF allows you to check how fingerprintable your browser is [1]. Do note that the results may not be very accurate. [0]: https://fingerprintjs.com/blog/audio-fingerprinting/ https://fingerprintjs.com/blog/audio-fingerprinting/ [1]: https://coveryourtracks.eff.org https://coveryourtracks.eff.org
- zagrebian 5y ago> this does not mean that the fingerprinting actually failed When does fingerprinting ever fail? Maybe in Brave and/or Tor, but I wouldn’t bet on it.
- deleted 5y ago[deleted]
- ravenstine 5y agoIn my experience, with tools like Cover Your Tracks (apparently this is the new name for Panopticlick), the more you try and thwart fingerprinting, the more unique you appear. Although I still do everything I can to block and filter everything conceivable, I've given up on trying to figure out how identifiable I am on the web because it seems useless. If you don't try then you're identifiable, and if you do then you are probably more identifiable. Whatever.
- bombcar 5y agoThose anti-fingerprinting tools should make you appear as the most common iPhone as much as possible.
- jefftk 5y agoThe author is concerned that an ad might be able to surreptitiously turn on the camera or microphone, but these are not accessible by default. In this case, it isn't even getting as far as a permissions prompt because the default Feature Policy doesn't allow camera or mic access in cross-origin iframes. (Ex, for Chrome: https://sites.google.com/a/chromium.org/dev/Home/chromium-security/deprecating-permissions-in-cross-origin-iframes https://sites.google.com/a/chromium.org/dev/Home/chromium-se...) Instead, I think the most likely thing happening here is that an advertiser is running a script that is trying to do fingerprinting, and which is blocked by the browser protection. (That it's an iframe running on https://[random].safeframe.googlesyndication.com https://[random].safeframe.googlesyndication.com tells us it's an ad served through Google Ad Manager, and the contents of the iframe are supplied by the advertiser.) Disclosure: I work for Google, speaking only for myself
- reaperducer 5y agoThe author is concerned that an ad might be able to surreptitiously turn on the camera or microphone You are correct, that is the author's concern. The reason the rest of us are concerned is because the general public has been conditioned by Google and others to just press "Accept" any prompt that pops up, no matter how dangerous.
- ethbr0 5y agoThis is a catch-22 though. If something dangerous to privacy is being widely used in the world, then putting it behind a prompt creates an avalanche of prompts, and results in user apathy. But not prompting requires you to choose a default, which either default to block and breaks things (if it was actually required) or defaults to allow.
- Hallucinaut 5y agoI would happily set all browsers to always deny all ads and untrusted domains the ability to use microphone and camera at all times. So there's no need for an avalanche of alerts, it just shouldn't be permissible for a resource from an untrusted source. It may be widely used, but for a highly concentrated set of sites. I can't think of an occasion I've used it beyond Google, Microsoft, and Zoom properties. Perhaps Slack and Discord too? So there must be a better way.
- alkonaut 5y agoI really don’t care what advertisers think is necessary to do in order to ensure targeting/fingerprinting or countering fraud, but running any third party script isn’t anything I consider remotely acceptable from an ad. Worst case I could accept that some generic script from the ad network is run - but for the ad network to pipe through the advertisers third party script should mean they are adblocked by the browser without even requiring a plugin.
- bennyp101 5y agoI wonder what would happen if you visited in a browser with it set to allow video/audio with no prompts? Would it bail out with a "oh crap, they actually let us" or would it actually try and do something?
- archsurface 5y agoThey recently changed their meet application for some reason. I use it without video, voice only; recently it has started trying to force me to use both - I have to refuse both, then once in the meet go and enable voice only. I loathe all things google but am forced to use meet for work.
- userbinator 5y agoI doubt you actually work there given your last sentence, but have you tried proposing an alternative (along with some reasons why it would be better) the next time someone asks you to use it?
- Ensorceled 5y ago> I doubt you actually work there given your last sentence, What is your logic? My company uses Meet and it's "mandated" in the sense that it is used for all company meetings. I'm in a position that I might get us to switch if I pushed it, but Teams and Zoom aren't much better. I assure you I work at my company.
- userbinator 5y agoI meant not working for Google. I'm not sure about Teams, but Zoom lets you use a standard SIP client to join meetings.
- Ensorceled 5y agoWhy do you think they claimed to work for Google? I didn't get that at all.
- tehlike 5y agoThis is not google, but a third party ad network serving ads through google. Google tries to sandbox the creatives in an attempt to prevent issues exactly like this, and develops browser features to prevent issues exactly like this. This is likely a script that somehow avoided google's malware scanning pipelines. This is definitely not google's malintent. Disclaimer: Ex googler, worked in ads, dealed with problems like this all the time.
- eganist 5y ago> This is likely a script that somehow avoided google's malware scanning pipelines. I can't think of a good reason for scripts through google ad syndication to be asking for camera and microphone permissions. I'd assume Google runs these scripts in something like a lab environment to see what's ultimately invoked before deploying them to production? If so, would this be indicative of both a deliberate controls bypass and a ToS violation by the ad network? Sounds like Google Syndication may have taken care of this by enabling Permissions Policies(1) across its domains? I can't tell because the article references Feature Policy (a predecessor to Permissions Policies(2)) "in Safari" even though Feature and Permissions Policies, as best as I understand them, are delivered from the origin for implementation by the browser. So I'm kinda confused. And if they don't implement it, it tells me they're totally fine with this kind of fingerprinting. (1)https://developer.mozilla.org/en-US/docs/Web/HTTP/Feature_Policy https://developer.mozilla.org/en-US/docs/Web/HTTP/Feature_Po... (2)https://www.w3.org/TR/permissions-policy-1/ https://www.w3.org/TR/permissions-policy-1/ --- A prior version of this comment suggested Google should add permissions policies. I since edited it to clarify that I'm quite confused over whether it's something Google already implemented or something Safari overlaid on top of Google syndication origins since I can't verify using the origins themselves. The article seems to suggest it's something Safari specific even though the spec for both FP and PP involves receiving a set of permissions from the origin as a header and implementing them in the browser.
- soared 5y agoYes - banner ads are constantly targeted by malicious actors. My employer pays a vendor something like $200k/mo for creative scanning to avoid issues like this. Google certainly spends tens of millions a year trying to avoid issues like this. See vendors like “the media trust”
- overshadow 5y agoAnother reason to disable JS globally whilst doing heavy surfing and only temporarily whitelisting/enabling it on sites you trust.
- d4mi3n 5y agoI have to wonder if anti-fingerprinting is the wrong approach to privacy invading advertising. There’s an inherent asymmetry between the resources available to those who build these systems and those who try to stop them. I’d love to see more stuff like CCPA. As a California resident I can simply tell Google that my data is not for sale, and they’re obligated to respect that regardless of what fingerprinting happens. This isn’t an ideal solution, but the whole issue of privacy seems like a people/politics problem we keep trying to solve with technology.
- greenyoda 5y agoLaws take a long time to enact, especially when there are companies with almost unlimited money lobbying against them. Technology (such as browser updates and ad-blocking extensions) can be deployed immediately and can adapt quickly to changing threats.
- YetAnotherNick 5y agoThere is extremely weak proof and all the crowd here has very predictable anti chrome response even though it has nothing to do with chrome. I think the domain is checking whether there is camera and mic present not turning it on and accessing content.
- luckylion 5y agoWhat are you talking about? chrome is being mentioned by two people besides yourself and neither mention is negative. Did you even read the comments before commenting about their predictability?
- denton-scratch 5y agoI don't use Chrome, and I don't give a sh*t about it. What I care about is ad networks, and the websites that vomit those ads into the browsers of their visitors. <mode style="grumpy-old-man"> I simply won't have it. At the moment, with FF, an adblocker and a JS blocker, I think I'm hard to track (but certainly not impossible). If my blockers get blocked, I can live without the WWW. Be careful, Goo! You may own the web, but the web doesn't own us. As someone once said, "It's just a fad". </mode>
- bhauer 5y agoDoes googlesyndication.com serve anything that is in the user's interest? I've had that domain blocked for several years and don't think I've ever noticed it hindering any experience.
- userbinator 5y agoIt's always been in my HOSTS file too. Ditto for their analytics and "tag manager" domains.
- throwaway81523 5y agoThe laptop camera can be disabled with small bit of black electrical tape, but I don't understand whose crazy idea it was to put microphones into laptops in the first place, especially without hardware kill switches like the Librems have. The same thing for modern cell phones, of course.
- charcircuit 5y agoIt's not that crazy of an idea. Laptop users want to be able to record videos, call people, and talk to others.
- ajsnigrutin 5y agoBest way to solve this would be, to have a physical switch that cuts power to webcam and microphone.... sadly I don't know any laptops who actually implement this. Atleast some (eg. lenovo), have physical shutters to cover the webcam lens, so even if the cam turns on, it records only a piece of black plastic.
- ok123456 5y agoOn modern android devices there's a "Quick settings developer tiles" option called "Sensors Off" that's available after you enable developer mode. After you enable that, a settings button will appear when you pull down your notification/settings menu for "Sensors Off". This disables the microphone, camera, fingerprint reader, accelerometer and other sensors.
- nobodyandproud 5y agoA physical, hard-disconnect on-off switch for mic and camera should be required by law.
- dheera 5y agoViewing this on a Framework Laptop that just came in today and I'm laughing because it's the first laptop I've had that actually has hardware switches for camera and microphone.