7 ms·
Wouldn't that mean that all your web traffic is going through a google server?
by cynusx 3y ago
Wouldn't that mean that all your web traffic is going through a google server?
- andylynch 3y agoYes. It’s like a Googled version of Apple’s Private Relay.
- layer8 3y agoYes, but it’s end-to-end-encrypted. See https://github.com/GoogleChrome/ip-protection/issues/10 https://github.com/GoogleChrome/ip-protection/issues/10 for example. Of course, Google can conceivably backdoor Chrome, and then the exfiltration of data wouldn’t be obvious from the client-side traffic.
- quenix 3y agoIf we assume Google to backdoor Chrome, the whole IP protection talk is irrelevant. They could backdoor it without needing that.
- layer8 3y agoChrome would need to contact Google servers to send the collected data. Such unexpected traffic would be more easily detectable without IP Protection. With IP Protection, Chrome is sending data to the Google proxy all the time, so it would be harder to detect extra data sent that way.
- onedognight 3y agoThe CA system and hence https/TLS is already backdoored, by construction. Any of root CA’s that your browser trusts can man-in—the-middle you unless you keep track of and pin certificates like Google does. These roots CAs are run by random companies and governments around the world. All of them have equal precedence in browsers.
- layer8 3y agoIt’s not that easy. They would also need to MITM the actual traffic, or the DNS.
- onedognight 3y agoSame with plain http.
- basique 3y agoAny fake certificates the malicious CA signs will have to be written to a Certificate Transparency log, which would make noticing the fact that the CA has done something like this easy.
- JimDabell 3y agoFrom the third paragraph of the article: > It's designed to run Chrome browser connections through two proxies, one operated by Google and one operated by a third-party (eg, Cloudflare), so that the true public IP address of the user is obscured, hopefully thwarting attempts to track them around the web using that address.
- justinclift 3y agoReading the front page the of GitHub repo with the Chrome "IP Protection" source code, it has this worrying statement: We are considering using 2 hops for improved privacy. A second proxy would be run by an external CDN ... https://github.com/GoogleChrome/ip-protection https://github.com/GoogleChrome/ip-protection "Considering" means "we're thinking about it, but it's in no way final". Sounds like Google could implement a proxy solution but decide the 2nd hop for improved privacy isn't needed after all. Or make it optional, defaulting to OFF, etc.
- buremba 3y ago^ This is an important "detail".
- eli 3y agoIn other words what apple has been doing for years now
- AnthonyMouse 3y agoWouldn't this be useful as a way to avoid getting blocked or having to do a thousand CAPTCHAs when using Tor? Access the relay via Tor, the relay doesn't know who you are because of Tor, the website sees you as someone using the relay which is too many ordinary people to block.
- mindslight 3y agoYes, but such proxies will likely require authentication with a Google account, and Google will keep an audit log to prevent "abuse". So at best it works out for maintaining somewhat persistent nyms for well-scoped purposes (that you make with a burner SIM or buy from someone who did), but not as some panacea for Internet privacy. This is of course assuming that the roadmap for these proxies isn't tied into their push for remote attestation ala "Safety" Net and WEI, in which case your "nym" becomes the entire device.
- LinuxBender 3y agoWouldn't that mean that all your web traffic is going through a google server? Yup just like most people using Android have their text messages routing through Google. Some don't even realize this.
- Andrex 3y agoRCS E2EE and Group E2EE are live which makes this a less dangerous attack surface / a less useful ad data reservoir. Google Voice users like myself are SOL but I've never had pretenses that my messages there are private. They're probably stored in plaintext even, there's a lot of 15+ year old GrandCentral cruft underpinning Voice even to this day (speaking only as a user).