今天看到以下訊息:
So, Google Chrome gives all *.google.com sites full access to system / tab CPU usage, GPU usage, and memory usage. It also gives access to detailed processor information, and provides a logging backchannel.
This API is not exposed to other sites - only to *.google.com.
— Luca Casonato 🏳️🌈 (@lcasdev) 2024年7月9日
This is interesting because it is a clear violation of the idea that browser vendors should not give preference to their websites over anyone elses.
— Luca Casonato 🏳️🌈 (@lcasdev) 2024年7月9日
The DMA codifies this idea into law: browser vendors, as gatekeepers of the internet, must give the same capabilities to everyone.
For those interested: this is done through a built-in Chrome extension that can not be disabled, and does not show up in the extensions panel. Source code is here: https://source.chromium.org/chromium/chromium/src/+/main:chrome/browser/resources/hangout_services/
It is unclear whether the same extension also ships in other Chromium derived browsers.
— Luca Casonato 🏳️🌈 (@lcasdev) 2024年7月9日
Update: in Microsoft Edge this capability is also available exclusively to *.google.com domains
— Luca Casonato 🏳️🌈 (@lcasdev) 2024年7月10日
And for everyone that keeps saying "Use Brave!!!":
Brave also has the same behaviour as Chrome and Edge here. The extension that allows Google to retrieve this information exclusively from *.google.com is also pre-installed in Brave.
— Luca Casonato 🏳️🌈 (@lcasdev) 2024年7月10日
這可不是簡單的事耶
簡單說,Google 在 Chromium 有塞一條後門,只要進去 Google 的網站,Google 就能使用這條API讀取某些資訊,而且僅 Google 自家網站能使用這條API。
目前看來,Google只是讀取使用者硬體資訊拿來優化自家產品,但光是這樣問題就夠多了。
從法律上來講,如同作者Luca Casonato所說的,這圖利特定廠商,可能違法。
從安全性來講,在電腦世界,你能讀的東西愈多,駭客能攻擊的範圍也愈廣。況且這是一條讀硬體資訊的耶。
沒有留言:
張貼留言
小提示:留言時,可以使用粗體(<b>)、斜體(<i>)、超連結(<a href="網址"> </a>)。另外,以「名稱/網址」留言時,網址可以留空的。