×
Google

Google's Data Collection is Hard To Escape, Study Claims (cnn.com) 100

Citing a report [PDF] published on Tuesday by Digital Content Next and Vanderbilt University, CNN writes that "short of chucking your phone into the river, shunning the internet, and learning to read paper maps again, there's not much you can do to keep Google from collecting data about you." From the report: So says a Vanderbilt University computer scientist who led an analysis of Google's data collection practices. His report, released Tuesday, outlines a myriad ways the company amasses information about the billions of people who use the world's leading search engine, web browser, and mobile operating system, not to mention products like Gmail, platforms like YouTube, and products like Nest. Although the report doesn't contain any bombshells, it presents an overview of Google's efforts to learn as much as possible about people.

[...] Google collects far more data than Facebook, according to the report, and it is the world's largest digital advertising company. Its vast portfolio of services, from Android to Google Search to Chrome to Google Pay, create a firehose of data. Professor Douglas Schmidt and his team intercepted data as it was transmitted from Android smartphones to Google servers. They also examined the information Google provides users in its My Activity and Google Takeout tools, as well as the company's privacy polices and previous research on the topic. The researchers claims that almost every move you make online is collected and collated, from your morning routine (such as music tastes, route to work, and news preferences) to errands (including calendar appointments, webpages visited, and purchases made). "At the end of the day, Google identified user interests with remarkable accuracy," the report states.
In a statement, Google said, "This report is commissioned by a professional DC lobbyist group, and written by a witness for Oracle in their ongoing copyright litigation with Google. So, it's no surprise that it contains wildly misleading information."
Mozilla

Mozilla to Remove Legacy Firefox Add-Ons From Add-On Portal in Early October (bleepingcomputer.com) 110

Mozilla announced today plans to remove all Firefox legacy add-ons from the official Mozilla add-ons portal in early October. From a report: The move comes after Mozilla updated the Firefox core to use a new add-ons system based on the Chrome-compatible WebExtensions API. This new add-ons API replaced Firefox's old XUL-based add-ons API in November 2017, with the release of Firefox 57. All Firefox legacy add-ons stopped working in Firefox 57, but Mozilla continued to support them in the Firefox Extended Support Release (ESR) 52 branch. Support for Firefox ESR 52 will end on September 5, in two weeks, meaning there won't be any official Firefox version that supports legacy add-ons anymore.
China

China's 'First Fully Homegrown' Web Browser, Used By Key Government Bodies, Under Fire For 'Heavily' Copying Google Chrome Files (ft.com) 134

Redcore, a Chinese start-up that claims to have produced a homegrown browser used by key government bodies and state-run companies, has come under fire after users discovered its software was heavily based on Google's Chrome browser [Editor's note: the link may be paywalled; alternative source]. From a report: The company, which says it has created "innovative and world-leading" browser technology, came under scrutiny on Thursday when users looked through the browser's installation directory and discovered an original "chrome.exe" file along with image files of the Chrome logo. "We have launched the world's only purely China-owned browser Redcore, to break the US monopoly," the company said in a statement on Wednesday. The Financial Times verified Chinese users' findings and found with its own examination that Redcore was using components from the v. 49 version of Google Chrome. "Redcore has Chrome [elements] in it," said company founder Gao Jing in response to fierce public criticism. "But this is not plagiarism; rather, we are standing on the shoulders of a giant for our own innovation," she added, according to local media reports. Ms Gao was also quoted as saying that the company had so far been doing very well in terms of customer satisfaction.
Bug

Google Patches Chrome Bug That Lets Attackers Steal Web Secrets Via Audio Or Video HTML Tags (bleepingcomputer.com) 14

An anonymous reader writes: "Google has patched a vulnerability in the Chrome browser that allows an attacker to retrieve sensitive information from other sites via audio or video HTML tags," reports Bleeping Computer. The attack breaks CORS -- Cross-Origin Resource Sharing, a browser security feature that prevents sites from loading resources from other websites -- and will attempt to load resources (some of which can reveal information about users) inside audio and video HTML tags. During tests, a researcher retrieved age and gender information from Facebook users, but another researcher says the bug can be also used to retrieve data from corporate backends or private APIs. Ron Masas, a security researcher with Imperva, first discovered and reported this issue to Google. The bug was fixed at the end of July with the release of Chrome v68.0.3440.75.
Chrome

Built-in Lazy Loading Lands in Google Chrome Canary (bleepingcomputer.com) 57

secwatcher writes: Google has started rolling out support for built-in lazy loading inside Chrome. Currently, support for image and iframe lazy loading is only available in Chrome Canary, the Chrome version that Google uses to test new features. Two flags are now available in the chrome://flags section of Chrome Canary. They are: chrome://flags/#enable-lazy-image-loading, chrome://flags/#enable-lazy-frame-loading. Enabling these two flags will activate a new type of content loading behavior inside the Chrome browser. The two flags have been available in Chrome Canary for a few days, since v70.0.3521.0.
Firefox

Internet Engineering Task Force Releases the Final Version of TLS 1.3; Newest Chrome and Firefox Versions Already Support a Draft Version of It (cnet.com) 28

The encryption that protects your browser's connection to websites is getting a notch faster and a notch safer to use. From a report: That's because the Internet Engineering Task Force (IETF) on Friday finished a years-long process of modernizing the technology used to secure website communications. You may never have heard of Transport Layer Security -- TLS for short -- but version 1.3 is now complete and headed to websites, browsers and other parts of the internet that rely on its security. "Publishing TLS 1.3 is a huge accomplishment. It is one the best recent examples of how it is possible to take 20 years of deployed legacy code and change it on the fly, resulting in a better internet for everyone," said Nick Sullivan, head of cryptography for Cloudflare, which helps customers distribute their websites and other content around the world, in a blog post.

TLS 1.3 brings some significant improvements over TLS 1.2, which was finished 10 years ago. Perhaps first on the list is that it'll mean websites load faster. Setting up an encrypted connection on the web historically has caused delays since your browser and the website server must send information back and forth in a process called a handshake. The slower your broadband or the more congested your mobile network is, the more you'll notice these delays.
Firefox and Chrome already support a draft version of TLS 1.3.
Chrome

Chromebooks May Get Apple Boot Camp-Like Windows 10 Dual Boot With 'Campfire' (xda-developers.com) 95

Google is reportedly working on a secret project to get Windows 10 running on Chromebooks. XDA Developers' Kieran Miyamoto reports on the latest developments surrounding "Campfire" -- the Chromebook equivalent of Apple's Boot Camp. From the report: Earlier this year, a mysterious project appeared on the Chromium Git. The Chrome OS developers had created a new firmware branch of the Google Pixelbook called eve-campfire and were working on a new "Alt OS mode" for this branch. We have since confirmed this Alt OS refers to Microsoft Windows 10 and found evidence that it wasn't just an internal project but intended for public release.

The developers have reworked the way in which they distribute updates to a rarely-used section of ROM on Chromebooks called RW_LEGACY. The RW_LEGACY section on a Chromebook's ROM traditionally gives users the ability to dual-boot into an alternative OS, but it is something of an afterthought during production and the section is rarely updated after a device leaves the factory. Now, with Campfire, Google will push signed updates to RW_LEGACY via the regular auto-update process, so firmware flashing won't be a concern for Joe Public. A recent commit for enabling Alt OS through crosh with a simple [alt_os enable] command indicates that it will be a fairly easy setup process from the user's end too.
We may expect to see the first demo of "Campfire" at Google's upcoming Pixel 3 launch event in October. Also, the report notes that the Google Pixelbook won't be the only Chromebook with Campfire support, citing "mentions of multiple 'campfire variants.'"
Censorship

Google Boots Open Source Anti-Censorship Tool From Chrome Store (torrentfreak.com) 95

Google has removed the open-source Ahoy! extension from the Chrome store with little explanation. The tool facilitated access to more than 1,700 blocked sites in Portugal by routing traffic through its own proxies. TorrentFreak reports: After servicing 100,000 users last December, Ahoy! grew to almost 185,000 users this year. However, progress and indeed the project itself is now under threat after arbitrary action by Google. "Google decided to remove us from Chrome's Web Store without any justification," team member Henrique Mouta informs TF. "We always make sure our code is high quality, secure and 100% free (as in beer and as in freedom). All the source code is open source. And we're pretty sure we never broke any of the Google's marketplace rules."

Henrique says he's tried to reach out to Google but finding someone to help has proven impossible. Even re-submitting Ahoy! to Google from scratch hasn't helped the situation. "I tried and resubmitted the plugin but it was refused after a few hours and without any justification," Henrique says. "Google never reached us or notified us about the removal from Chrome Web Store. We never got a single email justifying what happened, why have we been removed from the store, or/and what are we breaching and how can we fix it." TorrentFreak reached out to Google asking why this anti-censorship tool has been removed from its Chrome store. Despite multiple requests, the search giant failed to respond to us or the Ahoy! team.
Thankfully, the Ahoy! extension is still available on Firefox.
Earth

Google Maps Now Zooms Out To a Globe Instead of a Flat Earth (venturebeat.com) 123

Google Maps has been updated to present you with a 3D globe of the planet when you zoom out. Previously, Maps would have shown you a flat map of the world. An anonymous Slashdot reader shares a report from VentureBeat: About two weeks ago, however, Google quietly rolled out (hehe) a change so that the service now presents you with a 3D globe. You can manipulate the globe as you'd expect -- spin it, zoom in, and zoom back out. Google Earth, watch out -- Google Maps is coming for you. Globe mode only works on desktop, but all major browsers are supported, we're told. We tested it on Chrome, Firefox, and Edge -- they all showed the globe just fine. This is all thanks to WebGL.
Google

Chromebooks Don't Suffer From Bad User Experiences Found on Windows and Mac Computers, Google Says (aboutchromebooks.com) 185

Kevin C. Tofel, writing for About Chromebooks: Having worked for a Google Chrome Marketing team over an 18 month period, I never saw a project that aggressively goes after Windows and Mac computers like the one that was published today [Editor's note: the video is unlisted, but accessible]. [...] As someone who has used (and often still does use) other platforms, I can't really disagree with the point of this video. For too long, computer users have had to deal with cryptic errors, updates that can take hours to install and the dreaded blue screen of death / spinning beach ball.

Granted, some of my personal experience with those issues was when I was in corporate IT for 15 years; that career ended for me (by choice) back in 2007. And clearly, all desktop / laptop platforms have improved since then. Even so, Google is highlighting the modern approach of Chromebooks with this short video and that's an important point.

Mozilla

Mozilla Is Working On a Chrome-Like 'Site Isolation' Feature For Firefox (bleepingcomputer.com) 57

An anonymous reader writes: "The Mozilla Foundation, the organization behind the Firefox browser, is working on adding a new feature to its browser that is similar to the Site Isolation feature that Google rolled out to Chrome users this year," reports Bleeping Computer. "[Chrome's] Site Isolation works by opening a new browser process for any domain/site the user loads in a tab." The feature has been recently rolled out to 99% of the Chrome userbase. "But Chrome won't be the only browser with Site Isolation," adds Bleeping Computer. "Work on a similar feature also began at Mozilla headquarters back in April, in a plan dubbed Project Fission." Mozilla engineers say that before rolling out Project Fission (Site Isolation), they need to optimize Firefox's memory usage first. Work has now started on shaving off 7MB of RAM from each Firefox content process in order to bring down per-process RAM usage to around 10MB, a limit Mozilla deems sustainable for rolling out Site Isolation.
Opera

Opera Browser Raises $115 Million In Its Stock Market Debut (cnet.com) 53

An anonymous reader quotes CNET: Opera, an underdog in a browser market dominated by Google's Chrome, raised $115 million in an initial public offering Friday. The company sold 9.6 million American depositary shares at $12 each, the high end of the $10-to-$12 range it expected for the IPO. When the stock started trading more broadly at about 7:30 a.m. PT, it rose as high as 28 percent above that before settling in at a 10 percent rise, to $13.24, during midday trading.... In fact, Opera raised a big notch more, because at the same time as the IPO, it also secured a $60 million private funding round from Tospring Technology, also known as Bitmain, which makes Bitcoin mining computers, IDG Capital Fund and IDG Capital Investors. And the financial firms underwriting the IPO had an option to release another 15 percent of shares -- 1.44 million. "It gets us roughly up to $190 million," Chief Financial Officer Frode Jacobsen said....

In the first three months of 2018, Opera reported net income of $6.6 million on revenue of $39.4 million. The company makes money through partnerships with search engines, including Google and Yandex, that pay for search traffic it sends their way and through advertising deals like promoting websites on the browser's bookmarking, or speed dial, page. Opera has 264 million monthly active users on smartphones and 57 million on personal computers, Opera said in regulatory filings. Starting in 2017, it built an AI-powered news service into its browser and now offers it as a standalone app called Opera News. That has 90 million monthly users. The news app and service has been responsible for the turnaround in Opera's recent financial fortunes, Jacobsen said.

Firefox

Chrome Extensions, Android and iOS Apps Caught Collecting Browsing Data (bleepingcomputer.com) 24

Catalin Cimpanu, writing for Bleeping Computer: An investigation by AdGuard has revealed a common link between several Chrome and Firefox extensions and Android and iOS apps that were caught collecting highly personal user data through various shady tactics. The common link between all extensions and mobile apps is a company named Big Star Labs. AdGuard estimates these apps had been installed on around 11 million devices.
Firefox

Google Has Made YouTube Slower on Edge and Firefox, Mozilla Alleges (neowin.net) 145

Usama Jawad, writing for Neowin: Early last year, YouTube received a design refresh with Google's own Polymer library which enabled "quicker feature development" for the platform. Now, a Mozilla executive is claiming that Google has made YouTube slower on Edge and Firefox by using this framework. In a thread on Twitter, Mozilla's Technical Program Manager has stated that YouTube's Polymer redesign relies heavily on the deprecated Shadow DOM v0 API, which is only available in Chrome. This in turn makes the site around five times slower on competing browsers such as Microsoft Edge and Mozilla Firefox. Further reading: Safari Users Unable to Play Newer 4K Video On YouTube in Native Resolution.
Firefox

Firefox Blocks Autoplaying Web Audio (engadget.com) 121

Mozilla's latest Nightly builds for Firefox now include an option to mute autoplaying audio. The feature was recently added to the Chrome browser, but Mozilla's update offers a few more options. According to Engadget, "You can turn the feature off entirely, force it to ask for permission, and make exceptions for specific sites." Keep in mind that these are nightly releases, so you will most likely run into some bugs. The "polished version" is likely weeks away.
Chrome

In Encryption Push, Chrome Flags HTTP Sites as 'Not Secure' (zdnet.com) 268

On Tuesday, Chrome started marking sites that don't use HTTPS as "not secure." From a report: First announced two years ago, Google said it would flag any site that still uses unencrypted HTTP to deliver its content in the latest version of Chrome, out Tuesday. It's part of the company's years-long effort effort to gradually nudge more webmasters and site owners into adopting HTTPS, a secure encryption standard for data in transit. Any site that doesn't load with green padlock or a "secure" message in the browser's address bar will be flagged -- and shamed -- as insecure.

[...] According to nightly data compiled by security experts Troy Hunt and Scott Helme, roughly 100 of the top 500 websites are still serving their pages over unencrypted HTTP -- all of which will today be flagged as "insecure." Many of those sites -- like Baidu, JD.com, and Google.cn -- are Chinese language sites, but many popular Western sites -- including BBC.com, DailyMail.co.uk, and Fedex.com -- are HTTP. Of the top million sites, a little over half do not redirect to HTTPS.
Chrome 68 also brings with it Page Lifecycle API, and the Payment Handler API. From a report: The Payment Handler API builds on the Payment Request API, which helped users check out online. The new API enables web-based payment apps to facilitate payments directly within the Payment Request experience, as seen above. As with every version, Chrome 68 includes an update to the V8 JavaScript engine: version 6.8. It reduces memory consumption as well as includes improvements to array destructuring, Object.assign, and TypedArray.prototype.sort. Check out the full list of changes for more information.
Google

Google Video Shows All-White Redesigns For Gmail, Google Photos, and More (arstechnica.com) 105

An anonymous reader shares a report: This year, Google is pushing out a major revamp to its Material Design guidelines. The new design language is slowly creeping across Google's portfolio, and so far we've seen big changes for Gmail.com, early builds of Chrome, and for Android P. The Android side of things has so far only been the base operating system, but now a new Google design video has surfaced that shows off new designs for Gmail, Google Photos, Google Trips, and Google Drive.

[...] The Gmail screens strip the app of its trademark red UI elements and give us a white bottom bar and white background. The phone inbox shows attached documents and even has large thumbnails for images. The message screen appears to show attachments on a horizontal scrolling carousel, which looks a lot like the horizontally scrolling news articles in the Google Feed. This screen again places the important controls down at the bottom of the screen, where a bottom bar houses the usual "Mark as Read," "Delete," "Archive," and "Reply All" buttons. We even get to see the compose screen for a second, which shows previous replies above your compose field.

Chrome

Google Tests Curvy Chrome Tabs With Material Design Overhaul (cnet.com) 109

Google is trying out a new Chrome interface that for the first time in a decade presents a very different look for the tabs and address bar at the top of the widely used web browser, CNET reports. It adds: Since its public debut in 2008, Chrome has featured a trapezoidal tab for each website you have open. But tabs now look very different on Chrome Canary -- a very rough-around-the-edges version used to test changes before they reach a broader audience. The active tab has a slope-shouldered look with curved corners. The grayed-out inactive tabs merge with the the browser itself and are separated only by thin vertical lines. In addition, the address bar's text box is a gray oval against a white backdrop, instead of a round-cornered white rectangle with a hairline border.
Google

Google, Which Owns Duck.com, Confuses Users Searching For Its Rival DuckDuckGo and Redirects Them Back To Google (twitter.com) 118

Commenting on the record $5 billion fine on Google by the European Commission, privacy focused search engine DuckDuckGo said this week it welcomes the decision as it has "felt [Google's] effects first hand for many years and has led directly to us having less market share on Android vs iOS and in general mobile vs desktop." The company said: Up until just last year, it was impossible to add DuckDuckGo to Chrome on Android, and it is still impossible on Chrome on iOS. We are also not included in the default list of search options like we are in Safari, even though we are among the top search engines in many countries. The Google search widget is featured prominently on most Android builds and is impossible to change the search provider. For a long time it was also impossible to even remove this widget without installing a launcher that effectively changed the whole way the OS works. Their anti-competitive search behavior isn't limited to Android. Every time we update our Chrome browser extension, all of our users are faced with an official-looking dialogue asking them if they'd like to revert their search settings and disable the entire extension. Google also owns http://duck.com and points it directly at Google search, which consistently confuses DuckDuckGo users. "If it looks like a duck, swims like a duck, and quacks like a duck, then it probably is google," wrote security researcher Mikko Hypponen, summing up the story.

Update: Google makes amends.
Chrome

Chrome OS Isn't Ready For Tablets Yet (theverge.com) 35

The Verge's Dieter Bohn set out to review Acer's Chromebook Tab 10 tablet, but ended up sharing his impressions of using Chrome OS instead. An anonymous reader shares an excerpt from his review: If you're not familiar with Chrome OS, you should know that there are three different tracks you can run Chrome OS on. There's "Stable," which is what most people should use. It's the build I mostly used while testing this device and coming to the conclusions you see above. Then there's "Beta," which is a little on the edge but has been pretty solid for me. Lots of people run it to get slightly earlier access to new features. But because I wanted to see what the future of Chrome looks like, I also looked at the "Developer" build. Most people shouldn't do this. It's buggy and maybe a little less secure. Here be monsters. On a tablet, Chrome OS looks and feels a lot like it does when you have a keyboard. There's a button to get to your apps, a task bar along the bottom, and a system menu in the lower-right corner. In the Developer build, you'll find more squarish tabs and a system menu that's been "Android-ified," so it looks like the Quick Settings you'd see on an Android phone.

By default, all apps in Chrome OS go to full screen in tablet mode. Recently, however, split screen was rolled out. You tap the multitasking button on the lower right, drag one window to the left, then pick another open window to fill the right (or vice versa). You can then drag the divider to set up a one-third / two-thirds split screen if you like. That's all well and good, but it's the next steps that make this whole thing feel not quite baked. If you rotate the tablet 180 degrees, everything flips. So if you had a notepad open on the left and Chrome open on the right, when you flip it, the notepad ends up on the right. I found it disconcerting, but perhaps that's just a matter of it being different instead of it being broken. Different UX strokes for different OS folks. [...] I don't want to be too harsh on the lagginess I experienced because it's unfair to judge software that's still in development. But I did experience a lot, even on the more stable builds. That's a particularly egregious problem when there's no physical keyboard. If there's one thing that will drive a user crazy, it's input lag. And I saw much too much of that, even on the Stable build, which is what most educators will experience with this tablet. I also felt at times that I was struggling to hit buttons with my finger that would have been no problem if I had a mouse.

Slashdot Top Deals