top | item 40918398

(no title)

justo-rivera | 1 year ago

You just need to "register" a subdomain. So basically any google employee has potentially full access to your system?

discuss

order

sophiebits|1 year ago

You’re likely severely underestimating the amount of internal paperwork and review that is required to launch a new google.com subdomain.

drpossum|1 year ago

I did one on my local network and didn't fill out anything

isodev|1 year ago

Maybe they don't need a new subdomain, something unused could do the trick.

riccardomc|1 year ago

Probably a 'something.google.com'...

But you could have teams with DNS zone delegation who can.create.anything.like.this.google.com

drpossum|1 year ago

Or anyone who controls your DNS resolution which has a number of paths (for example a local hosts file, possibly a router, changing your config or how you get your config to a malicious DNS server, etc)

eknkc|1 year ago

Won’t work with https.

If that malicious actor can install a custom ca too, they can already install whatever spyware they want.

q3k|1 year ago

Not that easy with HSTS.

wbl|1 year ago

Also need a cert which is tricky

ruined|1 year ago

or public wifi access point

abirch|1 year ago

You'd probably need DNS and Root Certificates, something to which most employers have access

Tiberium|1 year ago

In what world does "system / tab CPU usage, GPU usage, and memory usage" mean "full access to the system"? Any Chrome extension can access this info easily, the point that the tweet makes is that there's a built-in Chrome extension that shares this info with Google's own websites without any confirmation.

mysterydip|1 year ago

What about anything on sites.google.com?

mywittyname|1 year ago

Is it really that easy? I just kind of assumed that devs could create subdomains under a dev TLD like googdev123.com, but not google.com until it was a fully-fledged product release.

hn_go_brrrrr|1 year ago

Nothing at Google is that easy. It is a large and slow-moving bureaucracy.

lyu07282|1 year ago

> full access to your system

Only to leak your CPU/GPU utilization though as far as I understand it. Those can also be exposed in other ways by legitimate JS/WebGPU by measuring/profiling shader runs/etc.

nashashmi|1 year ago

Drive.google.com links also work