Major Google Web Accelerator Security Issue


Recommended Posts

I just logged into Neowin and notice that I had logged in as several neowin users. Every time I refreshed the page, the username changed, and I could access any portion of the site.

I was able to access their control panels and possibly even post (I did so to make sure that this was a security issue.)

It is still happening and I apologize if that has already been posted.

Edit:

This is a major Google Web Accelerator security issue:

http://news.zdnet.co.uk/internet/security/...39197327,00.htm

"I went to the Futuremark forums and noticed that I'm logged in as someone I don't know. Great, I've used Google's Web Accelerator for a couple of hours, visited lots of sites where I'm logged in. Now I wonder how many people used my cache. I understand it's a beta, sure, but something like that is totally unacceptable."

Edit 2:

Someone please modify the title of this thread. At the time of its posting, I hadn't realized it was a Google issue.

(MOD EDIT: changed the title now, hope that helps... DB)

Edited by dbfriends
I just realized: Could it be because of Google's Web Accelerator?

It is because of it. I'd highly recommend people stay away from this tool. I love Google but I don't like this tool at all, it's useless really and don't like what they are doing with it.

Here's SlashDot's discussion, http://slashdot.org/article.pl?sid=05/05/0...&tid=217&tid=95 and also SomethingAwful, which I do not visit but got passed the link also has an article on Google's Web Accelerator that's a pretty good read, believe the links though are banned here on the forum though. So look for yourself if you want to read it.

What could a mod do though? If it truly shares your cookies, the only way to combat it would be to disable cookies and make you sign in at all times.

The issue isn't with Neowin, cookies were designed to store your info for a site on your computer, if your cookie gets shared it's not the sites fault. You need to complain to google, not neowin.

What could a mod do though?  If it truly shares your cookies, the only way to combat it would be to disable cookies and make you sign in at all times.

The issue isn't with Neowin, cookies were designed to store your info for a site on your computer, if your cookie gets shared it's not the sites fault.  You need to complain to google, not neowin.

585880087[/snapback]

I think you need to understand that at the time of the first posting, I did not know it was Google!

This should be posted on the front page.

I think you need to understand that at the time of the first posting, I did not know it was Google!

This should be posted on the front page.

585880093[/snapback]

Agree :yes:

this is a HUGE issue.

this info should also be passed on to other forums as an attempt to avoid this stuff from happening.

Considering how big the issue really is, I have a hard time seeing how it was ever greenlighted at all.

The interaction between a cookie and web page has been a relative standard for the internet for years, heck I think the idea's over 10 years old, and to make a tool that basically throws that out of the window was downright irresponsible of google.

I know it's beta, I know it's not for the mainstream and is basically damn near hidden on thier site but, crap, what was going through thier heads?

The person who came up with this idea should never be allowed to work on any network related program ever again, this is the worst judgement I've ever seen a company make on the internet.

Considering how big the issue really is, I have a hard time seeing how it was ever greenlighted at all.

The interaction between a cookie and web page has been a relative standard for the internet for years, heck I think the idea's over 10 years old, and to make a tool that basically throws that out of the window was downright irresponsible of google.

I know it's beta, I know it's not for the mainstream and is basically damn near hidden on thier site but, crap, what was going through thier heads?

The person who came up with this idea should never be allowed to work on any network related program ever again, this is the worst judgement I've ever seen a company make on the internet.

585880169[/snapback]

Very well said. As a software developer myself, I cannot comprehend how such a major issue would afflict a public beta. It's completely unacceptable.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • VS Code 1.123 introduces massive upgrades for persistent AI developer workflows by Paul Hill Microsoft has just released Visual Studio Code 1.123 alongside its annual developer conference, Build 2026. This release, as always, has a heavy focus on advanced AI agent integration and making the built-in browser more robust. Notably, this update brings big sync changes that keep your AI agents persistent across sessions. With this update, VS Code now supports cross-machine syncing for chat histories, touched files, repository contexts, and related PRs via GitHub accounts, tying users even more into Microsoft’s developer ecosystem. This update also introduces the new /chronicle command that allows you to query past sessions using natural language, generate instant standup reports, and get personal productivity insights. Microsoft has also made some improvements to network-dependent operations, it explains: “When a terminal command that is run by a local agent requires access to domains that are not configured as allowed domains, the command is automatically retried inside the sandbox with unrestricted network access. After that, if it still fails, it falls back to unsandboxed execution. This allows network-dependent operations such as git fetch to finish, while keeping filesystem protections in place.” Microsoft has not stopped there; in this update, it also allows developers to drag, drop, and pin multiple agent sessions side-by-side for easy code comparisons in real-time. It also introduces the Research Agent, accessible via /research. This is a read-only, depth-optimized tool that gets data from the web, local codebase, and GitHub to give you a Markdown report on complex APIs or unfamiliar code. Now, let’s talk about the integrated browser and some security enhancements. VS Code 1.123 features enhanced screenshot capture tools that allow for targeted Area Screenshots and Full Page Screenshots to send layout context instantly to AI chat. The address bar has also been revamped, supporting favorite pages and tab management. Finally, on the security front, this update introduces a safety-first two-hour delay on third-party extension auto-updates to safeguard against compromised or buggy releases. This release is now available for Windows, Mac, and Linux. If you have VS Code, keep an eye out for the update availability notification. If you still don’t have VS Code, you can get it here.
    • I'm hoping with the Surface Pro 12, I can use either USB-C for my Xreal One Pro glasses. With my Surface Pro 11 OLED X Elite, I have to plug them into the top port. The bottom port will power it, but nothing shows on the screen. Maybe it's my setting. When I plug in the glasses, I have it output only to the glasses. So maybe I need to turn on both displays with it in the top port, then switch the glasses to the bottom port and set it to output only to the glasses. And then hopefully Windows remembers the settings for either the top port and bottom port (one of the awesome features of Windows where it remembers the exact configuration when plugging in external monitors.
    • Forgive my ignorance, but the only difference I see here is that a USB-A is now a USB-C, so there are two of them. For the modern age (and I'd argue since 2020), most products would now come with USB-C as an option, if not the default. Display, charging, devices, etc on TWO connectors, sometimes all combined! So having 2 of those powerful ports is great for something this size! Meanwhile my Surface Pro (5) has a single USB-A port which I cannot even get display out to, instead relying on some Surface Connect dock which I don't have. That is a poor experience, not to mention expensive and not compatible with other devices. Thank God USB-C is mainstream!
    • wow. that color finally comes to Surface Pro. was always a little jelly when a friend had the sandstone Surface Laptop. I wonder how different this dune is from the sandstone. I'll be getting the dune version. always thought black and platinum were a little boring. I'll still have access to my blue Surface Pro 11 as it'll be a hand-me-down.
    • Looks a very subjective aren't they!? I like its simple design. I love the way Apple designs their products with function over form, minimalization, and simplicity over cluttered complex designs. Many, not all, of their products follow this trend, and the device becomes a tool rather than dominating the space. I do not however like their OS. I have never bought a Apple product, and while I'd consider the Neo for my wife, I am hoping there are better alternatives out there when her failing MacBook Pro 2017 finally stops. Fischer-Price is famously plastic, garish, and poorly made. Basically you're describing the Window Laptops the Neo competes against! This is how product design should be, and what Apple have often followed in recent years: https://tenprinciples.design/
  • Recent Achievements

    • One Month Later
      B2Proxy earned a badge
      One Month Later
    • One Year In
      MadMung0 earned a badge
      One Year In
    • Week One Done
      jefred earned a badge
      Week One Done
    • Apprentice
      JoeyNeo went up a rank
      Apprentice
    • Week One Done
      oliviaexpo earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      482
    2. 2
      PsYcHoKiLLa
      227
    3. 3
      Skyfrog
      70
    4. 4
      FloatingFatMan
      58
    5. 5
      Nick H.
      54
  • Tell a friend

    Love Neowin? Tell a friend!