Major Google Web Accelerator Security Issue


Recommended Posts

The bug sounds a lot worse than it is. You're not logged in as anybody, it's simply the cached page that you're seeing. You cannot perform actions as the user that you may see:

http://news.com.com/Google+speed+bump+draw..._3-5698447.html

And no - you don't have to worry about your banking information or anything like that being seen by anybody. Banking is always done over HTTPS, and google couldn't see that stuff even if they wanted to.

Where are the "ill follow Google into hell" fans now? i dont really buy this researchware stuff, spyware with a friendly name.

well Google made a bad bobo, they will fix it but broadband should be fast enough without it, do you really need it? you were fine before it

585884442[/snapback]

I couldn't agree more. :yes:

I was curious to see this so called speed improvement, so I installed it on another computer only for 15 minutes. It said that there was 1 second of speed improvement within 15 minutes of browsing. :woot:

Improvement of 1 second, but all your cookies and personal data exposed to other people. Does it worth? :no:

Not only that, but if programmers designed their applications properly, there wouldn't be any problems anyway. Google's WA uses standard HTTP headers to determine the status of whether a page can be served from cache or should be retrieved again. If somebody's privacy is somehow exposed, it ultimately *is* a bug that the host application should address by properly sending the Cache-Control HTTP headers, including the last-updated status of the page.

Why are people installing this anyway? Do people on broadband really need more speed? I agree that this is a HUGE bug, but come on, these web accelerators never do what they claim.

585882031[/snapback]

Agreed. If, and only IF it speeded things up, the speed would be so negligable that any memory/resources the app used were being wasted. Maybe Google Inc. are testing the waters to see how dumb people really are, and what crap they'll voluntarily install on their systems. :p

It really appears that absolutely nobody has read that this isn't as big of an issue as the users in this thread have made it out to be....

585886386[/snapback]

What do you mean.

I've seen screenshots of peoples PM's being read... via the cache.

This is defiantely a bigger issue then your playing it down to be.

Their sessions might not be stolen... but I've seen screenshots of cached PM inboxes, with their PM's viewable.

585887696[/snapback]

*nod* The programmers should fix their applications, then. It's not Google's fault if web applications aren't following standard HTTP protocols.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Yes, Scoop was created to promote Coreutils for Windows. You can still see early versions of their website on the Web Archive. It was a joke that nobody took seriously. Microsoft's implementation of Coreutils, however, are built in Rust.
    • Looks like EA's Star Wars Zero Company will be out this August by Pulasthi Ariyasinghe Over a year ago, EA surprise announced that a team of former Firaxis members is working on a brand-new Star Wars game. Dubbed Zero Company, the title would have XCOM-like turn-based tactics gameplay as players manage a squad of professionals from all over the galaxy. Now, just ahead of an official announcement, it looks like the release date has leaked out. The upcoming Summer Game Fest presentation on Friday is when EA is supposed to show off the title's gameplay footage, with fans also expecting it to reveal a release date. However, the ever-reliable billbil-kun from Dealabs says they have already managed to find out when the game is coming out and what versions fans will have the option of purchasing. Per the leak, Star Wars Zero Company has an August 27, 2026, release date attached to it. The title is slated to release on PC, Xbox Series X|S, and PlayStation 5 with a $49.99 standard and $59.99 Deluxe edition. The leaker also adds that there won't be any early access perk attached to this special edition. Pre-orders could kick off alongside the official announcement this Friday, too. For those unfamiliar with the title, Bit Reactor is developing Star Wars Zero Company with help from Respawn Entertainment and Lucasfilm Games. The EA-published title is said to be set during the "twilight of the Clone Wars." We will have to wait and see if base building and management mechanics from the XCOM series will be present here, too. "You will step into the shoes of Hawks, a former Republic officer who leads Zero Company — an unconventional outfit of professionals for hire hailing from across the galaxy," reads the game description. "Hawks and Zero Company are recruited for an operation that pits them against an emerging threat that will consume the galaxy if left unchecked. To succeed, Hawks will lead a team of uneasy allies who must set aside their differences to overcome nearly impossible odds." You can catch the Star Wars Zero Company extended gameplay reveal at the Summer Game Fest showcase that's kicking off on Friday at 2 pm PT / 5 pm ET.
    • All their other games always had a new cast and new story, so that's not very surprising. The new dev is worrisome though.
    • New dev usually means more trash. I also despise that they censored the 1 remake.
    • Oh, they're back to making console games that actually sell consoles? Shock horror.
  • Recent Achievements

    • One Month Later
      nothanks earned a badge
      One Month Later
    • One Month Later
      B2Proxy earned a badge
      One Month Later
    • One Year In
      MadMung0 earned a badge
      One Year In
    • Week One Done
      jefred earned a badge
      Week One Done
    • Apprentice
      JoeyNeo went up a rank
      Apprentice
  • Popular Contributors

    1. 1
      +primortal
      482
    2. 2
      PsYcHoKiLLa
      232
    3. 3
      Skyfrog
      75
    4. 4
      FloatingFatMan
      66
    5. 5
      Michael Scrip
      55
  • Tell a friend

    Love Neowin? Tell a friend!