1. Advertising
    y u no do it?

    Advertising (learn more)

    Advertise virtually anything here, with CPM banner ads, CPM email ads and CPC contextual links. You can target relevant areas of the site and show ads based on geographical location of the user if you wish.

    Starts at just $1 per CPM or $0.10 per CPC.

Google to patch Home and Chromecast bug that leaked your location

Discussion in 'Google' started by houssem545, Jun 18, 2018.

  1. #1
    Google is planning to release a patch for a worrying IoT security vulnerability that can enable precise location tracking of Home speaker and Chromecast users.
    Security researcher Craig Young of Tripwire claims to have found an authentication weakness that dishes near-pinpoint location data on users, via their smart home gadgets.

    An intruder could use a malicious website to exploit a loophole in Google’s back-end systems and “determine a user’s location to within a few feet.”

    Young says it works by asking the Google device for wireless network devices nearby and then sending the list to the company’s own geolocation services. The exploit requires the user to click and remain on the page for a minute in order to give up their location, but it’s worrying nonetheless, especially considering the attacker doesn’t have to be on the local network.

    “An attacker can be completely remote as long as they can get the victim to open a link while connected to the same Wi-Fi or wired network as a Google Chromecast or Home device,” Young told KrebsOnSecurity (via Engadget).

    “The only real limitation is that the link needs to remain open for about a minute before the attacker has a location. The attack content could be contained within malicious advertisements or even a tweet.”

    Young created a video of the exploit in action, which has been successful in three environments and gleaned a precise street address on each occasion.

    He added: “The Wi-Fi based geolocation works by triangulating a position based on signal strengths to Wi-Fi access points with known locations based on reporting from people’s phones.”

    After Young’s initial inquiries were brushed off, Krebs followed up with Google, who said the fix is coming sometime within the next month.

    source for information : http://www.trustedreviews.com/news/google-home-chromecast-devices-giving-away-location-3488702

    source for information :https://www.one-news1.com/
    houssem545, Jun 18, 2018 IP