{"id":10212,"date":"2014-05-01T08:24:47","date_gmt":"2014-04-30T22:24:47","guid":{"rendered":"http:\/\/michaelwyres.com\/?p=10212"},"modified":"2014-05-01T08:24:47","modified_gmt":"2014-04-30T22:24:47","slug":"timely-google-security-reminder","status":"publish","type":"post","link":"https:\/\/michaelwyres.com.au\/mwdc\/2014\/05\/timely-google-security-reminder\/","title":{"rendered":"Timely Google Security Reminder"},"content":{"rendered":"<p>With more and more people adopting tablet and smartphone devices running the Apple iOS and Google Android operating systems, I thought it timely to remember an important security issue if you choose to run the Google Chrome web browser on your device.<\/p>\n<p>I must admit, I had completely forgotten about this issue until yesterday when testing on my iPad, an early prototype for a web application I&#8217;m currently building for myself.  This web application displays to the user &#8211; (well, me in this instance) &#8211; the IP address and corresponding hostname from which they are logging into the application.<\/p>\n<p>I noticed the following statement of those details (outlined in red, click for a larger view):<\/p>\n<p><\/p>\n<p>Why is it coming up that I am logging in from a Google IP address\/hostname?  I was testing this during my lunch break at the office, so this wasn&#8217;t what I was expecting.<\/p>\n<p>After a few seconds of puzzling, I remembered why this was so.<\/p>\n<p>Google Chrome on iOS and Android has a &#8220;Reduce Data Usage&#8221; option, which seeks to compress data coming across the internet into your device, thereby reducing the overall amount of data you download.<\/p>\n<p>Possibly a good thing &#8211; but the fact that a Google IP address comes up when browsing to my web application reminds me that all traffic using this feature in Google Chrome for iOS or Android is routed <i>through<\/i> a Google server before it comes back to my device.<\/p>\n<p>Be conscious of what that means &#8211; Google can not only see <i>where<\/i> you are browsing, but what the content of the sites you are browsing actually is.  If you are browsing a corporate website that is normally password protected &#8211; (and therefore is normally unable to be indexed by Google) &#8211; it is now passing through their servers, thanks to the password you entered to access the page.<\/p>\n<p>Fortunately, if the page you are browsing to is SSL encrypted &#8211; (or is inside an &#8216;incognito&#8217; tab) &#8211; it does not pass through the Google proxy servers.  The SSL would not work if such pages tried to use this connection method.<\/p>\n<p>Hopefully, if your systems administrators are on the ball, even sites that are only accessible inside your corporate network are SSL encrpyted as a matter of course.  Certainly, all of my live web applications are SSL encrypted, which is why I don&#8217;t usually see this behaviour, and why it had slipped my mind a little bit yesterday.<\/p>\n<p>I&#8217;ve been working on this application without SSL, because I don&#8217;t have a spare IP address at the moment to do SSL on this app &#8211; something that I will able to fix when the application this new one is replacing is switched off &#8211; I&#8217;ll re-use that IP address.<\/p>\n<p>You will notice straight away when I switched the &#8220;Reduce Data Usage&#8221; option off, it was clear that the traffic was no longer being routed via Google, as the address I was logged in from was now as expected, with an IP address\/hostname that comes from the corporate network in the office:<\/p>\n<p><\/p>\n<p>So, if you are nervous about what Google might be seeing or not seeing when you are using Google Chrome on iOS or Android, consider turning this feature off in &#8220;Settings&#8221;, as shown:<\/p>\n<p><\/p>\n<p>Of course, I don&#8217;t know for certain if Google are capturing the traffic for other purposes as it passes through their proxy servers, but with my &#8216;security hat&#8217; on, I do see this behaviour as &#8211; (at the very least) &#8211; an issue to be aware of.<\/p>\n<p>Looking for the best IT security functionality possible is basically second nature to me &#8211; it&#8217;s part of what I do every day &#8211; so if something like this can slip my mind even just a little bit, it can easily slip yours a lot.<\/p>\n<p>If you even knew about it in the first place.<\/p>\n<p>As this option is switched on by default, I&#8217;m betting you didn&#8217;t even know about it &#8211; so have a think, and have a look.<\/p>\n<p>Safety first.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>With more and more people adopting tablet and smartphone devices running the Apple iOS and Google Android operating systems, I thought it timely to remember an important security issue if you choose to run the Google Chrome web browser on your device. I must admit, I had completely forgotten about this issue until yesterday when [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[90,148,259,294],"class_list":["post-10212","post","type-post","status-publish","format-standard","hentry","category-technology","tag-android","tag-chrome","tag-google","tag-ios"],"_links":{"self":[{"href":"https:\/\/michaelwyres.com.au\/mwdc\/wp-json\/wp\/v2\/posts\/10212","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/michaelwyres.com.au\/mwdc\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/michaelwyres.com.au\/mwdc\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/michaelwyres.com.au\/mwdc\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/michaelwyres.com.au\/mwdc\/wp-json\/wp\/v2\/comments?post=10212"}],"version-history":[{"count":0,"href":"https:\/\/michaelwyres.com.au\/mwdc\/wp-json\/wp\/v2\/posts\/10212\/revisions"}],"wp:attachment":[{"href":"https:\/\/michaelwyres.com.au\/mwdc\/wp-json\/wp\/v2\/media?parent=10212"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/michaelwyres.com.au\/mwdc\/wp-json\/wp\/v2\/categories?post=10212"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/michaelwyres.com.au\/mwdc\/wp-json\/wp\/v2\/tags?post=10212"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}