meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, February 25th 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 25 February 2020

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. ScrollToTextFragment Google Chrome; WhatsApp Invite Links @JordanWildon; OpenSMTPD again;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, February 25th, 2020 edition of the Sandstone Storm Center's Stormcast.

0:08.4

My name is Johannes Ulrich.

0:09.9

And then I'm recording from Jacksonville, Florida.

0:13.8

With the release of Google Chrome 80 around the corner, one feature has gotten some discussion and security concern and that's the

0:23.7

scroll to text fragment feature the way it is supposed to work is that i can send you a URL at the end

0:32.4

of the URL i add some text and then the browse i will automatically scroll to the first time this text

0:41.2

shows up on a particular page.

0:43.7

Now in existing browsers and in Google Chrome before this upcoming version, you were still

0:50.6

able to direct the user to a particular part of the page, but you had to add

0:56.2

a specific A tag in order to mark this location, and then you would add a hashmark at the

1:02.8

end of the URL and with the tag that was predefined, but I could not send you to sort of an

1:09.1

opt-repoint within the page.

1:11.6

So the way this is useful is that if I want to send you a link to an article and I want to sort of tell you about a particular paragraph,

1:18.6

whoever wrote the article didn't specifically mark the paragraph, I could add some text from this paragraph and the browser would automatically scroll to the paragraph

1:29.0

as you click on the link.

1:31.0

Sounds like a relatively simple, innocent feature, but there are some privacy concerns and

1:38.6

Peter Snyder, who is a researcher working with Brave software, the privacy focused browser, did point out

1:46.7

some of these issues. Essentially, what this could potentially lead to is if I sent you a link

1:54.4

to a page with a particular content, I may be able to detect if this content is present on the page, and as a result,

2:04.4

I could leak sensitive information if this page contained private information.

2:10.3

Think, for example, about like a medical page that lists search terms that you recently

2:16.5

searched for.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.