Privacy: Financial information revealed in New Tab Page thumbnails?
Reported by
andrewas...@gmail.com,
Oct 3 2017
|
||||||
Issue descriptionFull disclosure - not a technical person and I am not sure if this qualifies as a bug. However, when I open the chrome browser and my google home page recommends recently (or frequently) visited sites, one recommendation is the website of a securities brokerage. In the thumbnail, the details of actual accounts including values, profits, and losses are very clearly visible. I am not logged into any google account when this happens, nor am I logged into the brokerage. Rather than present a thumbnail of the brokerages home page, it appears that a screenshot of my personal accounts has been used - somewhat alarming that this information is stored. I suspect this is rather a minor issue, but I found it startling that anyone using my hardware after me could have access to my finances. Cheers!
,
Oct 3 2017
,
Oct 3 2017
The brokerage is Questrade.com . As far as what page this issue can be replicated, it's the same as what you see in Issue 670488 . It shows a thumbnail of the accounts summary page of questrade.
,
Oct 4 2017
Which Chrome version were you using? For issue 670488 , we limited the size of the thumbnails to 308x192 pixels, which should be too small to make out details. That change is in Chrome 61; I'm interested to know if for this page, the details are still visible at that low resoultion. Separately: As a workaround, you can remove the thumbnail by moving your mouse over it and clicking the small "x" that appears in the top right corner.
,
Oct 4 2017
Currently running Version 61.0.3163.100 . Even at low resolution, details are clearly visible, including : "Summary as of 29 Sept 2017" "Cash, Market Value, Total Equity" and all values are visible. I will definitely use the workaround in the meantime. Cheers!
,
Oct 9 2017
Issue 772719 has been merged into this issue.
,
Oct 9 2017
Hmm, I'm also using M61 and I see that my thumbnails have a size of 424x284. Perhaps we are not replacing old ones?
,
Oct 10 2017
We do replace them, but the exact logic for when that happens is a bit convoluted. Try the following: On an NTP, click on the thumbnail you want replaced, then press Ctrl-T to open a new tab. If the thumbnail doesn't get replaced, I'd be interested to look at this in more detail :)
,
Oct 13 2017
,
Oct 17 2017
,
Nov 15 2017
Closing this as I don't think there's anything to be done right now. For now, we've limited the resolution of the thumbnails as a mitigation, and there are long-term plans to stop using thumbnails at all on the NTP. Feel free to reopen if there are any other suggestions. |
||||||
►
Sign in to add a comment |
||||||
Comment 1 by elawrence@chromium.org
, Oct 3 2017Labels: -Type-Bug-Security -Restrict-View-SecurityTeam Type-Bug
Summary: Privacy: Financial information revealed in New Tab Page thumbnails? (was: Security: Financial information compromised?)