New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 771155 link

Starred by 3 users

Issue metadata

Status: WontFix
Owner:
Closed: Nov 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Windows , Chrome , Mac
Pri: ----
Type: Bug



Sign in to add a comment

Privacy: Financial information revealed in New Tab Page thumbnails?

Reported by andrewas...@gmail.com, Oct 3 2017

Issue description

Full disclosure - not a technical person and I am not sure if this qualifies as a bug. 

However, when I open the chrome browser and my google home page recommends recently (or frequently) visited sites, one recommendation is the website of a securities brokerage. In the thumbnail, the details of actual accounts including values, profits, and losses are very clearly visible. I am not logged into any google account when this happens, nor am I logged into the brokerage. 

Rather than present a thumbnail of the brokerages home page, it appears that a screenshot of my personal accounts has been used - somewhat alarming that this information is stored.

I suspect this is rather a minor issue, but I found it startling that anyone using my hardware after me could have access to my finances.

Cheers! 
 
Components: UI>Browser>NewTabPage Privacy
Labels: -Type-Bug-Security -Restrict-View-SecurityTeam Type-Bug
Summary: Privacy: Financial information revealed in New Tab Page thumbnails? (was: Security: Financial information compromised?)
This is  Issue 670488 , but apparently the fix isn't good enough.

Can you please share information about what securities brokerage has this issue, and on what page we can replicate the problem?

Thanks!
Labels: OS-Chrome OS-Linux OS-Mac OS-Windows
Owner: treib@chromium.org
The brokerage is Questrade.com . As far as what page this issue can be replicated, it's the same as what you see in  Issue 670488 . It shows a thumbnail of the accounts summary page of questrade. 

Comment 4 by treib@chromium.org, Oct 4 2017

Cc: msramek@chromium.org battre@chromium.org
Which Chrome version were you using? For  issue 670488 , we limited the size of the thumbnails to 308x192 pixels, which should be too small to make out details. That change is in Chrome 61; I'm interested to know if for this page, the details are still visible at that low resoultion.

Separately: As a workaround, you can remove the thumbnail by moving your mouse over it and clicking the small "x" that appears in the top right corner.
Currently running Version 61.0.3163.100 . Even at low resolution, details are clearly visible, including : "Summary as of 29 Sept 2017" "Cash, Market Value, Total Equity" and all values are visible. 

I will definitely use the workaround in the meantime. 

Cheers!
 Issue 772719  has been merged into this issue.

Comment 7 by fi...@chromium.org, Oct 9 2017

Hmm, I'm also using M61 and I see that my thumbnails have a size of 424x284. Perhaps we are not replacing old ones?

Comment 8 by treib@chromium.org, Oct 10 2017

We do replace them, but the exact logic for when that happens is a bit convoluted. Try the following: On an NTP, click on the thumbnail you want replaced, then press Ctrl-T to open a new tab. If the thumbnail doesn't get replaced, I'd be interested to look at this in more detail :)
Labels: zine-triaged
Status: Assigned (was: Unconfirmed)

Comment 11 by treib@chromium.org, Nov 15 2017

Status: WontFix (was: Assigned)
Closing this as I don't think there's anything to be done right now. For now, we've limited the resolution of the thumbnails as a mitigation, and there are long-term plans to stop using thumbnails at all on the NTP.
Feel free to reopen if there are any other suggestions.

Sign in to add a comment