News: 1632312852

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Google emits Chrome 94 with 'Idle Detection' API to detect user inactivity, despite opposition

(2021/09/22)


Google has released Chrome 94 for desktop and Android, complete with an "Idle Detection" API to detect user inactivity, despite privacy concerns expressed by Mozilla and Apple.

New and changed features in Chrome 94 are [1]listed here and include the removal of the AppCache feature, described as a "security and stability liability", and something which has "imposed a tax on all of Chrome's significant architectural efforts."

There is also a new VirtualKeyboard API with more control over its shape and an event fired when it covers page content; more efficient low-level access to media encoders and decoders; and a new JavaScript [2]Self Profiling API which enables developers to collect JavaScript performance profiles from end users.

[3]

"By providing an API to manipulate a sampling profiler, applications can gather rich execution data for aggregation and analysis with minimal overhead," say the [4]docs on the W3C Community Group.

[5]

[6]

The JS self-profiling API has enthusiastic support from Microsoft, Elastic and Dropbox, [7]recorded on GitHub.

[8]

Idle Detection: new in Chrome 94, but Mozilla considers it harmful

The IdleDetection feature is more contentious. The feature is designed for multi-user applications such as meetings, chat, and online games. It notifies the web application when a user is idle, using signals such as lack of use of mouse and keyboard, the screen locking, or the user switching away from the screen where the application is running.

These events occur outside the browser, rather than being reserved for usage of the browser itself.

"Applications which facilitate collaboration require more global signals about whether the user is idle than are provided by existing mechanisms that only consider a user's interaction with the application's own tab," say the release notes.

[9]

Support for the API was [10]expressed by developers from Slack and Google Chat, among others.

Our concerns are not limited to fingerprinting. There is an obvious privacy concern that this API lets a website observe whether a person is near the device or not...

Mozilla web standards lead Tantek Çelik [11]said on GitHub : "I consider the Idle Detection API too tempting of an opportunity for surveillance capitalism motivated websites to invade an aspect of the user’s physical privacy, keep longterm records of physical user behaviors, discerning daily rhythms (e.g. lunchtime), and using that for proactive psychological manipulation (e.g. hunger, emotion, choice [1][2][3]). In addition, such coarse patterns could be used by websites to surreptiously max-out local compute resources for proof-of-work computations, wasting electricity (cost to user, increasing carbon footprint) without the user’s consent or perhaps even awareness."

Google's Reilly Grant, one of the proposal's owners on the Chromium team, [12]asked for feedback on the WebKit mailing list, WebKit being the browser engine used by Apple for Safari.

Apple's Ryosuke Niwa [13]responded that: "Our concerns are not limited to fingerprinting. There is an obvious privacy concern that this API lets a website observe whether a person is near the device or not. This could be used, for example, to start mining bitcoins when the user is not around or start deploying security exploits, etc."

Grant responded that there is work being done to "define the semantics for throttling the work that sites are allowed to do in the background," to combat the crypto mining menace, and that the API would benefit the user by not showing notifications on inactive devices. "[U]sers want to receive notifications on only the device they are currently using," Grant said.

[14]

But Niwa replied that "none of the use cases presented either here or elsewhere are compelling, and none of the privacy or security mitigations you've presented here and I found elsewhere are adequate."

'Tentative deliverable'

Google has nevertheless now implemented the API, after two origin trials in previous versions of Chrome. Its [15]status with the W3C, the body which defines web standards, is as a "tentative deliverable," which means it is some way off being an agreed recommendation.

[16]Google experiments with user-choice-defying Android search box

[17]Microsoft does and doesn't want you to know it won't stop you manually installing Windows 11 on older PCs

[18]An easier way to Flutter? Custom functions improve visual code builder but devs may still be frustrated

The Idle Detection API is subject to user permission, which can be found in Chrome 94 settings. The user can specify whether or not sites are allowed to ask "to know when you're actively using device". A concern with such settings though is that sites may try to coerce the user by blocking certain content unless the permission is granted.

[19]

Idle Detection settings in Chrome 94

Google is also planning to improve memory security in Chrome, possibly by rewriting some components in Rust. According to a post [20]yesterday , "more than 70 per cent of our severe security bugs are memory safety problems."

The team is simultaneously exploring making C++ (the language with which Chrome is written) safer with compile-time and runtime checks, and also use of Rust which is inherently a more memory-safe language.

In a [21]separate post , the Chromium team said that "the hardest part of this is imagining a safe way to pass types between Rust and C++," which is why the Rust proposal remains a "background investigation." ®

Get our [22]Tech Resources



[1] https://www.chromestatus.com/features/4590256452009984

[2] https://github.com/WICG/js-self-profiling

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YUtTODvKq7OBFhgfoeZxXwAAAJU&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://wicg.github.io/js-self-profiling/

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YUtTODvKq7OBFhgfoeZxXwAAAJU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YUtTODvKq7OBFhgfoeZxXwAAAJU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://github.com/WICG/js-self-profiling/issues

[8] https://regmedia.co.uk/2021/09/22/idledetect.jpg

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YUtTODvKq7OBFhgfoeZxXwAAAJU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[10] https://discourse.wicg.io/t/idle-detection-api/2959/3

[11] https://github.com/mozilla/standards-positions/issues/453#issuecomment-888225596

[12] https://lists.webkit.org/pipermail/webkit-dev/2020-October/031558.html

[13] https://lists.webkit.org/pipermail/webkit-dev/2020-October/031562.html

[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YUtTODvKq7OBFhgfoeZxXwAAAJU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[15] https://w3c.github.io/dap-charter/DASCharter-2021.html#tentative

[16] https://www.theregister.com/2021/09/22/google_android_search_box_experiment/

[17] https://www.theregister.com/2021/08/27/windows_11_iso_install/

[18] https://www.theregister.com/2021/09/22/an_easier_way_to_flutter/

[19] https://regmedia.co.uk/2021/09/22/idlesettings.jpg

[20] https://security.googleblog.com/2021/09/an-update-on-memory-safety-in-chrome.html

[21] https://www.chromium.org/Home/chromium-security/memory-safety/rust-and-c-interoperability

[22] https://whitepapers.theregister.com/



Do Evil

Anonymous Coward

The browser should not be extending beyond the browser. No way. Never.

Re: Do Evil

seven of five

I am looking forward to the day this will come back to bite. Still accepting bets on when (IF is out of question).

Re: Do Evil

Randy Hudson

"Do Know Evil"

FTFY

So presumably Google is already gathering this data with their browser?

Anonymous Coward

With or without consent.

Also, can we (I say we, please red: chrome users) get a setting to simply always tell all websites that there is activity happening and that idling is not taking place. Surely that should at least take care of any "you have to allow this" shenanigans.

Surely that should at least take care of any "you have to allow this" shenanigans.

Meeker Morgan

I predict there will be an extension to do this.

Also, this demonstrates once again why NoScript (or equivalent) is absolutely essential.

Re: Surely that should at least take care of any "you have to allow this" shenanigans.

Dan 55

I would have thought uninstalling Chrome would be even more absolutely essential.

The last straw

bronskimac

I've not been happy with Chrome's privacy/snooping for a long time. I finally deleted it last night when I read about "Idle Detection". If there are Chrome features/extensions you simply cannot live without, then Comodo Dragon is a Chromium based browser that doesn't tell tales to Google.

Notifications

Barry Rueger

"[U]sers want to receive notifications on only the device they are currently using," Grant said.

I doubt that I am alone in struggling to eliminate all of the dozens of unwanted and unnecessary notifications from seemingly every web site and application that has ever come close to my devices.

The all pervasive and all intrusive nature of tech right now is damaging us in many ways.

roblightbody

Firefox and Duck Duck Go

Would've been good to give the settings link

Empire of the Pussycat

i.e. chrome://settings/content/idleDetection

Common sense is instinct, and enough of it is genius.
-- Josh Billings