https://techsparx.com/software-development/security/csp-camera-microphone.html [logo] * Blog News Doctor Who * Computers Chromebooks Hardware Apple Arduino Linux SBC's Linux * Privacy Social Media Warfare Spying * Software Development Spring Docker AWS Serverless Node.js * Catalog Learn Node.js Programming Learn Docker Arduino Raspberry Pi * About [ ] Search An iframe from googlesyndication.com tries to access the Camera and Microphone 1. TechSparx 2. Software Development 3. Secure Software Development 4. An iframe from googlesyndication.com tries to access the Camera and Microphone By David Herron ; Date: Tue Dec 14 2021 Tags: Content Security Policy >>>>>>>> Feature Policy The last thing we want is for an advertising network to access the Camera or Microphone on our computer. But, while looking for something else, I stumbled upon messages in the Safari JavaScript console saying that an iframe loaded from safeframe.googlesyndication.com tried to do exactly that. [adverts-ac] [INS::INS] In case you're not aware, there is extreme alarm about the possibility that the web-camera or microphone built-in to laptops, smart phones, and the like, could be surreptitiously turned on. What if Big Brother were to turn on the camera, without turning on the indicator light, and take pictures, or record audio from the built-in microphone? There's a long list of possible nefarious results, and this has to be seen as a serious privacy intrusion. There is no legitimate purpose for an advertising network to access either the camera or microphone. But, going by the messages I found in the JavaScript console, that appears to be what an advertisement tried to do. Trying to search for information on googlesyndication connecting to camera or microphone turns up results indicating that many believe safeframe.googlesyndication.com is some kind of malware or virus distribution server. That's a strange assumption to make, considering the purpose for the GoogleSyndication.com domain. Namely, that domain is affiliated with the Google Ads and Google Adsense advertising networks. The purpose is delivering tailored marketing (advertisements) to people. Whether you think this is malware, I suppose, depends on how you consider Google Ads or Google Adsense. The GoogleSyndication.com domain is part of Google's legitimate ad serving service. Given Google's policies around that service it is extremely unlikely for malware to be distributed through that particular service. But... if that's the case, how can you explain these messages? [access-cam] These messages appeared in the JavaScript console on Safari while browsing multiple pages on techsparx.com. At first I saw it on one page, then checked other pages and got the same messages. This site is using Ezoic's advertising system, which in turn uses Google Ad Manager for some advertising. The messages are somewhat clear -- that an