HomeSecurityAmazon Silk Browser forces Google to operate over HTTP

Amazon Silk Browser forces Google to operate over HTTP

Earlier versions of the built-in browser for all Amazon devices, called Silk, forced users to use an insecure version of Google for their web searches if users had the Google search engine installed on their browser.

Silk is a Chromium-based Web browser that comes bundled with Amazon Kindle and Fire devices. By default, the browser comes with Google as the primary search provider, but users can also choose between Bing and Yahooif they wish.

Amazon Silk Browser forces Google to operate over HTTP

In older versions before v51.2.1, the Silk browser sent user searches to Google over HTTP instead of HTTPS, and also prevented automatic redirection to the HTTPS version of the site when users accessed the HTTP version of Google.

While sending Google queries from the browser to Google servers may seem like a developer oversight, the second error was more concerning.

By default, Google automatically redirects all users from the HTTP version of its site to the HTTPS version. Google handles this redirection, and only a serious technical problem on the user's side would have prevented this process.

Security researchers from Nightwatch Cybersecurity, who discovered the issues, stated that accessing translated versions of the search engine, such as Google.es or Google.jp via HTTP would actually redirect them to the HTTPS version.

This means that there was no technical difficulty when SSL started working in the browser and that the HTTPS blocking for Google.com was not the result of a general error.

The problem with this behavior is that it exposes the user's Google searches to anyone "listening" to the user's Web traffic, because all data is sent as plain text.

silk-browser-settings

A Google searches are often used to gather information about an individual and are a treasure trove of information for advertisers. Even Google itself uses this data for advertising.

The researchers notified Amazon, which fixed the issue in Silk browser v51.2.1. “Apart from a general response we initially received, there was no further communication from the seller,” the Nightwatch team noted on its blog, revealing that Amazon had not bothered to explain why this strange issue was occurring.

Amazon knows its share of problems. The Silk browser itself raised privacy concerns when it launched in 2011because it uses the concept of cloud-based Web browsing, where all data is sent to Amazon's EC2 service for processing and then sent back to the user's device.

Amazon said this was done to save power on the device by outsourcing CPU-heavy tasks (like JavaScript) to powerful cloud computers that simply render the final web page at the end. The concept of a cloud browser has since spread to other companies as well, such as Opera.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS