{"id":1034,"date":"2011-03-24T18:09:14","date_gmt":"2011-03-24T22:09:14","guid":{"rendered":"http:\/\/www.braindeadprojects.com\/blog\/?p=1034"},"modified":"2011-03-24T14:52:48","modified_gmt":"2011-03-24T18:52:48","slug":"quit-googling-your-passwords","status":"publish","type":"post","link":"http:\/\/www.braindeadprojects.com\/blog\/what\/quit-googling-your-passwords\/","title":{"rendered":"Quit Googling your Passwords"},"content":{"rendered":"<p>Recently, I noticed someone using one of the QuickSearch toolbars included in <a title=\"FireFox\" href=\"http:\/\/www.mozilla.com\/\" target=\"_blank\">Firefox<\/a> as a place to temporarily paste something while working on their desktop.<\/p>\n<figure id=\"attachment_1041\" aria-describedby=\"caption-attachment-1041\" style=\"width: 263px\" class=\"wp-caption aligncenter\"><a href=\"http:\/\/www.braindeadprojects.com\/blog\/wp-content\/putithere.png\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-1041\" title=\"I'll put it here\" src=\"http:\/\/www.braindeadprojects.com\/blog\/wp-content\/putithere.png\" alt=\"\" width=\"263\" height=\"227\" \/><\/a><figcaption id=\"caption-attachment-1041\" class=\"wp-caption-text\">Put it here temporarily?<\/figcaption><\/figure>\n<p>It makes sense, you need to place to hold something for a moment &#8211; it&#8217;s right there and readily available. And since you&#8217;re not pressing the Enter key, it&#8217;s not going to be sent anywhere right?<\/p>\n<p>Well, actually it is. After you stop typing, it immediately sends an <a title=\"HTTP POST\" href=\"http:\/\/en.wikipedia.org\/wiki\/POST_%28HTTP%29\" target=\"_blank\">HTTP POST <\/a>request to it&#8217;s target (<a title=\"Google\" href=\"http:\/\/www.google.com\" target=\"_blank\">Google<\/a> in this case). And while the search does takes place, it doesn&#8217;t update your browser (so you might not realize it even happens). Here&#8217;s a copy of the content in the packet:<\/p>\n<p>&nbsp;<\/p>\n<blockquote><p>GET \/complete\/search?output=firefox&amp;client=firefox&amp;hl=en-US&amp;q=<strong>mysuperleetpassword <\/strong>HTTP\/1.1<br \/>\nHost: suggestqueries.google.com<br \/>\nUser-Agent: &lt;omitted&gt;<br \/>\nAccept: text\/html,application\/xhtml+xml,application\/xml;q=0.9,*\/*;q=0.8<\/p><\/blockquote>\n<p>&nbsp;<\/p>\n<p>Does this matter? That depends on what you put there. You probably wouldn&#8217;t pick up the phone and call Google (or <a title=\"Yahoo!\" href=\"http:\/\/yahoo.com\" target=\"_blank\">Yahoo!<\/a>, or <a title=\"Bing\" href=\"http:\/\/bing.com\" target=\"_blank\">BING<\/a>, etc) and tell the receptionist &#8220;Hey, my <a title=\"FaceBook\" href=\"http:\/\/facebook.com\" target=\"_blank\">Facebook<\/a> username is &#8230; and my password is &#8230;&#8221;, but you can very easily do this by simply pasting ANYTHING in that handy little search bar.<\/p>\n<p>Here&#8217;s a quick video of me running a packet capture and typing something into the search area. Again, I only moved my cursor &#8211; never did I press Enter (View it fullscreen for better detail).<\/p>\n<p>&nbsp;<\/p>\n<p><object width=\"480\" height=\"390\"><param name=\"movie\" value=\"http:\/\/www.youtube.com\/v\/O7Bv4-aCRBM?fs=1&amp;hl=en_US\" \/><param name=\"allowFullScreen\" value=\"true\" \/><param name=\"allowscriptaccess\" value=\"always\" \/><embed type=\"application\/x-shockwave-flash\" width=\"480\" height=\"390\" src=\"http:\/\/www.youtube.com\/v\/O7Bv4-aCRBM?fs=1&amp;hl=en_US\" allowscriptaccess=\"always\" allowfullscreen=\"true\"><\/embed><\/object><\/p>\n<p>I wonder how much garbage accidentally falls into search engine pits like this. I&#8217;m also curious as to how many sites log mistyped passwords (think of it this way &#8211; you accidentally type your webmail password into Facebook or vice versa).<\/p>\n<p>All the misguided traffic reminds me of\u00a0 the <a title=\"IPv4 pollution\" href=\"http:\/\/labs.ripe.net\/Members\/franz\/content-pollution-18\" target=\"_blank\">pollution problem of 1.0.0.0\/8<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Recently, I noticed someone using one of the QuickSearch toolbars included in Firefox as a place to temporarily paste something while working on their desktop. It makes sense, you need to place to hold something for a moment &#8211; it&#8217;s right there and readily available. And since you&#8217;re not pressing the Enter key, it&#8217;s not &hellip; <a href=\"http:\/\/www.braindeadprojects.com\/blog\/what\/quit-googling-your-passwords\/\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">Quit Googling your Passwords<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[14,1],"tags":[],"class_list":["post-1034","post","type-post","status-publish","format-standard","hentry","category-braindeadtip","category-what"],"_links":{"self":[{"href":"http:\/\/www.braindeadprojects.com\/blog\/wp-json\/wp\/v2\/posts\/1034"}],"collection":[{"href":"http:\/\/www.braindeadprojects.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.braindeadprojects.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.braindeadprojects.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/www.braindeadprojects.com\/blog\/wp-json\/wp\/v2\/comments?post=1034"}],"version-history":[{"count":18,"href":"http:\/\/www.braindeadprojects.com\/blog\/wp-json\/wp\/v2\/posts\/1034\/revisions"}],"predecessor-version":[{"id":1053,"href":"http:\/\/www.braindeadprojects.com\/blog\/wp-json\/wp\/v2\/posts\/1034\/revisions\/1053"}],"wp:attachment":[{"href":"http:\/\/www.braindeadprojects.com\/blog\/wp-json\/wp\/v2\/media?parent=1034"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.braindeadprojects.com\/blog\/wp-json\/wp\/v2\/categories?post=1034"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.braindeadprojects.com\/blog\/wp-json\/wp\/v2\/tags?post=1034"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}