Follow Slashdot stories on Twitter

 



Forgot your password?
typodupeerror
×
Google The Internet Technology

Google Not Reciprocating On IFrame Usage? 115

theodp writes "Over at the Google Web Search Community, posters are questioning why Google feels free to IFrame others' web pages, yet blocks attempts to IFrame pages on its own sites. 'Google has so much contradiction in what it wants for itself and what it does with other websites [e.g., Google frames Slashdot],' quipped one poster. 'Do no evil, right?' And over at the Google Maps Help Forum, developers are also begging for Google to allow them to IFrame entire pages again. 'I know there are other options (&embed etc.),' explains a poster, 'but then there is no sidebar which is useless. I really need the functionality like it was before.' Can any Googlers out there explain The Mystery of 'This content cannot be displayed in a frame'?"
This discussion has been archived. No new comments can be posted.

Google Not Reciprocating On IFrame Usage?

Comments Filter:
  • XSRF (Score:5, Informative)

    by Anonymous Coward on Sunday October 23, 2011 @02:59PM (#37811602)

    It's to prevent XF clickjacking, XSS and XSRF attacks. Please see recent web security papers. Many other major sites with valuable login credentials do the same thing.

    • Exactly. I'm over security for part of a fairly major website and our customers are starting to get after us for not disallowing iframes of our site.
      • by dankney ( 631226 )

        Exactly. I'm over security for part of a fairly major website and our customers are starting to get after us for not disallowing iframes of our site.

        Any authenticated site should be doing this -- it's only a couple of lines of Javascript to reasonably cover your bases.

        Why aren't you? Is there some sort of crazy business blocker?

    • by msobkow ( 48369 )

      People have been demanding that security holes be plugged, including these web attacks.

      Now they're complaining that Google fixed the problem.

      Hopefully they'll stop screaming about Google taking over the world long enough to hear that it's a security fix. Sometimes fixes break existing code.

  • Clickjacking (Score:4, Informative)

    by Anonymous Coward on Sunday October 23, 2011 @03:00PM (#37811614)

    http://en.wikipedia.org/wiki/Clickjacking may be related.

  • by Anonymous Coward

    'Clickjacking' UI-Redressing and assorted other attacks rely on framing the target page.

  • Get over it, it's a multi billion dollar multi national business. Not your local charity, nor grandma's coffee shop.

    Those who cling to the "don't be evil" meme say more about themselves and their naiveté, than it does about Google.
    • by luke923 ( 778953 )

      I think the reason people are upset that Google isn't living up to their own mantra of "Don't be evil" is the fact that they fail to meet the standard they set for themselves. On the other hand, if Google had the phrase, "Let's make lots of money off of others' content and technology," then no one would be upset with some of Google's questionable tactics. It goes back to basic symbolic logic p=>q. If p is false, no matter what q is, the statement is true; however, if p is true and q is false, the whol

      • That's only true if q and only q follows from p. If there is any time when q doesn't logically follow from p then the whole thing breaks down immediately.

        In this case there is the alternate explanation that Google is now defaulting to SSL for it's searches and perhaps they don't want to be a party to clickjacking and various other hijinks that could result.

      • Re: (Score:2, Insightful)

        by dave420 ( 699308 )
        Hint: There is a perfectly reasonable technical explanation for Google not allowing other sites to host their sites in iframes. Think about it for a minute. Seriously. It's rather easy to figure out. "Good" and "Evil" don't even feature in their reasoning.
      • by epine ( 68316 )

        Google's motto is "Let's make lots of money off of others' content and technology". Did anyone ever doubt that? It goes without saying.

        Where Google comes close to evil is booting people off the Google services without making it possible for the booted user to collect his or her belongings before the door slams their ass. There's effectively no recourse if Google makes an error in their determination. I think this pushes fairly deep into caprice, and with no real upside that I can see. At least your jilt

        • To follow up on my last post:

          I wouldn't be unhappy to see property law evolve in the cloud era so that blocking a user from recovering those possessions in a reasonable process and time frame would constitute actual theft.

          Property is a social construct and it changes as the embodiment of property changes (wives, children, slaves, agricultural boundaries, water, mineral rights, design, copyright, and in the ridiculous fullness of time as practiced by the legislature and legal profession ... personal cloudwar

      • On SEO pages there shouldn't be any reason to bitch as Google is doing you a service (exposing your site to potential customers). On intranet pages or pages requiring credentials to access, just ban any user agent with "google", "facebook", "bot", etc. That's what I do and I think it would be prudent for any other corporate website management.
      • by mldi ( 1598123 )
        OK, trying to apply the "don't be evil" mantra to this situation is really reaching. The issue of blocking iframes is security-related, end of story. Second, if a website doesn't like people iframing their shit, they can block it too. It's only a double-standard if Google complains.
  • by Anonymous Coward

    Preventing other sites from displaying a page from within a frame is a common defense against a web application vulnerability known as Clickjacking [wikipedia.org].

  • Comment removed (Score:4, Insightful)

    by account_deleted ( 4530225 ) on Sunday October 23, 2011 @03:19PM (#37811724)
    Comment removed based on user account deletion
    • Re: (Score:2, Insightful)

      by dave420 ( 699308 )
      Christ. There is no contradiction as they don't penalise other sites for not allowing themselves to be rendered in an iframe. If you have a site where clickjacking is a real threat to operations (as Google does, what with them being the #1 search engine, and having a very popular single-sign-on mechanism), you should have the option to disable the site being rendered in a frame. How the fuck is allowing others to do exactly what you do a contradiction?
    • Google has so much contradiction in what it wants for itself and what it does with other websites

      For them it already is theirs.
      As long as nobody clearly states that it isn't their data, they will treat it as theirs. And nobody is saying that the personal data belongs to the person, so companies can keep confusing you and telling that as soon as it is somehow online, it is not yours anymore.

      Are you suggesting Google is a toddler? [berkeley.edu]. They're supposed to be 13 years old now. Someone send them a note to grow up and start grunting and concentrating on their music like any other teenager!

    • As long as nobody clearly states that it isn't their data, they will treat it as theirs.

      Funny, even if your book had that text about not putting it in an automated storage and retrieval system in any format... still got scanned. I think they want you to say not just everyone, but also google in particular.

  • WTF? (Score:5, Insightful)

    by Mathinker ( 909784 ) on Sunday October 23, 2011 @03:19PM (#37811726) Journal

    The summary seems to imply that Google has "magical powers" which enable it to block displaying its pages in IFrames, which no one else has?

    The reality, AFAICT, is that everyone could block Google from displaying their pages in that way, also. They largely just don't (either want, bother or know how to do it), but I fail to see how that makes Google "evil".

    • Exactly. No conspiracy here, if you want to prevent google from displaying your pages in frames you are certainly able to.
    • Re: (Score:2, Interesting)

      Comment removed based on user account deletion
      • Really? I never saw the term "magical powers" anywhere in the summary, nor was it implied in any way. What was implied, and in fact outright stated, is that Google is being hypocritical. They are doing to others what they disallow being done to them.

        And what's stopping other from disallowing the same thing? Nothing, that's what. All Google is doing is *dramatic gasp* protecting its users! They may not be doing it out of any altruistic motives, but it is what it is. If web devs are too damn lazy to use the Google APIs for accessing and displaying this data, too damn bad. There's nothing hypocritical about this story.

      • They're not being hypocritical. Some pages can be safely IFRAMEd, others can't. It's up to the website developers to decide, like Google has for their website(s).

      • > They are taking without giving in kind.

        Your comment is, well, bizarre. As I pointed out. Thinking of various real-life analogies makes this clear.

        For example, if someone puts up "No Trespassing" signs anywhere on his property, in your opinion he is being hypocritical if he then doesn't continually check, wherever he goes, that he is not on unsigned private land? And what if the country where he is currently visiting doesn't have a central registry for doing this kind of checking --- do you have any ide

        • Comment removed based on user account deletion
          • > What sort of nonsense is this?

            What it seemed to me to be what you were proposing? I didn't quite understand how he Mother Theresa analogy in your rebuttal fits the Google situation. You claim that Google is "admonishing others" to not use standard technology which would prevent them from displaying web pages in IFrames? Have any evidence there?

            > Google is taking without giving

            I don't know about you, but I find them kind of useful, sometimes. Others seem to concur.

            > as we are saying that they sure

      • They are taking without giving in kind.

        I noticed Google also disallows crawlers to certain url's on google.com [google.com], yet they will happily crawl every url on your site if you don't take similar action to prevent it. We need to put a stop to this madness at once!

    • This is no magic, this is the result of the X-Frame-Options HTTP header, sent by Google servers, and honoured by browsers. That avoids a bunch of security vulnerabilities and anyone should do it. The weird thing is that Google still promotes the use of frames when displaying search results.
  • Congratulations (Score:3, Insightful)

    by Anonymous Coward on Sunday October 23, 2011 @03:21PM (#37811746)

    The threads you linked to have 18, 2, and no comments respectively.
    While this is mildly interesting, it appears all the links you could find have trivial numbers of people participating.

    Nobody cares, this is non-news. Oh wait, Google was mentioned?
    There's even a comment about DRM! Everyone loves DRM articles!
    Nevermind, proceed with the company-bashing.

    Congratulations on spamming your private battle to thousands of people via Slashdot editors.

  • What? (Score:4, Insightful)

    by xstonedogx ( 814876 ) <xstonedogx@gmail.com> on Sunday October 23, 2011 @03:23PM (#37811762)

    'Google has so much contradiction in what it wants for itself and what it does with other websites [e.g., Google frames Slashdot],' quipped one poster. 'Do no evil, right?'

    I don't see the contradiction. Everyone is allowed to decide whether or not they allow their content to be displayed in iframes. If Google chooses no for itself but takes advantage of the fact that others have chosen yes, that is not hypocrisy. (If Google was forcing yes on others, the poster might have a point.)

    There is plenty to complain about here, I'm sure, but that's not it.

    • I guess the hypocrisy accusation comes from the fact that your argument applies equally well to just about any evil organisation. The problem is simple. If everybody is allowed to shoot and kill, those with guns have the obvious advantage. Since google >>>>>>>>>>> other websites, a similar principle applies here.

      • Everyone else has exactly the number of guns that Google does, in that disabling IFrames is a single gun, and any website can use it free of charge. Your argument is bunk.
        • Everyone else has exactly the number of guns that Google does,

          Riiiiight ... you sound like the Iraqi information minister here.

          1) Does google have the same technical options as everybody else ? No, they have more (e.g. they use undocumented, or badly documented features of their own software, but it doesn't quite end there)
          2) Does google have the same clout as everybody else ? Definitely not.

  • by Anonymous Coward

    Couldn't you write a browser script that modifies JavaScript's window object and such to make frame-breaking impossible?
    And if you were a browser developer, couldn't you restrict frame-breaking to pages within the same website?

  • Google is an advertising company. Nearly all of their sites and services are focused to drive ad revenue.

    Please note: 2011-Q3: Total Ad Revenue $9.335B (96%), Other Revenue $0.385M (4%)
    Source: Google Financial Results [google.com]

    If Google did allow 3rd party frames of its websites, than that creates the situation that someone else can add their own advertising onto Google's pages/services, and prevents them from completing controlling the entire ad experience and ad revenue.

    Personally I don't fault Google for this, si

    • So you're arguing that Google is unwilling to tolerate the existence of other ad networks? That's odd, especially considering how many you can find using Google itself. [google.com] Someone using ads on a service that used a Google IFrame wouldn't stop Google from making money on its own ads.

      The other posters have hit the nail on the head. When you're dealing with as much personal data as Google, it would be irresponsible to allow IFrames. The fact that clickjacking isn't on the security radar of most users makes the
      • The argument is that google is perfectly willing to add it's own adds to views of other people's webpages, yet refused the reverse (e.g. someone showing google with an add on top).

        • Is Google adding ads to other people's sites? I just checked some search results and didn't see that happening. If you look at the image linked in the summary, there are no Google ads on the page.

          Anyway, Google putting other pages in IFrames isn't an issue, so long as you can block the use of IFrames and still be listed by Google. That's entirely equitable: they're able to opt-out and you're able to opt-out. And, unless I'm very much mistaken, that's how it works.
          • Okay, search for a term which has ads. Don't make it complicated, make it "car". There you go : content from external sites, google's ads. But this is quite tame, right ?

            Now hover your mouse over one of the results. Boom. All content of the external site, rendered. Google's ads still visible (and more prominent than those on the external site).

            Alternatively, click on the ">>" icon to the right of a result entry.

            • So you're complaining that the ads on Google's search page are more prominent then the ads in a thumbnail? How is that comparable to your "showing google with an add on top" example from above? Regardless of the content of the story, you'd find something to complain about, wouldn't you?
              • I'm not complaining, I like the thumbnails. But they do constitute exactly the situation you asked me to demonstrate :
                1) they're showing the site's content, often with the sites' advertisements downplayed
                2) google's ads, by contrast, are superimposed on that

    • This isn't why they're doing it. It's an issue of security, not protecting revenue by blocking sites from injecting their own ads into a framed google...

  • use the APIs (Score:5, Insightful)

    by Gravis Zero ( 934156 ) on Sunday October 23, 2011 @03:54PM (#37811950)

    Google has lots of APIs to let you do most anything. If you need to embed an entire page from google then you are doing it wrong. This is a security issue and frankly I'm glad they are acting responsible.

    DOING IT WRONG:

    I am designing a web site and I wish to make extensive use of google.com via iframing.

    • Well, yeah, but some of their APIs are "doing it wrong." Just one example (one that recently burned us): the Google Image Charts API has a neat feature that allows you to fetch the image data to construct an image map of a chart. [google.com] Just append "&chof=json" to any image request and viola! a nice, handy JSON object.

      Except... wait a second! That's totally useless! Why? Because there's no way to actually fetch the JSON object. If you put the URL as the SRC attribute of a script block, it doesn't return

      • What's wrong with writing the proxy, as you suggested? Is it that you'd run into rate limits per IP address that are far too low for a site that gets as much traffic as you reasonably plan to get?
        • Is it that you'd run into rate limits per IP address that are far too low for a site that gets as much traffic as you reasonably plan to get?

          This, plus the concern that we might be violating Google's ToS by using one (they can be very picky about that kind of thing). We don't want to run afoul of the Goog.

          • I see a web API that uses JSON (as opposed to JSONP) as an implicit statement that the API is intended for server-to-server communication, as opposed to communication directly with a user agent. If Google disagrees, consider it the same as discontinuing the service, which I'm pretty sure the TOS says Google can do at any time for any reason. If you think this is something Google is likely to disable for you specifically before it discontinues the service for the world, is it that the API allows the server t
  • The fundamental problem here is that google's services are ones you'd expect a government to run. But of course, google is not the government and the free market model in which google operates does not force them to work as a government. In other words, they do not need to serve the needs of all of their clients, but instead, to make a profit, they need to serve the needs of most of their clients. And that's the fundamental problem, and it isn't going away until either the government takes over google, spec

    • So you are proposing government mandated elimination of security measures? Do you by chance make a living by phishing?
    • ...what google services are ones you would expect a government to run? I can't think of a single one.

  • by kikito ( 971480 ) on Sunday October 23, 2011 @05:08PM (#37812424) Homepage

    You can ask them to give you your money back if you are not satisfied.

  • I found it interesting a couple months back when YouTube changed to using iframes by default for their embed code.

    You can check 'use old embed code' to use the original object code, but I haven't seen anyone do this since they made the change.

    I was massively surprised when they made this move because of the security side of things; I'm completely unsurprised that they're blocking iframes, but I'm just as surprised they're using them by default in Youtube.

  • I'm not a Web standards maven, but I thought that whereever iframes originally came from, they were now a completely legitimate part of the W3C HTML standard. If so, then they ought to work with anything. The description in the HTML 4.01 standard seems to be here [w3.org], and as a non-language-lawyer it seems to me that it is supposed to work unless your "user agent" (browser) does not support frames.

    If Google is intentionally doing something makes properly formed, Web-standard HTML not work properly, then shame on

    • It's standard HTML to use IFrames on a page. It's also standard to be able to flag a page with "don't load me in an IFrame." Google is raising that flag.
    • by ace123 ( 758107 )

      Yes, and the original standard allowed any site to frame any other site and access any data from it... This isn't 1999, and you shouldn't be quoting a 12-year-old spec to talk about security issues that weren't even known at the time. Read the HTML5 spec and maybe you will start to see just how many nuances there are in keeping things working while having security on top. Not even the HTML5 spec explains all the complicated shit that browsers have to do... Mozilla's documentation is the best resource for th

  • by Pinky3 ( 22411 )

    When translating from Chinese to English at http://www.mdbg.net/chindict/chindict.php?page=translate [mdbg.net] , the explanation is money.

    October 14, 2011

    Please note: This only affects the translation of text from Chinese to English and vice versa. The functionality to look up individual words or the dictionary definitions of any Chinese word in a text remains unchanged!

    The translation page of this website uses (now and before) Google Translate to perform text translation. Google recently changed their previously fre

  • Stop misquoting. These are hugely different slogans. A non-evil person can do evil, and it does not make him evil.
  • at school, they proxy through EMBC, who block stuff. If they want to block something themselves, at one time they had an inhouse smoothwall (dansguardian/squid) server, but they now block it by using the remote administration tool, by looking at the window title. eg notdoppler.com, which is unblocked at school, is closed automatically when a window with 'notdoppler' in it opens. I used to have a HTML page in my documents with 2 frames, a 1 pixel blank one, and Google. Now since google blocks frames (it seem
  • I hate it when websites filter by referrer and claim you are stealing their bandwidth. Really? It's just a hyperlink. If you're going to complain don't put it on the web! I use a Firefox add-on to spoof the referrer, to the wikipedia article on referrer spoofing, and sometimes sites claim I'm stealing their bandwidth, and recaptcha doesn't work, but luckily the extension has an exceptions list

You know you've landed gear-up when it takes full power to taxi.

Working...