{"id":1481,"date":"2018-12-02T15:09:15","date_gmt":"2018-12-02T20:09:15","guid":{"rendered":"http:\/\/blogs.iit.edu\/itm_loopback\/?p=1481"},"modified":"2019-01-14T15:13:33","modified_gmt":"2019-01-14T20:13:33","slug":"hotel-business-centers-can-steal-your-life","status":"publish","type":"post","link":"https:\/\/blogs.iit.edu\/itm_loopback\/2018\/12\/02\/hotel-business-centers-can-steal-your-life\/","title":{"rendered":"Hotel business centers can steal your life"},"content":{"rendered":"<p><strong>Many<\/strong> <strong>of<\/strong> <strong>us<\/strong> <strong>travel<\/strong> <strong>regularly<\/strong> <strong>for<\/strong> <strong>business<\/strong> <strong>or<\/strong> <strong>pleasure<\/strong>, and even though most of us probably haul along our own computer or tablet, occasionally we have to print something. Gee, right there off the hotel lobby is the business center, which today is often equipped with a nice color laser printer. How convenient! And how <em>dangerous<\/em>.<\/p>\n<p>How do we get the document from our device to the printer? Most if us would probably think, oh, that\u2019s easy. I\u2019ll just pop it into Google Drive, or One Drive, or Apple Cloud. Then I\u2019ll log in with the browser on the office center machine, print my stuff, and I\u2019m done! I just did this at the hotel I\u2019m staying at in Florida. Logged into the system, running Windows 10, and brought up Google Chrome. I looked at the photo icon on the upper right corner of the browser, and I see a picture of one of my colleagues\u2026he never logged off from using it the day before! It turns out that closing Chrome <em>does<\/em> <em>not<\/em> log you out, even though logic says it should. I logged him off, logged in to Google, did my printing from content on Google Drive, and logged off.<\/p>\n<p>Because neither Google nor Microsoft requires two-factor authentication, leaving an account logged in will allow the next system user to change your password. Once that\u2019s done, everything in that account is theirs and not yours. Wow. <u>Scary<\/u>. Rebooting <i>might<\/i>\u00a0fix it, but in normal operation, these systems hardly ever get rebooted.<\/p>\n<p>Once logged off, I clicked the login icon on the upper right corner of the default Google Search screen. This took me to a list of the users that had previously logged into Google using this browser listing their name, their email address, and even their photo if their account had one linked to it. And there I was, as well as my colleague. At the bottom of the screen was a \u201cremove login\u201d selection. Clicking it placed an X next to each user on the list, and clicking the X removed that user from the list. Does it remove it from the system as well, or just from this list? I don\u2019t know, and haven\u2019t yet had time to research it.<\/p>\n<p>I then moved to the machine next to this which I had used the day before. I looked at the list of Google users in Chrome, and there I was! I removed my entry and the other 10 on the screen\u2014one at a time, of course\u2014then I closed Chrome and logged out of the system.<\/p>\n<p>I know it seems like a bit much expecting hotels to control this serious vulnerability on their office center system, but frankly most users will never even be aware of the danger, and if the hotels don\u2019t take positive steps to control this it will never happen. I did some quick research to try to find a Chrome plugin to automatically log users out when the browser is closed, and to prevent the user list from being retained, but if there is such a beast, I didn\u2019t find it. Clearly this is a need, and to be perfectly honest, one that the hotels and anyone else providing public access to Google logins on Chrome should expect to pay for. Free business plan: write it. Then write <i>about<\/i> it. Frankly, people are crazy not to protect their users like this.<\/p>\n<p><em>\u2014Ray Trygstad<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Many of us travel regularly for business or pleasure, and even though most of us probably haul along our own computer or tablet, occasionally we have to print something. Gee, right there off the hotel lobby is the business center, which today is often equipped with a nice color laser printer. How convenient! And how [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3869],"tags":[10223,3916,10224,10221,10222,3898],"class_list":["post-1481","post","type-post","status-publish","format-standard","hentry","category-security","tag-chrome","tag-cyber-security","tag-cybersecurity","tag-email","tag-gmail","tag-security-2"],"_links":{"self":[{"href":"https:\/\/blogs.iit.edu\/itm_loopback\/wp-json\/wp\/v2\/posts\/1481","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.iit.edu\/itm_loopback\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.iit.edu\/itm_loopback\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.iit.edu\/itm_loopback\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.iit.edu\/itm_loopback\/wp-json\/wp\/v2\/comments?post=1481"}],"version-history":[{"count":5,"href":"https:\/\/blogs.iit.edu\/itm_loopback\/wp-json\/wp\/v2\/posts\/1481\/revisions"}],"predecessor-version":[{"id":1490,"href":"https:\/\/blogs.iit.edu\/itm_loopback\/wp-json\/wp\/v2\/posts\/1481\/revisions\/1490"}],"wp:attachment":[{"href":"https:\/\/blogs.iit.edu\/itm_loopback\/wp-json\/wp\/v2\/media?parent=1481"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.iit.edu\/itm_loopback\/wp-json\/wp\/v2\/categories?post=1481"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.iit.edu\/itm_loopback\/wp-json\/wp\/v2\/tags?post=1481"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}