Sundar Pichai says DOJ demands are a “de facto” spin-off of Google search

The Department of Justice (DOJ) rested its case in Google’s search remedy trial earlier this week, giving Google a chance to push back on the government’s attempt to break up the search giant. Today is arguably Google’s best chance to make the case that it should not be harshly penalized in the ongoing search antitrust case, with CEO Sundar Pichai taking the stand.

Pichai attempted to explain why Google isn’t abusing its market position and why the DOJ’s proposed remedies are too extreme. The issue of Chrome divestment came up, but Google’s team also focused intensely on the potential effects of the DOJ’s data remedies, which could force Google to share its search index and technology with other firms.

A de facto spin-off

Pichai, who chose to stand while giving testimony, took issue with the government’s proposal to force Google to license search technology to other companies. The DOJ claims that Google’s status as a monopolist has resulted in it accumulating a huge volume of user data on search behavior. Plus, its significant technological lead means its index of the web is much more robust than competing services.

If the market is going to be rebalanced, the DOJ believes Google must be forced to license this data. Google has derisively referred to this as “white labeling” Google search.

According to Bloomberg, Pichai used even harsher language when discussing these remedies in court. He called this part of the government’s case “so far reaching, so extraordinary” that it would remake Google as a company and lead to numerous unintended consequences. To hear Pichai tell it, forcing Google to license this data for a nominal fee would be a “de facto divestiture of search.”

Giving other companies the option of using Google search index to map the web would make other products better, but Pichai claims they would essentially be able to reverse-engineer everything that makes Google’s platform special. And at that point, Google would need to reevaluate how it approaches innovation. Pichai suggests the data remedies could make it “unviable” for Google to invest in research and development as it has been for the past 20 years.

https://arstechnica.com/gadgets/2025/04/sundar-pichai-says-doj-demands-are-a-de-facto-spin-off-of-google-search/




Google search’s made-up AI explanations for sayings no one ever said, explained

Contrary to the computer science truism of “garbage in, garbage out, Google here is taking in some garbage and spitting out… well, a workable interpretation of garbage, at the very least.

Google’s AI Overview even goes into more detail explaining its thought process. “Lick” here means to “trick or deceive” someone, it says, a bit of a stretch from the dictionary definition of lick as “comprehensively defeat,” but probably close enough for an idiom (and a plausible iteration of the idiom, “Fool me once shame on you, fool me twice, shame on me…”). Google also explains that the badger part of the phrase “likely originates from the historical sport of badger baiting,” a practice I was sure Google was hallucinating until I looked it up and found it was real.

It took me 15 seconds to make up this saying but now I think it kind of works!

Credit: Kyle Orland / Google

It took me 15 seconds to make up this saying but now I think it kind of works! Credit: Kyle Orland / Google

I found plenty of other examples where Google’s AI derived more meaning than the original requester’s gibberish probably deserved. Google interprets the phrase “dream makes the steam” as an almost poetic statement about imagination powering innovation. The line “you can’t humble a tortoise” similarly gets interpreted as a statement about the difficulty of intimidating “someone with a strong, steady, unwavering character (like a tortoise).”

Google also often finds connections that the original nonsense idiom creators likely didn’t intend. For instance, Google could link the made-up idiom “A deft cat always rings the bell” to the real concept of belling the cat. And in attempting to interpret the nonsense phrase “two cats are better than grapes,” the AI Overview correctly notes that grapes can be potentially toxic to cats.

Brimming with confidence

Even when Google’s AI Overview works hard to make the best of a bad prompt, I can still understand why the responses rub a lot of users the wrong way. A lot of the problem, I think, has to do with the LLM’s unearned confident tone, which pretends that any made-up idiom is a common saying with a well-established and authoritative meaning.

https://arstechnica.com/ai/2025/04/google-searchs-made-up-ai-explanations-for-sayings-no-one-ever-said-explained/




Google: Governments are using zero-day hacks more than ever

Governments hacking enterprise

A few years ago, zero-day attacks almost exclusively targeted end users. In 2021, GTIG spotted 95 zero-days, and 71 of them were deployed against user systems like browsers and smartphones. In 2024, 33 of the 75 total vulnerabilities were aimed at enterprise technologies and security systems. At 44 percent of the total, this is the highest share of enterprise focus for zero-days yet.

GTIG says that it detected zero-day attacks targeting 18 different enterprise entities, including Microsoft, Google, and Ivanti. This is slightly lower than the 22 firms targeted by zero-days in 2023, but it’s a big increase compared to just a few years ago, when seven firms were hit with zero-days in 2020.

The nature of these attacks often makes it hard to trace them to the source, but Google says it managed to attribute 34 of the 75 zero-day attacks. The largest single category with 10 detections was traditional state-sponsored espionage, which aims to gather intelligence without a financial motivation. China was the largest single contributor here. GTIG also identified North Korea as the perpetrator in five zero-day attacks, but these campaigns also had a financial motivation (usually stealing crypto).

Credit: Google

That’s already a lot of government-organized hacking, but GTIG also notes that eight of the serious hacks it detected came from commercial surveillance vendors (CSVs), firms that create hacking tools and claim to only do business with governments. So it’s fair to include these with other government hacks. This includes companies like NSO Group and Cellebrite, with the former already subject to US sanctions from its work with adversarial nations.

In all, this adds up to 23 of the 34 attributed attacks coming from governments. There were also a few attacks that didn’t technically originate from governments but still involved espionage activities, suggesting a connection to state actors. Beyond that, Google spotted five non-government financially motivated zero-day campaigns that did not appear to engage in spying.

Google’s security researchers say they expect zero-day attacks to continue increasing over time. These stealthy vulnerabilities can be expensive to obtain or discover, but the lag time before anyone notices the threat can reward hackers with a wealth of information (or money). Google recommends enterprises continue scaling up efforts to detect and block malicious activities, while also designing systems with redundancy and stricter limits on access. As for the average user, well, cross your fingers.

https://arstechnica.com/security/2025/04/google-governments-are-using-zero-day-hacks-more-than-ever/




Oltre 70 vulnerabilità 0-day sfruttate nel 2024: il report di Google


Secondo una recente analisi pubblicata dal Threat Intelligence Group di Google (GTIG), nel 2024 sono state individuate 75 vulnerabilità 0-day sfruttate dagli attaccanti. Anche se si tratta di un calo rispetto alle 98 del 2023, il numero dello scorso anno conferma la tendenza in aumento degli ultimi quattro.

I ricercatori del team di Google hanno diviso le vulnerabilità tra quelle trovate nelle piattaforme per utenti finali e quelle nei software enterprise. Se le piattaforme end-user si confermano di nuovo come le più colpite, negli ultimi cinque anni il GITG ha osservato un aumento significativo di bug presenti nei software enterprise, tanto che nel 2024 hanno raggiunto quasi la metà del totale.

Credits: GTIG

I bug 0-day nelle piattaforme end-user

Nel 2024 il 56% dei bug 0-day individuati è stato trovato nelle piattaforme end-user, ovvero tutti quei software e dispositivi usati quotidianamente dagli utenti. Chrome è stato tra gli obiettivi principali degli exploit, anche se il numero totale di exploit contro browser e dispositivi mobile è sceso drasticamente rispetto al 2023.

I device mobili sono rimasti però il target primario delle catene di attacco che sfruttano più 0-day, ammontando al 90% dei casi registrati. Android è il sistema operativo mobile più colpito, con più della metà delle vulnerabilità che interessavano componenti di terze parti.

Secondo il report di Google, il 2024 ha invece visto un incremento del numero di vulnerabilità 0-day che colpiscono i sistemi operativi desktop. Windows è stato il sistema operativo più colpito, confermando il trend in crescita cominciato nel 2022.

Vulnerabilità nei prodotti enterprise: l’analisi di Google

Dei 33 bug sfruttati presenti nei prodotti enterprise nel 2024, 20 di queste sono state individuate nei prodotti di sicurezza e di rete. Tra gli obiettivi più colpiti dagli exploit Google riporta Ivanti Cloud Services Appliances, Palo Alto Networks PAN_OS, Cisco Adaptive Security Appliance e Ivanti Connect Secure VPN.

“I tool e i dispositivi di sicurezza e di rete sono progettati per collegare sistemi distribuiti, rendendoli obiettivi di alto valore per gli attaccanti che cercano di accedere in maniera efficiente nelle reti enterprise” ha spiegato il GTIG.

Il team di Google ha evidenziato inoltre che i tool EDR non sono in grado di monitorare questi strumenti, lasciandoli scoperti a exploit di vulnerabilità. Stando ai risultati dell’analisi, gli attaccanti tendono a colpire intenzionalmente prodotti che possono fornirgli ampio accesso alle reti con un minor rischio di rilevamento.

Google vulnerabilità

Le vulnerabilità sfruttate e gli attaccanti

Dal report di Google emerge che i tre tipi di vulnerabilità più sfruttati sono lo user-after-free, prevalente da anni, il command injection e il cross-site scripting. Le ultime due tipologie, in particolare, sono state trovate quasi esclusivamente nei software e nelle appliance di sicurezza e di gestione della rete.

Il GTIG sottolinea che questo tipo di bug deriva da errori di sviluppo software che possono essere evitati solo seguendo elevati standard di programmazione, i quali comprendono, tra gli altri, revisioni attente del codice, aggiornamenti delle codebase obsolete e l’uso di librerie aggiornate.

Guardando invece al chi ha sfruttato le vulnerabilità, la maggior parte degli exploit è stata effettuata da gruppi affiliati ai governi, per lo più legati alla Cina. A seguire troviamo i vendor di software commerciali di sorveglianza e gruppi affiliati a governi e non spinti da motivazioni finanziarie.

Credits: GTIG

“Difendersi dagli exploit 0-day rimane una gara di strategia e prioritizzazione. Non solo le vulnerabilità 0-day stanno diventando più facili da individuare, ma gli attaccanti che usano nuovi tipi di tecnologia possono mettere in difficoltà i fornitori meno esperti” avverte il GTIG.

Il team di Google prevede che il numero di exploit che coinvolge vulnerabilità 0-day continuerà a crescere, poiché questi bug colpiscono prodotti e piattaforme di grande interesse per gli attaccanti. Le big tech, in particolare, rimarranno gli obiettivi preferiti del cybercrimine, vista l’ampia diffusione dei loro prodotti.

Oltre a seguire le buone pratiche di sicurezza per lo sviluppo del codice, i vendor dovrebbero includere i principi zero-trust nelle loro architettura, limitando i permessi di accesso al minimo. Quando possibile, è opportuno usare strumenti per il monitoraggio continuo dei software e segmentare la rete per limitare i danni derivanti da un attacco.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2025/04/29/oltre-70-vulnerabilita-0-day-sfruttate-nel-2024-il-report-di-google/?utm_source=rss&utm_medium=rss&utm_campaign=oltre-70-vulnerabilita-0-day-sfruttate-nel-2024-il-report-di-google




ChatGPT goes shopping with new product-browsing feature

On Thursday, OpenAI announced the addition of shopping features to ChatGPT Search. The new feature allows users to search for products and purchase them through merchant websites after being redirected from the ChatGPT interface. Product placement is not sponsored, and the update affects all users, regardless of whether they’ve signed in to an account.

Adam Fry, ChatGPT search product lead at OpenAI, showed Ars Technica’s sister site Wired how the new shopping system works during a demonstration. Users researching products like espresso machines or office chairs receive recommendations based on their stated preferences, stored memories, and product reviews from around the web.

According to Wired, the shopping experience in ChatGPT resembles Google Shopping. When users click on a product image, the interface displays multiple retailers like Amazon and Walmart on the right side of the screen, with buttons to complete purchases. OpenAI is currently experimenting with categories that include electronics, fashion, home goods, and beauty products.

Product reviews shown in ChatGPT come from various online sources, including publishers and user forums like Reddit. Users can instruct ChatGPT to prioritize which review sources to use when creating product recommendations.

An example of the ChatGPT shopping experience provided by OpenAI.

An example of the ChatGPT shopping experience provided by OpenAI. Credit: OpenAI

Unlike Google’s algorithm-based approach to product recommendations, ChatGPT reportedly attempts to understand product reviews and user preferences in a more conversational manner.  If someone mentions they prefer black clothing from specific retailers in a chat, the system incorporates those preferences in future shopping recommendations.

https://arstechnica.com/ai/2025/04/chatgpt-goes-shopping-with-new-product-browsing-feature/




Google announces 1st and 2nd gen Nest Thermostats will lose support in October 2025

Google’s oldest smart thermostats have an expiration date. The company has announced that the first and second generation Nest Learning Thermostats will lose support in October 2025, disabling most of the connected features. Google is offering some compensation for anyone still using these devices, but there’s no Google upgrade for European users. Google is also discontinuing its only European model, and it’s not planning to release another.

Both affected North American thermostats predate Google’s ownership of the company, which it acquired in 2014. Nest released the original Learning Thermostat to almost universal praise in 2011, with the sequel arriving a year later. Google’s second-gen Euro unit launched in 2014. Since launch, all these devices have been getting regular software updates and have migrated across multiple app redesigns. However, all good things must come to an end.

As Google points out, these products have had a long life, and they’re not being rendered totally inoperable. Come October 25, 2025, these devices will no longer receive software updates or connect to Google’s cloud services. That means you won’t be able to control them from the Google Home app or via Assistant (or more likely Gemini by that point). The devices will still work as a regular dumb thermostat to control temperature, and scheduling will remain accessible from the thermostat’s screen.

If you have one of these units, Google will be reaching out via email with some deals to soften the blow. In the US, owners can get a $130 discount if they upgrade to the fourth-gen Nest, which was released just last year for $280. In Canada, the discount will be CA$160.

https://arstechnica.com/gadgets/2025/04/google-ending-support-for-older-nest-thermostats-will-stop-selling-nests-in-europe/




Perplexity will come to Moto phones after exec testified Google limited access

Shevelenko was also asked about Chrome, which the DOJ would like to force Google to sell. Like an OpenAI executive said on Monday, Shevelenko confirmed Perplexity would be interested in buying the browser from Google.

Motorola has all the AI

There were some vague allusions during the trial that Perplexity would come to Motorola phones this year, but we didn’t know just how soon that was. With the announcement of its 2025 Razr devices, Moto has confirmed a much more expansive set of AI features. Parts of the Motorola AI experience are powered by Gemini, Copilot, Meta, and yes, Perplexity.

While Gemini gets top billing as the default assistant app, other firms have wormed their way into different parts of the software. Perplexity’s app will be preloaded, and anyone who buys the new Razrs. Owners will also get three free months of Perplexity Pro. This is the first time Perplexity has had a smartphone distribution deal, but it won’t be shown prominently on the phone. When you start a Motorola device, it will still look like a Google playground.

While it’s not the default assistant, Perplexity is integrated into the Moto AI platform. The new Razrs will proactively suggest you perform an AI search when accessing certain features like the calendar or browsing the web under the banner “Explore with Perplexity.” The Perplexity app has also been optimized to work with the external screen on Motorola’s foldables.

Moto AI also has elements powered by other AI systems. For example, Microsoft Copilot will appear in Moto AI with an “Ask Copilot” option. And Meta’s Llama model powers a Moto AI feature called Catch Me Up, which summarizes notifications from select apps.

It’s unclear why Motorola leaned on four different AI providers for a single phone. It probably helps that all these companies are desperate to entice users to bulk up their market share. Perplexity confirmed that no money changed hands in this deal—it’s on Moto phones to acquire more users. That might be tough with Gemini getting priority placement, though.

https://arstechnica.com/gadgets/2025/04/perplexity-will-come-to-moto-phones-after-exec-testified-google-blocked-access/




Stop alla Privacy Sandbox di Google


A sei anni dal primo annuncio, Google ha deciso di fare un (grosso) passo indietro sulla sua Privacy Sandbox e di tornare all’uso dei cookie di terze parti.

In un post sul proprio blog la compagnia ha spiegato che il cambio di direzione è dovuto alle “visioni contrastanti su cambiamenti che possono impattare la disponibilità dei cookie di terze parti“, facendo riferimento a sviluppatori, enti regolatori e i soggetti dell’industria pubblicitaria che si sono fortemente opposti al progetto fin dall’inizio.

“L’adozione di tecnologie che migliorano la privacy ha subito un’accelerazione, sono emerse nuove opportunità per salvaguardare e proteggere le esperienze di navigazione delle persone con l’intelligenza artificiale e il panorama normativo mondiale si è notevolmente evoluto. Tenendo conto di tutti questi fattori, abbiamo deciso di mantenere il nostro attuale approccio per offrire agli utenti la possibilità di scegliere i cookie di terze parti in Chrome e non introdurremo un nuovo prompt standalone per i cookie di terze parti” ha affermato Anthony Chavez, VP, Privacy Sandbox di Google.

Privacy Sandbox Google

Con Privacy Sandbox l’obiettivo di Google era spostare la profilazione utente dai cookie di terze parti al browser per ridurre il numero di informazioni condivise con compagnie terze. Gli utenti vengono comunque tracciati, ma i loro dati sono anonimizzati e riguardano solo le categorie di interesse e aree tematiche specificate dal singolo utente, non il dettaglio della navigazione.

Attivando questa funzionalità gli utenti possono scegliere quali interessi condividere con le compagnie terze e quali no, in modo da ricevere gli annunci più rilevanti.

Molti grandi nomi del mondo tech avevano avanzato le loro preoccupazioni e i loro dubbi per questa scelta, chi sostenendo che non fosse un aiuto effettivo per la privacy, chi sollevando il problema della generazione degli argomenti e della classificazione dei siti web; inoltre, la scelta di Google rischiava di accentrare ancora di più il controllo del web sul colosso di Mountain View.

Insomma, quella che secondo Google sarebbe dovuta essere la rivoluzione della privacy sul web, è stata relegata a una mera opzione: gli utenti possono infatti scegliere se usare o meno Privacy Sandbox dalle impostazioni di sicurezza di Chrome.

Google ha specificato che continuerà a migliorare la protezione dal tracking per la modalità incognito di Chrome e che prevede di lanciare IP Protection nel terzo trimestre del 2025. La feature promette di ridurre il rischio di tracciamento nascosto e bloccare la condivisione dell’IP dell’utente con terze parti.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2025/04/23/stop-alla-privacy-sandbox-di-google/?utm_source=rss&utm_medium=rss&utm_campaign=stop-alla-privacy-sandbox-di-google




OpenAI wants to buy Chrome and make it an “AI-first” experience

According to Turley, OpenAI would throw its proverbial hat in the ring if Google had to sell. When asked if OpenAI would want Chrome, he was unequivocal. “Yes, we would, as would many other parties,” Turley said.

OpenAI has reportedly considered building its own Chromium-based browser to compete with Chrome. Several months ago, the company hired former Google developers Ben Goodger and Darin Fisher, both of whom worked to bring Chrome to market.

Close-up of Google Chrome Web Browser web page on the web browser. Chrome is widely used web browser developed by Google.

Credit: Getty Images

It’s not hard to see why OpenAI might want a browser, particularly Chrome with its 4 billion users and 67 percent market share. Chrome would instantly give OpenAI a massive install base of users who have been incentivized to use Google services. If OpenAI were running the show, you can bet ChatGPT would be integrated throughout the experience—Turley said as much, predicting an “AI-first” experience. The user data flowing to the owner of Chrome could also be invaluable in training agentic AI models that can operate browsers on the user’s behalf.

Interestingly, there’s so much discussion about who should buy Chrome, but relatively little about spinning off Chrome into an independent company. Google has contended that Chrome can’t survive on its own. However, the existence of Google’s multibillion-dollar search placement deals, which the DOJ wants to end, suggests otherwise. Regardless, if Google has to sell, and OpenAI has the cash, we might get the proposed “AI-first” browsing experience.

https://arstechnica.com/ai/2025/04/chatgpt-head-tells-court-openai-is-interested-in-buying-chrome/




Google won’t ditch third-party cookies in Chrome after all

Maintaining the status quo

While Google’s sandbox project is looking more directionless today, it is not completely ending the initiative. The team still plans to deploy promised improvements in Chrome’s Incognito Mode, which has been re-architected to preserve user privacy after numerous complaints. Incognito Mode blocks all third-party cookies, and later this year, it will gain IP protection, which masks a user’s IP address to protect against cross-site tracking.

[embedded content]

What is Topics?

Chavez admits that this change will mean Google’s Privacy Sandbox APIs will have a “different role to play” in the market. That’s a kind way to put it. Google will continue developing these tools and will work with industry partners to find a path forward in the coming months. The company still hopes to see adoption of the Privacy Sandbox increase, but the industry is unlikely to give up on cookies voluntarily.

While Google focuses on how ad privacy has improved since it began working on the Privacy Sandbox, the changes in Google’s legal exposure are probably more relevant. Since launching the program, Google has lost three antitrust cases, two of which are relevant here: the search case currently in the remedy phase and the newly decided ad tech case. As the government begins arguing that Chrome gives Google too much power, it would be a bad look to force a realignment of the advertising industry using the dominance of Chrome.

In some ways, this is a loss—tracking cookies are undeniably terrible, and Google’s proposed alternative is better for privacy, at least on paper. However, universal adoption of the Privacy Sandbox could also give Google more power than it already has, and the supposed privacy advantages may never have fully materialized as Google continues to seek higher revenue.

https://arstechnica.com/gadgets/2025/04/google-wont-ditch-third-party-cookies-in-chrome-after-all/