FYI - I had also observed some similar issues which I recently presented at a security conference. (The conference talk happened to be the impetus for Google to fix this stuff when they did.) For my perspective on the issues, please check out my conference slides: http://connect.ncircle.com/t5/VERT-Security-Research-Blog/Ha...