Live data from Hacker News

Viewing profile — palant

palant

HN member
Joined
Mon, Nov 07, 2016, 2:56 PM UTC
HN karma
525
Public activity
194 items

About palant

I am Wladimir Palant, a security researcher. My blog: https://palant.info/

Recent public activity

  1. comment
    Comment #42783796

    Note : I am the author of this article. Apples and oranges. Android is supposed to isolate apps from each other (yes, theory). So a malicious app should only be able to steal data …

  2. comment
    Comment #42001289

    Note : I am the author of this article. MV3 makes it considerably harder to introduce a security vulnerability, but it doesn’t really help with outright malicious extensions. In th…

  3. comment
    Comment #41999430

    Note : I am the author of this article. That question is answered, in the last section of the article. And: yes, they are selling it, as they admit in the privacy policy.

  4. comment
    Comment #41847440

    As I said: “according to many credible witnesses, not all of them anonymous. Heck, some of it is even on video.”

  5. comment
    Comment #41846409

    What is there to be gained you ask? Well, there is currently a creep in a position of power at FSF who is actively making women and other people feel unwelcome, effectively pushing…

  6. comment
    Comment #41845882

    [flagged]

  7. comment
    Comment #37313806

    As I said, one device is enough.

  8. comment
    Comment #37313119

    Note : I am the author of this article. They have at least one device with an unencrypted copy of their data, likely two or more. They only need this passphrase to set up sync. If …

  9. comment
    Comment #37313082

    Note : I am the author of this article. Yes, they will probably ask Facebook then. Or check your web search history. There is more than one source for them to draw from. But you ca…

  10. comment
    Comment #37312995

    Note : I am the author of this article. Firefox Sync encrypts all data on the client side before sending it. Chrome Sync can do the same if you know which settings to use. 1Passwor…

  11. comment
    Comment #37312890

    Funny thing is: declarative access to websites still allows for plenty of mischief if one wanted to do it. I’ve actually seen malicious extensions abuse that. Browsers might have t…

  12. comment
    Comment #37312822

    Note : I am the author of this article. Yes, they fixed this particular issue (and a few more), the article mentions it. But the update I published today explains why Chrome Sync i…

  13. comment
    Comment #37312475

    Note : I am the author of this article. Every ad blocker gets full and complete access to all your data. It needs that kind of access in order to … tada … remove ads. It’s really s…

  14. comment
    Comment #37311908

    Note : I am the author of this article. They fixed this particular issue (and a few more), the article mentions it. But the update I published today explains why Chrome Sync is sti…

  15. comment
    Comment #36244134

    Note : I’m the author of this article. I’m fairly certain that these users didn’t leave it at reviews. There is a “Report abuse” form which one can use and which was certainly used…

  16. comment
    Comment #36244069

    It wasn’t really intended. I originally looked at ad blockers since I know that most of them are shady, that’s how I immediately found the PCVARK ad blockers. I stumbled upon these…

  17. comment
    Comment #36241592

    Note : I am the author of this article. Yes, Chrome uses Safe Browsing to flag malicious extensions. But they seem to use it very sparingly for some reason.

  18. comment
    Comment #36241558

    Note : I am the author of this article. Yes, Mozilla doesn’t publish the source code. Back when I was reviewing add-ons there (a long time ago), I did compile the supplied source a…

  19. comment
    Comment #36241149

    Note : I am the author of this article. I have no idea what it takes to get “featured” but having seen how pretty much any extension gets this tag, including plenty of malicious on…

  20. comment
    Comment #36212729

    Unfortunately, an extension in use is expected to behave very differently from one that was merely installed. That’s the crux with observing software in sandboxes in order to deter…

  21. comment
    Comment #36189464

    Note : I’m the author of this article. We aren’t talking about breaking out of the sandbox here, the extension sandbox stays intact. The problem is that this sandbox has plenty of …

  22. comment
    Comment #36170116

    As I said, outright malicious extensions will always find a way. I now discovered a newer variant of these extensions, this time using Manifest V3. And they still run arbitrary cod…

  23. comment
    Comment #36153562

    Yes, much better to let 55 million users blame the browser for redirecting search queries, excessive ads, erratic behavior and data leaks. :-) Funny thing is: I can imagine Google …

  24. comment
    Comment #36151952

    Back when I reviewed add-ons for Mozilla Add-ons, I did in fact verify that the source code produced the same build result as the extension submitted. Was tricky occasionally but u…

  25. comment
    Comment #36150316

    Note : I am the author of this article. Mozilla and Opera require source code to be uploaded along with the extension, there is some human component involved in the review there. M…