Live data from Hacker News

Mozilla stops distribution of WOT addon

news.ycombinator.com

11–20 of 84 posts

Re: Mozilla stops distribution of WOT addon

#11
This is more or less the same way SimilarWeb collects its data, so I wonder when will they start being treated the same. They operate a number of inhouse extensions and partner with other extension developers to collect the entire click trail of the users. Internal links in your intranet, localhost, "private" google drive links, all is collected and sold. It's beyond me how this shady business is treated as legitimate, including major web and tech publications citing their data reports.

Re: Mozilla stops distribution of WOT addon

#12

I wanted to say: And Google did not removed it. But actually it is also gone in Google extension store. Google also seriously needs to think about security in their Chrome extension store. I've seen more than once ads injected by extensions by the auto update (no real security there). Maybe I've been also tracked in the past. Google needs to actively monitor all extensions for ad injection and tracking code (where ar…

> Google needs to actively monitor all extensions for ad injection and tracking code (where are their AI experts on that?)

All the AI experts in the world won't be able to solve the halting problem. What you're asking for is impossible.

Re: Mozilla stops distribution of WOT addon

#13
Such innovation .. pure evil.

What's the takeaway? Not to install any browser add-on?

On a serious note, I guess that it might be safer to to run a browser in a Docker container and use one instance to browser only site. The question is that how feasible it would be?

Re: Mozilla stops distribution of WOT addon

#14
I came to the conclusion that one should use only addons which are widely used by netsec experts, because audit is a fairly rare thing these days and one has to rely on when somebody sees something suspicious.

Re: Mozilla stops distribution of WOT addon

#15
Here is the blog entry of the Journalist Mike Kuketz, explaining in detail how he uncovered the fraud, unfortunately only in German. This includes samples of the questionable GET and POST Requests, as well as a link to a commit to the WOT sources on GitHub, which introduced the necessary changes ...

https://www.kuketz-blog.de/wot-addon-wie-ein-browser-addon-s...

The commit referenced in the blog:

https://github.com/mywot/firefox-xul/commit/0df107cae8ac1890...

Re: Mozilla stops distribution of WOT addon

#17
post #15

Here is the blog entry of the Journalist Mike Kuketz, explaining in detail how he uncovered the fraud, unfortunately only in German. This includes samples of the questionable GET and POST Requests, as well as a link to a commit to the WOT sources on GitHub, which introduced the necessary changes ... https://www.kuketz-blog.de/wot-addon-wie-ein-browser-addon-s... The commit referenced in the blog: https://github.com/m…

And by the way, he also suggests in his blog post that Ghostery and Adblock Plus might as well sell browser histories as WOT does. There might be even more.

Re: Mozilla stops distribution of WOT addon

#18
post #5

Web of Trust is a browser extension that claims 140 million installs. The marketing language on the home page [1] is all about how the extension will help users decide which websites to trust. Their privacy statement [2] includes a section that describes "Browsing usage, including visited web pages, clickstream data or web address accessed;" as one of the categories of "non-personal information" that they may disclos…

Do you know what would be a great way to prevent this?

Every data send by an extension should be user viewable.

Here's the json file (or maybe something better) that we are posting, press Agree to send it

Post reply on HN