Live data from Hacker News

Mozilla stops distribution of WOT addon

news.ycombinator.com

51–60 of 84 posts

Re: Mozilla stops distribution of WOT addon

#51
post #17
post #15

Here is the blog entry of the Journalist Mike Kuketz, explaining in detail how he uncovered the fraud, unfortunately only in German. This includes samples of the questionable GET and POST Requests, as well as a link to a commit to the WOT sources on GitHub, which introduced the necessary changes ... https://www.kuketz-blog.de/wot-addon-wie-ein-browser-addon-s... The commit referenced in the blog: https://github.com/m…

And by the way, he also suggests in his blog post that Ghostery and Adblock Plus might as well sell browser histories as WOT does. There might be even more.

Ghostery allows you to OPT IN to sending your browsing data [1], which may be sold as part of services offered by their parent company to improve ad ROI for their customers. They also tell you that they're collecting the request data [2].

I think knowingly sharing your data (with a positive affirmation) is significantly different than having your data collected and sold without your knowledge

[1] http://imgur.com/a/ugglB

[2] https://www.ghostery.com/support/faq/ghostery-add-on/What-da...

Re: Mozilla stops distribution of WOT addon

#52
post #26

Earlier quoted context omitted.

No, the only thing that will work is to pummel guilty companies into the ground with fines. But you can bet GooBookSoft will lobby against that like their lives depended on abusing customer data. And they do depend on it.

Nope. I'm going for FaceGooSoft or FaceGleSoft. First writes better. Second sounds better. But you can have the copyrite because all are fun.

>Nope. I'm going for FaceGooSoft or FaceGleSoft. First writes better. Second sounds better.

With much regret, MiFaceGoo is rarely appropriate in the professional world.

Re: Mozilla stops distribution of WOT addon

#55
post #30
post #19

So basically I should uninstall it, correct? Does anyone know of anything to replace it?

I think you can use their bookmarklet, but personally I don't see any benefits as somewhat similar Google Safe Browsing service is internally used by all major browsers.

it was decently accurate at judging whether a random website contained "legal" downloads of books

Re: Mozilla stops distribution of WOT addon

#56
post #15

Here is the blog entry of the Journalist Mike Kuketz, explaining in detail how he uncovered the fraud, unfortunately only in German. This includes samples of the questionable GET and POST Requests, as well as a link to a commit to the WOT sources on GitHub, which introduced the necessary changes ... https://www.kuketz-blog.de/wot-addon-wie-ein-browser-addon-s... The commit referenced in the blog: https://github.com/m…

> The commit referenced in the blog

Interesting, the date of the commit is April 20, 2015.

I did comment on April 16, 2015 about how the WOT extension could record a user's browsing history[1], so it does look like they were doing this before this specific commit.

Edit: ah never mind, my comment was for the Chrome version of the extension while the commit is for the Firefox extension. So they have been doing it since longer for the Chrome extension.

[1] https://github.com/gorhill/uBlock/issues/65#issuecomment-937...

Re: Mozilla stops distribution of WOT addon

#57
post #54

Those stories about Adblockers selling browsing history and private data, is just a lame intent to make people stop using adblockers and make us digest all that advertising crap.... Watch an ad is our choice....

While advertisers would benefit if people are afraid to use adblockers, it doesn't necessarily mean that they did it themselves.

There was clearly a market for user browsing data (since WOT was able to find customers), so if WOT is shut down, more will pop up. And the apps that mine user data don't need to be adblockers, that's just the reason they give users to install the extension.

Re: Mozilla stops distribution of WOT addon

#58
post #13

Such innovation .. pure evil. What's the takeaway? Not to install any browser add-on? On a serious note, I guess that it might be safer to to run a browser in a Docker container and use one instance to browser only site. The question is that how feasible it would be?

You can use Chrome profiles to create private "sandbox" for certain extensions. Put for example webdev related to extensions in separate profile, which you don't use for daily surfing.

You can also use Lynx if you want to go Full Stallman.

Re: Mozilla stops distribution of WOT addon

#59
post #5

Web of Trust is a browser extension that claims 140 million installs. The marketing language on the home page [1] is all about how the extension will help users decide which websites to trust. Their privacy statement [2] includes a section that describes "Browsing usage, including visited web pages, clickstream data or web address accessed;" as one of the categories of "non-personal information" that they may disclos…

Do you know what would be a great way to prevent this? Every data send by an extension should be user viewable. Here's the json file (or maybe something better) that we are posting, press Agree to send it

They would just start obfuscating the data (with ciphers, word replacements, encoding, minification, etc.)

They'd then claim it was for your security/privacy/protection. You know, like how Microsoft encrypts your Windows 10 usage data it sends them.

At least you could use the presence of such obfuscation as a sign there's probably something bad afoot. Presuming only a tiny number of extensions try to encode the data they send.

Re: Mozilla stops distribution of WOT addon

#60
Good riddance, a vile site full of self appointed internet police with handpainted badges with a sense of importance

They falsely flagged a a website I ran a while back (social media management tools via approved APIs) as: pharmacy, scam and spam. Due to this mails from our server were not getting through.

I tried contacting saying they are all false. They updated saying we sold facebook likes and fake followers. We did nothing of the sort and did nothing at all with facebook anyways. I tried contacting again to which I was told we were a scam because the domain has privacy enabled nor had my personal name and address on the site. I value my privacy and do not have my full name and certainly not my address anywhere online.

I asked our customers via a support forum post if they could post an honest review of our site and service which did nothing to the score - it seems a couple of users have all the power. We then got branded as spammers for trying to manipulate our rating (with actual reviews, but as it was against the power users (who had never used our product) we were in the wrong.

Post reply on HN