Live data from Hacker News

37k Chrome users downloaded a fake Adblock Plus extension

engadget.com

11–20 of 42 posts

Re: 37k Chrome users downloaded a fake Adblock Plus extension

#11
post #2

Extensions are the new "Let's play find the download button on a webpage" that's been around for years. [1] So many users download replicas of uBlock and find it hard to install the original uBlock Origin extension. Countless times have I had to send them direct link to Chrome's extension site just to make sure they're installing the right one. This is the case especially as the genuine extension in this case has no…

>This is the case especially as the genuine extension in this case has no direct author website and instead lists a repo on Github

It's the other way round for me. I only install an extension if I find the github (or similar) repo with sufficient activity, stars or whatever. I would even sometimes use google search with the site:github.com string when looking for extensions or android apps. It would be nice if the chrome store and even android play store had a foss tick box.

Re: 37k Chrome users downloaded a fake Adblock Plus extension

#13
post #2

Extensions are the new "Let's play find the download button on a webpage" that's been around for years. [1] So many users download replicas of uBlock and find it hard to install the original uBlock Origin extension. Countless times have I had to send them direct link to Chrome's extension site just to make sure they're installing the right one. This is the case especially as the genuine extension in this case has no…

>This is the case especially as the genuine extension in this case has no direct author website and instead lists a repo on Github It's the other way round for me. I only install an extension if I find the github (or similar) repo with sufficient activity, stars or whatever. I would even sometimes use google search with the site:github.com string when looking for extensions or android apps. It would be nice if the ch…

Ordinarily, people might find seeing the repository straight-up too jarring. For people who aren't in the IT world, I'm not sure that seeing Github will be some definitive proof that an extension is legit.

Re: 37k Chrome users downloaded a fake Adblock Plus extension

#14

Earlier quoted context omitted.

>This is the case especially as the genuine extension in this case has no direct author website and instead lists a repo on Github It's the other way round for me. I only install an extension if I find the github (or similar) repo with sufficient activity, stars or whatever. I would even sometimes use google search with the site:github.com string when looking for extensions or android apps. It would be nice if the ch…

Ordinarily, people might find seeing the repository straight-up too jarring. For people who aren't in the IT world, I'm not sure that seeing Github will be some definitive proof that an extension is legit.

Furthermore, it is only definitive until it isn't. If we trained users to look for the github page, we'd have forked projects that point to the compromised extension, fake github clones that look like the project, fraudulent likes, and so forth.

Re: 37k Chrome users downloaded a fake Adblock Plus extension

#15

Earlier quoted context omitted.

>This is the case especially as the genuine extension in this case has no direct author website and instead lists a repo on Github It's the other way round for me. I only install an extension if I find the github (or similar) repo with sufficient activity, stars or whatever. I would even sometimes use google search with the site:github.com string when looking for extensions or android apps. It would be nice if the ch…

Ordinarily, people might find seeing the repository straight-up too jarring. For people who aren't in the IT world, I'm not sure that seeing Github will be some definitive proof that an extension is legit.

Even for people who are that isn't really "definitive proof" of anything.

Re: 37k Chrome users downloaded a fake Adblock Plus extension

#16
post #2

Extensions are the new "Let's play find the download button on a webpage" that's been around for years. [1] So many users download replicas of uBlock and find it hard to install the original uBlock Origin extension. Countless times have I had to send them direct link to Chrome's extension site just to make sure they're installing the right one. This is the case especially as the genuine extension in this case has no…

I had the exact same problem re: uBlock Origin. I even set up a quick site[1] a couple referrals ago just so I could have a place to easily point someone to.

[1] https://getublock.com/

Re: 37k Chrome users downloaded a fake Adblock Plus extension

#17
post #4

What are Google's rules about names? Only difference I can see here is the fake one is called "AdBlock" and the real one "Adblock". Is changing the case of one letter enough to get an extension into the Chrome store? Or even worse are overlapping names allowed?

The fake one is in the "Apps" section and the real one is in the "Extensions" section. Since apps aren't as popular overall as extensions, it's easier to game that section to get to the top.

Re: 37k Chrome users downloaded a fake Adblock Plus extension

#18
post #16
post #2

Extensions are the new "Let's play find the download button on a webpage" that's been around for years. [1] So many users download replicas of uBlock and find it hard to install the original uBlock Origin extension. Countless times have I had to send them direct link to Chrome's extension site just to make sure they're installing the right one. This is the case especially as the genuine extension in this case has no…

I had the exact same problem re: uBlock Origin. I even set up a quick site[1] a couple referrals ago just so I could have a place to easily point someone to. [1] https://getublock.com/

You could do a little bit of work to automatically select the right browser based on user-agent, and just display one button prominently.

Re: 37k Chrome users downloaded a fake Adblock Plus extension

#19
This is, unfortunately, remarkably common. It only received a lot of attention here because it pretended to be a well-known extension: The Web Store is full of extensions which hijack your start page and search provider and have full access to all of your web content. They're often installed via pages through malicious ads which state that you must accept Chrome's install extension request to continue web browsing and use a variety of JavaScript-based tricks to keep you on the page until you do. (The other thing that occasionally gets mentioned: Extensions get bought out so that adware and spyware is automatically pushed down to Chrome users silently.)

Many times, I've reported malicious extensions I've found on user's PCs, and months later they are still alive and well on the Web Store. Google has not taken significant steps to vet browser extensions despite the massive amount of access to your personal data they have, particularly if they use permissions like accessing the content of pages you're on.

Microsoft appears to only permit Edge extensions on a case-by-case, human-vetted basis. I strongly recommend instructing lay users to use Edge over Chrome, and those who insist on Chrome should have --no-extensions added to their shortcuts to ensure Google's extension interface is wholly disabled. (At the office, I use a group policy to block all extensions on all Chrome installs network-wide. Google provides surprisingly decent tools to do this.)

Unfortunately, while Chrome regularly brags about their security measures, it does very little when they permit (and distribute) malicious extensions in their store with permissions to do whatever they want with user data. Their Pwn2Own records, their bug bounties, it's all irrelevant while they don't consider this a serious issue. It is akin to bragging about how good your deadbolt is while leaving the door wide open.

Post reply on HN