Live data from Hacker News

Grammarly shared its tokens with all websites

bugs.chromium.org

61–70 of 176 posts

Re: Grammarly shared its tokens with all websites

#61

I feel like the first thing we should talk about is how this is effectively a keylogger, similar to Windows 10's inking and typing setting, albeit with likely poorer security. Collecting everything you type into a web browser (or MS Office) and sending it to them seems like a really bad idea.

Aren't all password managers keyloggers too?

I personally stay far away from password managers, especially as browser extensions. I'd really recommend everyone look at how many of their Chrome extensions have the permission to "access your data on all websites", and consider whether or not they really trust the companies or individuals who made those extensions with that permission.

It's eye-opening to people when I ask them about an extension they have, say "Honey", and they say they like it because it saves them money. And then I point out it can access everything they do online, and ask them if that's a concern or not.

Re: Grammarly shared its tokens with all websites

#62
post #26
post #25

Earlier quoted context omitted.

This was my experience as well. I don't know how anyone is able to use it; it brought my 2017 MacBook pro to its knees every time I would start writing a HN comment. I uninstalled it after about 5 minutes.

No issues with speed or anything, chromium, linux.

I had no speed issues here, either. Chrome, Windows and OSX.

That said, I removed it because the button in the lower right kept getting in the way of things like resizing the textarea.

Re: Grammarly shared its tokens with all websites

#66

I feel like the first thing we should talk about is how this is effectively a keylogger, similar to Windows 10's inking and typing setting, albeit with likely poorer security. Collecting everything you type into a web browser (or MS Office) and sending it to them seems like a really bad idea.

Aren't all password managers keyloggers too?

There are password managers that don't involve any cloud services.

Re: Grammarly shared its tokens with all websites

#67

Earlier quoted context omitted.

Aren't all password managers keyloggers too?

I personally stay far away from password managers, especially as browser extensions. I'd really recommend everyone look at how many of their Chrome extensions have the permission to "access your data on all websites", and consider whether or not they really trust the companies or individuals who made those extensions with that permission. It's eye-opening to people when I ask them about an extension they have, say "H…

As an open-source extension developer, I wish there was a way to prove that the extension uploaded is generated from a specific git commit. It wouldn't solve everything, but it would make it easier for anyone to audit the code and know that it actually matches the code I've uploaded.

Re: Grammarly shared its tokens with all websites

#68
What's the etiquette for disclosure timeline on something like this? It feels like 99.9999% of end users won't see this public disclosure, and waiting enough time for auto-updates to be applied would be ideal. Public disclosure as soon as the patch is available lets bad actors know about it while the vast majority of users are still vulnerable.

Re: Grammarly shared its tokens with all websites

#69

Earlier quoted context omitted.

One of the reasons I started writing my own editor.

Interesting, how is the progress going so far? I think there is a lot of demand out there for a certain type of editor.

A certain type you say?

Re: Grammarly shared its tokens with all websites

#70
post #36

Earlier quoted context omitted.

May I ask how you're detecting it? If you can't say [or don't want to] for whatever reason that's fine, I'm merely curious is all.

We have a couple different layers we can work with here, both on the computers and the network.

He asked for a specific thing, and you answered with nothing at all.
Post reply on HN