Live data from Hacker News

Grammarly shared its tokens with all websites

bugs.chromium.org

131–140 of 176 posts

Re: Grammarly shared its tokens with all websites

#131

I nearly missed this bit at the bottom: > Grammarly had fixed the issue and released an update to the Chrome Web Store within a few hours, a really impressive response time. Nice to see a company take this kind of thing appropriately seriously (although of course it should never have happened in the first place).

Maybe they knew what they were doing and had a fix tee'd up for when they were found out?

Re: Grammarly shared its tokens with all websites

#132

Earlier quoted context omitted.

Why is this story not bigger news? Grammarly is excreting ads into my eyes before nearly every YouTube video I watch, yet I don't see any mainstream sites covering this.

Totally. Here's some more info on the company. They are located in the Ukraine. http://escadra.com.ua/en/kak-dvoe-kievlyan-sozdali-servis-pr...

Interesting article.... they should have used grammarly to correct a few mistakes :-D

Re: Grammarly shared its tokens with all websites

#133
post #130
post #121

Earlier quoted context omitted.

It doesn’t detect the passive voice, punctuation errors, or tense mismatch. While spelling catches many, it doesn’t catch them all.

I, for one, don’t really care if someone has written to me in the passive voice. Or is changing tense. The message is still received. If it will mean they are more secure that way, then I will allow it.

Ok, but others want to correct those issues,and are specifically asking for ways to do so that don't require sending all typing away to a third party.

Re: Grammarly shared its tokens with all websites

#134

Earlier quoted context omitted.

Why is this story not bigger news? Grammarly is excreting ads into my eyes before nearly every YouTube video I watch, yet I don't see any mainstream sites covering this.

Mostly because cloud-connected keyloggers are mainstream. As I mentioned, Windows does it if you have their "inking and typing" setting enabled. A lot of mobile keyboard apps do it, especially if they say they use the cloud to help correct your typing. Of course, in the case of Microsoft or Google, you presumably either have disabled the setting or you place your trust in their security practices that it is okay, bec…

If it acts like a keylogger its a keylogger.

When people want privacy they will inevitably have to give up usability. I ditched Swiftkey for an open source Android keyboard that doesn't connect online or asks for any permissions. Its CRAP but it doesn't leak.

Re: Grammarly shared its tokens with all websites

#135
post #68

What's the etiquette for disclosure timeline on something like this? It feels like 99.9999% of end users won't see this public disclosure, and waiting enough time for auto-updates to be applied would be ideal. Public disclosure as soon as the patch is available lets bad actors know about it while the vast majority of users are still vulnerable.

The bad actors pay people to find these issues. It's prudent to assume that blackhats know about this already anyway. Thus, it's beneficial to push fixes asap in order to minimize the window for the blackhats.

It's a choice between visible pain and invisible weakness. The early disclosure hurts and amplifies the issue. However, the malicious actors you need to worry about would be glad for every day without disclosure, because every day without disclosure is profit to them.

Re: Grammarly shared its tokens with all websites

#136

I feel like the first thing we should talk about is how this is effectively a keylogger, similar to Windows 10's inking and typing setting, albeit with likely poorer security. Collecting everything you type into a web browser (or MS Office) and sending it to them seems like a really bad idea.

Any difference between that and say fcitx?

Re: Grammarly shared its tokens with all websites

#137
post #134

Earlier quoted context omitted.

Mostly because cloud-connected keyloggers are mainstream. As I mentioned, Windows does it if you have their "inking and typing" setting enabled. A lot of mobile keyboard apps do it, especially if they say they use the cloud to help correct your typing. Of course, in the case of Microsoft or Google, you presumably either have disabled the setting or you place your trust in their security practices that it is okay, bec…

If it acts like a keylogger its a keylogger. When people want privacy they will inevitably have to give up usability. I ditched Swiftkey for an open source Android keyboard that doesn't connect online or asks for any permissions. Its CRAP but it doesn't leak.

Ooh, what keyboard? Does it have gesture typing, and is it better than gboard (Google's own), which is the worst I've ever used?

Re: Grammarly shared its tokens with all websites

#138
post #103

I nearly missed this bit at the bottom: > Grammarly had fixed the issue and released an update to the Chrome Web Store within a few hours, a really impressive response time. Nice to see a company take this kind of thing appropriately seriously (although of course it should never have happened in the first place).

They probably should have waited to let Google know they fixed it though, as Google releases the bug details immediately when a fix is made rather than waiting to give people a chance to upgrade before it's made public.

Tavis notes that users should have been auto-updated to the fixed versions by now.

Re: Grammarly shared its tokens with all websites

#139

I nearly missed this bit at the bottom: > Grammarly had fixed the issue and released an update to the Chrome Web Store within a few hours, a really impressive response time. Nice to see a company take this kind of thing appropriately seriously (although of course it should never have happened in the first place).

Maybe they knew what they were doing and had a fix tee'd up for when they were found out?

Why would they wait to patch a massive vulnerability in their site that's just waiting to shower them in negative press?

Re: Grammarly shared its tokens with all websites

#140

I feel like the first thing we should talk about is how this is effectively a keylogger, similar to Windows 10's inking and typing setting, albeit with likely poorer security. Collecting everything you type into a web browser (or MS Office) and sending it to them seems like a really bad idea.

Isn't this also true of nearly all installable keyboards on mobile devices?

On iOS you currently have to explicitly allow network access to third party keyboards in the settings app (the not very clearly named "Allow Full Access" toggle), which as others have pointed out, is disabled by default on all newly installed keyboards. I have no idea how this works on other popular mobile device platforms.
Post reply on HN