I nearly missed this bit at the bottom: > Grammarly had fixed the issue and released an update to the Chrome Web Store within a few hours, a really impressive response time. Nice to see a company take this kind of thing appropriately seriously (although of course it should never have happened in the first place).
Grammarly shared its tokens with all websites
131–140 of 176 posts
Re: Grammarly shared its tokens with all websites
#132Earlier quoted context omitted.
Why is this story not bigger news? Grammarly is excreting ads into my eyes before nearly every YouTube video I watch, yet I don't see any mainstream sites covering this.
Totally. Here's some more info on the company. They are located in the Ukraine. http://escadra.com.ua/en/kak-dvoe-kievlyan-sozdali-servis-pr...
Re: Grammarly shared its tokens with all websites
#133Earlier quoted context omitted.
It doesn’t detect the passive voice, punctuation errors, or tense mismatch. While spelling catches many, it doesn’t catch them all.
I, for one, don’t really care if someone has written to me in the passive voice. Or is changing tense. The message is still received. If it will mean they are more secure that way, then I will allow it.
Re: Grammarly shared its tokens with all websites
#134Earlier quoted context omitted.
Why is this story not bigger news? Grammarly is excreting ads into my eyes before nearly every YouTube video I watch, yet I don't see any mainstream sites covering this.
Mostly because cloud-connected keyloggers are mainstream. As I mentioned, Windows does it if you have their "inking and typing" setting enabled. A lot of mobile keyboard apps do it, especially if they say they use the cloud to help correct your typing. Of course, in the case of Microsoft or Google, you presumably either have disabled the setting or you place your trust in their security practices that it is okay, bec…
When people want privacy they will inevitably have to give up usability. I ditched Swiftkey for an open source Android keyboard that doesn't connect online or asks for any permissions. Its CRAP but it doesn't leak.
Re: Grammarly shared its tokens with all websites
#135What's the etiquette for disclosure timeline on something like this? It feels like 99.9999% of end users won't see this public disclosure, and waiting enough time for auto-updates to be applied would be ideal. Public disclosure as soon as the patch is available lets bad actors know about it while the vast majority of users are still vulnerable.
It's a choice between visible pain and invisible weakness. The early disclosure hurts and amplifies the issue. However, the malicious actors you need to worry about would be glad for every day without disclosure, because every day without disclosure is profit to them.
Re: Grammarly shared its tokens with all websites
#136I feel like the first thing we should talk about is how this is effectively a keylogger, similar to Windows 10's inking and typing setting, albeit with likely poorer security. Collecting everything you type into a web browser (or MS Office) and sending it to them seems like a really bad idea.
Re: Grammarly shared its tokens with all websites
#137Earlier quoted context omitted.
Mostly because cloud-connected keyloggers are mainstream. As I mentioned, Windows does it if you have their "inking and typing" setting enabled. A lot of mobile keyboard apps do it, especially if they say they use the cloud to help correct your typing. Of course, in the case of Microsoft or Google, you presumably either have disabled the setting or you place your trust in their security practices that it is okay, bec…
If it acts like a keylogger its a keylogger. When people want privacy they will inevitably have to give up usability. I ditched Swiftkey for an open source Android keyboard that doesn't connect online or asks for any permissions. Its CRAP but it doesn't leak.
Re: Grammarly shared its tokens with all websites
#138I nearly missed this bit at the bottom: > Grammarly had fixed the issue and released an update to the Chrome Web Store within a few hours, a really impressive response time. Nice to see a company take this kind of thing appropriately seriously (although of course it should never have happened in the first place).
They probably should have waited to let Google know they fixed it though, as Google releases the bug details immediately when a fix is made rather than waiting to give people a chance to upgrade before it's made public.
Re: Grammarly shared its tokens with all websites
#139I nearly missed this bit at the bottom: > Grammarly had fixed the issue and released an update to the Chrome Web Store within a few hours, a really impressive response time. Nice to see a company take this kind of thing appropriately seriously (although of course it should never have happened in the first place).
Maybe they knew what they were doing and had a fix tee'd up for when they were found out?
Re: Grammarly shared its tokens with all websites
#140I feel like the first thing we should talk about is how this is effectively a keylogger, similar to Windows 10's inking and typing setting, albeit with likely poorer security. Collecting everything you type into a web browser (or MS Office) and sending it to them seems like a really bad idea.
Isn't this also true of nearly all installable keyboards on mobile devices?