Live data from Hacker News

Adware vendors buy Chrome Extensions to send ad- and malware-filled updates

arstechnica.com

21–30 of 44 posts

Re: Adware vendors buy Chrome Extensions to send ad- and malware-filled updates

#22
It appears to be an easy way to at least weaken this practice:

Why doesn't chrome prompt it's user / demands a confirmation of permissions when an extention changes ownership, before updating it again?

It could at least impact the rentability of this buying up of extentions, but definitely help alert users of such things

Re: Adware vendors buy Chrome Extensions to send ad- and malware-filled updates

#23

That is why I never install browser extensions.

Do you live without adblock?

Yes, but I have JS disabled on most sites. Regarding adblock, there were posts that it slows the browser down, injects huge CSS rules into every iframe etc.

Re: Adware vendors buy Chrome Extensions to send ad- and malware-filled updates

#24

Earlier quoted context omitted.

Do you live without adblock?

you can do it quite effectively outside the browser using a host block[1] list or pi-hole. my uBlock now only fires sporadically for cases I don't catch with the /etc/hosts approach (e.g. disallowing e.g. remote fonts) [1] https://github.com/StevenBlack/hosts

Many years ago Opera had a blacklist for URLs with wildcard support that was implemented in a native code, not HTML/JS. I used to use it then.

Re: Adware vendors buy Chrome Extensions to send ad- and malware-filled updates

#25

Earlier quoted context omitted.

Do you live without adblock?

Host blocking at the OS level. No need for extensions.

Sometimes you need to temporary disable filters or edit them. How do you manage that? Is it user-friendly?

Re: Adware vendors buy Chrome Extensions to send ad- and malware-filled updates

#26
post #22

It appears to be an easy way to at least weaken this practice: Why doesn't chrome prompt it's user / demands a confirmation of permissions when an extention changes ownership, before updating it again? It could at least impact the rentability of this buying up of extentions, but definitely help alert users of such things

How would they know it changed ownership?

Re: Adware vendors buy Chrome Extensions to send ad- and malware-filled updates

#27
post #22

It appears to be an easy way to at least weaken this practice: Why doesn't chrome prompt it's user / demands a confirmation of permissions when an extention changes ownership, before updating it again? It could at least impact the rentability of this buying up of extentions, but definitely help alert users of such things

But it couldn't/won't guarantee anything, say Chrome could notify user the change ownership of an extension then the new owner state that they won't be evil, blah blah blah, but 1 or 3 months later they changed their minds and send ads to users. What next?

Re: Adware vendors buy Chrome Extensions to send ad- and malware-filled updates

#28
post #9

Use uBlock Origin [1] and uMatrix [2] instead. Also using Inox [2] browser helps too. [1] https://github.com/gorhill/uBlock/ [2] https://github.com/gorhill/uMatrix [3] https://github.com/gcarq/inox-patchset/releases

Instead of what?

Re: Adware vendors buy Chrome Extensions to send ad- and malware-filled updates

#29
post #12

I have a relatively popular novelty extension and I get approached by ad companies to buy/monetize it regularly. I refuse, because I despise advertising and I don't need the money. But I suspect I am in the minority and that many extension owners probably just decide it is easier to sell it and not think about it.

How much did they offer?

Re: Adware vendors buy Chrome Extensions to send ad- and malware-filled updates

#30
post #12

I have a relatively popular novelty extension and I get approached by ad companies to buy/monetize it regularly. I refuse, because I despise advertising and I don't need the money. But I suspect I am in the minority and that many extension owners probably just decide it is easier to sell it and not think about it.

I switched my chrome extension to a paid model (one off payments). Most the offers from these shady people, work out as approximately 1 year worth of sales.

Who pays for extensions? Like, honest question.
Post reply on HN