Live data from Hacker News

Massive spying on users of Google's Chrome shows new security weakness

reuters.com

1–10 of 270 posts

Re: Massive spying on users of Google's Chrome shows new security weakness

#3
The other side of this is the many complaints in HN threads about restrictions on what extensions can do and which ones are allowed. I can't say whether chrome's extension library strikes the right balance, but I think it's a difficult tradeoff.

Re: Massive spying on users of Google's Chrome shows new security weakness

#5
I wonder if these extensions are so hard to spot because spying is a core feature of Google Chrome, and most top extensions do this.

For example, the extraordinarily popular extension Honey phones home about your purchases, shopping habits and other data without adequately disclosing that fact.

It's hard to see why Google would care when Chrome was always a trojan horse to co-opt web standards for their own purposes and to prevent measures taken against invasive tracking and data collection in the first place.

Tracking is built directly into Chrome's source. Chrome will send "X-Client-Data" headers with a low-entropy identifier on every request to DoubleClick, an advertising agency owned by Google. DoubleClick's hostname is explicitly whitelisted in Chrome source code.

Chrome was always meant for massive spying, and any "crackdowns" are only a reaction to media pressure.

Re: Massive spying on users of Google's Chrome shows new security weakness

#7
There is a web intelligence company in Israel that is known to buy popular browser extensions like “Web of Trust” and use them to exfiltrate browsing data (with tons of sensitive and personal information). They have been called out for this several times already and some of their extensions got removed from the store, they invariably turn back up again after a few weeks though (good connections to Google/Mozilla I guess). Firefox isn’t better than Chrome in that regard btw as it also turns a blind eye on this kind of data collection.

Extensions are ideal to exfiltrate data from browsers as they bypass all security measures and can literally see everything you do on every single page you visit. It still boggles my mind how you can call a browser secure and privacy-friendly (in the case of Firefox) and at the same time allow such blatant abuse for years and years. Me and other people have been pointing this out since at least 2016 and demanded better security controls for plugins / extensions but I’m getting really tired of it.

Re: Massive spying on users of Google's Chrome shows new security weakness

#8
post #4

At this point, I treat Chrome like a Huawei phone: never secure and only to be used at work for those sweet sweet dev tools.

I use Firefox’s tools. The console as a tiny editor is cool. I think Chrome has a better network timeline/waterfall and performance monitor thing. But I only use those occasionally.

Re: Massive spying on users of Google's Chrome shows new security weakness

#10

The other side of this is the many complaints in HN threads about restrictions on what extensions can do and which ones are allowed. I can't say whether chrome's extension library strikes the right balance, but I think it's a difficult tradeoff.

A solution would be that browser maker always check what are the most popular extensions and implement those feature in browsers so you get security and performance. It is more work for the browser maker but you do it for the popular extension (if you care about your users and not about yourself - this applies to GNOME too)
Post reply on HN