There is a web intelligence company in Israel that is known to buy popular browser extensions like “Web of Trust” and use them to exfiltrate browsing data (with tons of sensitive and personal information). They have been called out for this several times already and some of their extensions got removed from the store, they invariably turn back up again after a few weeks though (good connections to Google/Mozilla I gu…
Why is this business model usually from Israel?
Massive spying on users of Google's Chrome shows new security weakness
41–50 of 270 posts
Re: Massive spying on users of Google's Chrome shows new security weakness
#42There is a web intelligence company in Israel that is known to buy popular browser extensions like “Web of Trust” and use them to exfiltrate browsing data (with tons of sensitive and personal information). They have been called out for this several times already and some of their extensions got removed from the store, they invariably turn back up again after a few weeks though (good connections to Google/Mozilla I gu…
Why is this business model usually from Israel?
Re: Massive spying on users of Google's Chrome shows new security weakness
#43There is a web intelligence company in Israel that is known to buy popular browser extensions like “Web of Trust” and use them to exfiltrate browsing data (with tons of sensitive and personal information). They have been called out for this several times already and some of their extensions got removed from the store, they invariably turn back up again after a few weeks though (good connections to Google/Mozilla I gu…
Why is this business model usually from Israel?
Re: Massive spying on users of Google's Chrome shows new security weakness
#44I'd say most such issues with extensions could be solved if they were "read-only", i.e. were prevented from inserting data into documents, making or adding data into outbound requests.
GET /realylongstringwithmeaningfulbits/{user identifier}
This is basically what tracking pixels have been doing for years (1x1 transparent PNG).Re: Massive spying on users of Google's Chrome shows new security weakness
#45I wonder if these extensions are so hard to spot because spying is a core feature of Google Chrome, and most top extensions do this. For example, the extraordinarily popular extension Honey phones home about your purchases, shopping habits and other data without adequately disclosing that fact. It's hard to see why Google would care when Chrome was always a trojan horse to co-opt web standards for their own purposes…
Wow talk about revisionism! Chrome was meant as a hedge against IE and lesser so against Firefox. Microsoft owned the desktop with Windows and could easily shut Google out. See the reason surrounding the creation of the Google toolbar. Similarly Android is a hedge against IOS and mobile search.
Re: Massive spying on users of Google's Chrome shows new security weakness
#46Earlier quoted context omitted.
Wow talk about revisionism! Chrome was meant as a hedge against IE and lesser so against Firefox. Microsoft owned the desktop with Windows and could easily shut Google out. See the reason surrounding the creation of the Google toolbar. Similarly Android is a hedge against IOS and mobile search.
IE had bad standards support and bad defaults, while Chrome will actively track you on practically every site by sending an identifier to a whitelist including DoubleClick. Would you be defending it if it was called "DoubleClick Browser"? Google wants to secure the status quo with their own browser. What is the status quo? Massive spying, surveillance and tracking. This is why Safari and Firefox implemented strict me…
> Chrome was always a trojan horse to co-opt web standards for their own purposes
That wasn't the case. Google was concerned about Microsoft's ability to lock them out, and the lack of high quality browsers on non-Windows platforms.
Re: Massive spying on users of Google's Chrome shows new security weakness
#47The other side of this is the many complaints in HN threads about restrictions on what extensions can do and which ones are allowed. I can't say whether chrome's extension library strikes the right balance, but I think it's a difficult tradeoff.
Instead of just outright limiting extensions you could give users the choice. Give us an option to make it impossible for extensions to send out data for example.
Re: Massive spying on users of Google's Chrome shows new security weakness
#48At this point, I treat Chrome like a Huawei phone: never secure and only to be used at work for those sweet sweet dev tools.
Same here. Also never used any browser extension. Web devs need the pure browser experience.
I know I've been caught out on that one before..
Re: Massive spying on users of Google's Chrome shows new security weakness
#49Re: Massive spying on users of Google's Chrome shows new security weakness
#50Is Chromium safe to use, or at least safe to use as packaged with Ubuntu's snaps? I know, I know, snaps are a difficult topic on their own, but my point is that, if Chrome's (and Edge's AFAIK) general hunger for data is a generally accepted fact at this point, then wouldn't employers/enterprises advising to use Chrome in their corporate networks not put themselves under risk of being sued for gross neglect in case cu…