Live data from Hacker News

Massive spying on users of Google's Chrome shows new security weakness

reuters.com

71–80 of 270 posts

Re: Massive spying on users of Google's Chrome shows new security weakness

#71
post #36

There is a web intelligence company in Israel that is known to buy popular browser extensions like “Web of Trust” and use them to exfiltrate browsing data (with tons of sensitive and personal information). They have been called out for this several times already and some of their extensions got removed from the store, they invariably turn back up again after a few weeks though (good connections to Google/Mozilla I gu…

Why is this business model usually from Israel?

The business model of watching people's web browsing history and selling them adds? You mean like Jumpshot (through antivirus Avast -- Czech), Facebook/Twitter/Pinterest through their pixels (US), every ad tracking network (US/China/Europe generally), and Google through its search engine history & ad platform (US)?

It feels very unfair to malign Israel here when the majority of surveillance on the web for money is happening in other countries.

Re: Massive spying on users of Google's Chrome shows new security weakness

#72

Potentially dumb question here, but would it be generally possible to create a permissions system for browser extensions that can distinguish between an extension that is actually sending information based on sensitive sources like page content and browser history and an extension that only sends harmless stuff over the network like e.g. asking for updated ad block lists? I'm imagining something like a sufficiently a…

I don’t see why it wouldn’t be possible to make a more granular extension permission system that also has stricter sandboxing. Safari is already going in that direction. The new extension system is more restricted, although I don’t know if there is any granularity to it.

Re: Massive spying on users of Google's Chrome shows new security weakness

#73
post #21

Earlier quoted context omitted.

Why is DoubleClick in the whitelist?

Presumably, since, as the list you're referring to mentions, it's a Google owned property, and accessed by a lot of people, even those who don't usually access other google properties, which makes it really useful for analytics on a broader selection of sites/connections. Like, the function you're referring to, `IsGoogleAssociatedDomainUrl`, seems to only be used to log some information about https. Or at least that'…

You do know the history of the name doubleclick, right?

Now want to explain why a browser experiment or analytics domain whitelist includes an advertising surveillance domain?

(The answer, so far as I can work out, is that Google thinks "The stupid cattle won't even notice mostly, and the ones that do - we'll just get our stooges on social media to claim they're being paranoid, and that everybody should just keep fattening up on the delicious delicious free browser/email/search we so generously give them out of the kindness of our cold and black corporate heart. Then we harvest everything as per the plan.")

Re: Massive spying on users of Google's Chrome shows new security weakness

#74
post #6

Given that they're the engine now, does anyone know if Microsoft Edge is better than Chrome for for privacy?

Given that we're on HN, I distinctly remember reading on a comment that the new Edge supposedly dials home to MS and is not really secure either.

At least, if you're on Windows you pretty much already have to trust Microsoft, so you may as well not have to trust Google AS WELL.

Re: Massive spying on users of Google's Chrome shows new security weakness

#75

Potentially dumb question here, but would it be generally possible to create a permissions system for browser extensions that can distinguish between an extension that is actually sending information based on sensitive sources like page content and browser history and an extension that only sends harmless stuff over the network like e.g. asking for updated ad block lists? I'm imagining something like a sufficiently a…

Firefox already tells you what things an extension can do /what kind of permissions it has, when you are about to install one. You cannot install one and later turn off those permissions though.

Would this fit what you describe?

Re: Massive spying on users of Google's Chrome shows new security weakness

#76
post #60

Earlier quoted context omitted.

Let me put it another way. Do you think the average user knows of or would approve of Google Chrome itself sending information to an advertising network that could be used to track their behaviors and identity? Do you think this "feature" is adequately disclosed to customers downloading Google Chrome, that it includes a DoubleClick tracking backdoor that no other ad network or website receives.

Given that > that it includes a DoubleClick tracking backdoor that no other ad network or website receives. is false, yes, I think the disclosures are reasonable. Your standard of disclosure is that companies need to disclose things that they aren't actually doing. That's ridiculous.

How do you know they're not using it for tracking, beyond an ambiguous PR statement that actually doesn't even say they aren't using it for tracking? What makes you sure of that?

There are literally billions of dollars on the line.

Does Safari or Firefox implement a similar tracking header? If it's so needed for experiments, why is Chrome literally the only browser sending this data to their advertising network (or any site)?

If Google were using it for tracking purposes, they'd never confirm that unless forced to. Hence the ambiguous PR statement.

Re: Massive spying on users of Google's Chrome shows new security weakness

#77
I feel like Google Chrome should just have some icon or other visual indicator of when an extension has made a networking request. In addition, use the iOS model of permission and prompt the user when it wants to do something like access the network or read your browsing history. Perhaps if this happens on a frequent basis, give another indication that it's happening all the time with the ability to ignore such warnings. You need to repeatedly show such evidence to users for them to understand what's happening.

Re: Massive spying on users of Google's Chrome shows new security weakness

#78
post #70

Earlier quoted context omitted.

I have no clue if they're lying or not, and I'm open to the possibility that they are, but you're not really making a good case for it here. It's pretty disingenuous to claim they track users and base it on lack of mathematically airtight evidence that they don't. That's not how accusations are supposed to work, right? I might as well claim you're a burglar because there's nothing to indicate you're not one. If you w…

It's an advertising company making a statement about a "feature" in their browser that phones home to advertising domains with information that could be used for tracking purposes. You don't think that deserves extreme scrutiny? Do you think that statement was made by a random developer or filtered through 100 PR and legal people? Every single word of that statement was carefully crafted and constructed. Knowing that…

Where did I say it doesn't deserve scrutiny? Scrutinize it all you want, I'm sure it went through lots of people before being published. "Scrutiny" is not the same thing as actually accusing them of lying though.

> Every single word of that statement was carefully crafted and constructed.

I also don't believe this to be true (their statement seemed plain and clear enough to my eyes), but even if it were, it doesn't affect what I said above. You need actual evidence, not the mere possibility of mathematical loophole.

Re: Massive spying on users of Google's Chrome shows new security weakness

#79

Is Chromium safe to use, or at least safe to use as packaged with Ubuntu's snaps? I know, I know, snaps are a difficult topic on their own, but my point is that, if Chrome's (and Edge's AFAIK) general hunger for data is a generally accepted fact at this point, then wouldn't employers/enterprises advising to use Chrome in their corporate networks not put themselves under risk of being sued for gross neglect in case cu…

Well,once at umiversity I saw Chrome installed on all machines, so I asked, why they installed spyware on _university_ machines. All I got was disbelieve and ridicule. These people are not even aware of what they are doing, nor informed enough to make such decisions.

Re: Massive spying on users of Google's Chrome shows new security weakness

#80
post #70

Earlier quoted context omitted.

It's an advertising company making a statement about a "feature" in their browser that phones home to advertising domains with information that could be used for tracking purposes. You don't think that deserves extreme scrutiny? Do you think that statement was made by a random developer or filtered through 100 PR and legal people? Every single word of that statement was carefully crafted and constructed. Knowing that…

Where did I say it doesn't deserve scrutiny? Scrutinize it all you want, I'm sure it went through lots of people before being published. "Scrutiny" is not the same thing as actually accusing them of lying though. > Every single word of that statement was carefully crafted and constructed. I also don't believe this to be true (their statement seemed plain and clear enough to my eyes), but even if it were, it doesn't a…

Sorry, I hate to ask but I just have to know now. Have you ever worked in a large tech organization? Such a statement would never be made to the press without being touched by PR/legal.

They may not even be explicitly lying, because the statement is so ambiguous. When you're reading PR/legal speak then every single word matters.

Post reply on HN