Live data from Hacker News

Massive spying on users of Google's Chrome shows new security weakness

reuters.com

81–90 of 270 posts

Re: Massive spying on users of Google's Chrome shows new security weakness

#83
post #36

There is a web intelligence company in Israel that is known to buy popular browser extensions like “Web of Trust” and use them to exfiltrate browsing data (with tons of sensitive and personal information). They have been called out for this several times already and some of their extensions got removed from the store, they invariably turn back up again after a few weeks though (good connections to Google/Mozilla I gu…

Why is this business model usually from Israel?

It's not. What's more common isn't that it's from Israel, but that people bother to mention Israel when that's the home country of the responsible company.

Re: Massive spying on users of Google's Chrome shows new security weakness

#84
I see this as an argument in favor of native apps. I mean really native, not Electron-esque ones.

As you more and more turn the browser into an OS, you have to treat it like an OS. Don't allow unprivileged user to install unsigned kernel modules.

Re: Massive spying on users of Google's Chrome shows new security weakness

#85
post #46
post #24

Earlier quoted context omitted.

IE had bad standards support and bad defaults, while Chrome will actively track you on practically every site by sending an identifier to a whitelist including DoubleClick. Would you be defending it if it was called "DoubleClick Browser"? Google wants to secure the status quo with their own browser. What is the status quo? Massive spying, surveillance and tracking. This is why Safari and Firefox implemented strict me…

You claimed: > Chrome was always a trojan horse to co-opt web standards for their own purposes That wasn't the case. Google was concerned about Microsoft's ability to lock them out, and the lack of high quality browsers on non-Windows platforms.

Chrome was great (and offered some unique advantages at the time), but it's absurd to say there weren't high quality browsers on non-Windows platforms. Firefox was fine, and WebKit was good enough for Google to decide to adopt it. They raised the bar by throwing engineering muscle at the problem but there was nothing "low quality" about Safari, Opera or Firefox at the time.

Re: Massive spying on users of Google's Chrome shows new security weakness

#86
post #80

Earlier quoted context omitted.

Where did I say it doesn't deserve scrutiny? Scrutinize it all you want, I'm sure it went through lots of people before being published. "Scrutiny" is not the same thing as actually accusing them of lying though. > Every single word of that statement was carefully crafted and constructed. I also don't believe this to be true (their statement seemed plain and clear enough to my eyes), but even if it were, it doesn't a…

Sorry, I hate to ask but I just have to know now. Have you ever worked in a large tech organization? Such a statement would never be made to the press without being touched by PR/legal. They may not even be explicitly lying, because the statement is so ambiguous. When you're reading PR/legal speak then every single word matters.

> Sorry, I hate to ask but I just have to know now. Have you ever worked in a large tech organization?

Sorry, but you're not going to.

> They may not even be explicitly lying, because the statement is so ambiguous. When you're reading PR/legal speak then every single word matters.

Then say it's ambiguous, instead of saying the opposite is true, is all I'm saying. You misinform people that way.

Re: Massive spying on users of Google's Chrome shows new security weakness

#87

Is Chromium safe to use, or at least safe to use as packaged with Ubuntu's snaps? I know, I know, snaps are a difficult topic on their own, but my point is that, if Chrome's (and Edge's AFAIK) general hunger for data is a generally accepted fact at this point, then wouldn't employers/enterprises advising to use Chrome in their corporate networks not put themselves under risk of being sued for gross neglect in case cu…

Well,once at umiversity I saw Chrome installed on all machines, so I asked, why they installed spyware on _university_ machines. All I got was disbelieve and ridicule. These people are not even aware of what they are doing, nor informed enough to make such decisions.

I guess if it were a CompSci faculty, the therapy is making these actions of your uni public, then see their academic reputation asymptotically approaching zero :) Though it's not clear what Chrome sends home, and TFA is only about Chrome plugins, so lets not prematurely start a witch hunt.

Re: Massive spying on users of Google's Chrome shows new security weakness

#88
post #72

Potentially dumb question here, but would it be generally possible to create a permissions system for browser extensions that can distinguish between an extension that is actually sending information based on sensitive sources like page content and browser history and an extension that only sends harmless stuff over the network like e.g. asking for updated ad block lists? I'm imagining something like a sufficiently a…

I don’t see why it wouldn’t be possible to make a more granular extension permission system that also has stricter sandboxing. Safari is already going in that direction. The new extension system is more restricted, although I don’t know if there is any granularity to it.

So WebExtensions support this, even dynamic permissions (like on Android). But I've found I've had to push developers to use it because it makes their life a bit harder and it's already a side-project.

Re: Massive spying on users of Google's Chrome shows new security weakness

#89

There is a web intelligence company in Israel that is known to buy popular browser extensions like “Web of Trust” and use them to exfiltrate browsing data (with tons of sensitive and personal information). They have been called out for this several times already and some of their extensions got removed from the store, they invariably turn back up again after a few weeks though (good connections to Google/Mozilla I gu…

Could browser extensions be ran in a sandbox, with read_access to the page, but only able to read from whitelisted registered and fixed URLs for updating configuration etc? So your blocking extension can download lists of things to block, or other config, but it can't exfiltrate any information about the user's browsing habits.

The only side channel I can then think of is using page rewriting or timing to communicate when the user browses to a page controlled by the extension owner. This would be something that there is at least a hope of spotting?

Re: Massive spying on users of Google's Chrome shows new security weakness

#90
post #46

Earlier quoted context omitted.

You claimed: > Chrome was always a trojan horse to co-opt web standards for their own purposes That wasn't the case. Google was concerned about Microsoft's ability to lock them out, and the lack of high quality browsers on non-Windows platforms.

Chrome was great (and offered some unique advantages at the time), but it's absurd to say there weren't high quality browsers on non-Windows platforms. Firefox was fine, and WebKit was good enough for Google to decide to adopt it. They raised the bar by throwing engineering muscle at the problem but there was nothing "low quality" about Safari, Opera or Firefox at the time.

A good part of the initial engineering muscle came from Mozilla. Google used to pay people working on Firefox, including the Firefox lead developer Ben Goodger, but pulled them to work on Chrome instead. So they already had a system set up for moving the web forward, but clearly they wanted more than that.
Post reply on HN