Live data from Hacker News

Massive spying on users of Google's Chrome shows new security weakness

reuters.com

111–120 of 270 posts

Re: Massive spying on users of Google's Chrome shows new security weakness

#111

The other side of this is the many complaints in HN threads about restrictions on what extensions can do and which ones are allowed. I can't say whether chrome's extension library strikes the right balance, but I think it's a difficult tradeoff.

A solution would be that browser maker always check what are the most popular extensions and implement those feature in browsers so you get security and performance. It is more work for the browser maker but you do it for the popular extension (if you care about your users and not about yourself - this applies to GNOME too)

Remember pdfjs? Performance will be the same.

Re: Massive spying on users of Google's Chrome shows new security weakness

#112

There is a web intelligence company in Israel that is known to buy popular browser extensions like “Web of Trust” and use them to exfiltrate browsing data (with tons of sensitive and personal information). They have been called out for this several times already and some of their extensions got removed from the store, they invariably turn back up again after a few weeks though (good connections to Google/Mozilla I gu…

Who? - please name names

Re: Massive spying on users of Google's Chrome shows new security weakness

#113
post #83
post #36

Earlier quoted context omitted.

Why is this business model usually from Israel?

It's not. What's more common isn't that it's from Israel, but that people bother to mention Israel when that's the home country of the responsible company.

It is both. They're super proud of what they do. The mystery is why everyone cowers when they're the only ones who do genetic testing to determine nationality... How many US politicians have dual citizenship with a single country? And they have millions of "whites" reading books about "white fragility" - its a sad state of affairs!

Re: Massive spying on users of Google's Chrome shows new security weakness

#114
I am curious as to how Brave browser works out of the box to thwart these types of malicious extensions. Brave neuters the common abuses of browser technology like tracking, but what about detecting third requests _even if you have agreed to them_?

Re: Massive spying on users of Google's Chrome shows new security weakness

#115
post #6

Given that they're the engine now, does anyone know if Microsoft Edge is better than Chrome for for privacy?

Given that we're on HN, I distinctly remember reading on a comment that the new Edge supposedly dials home to MS and is not really secure either.

The concern is not that Chrome dials home to Google, but that any random dude scatters your data across entire internet.

Re: Massive spying on users of Google's Chrome shows new security weakness

#116
post #34

There is a web intelligence company in Israel that is known to buy popular browser extensions like “Web of Trust” and use them to exfiltrate browsing data (with tons of sensitive and personal information). They have been called out for this several times already and some of their extensions got removed from the store, they invariably turn back up again after a few weeks though (good connections to Google/Mozilla I gu…

Re security measures: these features have sadly been put under "enterprise" stuff but they are there: https://support.google.com/chrome/a/answer/9296680?hl=en I wonder if there could be a community pseudo-enterprise that could eg have a reasonable whitelist of extensions... edit: whoops, that was a windows-only guide despite the title, here are linux / mac links: https://support.google.com/chrome/a/answer/7517525#per…

IMO, at least for linux, popular (open source) extensions should be part of the distribution.

Re: Massive spying on users of Google's Chrome shows new security weakness

#117

There is a web intelligence company in Israel that is known to buy popular browser extensions like “Web of Trust” and use them to exfiltrate browsing data (with tons of sensitive and personal information). They have been called out for this several times already and some of their extensions got removed from the store, they invariably turn back up again after a few weeks though (good connections to Google/Mozilla I gu…

The only trustworthy extensions are uBlock Origin and EFF's Privacy Badger. Everything else is best viewed as potential malware, no different than random downloadable executables.

Honestly, uBlock Origin and Privacy Badger are so important at this point they should just become part of the browser itself. They're already in a league of their own.

Re: Massive spying on users of Google's Chrome shows new security weakness

#118
post #99

Earlier quoted context omitted.

> What is the "tracking" aspect? See this post I made when X-Client-Header was introduced. > But they claim [1] this X-Client-Data header is used for experimenting with Chrome, not for tracking. They claim a lot of things. Sometimes they even modify their claims years after they first made them. Even if they were making 100% innocent claims now , they are not guaranteeing[2] they won't change how they use the data in…

> Google is saying they are tracking people with that header No they don't. Nothing in your comment sounds anything like Google claiming to be tracking people. And as mentioned elsewhere in this thread, they explicitly claim to not be tracking individuals.

Maybe its more doublespeak: "individuals" isn't the same as "everyone"

Re: Massive spying on users of Google's Chrome shows new security weakness

#119
post #104

Earlier quoted context omitted.

Could browser extensions be ran in a sandbox, with read_access to the page, but only able to read from whitelisted registered and fixed URLs for updating configuration etc? So your blocking extension can download lists of things to block, or other config, but it can't exfiltrate any information about the user's browsing habits. The only side channel I can then think of is using page rewriting or timing to communicate…

In the same way that DNS requests can exfiltrate data, requesting URLs can also exfiltrate data. This is trivial to perform.

This is an apples to oranges comparison. DNS requests exfiltrate data such as IP and the domain you want to visit. Currently extensions can literally upload all your passwords if they wish to. Restricting them to be able to only GET whitelisted URLs (no query params or paramterized URLs) would cut down on pretty much 99.999% of possible data theft scenarios.

Re: Massive spying on users of Google's Chrome shows new security weakness

#120

There is a web intelligence company in Israel that is known to buy popular browser extensions like “Web of Trust” and use them to exfiltrate browsing data (with tons of sensitive and personal information). They have been called out for this several times already and some of their extensions got removed from the store, they invariably turn back up again after a few weeks though (good connections to Google/Mozilla I gu…

The only trustworthy extensions are uBlock Origin and EFF's Privacy Badger. Everything else is best viewed as potential malware, no different than random downloadable executables. Honestly, uBlock Origin and Privacy Badger are so important at this point they should just become part of the browser itself. They're already in a league of their own.

I trust both of these extensions far more as extensions than I would if they were part of Chrome.
Post reply on HN