Live data from Hacker News

“Tencent QQ caught scraping all browser history on Windows”

twitter.com

101–110 of 121 posts

Re: “Tencent QQ caught scraping all browser history on Windows”

#101

For those unaware, QQ is a desktop IM service by Tencent

It’s also a massive source of spam. We’ve had to do a lot of work last year to prevent spam qq signups while also allowing legit users. Those spammers are freakin relentless.

Re: “Tencent QQ caught scraping all browser history on Windows”

#102
post #99
post #98

Earlier quoted context omitted.

So you're asserting that the only reason developers would keep developing for the Apple App Store is if they have no other choice? Security guarantees are a sales-pitch, hard to get numbers on that but I bet I'm not the only one that avoids installing random proprietary apps out of fear for privacy violations. The recent move to showing "privacy promises" on the App store pages is an indication of that. If alternativ…

“If alternative stores can't give sufficient security guarantees, then users will prefer the official one.” Nope. Users will use the stores where the apps they want are. Players starting new stores will just pay for exclusives of popular apps, so that users are forced to install other stores, which will of course claim to support privacy and security in marketing terms that have no substance. Android is why it is cle…

> Android is why it is clearly wrong to intervene in Apple’s secure store.

Why is Android wrong? The sky hasn't fallen over on the Android side.

Android's security woes are caused by lack of updates from carriers (which frequently delay or block Android updates), OEMs (which frequently don't bother to port security updates because they want to sell the newest devices, shenanigans similar to those pulled by Apple until it changed its stance about 2 years ago or so).

I don't know many people side loading apps or installing alternate app stores. The big alternative app stores are Chinese, which are there for obvious, non security related issues, and Amazon's app store, which is used primarily on their devices.

So I don't really see the problem. I do see a solid Stockholm syndrome.

Re: “Tencent QQ caught scraping all browser history on Windows”

#103

This is the type of behavior Apple intends to prevent with their signed app distribution, loathed by so many here.

That's why most people here agree it has a purpose but that it should be opt in rather than opt out

Re: “Tencent QQ caught scraping all browser history on Windows”

#104
post #7

Earlier quoted context omitted.

It just reads the history file off of the disk directly

So browse in incognito mode?

Always browse in incognito? Eff that, uninstall the offending app when you find out they are tracking everything you do online.

Re: “Tencent QQ caught scraping all browser history on Windows”

#105
post #100

Earlier quoted context omitted.

Would iPhone users be worse off if they gained the ability to use multiple different app stores?

Yes. They would lose the option to use one trusted store, and be forced to use set of different stores of varying different trust levels.

Are you sure about that? Chinese phones use Chine app stores because Google products are banned in China, but outside of China 99% of apps are installed through the Play Store.

Why would iOS be any different?

Re: “Tencent QQ caught scraping all browser history on Windows”

#106
post #23

Earlier quoted context omitted.

To clone Chinese OSS, you need WeChat account or OTP+Phone in China. This feels totally against the principles of good faith in OSS dev. They can clone and take advantage of the rest of the world’s efforts while returning nothing back. Asshole, is the term for such entities. To be fair, some cool Chinese developers do have repos on GitHub. They’re not the majority though. Edit: Hold on folks, I need to find source of…

Wait what? Last time youtube-dl got taken down on GitHub, someone advertised a Chinese mirror https://gitee.com/mirrors/youtube-downloader , and I was able to clone it just fine. Not sure where you got the idea that you need a WeChat account to clone. Are you talking about some other site?

I just tried it with no issues. Maybe they meant to sign up and use it as a developer you have to have something traceable by the CCP?

Re: “Tencent QQ caught scraping all browser history on Windows”

#107

Earlier quoted context omitted.

It’s just one company. There's no private Chinese companies, only CCP subsidiaries. Comparisons with e.g. Facebook are moot. At this point, comments like this are plain disingenuous, or purposefully misleading.

What about getting a National Security Letter from the US government? Apparently, your company and your industry, must be important enough that the government will send you a Top Secret document, forcing you to comply, and also forcing you to maintain the secrecy of its existence, and to even deceive your customers of ever enacting its mandates. This sounds to me like the exact same thing as your argument here. That…

Name the last American billionaire who fell off the face of the planet without an explanation that got traced back to the US government for critical. If it were true Theil and Koch (brothers) would have dropped out of the phone directory a long time ago. I think that sums up the way the chessboard is set up for for American vs Chinese style capitalism.

Re: “Tencent QQ caught scraping all browser history on Windows”

#108
post #82
post #65

Earlier quoted context omitted.

I happen to know the language so don’t need a Chinese person with me. And I can tell you it doesn’t say that, or anything close to that, apparently or not; it’s not a long post so it’s not like I would miss anything. If you disagree, point to the specific sentence and we can have a discussion.

I guess it might be a misunderstanding based on 幸好之前用火绒的自定义拦截功能,设置了一些重要或敏感数据目录的保护。 "Luckily I had previously used Huorong's user-defined interception functionality to set up protection for a few important or sensitive data folders." (Which is how they noticed that QQ was trying to access them.) So yes, if your antivirus allows you to deny QQ access to your browser history, it won't read your browser history. But most…

'disabling a rule' is a lot different than 'create a manually defined protected folder from within a third party application elsewhere'.

these two statements are in no way equivalent.

Re: “Tencent QQ caught scraping all browser history on Windows”

#109
post #5

If China wants to use protectionism to wage digital economy warfare, let's respond in kind. No more Wechat, TikTok, Alipay, or League of Legends or Valorant, until China gives equal treatment to foreign internet firms. Note: Valorant installs a kernel driver as part of the "anti-cheat" system; described by many as a rootkit: https://www.osnews.com/story/131665/riot-games-maker-of-leag... Valorant's parent company is…

>Note: Valorant installs a kernel driver as part of the "anti-cheat" system; described by many as a rootkit: https://www.osnews.com/story/131665/riot-games-maker-of-leag...

yeah. that's going to be more-and-more commonplace, too.

I don't know why it's suddenly fashionable/allowable to touch ring 0 as installed software, but here we are.

the irony of the whole thing is that while game-devs rootkit clients in order to pull in more marketing data/telemetry/whatever else the ToS allows them to steal, the real game cheaters out there are using extremely cheap CotS parts to create artificial man-in-the-middle clients that they can manipulate instead, with the host PC totally oblivious that the computer that's plugged into it as a HID is the one cheating.

I've said this thousands of times, I'll use this opportunity to say it again : the only method available to routinely and reliably find game-cheaters is through constant statistical analysis of the players performance/inventory/score versus the environment they're in.

The days of tuning such a system will be filled with false-positives, but it's the only way to accomplish anything near comprehensive anti-cheat.

Need to get a few bucks for the project? Call that statistical analysis machine learning and say that you're going to provide it as a service. Sit back and watch the money flow in.

Re: “Tencent QQ caught scraping all browser history on Windows”

#110
post #108
post #82

Earlier quoted context omitted.

I guess it might be a misunderstanding based on 幸好之前用火绒的自定义拦截功能,设置了一些重要或敏感数据目录的保护。 "Luckily I had previously used Huorong's user-defined interception functionality to set up protection for a few important or sensitive data folders." (Which is how they noticed that QQ was trying to access them.) So yes, if your antivirus allows you to deny QQ access to your browser history, it won't read your browser history. But most…

'disabling a rule' is a lot different than 'create a manually defined protected folder from within a third party application elsewhere'. these two statements are in no way equivalent.

Of course not, but if you retell it twice, one might turn into the other.
Post reply on HN