Live data from Hacker News

Let's build a Chrome extension that steals as much data as possible

mattfrisbie.substack.com

151–160 of 320 posts

Re: Let's build a Chrome extension that steals as much data as possible

#151
post #9

> Chrome scrolls the permission warning message container, so more than half of the warning messages don’t even show up. I’d bet most users wouldn’t think twice about installing an extension that appears to ask for just 5 permissions. An egregious and nearly unbelievable oversight on Google's part. :-\ As a developer, it's unimaginable to me to not test the extreme high and low numbers of inputs cases to ensure thing…

> The chain of humans who've been responsible for developing and testing Chrome Extension functionality and security has been asleep at the wheel this whole time, for something like 15 years. As the first in this chain of humans, I can tell you that (a) we obviously considered this in the first version of extensions and did not allow permissions "below" the fold, (b) Chrome's extension model dramatically improved on…

"I also encourage readers to remember that generally speaking, you all _want_ extensions."

Exception here. Never asked for them. Never wanted them. Do not and cannot use them.^1 Seems moot anyway as I doubt anyone ever asked for Chrome itself.

When an extension collects data under the radar it's "malware" but when Google does this, it isn't malware. Funny.

There's really no greater "danger" to www users than Google because it's nearly impossible to stop Google from doing what it wants. The company is embedded in every aspect of using the web. Malware authors might be a threat but they hold no such omnipotent control. Google is the largest threat.

1. Occasional Chrome user via Guest mode that does not permit Extensions.

Re: Let's build a Chrome extension that steals as much data as possible

#152

Earlier quoted context omitted.

If you don't install any addons, you'll be fine. You'll have to do without uBlock Origin and other ad blockers, though. Consider Brave if you still want those and want to stick to Chromium. In Firefox, you can go to about:config and set the default permission to deny to a lot of stuff (notifications, clipboard, etc.). You can also disable webgl and other features like those.

> uBlock Origin and other ad blockers Router based adblockers work well, Flint by GL.net comes with nice UI and adhlock and VPN built in. Some people complain about its chinese origin but at least I know only 1 government is spying on me - my provider supplies a router with a linux kernel older than this house. There could be an entire ensemble of Trojans partying there

Pi-Hole or the adblock package for OpenWRT are probably better examples. GL.Inet routers are already natively supported by OpenWRT (since their firmware are just custom forks) so one can flash them.

Re: Let's build a Chrome extension that steals as much data as possible

#153
post #9

> Chrome scrolls the permission warning message container, so more than half of the warning messages don’t even show up. I’d bet most users wouldn’t think twice about installing an extension that appears to ask for just 5 permissions. An egregious and nearly unbelievable oversight on Google's part. :-\ As a developer, it's unimaginable to me to not test the extreme high and low numbers of inputs cases to ensure thing…

> The chain of humans who've been responsible for developing and testing Chrome Extension functionality and security has been asleep at the wheel this whole time, for something like 15 years. As the first in this chain of humans, I can tell you that (a) we obviously considered this in the first version of extensions and did not allow permissions "below" the fold, (b) Chrome's extension model dramatically improved on…

> (a) we obviously considered this in the first version of extensions and did not allow permissions "below" the fold

Irrelevant.

> (b) Chrome's extension model dramatically improved on the previous state of the art which was Firefox's "every extension can do everything, extensions can't be uninstalled completely, and there's no review"

Irrelevant.

> (c) the install dialog is just one part in a bigger system which includes the review process.

"Our MFA system is broken and will accept wrong input, but that doesn't matter because you without the correct password you won't get in."

Would that fly?

> I also encourage readers to remember that generally speaking, you all _want_ extensions. When Chrome didn't have them, they were the top feature request in the bug tracker.

What are you trying to say? That because users want it then overlooking security issues is excusable?

> If you don't solve user needs, users solve them themselves with solutions that are even worse (ie native code).

That falls under the realm of 'their fault.' This problem does not.

> Please spare a bit of empathy for the "chain of humans" that have had it.

OK, I feel bad for the poor Google worker with the thankless job and a six figure salary. Now fix it.

Re: Let's build a Chrome extension that steals as much data as possible

#154
post #9

> Chrome scrolls the permission warning message container, so more than half of the warning messages don’t even show up. I’d bet most users wouldn’t think twice about installing an extension that appears to ask for just 5 permissions. An egregious and nearly unbelievable oversight on Google's part. :-\ As a developer, it's unimaginable to me to not test the extreme high and low numbers of inputs cases to ensure thing…

A completely foreseeable negative externality of the ubiquitous GDPR cookie permission popup, is training users to just click on any old shit.

Re: Let's build a Chrome extension that steals as much data as possible

#155
I have a chrome extension with about a 1000 DAU right now [link below]. I'm getting messages to buy the whole thing out but the buyer always fails to answer why they want to buy it. they are also open to buying any extension whatsoever. I suspect it's to open up the permission model and started stealing user's data.

link: https://github.com/prakhar897/workaround-gpt

Re: Let's build a Chrome extension that steals as much data as possible

#156

Earlier quoted context omitted.

@metadat -- can you provide the source for that? I'm genuinely curious how much Google spends on their privacy org, and esp. how that compares with the other big tech companies.

Privacy is bundled under Trust & Security. I don't have precise numbers or estimates, but basically every Google product area has a team of Technical Privacy Engineers, TPMs, TPgMs, and VPs. They are the arbiters who can block a production release if privacy and security issues are discovered and not remedied. No other company I can think of has invested in such a rigorous Privacy review and support structure in an a…

> No other company I can think of has invested in such a rigorous Privacy review and support structure in an attempt to reduce risk.

In recent court cases Google employees admitted they have no idea where user data is stored (specifically location data), which systems have access to it, and how to fully turn tracking off.

80-90% of Google's revenue comes from online ads. There's a huge conflict of interest between Google's business model and whatever "arbiters" pretend they want to block.

And of course the number of privacy things that Google pioneered is minuscule to non-existent. Google has been dragged into caring about privacy against its will, kicking and screaming, by government actions like GDPR and CCPA.

Facebook poaches Google's privacy people because Facebook is the only one of mega corps who are worse than Google, and wants to continue its practices as much as Google.

Re: Let's build a Chrome extension that steals as much data as possible

#157
post #9

> Chrome scrolls the permission warning message container, so more than half of the warning messages don’t even show up. I’d bet most users wouldn’t think twice about installing an extension that appears to ask for just 5 permissions. An egregious and nearly unbelievable oversight on Google's part. :-\ As a developer, it's unimaginable to me to not test the extreme high and low numbers of inputs cases to ensure thing…

> The chain of humans who've been responsible for developing and testing Chrome Extension functionality and security has been asleep at the wheel this whole time, for something like 15 years. As the first in this chain of humans, I can tell you that (a) we obviously considered this in the first version of extensions and did not allow permissions "below" the fold, (b) Chrome's extension model dramatically improved on…

OP could have worded the criticism as an organizational attack and not aimed at the individuals that make up the organization...

But anyhow, you work on the system and can't point out if this is an issue or not in the end-to-end sense? Like, why say OP is "missing the point" if you are not sure if they are missing the point?

TBF you do say "I'm not even certain that an extension that requests more than 5 permissions would be approved in the first place." Which if true, would make this pretty low priority.

(On the Empathy note, I just want to add: stating "Trust me you really don't want this job." In this context to random members of a forum is a bit of an empathy-lacking thing to do)

Re: Let's build a Chrome extension that steals as much data as possible

#158
post #87
post #56

Earlier quoted context omitted.

You should have been around before chrome books when any extension could do whatever it wanted without any permissions at all. Your understanding of history is missing some key pieces. Over time, Google has generally locked these APIs down not opened them up.

Browser JS definitely never had the ability to unmount storage volumes before Chromebooks existed.

Extensions could, and this action could be triggered from browser JS.

Re: Let's build a Chrome extension that steals as much data as possible

#159

100% this is how people are getting their social media accounts hacked for scams, crypto stolen, etc. Stronger passwords is useless when the session is stolen, when the actual data is read and sent off

Being able to lift cookies from every website you are logged into sounds crazy and amazing. Anyone have any clue what people are using it for? Maybe roll your own session sync?

Re: Let's build a Chrome extension that steals as much data as possible

#160
post #9

> Chrome scrolls the permission warning message container, so more than half of the warning messages don’t even show up. I’d bet most users wouldn’t think twice about installing an extension that appears to ask for just 5 permissions. An egregious and nearly unbelievable oversight on Google's part. :-\ As a developer, it's unimaginable to me to not test the extreme high and low numbers of inputs cases to ensure thing…

A completely foreseeable negative externality of the ubiquitous GDPR cookie permission popup, is training users to just click on any old shit.

GDPR does not mandate the popup (which in most cases is even illegal under GDPR).
Post reply on HN