Live data from Hacker News

Let's build a Chrome extension that steals as much data as possible

mattfrisbie.substack.com

231–240 of 320 posts

Re: Let's build a Chrome extension that steals as much data as possible

#231

Earlier quoted context omitted.

Having less visual clutter -is- function to me. I really don’t miss permanent scroll bars and hope they don’t bring them back. Most Macs ship with a trackpad, which means I can’t remember when I last deliberately gripped a scroll bar. They are just a waste of space most of the time, even as an affordance/reminder that scrolling is possible.

I hardly use the scrollbar either (even when using a mouse), but the scrollbar is an important visual clue what portion of a scrollable page is currently being shown, no matter what the input method is. Apple could just have turned the interactive scrollbar into a much slimmer non-interactive hint and all would be fine, but no, they had to go "form over function" again :/

I see your point, but I still think this is a matter of preference and priorities.

I stand by the original argument that for most people, a minor twitch of their fingers on the trackpad reveals this information if they want it. I very rarely do want this though, and on average I prefer that it's not shown by default, or until I move.

This discussion was prompted by a UI fail in presenting relevant security information. Relying on permanent scroll bars would still be a UX fail, even if it were the default on Macs.

Re: Let's build a Chrome extension that steals as much data as possible

#232
> Who maintains them? Is it the same entity that maintained it when you first installed? Are you sure?

Oh yeah, got bitten hard myself on that one a couple years back, it took Google days to respond to the extension buyer uploading a malware'd version. The worst problem is that extensions auto-update silently so you as an user don't even have the chance to spot anything in time.

Re: Let's build a Chrome extension that steals as much data as possible

#233
post #9

> Chrome scrolls the permission warning message container, so more than half of the warning messages don’t even show up. I’d bet most users wouldn’t think twice about installing an extension that appears to ask for just 5 permissions. An egregious and nearly unbelievable oversight on Google's part. :-\ As a developer, it's unimaginable to me to not test the extreme high and low numbers of inputs cases to ensure thing…

> The chain of humans who've been responsible for developing and testing Chrome Extension functionality and security has been asleep at the wheel this whole time, for something like 15 years. As the first in this chain of humans, I can tell you that (a) we obviously considered this in the first version of extensions and did not allow permissions "below" the fold, (b) Chrome's extension model dramatically improved on…

Your response explains SO much about why this is a dumpster fire. Rather than a professional "these are some valid concerns, we may have made some serious mistakes and this deserves a credible response", here's how your defensive commentary was received by at least one person:

"Public criticism (however valid) of something I worked on hurts my feelings. Just so you know, we already thought through ALL these possible "problems" (and more) and we chose the "one true way". So your criticisms are just, waves hands, whatever.

Plus, these "issues" could never happen anyway (just try it lol!), so your criticisms are basically imaginary. Also and anyway this is YOUR fault (not mine, no!) because YOU wanted extensions. Also, also: the other guys were worse. Your fault, shame on you, other guys worse, I'm a good person.

And finally, this is hard work, no-one ever said thank you to me."

Re: Let's build a Chrome extension that steals as much data as possible

#237
Is anyone aware of a Chrome extension (or other spyware) that uses the macOS system clipboard to steal WhatsApp data?

I recently had an incident where WhatsApp Web was open in a tab in the background in a different browser window to the one I was actively using. I received and replied to a message on my phone. So imagine my surprise when I went to paste what I had previously copied from a web app in one Chrome tab to into a textfield in another, both in the active Window, to find that what was pasted was the second last message that I had sent in WhatsApp on my phone.

I have since deleted my Chrome profile at a system level, and the only extension currently installed is a well known password manager, but it bothers me to think what could have caused this aberrant behaviour, and whether there's something still installed on my system that's stealing data.

Post reply on HN