Live data from Hacker News

Temptations of an open-source Chrome extension developer (2021)

github.com

111–120 of 374 posts

Re: Temptations of an open-source Chrome extension developer (2021)

#111
post #80

Earlier quoted context omitted.

But every time this comes up the threads are flooded with people saying it doesn't actually happen and the ad companies just work out what you're interested in by what you're browsing.

Two different things. The popular conspiracy theory is that the phone listens to and presumably transcribes your conversations, sending them to a third party. The example the OP gave is specifically listening for TV content: they’ll have hashes of known ads/shows/whatever to compare against rather than do something like live transcription. Don’t get me wrong it’s shitty and gross. But they are different things.

Both iOS and Android show when your microphone is active so the whole conspiracy theory about it always listening to you and sending it back is pretty bullshit. And no one has yet found evidence of such network traffic either.

Re: Temptations of an open-source Chrome extension developer (2021)

#112
post #27

I wonder whether there exists a cottage industry of fake extension writers pumping up their numbers with fake installs, all with the goal to sell the fake extensions to these scammers.

You make the extension. I'll use bots to inflate the stats and make it look used. You pretend to not notice and sell-out. We split the profits. Fraud as easy as 1-2-3.

Re: Temptations of an open-source Chrome extension developer (2021)

#113
Of all of these, I appreciated the one from 05/11/2016 the most. It felt the least shady because they were very up front with the scope and the data collected (which was narrowly focused), and left the implementation up to the developer (along with an optional script they could use).

They also provided several options for sending the data, just to guarantee that the extension couldn't be compromised by their code. This one stood out from the rest for me. Curious though if I'm missing some way that this could be used for nefarious purposes though. Full text of the proposal below:

------

I’m sure you get business proposals all the time, so I’ll get straight to the point. I hope what I’m proposing is a little different and might actually interest you. I like Hover Zoom+ as a great alternative to it’s bigger brother Hover Zoom that lost its glamour over the last couple of months.

We're conducting a DNS error research and we’re interested in small amounts of anonymous data that you might be able to provide via your Chrome extension. Our research has been going on for years and Google has never had the slightest problem with it.

Compatible with Google’s strict policies No personal user data No ads, no malware The data we’re interested in are basically just DNS errors:

NXD – Non Existent Domain - the domain that a user entered that resulted in a DNS error. A time stamp – when it happened. GEO – where it happened (USA, UK, RU etc.). A unique randomly generated user ID (can be hashed, not traceable back to the user). Please, don’t confuse this with the user IP address. And that’s all. You can either use our script or collect the data on your own and send it to us via an FTP server, API etc. There’s a lot of different ways we can do this. We pay on a monthly basis. The payments depend on user GEOs, but it would be in thousands of dollars per year.

Is this worth at least a brief discussion? Looking forward to hearing from you.

A while back I reached out to you regarding a DNS error research our company conducts. Hover Zoom+ would be an ideal medium for our research. In return, this could become a solid new revenue stream for you.

Our method has been going on for years and we’ve never had the slightest problem with Google. We pay regularly on a monthly basis. For you it would be in tens of thousands of dollars per year - the amount depends on your users base and data quality.

If you’re concerned about including third party scripts, there’s still a lot of ways we can make this work.

Please let me know if this is worth a brief discussion to you.

Re: Temptations of an open-source Chrome extension developer (2021)

#114
post #67

Earlier quoted context omitted.

But every time this comes up the threads are flooded with people saying it doesn't actually happen and the ad companies just work out what you're interested in by what you're browsing.

Fly-by-night ad networks might engage in this. Ad networks that are in the sights of regulators, and can be slapped with $X billion fines, that may well exceed the marginal revenue produced by improved tracking[1] are going to be a bit antsier around doing that sort of thing. [1] How much more money will a $100B ad business make if they improved tracking accuracy by %1? It's some positive number, but significantly le…

So instead they buy that data from the fly-by-night operators and carry on as usual. That's the key problem here, this data only needs to be collected by one shady operator, "the market" will handle the rest.

Re: Temptations of an open-source Chrome extension developer (2021)

#115

Earlier quoted context omitted.

Your phone notifies you when an app accesses the microphone. If this is happening so much, how is it not blatantly obvious?

Android phones that are 8 major versions out of date because the OEM won't support them probably don't have that feature.

8 major versions, that is surely less than 5% of the Android population. I'm sure the security flaws in those non-updated phones is far more serious than the lack of microphone indicator.

Re: Temptations of an open-source Chrome extension developer (2021)

#116
This reminds me of a dirty plan I had as a kid in middle school.

1. Make a legitimately useful Minecraft Bukkit plugin.

2. Wait for lots of installs.

3. Add a well-hidden backdoor that makes me "op" (admin) on any server I choose.

4. Surprise some mean op on a public server by suddenly banning him.

I got through step 2 then decided to stop there.

Re: Temptations of an open-source Chrome extension developer (2021)

#117

I don't know what the solution to this is, but I know a few trusted/legitimate companies that sell their user data for around £20/year even after having monetized their users with actual money I will never do this because violating privacy goes against the core of my beliefs, but there is a conflict I can't seem to work out. On the one hand, I KNOW that the vast majority of users prefer to sell their privacy than pay…

>They would gladly click on a "sell my data" over a "pay money" button any day of the week. You don't know that because no one is given a clear choice like you present (and even saying "data" is opaque to joe average user). And this is what regulations like EU's and CA's should be enforcing. Imagine if the choice was: We have this data about you (a comprehensive list of all the fruits of our creepy stalking: a,b,c,d,…

[deleted]

Re: Temptations of an open-source Chrome extension developer (2021)

#119

And if you run a website you get constant emails like this: Hey There, I wanted to reach out and see if accepts guest post contributions or link insertion in existing posts? If so, I'd love to hear more about your guidelines and any specific topics of interest. Thank you for your time, and I'm looking forward to your response. Best Regards, These ones are definitely spammed out en-masse, my site doesn't even have a b…

This is my favorite sort of email that we get about once a month in various forms... their title at the end is hilarious.

---

Subject: Found a security vulnerability on your website.

Hi Team, I am Harris, a security researcher, and I have found a security vulnerability in your website outside a bug bounty program.

I can disclose all the vulnerabilities found and their proper fixes too, to make your website more secure.

Companies I helped have always been generous and helped me back with rewards in amounts they think are appropriate to the issues I have found. If you appreciate my help, I'd be happy to receive a bonus payment via PayPal, Bitcoin, Payoneer, or Bank Transfer.

Waiting for a positive response from your end.

Thanks and Regards,

Harris A

Certified Ethical Hacker

Re: Temptations of an open-source Chrome extension developer (2021)

#120

Earlier quoted context omitted.

> the ad companies just work out what you're interested in The word "just" doesn't belong in that sentence. The ad companies being able to know things about you without actually listening to you is even more scary. Evil-Ad-Company Neo: "You're telling me I can know things about my customers by secretly listening to them?" Evil-Ad-Company Morpheus: "No Neo, I'm telling you that with the right license agreements, data…

I mean showing you ads for diapers because you googled "best diapers" falls under that same category and I daresay isn't evil at all

Those two categories are really far away from each other.

Googling X is a voluntary act to search for X.

Speaking about X with a friend, while the phone sits in a bag nearby, has exactly zero connotations of wanting to search for X.

Post reply on HN