Live data from Hacker News

Temptations of an open-source Chrome extension developer (2021)

github.com

141–150 of 374 posts

Re: Temptations of an open-source Chrome extension developer (2021)

#141

I don't know what the solution to this is, but I know a few trusted/legitimate companies that sell their user data for around £20/year even after having monetized their users with actual money I will never do this because violating privacy goes against the core of my beliefs, but there is a conflict I can't seem to work out. On the one hand, I KNOW that the vast majority of users prefer to sell their privacy than pay…

>They would gladly click on a "sell my data" over a "pay money" button any day of the week.

Even though many people assume it's this way, this choice hardly ever happens in practice. You allude to this yourself. In reality, the choices are usually between paying for something and they still sell your data, and getting it free and they really sell your data.

The majority of paid services have privacy policies, terms of service and user agreements that spell out how they sell data just as much. At best, you might expect that they are a bit more selective in who they sell to, since they're not as desperate for cash flow. However the impact to you is greater - they now have your credit card, address, full name, phone number (all vulnerable to hacks and leaks) and it's harder to lie about these things than with a free account. So the data they collect is more valuable, hence the temptation is higher as well.

Moreover, the paid services have consumer-hostile subscription systems rife with dark patterns. It's needlessly tedious to cancel a service if you decide you don't like it, and even free trials demand a credit card.

Transparency is very low about what is actually done with your money as well. Many services operate at a loss, and the customer charge is just a fig leaf while the real money comes from investors. Arguably, the paid model is a sham for some companies and their real exit is to collect data for a years and then get bought by some data aggregator. On the other end of the spectrum you have people fishing for suckers with ridiculously inflated prices.

For these reasons the choice of paying money is tainted by lack of trust, it is not just consumers being stingy and entitled. Lack of trust can quickly bog down any market.

I don't really blame the industry here, though. It's a bit like California in 1848 - you can hardly blame people for picking up the gold that's just lying around. The real problem is that we don't have the tools, infrastructure and regulatory frameworks that let users see and control how their data is used. If people really want to sell their data in lieu of payment, then let them. But currently, most users are not aware exactly what data gets collected and how much it is worth - they're not able to rationally decide that paying $5 for an app is better than being mined for $20 worth of your data.

Re: Temptations of an open-source Chrome extension developer (2021)

#142
post #108
post #98

Earlier quoted context omitted.

What size cash offers? Not that I want some of it, but then I do think there could be an industry re-scamming these people and want to know how much we're talking about.

Convincing offers to buy it for $10-40K. One offer said $250K but I doubt that one was serious, more likely just a straight up scam. I have often emailed them back feigning interest to see if I can get them to state what they plan to do with it, since I cannot see anything that could possibly be ethical, but they always just start talking mumbo jumbo about their innovative monetisation strategy. Recently I’ve had a s…

Thank you very much for the very informative response. As with any offer I think it's crucial to know what's at stake. You're very admirable for turning down tens of thousands, but if it had been tens of millions I'd have been questioning your judgement, as morally odious as the buyer might be.

See also: https://news.ycombinator.com/item?id=14808881

Re: Temptations of an open-source Chrome extension developer (2021)

#143

ChatGPT for Google was #1 on HN earlier this year. Check out the GitHub repo now: that person sold the extension. I had a small side project extension, ~25,000 installs & free to use. I got enough inbound interest trying to "help me monetize" that I thought it would be worth cataloguing all the different unsavory avenues: https://mattfrisbie.substack.com/p/the-ugly-business-of-mone...

I am not at all surprised to see one of the emails you got matches exactly (other than the extension name) one from the linked post. Definitely a lot of this crap is heavily automated.

> I'm a fan of [extension name] and I really like how convenient and useful it is.

> Have you considered offering promotional spots to those interested in promoting their products on your extension? I'm interested in promoting my own extension on [extension name] and would love to discuss this possibility with you.

> Let me know if you're open to this.

Re: Temptations of an open-source Chrome extension developer (2021)

#144

What's wrong with selling data if it's truly anonymized?

It would require collecting this data in the first place. Since it's not related to the primary functionality of the extension, it would require me to declare it in the privacy policy and extension stores. Probably needs additional access permissions as well. It's much easier to just not collect anything at all.

Re: Temptations of an open-source Chrome extension developer (2021)

#145

Earlier quoted context omitted.

This is my favorite sort of email that we get about once a month in various forms... their title at the end is hilarious. --- Subject: Found a security vulnerability on your website. Hi Team, I am Harris, a security researcher, and I have found a security vulnerability in your website outside a bug bounty program. I can disclose all the vulnerabilities found and their proper fixes too, to make your website more secur…

On the off chance you entertain these individuals, it's usually something really dull an automated scanner picked up.

What happens if you don't pay? Or do they expect you to pay up front for essentially a pig in a poke?

Re: Temptations of an open-source Chrome extension developer (2021)

#146

Earlier quoted context omitted.

> the ad companies just work out what you're interested in The word "just" doesn't belong in that sentence. The ad companies being able to know things about you without actually listening to you is even more scary. Evil-Ad-Company Neo: "You're telling me I can know things about my customers by secretly listening to them?" Evil-Ad-Company Morpheus: "No Neo, I'm telling you that with the right license agreements, data…

I mean showing you ads for diapers because you googled "best diapers" falls under that same category and I daresay isn't evil at all

Advertising, by its very nature, is emotional manipulation with the goal of getting you to give up some of your money for something you most likely don't really need and won't improve your life all that much, if at all. To me, that's evil.

Sure, there are varying degrees of this evil, but IMO even the least-objectionable advertising out there still can't be called "good".

In my experience, the case where advertising gets you to buy something that ends up being materially useful, that you would not have bought (or found a substitute for) without that advertising, is the exception, not the rule.

Oh, and to address your specific example: if you search "best diapers", and get shown ads for diapers, that absolutely is evil, because some ad-presentation algorithm is pushing you toward whatever diapers will generate the most money for the ad network, likely not toward which diapers are best. Not to mention that "best" often means different things to different people, and the ad networks only care about that insofar it increases their profit.

Re: Temptations of an open-source Chrome extension developer (2021)

#147
post #76

Maintainer here. My extension is pretty much unmonetizable so any offer I receive would require some degree of a moral sacrifice. The least intrusive offer I've seen so far is to put a reciprocal link to somebody else's extension inside of mine, kind of like DarkReader is doing on their website. Even though it won't compromise any of my users data, the reason I'm not doing this is because it indirectly endorses that…

Hi, I used to love hoverzoom... was there a malware scare a while back or am I thinking of a similarly named plugin ? At the time I switched to imagus & adjusted to it. Either way, thanks for turning away the monetization attempts :)

Re: Temptations of an open-source Chrome extension developer (2021)

#148

Earlier quoted context omitted.

On the off chance you entertain these individuals, it's usually something really dull an automated scanner picked up.

What happens if you don't pay? Or do they expect you to pay up front for essentially a pig in a poke?

The last one I engaged with only mentioned payment after the fact (along with wanting me to hire them to do a full pentest).

I just ignored them and that was it.

Re: Temptations of an open-source Chrome extension developer (2021)

#149

If you put something out on the web that gets somewhat popular, you are going to get all sorts of scummy people contacting you. The first one that happened to me: I have a domain name and someone emailed me to let me know, as a courtesy, that someone was buying similar Chinese domain names and did I want to get them first. I thought that was nice that they were notifying me ... oh wait, they're just trying to get me…

Android apps too. Always getting offers to have some code added.

Re: Temptations of an open-source Chrome extension developer (2021)

#150
post #113

Of all of these, I appreciated the one from 05/11/2016 the most. It felt the least shady because they were very up front with the scope and the data collected (which was narrowly focused), and left the implementation up to the developer (along with an optional script they could use). They also provided several options for sending the data, just to guarantee that the extension couldn't be compromised by their code. Th…

If they find out which domains people are mis-typing, then they can buy them and use them to steal login credentials.
Post reply on HN