Live data from Hacker News

Temptations of an open-source Chrome extension developer (2021)

github.com

291–300 of 374 posts

Re: Temptations of an open-source Chrome extension developer (2021)

#291
post #286
post #270

Earlier quoted context omitted.

Of course, someone who has been successfully manipulated would also think they've escaped manipulation. Isn't that the scariest part

At some point a reality check should be possible. Do you find yourself spending money on advertised-things?

That's the metric I usually use. It's absolutely inconclusive, but it works for peace of mind at least. Have I seen any ads for something I bought? Usually the answer is "no". I'm still at the mercy of sort order on sites like Amazon and eBay, but that's much less scary because if I really care, I can sort by lowest price first.

Re: Temptations of an open-source Chrome extension developer (2021)

#292

I don't know what the solution to this is, but I know a few trusted/legitimate companies that sell their user data for around £20/year even after having monetized their users with actual money I will never do this because violating privacy goes against the core of my beliefs, but there is a conflict I can't seem to work out. On the one hand, I KNOW that the vast majority of users prefer to sell their privacy than pay…

Open source, audited extensions. I noticed this already exists in Firefox ( https://mzl.la/3Acn4DU ), I don't know of any auditors for Chrome extensions. Have some trusted organization or group (like Google or Mozilla themselves) who run audits on extensions to "certify" they don't have any malware. Additionally, the extensions are all 100% open-source, so if the "trusted organization" is compromised (or just bad at…

This is essentially the model of App Stores.

And it works. At least to keep the worst off Apples App Store. Mostly. Googles play store is apparently much more linient. And contains lots of horrible apps.

But the costs, as you mention, are real too. So much, that many, including myself, simply forego Apple as target at first. Sure, it's the more popular platform and it has more people willing to pay. But the review hurdles aren't worth it in the beginning.

Re: Temptations of an open-source Chrome extension developer (2021)

#293
post #249
post #94

FWIW, and since a few of you probably use it… I own the JSON Formatter extension [0], which I created and open-sourced 12 years ago and have maintained [1] ever since, with 2 million users today. And I solemnly swear that I will never add any code that sends any data anywhere, nor let it fall into the hands of anyone else who would. I’ve been emailed several tempting cash offers from shady people who presumably want…

If an extension I used got sold out … would it ask me if the permissions are changing? Or would it straight up sneak them in. Id hope id at least see a popup notice that would raise a red flag

Chrome and Firefox tell you the permissions of the extension changed and ask you to confirm or deny in a dialog box that doesn’t go away until you choose one.

Re: Temptations of an open-source Chrome extension developer (2021)

#294
post #249
post #94

FWIW, and since a few of you probably use it… I own the JSON Formatter extension [0], which I created and open-sourced 12 years ago and have maintained [1] ever since, with 2 million users today. And I solemnly swear that I will never add any code that sends any data anywhere, nor let it fall into the hands of anyone else who would. I’ve been emailed several tempting cash offers from shady people who presumably want…

If an extension I used got sold out … would it ask me if the permissions are changing? Or would it straight up sneak them in. Id hope id at least see a popup notice that would raise a red flag

I don't know how Chrome handles this but Firefox won't install the update without the user confirming it.

Re: Temptations of an open-source Chrome extension developer (2021)

#295
post #277

Earlier quoted context omitted.

Did your extension go through the normal vetting process or the extended review necessary to become a recommended extension?

If by recommended you mean "featured" flag on Chrome webstore then I believe that happens automatically if the extension satisfies their "best practices" criteria.

I was referring to Mozilla's extended manual review process necessary to become one of their "Recommended" extensions.

https://support.mozilla.org/en-US/kb/recommended-extensions-...

Re: Temptations of an open-source Chrome extension developer (2021)

#296

Earlier quoted context omitted.

You do realize all forms of media embed advertising directly into the content going right back to the beginning, right? There's nothing modern about it. Showing you a product when you actually want to see it is the most effective way to induce demand. All your favorite shows, movies, youtube personalities, etc. still do this.

Well, seeing that: - I use ad blockers for my browser on both mobile and PC - pay for the ad free version of all of my streaming providers - don’t use apps that have ads and don’t have a method to pay to get rid of them

[deleted]

Re: Temptations of an open-source Chrome extension developer (2021)

#297
post #23

Earlier quoted context omitted.

The most galling offer we saw on the mobile app side was something that would turn on the user's microphone, and listen for ads on tvs around them to track what they'd been exposed to offline. Adtech is such a thoroughly gross field.

"Adtech is such a thoroughly gross field." Someone else on HN called it "elegant" last week. https://news.ycombinator.com/item?id=36975056

> "The current movement to avoid tracking is an extremely powerful centralizing force."

What a biased, myopic comment. As if ad companies are a grassroots movement against centralisation. As if ad tech is not in the hands of the powerful few tech companies.

They have defended ads in 2021 as well. I wonder where they work. I mean, somebody must be writing the backend for all these ad companies.

Re: Temptations of an open-source Chrome extension developer (2021)

#299
post #243

Earlier quoted context omitted.

and you are essentially trusting the moral integrity of the current maintainer. why can't there be a method for making sure that such trust cannot be abused? Is this a tractable problem at all?

I don't think there's a solution for it after all. At the end of the day, you need to trust someone / something, unless you are the one who writes the whole code. Which browser are you using?

Blockchain technology! ;D

Re: Temptations of an open-source Chrome extension developer (2021)

#300
post #240

Earlier quoted context omitted.

They're saying it's scarier that ad companies can figure out these things without the data because it means that you can't protect yourself by withholding your data.

> you can't protect yourself but what are you protecting yourself from? What's the threat model?

Deanonymizing people across datasets for one. Maybe attacker or maybe next gov that goes full Hitler and subpenas tech companies to introduce social karma and you are put on a no-fly list because you expressed interest in UK royalty or have a cousin in Iran. Invisible bubble and radicalization for another.
Post reply on HN