Earlier quoted context omitted.
Smooth Gestures (lfkgmnnajiljnolcgolmmgnecgldgeld) has done the same thing for well over a year now. I (and many others) reported the addon to Google, but it still remains. What does it take to get something like this removed?
In the extension text, they say: "This extension is ad supported, you can disable your support by going to the options and making a one-time donation. We depend on your support, but we understand if you would prefer to withhold it." This, from what I can tell, plays within the bounds of Chrome's policy on extensions. (I also spent some time looking at the extension source to verify that the only annoying thing they d…
The "Window Resizer" extension for Chrome now contains malware (2013)
101–110 of 124 posts
Re: The "Window Resizer" extension for Chrome now contains malware (2013)
#102With JavaScript, it's nearly impossible for Chrome to reasonably explain, with any level of granularity, what exactly an extension will do with its access - hence the "access your data on all websites" warning.
A proof of concept to demonstrate how you can take advantage of this access for nefarious reasons, even after getting approval into the Chrome Web Store, would be quite simple.
Long/short of it is: make sure you trust the author of any extension you install!
Re: The "Window Resizer" extension for Chrome now contains malware (2013)
#103The extension is now uninstalled.
Re: The "Window Resizer" extension for Chrome now contains malware (2013)
#104Earlier quoted context omitted.
He asks specifically if he has broken some rules in Google Chrome's terms of service, where another user replies with quotations from the ToS. He barks at that saying his extension is allowed to do what he does, because his extension does reveal exactly what it does, if you read its permissions carefully. Although, I cannot confirm whether that is true, but that's what he is saying. I have no idea what he is up to; b…
He does indicate the user gives the OK to 'access all data on all websites' - like most extensions do, come to think of it. I do think things like that should be more fine-grained, and/or that developers have to indicate /why/ they need that access.
- For a very few extensions, I allow it, but it is very clear that it is an open gateway for hackers,
- Most often, I deeply regret I can't even tell Chrome that I allow the extension on a subset of sites... At least not my gmail please...
- So the base rule is, never install something which requires all perms, obviously.
Users have been warned properly. They're at the mercy of untrustable people.
Re: The "Window Resizer" extension for Chrome now contains malware (2013)
#105Earlier quoted context omitted.
They seem to have an automated review process unless the extension is flagged for manual review. Source - https://developers.google.com/chrome/web-store/faq#faq-gen-0... .
Yeah, seems like they should maybe institute some type of manual review for any type of "global" permissions. It would impede the well-behaving apps that legitimately need global permissions, but it might be worth it.
Re: The "Window Resizer" extension for Chrome now contains malware (2013)
#106Re: The "Window Resizer" extension for Chrome now contains malware (2013)
#107I'm most concerned about the keylogging claims. Does anyone have a copy of the CRX so that we can determine if keystrokes were in fact being transmitted?
Re: The "Window Resizer" extension for Chrome now contains malware (2013)
#108I'm most concerned about the keylogging claims. Does anyone have a copy of the CRX so that we can determine if keystrokes were in fact being transmitted?
NO! It wasn't logging anything! The only thing it was doing was proxying clicks on search results through Ecosia's analytics servers instead of Google's.
Anyone who still has the extension installed can view the source code by looking in their /%USER_FOLDER%//Extensions/kkelicaakdanhinjdeammmilcgefonfh The extension is also available at http://ionut-botizan.net/window-resizer/ both as a .zip and .crx file.
Re: The "Window Resizer" extension for Chrome now contains malware (2013)
#109Reddit discussion from last month: http://www.reddit.com/r/YouShouldKnow/comments/1snyyl/ysk_th... Also, alternative as discussed on SO: http://stackoverflow.com/questions/20775775/alternative-to-c... See it in action: http://chrisbalt.com/blog/2013/12/20/link-hijacking-through-... Edit: Related: http://superuser.com/questions/694825/why-my-google-search-r... http://windowresizer.userecho.com/topic/353032-did-you-pul…
One thing I wish I had called out more clearly in my post ("See it in action") was the fact that the "feature" would re-enable itself after every update of the extension, which seemed to be quite frequently. It's a shame; it really was a feature-packed, helpful extension.
Thanks!
Re: The "Window Resizer" extension for Chrome now contains malware (2013)
#110Whoa, wait. One guy in this thread is claiming that Window Resizer was sending all your keystrokes back to a central server based on what he saw in Wireshark. Can anyone else verify this? I've had this extension installed for...a year, at least. Do I need to now go change every single password on every site because chances are it's been keylogged? This is insane.
The developer also seems to claim that the keylogger exists as well. If you want to take his word for it as well.