Earlier quoted context omitted.
The developer also seems to claim that the keylogger exists as well. If you want to take his word for it as well.
I just can't even fathom. Like, every email I've typed. Every interaction with any site. Credit card numbers. How is this not entirely illegal? And it certainly shows an incredible flaw in Chrome extensions. This extension didn't do this when I installed it. A silent auto-update though basically turned it into the worst malware I've ever had installed on my computer. How can any Chrome extension ever be trusted? Furt…
The "Window Resizer" extension for Chrome now contains malware (2013)
111–120 of 124 posts
Re: The "Window Resizer" extension for Chrome now contains malware (2013)
#112Earlier quoted context omitted.
Where did you see that from the author?
Technically, he is quoted by another poster further up in the discussion. But the developer does not deny this quote.
Look! I deny it now, ok?! I haven't done anything like that. I just mentioned somewhere that it is technically possible to do such thing in an attempt to increase users' awareness about what would truly be a "horrible thing", unlike my attempt to support further development of my extension through advertising.
Re: The "Window Resizer" extension for Chrome now contains malware (2013)
#113The original post on productforums.google.com is complete BS and the extension was NOT suspended because of that, but because it failed to make it clear, in the context of the ads, which extension enabled the EcoLinks. This is not the first, nor last, piece of software that uses ads in order to support its development.
Also, the extension never logged anything from the users. All the "keylogger" stuff is just rumors started by people who are either incapable of reading a sentence from start to end or are knowingly lying about it.
It didn't alter the search results either. Those were exactly what Google returned for your search, nothing more, nothing less.
There was no malicious intent whatsoever. The whole purpose was to support further development of the extension through some form of advertising which you could disable at any point. The disable option was not even hidden among the other options; it had a dedicated page with a link in the main menu that only consisted of a checkbox - it was that simple and obvious.
Another false rumor is that the setting would enable itself automatically. No, it didn't! The only way that it would re-enable itself was to remove the extension and then install it right back. On uninstall all settings are lost and it fallbacks to the defaults.
The source code is plain HTML & JavaScript and it has always been available for anyone to review. Anyone could download the .CRX file and unzip it (it's just a special ZIP file) or take a look in the /%USER_FOLDER%//Extensions/kkelicaakdanhinjdeammmilcgefonfh folder (this varies based on your operating system) where the installed extension is. The source code has also been available at http://ionut-botizan.net
If you don't know JavaScript, you don't have to take my word for it; there is this prominent person in the web industry that, although he does not endorse this extension, has reviewed the code and confirmed there was no keylogger there: https://news.ycombinator.com/item?id=7048156#up_7056031
Another false accusation is that I bragged about how "I could sell your personal data and it wouldn't matter to me".
What I actually said is that "I could sell MY EXTENSION (as in transfer all rights and ownership to someone else) and it shouldn't matter to me (from a legal standpoint) what the buyer would do with it, be it collecting your private data or whatever". That claim was made just to point out that in fact I do care about the users' privacy and I chose not to sell the extension, even though I received plenty of offers. Some people asked "how could I even think of that"? Well, the extension is my property and receiving all those offers put me in the position where I had to think about it, whether I liked it or not.
In conclusion, yes, I admit the opt-out pattern is not the friendliest one and the whole thing could have been handled in some other way, but the reality is far from all these claims that I sneakily added malware to the extension, logged your keys and private data and sell all that to third parties or whatever.
The reality is I took your Google search results and converted them to sponsored links, plain and simple. All data that was transmitted when you clicked a search result was about the same that is sent whenever you click on any other ad or banner, which can not, in any circumstances, be used to identify you personally.
I am the developer and this is my answer; no excuses, just stating the facts. Learn what you want from it.
Re: The "Window Resizer" extension for Chrome now contains malware (2013)
#114Is it correct to class this as malware? I get that the portmanteau is "malicious software" and hijacking your Google search results isn't the friendliest thing to do but I think this is closer to "adware" than "malware". Although the author seems like a bit of a di- ...fficult person, maybe we should coin the term "dickware" to cover this sort of software. EDIT: I missed the keylogging bit, thanks to everybody that p…
It's inserting fake search results and running a keystroke monitor. To me this isn't even a close call; of course it's malware. I would also say that any developer who would do this simply can't be trusted; if he will do this, he might do just about anything else. He doesn't seem to have any regard for others.
It is just proxying clicks on real results through Ecosia's servers instead of Google's.
Re: The "Window Resizer" extension for Chrome now contains malware (2013)
#115This is completely egregious. Deleting now. I love that the developer's defense is that he could have sold our passwords to someone but (supposedly) didn't. That really instills confidence in his morals, doesn't it?
Read more carefully next time, ok?!
Re: The "Window Resizer" extension for Chrome now contains malware (2013)
#116It is adware, not malware! The original post on productforums.google.com is complete BS and the extension was NOT suspended because of that, but because it failed to make it clear, in the context of the ads, which extension enabled the EcoLinks. This is not the first, nor last, piece of software that uses ads in order to support its development. Also, the extension never logged anything from the users. All the "keylo…
I went ahead and looked at the code after downloading the zipped extension you linked too, and I effectively cannot see anything re. key logger. Where was that first reported? I would like to ask the original reporter on what piece of code he based his conclusion that there was a key logger in there.
Edit: Never mind, I see this apparently comes from original poster on google groups, so I asked him exactly how he came to this conclusion.
Re: The "Window Resizer" extension for Chrome now contains malware (2013)
#117I'm most concerned about the keylogging claims. Does anyone have a copy of the CRX so that we can determine if keystrokes were in fact being transmitted?
Re: The "Window Resizer" extension for Chrome now contains malware (2013)
#118I'm most concerned about the keylogging claims. Does anyone have a copy of the CRX so that we can determine if keystrokes were in fact being transmitted?
It is passing the search string I submit via google to ecosia which I elaborated on a few posts after the initial one. It is logging all search traffic keywords and then serving related ads in a backdoor manner. It is not sitting on my desktop logging or anything like that. But it is breaching my privacy expecations with Google by logging my user submitted keystrokes and sending them to Ecosia for sure. What are they…
Re: The "Window Resizer" extension for Chrome now contains malware (2013)
#119It is adware, not malware! The original post on productforums.google.com is complete BS and the extension was NOT suspended because of that, but because it failed to make it clear, in the context of the ads, which extension enabled the EcoLinks. This is not the first, nor last, piece of software that uses ads in order to support its development. Also, the extension never logged anything from the users. All the "keylo…
> All the "keylogger" stuff is just rumors started by people who are either incapable of reading a sentence from start to end or are knowingly lying about it I went ahead and looked at the code after downloading the zipped extension you linked too, and I effectively cannot see anything re. key logger. Where was that first reported? I would like to ask the original reporter on what piece of code he based his conclusio…
https://productforums.google.com/forum/#!msg/chrome/mlAD1ygc...
So, this is what caused all this shit storm...
Re: The "Window Resizer" extension for Chrome now contains malware (2013)
#120Earlier quoted context omitted.
Smooth Gestures (lfkgmnnajiljnolcgolmmgnecgldgeld) has done the same thing for well over a year now. I (and many others) reported the addon to Google, but it still remains. What does it take to get something like this removed?
In the extension text, they say: "This extension is ad supported, you can disable your support by going to the options and making a one-time donation. We depend on your support, but we understand if you would prefer to withhold it." This, from what I can tell, plays within the bounds of Chrome's policy on extensions. (I also spent some time looking at the extension source to verify that the only annoying thing they d…
If the user hovered with his mouse over a link, he couldn't tell the link would lead him to http://www.ecosia.org/. But this is exactly what was happening, because the click listener was changing the URL only after the user clicked.
So now the user was redirected to http://www.ecosia.org/ along with a bunch of parameters, including the original query and the original URL, and from there http://www.ecosia.org/ redirected the user to the original URL (after logging whatever it wanted to log), without the user having a way to notice what had just happened (unless looking in the dev console).
The fact that the URL was changed only after the user clicked is quite a hint that deception was intended there.