Live data from Hacker News

Adware vendors buy Chrome Extensions to send ad- and malware-filled updates

arstechnica.com

31–40 of 111 posts

Re: Adware vendors buy Chrome Extensions to send ad- and malware-filled updates

#31
post #5

This is a disturbing situation, but it's hard to say what the best way of dealing with it is. The first thing most people reach for first is that extensions shouldn't auto-update. Personally, I disagree - I love silent auto-updates in general. It's a huge drag on the computing experience to have dozens of different widgets all requiring manual updates, all with different mechanisms and all on their own schedules. If…

The problem is with users. They ignore the scary "access to all websites" dialogs and install extensions.

Sites like pinterest have extensions that request these permissions, when they don't even need them. There's a way to have the extension only have access to the site you're on when you CLICK somewhere in your toolbar.

There are fine grained permissions and optional permissions to specific hosts and ports and URL patterns. It's all very well thought out.

The problem is with users.

For example, I have an extension that enables autocomplete on all web pages: https://chrome.google.com/webstore/detail/autocomplete-on/gd..., and it has access to all data on all websites. People install it every day, I don't know why. I would never install or trust anybody else with such an extension. I have to manually clone any extension I like and upload it to the chrome web store; that way I know it's not going to auto update and do nefarious things.

Re: Adware vendors buy Chrome Extensions to send ad- and malware-filled updates

#33
I have the feeling that every "good" message about Chrome is followed by a disastrous one. This time it was the funky "audio feature" on tabs, followed by this. Chrome developed a scary creativity with good and evil stuff. I used Chrome once because everybody was telling me how fast it is. It wasn't. People just couldn't add all the processes properly. Since then it was a roller coaster I won't jump on anymore. I use Opera as an reference alternative to FF.

btw: my parents end up with Chrome every time I come by on the Windows. Installed through some update (Java maybe?). Is there any way to block this without taking all installation rights from them?

Re: Adware vendors buy Chrome Extensions to send ad- and malware-filled updates

#35
post #31
post #5

This is a disturbing situation, but it's hard to say what the best way of dealing with it is. The first thing most people reach for first is that extensions shouldn't auto-update. Personally, I disagree - I love silent auto-updates in general. It's a huge drag on the computing experience to have dozens of different widgets all requiring manual updates, all with different mechanisms and all on their own schedules. If…

The problem is with users. They ignore the scary "access to all websites" dialogs and install extensions. Sites like pinterest have extensions that request these permissions, when they don't even need them. There's a way to have the extension only have access to the site you're on when you CLICK somewhere in your toolbar. There are fine grained permissions and optional permissions to specific hosts and ports and URL…

Depending on how the extension developer feels future development may pan out, requesting access to all websites is the only reasonable way to do it.

With how the update system works[1], when requesting new permissions the extension is disabled until manually reenabled. If there's even a slight possibility you may want to request access to additional sites in the future, you basically have to request "all websites" to prevent this from happening.

Since Chrome 16 there have been optional permissions around (so you only request permissions when they're needed, preventing the extension from auto-disabling), although that introduces additional overhead beyond simply requesting everything in the manifest file.

The extension update system should probably work more along the lines of that in Android - it auto-updates if the new version needs no additional permissions, but requires user input when new permissions are required. The current[1] state of auto-disable-on-update isn't ideal from either a developer or user position.

[1] as of about a year ago when I last tested this

Re: Adware vendors buy Chrome Extensions to send ad- and malware-filled updates

#37
I wouldn't be surprised if some of the instances of this happening was the result of the original extension writer trying to boost his bottom line. (And not the work of shady malware marketers).

It's easy to convince yourself you have been cheated when you know your extension has over 1M+ downloads and you only have ~!$100 sent to your donation button.

Re: Adware vendors buy Chrome Extensions to send ad- and malware-filled updates

#38

I wouldn't be surprised if some of the instances of this happening was the result of the original extension writer trying to boost his bottom line. (And not the work of shady malware marketers). It's easy to convince yourself you have been cheated when you know your extension has over 1M+ downloads and you only have ~!$100 sent to your donation button.

I forked an extension released under MIT license because of this -- original author pushing shady updates.

After I re-released it on the Chrome Store, now I get emails trying to buy "my" extension from me.

Re: Adware vendors buy Chrome Extensions to send ad- and malware-filled updates

#39
First, Chrome needs to alert the user before updating an addon that has changed owners, and the default should be "do not update". This change should be pretty uncontroversial.

Second, Google needs to modify their policy towards Chrome addons to disallow ad injections and all user tracking.

There should be a clear demarcation between addons and "apps" in the Chrome store. Apps can be legitimately supported by ads. Addons shouldn't be.

Re: Adware vendors buy Chrome Extensions to send ad- and malware-filled updates

#40
From the comments:

  It sounds like Google needs to flag ownership changes and NOTIFY USERS about them 
  before the next auto-update of that extension.
  
  ------------
  NoteBuddy has been transferred from Joe Garage to Russian Mafia LLC. 
  Do you want to keep this extension enabled? 
  [ Da ] [ Nyet ]
  ----------- 
  
  - DaveSimmons
While this may seem like the most convenient step, it's actually not that simple either. The majority of users don't want to be notified of too many things and more notices may just be ignored. This is especially true of users with many extensions. As an alternative, it's possible to put extensions into a probationary period (I don't know if they already do this) when it's first created or the ownership has changed.

Extensions are reaching the wild-west of Play and no one's happy about that except malware/adware authors. If Google continues to serve more free users than their quality capacity (already a problem with every other service they offer), it won't be long before people move on.

And they will move on. Contrary to what most people believe, no one rules one domain forever. Whether it's the big iron of IBM, telecom of Bell, OS of Microsoft or the services of Google. Someone else will eventually wrestle in on your domain.

Post reply on HN