Live data from Hacker News

Adware vendors buy Chrome Extensions to send ad- and malware-filled updates

arstechnica.com

81–90 of 111 posts

Re: Adware vendors buy Chrome Extensions to send ad- and malware-filled updates

#81

Obligatory note: Another example of why we should only run Free Software and only from trusted sources. Users of Trisquel or gNewSense never have problems like this.

All Chrome Extensions are completely opensource (lowercase - in the sense you can unzip them and inspect the source).

The evidence seems to be that this does actually work - people do look, and find out suspicious looking issues. However, that is insufficient to protect users of extensions that were previously trustworthy and then become malicious.

Re: Adware vendors buy Chrome Extensions to send ad- and malware-filled updates

#82
post #77
post #2

Can we start a petition for Google to let us disable extensions on specific sites? After reading the last few stories about this, I am quite sure I don't want any extensions whatsoever running in the same tab as my Gmail account. I think there is some extension that does this for you (turns off other extensions per site), but then we get into a "who guards the guardians" situation. Not to mention we need better and f…

I achieve this by having multiple users in Chrome. My main user is signed into my google account and has no extensions installed and all plugins disabled, I only access gmail and google services with it. My second user account is logged into basic services like HN, reddit, amazon and has only adblock and disconnect installed. A third user is not logged in anywhere and has adblock and a half-dozen other extensions ins…

honestly this sounds like a pain in the ass

Re: Adware vendors buy Chrome Extensions to send ad- and malware-filled updates

#83

Earlier quoted context omitted.

Opera 12 has ability to disable access of specific extensions to https sites and/or private tabs (by default access to https sites is enabled and to private tabs is disabled). May be there is a hope that they implement it in Blink based Opera, but now they only have ability to disable access of specific extensions to private windows and have no private tabs at all.

Opera 12 is ancient history. Opera 18 is now basically Chrome without the ability to set a custom search engine as default. Even with sqlite hacks, there's no way to set DDG as default on the stable release versions. (I use FF.)

Opera 12 is the latest version on Linux.

Re: Adware vendors buy Chrome Extensions to send ad- and malware-filled updates

#84
post #77

Earlier quoted context omitted.

I achieve this by having multiple users in Chrome. My main user is signed into my google account and has no extensions installed and all plugins disabled, I only access gmail and google services with it. My second user account is logged into basic services like HN, reddit, amazon and has only adblock and disconnect installed. A third user is not logged in anywhere and has adblock and a half-dozen other extensions ins…

honestly this sounds like a pain in the ass

Start off with two profiles and go from there. I use virtual desktops (spaces on OS X) to manage it. Space 2 is gmail, space 3 is logged in sites, space 4 is development, etc.

Once you get used to it you instinctively switch without thinking about it

I also created an app for OS X that creates temporary throwaway browser sessions for any supported browser you have installed:

https://github.com/nikcub/tmpbrowser

Makes it easier than using command line options and creating users

Re: Adware vendors buy Chrome Extensions to send ad- and malware-filled updates

#85
post #77
post #2

Can we start a petition for Google to let us disable extensions on specific sites? After reading the last few stories about this, I am quite sure I don't want any extensions whatsoever running in the same tab as my Gmail account. I think there is some extension that does this for you (turns off other extensions per site), but then we get into a "who guards the guardians" situation. Not to mention we need better and f…

I achieve this by having multiple users in Chrome. My main user is signed into my google account and has no extensions installed and all plugins disabled, I only access gmail and google services with it. My second user account is logged into basic services like HN, reddit, amazon and has only adblock and disconnect installed. A third user is not logged in anywhere and has adblock and a half-dozen other extensions ins…

What exactly are you trying to achieve with that, if I may ask?

Re: Adware vendors buy Chrome Extensions to send ad- and malware-filled updates

#86
post #85
post #77

Earlier quoted context omitted.

I achieve this by having multiple users in Chrome. My main user is signed into my google account and has no extensions installed and all plugins disabled, I only access gmail and google services with it. My second user account is logged into basic services like HN, reddit, amazon and has only adblock and disconnect installed. A third user is not logged in anywhere and has adblock and a half-dozen other extensions ins…

What exactly are you trying to achieve with that, if I may ask?

What exactly are companies trying to achieve with very precise, self-healing tracking methods?

Re: Adware vendors buy Chrome Extensions to send ad- and malware-filled updates

#87
post #86
post #85

Earlier quoted context omitted.

What exactly are you trying to achieve with that, if I may ask?

What exactly are companies trying to achieve with very precise, self-healing tracking methods?

Serve you more relevant ads? I don't really know. Which companies do you mean anyway? And what are these self-healing tracking methods?

Re: Adware vendors buy Chrome Extensions to send ad- and malware-filled updates

#88
I created an extension for Facebook that had 30k active users. I sold it after I was contacted like this. I was suspicious immediately from the outset about who the buyer was, but I figured I'd sell anyway as it took me about an hour to write. Strangely the app was deleted from the store within an hour of my purchase and has yet to re-appear: https://chrome.google.com/webstore/detail/facebook-chat-fix/...

Re: Adware vendors buy Chrome Extensions to send ad- and malware-filled updates

#89
post #5

This is a disturbing situation, but it's hard to say what the best way of dealing with it is. The first thing most people reach for first is that extensions shouldn't auto-update. Personally, I disagree - I love silent auto-updates in general. It's a huge drag on the computing experience to have dozens of different widgets all requiring manual updates, all with different mechanisms and all on their own schedules. If…

I don't understand the appeal of updating software at all. Once a piece of code becomes feature complete for my purposes I don't ever want it to change. Change just means more things break, features disappear, or the app becomes bloated, and now apparently, may start injecting ads.

I uninstalled noscript years ago when it started updating twice a week with apparently miniscule changes just to pop up its ad filled landing page. Its a fucking javascript blacklist/whitelist app, why on earth does it need to update? If I wanted a "browser security suite" (what noscript currently bills itself as) I'd download that specifically.

Post reply on HN