Live data from Hacker News

Google purges bad extensions from Chrome

bbc.com

61–70 of 93 posts

Re: Google purges bad extensions from Chrome

#61
post #58

Earlier quoted context omitted.

It sounds like you would need the ability to access all the data on the page but not be able to phone home. Enforcing that sounds like a nightmare.

Right now extensions can provide a regex of the URLs that they will be enabled on. Obviously a malicious developer will just say "all" though.

Please tell me that it actually displays a regex to the end user during installation and asks them to read and approve it.

Re: Google purges bad extensions from Chrome

#62
Chrome extensions can do some really nasty things.. Just last year while doing adware research for extensions, I actually came across an extension monetization company who was silently installing google android apps to the users phone with no human interaction what so ever, I wrote a break down of this on my blog:

http://extensiondefender.com/blog/red-alert-dangerous-exploi...

Re: Google purges bad extensions from Chrome

#63
post #9

This is fantastic news. The Quick Note Chrome extension from Diigo (now removed) submits every URL visited to a third-party server and those URLs are then crawled the next day. We just switched our 25 member customer service team to Chromeboxes and were very concerned to find soon after that an EC2-based crawler was querying private URLs of our platform. Because the Chrome Web Store had not banned bad actors like Dii…

this is exactly what Google does with every single link you receive in gmail

Re: Google purges bad extensions from Chrome

#64
post #33
post #29

Earlier quoted context omitted.

> You can manually install extensions Not on Chrome stable. You have to use beta, dev, or a Chromium build for that.

I think you can on regular Chrome. Just tick the 'Developer Mode' box at the top of the extensions page.

I don't think you can on Windows.

Re: Google purges bad extensions from Chrome

#65
post #60
post #22

Better yet, disable all of them.

Disable all extensions? No more Tampermonkey, Postman, LastPass? Seems like a massive overkill. Extensions provide vital functionality.

What functionality? Never heard any of those.

Browsers are for interactive documents, for everything else there are native applications, even though I also do web development gigs.

Re: Google purges bad extensions from Chrome

#66

Should say "Google does a lousy job purging bad extensions from Chrome". A: Because all of the malware I reported is still there. And B: Because actually policing your store for malware for once shouldn't be a news item.

Could you give some examples of malware that you reported that are still there? What conditions do you use to classify extensions as malware?

Re: Google purges bad extensions from Chrome

#67
post #58

Earlier quoted context omitted.

Right now extensions can provide a regex of the URLs that they will be enabled on. Obviously a malicious developer will just say "all" though.

Please tell me that it actually displays a regex to the end user during installation and asks them to read and approve it.

IIRC (using Firefox nowadays) it did tell the user what sites it was allowed on, although it did this through wildcards (e.g. "http://news.ycombinator.com/*") instead of regexes.

Re: Google purges bad extensions from Chrome

#68

Just FYI, there are many cases of malware (presumably browser extensions) targeting online bankings in Indonesia recently. The typical flow is like this: 1. The user logs in to his/her online banking website. 2. The malware gets triggered and phones home with user's credentials. 3. The bad guy logs in using user's credentials in own computer. 4. The bad guy initiates bank transfer from user's account to his account.…

Ew, bank fail. My bank will send me a 2FA code to my phone, it'll explain what it's for first. So the message will say 'you're trying to send $200 to xyz at date yxz. Enter this code'. You'd then have to go to a screen on your computer with that particular transaction, find it, and enter the code. You don't suddenly get some kind of authentication pop up, and know to enter a particular code that authorises anything t…

Even contextual messages are game-able - the default text "enter your verification code" showing up on the website will likely catch a LOT of people, since they're thinking it's from the bank.

Extensions are Apps.

Without a meaningfully robust (and mandatory) security model and some basic security audits to prevent over-reaching security defaults/requests, you might as well be running Windows XP.

Re: Google purges bad extensions from Chrome

#69
post #66

Should say "Google does a lousy job purging bad extensions from Chrome". A: Because all of the malware I reported is still there. And B: Because actually policing your store for malware for once shouldn't be a news item.

Could you give some examples of malware that you reported that are still there? What conditions do you use to classify extensions as malware?

A good example of Vosteran New Tab. Almost two million users, none or near none of which are consensual users. Nobody I've ever uninstalled that from ever intended to install it. It hijacks your new tab page and search.

Interestingly enough, Vosteran also produces a rogue fork of Chrome which makes Vosteran's own search/ad platform built-in and unavoidable. Said rogue fork is also installed without users' permission.

https://chrome.google.com/webstore/detail/vosteran-new-tab/o...

I invite you to peruse the first five pages of search results here and make your own assumptions about the legitimacy of all it's five star ratings: https://www.google.com/?gws_rd=ssl#q=vosteran

Re: Google purges bad extensions from Chrome

#70

So how long until AdBlock Plus and uBlock are "bad" extensions? Enjoy your walled garden. Soon enough the walls will be so high you wont even remember what a free browser felt like.

Well, AdBlock Plus is a bad extension. People who use it should feel like scum. Because they are scum.

That being said, your walled garden notion is accurate. Chrome used "security" as an excuse to lock down the extensions platform to only their Web Store. But it's not any more secure, since there's plenty of malware in the Web Store. It was just an excuse to wall in their product.

Post reply on HN