Live data from Hacker News

AI browser extensions are a security nightmare

kolide.com

111–120 of 129 posts

Re: AI browser extensions are a security nightmare

#111

Earlier quoted context omitted.

you can make a warning as big and scary as you can, and people will just blindly hit accept/agree/ok. the look/design of the banner is not what will stop people from hitting ok, as at this point, i don't think anything will

While this is historically true, if the text is human readable - ‘may be able to read and transmit to a third party any data you input, including credit card numbers and passwords’ - is fairly likely to raise awareness. It’s not effect, but it’s better than nothing. It’s worth contrasting clear communication such as the above to a EULA designed by scummy companies to not be read, browsers presumably have nothing to g…

In isolation this is true, but for most people they just want the product the extension is offering - skipping past boring warnings is a means to an end. There is also the issue of warning fatigue when extension authors normalise asking for more permissions - more warnings leads to less engagement.

One way to avoid this would be to have an extension market which highlights alternative extensions and how they differ in permissions. But it would be hard to maintain those relationships, create a new oppportunity to game trust, push responsibility onto the market owners, etc. And ultimately, many interact with proprietary products without a direct competitor e.g. if FAANGs made them. So I can't see it happening.

Re: AI browser extensions are a security nightmare

#112

>Actually, the current AI situation may be even more perilous than Jurassic Park. In that film, the misguided science that brought dinosaurs back to life was at least confined to a single island and controlled by a single corporation. In our current reality, the dinosaurs are loose, and anyone who wants to can play with one. I'm really tired of reading stuff like this above. Seriously, AI is a disruptive tech and som…

[deleted]

Re: AI browser extensions are a security nightmare

#113
post #61

Earlier quoted context omitted.

The problem is the permission system. Like apps, extensions have an all-or-nothing attitude to permissions. Browsers should allow the user to be more specific about permissions, and let extensions think the user gave more permissions than they actually did. E.g. if extension insists that they need "access to entire filesystem", the browser should make the extension believe they have access to the entire filesystem, b…

> Like apps, extensions have an all-or-nothing attitude to permissions Browser extensions needs to declare their permissions. With Manifest V3 we’re seeing even more need to declare permissions. Any extension cannot do anything not explicitly granted to it by the user upon installation.

Yes but this extension needs to send the content of webpages you visit to APIs. You're gonna give it explicit permission to effectively do whatever the hell it wants.

Re: AI browser extensions are a security nightmare

#114
post #59

Earlier quoted context omitted.

No, because a typical safe-to-run browser extension is written in such a way that it can be examined to see what it does. AI-based tools can’t be analyzed based on their code, so the only way to make them safe is by limiting their capabilities. Any such capability limit is likely to be either too constraining, not constraining enough, or require as much planning ability as the AI itself.

When you talk about not being able to analyze these based on their code do you mean because today they're all just calling out to OpenAI or whoever? The risks listed in the article itself mostly seem to fall under the same, non-AI-extension, core problem of "you're given them all your data." And that's a risk for non-AI-based extensions too, but if you look at the code of an AI one, it's gonna be obvious that it's sh…

>When you talk about not being able to analyze these based on their code do you mean because today they're all just calling out to OpenAI or whoever?

I think that the issue here is that AIs are probabilistic in nature, meaning that you can't fully predict their behavior in a particular situation just by reading the code. Instead in a tipical (non AI poweered) extension, the code is a precise description of what the extension will do in every possible situation.

Re: AI browser extensions are a security nightmare

#115
post #89
post #54

Actually, aren't all browser extensions a security nightmare? Or has something changed recently?

Yeah parts of the article would still be as valid if this was about regular extensions. The main difference is that AI extension, by design, send the content of the pages you browse to a server. A malicious "calculator" extension could also send all the content to a server, and extension users don't really have an idea of what each extension is actually doing. So skip the "Malware posing as AI browser extension" sect…

[deleted]

Re: AI browser extensions are a security nightmare

#116
I do not understand how is it possible that Internet browsers do not currently have already built-in firewall that allows the user to control where the connection requests in the browser in general -the tab, the loaded web, the addon- are going to and from, and filter them.

Re: AI browser extensions are a security nightmare

#117
I have perment unstoppable hiccups that have occurred in the last week or so. Nothing I have tried has made them stop in fact I just hit up more every time I try to report record anything. I would like to just breathe without having hiccups and it's not even a choice for me I'm not even permitted to even attempt to stop this Behavior May hiccups are constant and unending. I have run out of ideas of who to pursue for help this is just Agony I can't even breathe without constant hiccup interruption I don't know how to make it stop and I'll do anything at this point.

Re: AI browser extensions are a security nightmare

#118
post #93

Earlier quoted context omitted.

That's a lot more work than saying "No" to using the malware.

It's common for various counterparties, including software, to ask for much more information than they need and possibly be doing untrustworthy things with it while also providing legitimate value to the end user. I've lied about my birthday while signing up for websites before. I've also made ad-hoc email addresses with forwarding to conceal my main email address. I've given fictitious phone numbers and I've used th…

> It's common for various counterparties, including software, to ask for much more information than they need

I believe if you ask for very wide permissions, at least when publihsing a browser-extension in the Google Chrome-store, you will have to justify why those are needed (from a user-facing POV), and your extension will be subject for additional review.

The same also applies when creating other Google-related apps which uses APIs which Google deems sensitive or restricted: You will have to justify their usage and be prepared for a review.

It's not bullet-proof, but it's more than nothing.

Re: AI browser extensions are a security nightmare

#119

I have perment unstoppable hiccups that have occurred in the last week or so. Nothing I have tried has made them stop in fact I just hit up more every time I try to report record anything. I would like to just breathe without having hiccups and it's not even a choice for me I'm not even permitted to even attempt to stop this Behavior May hiccups are constant and unending. I have run out of ideas of who to pursue for…

https://pubmed.ncbi.nlm.nih.gov/3395000/

In case you're not joking

Re: AI browser extensions are a security nightmare

#120

Earlier quoted context omitted.

It's statistical models all the way down.

That is not a very good reason to call an entity unintelligent. There are uncontroversial models of human intelligence that are Bayesian.

There are uncontroversial models of human intelligence that are Bayesian

But they're still models. Anyone claiming that Bayesian/statistical models have intelligence is confusing the map for the territory.

Post reply on HN