Live data from Hacker News

8M users' AI conversations sold for profit by "privacy" extensions

koi.ai

111–120 of 261 posts

Re: 8M users' AI conversations sold for profit by "privacy" extensions

#111

Earlier quoted context omitted.

Wasn't there a comment on this phenomenon along the lines "we were so afraid of 1984 but what we really got was Brave New World"?

The apathy of the oppressed is a core theme of 1984.

Not really? In 1984 you were made an active participant of the oppression. The thought police and 5 minutes hate all required your active, enthusiastic participation.

Brave New World was apathy: the system was comfortable, Soma was freely available and there was a whole system to give disruptive elements comfortable but non disruptive engagement.

The protagonist in Brave New World spends a lot of time resenting the system but really he just resents his deformity, wanted what it denied him in society, and had no real higher criticisms of it beyond what he felt he couldn't have.

Re: 8M users' AI conversations sold for profit by "privacy" extensions

#113

Earlier quoted context omitted.

Adblockers are still working fine though? I’m on chrome with ublock and I’m not seeing any ads.

you're not using ublock, you're using ublock lite. it cannot do dynamic filtering, script blocking, or url parameter removal, among other limitations.

Why does that matter if he's not seeing ads. A severely crippled adblocker means that you would see ads during regular usage.

Additionally, Brave a chromium based browser has adblocking built into the browser itself meaning it is not affected by webextention changes and does not require trusting an additional 3rd party.

Re: 8M users' AI conversations sold for profit by "privacy" extensions

#114
post #47

I don't understand why so many people are using / trusting VPNs "Let us handle all your internet traffic.. you can trust us.. we're free!" No thank you.

The use case is people that are urged to view something that is blocked (torrent / adult / gambling). They want it now, and they don't want to get involved with some shady company that slaps on a 2 year contract and keeps extending indefinitely. These people instead find "free vpn" in the web store and decide to give it a try.

VPNs are just one example. How many chrome extensions do you have that you don't use all the time, like adblockers, cookie consent form handlers or dark mode?

Re: 8M users' AI conversations sold for profit by "privacy" extensions

#117
post #25

The company behind this appears to be "real" and incorporated in Delaware. > Urban Cyber Security INC https://opencorporates.com/companies/us_de/5136044 https://www.urbancybersec.com/about-us/ I found two addresses: > 1007 North Orange Street 4th floor Wilmington, DE 19801 US > 510 5th Ave 3rd floor New York, NY 10036 United States and even a phone number: +1 917-690-8380 https://www.manhattan-nyc.com/businesses/urba…

https://www.manhattanvirtualoffice.com/ The NY address is a virtual office. https://themillspace.com/wilmington/ The DE address is a virtual office plus coworking facility.

Amazing.

Re: 8M users' AI conversations sold for profit by "privacy" extensions

#118
post #25

Earlier quoted context omitted.

https://www.manhattanvirtualoffice.com/ The NY address is a virtual office. https://themillspace.com/wilmington/ The DE address is a virtual office plus coworking facility.

Wow the virtual office concept is so beyond shady. I wonder if there are any legitimate uses of it?

Many:

You run a business from home but do not want to reveal you personal address to the world.

You are from a country that Stripe doesn’t support but need to make use of their unique capabilities like Stripe Connect, then you might sign up for Stripe Atlas to incorporate in the USA so you can do business directly with Stripe. Your US business then needs a US physical address ie virtual office.

Etc

Re: 8M users' AI conversations sold for profit by "privacy" extensions

#119
post #89
post #82

Earlier quoted context omitted.

Its the reason why they found it because the code was in extension. Before manifest v3, extensions could just load external scripts and there's no way you could tell what they were actually doing.

> extensions could just load external scripts and there's no way you could tell what they were actually doing. I do think security researchers would be able to figure out what scripts are downloaded and run. Regardless, none of this seems to matter to end users whether the script is in the extension or external.

nothing stopping server side logic: if request.ip != myvictim, serve no malicious payload.

Re: 8M users' AI conversations sold for profit by "privacy" extensions

#120
post #43

From my experience, Google does not do a thorough app review. Reviewers get maybe a few minutes to review and move on due to the volume of apps awaiting review.

I imagine this would be a great use case for AI helping out?

I'm thinking of installing the extension in a sandbox and then use a local agent to have endless fake conversations with it
Post reply on HN