Earlier quoted context omitted.
Instead of just outright limiting extensions you could give users the choice. Give us an option to make it impossible for extensions to send out data for example.
I do notice that almost all of the extensions I use have no need to make http requests nor modify the dom (e.g. to add tracking or css url()). I wonder what other methods there are to exfiltrate info beyond that.
Massive spying on users of Google's Chrome shows new security weakness
121–130 of 270 posts
Re: Massive spying on users of Google's Chrome shows new security weakness
#122Earlier quoted context omitted.
Instead of just outright limiting extensions you could give users the choice. Give us an option to make it impossible for extensions to send out data for example.
Exactly. What Chrome and Firefox should do, is bundle their own analytics program into the extensions program, make these analytics available via AMO or Chrome Web Store (already has a very basic version), and remove the ability for extensions to perform outgoing network requests unless the user explicitly whitelists the extension. Even then, show big scary warnings about extensions given this permission being able t…
Re: Massive spying on users of Google's Chrome shows new security weakness
#123Potentially dumb question here, but would it be generally possible to create a permissions system for browser extensions that can distinguish between an extension that is actually sending information based on sensitive sources like page content and browser history and an extension that only sends harmless stuff over the network like e.g. asking for updated ad block lists? I'm imagining something like a sufficiently a…
An invasive but effective strategy would be Javascript string/object tagging, where objects and strings derived from identifying API accesses are marked as dirty, and attempting to serialise these into requests or URLs triggers a permissions check. This would also give the option of replacing numbers and strings with junk data if the permission is denied, which seems pretty attractive.
Given the massive scope of a change like this, I don't expect it to happen, but it's nice to think of a world where any website or extension that attempts to exfiltrate data will be noticed by default.
Re: Massive spying on users of Google's Chrome shows new security weakness
#124There is a web intelligence company in Israel that is known to buy popular browser extensions like “Web of Trust” and use them to exfiltrate browsing data (with tons of sensitive and personal information). They have been called out for this several times already and some of their extensions got removed from the store, they invariably turn back up again after a few weeks though (good connections to Google/Mozilla I gu…
Re: Massive spying on users of Google's Chrome shows new security weakness
#125There is a web intelligence company in Israel that is known to buy popular browser extensions like “Web of Trust” and use them to exfiltrate browsing data (with tons of sensitive and personal information). They have been called out for this several times already and some of their extensions got removed from the store, they invariably turn back up again after a few weeks though (good connections to Google/Mozilla I gu…
Re: Massive spying on users of Google's Chrome shows new security weakness
#126Earlier quoted context omitted.
The only trustworthy extensions are uBlock Origin and EFF's Privacy Badger. Everything else is best viewed as potential malware, no different than random downloadable executables. Honestly, uBlock Origin and Privacy Badger are so important at this point they should just become part of the browser itself. They're already in a league of their own.
I trust both of these extensions far more as extensions than I would if they were part of Chrome.
Re: Massive spying on users of Google's Chrome shows new security weakness
#127Earlier quoted context omitted.
Yeah, and that sounds totally plausible. That Google need to send "experimental headers" to a hardcoded domain for an advertising company they bought a decade or so back - because of course the results of web browser experiments should go to an advertising company (or these days th advertising division of a company) ad not, say, to google's own domain? /s Google are totally lying here.
You realize that the tracking headers are headers as part of the requests that you were already making to doubleclick. So, what's happening here is that if you make a request to doubleclick (say because you're viewing an ad), extra information is included that allows Google to understand which experiments were enabled on your browser. If you never go to doubleclick yourself, chrome won't ever send data to it. It's no…
Re: Massive spying on users of Google's Chrome shows new security weakness
#128Earlier quoted context omitted.
Yeah, and that sounds totally plausible. That Google need to send "experimental headers" to a hardcoded domain for an advertising company they bought a decade or so back - because of course the results of web browser experiments should go to an advertising company (or these days th advertising division of a company) ad not, say, to google's own domain? /s Google are totally lying here.
You realize that the tracking headers are headers as part of the requests that you were already making to doubleclick. So, what's happening here is that if you make a request to doubleclick (say because you're viewing an ad), extra information is included that allows Google to understand which experiments were enabled on your browser. If you never go to doubleclick yourself, chrome won't ever send data to it. It's no…
To a first approximation, _nobody_ "goes to doubleclick themselves".
At the same time, back in 2016 a study at Princeton found almost 50% of all sites on the web had Doubleclick on them (this is separate to the 70% of sites running Google Analytics - and I'd bet there's approximately zero sites that serve doubleclick ads/trackers but not google analytics ones, so there's even less way to spin this as being a necessary way for google to "understand experiments" by whitelisting the doubleclick domain...).
I never "go to doubleclick". My browser "sneakily in the background goes to double click" while I browse about half the sites on the internet.
"It's extra data attached to requests you were already making." is technically true, and gaslighting at it's most brazen.
If you asked your mom how many times she made a went to doubleclick today, what would she say? What would the actual answer be if we wanted to use the tortured terminology of "requests she was already making to doubleclick" from your apologia about your employer up there?
You took me to task for calling you a stooge and that being "against HN policy" elsewhere in this discussion...(Well, I said "stooge", you accused me of saying "shill", but whatever.) I guess I apologise for using the term "stooge" for someone who's told us they work at google and are telling lies about how Chrome is sending unexpected tracking data to Doubleclick. But it seems very much the right term.
How about instead I say that your statement "If you never go to doubleclick yourself, chrome won't ever send data to it." is a brazen lie, wrapped up in a weasel-wordy disingenuous interpretation of what 99.99% of people would clearly understand "go to doubleclick yourself" to mean?
I'll leave this argument now, with a quote for you and all googlers:
"It is difficult to get a man to understand something, when his salary depends upon his not understanding it!" -- Upton Sinclair
(Source for my 50% number: https://www.technologyreview.com/2016/05/18/160139/largest-s... )
Re: Massive spying on users of Google's Chrome shows new security weakness
#129Earlier quoted context omitted.
Given that we're on HN, I distinctly remember reading on a comment that the new Edge supposedly dials home to MS and is not really secure either.
The concern is not that Chrome dials home to Google, but that any random dude scatters your data across entire internet.
Re: Massive spying on users of Google's Chrome shows new security weakness
#130Earlier quoted context omitted.
You realize that the tracking headers are headers as part of the requests that you were already making to doubleclick. So, what's happening here is that if you make a request to doubleclick (say because you're viewing an ad), extra information is included that allows Google to understand which experiments were enabled on your browser. If you never go to doubleclick yourself, chrome won't ever send data to it. It's no…
Do you really believe this is even vaguely close to true? To a first approximation, _nobody_ "goes to doubleclick themselves". At the same time, back in 2016 a study at Princeton found almost 50% of all sites on the web had Doubleclick on them (this is separate to the 70% of sites running Google Analytics - and I'd bet there's approximately zero sites that serve doubleclick ads/trackers but not google analytics ones,…
> At the same time, back in 2016 a study at Princeton found almost 50% of all sites on the web had Doubleclick tracking on the
Means that many people are going to doubleclick, via it's ads existing on other sites. If the extent of your concern is that I said "going to" instead of "makes requests to", valid and I apologise for not being precise in my use of language.
However, the HN guidelines also ask that you respond to the strongest possible interpretation of what someone is saying. So please respond to what it is clear I meant, and not the straw man you feel compelled to attack.
And since that bit of rhetorical drama seems to at this point be the core of your concern, I don't know that theres anything of substance for me to address here, just more personal attacks.
> My browser "sneakily in the background goes to double click" while I browse about half the sites on the internet.
To be clear, this is false. Your browser isn't doing anything sneaky here. Perhaps you can argue that individual websites are being sneaky by including 3p advertising. That's a valid concern. But a browser "loading the HTML of the page you direct it to" isn't being sneaky or nefarious.