Live data from Hacker News

Grammarly shared its tokens with all websites

bugs.chromium.org

171–176 of 176 posts

Re: Grammarly shared its tokens with all websites

#171
The day I heard about Grammarly (saw a Youtube ad). Free to use, I thought to myself, this surely monetizes by analysing all my input in their servers, wherever they are.

It looks like a good product. If they offered a true offline version for desktop with 4+ updates a year, I could see myself paying for it.

Re: Grammarly shared its tokens with all websites

#172

I feel like the first thing we should talk about is how this is effectively a keylogger, similar to Windows 10's inking and typing setting, albeit with likely poorer security. Collecting everything you type into a web browser (or MS Office) and sending it to them seems like a really bad idea.

Aren't all password managers keyloggers too?

Not even close. For instance check out password-store. It's a cli that uses gpg to store passwords. You can install an open source browser extension, but it only allows you to login easily and is manually triggered. It only connects to your local password-store.

Re: Grammarly shared its tokens with all websites

#173

Earlier quoted context omitted.

Your brain. If you offload too many tasks to computers, those skills will weaken.

> Your brain. Trying I promise, even different languages. But I'm not a native speaker and a bit dyslexic. So someone or thing looking over my shoulder would be nice.

I highly recommend friends and family as proofreaders.

Re: Grammarly shared its tokens with all websites

#174

Earlier quoted context omitted.

I am too paranoid to use them, but, from what I read (regarding the biggest one): "LastPass encrypts your Vault before it goes to the server using 256-bit AES encryption. Since the Vault is already encrypted before it leaves your computer and reaches the LastPass server, not even LastPass employees can see your sensitive data" If there is an attack still possible (even using LastPass employees) can you post it here?

I used LastPass for a while. Then it filled in my username and password (correctly) on a website without my having authenticated... It looks like there's an unencrypted local cache which is not flushed when your authentication expires or you log out. I wasn't able to reproduce it but I was sufficiently spooked to stop using it after that.

Sure it wasn't the browser that filled it in?

Re: Grammarly shared its tokens with all websites

#175

Last year I signed up for a paid subscription to Grammarly...then I read terms of use[1]. I know...it should have been the other way around, but here it goes: > "By uploading or entering any User Content, you give Grammarly (and those it works with) a nonexclusive, worldwide, royalty-free and fully-paid, transferable and sublicensable, perpetual, and irrevocable license to copy, store and use your User Content in con…

Is the grammarly ToS more than a CYA? I think they may do it that way to protect themselves from being sued after retaining your work. But I don't like the possibility of them owning your work.

Re: Grammarly shared its tokens with all websites

#176

Last year I signed up for a paid subscription to Grammarly...then I read terms of use[1]. I know...it should have been the other way around, but here it goes: > "By uploading or entering any User Content, you give Grammarly (and those it works with) a nonexclusive, worldwide, royalty-free and fully-paid, transferable and sublicensable, perpetual, and irrevocable license to copy, store and use your User Content in con…

Is the grammarly ToS more than a CYA? I think they may do it that way to protect themselves from being sued after retaining your work. But I don't like the possibility of them owning your work.

I agree that like many of such documents, it is CYA indeed. I don't mind CYA, but this is just sloppy encroaching legalese gobbledygook.
Post reply on HN