Earlier quoted context omitted.
My comment is the answer to a specific comment asking about a tangential derivative based on the discussion (which is why it is not a new parent comment under the post itself). Thank you.
Yeah, I mean a disconnected reply to a tangential question is misleading.
Massive spying on users of Google's Chrome shows new security weakness
191–200 of 270 posts
Re: Massive spying on users of Google's Chrome shows new security weakness
#192What extensions do you primarily use on Chrome (if you do)? My list (on brave) includes: >uBlock Origin >Decentraleyes >Stylus
Stylus is the only one I had installed in Brave at the time you asked. I have several in Chrome but the thing is I no longer really use Chrome for general browsing. Chrome has been relegated to development activity; I isolate developer tools to that browser and leave them out of my day-to-day browser (Brave.) It's a nice arrangement really. Decentraleyes is interesting. Thanks for pointing that out.
About decentraleyes, happy to help. It's a remarkable extension and I've been using it for about 2 years now. It's crazy how I still discover little tips and tricks that really help me while browsing forums to this date. Things that I would never otherwise encounter. I would have installed HTTPS everywhere but given that I rarely browse websites on brave, I reserved it for firefox.
Re: Massive spying on users of Google's Chrome shows new security weakness
#193Earlier quoted context omitted.
A solution would be that browser maker always check what are the most popular extensions and implement those feature in browsers so you get security and performance. It is more work for the browser maker but you do it for the popular extension (if you care about your users and not about yourself - this applies to GNOME too)
Remember pdfjs? Performance will be the same.
Re: Massive spying on users of Google's Chrome shows new security weakness
#194There is a web intelligence company in Israel that is known to buy popular browser extensions like “Web of Trust” and use them to exfiltrate browsing data (with tons of sensitive and personal information). They have been called out for this several times already and some of their extensions got removed from the store, they invariably turn back up again after a few weeks though (good connections to Google/Mozilla I gu…
Re security measures: these features have sadly been put under "enterprise" stuff but they are there: https://support.google.com/chrome/a/answer/9296680?hl=en I wonder if there could be a community pseudo-enterprise that could eg have a reasonable whitelist of extensions... edit: whoops, that was a windows-only guide despite the title, here are linux / mac links: https://support.google.com/chrome/a/answer/7517525#per…
Re: Massive spying on users of Google's Chrome shows new security weakness
#195There is a web intelligence company in Israel that is known to buy popular browser extensions like “Web of Trust” and use them to exfiltrate browsing data (with tons of sensitive and personal information). They have been called out for this several times already and some of their extensions got removed from the store, they invariably turn back up again after a few weeks though (good connections to Google/Mozilla I gu…
Might as well call out this company. it is Similarweb.
> We do not want ...
does not mean we do not do
> any data collected from you simply by your use of our product will never be used to figure out who you are or to send you targeted ads, and will not be shared with any other parties for those purposes.
does not mean impossible, yes, that's was not on purpose (like facebook cambridge analytica)
> Standard web server log information (i.e., page views)...
> ... browser type, operating system, device model name, device screen size, time and date. We further collect IP Address (trimmed for anonymization).
I can't process this.
Compared with Stylus [3]:
> Privacy Policy
> Unlike other similar extensions, we don't find you to be all that interesting. Your questionable browsing history should remain between you and the NSA. Stylus collects nothing. Period.
[1] https://robertheaton.com/2018/07/02/stylish-browser-extensio...
[2] https://userstyles.org/login/policy
[3] https://chrome.google.com/webstore/detail/stylus/clngdbkpkpe...
Re: Massive spying on users of Google's Chrome shows new security weakness
#196There is a web intelligence company in Israel that is known to buy popular browser extensions like “Web of Trust” and use them to exfiltrate browsing data (with tons of sensitive and personal information). They have been called out for this several times already and some of their extensions got removed from the store, they invariably turn back up again after a few weeks though (good connections to Google/Mozilla I gu…
Is there a list of extensions that have been caught exfiltrating data? I look at the 20 I've got installed and wonder which are using the "Access to every website" permission for their own ends.
Check Privacy Policy, if none exists it is either clear or non conformant. Extensions which states they collect data are not removed - for example Stylish, Web of Trust.
Re: Massive spying on users of Google's Chrome shows new security weakness
#197There is a web intelligence company in Israel that is known to buy popular browser extensions like “Web of Trust” and use them to exfiltrate browsing data (with tons of sensitive and personal information). They have been called out for this several times already and some of their extensions got removed from the store, they invariably turn back up again after a few weeks though (good connections to Google/Mozilla I gu…
These are strong words. Mozilla is miles ahead of chrome with recommended extensions [1]: > Recommended extensions undergo full code review by staff security experts to provide a strong additional security check. It has a list of blocked addons [2]. And I believe that is Chrome who turned addons into Wild West, Mozilla had a long review process [3]. [1] https://blog.mozilla.org/firefox/firefox-recommended-extensi...…
Re: Massive spying on users of Google's Chrome shows new security weakness
#198Earlier quoted context omitted.
In 2016 we proved that the owner of "Web of Trust" was exfiltrating and illegally selling clickstream data to anyone who would pay. For Germany alone the data contained the browing information of more than three million people, often revealing highly intimate and sensitive details about their lives. Still, Chrome and Firefox reinstated the extension after less than four weeks, and to this day it keeps collecting clic…
I am outsider interested in this topic, it would be great if you provided some links. I've found Web of Trust addon [1] and its Privacy Policy [2]: > Automatically Collected Information > Internet Protocol Address (trimmed to permanently remove specific location information other than country, city & postal code); device type; operating system and browser; Search engine results page (keyword, order/index of results,…
The data under "web pages visited and time stamp of the visit" is your clickstream data (you can check which data the extension sends using the network tab in the extension developer tools, though some extensions go to great lenghts to obfuscate it).
Re: Massive spying on users of Google's Chrome shows new security weakness
#199What extensions do you primarily use on Chrome (if you do)? My list (on brave) includes: >uBlock Origin >Decentraleyes >Stylus
Re: Massive spying on users of Google's Chrome shows new security weakness
#200Earlier quoted context omitted.
> What is the "tracking" aspect? See this post I made when X-Client-Header was introduced. > But they claim [1] this X-Client-Data header is used for experimenting with Chrome, not for tracking. They claim a lot of things. Sometimes they even modify their claims years after they first made them. Even if they were making 100% innocent claims now , they are not guaranteeing[2] they won't change how they use the data in…
> Google is saying they are tracking people with that header No they don't. Nothing in your comment sounds anything like Google claiming to be tracking people. And as mentioned elsewhere in this thread, they explicitly claim to not be tracking individuals.
>> "The information included in this header reflects the variations, or new feature trials, in which an installation of Chrome is currently enrolled. [...] it is not used to identify or track individual users."
I believe this statement is true. They are not using the X-Client-Data HTTP Header to track "individual users". As they state in their "Privacy Whitepaper"[3], a "low entropy variation" is
>> randomized based on a number from 0 to 7999 (13 bits) that's randomly generated by each Chrome installation on the first run.
This per-installation 13 bit id number is sent in HTTP requests to certain Google domains:
>> [...] a subset of low entropy variations are included in network requests sent to Google. [...] These are transmitted using the "X-Client-Data" HTTP header. [...] This header is used to evaluate the effect [of the variation (presumably?)] on Google servers [...]
Google is explicitly saying they are tracking the new 13 bit id number. This particular id number is somewhat low granularity, due to the limited bit length, which - as Google correctly claims in their statement to the press - is too small to "identify or track individual users". Regardless, they are still claiming they track a 13 bit identifier tied to "each Chrome installation".
I never said the X-Client-Data header was enough to track individuals. An IP address doesn't uniquely identify individuals either. Google's use of language is hoping you stop there. The header is too small to be identifying, so it doesn't matter! This framing is only true if you limit your questioning to considering the "low entropy variation" number in isolation. If that was the only number Google was able to track, it indeed wouldn't be concerning. However, that number is probably transported to Google over the internet in an IP Protocol packet, meaning they are at a minimum also receiving either a 32 bit (IPv4) or 128 bit (IPv6) identifier in the Source Address field of each packet's IP Protocol header.
Google doesn't need to use the X-Client-Data header to "identify or track individual users". They can simply use it to disambiguate different Chrome installs that share the same public IP address. This usage of the number isn't identifying users; it's only identifying the different Chrome installs e.g. behind a typical household stateful NAT router. Both the X-Client-Data header and the IP address are both not unique personally identifying IDs. However, the tuple {X-Client-Data, IPv4 Address} is probably unique for most people. In the rare instance where it isn't unique, one of the related tuples like {X-Client-Data, IPv4 Address, User-Agent} will be.
The doublespeak is pretending the header "will not contain any personally identifiable information" when the stated purpose of header is to create a new tracking identifier that accomplishes the same thing as a personally identifying identifier when you combine it with the other data that Google already tracks (such as the 24 bits of "anonymized" IP address (they zero the LSB) that they store with each GA record.
[3] https://www.google.com/chrome/privacy/whitepaper.html#variat...