Live data from Hacker News

Our Copyfish extension was stolen and adware-infested

a9t9.com

211–217 of 217 posts

Re: Our Copyfish extension was stolen and adware-infested

#211
post #196

Earlier quoted context omitted.

It's interesting, if you go to the support tab and follow the link to the maker's support website, you end up on https://spoofer-extension.appspot.com/ The contact page there links to "Glenn Willson" as the author - and their G+ page has a link to The User-Agent Switcher Has A New Owner: Google! http://www.glennwilson.info/2017/02/the-user-agent-switcher-... Now, is that trustworthy or not? Good question.

Search for an official Google Chrome extension (such as Chrome Remote Desktop). You'll see a 'By Google' logo ( https://chrome.google.com/webstore/category/collection/by_go... ) as well as an 'offered by google.com'. This just has the 'offered by google.com'. I would have assumed a 'By Google' logo would have been added after acquisition?

If you go to the listing of all Google extensions (the URL you linked) and open the "Chrome Sign Builder" Extension, go to Related -> "More from this Developer" you will find the User-Agent Switcher for Chrome. So it does seem legit.

Re: Our Copyfish extension was stolen and adware-infested

#213

Earlier quoted context omitted.

>> The only real defense is to glance at the url bar every time you're about to enter your password With Google specifically, the worst part is you really do have to look at the URL every single time you go to enter your password. And by that I mean that if you land on the login page, verify the URL, enter your password, submit, and get the error page saying you got the password wrong... you must check the URL again…

Pretty sure Google and other sites will do another 2FA challenge when you try to remove or change the 2FA challenge.

Most do not, and even Google doesn't. I just verified on my account. You only need to provide your password to access account settings. Completely stripping all two-factor authentication requires no additional 2FA code.

Re: Our Copyfish extension was stolen and adware-infested

#214
post #185
post #120

Earlier quoted context omitted.

I don't trust any of the 2FA providers. And I have neither the time nor the interest to try and learn to code it in binary.

TOTP is a specification and there are many free software implementations. U2F is also a specification (but generally they aren't free software implementations).

Again - I don't trust the people who created the specifications; and I don't trust either the free implementors or the non-free ones, though my inclination would be to go with non-free if I were forced. As it is, I simply don't use services that rely on them.

Re: Our Copyfish extension was stolen and adware-infested

#215
post #61

Earlier quoted context omitted.

Sorry to tell you, does show up as apple.com in my browser. Chrome 52.0.2743.82-1 on Arch x86_64.

The IDN vulnerability was fixed by Google in Chrome 58. https://arstechnica.co.uk/information-technology/2017/04/chr... https://bugs.chromium.org/p/chromium/issues/detail?id=683314 Why have you got such an old version of Chrome?

Thank you. That gives me a strong reason to update.

To answer your question, (1) it's pretty arduous to install Chrome from the AUR, and (2) I am wary of Google removing useful functionality from Chrome.

Re: Our Copyfish extension was stolen and adware-infested

#216

I guess this is as good a place as any to post that I noticed something similar had happened to [User-Agent Switcher for Google Chrome]( https://chrome.google.com/webstore/detail/user-agent-switche... ) and [Block Site]( https://chrome.google.com/webstore/detail/block-site/eiimnmi... ). The "report abuse" link on the page is useless. The former is very insidious in that it actually hides the malware in a .jpg file th…

Wow, I went to try and add a 1-star review to each to warn users (since both have extremely high ratings) and you need to install the malware-ridden extension to leave a review. So we have a web store that that average Chrome users think is "safe," especially when apps have high review scores, and no meaningful ability to report malware to Google or to the users. Nice.

There is literally a 'Report Abuse' button about two inches below the download button. That's what you use in this case. Being able to leave a review of something you haven't tried would just be silly.

Re: Our Copyfish extension was stolen and adware-infested

#217

Earlier quoted context omitted.

> I was looking for a bulk downlowned about a week ago, and the only ones I found requested "Read data from all websites", which is a lot of trust to put in something I have limited ability to test/know if it is malicious. AIUI that's a consequence of the Chrome extension security model. How could a bulk-downloader extension download files from arbitrary web sites without "Read[ing] data from all websites"? Compare t…

> AIUI that's a consequence of the Chrome extension security model. How could a bulk-downloader extension download files from arbitrary web sites without "Read[ing] data from all websites"? What I was hoping for was something along the lines of " wants to access this page" (similar to the notification when a website tries to access your location) upon use. I've no idea if that's possible or not in the Chrome security…

I don't think it currently is. I guess that would work, if you didn't mind a lot of popups every time you visit another web page... :)
Post reply on HN