Live data from Hacker News

Massive spying on users of Google's Chrome shows new security weakness

reuters.com

221–230 of 270 posts

Re: Massive spying on users of Google's Chrome shows new security weakness

#221
post #213

Earlier quoted context omitted.

It's still so easy in Firefox to install add-ons that spy on your entire browser session and send tons of telemetry data to a backend (Ghostery is a popular example) while the user has no clue that any kind of data transfer even happens. Such behavior shouldn't be something that can be turned on with two clicks.

Ghostery is even a recommended Addon on AMO [1]. What would really be practical were some kind of extension analyzer/profiler that runs newly installed addons in a sandbox and displays attempted connections and payloads. Or a mode where connections need to be whitelisted, to limit the impact of silent addon takeovers. Too many times I find myself having to download, unpack, and skim through an addon's source to make…

They state it in plain site. Sadly it is not advertised clearly.

Yes, that would be good. I would love to hear that someone I trust checked latest version. If enough people joined we can make distribution.

And, hey! It is MPL-2 [1], bad defaults can be patched.

[1] https://github.com/ghostery/ghostery-extension

Re: Massive spying on users of Google's Chrome shows new security weakness

#222

Earlier quoted context omitted.

The only trustworthy extensions are uBlock Origin and EFF's Privacy Badger. Everything else is best viewed as potential malware, no different than random downloadable executables. Honestly, uBlock Origin and Privacy Badger are so important at this point they should just become part of the browser itself. They're already in a league of their own.

For those who like uBlock origin, you owe it to yourself to also checkout uMatrix. I use both.

I use both, and it's amazing what origin night let through that i can granularly stop with matrix.

Re: Massive spying on users of Google's Chrome shows new security weakness

#223

I would pay money for an extension that keeps track on datatraffic of other installed extension and creates firewall rules (or something equivalent) based on my permission/deny. (I know that this is the other way around, but apparantly chrome isn't fixing these data issues...)

While I only have limited experience writing extensions, this seems doable. You can most definitely add a hook for every outgoing request, though I'm not sure if the browser lets you know the origin of the request, i.e. the browser window or an extension. If it could, at the most basic level it could write outgoing data to a log file.

AFAIK this is not possible. I don't think you can block request made by other extensions. I assume the API you were referring to is https://developer.mozilla.org/en-US/docs/Mozilla/Add-ons/Web...

Re: Massive spying on users of Google's Chrome shows new security weakness

#224
post #63

Earlier quoted context omitted.

Yeah, and that sounds totally plausible. That Google need to send "experimental headers" to a hardcoded domain for an advertising company they bought a decade or so back - because of course the results of web browser experiments should go to an advertising company (or these days th advertising division of a company) ad not, say, to google's own domain? /s Google are totally lying here.

You realize that the tracking headers are headers as part of the requests that you were already making to doubleclick. So, what's happening here is that if you make a request to doubleclick (say because you're viewing an ad), extra information is included that allows Google to understand which experiments were enabled on your browser. If you never go to doubleclick yourself, chrome won't ever send data to it. It's no…

You should probably disclose in this comment thread that you work for Google.

Re: Massive spying on users of Google's Chrome shows new security weakness

#225
post #138

There is a web intelligence company in Israel that is known to buy popular browser extensions like “Web of Trust” and use them to exfiltrate browsing data (with tons of sensitive and personal information). They have been called out for this several times already and some of their extensions got removed from the store, they invariably turn back up again after a few weeks though (good connections to Google/Mozilla I gu…

I feel like this argument is the same as ‘how third party apps are allowed in windows and macOS by Microsoft and Apple’ To me there has always been a trusted part of computing which is audited to some extent and marked as trusted. Browser extensions work the same way as software on an operating system. If they blocked all extensions outside trusted ones they would be criticised as well. However the auditing process i…

I think the difference here is that browser extensions are distributed through a package manager provided by the browser vendor. People expect the vendor to perform some sort of security validation on apps that it is effectively publishing. You can't reasonably have the same expectation for binaries downloaded from a website.

Re: Massive spying on users of Google's Chrome shows new security weakness

#226

There is a web intelligence company in Israel that is known to buy popular browser extensions like “Web of Trust” and use them to exfiltrate browsing data (with tons of sensitive and personal information). They have been called out for this several times already and some of their extensions got removed from the store, they invariably turn back up again after a few weeks though (good connections to Google/Mozilla I gu…

The only trustworthy extensions are uBlock Origin and EFF's Privacy Badger. Everything else is best viewed as potential malware, no different than random downloadable executables. Honestly, uBlock Origin and Privacy Badger are so important at this point they should just become part of the browser itself. They're already in a league of their own.

Also HTTPS Everywhere and, in Firefox, NoScript.

Re: Massive spying on users of Google's Chrome shows new security weakness

#227

Earlier quoted context omitted.

How many people are looking at the code ? The github commits show only one active contributor. I use uBlock Origin myself but I sometimes question the faith we place on open-source. We assume someone else is looking at the code.

It would be awesome if there was a volunteer financed code review group to review popular open source projects. I think I’m not the only one who would happily donate money to such a group for code reviews for various OSS projects. Initial code reviews would require a lot of effort, unless somehow automated, but after that it would be fairly easy to monitor and verify updates and changes to the code.

Maybe on top of existing practice? Debian packages some addons [1], I don't know do they perform audit [2] on them.

[1] https://packages.debian.org/search?suite=default&section=all...

[2] https://www.debian.org/security/audit/auditing

Re: Massive spying on users of Google's Chrome shows new security weakness

#228

Earlier quoted context omitted.

Do you really believe this is even vaguely close to true? To a first approximation, _nobody_ "goes to doubleclick themselves". At the same time, back in 2016 a study at Princeton found almost 50% of all sites on the web had Doubleclick on them (this is separate to the 70% of sites running Google Analytics - and I'd bet there's approximately zero sites that serve doubleclick ads/trackers but not google analytics ones,…

You've contradicted yourself in the first 3 lines. > At the same time, back in 2016 a study at Princeton found almost 50% of all sites on the web had Doubleclick tracking on the Means that many people are going to doubleclick, via it's ads existing on other sites. If the extent of your concern is that I said "going to" instead of "makes requests to", valid and I apologise for not being precise in my use of language.…

I hope there is generally less rationalization at Google towards privacy practices to be honest.

I think the behavior on display is pretty sneaky, undermines privacy and users aren't really informed about Google doing "research" on them.

Re: Massive spying on users of Google's Chrome shows new security weakness

#229

Earlier quoted context omitted.

In 2016 we proved that the owner of "Web of Trust" was exfiltrating and illegally selling clickstream data to anyone who would pay. For Germany alone the data contained the browing information of more than three million people, often revealing highly intimate and sensitive details about their lives. Still, Chrome and Firefox reinstated the extension after less than four weeks, and to this day it keeps collecting clic…

I am outsider interested in this topic, it would be great if you provided some links. I've found Web of Trust addon [1] and its Privacy Policy [2]: > Automatically Collected Information > Internet Protocol Address (trimmed to permanently remove specific location information other than country, city & postal code); device type; operating system and browser; Search engine results page (keyword, order/index of results,…

The initial part perhaps falls into the widely accepted consensus of monitoring usage, but an extension collecting all"web pages visited and time stamp of the visit" crosses the boundary to totally unacceptable.

Re: Massive spying on users of Google's Chrome shows new security weakness

#230

Earlier quoted context omitted.

Here's a talk from 33C3: https://media.ccc.de/v/33c3-8034-build_your_own_nsa The data under "web pages visited and time stamp of the visit" is your clickstream data (you can check which data the extension sends using the network tab in the extension developer tools, though some extensions go to great lenghts to obfuscate it).

Danke schön. Schade, aber mein Deutsch ist nicht so gut. Most of the users live in Privacy Nightmare and accept it. They also run closed source OS and applications. The truth is privacy has a cost - monetary (Apple ecosystem) or time/experience (Linux etc). Apple can hire maintainers, Linux users can become maintainers. Those who live in free as beer land has free as beer support.

There's an English translation available btw!
Post reply on HN