Live data from Hacker News

8M users' AI conversations sold for profit by "privacy" extensions

koi.ai

241–250 of 261 posts

Re: 8M users' AI conversations sold for profit by "privacy" extensions

#241
post #184

I am surprised because google review team rejects half of my extensions and apps. Sometimes things don't make sense to me, like how "Uber Driver app access background location and there is no way to change that from settings" - https://developer.apple.com/forums/thread/783227

This might be a case of app permissions just being poorly delineated. E.g. I've seen Android apps require "location data" access just because they want to connect over bluetooth or manage WiFi or something (not entirely sure which one it was specifically) because that is actually the same permission and the wording in the permission modal is misleading.

They are the same permission because you can guess the user’s location using Bluetooth and WiFi.

Re: 8M users' AI conversations sold for profit by "privacy" extensions

#242

I stick to extensions that Mozilla has manually vetted as part of the Firefox recommended extensions program. > Firefox is committed to helping protect you against third-party software that may inadvertently compromise your data – or worse – breach your privacy with malicious intent. Before an extension receives Recommended status, it undergoes rigorous technical review by staff security experts. https://support.mozi…

The question is, does Mozilla rigorously review every single update of every featured extension? Or did they just vet it once, and a malicious developer may now introduce data collection or similar "features" though a minor update of the extension and keep enjoying the "recommended" badge by Mozilla?

> The question is, does Mozilla rigorously review every single update of every featured extension?

Yes.

Re: 8M users' AI conversations sold for profit by "privacy" extensions

#243
post #218

Earlier quoted context omitted.

There is no evidence whatsoever that having or not having inner monologue confers any advantages or disadvantages. For all we know, it's just two paths the brain can take to arrive at the same destination.

The comment (at least my reading of it) did not cast any judgement on whether this was a good or bad thing.

The response didn't suggest that it did.

Re: 8M users' AI conversations sold for profit by "privacy" extensions

#244

Earlier quoted context omitted.

If Google would care at all for their users, they'd tell WhatsApp to not require the use of the Contacts permission only to add names to numbers when you don't share the Contacts with the App. Or they'd tell WhatsApp to allow granting microphone permissions for one single call, instead of requesting permanent microphone permissions. All apps that I know of respect the flow of "Ask every time", all but Meta's app. Goo…

That's all opinionated, and the latter is part of the OS, not WhatsApp. Not liking how an app works does not compare to an app exfiltrating data without your consent.

Let me explain: my WhatsApp has no privileges granted. So when a call comes in, which is a very rare thing, I get asked to grant the microphone permission. So I grant it, but only for one time, and when Android hands back focus to WhatsApp, it won't just make use of the microphone, but re-ask for microphone access, so you go into the permissions intent but there it is already set to "only this time". Only if i change it to "when I am using the app", then it works, but that is not acceptable for me, because that background use is a passive use, which can access the microphone. This means that WhatsApp can enable the mic whenever it likes, which it cannot do if "only this time" is selected. But the app is against that. I do not know how they do this, but that is what happens.

Re: 8M users' AI conversations sold for profit by "privacy" extensions

#245
post #218

Earlier quoted context omitted.

The comment (at least my reading of it) did not cast any judgement on whether this was a good or bad thing.

The response didn't suggest that it did.

It absolutely did. Seems like you may be an example of exactly what they're discussing, and it looks disadvantageous to me.

Re: 8M users' AI conversations sold for profit by "privacy" extensions

#246

Earlier quoted context omitted.

The situation won’t be improved for as long as an incentive structure exists that drives the degradation of the user experience. Get as off-grid as you possibly can. Try to make your everyday use of technology as deterministic as possible. The free market punishes anyone who “respects their users”. Your best bet is some type of tech co-op funded partially by a billionaire who decided to be nice one day.

We're not totally unempowered here, as folks who know how to tech. We can build open source alternatives that are as easy to use and install as the -ware we are trying to combat. Part of the problem has been that there's a mountain to climb vis a vis that extra ten miles to take something that 'works for me' and turn it into 'gramps can install this and it doesn't trigger his alopecia'. Rather, that was the problem.…

I agree and with how much money people in this field can make I’m surprised their aren’t more retired hackers banding together to build something like this. Personally I still have a mortgage to pay off but eventually I would like to be involved in something like this.

Re: 8M users' AI conversations sold for profit by "privacy" extensions

#247
post #47

I don't understand why so many people are using / trusting VPNs "Let us handle all your internet traffic.. you can trust us.. we're free!" No thank you.

The use case is people that are urged to view something that is blocked (torrent / adult / gambling). They want it now, and they don't want to get involved with some shady company that slaps on a 2 year contract and keeps extending indefinitely. These people instead find "free vpn" in the web store and decide to give it a try. VPNs are just one example. How many chrome extensions do you have that you don't use all th…

Me personally? I'm using Firefox with EFF privacy badger. No others.

Re: 8M users' AI conversations sold for profit by "privacy" extensions

#248

Earlier quoted context omitted.

We're not totally unempowered here, as folks who know how to tech. We can build open source alternatives that are as easy to use and install as the -ware we are trying to combat. Part of the problem has been that there's a mountain to climb vis a vis that extra ten miles to take something that 'works for me' and turn it into 'gramps can install this and it doesn't trigger his alopecia'. Rather, that was the problem.…

I agree and with how much money people in this field can make I’m surprised their aren’t more retired hackers banding together to build something like this. Personally I still have a mortgage to pay off but eventually I would like to be involved in something like this.

What product(s) do you think present the best opportunity for reinventing today with a genuine, user-centric approach?

Personally I feel it's everything from the ground up - silicon IC's through to device platforms and cloud services. But we need a plan to chip away at the problem one bite at a time.

Re: 8M users' AI conversations sold for profit by "privacy" extensions

#249

Earlier quoted context omitted.

I agree and with how much money people in this field can make I’m surprised their aren’t more retired hackers banding together to build something like this. Personally I still have a mortgage to pay off but eventually I would like to be involved in something like this.

What product(s) do you think present the best opportunity for reinventing today with a genuine, user-centric approach? Personally I feel it's everything from the ground up - silicon IC's through to device platforms and cloud services. But we need a plan to chip away at the problem one bite at a time.

Probably a phone OS would be the most impactful. If it had the ability to really cut back on tracking and data sharing by default.

But if you’re talking about building hardware… that feels like something the NSA would be happy to be involved with whether you want them to be or not. I’d vote for an 80/20 solution that gets people protected from some of the most rampant data mining going on by corporations vs. state actors.

The other issue to keep in mind is that the tech ecosystem absolutely will suffocate anything like this by disabling access to their apps / website with this OS. So at the end of the day I really don’t know if there’s a solution to any of this.

Re: 8M users' AI conversations sold for profit by "privacy" extensions

#250
post #205

> A free VPN promising privacy and security. If you are not paying for the product, you are the product.

Can we please, please stop using this absolutely deprecated proverb? As shown in YouTube lite, Samsung fridges with ads, cars with telemetry etc. etc. even if you paid, you are still subject to manipulation, spyware, ads and telemetry. It has absolutely nothing to do with payment.

While that’s not untrue, I think one ought to be extra suspicious if you get something of value (eg VPN software that guarantees privacy and security, in this particular case), that cost the operator money but you get it for free.

Perhaps a better proverb would be: there ain’t no free lunch.

Post reply on HN