Live data from Hacker News

Massive spying on users of Google's Chrome shows new security weakness

reuters.com

251–260 of 270 posts

Re: Massive spying on users of Google's Chrome shows new security weakness

#251

Earlier quoted context omitted.

While I only have limited experience writing extensions, this seems doable. You can most definitely add a hook for every outgoing request, though I'm not sure if the browser lets you know the origin of the request, i.e. the browser window or an extension. If it could, at the most basic level it could write outgoing data to a log file.

AFAIK this is not possible. I don't think you can block request made by other extensions. I assume the API you were referring to is https://developer.mozilla.org/en-US/docs/Mozilla/Add-ons/Web...

I wasn't sure if you could identify the origin of the request, I guess it makes sense that would not be possible or it could end up being cat and mouse between extensions.

For me specifically I had done some work with Firefox extensions, pre-quantum.

Re: Massive spying on users of Google's Chrome shows new security weakness

#252

Earlier quoted context omitted.

Would be good training for apprentices too. Reading code is probably one of the best ways to learn. Granted, it could include a sophisticated and obfuscated backdoor, but I think it would still be caught.

I wouldn't be so sure that it's an inevitability that things would be caught. The "underhanded C contest" [1] is a good example of this and something I like to point people to. From their about page: >The Underhanded C Contest is an annual contest to write innocent-looking C code implementing malicious behavior. In this contest you must write C code that is as readable, clear, innocent and straightforward as possible…

Ok, those might indeed not be found. Only fair that they could take something from my wallet then.

That is an awesome site, thanks. Sadly the contest seems to have stopped in 2014.

Re: Massive spying on users of Google's Chrome shows new security weakness

#253

Earlier quoted context omitted.

1. I just said it is good if at least subset can be trusted. It would be nice to have such feature in Chrome. 2. Sorry, could you please make your point clear (edit)? Firefox third party extensions used to access internal constructs. I think most of what is Firefox on top of Gecko is privileged extensions. 3. Yes, Firefox had addons with review process.

2. I'm talking about the switch to WebExtensions, https://wiki.mozilla.org/WebExtensions/FAQ , which every major browser followed Chrome in doing, which was largely done for security reasons 3. Firefox does not manually review every extension, they perform some cursory virus/malware scans, same as Google. I think you're really overplaying the idea that Firefox has some manual review process ensuring only quality and…

2. My understanding that nothing has changed much. Mozilla forbidden internals access to 3rd party developers, mostly driven to ease refactoring - completing the drop of non Firefox browsers started in 2008 [1]. Those who need (and were allowed) these API (like Developer tools) moved in tree. Others have to use new API which for compatibility reasons looks like Chrome.

3. Today looks like every browsers gallery dropped security. I was talking about days before Chrome and how things changed. I gave a link, there were just several blocked addons in 2008-2010. Something changed and I remember publishing process was different in Firefox and Chrome. Search gives me no complains about long review in 2010 for Chrome.

I am not Mozilla funboy. I do not think that Mozilla actions is enough, Chrome had good things too - reviews without "I like it" and "Works for me". Everyone deploys automatic scan. Manual review is better than no manual review. How many extensions from Recommend list were blocked?

We have to find a way to reduce pressure to buy/sell addon for use as spyware. Someone has to think twice before trying to buy Recommended addon. Or looking on a list of blocked addons. Or maybe someday "Collects data" badge. Today Mozilla is ahead, just copy and move on.

[1] Mike Pinkerton on Mozilla and Camino https://www.youtube.com/watch?v=ttiZevbtvf0

Re: Massive spying on users of Google's Chrome shows new security weakness

#254
post #59

Earlier quoted context omitted.

Argentinian here, can confirm. Just look up Nisman death AMIA bombing.

I know a little bit about that saga, but who are you accusing the Israeli government of blackmailing?

Anyone and everyone. One of the reasons they don't have a single true ally.

Re: Massive spying on users of Google's Chrome shows new security weakness

#255

I feel like Google Chrome should just have some icon or other visual indicator of when an extension has made a networking request. In addition, use the iOS model of permission and prompt the user when it wants to do something like access the network or read your browsing history. Perhaps if this happens on a frequent basis, give another indication that it's happening all the time with the ability to ignore such warni…

Most people would click on any warning without even reading, unfortunately.

Which is why I say "You need to repeatedly show such evidence to users for them to understand what's happening."

But showing the warning at least lets the more sophisticated people know what's up, and alerts them sooner that an extension that they previously trusted in one context now is doing something unexpected post-update.

Re: Massive spying on users of Google's Chrome shows new security weakness

#257

Earlier quoted context omitted.

For me it's honest author. I don't trust code, I trust people.

I used to trust the authors of unlock, adblock, adblock origins. But they all sold out. Why do you think this time it's different?

Gorhill isn't doing it for money, he's doing it because he believes in an internet where "user agent" means something. He engages in numerous ways with the community. You're sort of asking "How can I trust Gorhill?", and I guess my answer is "How can you trust _anyone_?" I trust Gorhill with this task more than I trust Mozilla, Google, Brave, or any extension put out by a company. Whether that level of trust exceeds a particular individual's thershold is a personal choice, naturally. To echo the sentiment above, I trust a person, but not code, and not companies. This approach is certainly not bulletproof, but it's the best I've found.

Re: Massive spying on users of Google's Chrome shows new security weakness

#258

Earlier quoted context omitted.

I know a little bit about that saga, but who are you accusing the Israeli government of blackmailing?

Anyone and everyone. One of the reasons they don't have a single true ally.

The person I was asking had brought up the death of Alberto Nisman and the investigation into the AMIA bombing in response to a statement that Israel "uses blackmail as a foreign policy tool". It seems to me like people make vague accusations against Israel without being specific about what exactly Israel allegedly did, and when challenged to be more specific they don’t respond.

I have an open mind about whether any particular allegation against Israel (or any other country) is true, but if people won't make the allegation specific it is impossible to judge.

Re: Massive spying on users of Google's Chrome shows new security weakness

#259
post #174

Earlier quoted context omitted.

If Google can't keep things quiet, where can I find a rough list of factors DoubleClick uses in order to track users? Has any of those factors leaked in the past? Would anyone on the ad team at Google jeopardize their $350k per year to leak unethical behavior in that division? There's plenty ambiguous about that statement. Firstly, it doesn't cover past or future. Room for weaseling there. Secondly, it specifically s…

> If Google can't keep things quiet, where can I find a rough list of factors DoubleClick uses in order to track users? Do you mean like, categories into which it divides users (age, gender, interest), in which case a reasonable answer is https://adssettings.google.com/ or do you mean what request attributes it uses to make these determinations initially and tie them to particular users? In which case the answer is p…

>How can something be a factor in ad targeting without being used to target individuals?

Really weird question. Easy. The tracking ID sent to DoubleClick could be used to target groups of people, such as "people who rarely update their browser". Such heuristics can indicate age, tech knowledge, etc.

No other browser is doing this. Why does Google need to send such tracking information to DoubleClick? You cannot justify it without also explaining why Safari and Firefox don't need this.

Coupled with Google's other self-dealing behavior such as refusing to crackdown on egregious third-party cookies like Safari and Firefox, then this is starting to look very suspicious.

For me personally, the fact this data is even being sent is the smoking gun. Shifting the goalposts to "well we don't abuse it" is classic gaslighting. You don't need to send tracking information to an advertising network.

Why should I trust an advertising network with a hard-coded, impossible to disable, opaque tracking backdoor in the first place?

Google does not disclose it does this. Google provides no way to opt out. Google has not adequately explained why it needs to send it to DoubleClick, given Google Analytics. Google snuck this into the Chromium source code hoping nobody noticed.

Re: Massive spying on users of Google's Chrome shows new security weakness

#260

Earlier quoted context omitted.

You're a Google employee, and you're vociferously defending Google's use of a tracking header in Chrome. Others deserve to know your conflict of interest so that they can read your arguments in the right context.

I disclosed that in the comment this user was commenting in response to, before they commented. In other words, they accused me of shilling in reply to a comment where I openly and willingly clarified my relationship with Google. It is possible to ask someone to, or disclose for someone, a conflict of interest, without breaking the HN guidelines. The comment did neither.

Do you work primarily on ads or DoubleClick at Google? Would you stake your own reputation on this tracking ID not being using in any behavioral, group or user tracking algorithm at DoubleClick or any other ad system at Google?
Post reply on HN