Live data from Hacker News

Amazon Assistant lets Amazon track your every move on the web

palant.info

41–50 of 67 posts

Re: Amazon Assistant lets Amazon track your every move on the web

#41

This place is becoming like Reddit with the conspiracy theories

Except he gives technical proof how this is done.

No, it's not possible to see what Amazon does with this information but it's clear they can do way too much. And, they can change the behaviour at any moment without the user getting notified within these existing wide permissions. At the very least it's very poor design.

Re: Amazon Assistant lets Amazon track your every move on the web

#43

Seems to me that browser extensions need better access control. Why isn't it possible to restrict it to just amazon.com itself, for example?

If the dominant web browser wasn't an ad company, browser extensions would not exist in the way they do today. Because any responsible security engineer would nuke browser extensions from orbit, but currently everyone who isn't an ad company has to maintain feature parity with the ad company for competitive reasons.

They are by far the most risky thing one could possibly put on a PC. They essentially remove any alleged benefit to HTTPS/encryption or anything of the sort, because they live inside your web browser and have post-decryption access, often to every website you visit and everything you enter into them.

Do not use browser extensions. Ask your IT person to restrict the ability to install browser extensions.

Re: Amazon Assistant lets Amazon track your every move on the web

#45

Seems to me that browser extensions need better access control. Why isn't it possible to restrict it to just amazon.com itself, for example?

If the dominant web browser wasn't an ad company, browser extensions would not exist in the way they do today. Because any responsible security engineer would nuke browser extensions from orbit, but currently everyone who isn't an ad company has to maintain feature parity with the ad company for competitive reasons. They are by far the most risky thing one could possibly put on a PC. They essentially remove any alleg…

Huh? From my point of view extensions like uBlock Origin and 1PasswordX further enhance and secure my browsing, with uBO I'm blocking ads and trackers (including malicious ones) and with 1Pass I get secure form fill.

Novelty extensions are a completely different story but I wouldn't go so far as to ban all extensions ever.

Re: Amazon Assistant lets Amazon track your every move on the web

#46

Earlier quoted context omitted.

If the dominant web browser wasn't an ad company, browser extensions would not exist in the way they do today. Because any responsible security engineer would nuke browser extensions from orbit, but currently everyone who isn't an ad company has to maintain feature parity with the ad company for competitive reasons. They are by far the most risky thing one could possibly put on a PC. They essentially remove any alleg…

Huh? From my point of view extensions like uBlock Origin and 1PasswordX further enhance and secure my browsing, with uBO I'm blocking ads and trackers (including malicious ones) and with 1Pass I get secure form fill. Novelty extensions are a completely different story but I wouldn't go so far as to ban all extensions ever.

I would say any feature worth building as an extension should be a browser feature (like Edge and Firefox have brought ad/tracker blocking). An extension or two for critical functionality is fine if you really, really trust the source, but the default should be hostile to extensions.

Re: Amazon Assistant lets Amazon track your every move on the web

#48
post #47

I designed this. I won't speak to any past or current practices, but I will say this: Amazon is obsessive about protecting customer privacy.

> protecting customer privacy

Does "privacy" mean Amazon will spy on their customers, but won't share that data further?

Re: Amazon Assistant lets Amazon track your every move on the web

#50

> Putting these JavaScript files into the extension would have been possible with almost no code changes The AMO team at Firefox used to outright ban addons with remote script injection. I guess it matters who you are -- like on the Apple App Store, big names just need to pull the right strings or call the right people for a free pass. Rules are not applied equally. The playing field is NOT level.

The AMO team used to review every submitted add-on. They no longer do, now it just says “This add-on is not actively monitored for security by Mozilla. Make sure you trust it before installing.” on virtually every add-on. They still enforce this policy, but usually only when someone reports an add-on violating it. I reported this add-on, we’ll see now when/how they take action.

Note: I’m the author of this article and a former AMO reviewer.

Post reply on HN