Live data from Hacker News

uBlock Origin GPL code being stolen by team behind Honey browser extension

old.reddit.com

451–460 of 469 posts

Re: uBlock Origin GPL code being stolen by team behind Honey browser extension

#452
post #429

Earlier quoted context omitted.

> Cookie stuffing is criminal fraud There is no disagreement about that. Murder is also criminal. The disagreement is whether what Honey did classifies as "cookie stuffing". (I hope there is no disagreement that it does not qualify as murder, which is a different crime.) > Obtaining money by means of false or fraudulent pretenses is wire fraud. This is ... not the definition of what "wire fraud" is, but let's leave i…

A distinction without a difference. It's functionally the same whether you store the same referral info elsewhere and stuff the cookies "just in time" vs stuffing the cookies all at once beforehand. Functionally the extension is inserting itself as a second impromptu persistence mechanism ("cookie jar"), allowing it to stuff its cookies at a different phase of the e-commerce flow. Slightly altered mechanism, same eff…

Similar actions can result in different verdicts. For example, an act of firing a gun on one end and having a dead body on the other can result in a whole variety of verdicts, which includes (but not limited to) “terrorism”, “murder”, “killing”, “negligence”, or “self-defense”. You can have several functionally identical cases — e.g. same gun, same ammunition, same wounds, etc. - and still end up with a variety of verdicts, from “not guilty” to “death sentence”.

Re: uBlock Origin GPL code being stolen by team behind Honey browser extension

#453

Google removed chrome extensions that do cookie stuffing before: https://www.zdnet.com/article/google-removes-two-chrome-ad-b... PayPal's Honey extension should be pulled by Google for doing the exact same thing. There is no difference and Honey shouldn't get special treatment just because it's owned by PayPal. --- UPDATE: It's criminal wire fraud. Brian Dunning sentenced to 18 months jail for cookie stuffing: https:…

but they provide coupons and stuff. So it's more a "service", and they get their cut by offering "refferals".

Re: uBlock Origin GPL code being stolen by team behind Honey browser extension

#454

Is there a better option to Honey? The extension has saved me a good bit of money over the years, especially on newer and independent sites that sometimes offer deep discounts for your first order. But it does seem like the coupon codes come from the community and there should be a community version of the extension.

Honey actually hides the best deals from you at the site's request. You'd be better off finding the codes yourself.

I'd rather get 10% off automatically instead of 15% off if I have to spend 30 minutes on every single purchase trying dozens of dead codes from various sites. It being automated is the entire point.

Re: uBlock Origin GPL code being stolen by team behind Honey browser extension

#455

Google removed chrome extensions that do cookie stuffing before: https://www.zdnet.com/article/google-removes-two-chrome-ad-b... PayPal's Honey extension should be pulled by Google for doing the exact same thing. There is no difference and Honey shouldn't get special treatment just because it's owned by PayPal. --- UPDATE: It's criminal wire fraud. Brian Dunning sentenced to 18 months jail for cookie stuffing: https:…

This reminds me of how as times changed, once illegal behaviors are now considered normal because "big tech" embraced it.

Remember Kazaa, BonziBuddy, Gator (The OG adware), etc.? They were demonized for collecting data on all the web traffic you were doing it. They got sued by the FTC and were forced to change their business models and/or close down.

Then Facebook, Google came along and did the same thing in the early 2010's except via cookies and Javascript, but somehow that's ok. Even worse, it's considered a normal business practice.

It amazes me that Honey has been able to become so popular given it's business model has always been more of a hack than an actual product. How did commission programs not sue them for fraud?

Probably because they had good ole Silicon Valley VC money to scare them off.

Re: uBlock Origin GPL code being stolen by team behind Honey browser extension

#456

Earlier quoted context omitted.

> as I watched the video all I could think was "what the fuck did you think they were doing?". Well, not screwing over their partners and customers? They didn't have to overwrite existing affiliate codes to make lots of money. And the stuff you list in your last sentence is a really big deal.

Yeah, you're right about them not having to rewrite existing ones. They could've only inserted affiliate codes when there weren't existing ones. It's less that I think it's OK, more that I'm unsurprised.

No, cross site cookie reading were banned for a reason. A site can only read its own cookies now.

Re: uBlock Origin GPL code being stolen by team behind Honey browser extension

#457

Earlier quoted context omitted.

I'm with you until the final sentence. From my perspective, that's the current state of software development. Hundreds of megabytes of JavaScript and "assets" for what could be a 60KiB bundle of HTML, or a 500KiB Win32 program.

Forgot the name, but it's a variant of Hawthorne's laws for computers. If tech gets faster, programs will work to fill that newfound space and performance. even if it's just a simple web text page. But no one complains and it lets them ship faster. So not much will change here.

It's called Wirth's law.

Re: uBlock Origin GPL code being stolen by team behind Honey browser extension

#458

Earlier quoted context omitted.

Yeah, you're right about them not having to rewrite existing ones. They could've only inserted affiliate codes when there weren't existing ones. It's less that I think it's OK, more that I'm unsurprised.

No, cross site cookie reading were banned for a reason. A site can only read its own cookies now.

It's a browser extension. It can check the current state of the store page.

Re: uBlock Origin GPL code being stolen by team behind Honey browser extension

#459
post #285

If piracy isn't 'stealing' neither is this, since the original code is still available.

You are not making money off the product when doing piracy. In this case they stole the code to make money off it which is very different

Money has nothing to do with it. The justification for piracy has always been that the original work is still there, so it's not considered theft.

Not only is the original GPLd code still there, the owner of that code didn't have the money in their pocket, so nothing was actually 'stolen'.

It's why I support using GPLd code in proprietary applications. This team just got sloppy and copy/pasted. They should have hired me and I would have made it virtually untracable.

Re: uBlock Origin GPL code being stolen by team behind Honey browser extension

#460
post #452

Earlier quoted context omitted.

A distinction without a difference. It's functionally the same whether you store the same referral info elsewhere and stuff the cookies "just in time" vs stuffing the cookies all at once beforehand. Functionally the extension is inserting itself as a second impromptu persistence mechanism ("cookie jar"), allowing it to stuff its cookies at a different phase of the e-commerce flow. Slightly altered mechanism, same eff…

Similar actions can result in different verdicts. For example, an act of firing a gun on one end and having a dead body on the other can result in a whole variety of verdicts, which includes (but not limited to) “terrorism”, “murder”, “killing”, “negligence”, or “self-defense”. You can have several functionally identical cases — e.g. same gun, same ammunition, same wounds, etc. - and still end up with a variety of ve…

The difference is intent.

It's the same intent in both cookie-stuffing cases.

Thanks, I should have pointed that out before.

Post reply on HN