Live data from Hacker News

Adware vendors buy Chrome Extensions to send ad- and malware-filled updates

arstechnica.com

51–60 of 111 posts

Re: Adware vendors buy Chrome Extensions to send ad- and malware-filled updates

#51
post #46
post #2

Can we start a petition for Google to let us disable extensions on specific sites? After reading the last few stories about this, I am quite sure I don't want any extensions whatsoever running in the same tab as my Gmail account. I think there is some extension that does this for you (turns off other extensions per site), but then we get into a "who guards the guardians" situation. Not to mention we need better and f…

Chrome doesn't run extensions by default in incognito mode. > Because Google Chrome does not control how extensions handle your personal data, all extensions have been disabled for incognito windows. You can reenable them individually in the extensions manager. Keeping your gmail tab in an incognito window might be a good approach.

Or just using thunderbird. I can't be the only one who doesn't like gmail's wonky interface.

Re: Adware vendors buy Chrome Extensions to send ad- and malware-filled updates

#52
post #32
post #24

Why use any extensions ever ?

Because extensions can provide useful functionality that's not provided by the browser. For instance, ad blocking or developer tools.

Chromium has all the dev tools I need OOTB. Adblock? Perhaps one risk I'll take on extensions. What else? Nothing. Unnecessary shit for people who want to configure every detail but can't be bothered to hack it themselves with uzbl or one of its equivalents.

Re: Adware vendors buy Chrome Extensions to send ad- and malware-filled updates

#53
post #14

It's not just a DOM change problem. What if an extension change owner and start sending pairs (domain/user's credentials) to someone else? What if one buy an extension to get bank sites accesses?

What's surprising is that extensions are by default not "Allowed in incognito", however they are allowed when using HTTPS and there is no option to disable them there.

Opera seems to allow this (and it seems to give a bit more fine grained control over when/where extensions are allowed).

Re: Adware vendors buy Chrome Extensions to send ad- and malware-filled updates

#54
post #40

From the comments: It sounds like Google needs to flag ownership changes and NOTIFY USERS about them before the next auto-update of that extension. ------------ NoteBuddy has been transferred from Joe Garage to Russian Mafia LLC. Do you want to keep this extension enabled? [ Da ] [ Nyet ] ----------- - DaveSimmons While this may seem like the most convenient step, it's actually not that simple either. The majority of…

[deleted]

Re: Adware vendors buy Chrome Extensions to send ad- and malware-filled updates

#55
There is an easy solution:

Follow http://superuser.com/questions/290280/how-to-download-chrome... in order to download the crx file manually.

Then unzip it and vet it manually to be clean.

Copy it in a folder, enable extension developer mode in Chrome and install the local copy of the extension.

No autoupdate, everything's fine.

Unfortunately Google plans to disallow local extensions, which is a major disaster and very evil: http://thenextweb.com/google/2013/11/07/google-block-local-c...

What happened to that?

Re: Adware vendors buy Chrome Extensions to send ad- and malware-filled updates

#56
I had similar problem few days ago ...

I'm using "Super Awesome New Tab Page" for Chrome, and since few days ago random ads started popping on youtube, ebay, dx.com, amazon etc ... Took me ~30 mins to figure out which extension it was, and removed it... They also injected tags to ALL websites I visited (that loaded external JS), tracking my history and they could easily put any form/input logging and silently insert keylogger into my Chrome if they wanted. I have reported the extension then, but nothing happened yet.

Link: https://chrome.google.com/webstore/detail/awesome-new-tab-pa...

Re: Adware vendors buy Chrome Extensions to send ad- and malware-filled updates

#57
post #55

There is an easy solution: Follow http://superuser.com/questions/290280/how-to-download-chrome... in order to download the crx file manually. Then unzip it and vet it manually to be clean. Copy it in a folder, enable extension developer mode in Chrome and install the local copy of the extension. No autoupdate, everything's fine. Unfortunately Google plans to disallow local extensions, which is a major disaster and ve…

I mistakenly installed a Minecraft modloader for my son without checking it out first. It silently installed a couple of local Chrome extensions that injected ads in every page. It would reinstall them (again, silently) every time you deleted them. It wasn't detected by Microsoft Defender or Avast until I ran Malwarebytes which took care of the problem.

So, pardon my french, but no freaking way do I want any local Chrome extensions allowed by default anymore.

For extensions from the Chrome store, perhaps Chrome should make updates more like on Android, where you are notified and can click for more info.

Re: Adware vendors buy Chrome Extensions to send ad- and malware-filled updates

#58
post #5

This is a disturbing situation, but it's hard to say what the best way of dealing with it is. The first thing most people reach for first is that extensions shouldn't auto-update. Personally, I disagree - I love silent auto-updates in general. It's a huge drag on the computing experience to have dozens of different widgets all requiring manual updates, all with different mechanisms and all on their own schedules. If…

Minor nitpick: you're romanticizing what the autoupdate policy achieves, it does not give you the latest, most feature filled and bug fixed versions of things, just the latest.

Re: Adware vendors buy Chrome Extensions to send ad- and malware-filled updates

#59

I was thinking about this just the other day. The movement towards auto-update-everything is a massive security breech. Browser extensions are a prime example. So much of what we do is centered around the browser, and yet we allow essentially random pieces of code complete access to all that activity. Even worse, this code is allowed to download and run new versions without any user interaction. Needless to say, the…

> Auto updating anything but the most critical and most trusted software is absolutely bone-headed

Yep. It's kind of mind-blowing that Crome defaults to auto-updating extensions, then lets just anyone upload new versions of them. (Is it even possible to disable this idiocy?) I take some perverse joy in the fact that someone has "monetized" the auto-update treadmill. Maybe it will encourage people to think about the consequences of installing random code to your computer whenever someone else decides to do so.

Re: Adware vendors buy Chrome Extensions to send ad- and malware-filled updates

#60
post #14

It's not just a DOM change problem. What if an extension change owner and start sending pairs (domain/user's credentials) to someone else? What if one buy an extension to get bank sites accesses?

What's surprising is that extensions are by default not "Allowed in incognito", however they are allowed when using HTTPS and there is no option to disable them there.

if adblock didn't work on https that'd be one way to see it massively deployed ;)
Post reply on HN