Live data from Hacker News

Adware vendors buy Chrome Extensions to send ad- and malware-filled updates

arstechnica.com

61–70 of 111 posts

Re: Adware vendors buy Chrome Extensions to send ad- and malware-filled updates

#61
post #33

I have the feeling that every "good" message about Chrome is followed by a disastrous one. This time it was the funky "audio feature" on tabs, followed by this. Chrome developed a scary creativity with good and evil stuff. I used Chrome once because everybody was telling me how fast it is. It wasn't. People just couldn't add all the processes properly. Since then it was a roller coaster I won't jump on anymore. I use…

> my parents end up with Chrome every time I come by on the Windows. Installed through some update

My guess would be the tooltip-like thing that Google puts on its search page telling them to "make the web better with Chrome." I've never clicked on the thing, but it probably changes your default browser and installs a bunch of shortcuts.

Re: Adware vendors buy Chrome Extensions to send ad- and malware-filled updates

#62
post #12

Earlier quoted context omitted.

Look into running separate sessions of your browser(s). Both Firefox and Google Chrome (or Chromium) allow you to do this, although the interfaces for doing so differ. A simple way to do this is to use different brands of browser, e.g. Gmail in Chrome and everything else in Firefox. But... if you really prefer one browser over another, for all use, then the separate profiles thing works. Note that in Chrome, this is…

To run a new, separated Firefox with a (possibly) different profile firefox -no-remote -ProfileManager It's always handy to have a "vanilla" profile, to compare how much the extensions tuned down the browser or try to understand if the error that you're seeing is caused by an extension. Having a "privacy" profile with some ad-hoc extensions helps too.

Mind you, -ProfileManager actually opens to the full profile manager interface (where you select a profile to run, or create a new one, or whatever). You can load a specific profile (that already exists) directly by replacing "-ProfileManager" with "-P [profile name]". (Omitting the name will open the manager, too.)

https://developer.mozilla.org/en-US/docs/Mozilla/Command_Lin...

Re: Adware vendors buy Chrome Extensions to send ad- and malware-filled updates

#65
post #2

Can we start a petition for Google to let us disable extensions on specific sites? After reading the last few stories about this, I am quite sure I don't want any extensions whatsoever running in the same tab as my Gmail account. I think there is some extension that does this for you (turns off other extensions per site), but then we get into a "who guards the guardians" situation. Not to mention we need better and f…

[deleted]

Re: Adware vendors buy Chrome Extensions to send ad- and malware-filled updates

#66
post #46

Earlier quoted context omitted.

Chrome doesn't run extensions by default in incognito mode. > Because Google Chrome does not control how extensions handle your personal data, all extensions have been disabled for incognito windows. You can reenable them individually in the extensions manager. Keeping your gmail tab in an incognito window might be a good approach.

While it's a decent workaround, I wouldn't call it ideal, namely because it requires a second window open when you might be starved for screen real estate and also because accidentally opening your mail once in a normal window could cause damage.

The Ghost Incognito extension allows you to force certain sites to always use Incognito mode. I realize using an extension to accomplish this objective is somewhat ironic, but seems like it'd work in this case if you can trust that one extension.

https://chrome.google.com/webstore/detail/ghost-incognito/ge...

Re: Adware vendors buy Chrome Extensions to send ad- and malware-filled updates

#67
post #5

This is a disturbing situation, but it's hard to say what the best way of dealing with it is. The first thing most people reach for first is that extensions shouldn't auto-update. Personally, I disagree - I love silent auto-updates in general. It's a huge drag on the computing experience to have dozens of different widgets all requiring manual updates, all with different mechanisms and all on their own schedules. If…

[deleted]

Re: Adware vendors buy Chrome Extensions to send ad- and malware-filled updates

#68
post #50
post #31

Earlier quoted context omitted.

The problem is with users. They ignore the scary "access to all websites" dialogs and install extensions. Sites like pinterest have extensions that request these permissions, when they don't even need them. There's a way to have the extension only have access to the site you're on when you CLICK somewhere in your toolbar. There are fine grained permissions and optional permissions to specific hosts and ports and URL…

Looks like what we really need to do is to remove those universal permissions entirely, then. Say after some particular date, no new extensions or updates to existing ones are allowed unless they remove the universal permissions and switch to the site-specific ones. Of course, then you need a solid extension update system where there's some way to alert the user of when an extension needs new permissions, and have th…

[deleted]

Re: Adware vendors buy Chrome Extensions to send ad- and malware-filled updates

#69
post #46

Earlier quoted context omitted.

Chrome doesn't run extensions by default in incognito mode. > Because Google Chrome does not control how extensions handle your personal data, all extensions have been disabled for incognito windows. You can reenable them individually in the extensions manager. Keeping your gmail tab in an incognito window might be a good approach.

Or just using thunderbird. I can't be the only one who doesn't like gmail's wonky interface.

If I didn't use gmail through the web, I probably would use a different provider.

Re: Adware vendors buy Chrome Extensions to send ad- and malware-filled updates

#70
post #17

That shouldn't come as a surprise to anyone who has an app on any app store. I get at least two emails per week from some shady advertiser that wants to place ads, add notifications, gather user data or some else equally awful. I had at least one app where I didn't pay close enough attention to the permissions it required upfront and at some point it started injecting ads into random pages (it was a stopwatch, by the…

While the app developers may not be surprised, I strongly suspect the overwhelming majority of app users are.

And for Google to allow this to happen is unconscionable.

Post reply on HN