Live data from Hacker News

Grammarly shared its tokens with all websites

bugs.chromium.org

81–90 of 176 posts

Re: Grammarly shared its tokens with all websites

#81
post #10

Earlier quoted context omitted.

Yes, it is crazy. For these cases we shouldn't be using SaaS at all. Installed applications can still be useful, I guess.

Anything you can recommend that integrates with a browser but runs locally and check grammar and spelling mistakes?

Your browser can do spellcheck...

Re: Grammarly shared its tokens with all websites

#82

I feel like the first thing we should talk about is how this is effectively a keylogger, similar to Windows 10's inking and typing setting, albeit with likely poorer security. Collecting everything you type into a web browser (or MS Office) and sending it to them seems like a really bad idea.

Aren't all password managers keyloggers too?

No. 1Password, as far as I know, doesn't trigger anything until after I've given it the OK to do its thing. It can input passwords when I allow it to and it saves the password only after I've confirmed that it's ok to. It's possible that they're secretly logging everything in the background but that seems to be completely antithetical for a company that requires the trust of its users for its product to sell.

Re: Grammarly shared its tokens with all websites

#83
I don't want to be mean or anything... but how retarded do you have to be to jeopardize users expectations like this?

This is outrageous.

> Grammarly had fixed the issue and released an update to the Chrome Web Store within a few hours, a really impressive response time.

Oh my god. Impressive is your insane lack of competence and responsability.

Re: Grammarly shared its tokens with all websites

#84

Earlier quoted context omitted.

Yes. Google offers ADMX templates for controlling Chrome which can be deployed through group policy. It includes an extension blacklist, which accepts wildcards. In my case, I put a * in there. It also has an extension whitelist, and a list of "force-installed apps and extensions". https://support.google.com/chrome/a/answer/187202?hl=en This is one place where Google actually did really do their homework, IMHO.

Is something comparable available for Firefox?

They are working on it: https://wiki.mozilla.org/Firefox/EnterprisePolicies

Re: Grammarly shared its tokens with all websites

#85

Earlier quoted context omitted.

One of the reasons I started writing my own editor.

Interesting, how is the progress going so far? I think there is a lot of demand out there for a certain type of editor.

Oh well, you know. https://eddtor.com

Re: Grammarly shared its tokens with all websites

#86

Earlier quoted context omitted.

Gotta get that HN karma tho

You are getting down votes because HN has a policy that the HN Title should match the Title on the link to prevent editorializing in almost all cases. This prevents users from creating click bait headlines to get that karma tho , the majority of the time. Cases where the actual title is the click bait like this one, are the unintended consequence of that policy.

That's true, except the guideline reads "Please use the original title, unless it is misleading or linkbait" and you can argue that once a vulnerability is fixed, implying it's still there is misleading. So we often edit those titles to past tense once that's more accurate. Same with "$site is down" -> "$site was down".

https://news.ycombinator.com/newsguidelines.html

Re: Grammarly shared its tokens with all websites

#87
post #14

I nearly missed this bit at the bottom: > Grammarly had fixed the issue and released an update to the Chrome Web Store within a few hours, a really impressive response time. Nice to see a company take this kind of thing appropriately seriously (although of course it should never have happened in the first place).

It seems like it would be more fair for the headline to use the past tense.

Agreed; edited. Explained at https://news.ycombinator.com/item?id=16318122.

Re: Grammarly shared its tokens with all websites

#88

Earlier quoted context omitted.

Gotta get that HN karma tho

You are getting down votes because HN has a policy that the HN Title should match the Title on the link to prevent editorializing in almost all cases. This prevents users from creating click bait headlines to get that karma tho , the majority of the time. Cases where the actual title is the click bait like this one, are the unintended consequence of that policy.

HN seems like the kind of place where there could be exceptions to the policy when there's good reason.

Re: Grammarly shared its tokens with all websites

#89

I feel like the first thing we should talk about is how this is effectively a keylogger, similar to Windows 10's inking and typing setting, albeit with likely poorer security. Collecting everything you type into a web browser (or MS Office) and sending it to them seems like a really bad idea.

>I feel like the first thing we should talk about is how this is effectively a keylogger,..

Same as Google/Firefox autocomplete and history, or keyboard spell checker, or email autocomplete and spell checker, etc.

So linux and android are also in the boat of having apps that make your life easier, also need security enforced.

Just wanted to say, its not a Windows only issue, OSX, iphone, android, they are all going to be affected to simular issues.

Re: Grammarly shared its tokens with all websites

#90
post #10

Earlier quoted context omitted.

Yes, it is crazy. For these cases we shouldn't be using SaaS at all. Installed applications can still be useful, I guess.

Anything you can recommend that integrates with a browser but runs locally and check grammar and spelling mistakes?

Your brain. If you offload too many tasks to computers, those skills will weaken.
Post reply on HN