Live data from Hacker News

The "Window Resizer" extension for Chrome now contains malware (2013)

productforums.google.com

81–90 of 124 posts

Re: The "Window Resizer" extension for Chrome now contains malware (2013)

#81
I noticed this about a month back. I was browsing the web one Saturday morning and spotted an "Eco link" next to the search results. Most of them were big sites, like Amazon and eBay etc.

I immediately emailed one of our SEO guys with a snippet of the page and said, "we need to know how to do this in Google, it must be a new feature". I stupidly assumed it was a new feature Google had rolled out. When he replied that he can't see it I started googling the problem, most of the results pertained to Malware and I was shocked, I'm a very careful browser in general.

When I started digging around it was only then I started switching off my plugins 1 by 1 and the eco link went when I switched off the browser resizer, I was honestly shocked. I knew the developer wasn't supporting the plugin any more due to funding but I didn't think it would go in that direction, I expected it to just fade away.

No, I didn't read the updates on the product. I don't have time to read updates on products, especially plugins. After reading his comments on there, there is no remorse for his actions. He is nothing more than a simple malware spreader, he should apply for a job at SourceForge.

Re: The "Window Resizer" extension for Chrome now contains malware (2013)

#82

I noticed this about a month back. I was browsing the web one Saturday morning and spotted an "Eco link" next to the search results. Most of them were big sites, like Amazon and eBay etc. I immediately emailed one of our SEO guys with a snippet of the page and said, "we need to know how to do this in Google, it must be a new feature". I stupidly assumed it was a new feature Google had rolled out. When he replied that…

Here is a version from before the takedown: http://ge.tt/8PSuzxD1/v/0

(I zipped the '3rd-party' directory and removed references to those scripts in the manifest file. So it's there if you wanna inspect it, but ecolinks won't run. I don't have time to restructure the options page though :-)

Re: The "Window Resizer" extension for Chrome now contains malware (2013)

#83

I noticed this about a month back. I was browsing the web one Saturday morning and spotted an "Eco link" next to the search results. Most of them were big sites, like Amazon and eBay etc. I immediately emailed one of our SEO guys with a snippet of the page and said, "we need to know how to do this in Google, it must be a new feature". I stupidly assumed it was a new feature Google had rolled out. When he replied that…

Here is a version from before the takedown: http://ge.tt/8PSuzxD1/v/0 (I zipped the '3rd-party' directory and removed references to those scripts in the manifest file. So it's there if you wanna inspect it, but ecolinks won't run. I don't have time to restructure the options page though :-)

I'm assuming you are the developer?

Now I see these pages I can see you were quite transparent about the eco links update. I still didn't see it though.

It's a shame it went in this direction as I used it all the time.

Re: The "Window Resizer" extension for Chrome now contains malware (2013)

#84

I noticed this about a month back. I was browsing the web one Saturday morning and spotted an "Eco link" next to the search results. Most of them were big sites, like Amazon and eBay etc. I immediately emailed one of our SEO guys with a snippet of the page and said, "we need to know how to do this in Google, it must be a new feature". I stupidly assumed it was a new feature Google had rolled out. When he replied that…

It just occurred to me: installing malware on an extension targeted towards developers - the kind of people who just might notice hijacked links - seems like the dumbest idea in the world. Leads me to wonder what sort of nastiness is hidden in those other extensions.

Re: The "Window Resizer" extension for Chrome now contains malware (2013)

#85
post #78

Hover Zoom had a similar problem recently, but still exists on the Chrome store. Up until a certain version, their data collection did nothing much (perhaps save non-existing domain hits). Then they partnered with someone and started sending certain form data (!!) to a third party -- claiming they wanted to collect anonymous demographic information. It didn't help that the script injection on all pages (which I disco…

Looks like it's time to find a replacement for Hover Zoom.

Re: The "Window Resizer" extension for Chrome now contains malware (2013)

#86
post #9

Earlier quoted context omitted.

He asks specifically if he has broken some rules in Google Chrome's terms of service, where another user replies with quotations from the ToS. He barks at that saying his extension is allowed to do what he does, because his extension does reveal exactly what it does, if you read its permissions carefully. Although, I cannot confirm whether that is true, but that's what he is saying. I have no idea what he is up to; b…

He does indicate the user gives the OK to 'access all data on all websites' - like most extensions do, come to think of it. I do think things like that should be more fine-grained, and/or that developers have to indicate /why/ they need that access.

Problem is, almost no user will ever actually READ any message. They'll just click "OK".

Re: The "Window Resizer" extension for Chrome now contains malware (2013)

#87
Story sharing time!

I run a local user group that educates developers on Google's technologies that while proudly independent from Google, has a great working relationship with their developer relations teams.

Back in March of 2012 (that's almost two years ago) I first brought to the attention of the Chrome developer relations team an extension called Bookmark Sentry that essentially contained a trojan that hijacks links to serve up spam ads. You can read more about it here: http://stopmalvertising.com/malvertisements/beware-of-the-go...

What I found troubling was the response back. I received an official response that it was within compliance of Chrome App Store policies. Specifically I was told:

"Ad injections are not in violation of the Chrome Web Store program policies. The policy requires that ads must be presented in the context of the extension or, when present within another page, ads must be outside the page's normal flow and clearly state which extension they are bundled with. We believe that ads are a legitimate way to monetize, but that they should be a known cost to the extension user."

I certainly hope since then they've changed their policy on this issue and are actively policing and enforcing against spyware and malware.

Chrome App extensions can access extremely sensitive data such as webforms with credit card, contact details, passwords and more and in the wrong hands can do untold damage.

Re: The "Window Resizer" extension for Chrome now contains malware (2013)

#89

Whoa, wait. One guy in this thread is claiming that Window Resizer was sending all your keystrokes back to a central server based on what he saw in Wireshark. Can anyone else verify this? I've had this extension installed for...a year, at least. Do I need to now go change every single password on every site because chances are it's been keylogged? This is insane.

This comment from Paul Irish suggests that there was no keylogger: https://news.ycombinator.com/item?id=7048862

Re: The "Window Resizer" extension for Chrome now contains malware (2013)

#90

Google really REALLY needs to up their game. https://news.ycombinator.com/item?id=7046240 I don't feel safe using their services anymore.

Theory: Google decided to have relaxed rules to play catch up with Apple's App Store.

After hearing from other Android devs and what they were getting away with I decided to stick to Apple for a while.

Post reply on HN