4 ms·
Here is the blog entry of the Journalist Mike Kuketz, explaining in detail how he uncovered the fraud, unfortunately only in German. This includes samples of th
by moppl 10y ago
Here is the blog entry of the Journalist Mike Kuketz, explaining in detail how he uncovered the fraud, unfortunately only in German. This includes samples of the questionable GET and POST Requests, as well as a link to a commit to the WOT sources on GitHub, which introduced the necessary changes ...
https://www.kuketz-blog.de/wot-addon-wie-ein-browser-addon-seine-nutzer-ausspaeht/ https://www.kuketz-blog.de/wot-addon-wie-ein-browser-addon-s...
The commit referenced in the blog:
https://github.com/mywot/firefox-xul/commit/0df107cae8ac18901bd665acace4b369c244a3f9 https://github.com/mywot/firefox-xul/commit/0df107cae8ac1890...
- moppl 10y agoAnd by the way, he also suggests in his blog post that Ghostery and Adblock Plus might as well sell browser histories as WOT does. There might be even more.
- FuNe 10y agoReminds me of the old saying. "When the service is free the product is you."
- blub 10y agoLateley there's a trend to dismiss the above saying (i.e. if it's free you are the product) in a casual manner. Reality isn't influenced by such dismissals or wishful thinking however. If a company's financial interests aren't aligned with the general interests of its customers, then it will trample over the interests of its customers. Google, Facebook, any company that's selling advertising are not only not your friends, but they're screwing you over.
- admax88q 10y agoMy issue with that saying is that it prejudices people against Free (as in libre) Software. Free Software is free, and you aren't the product when you use it. In most cases its the only software that actually puts the user first. Saying "If it's free, you are the product" tells people that the only way to get good software is to pay money for it. When in reality lots of payed software harvests your data just as much.
- paulryanrogers 10y agoIME free and open software does tend toward abandonment or some form of monetization over time. Just ran into this with Synergy recently.
- denzil_correa 10y agoI just stick with EFF Privacy Badger. https://www.eff.org/privacybadger https://www.eff.org/privacybadger
- aroch 10y agoGhostery allows you to OPT IN to sending your browsing data [1], which may be sold as part of services offered by their parent company to improve ad ROI for their customers. They also tell you that they're collecting the request data [2]. I think knowingly sharing your data (with a positive affirmation) is significantly different than having your data collected and sold without your knowledge [1] http://imgur.com/a/ugglB http://imgur.com/a/ugglB [2] https://www.ghostery.com/support/faq/ghostery-add-on/What-data-does-Ghostery-collect/ https://www.ghostery.com/support/faq/ghostery-add-on/What-da...
- qznc 10y agoThe problem is not the selling of browsing data. WOT tells you openly that they do it. The problem is that the data is not anonymized enough. The question is, if this is actually possible.
- rndgermandude 10y agoGhostery yes. Regarding AdBlock Plus he is complaining about the Acceptable Ads "feature", not that ABP is collecting and/or selling user data
- onli 10y agoFirefox really needs to start to disable extensions (but enable exceptions) when in private mode. And maybe it is time to completely forbid data logging in browser addons. Then suspicious activity, like the linked commit would have caused, could be detected.
- pfg 10y agoThis begs the question: Where do you draw the line between "data logging" and submitting the URL (or domain, I'm not certain on what level WoT would normally operate) to a server in order to get its reputation? In the end, you can't be certain what the backend does with the data just by looking at the extension code. If you go too far with a rule like that, you'll likely block a lot of legitimate and useful extension. If all you ask for is the word of the extension developer that the data won't be used in this fashion, that probably won't change much in practice.
- codedokode 10y agoThe line should be drawn in a court.
- onli 10y agoThough what happened here is already forbidden. It is just very difficult to use the law against those criminals. That is why the browser makers are in a better position to control this.
- onli 10y agoCurrently, facing this abuse, I'd completely forbid data transfer from an extension to a server by default. Then add exceptions: If the transfer is necessary for the legitimate function of the extension (note: It is not for stuff like adblocker, where the lists are already cached locally), allow it under special control as long as the data sent out is anonymized as much as reasonable. URLs for example should be hashed before going out.
- 10y ago
- gorhill 10y ago> The commit referenced in the blog Interesting, the date of the commit is April 20, 2015. I did comment on April 16, 2015 about how the WOT extension could record a user's browsing history[1], so it does look like they were doing this before this specific commit. Edit: ah never mind, my comment was for the Chrome version of the extension while the commit is for the Firefox extension. So they have been doing it since longer for the Chrome extension. [1] https://github.com/gorhill/uBlock/issues/65#issuecomment-93733679 https://github.com/gorhill/uBlock/issues/65#issuecomment-937...
- omouse 10y agothanks for linking, I'd like to see if there's a news article on it as well.