7 ms·
Extensions are the new "Let's play find the download button on a webpage" that's been around for years. [1] So many users download replicas of uBlock and find
by sengork 9y ago
Extensions are the new "Let's play find the download button on a webpage" that's been around for years. [1]
So many users download replicas of uBlock and find it hard to install the original uBlock Origin extension. Countless times have I had to send them direct link to Chrome's extension site just to make sure they're installing the right one. This is the case especially as the genuine extension in this case has no direct author website and instead lists a repo on Github (average users feel this indicates a knockoff and look elsewhere).
[1] https://www.pcworld.com/article/2012958/how-to-avoid-fake-download-buttons.html https://www.pcworld.com/article/2012958/how-to-avoid-fake-do...
- krackers 9y agoThis is especially a problem when you try looking for new extensions. It's not sufficient to just look at the reviews or popularity since often times the users themselves have no idea their browsing history is being captured and sold. Also it seems that Google is in no hurry to fix this issue as even having discovered and reported malicious extensions they remain up (see: https://news.ycombinator.com/item?id=14889619 https://news.ycombinator.com/item?id=14889619). From the client side one mitigation might be to have all extensions denied network access by default and have the user manually whitelist those in a little-snitch like manner. There is an experimental flag for something similar to this called "User consent for extension scripts." From Google's side the best thing would be to run all extensions in a sandbox like they supposedly do for Android apps and monitor its activity to see if it does anything suspicious like record browsing history, redirect pages, or call out to sketchy URLs.
- 482794793792894 9y ago> From the client side one mitigation might be to have all extensions denied network access by default and have the user manually whitelist those in a little-snitch like manner. I don't think, Google has any interest in doing that. You can't either block internet access on a per-app basis on Android, even though this would close tons of information leaks, that the clunky permission system they currently have in place just can't fix. And as for the best thing to do from Google's side, that would probably be what Mozilla is doing. Sit actual human beings down to look at the code of newly submitted extensions and of extension updates. No, this does not scale, can't be automated by some algorithm, but it actually works. And it's not like it needs to scale into the millions.
- krackers 9y agoA good middle ground might be to review only the top 1000 extensions or so and put a trusted checkmark on them. Reflecting back on the automated extension review, I just realized that the problem is more complex that it seems at first glance since extensions can also contain content scripts that inject JS directly into pages themselves, so it's easy to mask the source of a POST by injecting the xhr directly into the webpage.
- PhasmaFelis 9y agoAs an aside, anyone know why both of the major adblockers have an unrelated adblocker with the same name? (AdBlock/AdBlock Plus, uBlock/uBlock Origin.) Who thought this was a good idea?
- fwn 9y agoAdblock and Adblock Plus were different developers. (Now, I believe, they are both controlled by Eyeo.) The obvious name is shared, the "Plus" were added to indicate a fork of an earlier project. I believe this was far prior to the project getting monetized. uBlock Origin was originally just uBlock, but a rough moderator took it over (or that's somewhat the story) so there's the Origin fork with the original Dev, the uBlock project does not appear to progress anymore.
- bubblethink 9y ago>This is the case especially as the genuine extension in this case has no direct author website and instead lists a repo on Github It's the other way round for me. I only install an extension if I find the github (or similar) repo with sufficient activity, stars or whatever. I would even sometimes use google search with the site:github.com string when looking for extensions or android apps. It would be nice if the chrome store and even android play store had a foss tick box.
- TwelveNights 9y agoOrdinarily, people might find seeing the repository straight-up too jarring. For people who aren't in the IT world, I'm not sure that seeing Github will be some definitive proof that an extension is legit.
- traviscj 9y agoFurthermore, it is only definitive until it isn't. If we trained users to look for the github page, we'd have forked projects that point to the compromised extension, fake github clones that look like the project, fraudulent likes, and so forth.
- tracker1 9y agoOr clones that point to the legitimate github repo.
- emodendroket 9y agoEven for people who are that isn't really "definitive proof" of anything.
- TwelveNights 9y agoIf a project looks popular, you can at least assume it isn't total rubbish though.
- 9y ago
- corobo 9y agoI had the exact same problem re: uBlock Origin. I even set up a quick site[1] a couple referrals ago just so I could have a place to easily point someone to. [1] https://getublock.com/ https://getublock.com/
- artursapek 9y agoYou could do a little bit of work to automatically select the right browser based on user-agent, and just display one button prominently.
- corobo 9y agoYeah it does need a bit of love, I whipped it up in about 15 minutes or so when I wanted to link someone to the extension
- 482794793792894 9y ago> Extensions are the new "Let's play find the download button on a webpage" that's been around for years. Chrome extensions are that. No other browser has this problem. I think, it's necessary to be pointing fingers here, to get Google to maybe finally do something about it and so that people don't mistakenly limit their use of extensions on other browsers.
- NiveaGeForce 9y agoChrome extension malware is very common * https://www.reddit.com/r/chrome/comments/6fotke/the_great_suspender_extension_gone/dijtvud/ https://www.reddit.com/r/chrome/comments/6fotke/the_great_su... * https://threatpost.com/seven-more-chrome-extensions-compromised/127458/ https://threatpost.com/seven-more-chrome-extensions-compromi... * http://chrispederick.com/blog/web-developer-for-chrome-compromised/ http://chrispederick.com/blog/web-developer-for-chrome-compr... * https://www.reddit.com/r/Windows10/comments/6hvzzt/psa_my_chrome_extension_chrometana_has_been/ https://www.reddit.com/r/Windows10/comments/6hvzzt/psa_my_ch... * https://thehackernews.com/2017/07/chrome-extention-hacking-adware.html https://thehackernews.com/2017/07/chrome-extention-hacking-a... * https://arstechnica.com/security/2017/01/ciscos-webex-chrome-plugin-opens-20-million-users-to-drive-by-attacks/ https://arstechnica.com/security/2017/01/ciscos-webex-chrome... * https://www.bleepingcomputer.com/news/security/coinhive-is-rapidly-becoming-a-favorite-tool-among-malware-devs/ https://www.bleepingcomputer.com/news/security/coinhive-is-r... * https://lifehacker.com/many-browser-extensions-have-become-adware-or-malware-1505117457 https://lifehacker.com/many-browser-extensions-have-become-a...
- Feniks 9y agoI always get my addons straight from github. That way I'm running the latest version and bypassing Mozilla. But you have to be an advanced user, it is complex now to install an "unsupported" adon.