13 ms·
“Stylish” browser extension steals all your internet history
- lifthrasiir 8y agotl;dr: Use Stylus [1]. Use Stylus. Use Stylus. I guess there should be an addon that notifies users for any ownership changes to browser addons they use. Or is there? [1] https://github.com/openstyles/stylus https://github.com/openstyles/stylus
- bjoli 8y agoThey do have to make you agree to the new TOS, so just make sure to at least skim any plugin popups/pages that come up after an extension update.
- ehsankia 8y agoYep switched a few months back last I heard about Stylish being bad, and never looked back. It works very similarly and you can import/export all your stuff so it's super easy to switch.
- kawera 8y agoThis extension disables any updated extension that requires new permissions, among other niceties: https://chrome.google.com/webstore/detail/extensions-update-notifie/nlldbplhbaopldicmcoogopmkonpebjm https://chrome.google.com/webstore/detail/extensions-update-... (I'm only a user)
- spookyuser 8y agoI thought chrome did this automatically now.
- mmsimanga 8y agoFirefox lets you know when addon changes permission between versions. You are prompted to accept the new permissions before upgrading the addon. This has been helpful in weeding out addons that become too data hungry.
- mastef 8y agoSometimes extensions plan such things a long time ahead - for example this extension https://chrome.google.com/webstore/detail/bitcoin-litecoin-ethereum/jmmnaflnlpniogaclpnhmlheojfgpngc https://chrome.google.com/webstore/detail/bitcoin-litecoin-e... injects itself currently into all websites, and sends the url back to its own background page. So once they are ready to add malicious code in the future to pass that information somewhere else, no permission changes will be required. Before downloading any extensions, I usually inspect them quickly with https://chrome.google.com/webstore/detail/chrome-extension-source-v/jifpbeccnghkjeaalbbjmodiffmgedin https://chrome.google.com/webstore/detail/chrome-extension-s... Most important parts are "manifest.json" and then if defined then content scripts that match catch all urls and "https://*/*" https://*/*" / "http://*/* http://*/*.
- mmsimanga 8y agoThank you for the information. Very helpful.
- ahmetkun 8y agoBefore uninstalling stylish, consider visiting its webstore page and rating it 1-star so that upcoming users know it's not a great extension.
- zamalek 8y agoYou can report abuse without installing, so that's an option too.
- dingaling 8y agoAnd also keep a separate browser profile without ANY extensions for doing your banking and other financial work.
- rain1 8y agoOr don't. because it depends on openstyles.org which is also owned by SimilarWeb.
- mappu 8y agoI discussed this problem (in a bit inflammatory way) last month: https://news.ycombinator.com/item?id=17242003 https://news.ycombinator.com/item?id=17242003 It's particularly annoying, because I do have this Stylish extension installed (using css ::after rules to tag HN users) EDIT: You can submit an abuse report when uninstalling a Chrome extension.
- yborg 8y agoSort of ironic sending an abuse notification to a company that does precisely the same thing on a much vaster scale. And I would assume that the T&C for the new and improved Stylish that you accept when you install it informs you that you are giving them permission to do this, so there isn't even any abuse to complain about here.
- mappu 8y agoI had this extension installed for years, from back when it was "still good". I don't recall ever seeing a T&C prompt, and in the last 3-4 years I've become quite vigilant about always reading full T&C texts (much to the amusement of others). I was put in this tracking program without my consent.
- ssivark 8y agoMost browser extensions seem to require access to one's browsing history and keystrokes, even for legitimate functioning. Is there any way to ensure that they do only what they claim to do, and don't abuse the permissions? (Apart from verifying the source code, because clearly, lines of junk code >> interested eyeballs). For example, would it be reasonable to enforce that an extension only acts locally, and cannot communicate with any external server? (I guess allowing arbitrary local modifications essentially allows the extension to execute arbitrary javascript code, including communicating with arbitrary remote entities?)
- icebraining 8y agoYes, it's very hard to block that, since even if you block XHR from their JavaScript code, by changing the page DOM they can inject elements that communicate with a server.
- mirimir 8y agoDoes NoScript detect connections by other add-ons to remote servers? I do see in https://noscript.net/faq https://noscript.net/faq > ... Firefox extensions are written in JavaScript too and NoScript doesn't block scripts living outside web pages (i.e. the browser components, included extensions) ...
- psergeant 8y agoOffices in the UK. I would encourage anyone in the EU who used this to file a GDPR complaint.
- thiagocsf 8y agoQuickly though.
- the_duke 8y agoGDPR applies for all users located in the EU, not only to companies headquartered in the EU, so Brexit is not that much of a concern here. Also, the transition period will bind the UK to most EU laws for a few more years.
- JdeBP 8y agoIt is already in U.K. law, in any event: * http://legislation.gov.uk/ukpga/2018/12/contents/enacted/data.htm http://legislation.gov.uk/ukpga/2018/12/contents/enacted/dat...
- M2Ys4U 8y agoThat isn't the GDPR, although it is related. The GDPR is UK law automatically because it is a Regulation, not a Directive (which needs to be transposed into national law). The Data Protection Act 2018 implements the Law Enforcement Directive (as the GDPR excludes that from its scope) and a couple of minor derogations (such as changing the age of consent for children to use websites by themselves to 14).
- DavideNL 8y agolook here to find out where you can file the complaint in your local country: https://ec.europa.eu/commission/sites/beta-political/files/national-data-protection-authorities-jan_2018_en.pdf https://ec.europa.eu/commission/sites/beta-political/files/n...
- spyder 8y ago
- Phait 8y agoIt took me less than a minute to install Stylus and import all my userstyles from Stylish.
- dredmorbius 8y agoThe headache for me was that the stylesheets are transferred, but the applied domains are not. I've got a system where I use a set of standard styles applied broadly against many sites. E.g., Annoyances -- applied globally to all websites by default: https://pastebin.com/raw/GrE9KX6D https://pastebin.com/raw/GrE9KX6D Local Gifs: https://pastebin.com/raw/tn7cqGtJ https://pastebin.com/raw/tn7cqGtJ (Exceptions to global gif filtering) The following break on many sites too much to be applied as default, but can be used fairly generally to selected sites as needed. Animations blocking: https://pastebin.com/raw/7Gjxj6AT https://pastebin.com/raw/7Gjxj6AT Headers / Footers: https://pastebin.com/raw/PsXWhUGf https://pastebin.com/raw/PsXWhUGf Popups / Overlays blocker: https://pastebin.com/raw/VcgNNwDp https://pastebin.com/raw/VcgNNwDp "Unstyled" CSS: what I apply to unstyled / minimally styled pages: https://pastebin.com/raw/rtfev3vj https://pastebin.com/raw/rtfev3vj For development / testing / debug: Debug CSS: https://pastebin.com/raw/Z3kFrRQy https://pastebin.com/raw/Z3kFrRQy (Highlights class/id and entities in page.)
- psychometry 8y agoOne of those (either annoyances, headers, or popups) broke a fork of Stylish. I'd click on the icon in the toolbar and the drop-down wouldn't appear. I noticed the user style also broke AWS navigation.
- dredmorbius 8y agoNone of those sheets except for Annoyances should be applied globally. I don't guarantee Annoyances won't break other things, but I do guarantee that the others will. Assign the to a nonexistent URL or domain initially, or disable them. If you've got specific bugs with the Annoyances sheet ... I may be able to address them. My usual first-stop debugging tools are adding either an outline or background colour to an element: outline: solid 2px red; background: #faa; ... which tends to show what rule(s) are being triggered. If something breaks, add those rules, and disable the "display: none;" one. I'm also finding that the shift to "display: flex;" styles is breaking some of my assumptions. It's no longer safe to presume that everything is displayed as one of block, inline-block, or inline. Position directives are also problematic: initial, static, relative, absolute. That said: I've evolved those styles over a few years, and they tend to work reasonably well. Some nursemaiding required.
- eastendguy 8y agoThis reminds of the "WOT, Web of Trust" (haha) privacy issue in 2016: Reporters (disguising as business men) were offered data that includes the surfing habits of three million German citizens. This data was, at least partly, collected by the “Web of trust” (WOT) browser extensions. The reporters were able to use this data to identify the browsing habits of individual persons – including high-ranking German and EU politicians. English: https://ocr.space/blog/2016/11/wot-browser-extension-collects-habits.html https://ocr.space/blog/2016/11/wot-browser-extension-collect...
- mirimir 8y agoIndeed. I never trusted it. I never trust any feature or add-on that uploads anything. That includes malicious site detectors. I only use stuff that relies on local databases.
- dredmorbius 8y agoAny recommendations on malicious site alternatives? I'm still looking to update my router (Turris Omnia) to use DNSMasq rather than Knot Resolver, which may offer an edge on DNSSec capabilities (though I believe this has lapsed), but is far less capable of being locally customised along the lines of DNSMasq. https://www.knot-resolver.cz/ https://www.knot-resolver.cz/ http://www.thekelleys.org.uk/dnsmasq/doc.html http://www.thekelleys.org.uk/dnsmasq/doc.html
- dannyw 8y agoGoogle needs to take action here. From requiring re-confirming permissions every time a significant privacy policy change is made, or just by nuking SimilarWeb altogether from the web App Store.
- izacus 8y agoI can already see the followup HN news: "Google attacking developers on Chrome Web Store and breaking free web!"
- nailer 8y agoYeah one thing Google doesn't do is collect info about what you do on the internet and sell it to other people. https://myactivity.google.com/myactivity https://myactivity.google.com/myactivity More seriously: if Stylish concerns you, Chrome should too.
- izacus 8y agoGoogle indeed doesn't sell info to other people. (It does collect it though.)
- nailer 8y agoGood point, I should say sell /access to/ (via DoubleClick, AdWords and their other sources of revenue)
- Silhouette 8y agoIs there a definitive list anywhere of what Chrome collects and where it goes? There have been rumours forever, but I'm interested in verifiable facts.
- nailer 8y agoIf you're logged in, which Chrome strongly encourages, it's your entire browsing history. See the URL above.
- TheCapeGreek 8y agoAs others have said, immediately switch to Stylus. While we're at it stop using Ghostery as well since they were bought by an ad company. Use Privacy Badger or a decent alternative (noscript + heavy/custom uBlock lists should work just fine)
- Chilinot 8y agoIf you dont want the heavy handed solution that NoScript provides, i would suggest "uBlock Matrix".
- icebraining 8y agoI think it's just "uMatrix".
- Chilinot 8y agoIt is, my bad.
- liamfd 8y agoHow does that compare to uBlock Origin?
- dredmorbius 8y agoThere are two, similar, though different, extensions. uBlock origin is a dedicated, quite-good, low-fuss, ad blocker. uMatrix is a much more general, very powerful, though somewhat fussy, general Web capabilities manager. If you don't mind fiddling with sites periodically, it's very strongly recommended, but for user populations who don't do this or grasp technology poorly, it will require some fairly close managing, _especially_ if the user base doesn't report problems and just accepts "the site is broken". I'd highlighted my preset recommended set of browser extensions for 2018 a couple of weeks back. The hero image is uMatrix's control interface. https://plus.google.com/104092656004159577193/posts/WVEM83FY169 https://plus.google.com/104092656004159577193/posts/WVEM83FY...
- 8y ago
- mcjiggerlog 8y agoThis is a huge problem for the extension ecosystem in general. Who originally publishes an extension may not be the same entity that is pushing you updates in two years time, and there's no way as a user to know this. I publish a few extensions [1] [2] [3] and have been contacted multiple times by companies asking to buy them for several thousand dollars. They told me the going rate was 0.20 USD per user. You can imagine what kind of deals are being made when the extension has a million plus users. When pushed for exactly why they wanted to buy the extensions, which are in no way monetizable, they gave vague answers about "user insights". I can guarantee there will be many other major extensions that have sold out their users. [1] https://chrome.google.com/webstore/detail/old-reddit-redirect/dneaehbmnbhcippjikoajpoabadpodje https://chrome.google.com/webstore/detail/old-reddit-redirec... [2] https://chrome.google.com/webstore/detail/break-timer/hklkdbpicdmlpoiellngedpejjkmapei/reviews https://chrome.google.com/webstore/detail/break-timer/hklkdb... [3] https://chrome.google.com/webstore/detail/reddit-comment-collapser/njmimaecgocggclbecipdimilidimlpl https://chrome.google.com/webstore/detail/reddit-comment-col...
- logicallee 8y agoI realize this is bad, but what happens to the user data exactly? I mean can someone here paint the bleakest, most dystopian possible use or future?
- garganzol 8y agoBuild a social/interaction graph and fill everything with Ads while selling the same information to intelligence agencies. No discretion. Only money. Nothing personal, it's just business. Sounds familiar? Facebook invented that already.
- peteretep 8y agoIt gets sold to private investigators and insurers, and you shouldn't have ever Googled for "alzheimer disease symptoms" and you lose your child custody rights after a judge decides what you're looking at on YouPorn isn't sufficiently healthy.
- throwawaymath 8y ago
- trio333 8y agoAlways the same cycle. 1/ New great product is built. People love it. 2/ Once enough people use it, start monetizing in shady ways, annoying users just not too much or they leave. 3/ Very annoyed users switch to another product back to 1/
- oblio 8y agoSmall correction: 1/ New great _free_ product is built. People love it. Image and file hosting services and messengers are the best examples. I swear it's because the well has been poisoned and it's just impossible to monetize these services in a moral way.
- owlmirror 8y agoThis is absolutely not confined to free products. I did security audits for companies and part of that job was giving a go ahead before we allowed people to install software on their devices. Free software behaved much better than paid software by a wide margin.
- reshie 8y agoshouldn't have needed it in the first place. what happened to pointing to a css file.
- TeMPOraL 8y agoTrue. Userscripts and userstyles should be a part of the browser itself. Userstyles were at some point, AFAIR, at least on Firefox.
- akerro 8y agoDont google and mozilla review source code of addons?
- mcjiggerlog 8y agoMozilla yes - there's a delay when publishing whilst an actual human reviews the changes. For Google, updates are instantly published with, as far as I can tell, no kind of audit.
- fabricexpert 8y agoThe Mozilla one is great, they insist on reproducible builds and do a thorough review. Although they can't catch everything, I would pick FF over Chrome all day for this reason alone.
- tim1994 8y agoAre you sure about that? AFAIK there is just an automatic validation system. I am an extension author myself and this is from a recent update approval email: "This version has been screened and approved for the public. Keep in mind that other reviewers may look into this version in the future and determine that it requires changes or should be taken down. In that case, you will be notified again with details and next steps." Perhaps this also depends on the number of users...
- zulln 8y agoBack in 2015 when Detectify (me being co-author) looked into this issue [1] many plugins do not actually have this code in the extensions, but rather a feature to download remote code and add it to the extension so to say. As long as that practice is allowed, source review would not help. [1] https://labs.detectify.com/2015/11/19/chrome-extensions-aka-total-absence-of-privacy/ https://labs.detectify.com/2015/11/19/chrome-extensions-aka-...
- gruez 8y agoAFAIK this isn't allowed in firefox extensions
- hetfeld 8y agoYou can use my Chrome extension "Styler" for as an alternative: https://chrome.google.com/webstore/detail/styler-classic/hbhkfnpodhdcaophahpkiflechaoddoi?hl=en https://chrome.google.com/webstore/detail/styler-classic/hbh... Addon for Firefox: https://addons.mozilla.org/en-US/firefox/addon/sudo-styler/ https://addons.mozilla.org/en-US/firefox/addon/sudo-styler/ I'm getting all money on development/support from Patreon.
- fishtopher 8y agoIn what is certainly a complete coincidence, the Stylish Firefox extension threw up an "agree to our new TOS 'effective May 22, 2018.'" modal for me today..
- ccnafr 8y agoIt's not actually stealing if it's in the ToS, is it?
- j88439h84 8y agoYes, it is. For example, > TOS agreements require giving up first born—and users gladly consent https://arstechnica.com/tech-policy/2016/07/nobody-reads-tos-agreements-even-ones-that-demand-first-born-as-payment/ https://arstechnica.com/tech-policy/2016/07/nobody-reads-tos...
- reitanqild 8y agoAs someone who used to read TOS and EULAs: Somewhere around 10 years ago I switched strategy: I don't read them at all. If anyone wants to sue my defense would be that nobody in their right mind (sorry younger me) would read that nonsense. I assume the rules are basically "don't abuse our content or service", ... and I assume that they will sooner or later sell, abuse, leak, or hand over my data to law enforcement in any country including middle Eastern and African ones.
- nailer 8y agoJust filed this Firefox bug: https://bugzilla.mozilla.org/show_bug.cgi?id=1472948 https://bugzilla.mozilla.org/show_bug.cgi?id=1472948
- beart 8y agoLooks like the extension has already been removed from the store.
- HelenePhisher 8y agoTampermonkey seems to be a good alternative as well and is available for all major browsers. Does anyone have information on if the Safari Stylish Addon does the same shady things? It's available in the official App Store and was approved by Apple it seems.
- Volt 8y agoI was curious about this too. The source is on GitHub (https://github.com/350d/stylish https://github.com/350d/stylish), but who knows if Apple checks that they're the same when they're approving it. Edit: I should note that it collects analytics, but it can be turned off in the preferences. I don't remember if it's on by default, but I suspect it is.
- HelenePhisher 8y agoYes, the option is called "Collect anonymous usage statistics" and is turned on by default. But I don't trust it anymore. Tampermonkey is here BTW: https://tampermonkey.net/?browser=safari https://tampermonkey.net/?browser=safari I really love that one, it does a great job in Safari. Unfortunately, there is no Safari App Extension yet. Since I'm running Safari Preview and Safari 12 does not accept extensions from unknown sources anymore I'm out for now.
- garganzol 8y agoSo it boils down to trust anyway. No way a code signing certificate can impose that trust. At the end of the day, it all goes back to human stance towards other beings in this world and own dignity.
- SSchick 8y agoI actually ran into this issue previously when for some reason I got a request on a `hidden` (very cryptic URL listed nowhere) diagnostic endpoint on one of our APIs. I ended up identifying stylish as the culprit, at first I disabled the tracking option (which is opt out and probably violates GDPR), a few weeks later I installed stylus. I also reported it around the same time and gave it a 1/5 star rating but google had no interest in the report it seems.
- therealmarv 8y agoreport stylish to Google https://chrome.google.com/webstore/report/fjnbnpbmkenffdnngjfgmeleoegfcffe https://chrome.google.com/webstore/report/fjnbnpbmkenffdnngj...
- eurticket 8y agoIs there a system in place to update everyone on new ownership changes and implementation of anti user-good practices like this?
- roadbeats 8y agoMeanwhile a simple and open source bookmarking extension was taken down with no notice, no information (https://news.ycombinator.com/item?id=17440358 https://news.ycombinator.com/item?id=17440358).
- Zren 8y agoI've gotten annoyed enough to just copy the source from most of my extensions (located at `~/.config/google-chrome/Default/Extensions/`), remove the update stuff from the `metadata.json` and load them as developer extensions so they never update. It's easy enough to update them + audit the code when something breaks. The hardest part is downloading the new code (.crx) without installing it, I had to write javascript I paste into the console. StackOverflow can unzip a crx by striping the first 306 bytes. I forked Stylish v1.5.2 a year ago before I heared of Stylus, but I've no need to to switch since the original extension was pretty good. https://github.com/Zren/chrome-extension-stylish#fork https://github.com/Zren/chrome-extension-stylish#fork
- e1ven 8y agoI'm glad that workflow works for you. I'm curious though - What about it is better than turning off automatic updates for addons?
- HelenePhisher 8y agoYou can extract the .crx without Javascript using this webservice: http://crxextractor.com/ http://crxextractor.com/ Used it a couple of times in the past, it is a good one.
- Zren 8y agoAll you need to do is remove the first 306 bytes to turn it into a normal zip file. tail -c +307 in.crx > out.zip Credit to this guy in the comments. https://superuser.com/questions/139190/how-to-unpack-a-chrome-theme#comment624001_139198 https://superuser.com/questions/139190/how-to-unpack-a-chrom...
- mholt 8y agoDangit - I just installed it yesterday to block Twitter's annoying timeline additions ("So-and-so liked such-and-such") which don't honor the account's word filter/blacklist. Any alternatives out there that are better?
- KwanEsq 8y agoStylus, as mentioned in the article: https://addons.mozilla.org/firefox/addon/styl-us/ https://addons.mozilla.org/firefox/addon/styl-us/
- alexanderby 8y agoDark Reader (which generates dark themes dynamically) added support for static CSS so that style sheets can be migrated http://darkreader.org/blog/stylish/ http://darkreader.org/blog/stylish/
- seba_dos1 8y agoIsn't it a common knowledge? People were massively switching to Stylus long time ago.
- exodust 8y agoI didn't know until today. I'm annoyed because I never noticed the opt-out checkbox. It feels almost like I've been hacked... my browser history I thought was my own private business, is actually in the hands of a some marketing company.
- pdimitar 8y agoSadly Stylus is not in the Safari's plugins store. Any alternatives for Mac users?
- kitsunesoba 8y agoI’ll have to double check and make sure but as far as I know the safari version of stylus doesn’t do this — it’s written and maintained by a totally different developer. I’m planning to write my own Safari stylesheet extension some time in the coming months, though, because old style Safari extensions are being phased out in favor of Safari app extensions and I don’t know if the dev of the Safari stylish extension plans to make the leap.
- pdimitar 8y agoDo you know the name of the extension in the Safari's addons store? I disabled Stylish the moment I read this article here but I have no replacement. If you do write such an addon as you said, please advertise it here in HN!
- kitsunesoba 8y agoCorrection, in my previous reply I meant to say that the Safari version of Stylish (not stylus) has a different developer and doesn’t appear to share the Chrome/Firefox extension’s tracking issues. The code for the safari version is available here: https://github.com/350d/stylish https://github.com/350d/stylish With a quick glance it looks to include google analytics, but that’s only used on the extension’s settings page and doesn’t send browser history or anything like that. JS isn’t my forte, though, so if anybody else could take a look and confirm that’d be great.
- touristtam 8y agoUse a real browser ? But (bad) joke aside, could you not use multiple browser instead of the just the one ? Stylus and Dark Reader are both available for Firefox and Chrome/Chromium.
- IngvarLynn 8y ago"OneTab" is another popular extension with the same issue. Switched to ff+"tabs aside" since then.
- alexeiz 8y agoReally? This is getting out of hand. I found to be using at least several of the extensions mentioned here that I wasn't aware were stealing user data.
- srgseg 8y agoThat is absolutely not true. OneTab has never, ever transmitted any information about your tabs outside of your browser, and will never divulge them. I'm the developer. OneTab has never made a penny, and absolutely does and always will deliver on the privacy promise.
- _bxg1 8y agoThis has been going on for years and Google has done nothing about it. These days I don't use any extensions where a major organization's reputation doesn't depend on them not becoming spyware. Truly a shame; I used to get a lot of benefit out of extensions, including a similar one named Stylebot, but now I don't trust anything other than Adblock Plus and the React Developer Tools to not covertly become malicious.
- SippinLean 8y agoYou probably shouldn't trust AB+ either (but switch to uBlock instead) https://en.wikipedia.org/wiki/Adblock_Plus#Controversy_over_ad_filtering_and_ad_whitelisting https://en.wikipedia.org/wiki/Adblock_Plus#Controversy_over_...
- zulln 8y agoFor reasons I do not recall now, you should use uBlock Origin instead of uBlock as well. The former is often what people are referring to anyway, but worth mentioning.
- mjgoeke 8y agoFor those actively using Stylish and needing to switch: '"Stylus" is a fork of the popular Stylish extension which can be used to restyle the web. Not "ish", but "us", as in "us" the actual users. Stylus is a fork of Stylish that is based on the source code of version 1.5.2, which was the most up-to-date version before the original developer stopped working on the project. The objective in creating Stylus was to remove any and all analytics, and return to a more user-friendly UI. We recognize that the ability to transfer your database from Stylish is important, so this is the one and only feature we've implemented from the new version.' [1] [1] https://add0n.com/stylus.html https://add0n.com/stylus.html and https://github.com/openstyles/stylus https://github.com/openstyles/stylus
- captn3m0 8y agoFound same issue with Pricee the other day, not sure how to report: https://addons.mozilla.org/en-US/firefox/addon/pricee-search-engine/ https://addons.mozilla.org/en-US/firefox/addon/pricee-search...
- Sephr 8y agoThe culprit in question tried to do the same thing to a Voice Search Chrome extension in the past[1]. [1] https://twitter.com/sephr/status/1014240895095300096 https://twitter.com/sephr/status/1014240895095300096
- O1111OOO 8y ago10 months ago, I discovered and recommended stylish on a post titled: "Show HN: Make Medium Readable Again"[0]. I have only ever used it for a single site: medium. It's times like these I wish I could go back and edit/update an old post with new info. I feel like I got stabbed in the back... which happens way too often in tech these days no matter how careful you are. [0] https://news.ycombinator.com/item?id=15123638 https://news.ycombinator.com/item?id=15123638
- tripzilch 8y agoWell, shit. I installed this extension a few months ago, because multiple people HN recommended it. Tried it out, but found a different way to restyle and adjust sites to my tastes (uBlock and custom Greasemonkey) that I found easier. Then forgot about it. And now it turns out this thing has been slurping my Internet history for months. No downvotes, nobody calling them on it, just happy oblivious HN users that carelessly install random browser extensions and then recommend them to other people. Urgh.
- aplc0r 8y agoIt appears Firefox has already moved on this. Came home today and was warned that Stylish was an unsafe extension, and I can no longer find it listed as an available add-on.
- alexanderby 8y agoDark Reader (which generates dark themes dynamically) added support for static CSS so that style sheets could be migrated http://darkreader.org/blog/stylish/ http://darkreader.org/blog/stylish/
- sahin-boydas 8y agoAre There any response from Stylish developer?
- franga2000 8y agoI've been lucky enough to have never had an extension installed when it was sold, so I don't know that this isn't already the case, but if it isn't, I believe it should be: Whenever an extension changes hands (is transfered to another account), the user should be notified in the same way they would be if it requested new permissions. Along with a rule that accounts are non-transferable, of course.
- Bromskloss 8y agoSince "youtube-dl does not include support for services that specialize in infringing copyright", is there a fork, or addition, without this restriction?
- yuber 8y agoI wonder if Stylish is also able to data-mine the websites you visited while in incognito mode, since extensions don't work there. Does anybody have an idea?
- kup0 8y agoIs there an alternative to userstyles.org for hosting styles? That site is run by the Stylish folks, and I have removed my account and styles from it.
- stonecrusher 8y agoNot really. Though, https://openusercss.org/ https://openusercss.org/ is in development right now. freestyler.ws is an unmaintained copy of userstyles.org
- stratigos 8y agoUgh! After so many years, I now have to view a white-themed internet again. I forgot how painful and blindy websites are! Pls redesign the whole internet to be dark themed, so we dont need add ons like this to fix the world. Thanks!