5 ms·
As the creator of several popular Chrome extensions, once you reach about 10,000 installs people will start contacting you to acquire the extension. In particu
by typpo 7y ago
As the creator of several popular Chrome extensions, once you reach about 10,000 installs people will start contacting you to acquire the extension. In particular, I created a native ad detector that was briefly popular[1]. In my experience, acquirers will go after extensions that have permissions to modify any page.
My extensions were open source and had no clear path to monetization, so I can only speculate on how the purchasers planned to recoup their investments. The permissions in these extensions would allow them to inject ads or even collect credentials, etc.
Not saying that the top extension developer does this, but people are definitely making money by collecting innocuous Chrome extensions!
[1] https://www.ianww.com/ad-detector/ https://www.ianww.com/ad-detector/
- AznHisoka 7y agoSimilarWeb and Jumpshot acquire extensions so they can gather data on the websites you visit. They then sell this data to other companies for marketing/intelligence purposes. I hope Google can close this loophole soon (anyone from Google listening? dustballs)
- Scoundreller 7y agoAnything that weakens Google’s ad-targeting advantage is bad for Google, so I could see them interested in restricting telemetry.
- steve19 7y agoChrome desperately needs a trigger whereby an extension can access a site's data only if there has been an interaction such clicking a button on the toolbar or the right click menu.
- factsaresacred 7y agoIt exists - activeTab: > The activeTab permission gives an extension temporary access to the currently active tab when the user invokes the extension - for example by clicking its browser action. Access to the tab lasts while the user is on that page, and is revoked when the user navigates away or closes the tab. https://developer.chrome.com/extensions/activeTab https://developer.chrome.com/extensions/activeTab
- steve19 7y agoThat is good! I guess they will eventually transition to this.
- kevingadd 7y agoPart of the problem is that activeTab makes a ton of the things extensions usually do impossible, so lots of extensions will keep requesting full permissions. I'm not really sure how you fix it. Scoping to a list of domains could potentially work, but adding new domains shuts off your extension so it seems unlikely that anyone could do it when they could request wildcard permissions at install instead. In practice users want extensions to do stuff that implicitly violates security boundaries, so I think making that stuff secure would basically require Google to build it in. Like for example, 1password naturally needs both a way to intercept entry of new passwords (to offer saving) and a way to detect password fields and type into them. Detecting a password field means you need to be able to scan the DOM and detect when the user is interacting with the field. At the point where you can do that, you can snoop on the user on an important page, activeTab or no. If the Chrome Web Store offered straightforward ways to sell paid extensions at least then there'd be less reason to embed malware in your extension instead... My extension (now removed due to legal threats and DMCA abuse) was originally scoped to an application's domain, and then the developer added a new domain so I had to update my extension manifest to add that domain. Doing so shut it off for every user and I had to explain how to turn it back on. Given that experience I should have just put a wildcard in the permissions instead, but I underestimated how bad Chrome's extension infrastructure would be.
- nitrogen 7y agoIsn't that already possible? I have to click to activate extensions until I specifically enable them for all sites.
- mikob 7y agoIt's not that simple. For example, this would break my accessibility Chrome Extension that lets users browse just using their voice (https://www.lipsurf.com https://www.lipsurf.com)
- michaelbuckbee 7y agoThe speculation is that NachoAnalytics (they let you "spy" on your competitor's traffic) does something similar -> using lots of general purpose extensions to collect data.
- AznHisoka 7y agothey shutdown a few months ago.
- dessant 7y agoRecently someone has contacted me to publish a dummy Chrome extension with broad permissions, which they would have updated with their code. After declining, they have offered $20k for the job. It was interesting to see this strategy, they are trying to implicate people to create publisher accounts for them, verified with credit cards that cannot be traced back to them and do not look suspicious. Though the money they have offered seemed too much for the job, I guess they are also trying to hook developers and convince them to do other stuff down the road. I do get plenty of purchase and monetization offers, some of which I have shared in a blog post [1], but this was a trick I have never encountered before. [1] https://armin.dev/blog/2019/08/supporting-browser-extension-developers/ https://armin.dev/blog/2019/08/supporting-browser-extension-...
- deleted 7y ago[deleted]
- ghostbrainalpha 7y agoCould you help me understand how that could be worth 20k? Is your reputation that good? Why not pay any random person $500 for the use of their identity for the same thing.
- dessant 7y agoI do not know what were their exact intentions. If someone from Google would like to take a closer look, contact me to have the emails forwarded.
- bduerst 7y agoIt's like the third party really had no intention of paying 20K, other than to use it as a carrot to dangle in front of the publisher.
- dmix 7y agoProbably some tech support scam thing. It seems to be the biggest business around in shady blackhat circles. You could push a lot of scareware with an extension with full access to the browser.
- wnevets 7y agoand with auto updating you'll never notice the changes.