9 ms·
Amazon Assistant lets Amazon track your every move on the web
- KoftaBob 6y ago"Still, I was astonished to discover that Amazon built the perfect machinery to let them track any Amazon Assistant user or all of them: what they view and for how long, what they search on the web, what accounts they are logged into and more. Amazon could also mess with the web experience at will and for example hijack competitors’ web shops. Amazon Assistant log with a borg eye Image credits: Amazon, nicubunu, OpenClipart Mind you, I’m not saying that Amazon is currently doing any of this." This goes for any browser extension you install if you don't limit which websites it's allowed to read data from. In both the title and beginning paragraph, the author essentially describes the privacy risks that would apply to any browser extension, but words it in a way that implies Amazon is actively abusing those privacy holes, before finding any evidence for it. I really wish people would stop giving views to blatantly manipulative and slimy clickbait like this.
- palant 6y agoYou could also read the article before commenting. It’s one thing when an extension could do something but its code can be inspected to verify that it doesn’t. It’s an entirely different thing if it delegates its privileges to a web service that could do anything and that nobody can inspect. Note: I’m the author of this article.
- KoftaBob 6y agoI stand corrected, I must not have read the article carefully enough my apologies!
- bagacrap 6y agoThis distinction seems somewhat meaningless in practice. Are you going to audit every line of every extension you install, assuming it's all local code? And are you going to do this again every time it's (automatically) updated?
- alisonkisk 6y agoYes. This is exactly what happened with Great Suspender, which led to Google being succesfully pressured to ban it.
- tantalor 6y ago> before finding any evidence for it Did you see the screenshot with the Amazon ad popup obscuring Google ads?
- palant 6y agoThat’s actually legitimate functionality of this extension. :-) Note: I am the author of this article.
- tantalor 6y agoCovering up your competitors ads with your own sounds a lot like "mess with the web experience at will and for example hijack competitors’ web shops". Disclaimer: I work for Google Shopping, but not the ads part :)
- palant 6y agoThe whole extension is all about “let’s see when customers go to competition and try to bring them back.” That’s rather shady but it’s exactly the advertised functionality. And I’ve already got the first comment on the blog essentially saying “I don’t care what else they do, this extension gives great suggestions and I love that.” :-)
- alisonkisk 6y agoYes, but that part is with user consent, so it's an attack on Google and their partners, not an attack on the user.
- mritun 6y agoYou mean the screenshot that shows a browser window just about 400px wide in which page content is forced behind the notification window? Yeah. I saw that too. Disclosure: I work for Amazon but not anywhere close to the browser plugin team(s).
- scubazealous 6y agoThis is a greater issue with the extension/app ecosystem. This morning I wanted to find a android app which would help me time exercises, specifically planking. It should be simple, set up countdown times for front and each side with 5 second breaks in between, playing a tone to let me know when I can move on or I am done with the exercise. I looked through at least the top 20 apps on the play store and all of them require at least full network access and to run at startup. Many were so invasive as to request location and to be able to record audio and take pictures. Being able to monetize these apps is an important thing for developers but it is becoming a real problem I do not see getting any better soon.
- bobthepanda 6y agoStronglifts has a nice app that I don’t remember being overly intrusive. I just wish it were easier to use for other lifting programs.
- pkaye 6y agoThe assistant should play the tune of "Every Breath You Take" by The Police when its doing this.
- cptskippy 6y agoSome smartass developer at Amazon is going to make it console.log that.
- asdfsfkwqe 6y agoYou're gonna need a bunch of them. Cause one single developer cannot get through code review.
- pvaldes 6y agoBeing Amazon, updating it to "Every break you take" feels more appropriated.
- 908087 6y agoI've always thought this would be the perfect theme song for the entire modern "tech" industry.
- antattack 6y agoSeems to me that browser extensions need better access control. Why isn't it possible to restrict it to just amazon.com itself, for example?
- navanchauhan 6y agoI’m not familiar with Chrome/Firefox extensions, but for Safari Web Extensions you can indeed restrict extensions. [0] Edit: Looks like this feature is present in Chrome/Firefox extensions as well but for all these platforms (Safari included I think), this needs to be implemented in the code itself[1] [0] https://developer.apple.com/documentation/safariservices/safari_app_extensions/safari_app_extension_info_property_list_keys/adjusting_website_access_permissions https://developer.apple.com/documentation/safariservices/saf... [1] https://stackoverflow.com/questions/10504239/limit-chrome-extension-to-certain-urls https://stackoverflow.com/questions/10504239/limit-chrome-ex...
- fosefx 6y agoIt's at the core of the WebExtensions APIs permissions system: https://developer.mozilla.org/en-US/docs/Mozilla/Add-ons/WebExtensions/manifest.json/permissions https://developer.mozilla.org/en-US/docs/Mozilla/Add-ons/Web... WE are implemented both by Chromium and Firefox (with nuances)
- palant 6y agoMost of its functionality is meant to work on other websites. There is probably little reason to install it for amazon.com only. Note: I’m the author of this article.
- happyconcepts 6y agoWhich browsers allow users to whitelist specific sites for access by a browser extension? Or else what is the !#?!% technology hurdle preventing users from making their own lists?
- 6y ago
- kevinsundar 6y agoThis is clickbait. The authors argument is that the extension has enough privileges to track you, not that it actually does. For example, uBlock Origin has similar privileges but I doubt the author would bat an eye. EDIT: I take back my comment :)
- ziddoap 6y agoNot only did you miss the point of the article, you must have missed where in these very comments the author replies to someone else who just barely skimmed the article. I will copy/paste it for you. "You could also read the article before commenting. It’s one thing when an extension could do something but its code can be inspected to verify that it doesn’t. It’s an entirely different thing if it delegates its privileges to a web service that could do anything and that nobody can inspect. Note: I’m the author of this article. "
- kevinsundar 6y agoAll right upon closer reading you are correct. I seem to have missed the point of the article. There are some good points that the author brings up. However I still think the title could be better. There are lots of things that applications "can" do. I put more trust into random applications that run on my system.
- palant 6y agoYes, you put considerable trust into applications running on your system. But I hope that you don’t just install random applications. You probably choose only vendors where you can reasonably assume that they don’t want to accept the backlash of having shipped a malicious application. Now shipping a malicious application is always a risk. This application release is evidence of misbehavior, should someone choose to analyze it. This risk is almost non-existent with dynamic web applications. It would have to be the one targeted user who analyzes megabytes of code. To sum up: there is a good reason why websites are sandboxed and don’t get any access to your system. Note: I am the author of this article.
- 6y ago
- drewda 6y agoWasn't this the shtick of the "toolbar" plugins offered by AOL, Yahoo, and even Google at one point over the years?
- space_ghost 6y agoMy first thought was BonziBuddy: a free "assistant" program that was monetized by capturing and selling your personal data and displaying ads directly.
- tgsovlerkhgsel 6y agoThe Google toolbar specifically had a privacy settings popup with a big fat red "PLEASE ACTUALLY READ THIS" notice, explaining what it does, and letting you choose between a mode that only worked locally (unless you were making a search or explicitly triggering some other online feature of course) vs. one that sent some data to Google with each visit (with PageRank display being tied to sending the data). Users weren't pushed to choose one or the other. Both buttons had the same size and color. It was VERY clear that the developers wanted users to make a meaningful, free choice vs. "just click approve". The benefit for Google was that installing the toolbar made it easier for you to do Google searches, driving usage up. Edit: https://searchengineland.com/turning-the-tables-on-the-google-toolbar-disclosure-claims-63596 https://searchengineland.com/turning-the-tables-on-the-googl... has a history of these screens, going from the above-mentioned exemplary "please read" screen to an increasing amount of dark patterns.
- TedDoesntTalk 6y ago> Putting these JavaScript files into the extension would have been possible with almost no code changes The AMO team at Firefox used to outright ban addons with remote script injection. I guess it matters who you are -- like on the Apple App Store, big names just need to pull the right strings or call the right people for a free pass. Rules are not applied equally. The playing field is NOT level.
- cptskippy 6y ago> Rules are not applied equally. The playing field is NOT level. That's true, always has been. > big names just need to pull the right strings or call the right people for a free pass I'd be curious if that's the case. For the most part in B2B, "the rules" generally only apply when the risk of a client doesn't out weight the benefit of that client. T&C and Contracts are always negotiable, it's just a matter of if it's worth it to both parties. Amazon has more street cred than say, me, as a developer. And Amazon has a lot more to lose from their Add-On doing a bunch of evil things that I would if I decided to do evil things with mine. Amazon is big enough to assume liability for both itself and Mozilla if something goes wrong, I can't.
- alisonkisk 6y agoIf you did exactly what Amazon did you'd be "evil", but they get a pass because they bought the companies they sell data to.
- cptskippy 6y agoI'm not defending Amazon but what did they do that was evil? From what I read in the article, they were doing things a normal add-on developer isn't allowed to do, but that isn't inherently evil. In a similar vein, your reasoning would conclude that white hat hackers are evil as well. Having the power to do something bad, and doing something bad with that power are not equivalents. Is it unfair that they received that power? Yes. Does that make it evil? No. Do I trust them? No. I'm not defending Amazon, I'm questioning your reasoning because I don't arrive at the same conclusion.
- unhba 6y agoIt will be interesting to see how the developers of this extension respond to Google’s roll out of extensions Manifest V3 - the new specification could almost be directly targeting them: with service worker replacing background script there will no longer be a concealed window to mount those iframes. Thanks to the author for this write-up
- EastSmith 6y agoIs there a need for iframes to exists today? Can we somehow block them?
- ctvo 6y agoExcellent article by the author. The subtle point of delegating everything to remote services is your user doesn't need to know when you've modify behavior. If Amazon were to bundle the content, you'd need to explicitly update your extension. You're delegating to Amazon that they'll continue to respect your privacy (no claims were made they weren't), but also their systems are secure, and will continue to be. This is too much trust to give any entity. No thanks. From Amazon's perspective, they probably have more than one team working on the extension. A coordinated deployment process at scale is painful. Allowing each team to deploy to its own endpoint and communicate with other components via message passing (events) is exactly how you'd expect a company that grew up on SOA to design.
- joshgoldman 6y agoThis place is becoming like Reddit with the conspiracy theories
- Klwohu 6y agoHahaha, take your meds you schizo incels, right? Ya ever think you could be overdoing it a tad? It's becoming a joke you know...
- GekkePrutser 6y agoExcept he gives technical proof how this is done. No, it's not possible to see what Amazon does with this information but it's clear they can do way too much. And, they can change the behaviour at any moment without the user getting notified within these existing wide permissions. At the very least it's very poor design.
- propogandist 6y agohere's a campaign [1] where Amazon was paying $5 credit to get this spyware installed on the browser. These campaigns have been going on for years. [1] https://slickdeals.net/e/14668013-select-amazon-member-earn-5-amazon-credit-with-amazon-assistant https://slickdeals.net/e/14668013-select-amazon-member-earn-...
- mgdev 6y agoI designed this. I won't speak to any past or current practices, but I will say this: Amazon is obsessive about protecting customer privacy.
- MikeUt 6y ago> protecting customer privacy Does "privacy" mean Amazon will spy on their customers, but won't share that data further?
- alisonkisk 6y agoYes. It means they don't outsource privacy exploitation.
- palant 6y agoUnfortunately, that’s only your word. The way this system is designed, nobody will notice if Amazon chooses to be less obsessive about it. Or if their systems are hacked. Are you certain that these web services are secure? I’m not (one obvious vulnerability has been reported). If someone compromises one of these services, the results will be disastrous. Note: I am the author of the article above.
- mgdev 6y agoSpeaking for myself, not the co: we all decide who we want to trust and why, whether it’s browser extension, or a browser, or a phone. For me, it comes down to alignment and value. Amazon stands to lose a lot if they decided to suddenly stop caring about customers, or not take security seriously. And the Internet gets pretty small if your threat model requires zero trust.
- unhba 6y agoI work on a shopping assistant type browser extension and I am very confident that if I proposed an architecture and implementation such as the author identifies here I would be turned down immediately: having good intentions around privacy is one thing but deliberately designing your application in a way that allows to bypass almost entirely the review process required on submission to the store is something that should be answered for.
- tobib 6y agoOh my. Who in their right mind would install that?! I just setup pihole today because it's so difficult to avoid being spied on wherever you go.
- m463 6y agoI remember, years ago, installing the amazon app on my phone. And one day I was browsing a web page in safari and boom - it auto-launched the amazon app and opened it there? That's when I learned about deep linking, where apps can snoop on ios website activity (in safari, in messages, in mail, etc).