24 ms·
Let's build a Chrome extension that steals as much data as possible
- WWLink 4y agoYea Chrome would be a lot more secure if we didn't let anyone view any data at all.
- krono 4y agoJust the title of this post alone should make it more than obvious that the article is not about preventing anyone to view data, but rather to grant anyone access to it in an exploitative way. In response to the article itself: you might even be able to get such an extension on the Firefox Extensions store and just maybe get a "Recommended" status too. Refer to my comment in another post from a few days ago for other such current violations: https://news.ycombinator.com/item?id=34832280 https://news.ycombinator.com/item?id=34832280
- Afforess 4y agoThis is an excellent accidental rebuttal to the entire Manifest v3 project. The stated reason for the new major version and breaking changes is officially: > Manifest V3 represents one of the most significant shifts in the extensions platform since it launched a decade ago. Manifest V3 extensions enjoy enhancements in security, privacy, and performance... https://developer.chrome.com/docs/extensions/mv3/intro/ https://developer.chrome.com/docs/extensions/mv3/intro/ Web developers (see uBlock origin for one) have been complaining that Manifest v3 breaks chrome extensions for no discernible benefit and Manifests v3 exists entirely to protect Google's ad business. This review gives fresh evidence to support that assertion and showcases Google's deception. As seen in this blog post, extensions can request literally every permission and the user permission warning actively hides the permissions beyond the content fold.These changes haven't been made for security's sake. I wish the entire Manifest v3 was scrapped, but that likely won't happen. I'll settle for people assuming Google is lying by default.
- krackers 4y agoThe counterpoint might be that being declarative it's easier to do static analysis to find malicious extensions. But I'm not sure how much I buy that argument, and it's no excuse to disable v2 extensions entirely.
- tyingq 4y agoIt just removes the OnBeforeRequest() way of injecting javascript. There are other directly supported ways to inject javascript, some of them easier than OnBeforeRequest(). The counterpoint would have to be something like removing that was just the first step, and that they plan on closing all the doors. But, if you close all the doors, really all the most popular extensions are hobbled. Edit: Removing just OnBeforeRequest() js injection does sort of uniquely harm mostly heuristic ad blocking and things like tampermonkey. It's not hard to feel like that was probably the real goal.
- jsnell 4y agoIt's good that it doesn't pretend to be a rebuttal, because it'd be a bad one. I'm pretty sure the point of making a declarative content blocking API for adblockers is not to block all possible ways of writing a malware extension. It is just to make the most popular category of extensions safe by design. Once that has been done, it's then much easier to improve the situation with the remaining niche use cases. What would those improvements look like? It could be finding other common ways of dangerous permissions being used by legit extensions, and extracting these patterns out as explicit and safe capabilities. It could be changing the messaging to make it easier for users to understand how dangerous the requested permission is (which they can't reasonably do while those dangerous permissions are still used by adblockers!). Or it could be a stricter review process for any extensions needing such permissions. This extension that the author themselves think would never pass review doesn't really rebut that in any way.
- Afforess 4y agoChrome extensions that contain malware aren't written and submitted to the chrome store hoping to sneak past review. Malware authors _purchase_ the intellectual property of fulling functioning, useful extensions, and update them to contain their extra malware payload. I'm not sure where you got the idea that a review would be involved here at all.
- zapstar 4y agoAnd this is why I am hesitant to install any and all Chrome extensions. Well done!
- ocdtrekkie 4y agoAt the office we maintain a policy which restricts any extension installs but ones explicitly vetted by IT. I would go so far as to suggest any company that doesn't do this is negligently irresponsible with computer security at this point.
- KennyBlanken 4y agoThe author notes that this sort of extension would be laughed out of the review queue....but there are plugin authors who get plenty of users by putting up a website and making the plugin available directly from their site. For example, the author of FB Purity hasn't explained to anyone why his plugin is not available via Firefox's extension store, only via his page. Presumably, he didn't meet some requirements they had...but he won't say what they were...
- mimimi31 4y agoDon't all Firefox extensions have to be signed by Mozilla in order to be installable (in non-developer Firefox editions at least) these days? Even if they're publishing it on their own site, it should have gone through the review.
- lapcat 4y agoYes. It's mostly automated review, usually taking a matter of minutes, though I guess Mozilla reserves the right to do manual checks if they find something suspicious.
- dcow 4y agoWhich is exactly why these permissions exists. If you don't take permissions that allows you to horrible things, you are rubber stamped and can go on your way. If you want to do more involved things, you're escalated.
- lapcat 4y agoMy Firefox add-on has "<all_urls>" permission and gets rubber-stamped.
- stefan_ 4y agoGiven all the extensions in the store that are at some point updated with a trojan to sell your internet connection to shady people, the "review queue" is some kind of mythical beast that doesn't in practice do or achieve anything. It would be trivial for Google to find all the extensions using that kind of crap, but they don't care.
- NovemberWhiskey 4y ago>Identify and eject storage devices I mean, why?
- codetrotter 4y agoBecause browser makers and web app devs want to be able to do everything desktop software can, but inside of a browser. In theory it’s kind of neat.
- abraham 4y agoIt's a chrome APi, not a browser web API. https://developer.chrome.com/docs/extensions/reference/system_storage/ https://developer.chrome.com/docs/extensions/reference/syste...
- autoexec 4y agoIn theory that's basically like letting anyone on the internet run arbitrary code on your devices which is a terrible idea. In practice it's like letting anyone on the internet run arbitrary code with a few guardrails to catch the worst and most obvious abuses while it takes control away from the user and allows for highly invasive forms of tracking that is very hard to prevent.
- pcthrowaway 4y agoIn theory, there is no difference between theory and practice; but in practice, there is.
- Gigachad 4y agoIt’s all because of chromebooks. Google has had to implement basically every capability as a js api so Chromebook’s can do real work.
- dcow 4y agoYou should have been around before chrome books when any extension could do whatever it wanted without any permissions at all. Your understanding of history is missing some key pieces. Over time, Google has generally locked these APIs down not opened them up.
- metadat 4y ago> Chrome scrolls the permission warning message container, so more than half of the warning messages don’t even show up. I’d bet most users wouldn’t think twice about installing an extension that appears to ask for just 5 permissions. An egregious and nearly unbelievable oversight on Google's part. :-\ As a developer, it's unimaginable to me to not test the extreme high and low numbers of inputs cases to ensure things look and operate as expected. Especially for a security sensitive UI element. The chain of humans who've been responsible for developing and testing Chrome Extension functionality and security has been asleep at the wheel this whole time, for something like 15 years. There are so many risk-reduction controls in place; tons of red tape and umpteen security and privacy reviews required to ship even minor features or updates, yet here we are. How many hands have been in the pot and not noticed/raised/resolved what amounts to a pretty obvious security vulnerability? And if this kind of issue can fly undetected for so long, what can organizations with drastically less resources than $GOOG do to ensure adequate velocity while not leaving the proverbial barn doors open? The author deserves the highest tier of bug bounty reward for bringing this to light. What's that? It wasn't submitted through the proper channels to be eligible? Right. <insert relevant Dildbort cartoon>
- s4i 4y agoBut isn't the scrolling problematic here only because macOS by default hides the scrollbars when there is no traditional mouse connected?
- eimrine 4y agoI've experienced this problem once on Windows when I've installed a free VPN and noticed that the list of permissions lacks some obvious points.
- eyelidlessness 4y agoThis introduces an especially silly attack vector: if you expect that asking for a specific permission might alarm users, and if you can push it below the fold, just ask for more innocuous or plausible permissions than you need! Besides the oversight of hiding some permission requests, this highlights that the order they’re presented matters too. Even if it weren’t scrollable with ~invisible indication of that, people stop reading at some point. If N lines (I’m gonna guess ~5 for most people) seem totally innocuous, the rest are probably effectively invisible.
- nostromo 4y agoWait until you see what’s possible with executables! I like this project, but I also worry that eventually we’re going to lose access to extensions entirely because people will take away the wrong message. Safeguards are good, but at a certain point I want my devices to trust that I know what I’m doing.
- Sunspark 4y agoThat already happened with Firefox for Android. The old version allowed extensions, the current version only allows something like 10 specific ones. There will always be a forked browser or an independent browser that supports/allows extensions as long as the web uses HTTP.
- ClumsyPilot 4y ago> Wait until you see what’s possible with executables! The most important thing is whay you tell the user - Windows says "We don't know where Trojan.exe came from, it could be a virus, are you sure you want to run it?" Chrome says: "You downloaded Trojan.exe from our store, we manage it and check it for viruses. It only asks for harmless permission, install it!" One is warning you, the other is entrapment.
- dcow 4y agoWindows has an app store now too. > It only asks for harmless permission, install it! Not true. It lists all the permissions being requested. Sure the scrollbar issue is real and should be an easy fix. I don't understand why people are so confused about permissions. If the user grants your extension permission to read your browsing history so it can provide value to them, why is that a problem? It's not. The problem is if the user grants a malicious extension the same permission because the extension is fraudulent. The author said this extension would never pass chrome store review, so it seems that the user would never be in this position in the first place and your example doesn't really match reality.
- Dalewyn 4y ago>I don't understand why people are so confused about permissions. I don't understand why people (read: devs) still assume permissions are read and understood. The vast majority of people simply do not read nor understand permissions and just instantly hit the OK button. Even Linus from LinusTechTips doesn't read permissions, and he's even a tech guru unlike most people.
- mfrisbie 4y agoAuthor here! I'm tickled to see that this whimsical cautionary tale is so resonant.
- dcow 4y agoDo you have any concrete recommendations beyond the obvious "fix the glaring permissions UI scroll box issue"? Are you advocating for browsers to remove these permissions altogether because you feel they're too dangerous? Are you lobbying for a shift towards use-site triggered permission requests like Safari does? It seems you understand the tale is whimsical but I fear some people view it much more seriously and want to start an extension witch hunt. It would be nice to see a concrete call to action so it would be more clear what your proposed solution is instead of just inciting a bunch of pitchforks with no clear goal.
- drpixie 4y agoI'd like a fork of chrome which removes all (or at least most) the "features" mentioned - a browser that renders well but just doesn't support these masses of unsecure features. If you want to give 3rd parties access to all that stuff, you can run chrome. But I don't - I want the bare minimum that will run normal websites. I know that will break some pages, I'll accept that. (And that would give me a smaller & faster browser.)
- alooPotato 4y agoWhat else would you remove? If it's just extensions, can you just not install them?
- jeroenhd 4y agoIf you don't install any addons, you'll be fine. You'll have to do without uBlock Origin and other ad blockers, though. Consider Brave if you still want those and want to stick to Chromium. In Firefox, you can go to about:config and set the default permission to deny to a lot of stuff (notifications, clipboard, etc.). You can also disable webgl and other features like those.
- drpixie 4y agoI'd feel much more secure, from extensions and websites if those permissions just didn't exist. I can only turnoff what I know about, but not those new things quietly added with each update.
- deleted 4y ago[deleted]
- sb8244 4y agoI don't understand this sentiment. Websites can't use these permissions so it's not applicable at all.
- ClumsyPilot 4y ago> uBlock Origin and other ad blockers Router based adblockers work well, Flint by GL.net comes with nice UI and adhlock and VPN built in. Some people complain about its chinese origin but at least I know only 1 government is spying on me - my provider supplies a router with a linux kernel older than this house. There could be an entire ensemble of Trojans partying there
- alooPotato 4y agoNow try actually distributing it. My guess is this wouldn't even get close to getting through the review process for the Chrome Webstore. From our experience with Streak, this would def get picked up in review. Seeing other comments in the thread pointing to this article as a reason why MV3 is bad I think misses the point. Personally I think MV3 is a step in the right direction (even though it negatively affects us!). But it's only one piece to make extensions more secure - the others being manual review, policy adjustments and automated scanning. Even though the APIs allow for all sorts of functionality doesn't mean you'll be able to get through the rest of checks.
- schoolornot 4y agoMy experience so far with publishing to the extension store has been that they examine both the code shipped as well as the scopes used. I've had apps rejected due to overly broad scopes and it was obvious based on the responses that the reviewer was pretty competent at JS.
- jackdh 4y agoHe mentions this in the article, the heading is "Publishing to the Chrome Web Store" "This extension would be laughed out of the review queue."
- moneywoes 4y agoThe real trick isn’t publishing a new app, it’s purchasing an existing app and pushing an update with malicious code. The latter review process is more lax
- alooPotato 4y agoNo it's not. From our experience at least.
- shultays 4y agoJust buy an already published popular extension and submit an update
- wolpoli 4y agoOne of the issues here is that the browser is prompting the user for all the Permissions at install time. Both Android and IOS have moved away from that. Perhaps it is time browsers to move away from that as well.
- mard 4y agoExtensions are one thing, but I'd also welcome granular permissions to various JavaScript capabilities for every website. I don't like when some websites capture native browser hotkeys (CTRL+F), disable my right mouse button, change scrolling behavior or perform asynchronous HTTP requests. The only solution I found to protect against these practices is disabling JavaScript completely for given site, but more often than not it prevents the page from rendering altogether.
- dcow 4y agoThis is a spicy essay for sure but what is the author's actual point? If the user grants you permission to do all these things, then you have permission to do all these things. If you can't be trusted and abuse that permission then you are not ethical. If you aren't ethical someone will find out and your extension will be removed in the worst case and simply not approved in the common case. The author even admits as much saying this thing would never pass Google's review process in a million years. Sounds like there's no real risk here and we're mostly just enjoying the show... I do agree about the permission UI box. Surely that's a completely simple fix on Google's part to force the user to scroll through the permissions box before accepting.
- modeless 4y agoIs that solving any real problem? Will any single person actually be protected by that annoyance? The permissions already appear roughly sorted by invasiveness. Is the sixth one really going to be the one that your install decision hinges on? I mean, once you have "Read and change all your data on websites" it's game over anyway if the extension is truly malicious.
- dcow 4y agoI think perhaps we need to agree on the real problems that exist. It's not like users are getting their data stolen left and right out there and man these extension trojans are winning the battle against good extensions and we just can't shake 'em. All your base... are belong to us. It seems the status quo is that extension fraud, while entirely possible as this article demonstrates, is not actually a problem. If you don't trust a piece of software to access your webpage content then don't grant it the permission to do so. I think the onus is on alarmist pieces like this to bring the data supporting the existence of a problem to be alarmed about in the first place. I mean, raise your hand if you've been pwned by a malicious Chrome extension recently...
- panda888888 4y agoIt's very early for users to not understand and for apps to ask for a bunch of permissions. One great example is Grammarly, which is a keylogger that helps users with grammar. I don't think Grammarly has bad intentions, but still, millions of users are giving it access to everything they type.
- Sephr 4y ago> If we’re expecting the page DOM to change often (for example, with SPAs), we certainly don’t want to miss out on any valuable data. Just set a MutationObserver to watch the entire page, and reapply listeners as needed. The code below this text is highly inefficient and may lead the user detection solely from page interactivity slowdown alone. A more efficient implementation could read input using the 'input' event[1]. For example, here[2] is how you would use the input event to detect changes to any fields in a page. 1. https://developer.mozilla.org/en-US/docs/Web/API/HTMLElement/input_event https://developer.mozilla.org/en-US/docs/Web/API/HTMLElement... 2. https://gist.github.com/eligrey/615fcc9fa9edbfb5153478109b5b1185#file-universal-unsaved-changes-detector-js-L21-L37 https://gist.github.com/eligrey/615fcc9fa9edbfb5153478109b5b...
- mfrisbie 4y agoFair point, multiple people have circled this snippet as problematic. I'll confess, I didn't spend much time testing this for performance. My idea was that separate inputs should have separate debounced handlers, but it's likely you could do away with that and just listen for input events globally with no adverse effect on data collection.
- harry8 4y ago"Let's build a Chrome extension that taps what google is already stealing." But it isn't stealing if you clicked something somewhere sometime so "stealing" is wrong will be the PR response because people are being paid to not understand "stealing is wrong"
- paulpauper 4y ago100% this is how people are getting their social media accounts hacked for scams, crypto stolen, etc. Stronger passwords is useless when the session is stolen, when the actual data is read and sent off
- lewantmontreal 4y agoBeing able to lift cookies from every website you are logged into sounds crazy and amazing. Anyone have any clue what people are using it for? Maybe roll your own session sync?
- interpol_p 4y agoI don't understand why Chrome even does up-front permissions. iOS got this right from the start: ask on the first attempted access of the gated resource, allow the user to grant the permission once or on an ongoing basis, respect the choice. Don't allow permission prompt spam. Even Android recently moved to this model from up-front permissions, so Google is aware of it.
- vivegi 4y agoProbably off-topic. Has anyone done a security review of ublock origin chrome extension?
- a13o 4y agoLook, I hate MV3 as much as the next guy. I've even wasted part of my life porting a large extension to it, so I might hate it MORE than the next guy. But I don't draw any security conclusions from this article. For every permission in your manifest you need to provide the chrome web store reviewer with a written justification for why your extension needs that permission. Even the ones that don't prompt the user. And they definitely read it, and your code. Shipping malicious extensions is almost entirely a social engineering problem and not a technical one.
- patientplatypus 4y ago[dead]
- Dr-NULL 4y agoYou really know how to write an article which is technical and at the same time fun to read.
- mfrisbie 4y agoHigh praise indeed! Thank you.
- dclowd9901 4y agoIf not alerting the user was a primary goal, they done messed up using MutationObserver. It would absolutely halt the browser completely, especially running across multiple tabs.
- cush 4y agoReading this makes the Apple App Store walled garden not seem so bad after all. If someone were to add an extention with this manifest, would it even be reviewed, or would it need to be flagged first?
- prakhar897 4y agoI have a chrome extension with about a 1000 DAU right now [link below]. I'm getting messages to buy the whole thing out but the buyer always fails to answer why they want to buy it. they are also open to buying any extension whatsoever. I suspect it's to open up the permission model and started stealing user's data. link: https://github.com/prakhar897/workaround-gpt https://github.com/prakhar897/workaround-gpt
- eimrine 4y ago> Just set a MutationObserver to watch the entire page, and reapply listeners as needed. I did not know such thing is possible. I want to make an extension which undeletes some chat messages in typical chats (usually that happens because of moderation)
- waqas_x 4y agoMaintainer of a Chrome Extension with 10,000+ installs here. Chrome doesnt willy nilly approve your extension. They even take down extensions that ask for permissions you do not legitimately use. The article doesnt say for how long op was able to put his extension on the chrome store without it being reviewed or taken down.
- Reventlov 4y agoIt does: « Publishing to the Chrome Web Store − I’m kidding, of course. This extension would be laughed out of the review queue. »
- quectophoton 4y agoThis is my main worry with Firefox as well. How can I even be confident beyond reasonable doubt that the uBlock Origin extension I have installed won't suddenly start exfiltrating any passwords I enter on websites, for example.
- bakugo 4y ago>How can I even be confident beyond reasonable doubt that the uBlock Origin extension I have installed won't suddenly start exfiltrating any passwords I enter on websites, for example. You can't, just like you can't be confident that any other piece of software on your computer won't start doing it. This problem isn't specific to extensions in any way and I don't understand why people act like it is. If the risks are too much for you, don't install them, just like you wouldn't install any other software you don't trust. Don't try to ruin it for other people who understand and are willing to take the risk.
- quectophoton 4y agoPlease try not to extrapolate my comments to conclusions like I'm (quote) trying to ruin it. Keywords are "beyond reasonable doubt". uBO is a Recommended Extension, and even has a badge that says it's only granted to extensions that meet their standards of security. But do we know if Firefox manually reviews updates as well, for changes in their source code? Or do they only review them once (at the moment where they grant that badge)? I can't find conclusive info on that front. I would be happy to know that a few extensions get their updates manually reviewed.
- emaro 4y agoYou cannot. Not with any software you didn't write or very carefully review. It's always about trust. In the case of your example, I think gorhill is a prime example of a trustworthy author. He has a very good track record, never betrayed the users, explains his thought process and behaved consistently in the users (my) interest in the past. uBlock Origin is the one extension I trust the most, even more than say the Multi Container extension from Mozilla.
- marcopicentini 4y agoCool. What’s the easiest way to push this data to a remote server?
- tomthumb 4y agoThe probable intent of the author of this article is to let devs to know about his book: “Building Browser Extensions”. Ordered mine just now.
- imiric 4y ago> Without looking, can you name more than half of the extensions you have installed right now? Sure. uBlock Origin, Multi-containers, Temporary Containers and cookies.txt on Firefox, which I only use for specific purposes. History and all data is wiped frequently. None on Chromium, which I always use in incognito mode. I use this daily, but don't need even uBlock on it, since I run a DNS ad blocker on my network. And none on my main browser, Luakit, since it doesn't support extensions. :) Technically, I have some user scripts, which I've all reviewed or written myself. Browser extensions are the number one security and privacy risk for all users, more than any OS exploits. The fact they've historically been handled so poorly, and these issues exist even today, should be terrifying. Great article and extension! <3
- mschuster91 4y ago> Who maintains them? Is it the same entity that maintained it when you first installed? Are you sure? Oh yeah, got bitten hard myself on that one a couple years back, it took Google days to respond to the extension buyer uploading a malware'd version. The worst problem is that extensions auto-update silently so you as an user don't even have the chance to spot anything in time.
- mariusmg 4y agochrome.tabs.captureVisibleTab() Anyone knows what is the actual legitimate use case for this API ? Seems very dangerous to allow extensions access to it.
- MagicMaker55 4y ago[dead]
- UniLove 4y ago[dead]
- scoot 4y agoIs anyone aware of a Chrome extension (or other spyware) that uses the macOS system clipboard to steal WhatsApp data? I recently had an incident where WhatsApp Web was open in a tab in the background in a different browser window to the one I was actively using. I received and replied to a message on my phone. So imagine my surprise when I went to paste what I had previously copied from a web app in one Chrome tab to into a textfield in another, both in the active Window, to find that what was pasted was the second last message that I had sent in WhatsApp on my phone. I have since deleted my Chrome profile at a system level, and the only extension currently installed is a well known password manager, but it bothers me to think what could have caused this aberrant behaviour, and whether there's something still installed on my system that's stealing data.
- DragonShoot 4y ago[dead]
- MoonBabe 4y ago[dead]
- DireFire 4y ago[dead]
- CandyRandy 4y ago[dead]
- MapleDreams 4y ago[dead]
- PeachyCupcake 4y ago[dead]
- SunkissedSue 4y ago[dead]
- WaterWanderer 4y ago[dead]
- Moonshining 4y ago[dead]
- SunnyMaylor 4y ago[dead]
- WiseWolfie 4y ago[dead]
- LuckyBug 4y ago[dead]
- FriendlyFlame 4y ago[dead]
- FriendlyFlame 4y ago[dead]
- WoozyWarrior 4y ago[dead]
- AdorableLama 4y ago[dead]
- TurkeyTurtle 4y ago[flagged]
- antisthenes 4y agoIt's funny. They crippled extension usefulness in the name of "security", yet you can still make something like this that will steal every piece of your data and masquerade as your tabs while performing malicious behavior. Very secure, indeed! But at least those pesky adblocks are defeated.
- DuskyHusky 4y ago[dead]
- PenguinPeace 4y ago[dead]
- SunnyHorsey 4y ago[dead]
- WiseSnail 4y ago[dead]
- stillsleepy 4y ago[dead]
- ZappyHippo 4y ago[dead]
- PudgyPanda 4y ago[dead]
- SassyStarlet 4y ago[dead]
- BeingBean 4y ago[dead]
- LovableLily 4y ago[dead]
- SappyHippo 4y ago[dead]
- FoxyFox22 4y ago[dead]
- LetFree 4y ago[dead]
- FreeBee 4y ago[dead]
- SuperDud 4y ago[flagged]
- infinityio 4y agoWorth noting the "Netflix Party" in question is not the extension now called Teleparty (previously Netflix Party), which is an order of magnitude more popular than the compromised equivalent named here
- QueenBean 4y ago[dead]
- NerdAlerts 4y ago[flagged]
- KomoD 4y agoNice, a bot account trying to farm karma.
- LadyXaga 4y ago[flagged]
- KomoD 4y agoCool, two bot accounts farming karma
- ChillNilly 4y ago[flagged]
- KomoD 4y agoWild! There's 3 "bot" accounts posting stolen snippets
- SmoothBooth 4y ago[dead]
- AboveSkies 4y ago[dead]
- AboveSkies 4y ago[dead]
- KomoD 4y agoWhat's up with the tons of fresh accounts (all created 3 days ago) posting plagiarized snippets in the comments? Various snippets from news articles, Quora, etc. Sample of accounts: ChillNilly, LadyXaga, NerdAlerts, SuperDud, QueenBean, Moonshining, LetFree, FoxyFox22, TurkeyTurtle, LovableLily, BeingBean, CandyRandy, AdorableLama, WiseWolfie, WoozyWarrior, PenguinPeace, SunnyHorsey, SunnyMaylor, WiseSnail, ZappyHippo, FriendlyFlame, PudgyPanda, FriendlyFlame
- mfrisbie 4y agoIt's very bizarre, and possibly why it got kicked off the front page
- greenhearth 4y agoGreat stuff! This is what I come here for.