11 ms·
Show HN: Little Rat – Chrome extension monitors network calls of all extensions
Hi HN
I needed a way to monitor network calls made by chrome extensions so I made a small extension.
You can install it by dropping the zip or crx into the extensions page. It'll be on the chrome store whenever/if it gets through the review.
Hopefully it's useful to others.
https://github.com/dnakov/little-rat https://github.com/dnakov/little-rat
https://twitter.com/dnak0v https://twitter.com/dnak0v
- mickelsen 3y agoThank you so much! This is so useful, now I don't have to audit extensions manually.
- chinmayag32 3y agothat's a good use case.
- budoso 3y agoBut who’s watching rat man?
- npace12 3y agolittle rat is watching itself too
- deleted 3y ago[deleted]
- canthonytucci 3y agoLove the name. I have been looking for something just like this.
- leke 3y agoWhy not on the chrome store?
- npace12 3y agoIt's currently under review because it's using the chrome.declarativeNetRequest (same API uBlock is using)
- cal85 3y agoHang on do you mean to say the web store might accept an extension with `declarativeNetRequestFeedback` permission, it just might take longer and be less certain? I've got an extension that could potentially really benefit from using this permission (because I want to be able to dynamically decide whether to take an action in a content script based on the `Content-Type` header; currently I use imperfect content-sniffing heuristics instead). The last time I dug into it, it seemed that this permission just wasn't going to be available after the Manifest v3 moratorium that has already passed. So I'm interested to know if anything has changed (or if there's any special way that extensions can be approved with this permission, e.g. if they're popular enough and have a good privacy track record).
- npace12 3y agoI'm not sure, but I was curious too, so I submitted it for review to find out.
- cal85 3y agoInteresting, I had assumed it wouldn't even allow uploading it if the manifest required that permission. Hope they allow it for you!
- npace12 3y agoIt got rejected today but not due to the permission, I'll pretty it up and try again. Violation reference ID: Yellow Zinc Violation: Description provided is insufficient to understand the functionality of the item.
- 3y ago
- cantSpellSober 3y agoThanks for sharing! I'll wait till it's on chrome store cuz I'm lazy and don't use Twitter.
- Daviey 3y ago1) Go to Releases, right click the crx file and save. 2) In Chrome, go to Extensions then drag and drop the crx file 3) Profit
- smusamashah 3y agoIt is added to extensions but remains disabled with following message > This extension is not listed in the Chrome Web Store and may have been added without your knowledge. Learn more https://support.google.com/chrome_webstore/answer/2811969?visit_id=638276282560193128-2659469452&p=ui_remove_non_cws_extensions&hl=en&rd=2 https://support.google.com/chrome_webstore/answer/2811969?vi...
- judge2020 3y agoSince it uses `declarativeNetRequest.onRuleMatchedDebug`[0], which is supposed to be debug-only, I doubt it'll be allowed in the chrome webstore. 0: https://github.com/dnakov/little-rat/blob/f0b9b6be39af9fe7f4260604baccbc1ebd4d470e/service-worker.js#L31 https://github.com/dnakov/little-rat/blob/f0b9b6be39af9fe7f4...
- bluish29 3y agosounds great, do you have plans to port it to Firefox? Does anyone know an equivalent that do the same thing on Firefox?
- npace12 3y agoYeah, I'm going to try this shortly, will post an update.
- distortedsignal 3y agoInteresting. I'll be watching this. Thanks for the project!
- fjfuvucucuc 3y agoWaiting :)
- npace12 3y agoupdate: so far not great... declarativeNetRequest.onRuleMatchedDebug is not available [1] Even though the docs say it's behind a flag [2], it's undefined. [1]: https://bugzilla.mozilla.org/show_bug.cgi?id=1745773 https://bugzilla.mozilla.org/show_bug.cgi?id=1745773 [2]: https://developer.mozilla.org/en-US/docs/Mozilla/Add-ons/WebExtensions/API/declarativeNetRequest#testing https://developer.mozilla.org/en-US/docs/Mozilla/Add-ons/Web...
- 123pie123 3y agolooking forward to this
- username135 3y agoSame
- vdfs 3y agoIn most cases, just adding "var chrome = browser;" to the top of each js files would make it work for firefox, which is just a copy of Chrome Extension APIs with slight changes
- yuvalkarmi 3y agoPretty close naming to Little Snitch - the Mac network monitoring tool!
- deleted 3y ago[deleted]
- cantSpellSober 3y agoI assumed that was intentional (rat being slang for snitch)
- npace12 3y agohaha yes, I called it Tiny Snitch at first, but it's too close.
- Daviey 3y agoThanks for sharing, would you mind explaining how it works and if there are any general concerns you have with Chrome not sandboxing between extensions? ie, what else is shared between extensions and what risks do you feel are here. Thanks
- lapcat 3y agoThe key code is here: https://github.com/dnakov/little-rat/blob/f0b9b6be39af9fe7f4260604baccbc1ebd4d470e/service-worker.js#L31 https://github.com/dnakov/little-rat/blob/f0b9b6be39af9fe7f4... chrome.declarativeNetRequest.onRuleMatchedDebug.addListener((e) => { if (e.request.initiator?.startsWith('chrome-extension://')) { Given that the extension is using a "Debug" API, it seems unlikely that the Chrome Web Store will approve. "Only available for unpacked extensions with the declarativeNetRequestFeedback permission as this is intended to be used for debugging purposes only." https://developer.chrome.com/docs/extensions/reference/declarativeNetRequest/#event-onRuleMatchedDebug https://developer.chrome.com/docs/extensions/reference/decla...
- npace12 3y agoYeah, that's correct. The extension loads a rules_1.json file that just "allow"s all traffic originating from third-party scripts through, then logs just the URL of each request coming from a chrome extension. There's probably a way to do this with chrome.webRequest, I'll experiment with that, but generally that one is more expensive in terms of performance.
- gorhill 3y ago> There's probably a way to do this with chrome.webRequest Network requests initiated by other extensions in their own context are not visible to other extensions through the webRequest API.
- npace12 3y agoDamn, I was gonna go research it just in case, but then I noticed who posted this. Mad respect for your work!
- FrenchDevRemote 3y agoreally cool thanks!
- jedberg 3y agoHow can I be assured that installing a random Chrome extension from a random person on the internet that has access to all my network data and can't get approved in the Chrome store is safe? :)
- devilsAdv0cate 3y ago[dead]
- npace12 3y agoI'm with you on that one, that's why the code is on github. The best way to install it is to check out the code for any risks, download the repo as a ZIP file and install it.
- duiker101 3y agoI guess the answer is that you must be able to read the code and use your own judgement. Here the actual code of the extension is basically 2 files, one of 114 lines and the other 66. Plain js, easy to digest. Looks pretty safe.
- BowBun 3y agoVerifying Github source code is not sufficient, since you don't know the release contains that source code (when downloading fro the store). You'd have to verify signatures Also, plenty of these extensions have been acquired by data firms or other sketchy places to then add your browser to botnets. If these are absolutely necessary for you, I highly recommend downloading the source and dumping it into Chrome/Edge via developer mode. At least then you know they can't update it in the background and you know what you're running.
- SoKamil 3y ago.crx is just a .zip underneath. You can unzip it and inspect the code.
- throwaway290 3y ago
- bromuk 3y agoooh, love it. Would be great to have some installation information within the repo for people who aren't savvy at enabling dev mode in chrome extensions
- swyx 3y agoor just link to something off google for it, we shouldnt have to write that for every oss chrome extension
- mschuster91 3y agoThing is, you can't, Google makes it very difficult to run extensions from anywhere but Chrome Store for a reason - if they didn't, scammers would jump on it.
- mdaniel 3y agoDepending on your intentions, the repo would benefit from a license instead of just using github for code hosting
- npace12 3y agoThanks for pointing it out, forgot to add it.
- swyx 3y agogithub could advance OSS a lot by making license reminders much more prominent. so much code intended-to-be-open-source cant be treated that way because no license file. if anyone from github is here please prod someone in your UI department to make a banner or something!
- deleted 3y ago[deleted]
- p1mrx 3y agoGiven that this extension is not very easy to install, I suggest adding a screenshot showing some actual captured network events. The current screenshot hides the most interesting feature.
- deleted 3y ago[deleted]
- jimmychoozyx 3y agoOpen google chrome > click options (3 dots) in upper right corner > Extensions > Manage Extensions > Click to toggle Developer Mode in upper right corner > upper left corner button "Load Packged" > Load the directory of the un-zipped .zip file Next, back in the normal browser-- Click the puzzle piece icon where your extensions icons are to the right side of the URL address bar. Click the little thumbtack next to Little Rat extension. Now it's installed and shows in the list of extension icons
- emmanueloga_ 3y agoNice! Feels like something that should be a chrome:// URL.
- UberFly 3y agoThat was my first thought. Why isn't this native to Chromium seeing that extensions are such a security/privacy risk.
- benrapscallion 3y agoBecause Chrome is made by a company whose primary source of revenue is the sale of its users’ data. Cui bono. Or, “It is difficult to get a man to understand something, when his salary depends on his not understanding it.”
- midoridensha 3y agoSure, but someone could fork Chromium and add it in.
- altairprime 3y agoI wish this was a feature of Firefox (or Chrome, as if Google would ever), rather than a third-party extension, so that it had enough adoption to compel other browsers to care too. I'd like very much to authorize certain extensions to only make GET requests to specific static URLs without any ability to vary the headers, so that they can get data updates without there being any risk of leaking data. And for others, they don't need network access at all to do their job locally in my browser instance. But that would be circumventable (since anything that can modify page source can add data transmission), so I imagine they aren't doing it because of that. Too bad — better to try than just give up and cede it to a Chrome extension.
- hsbauauvhabzb 3y agoA get request can leak data via the request path or querystring parameters, if that was restricted you could setup communication which time or frequency imply activity with a morse code like protocol (and with enough requests, easily transfer megabytes of data).
- altairprime 3y agoYou can just do whatever the modern equivalent of document.trackingPixel.src = 'leak all your data here in a single request', since extensions can modify content blocking. Firefox should ask for, accept, and audit a statement of whether your extension needs to make dynamic network calls or not, and why it needs to do so. Yes, you could lie — but then you'd get caught lying, in violation of, kicked off the store, etc. Today, you can just add tracking, and no one can take any useful action as a result.
- hsbauauvhabzb 3y ago100% agree. I think extensions are an odd place to start, but this is the exact reason I avoid browser extensions unless I’ve explicitly audited them (and still don’t like they auto update without permission).
- 3y ago
- horsawlarway 3y agoNifty - but please do this more carefully: https://github.com/dnakov/little-rat/blob/main/popup.js#L36 https://github.com/dnakov/little-rat/blob/main/popup.js#L36 I do not want to have to worry about whether another extension can inject xss into yours with a crafted request/id/name.
- npace12 3y agothat is a very good point but: * the content security policy does not allow unsafe-inline * extension ids are autogenerated by chrome
- btown 3y agoWhile unsafe-inline prevents execution of scripts, it doesn't prevent another extension from including HTML in one of the URLs it is requesting, and adding DOM elements that might entirely change the display of the extension. Likely not a huge problem here (there are much easier ways to bypass/cheat this extension e.g. by inserting tracking code into the DOM of a visited page so it's executed by that page) but it's definitely not good practice to interpolate HTML with untrusted strings.
- deleted 3y ago[deleted]
- cryptoegorophy 3y agoIf you can - do not install any extensions. I’ve had a couple like an ad blocker and something else leak my browser history to similarweb and neither extension or similarweb showed that they sell/collect my data.
- devilsAdv0cate 3y ago[dead]
- pkd 3y agoWhich ad blocker was it?
- _V_ 3y agoThe only viable adblocker is uBlock Origin. There are several clones that are trying to piggyback on that name though. You have to go for the original one - the one from Raymond Hill (or gorhill)!
- deleted 3y ago[deleted]
- _V_ 3y agoFYI: That CRX in Releases did not work for me - it did install correctly, it showed up in the toolbar but opened an empty popup (no extensions were listed)... The upnacked zip worked just fine though! Nice extension, thanks! (Vivaldi 6.2.3096.3 on Linux)
- _V_ 3y agoAlso it seems that the "mute" button is somewhat broken or something - I have ~10 extensions and when I click "mute" on some extension, it will toggle mute on the second to the last. Repeated clicking results in loop of 1) muting second to the last extension 2) muting the extension I'm actually clicking 3) unmuting second to the last and 4) unmuting the one I'm clicking :-D It is quite hard to describe, I may create a video and upload it somewhere later.
- npace12 3y agoThanks for the feedback, I'll check it out, I haven't tried it in Vivaldi yet.
- _V_ 3y agoHope it helps! I was clicking around for a bit and noticed one more thing: it does not display "Anti Anti Debug" extension - but that extension suddenly appears when I toggle any mute button. Maybe that extension is doing something funny? It is too late for me to try now but I will keep digging around tomorrow.
- npace12 3y agofixed the mute button btw. i noticed the other thing you mentioned as well
- scrum-treats 3y agoDownloaded the extension and tested that it's working. QQ: What does it mean when there is a "hit" (e.g., 1 appears), but when I click the extension to investigate all extensions show 0, and the original displayed number disappears? Also, if I delete an extension, it still appears in the list of extensions in Little Rat. Any easy way to fix this?
- npace12 3y agoYeah, it's only getting the list of extensions once on load, I'll push a change in tomorrow to have it refresh. The number shows the number of requests the extension has made. When you click on the name (if > 0), it will show the unique URLs of those requests
- scrum-treats 3y agoWhat does it mean when there is a number shown (indicative of a network call), however when you check little rat extension no extension in the list shows > 0?
- npace12 3y agothis was probably due to an earlier bug where not all extensions were showing on the first load of the popup page, it should be fixed now
- Groxx 3y agoNeat. I'm surprised this is possible tbh. Not being familiar with exactly what data these APIs (or similar?) provide: could extensions' abilities to access other extensions' requests imply any security concerns for e.g. password manager extensions? Or auth-token-using extensions?
- quickthrower2 3y agoThe lack of a network call doesn't prove the extension is safe. It might cache some data you want to keep private, and send it periodically.
- devilsAdv0cate 3y ago[dead]
- deleted 3y ago[deleted]