19 ms·
Browser extensions spy on you, even if its developers don't
- pierat 3y agoIf you use the browser made by an adtech company, what are you expecting? Similar, but for convicted monopolist. And you have no choice if you're using Apple. The only 'not terrible' choice is Firefox. But again, Mozilla Org has made constantly terrible choices that smell like adtech, kind of bad. Degoogled chrome can be better, as can de-mozilla'd Firefox (Ice weasel, etc).
- JeremyBarbosa 3y agoThese type of malicious offers for extensions are actually quite common. See this[0] and the discussion[1]. I try to stick with only the most popular of extensions in the hope that any malicious changes would be widespread news, but it is still a gamble. [0] https://github.com/extesy/hoverzoom/discussions/670 https://github.com/extesy/hoverzoom/discussions/670 [1] https://news.ycombinator.com/item?id=37066680 https://news.ycombinator.com/item?id=37066680
- FredPret 3y agoI recently installed Chrome and, all of a sudden, got really spooked that the AdBlock extension can see and edit everything I can see. Obvious as it is, for some reason this never occurred to me before! I'm now routing my traffic through a PiHole via a VPN to cut down the worst ads and will probably never install another extension.
- xnx 3y agoThis is what Manifest v3 is trying to protect against.
- josephcsible 3y agoThat's what Google claims Manifest v3 is trying to protect against, but it's actually trying to protect against ad blockers being effective.
- NoZebra120vClip 3y agoTell me, is it a sound security architecture that allows extensions like that to read and write to every web page I will ever see? Or perhaps that is a desperate hack to get'er done and there may be a safer way to implement that kind of thing? Sure, Google wants to architect things so that ad blockers as we know them now aren't really feasible. But I think that we can conceded that Google has a good point in saying these world-read-write-anything extensions are not good for us.
- plorkyeran 3y agoManifest v3 does not remove the ability for an extension to spy on all of your network traffic; only the part where it can block the network requests it's observing.
- autoexec 3y agoBesides the fact that Google doesn't stop extensions from seeing everything, there's nothing wrong with allowing extensions to do that. You should have the ability to selectively block/allow/modify content however you want before it's displayed in your browser. The biggest issues with extensions are things like silent updates (perhaps after the developer sold their extension to a bad actor) and extensions that depend on online resources. An extension that you've verified does what it claims to and nothing else, can read/write everything, doesn't update automatically, and never sends data to random servers isn't a problem at all.
- NoZebra120vClip 3y ago> You should have the ability to selectively block/allow/modify content however you want before it's displayed in your browser. Conceivably, this could mostly be accomplished without the extension being able to see all content. Such as manipulation by regexp.
- autoexec 3y agoI can't have an extension remove every line that contains the string "google" if it can't see every line. It'd still have to be able to access all the content to be able to parse through it for a match.
- kccqzy 3y agoAnd also Apple's 2015-era content blocker extensions.
- jeffbee 3y agoThis is why I am convinced that the entire online privacy discourse is a psy-op by global intelligence agencies.
- GeekyBear 3y agoOf course, Google doesn't want to do what Mozilla and Apple do and pay human beings to vet extension code looking for malware. They'll just claim that making ad blockers less effective is the only possible action they can take.
- xnx 3y agoIf an extension can load and interpret new code on the fly, that code cannot be vetted by human beings.
- franga2000 3y agoJust don't allow extensions that do that. An automated search for eval(), remote imports and script tags would probably catch most of these and if someone manages to hide it from the auditors, since source code needs to be available, a security researcher would find and report it eventually.
- GeekyBear 3y agoThis is one of the major differences between Apple's App Store rules and Google's Play Store rules. Apple has traditionally not allowed third party apps to download and execute code. Apple doesn't trust you to write your own JavaScript engine, for instance. You have to use Apple's. On the Play Store side, the ability to download executable code has proven to be an issue, as you mention. > Known as Joker, this family of malicious apps has been attacking Android users since late 2016 and more recently has become one of the most common Android threats. One of the keys to Joker’s success is its roundabout way of attack. The apps are knockoffs of legitimate apps and, when downloaded from Play or a different market, contain no malicious code other than a “dropper.” After a delay of hours or even days, the dropper, which is heavily obfuscated and contains just a few lines of code, downloads a malicious component and drops it into the app. https://arstechnica.com/information-technology/2020/09/joker-the-malware-that-signs-you-up-for-pricey-services-floods-android-markets/ https://arstechnica.com/information-technology/2020/09/joker...
- tredre3 3y agoMozilla claims that they review all the code, but in practice they don't. They have an automated tool that looks for certain things. If nothing is found, this is the end of the code review. If things are flagged, then a human will look at the code a little. If you have an established extension and push an update, odds are there will be no human review of the code changes. That is how most malicious extensions happen. Sure, Mozilla historically had less malicious extensions than Chrome. But that's for the same reason that Linux has less viruses than Windows: hackers will target the 90% of users and not waste time on the rest. I say all this as a staunch Firefox user and maintainer of a handful of extensions.
- syntaxing 3y agoUblock origin is the way to go for Adblock extensions. Also, NextDNS is way more flexible than pihole since you don’t need to host anything. AdGuard DNS provides the same service. Both are priced at $20/year and its money well spent IMO. NextDNS provides 300K queries per montb for free. With cache, that should last one person for one month.
- hedora 3y agoOf course, NextDNS and AdGuard are indistinguishable from a watering hole attack. (I've never heard of them; this is a fundamental problem with using centralized "privacy preserving" services.) https://en.wikipedia.org/wiki/Watering_hole_attack https://en.wikipedia.org/wiki/Watering_hole_attack I think ublock origin is a bit better, in that it is open source. Does it support reproducible builds though?
- akyuu 3y agoNextDNS and AdGuard DNS are just DNS providers that return filtered results for ad-related DNS queries. Their filter lists are public: https://github.com/orgs/nextdns/repositories?type=all https://github.com/orgs/nextdns/repositories?type=all https://github.com/AdguardTeam/AdGuardSDNSFilter https://github.com/AdguardTeam/AdGuardSDNSFilter If you don't trust their DNS servers for whatever reason, you can simply add these entries to your hosts file to replicate their functionality locally.
- ameshkov 3y agoSorry for jumping in but since AG is mentioned. If you want to have all the data under you control, there's this: https://github.com/AdguardTeam/AdGuardHome https://github.com/AdguardTeam/AdGuardHome Regarding open source, AdGuard DNS actually is: https://github.com/AdguardTeam/AdGuardDNS https://github.com/AdguardTeam/AdGuardDNS In the case of AdGuard DNS being open source does not change the fact that it is a centralized service and using such a service is a matter of trust.
- syntaxing 3y agoAdGuard home or pihole does not prevent “watering hole attacks” (honestly feels like paranoia more than safety but whatever). At the end of the day, you need a DNS for non filtered sites which AdGuard home and pihole uses cloudflare by default.
- andai 3y agoEven worse, even if you know an extension is OK (you can audit the code: iirc the rules say the source has to be readable), it can auto-update after being acquired by a malicious actor (e.g. The Great Suspender). For TGS I use the last known good version, as an "unpacked" extension. I think this approach of taking ownership of the code (i.e. running the extension "manually") is the best option, aside from two critical factors: skill and effort. (Not very much of either is needed, if you know basic JavaScript, but it's a significant "mental hurdle".)
- akyuu 3y agoYou can also use a declarative adblocker like uBlock Origin Lite [1], which only provides the browser with a list of elements to filter, but doesn't have any permissions to read content or perform requests. Or simply use your hosts file to apply OS-wide filtering with no browser add-ons needed [2]. Be aware that if you use these "passive" blocking methods, there are some sites like YouTube where you will see ads, because in these cases it's necessary to actually manipulate page content to hide them. What you can do is use a traditional adblocker but enable it only for these few sites where the declarative approach is not enough, take a look at [3] for more details. [1] https://github.com/uBlockOrigin/uBOL-home https://github.com/uBlockOrigin/uBOL-home [2] https://github.com/StevenBlack/hosts https://github.com/StevenBlack/hosts [3] https://seirdy.one/posts/2022/06/04/layered-content-blocking/ https://seirdy.one/posts/2022/06/04/layered-content-blocking...
- npace12 3y agoIn chrome, you can block network traffic coming from extensions. I built an open-source extension you can check out that does that [1] 1: https://chrome.google.com/webstore/detail/little-rat/oiopkpalpilladnibecobcecijffaflf https://chrome.google.com/webstore/detail/little-rat/oiopkpa...
- hedora 3y agoIsn't the more common problem that the extension contains malware from Google/FB? (This is definitely the case for phone apps.) How do you deal with side channels when the page is running javascript that's being served by the attacker? (Little Rat sounds like a great tool; I've been meaning to check it out.)
- npace12 3y agofor that, you can use ublock. Little Rat can block any traffic originating from a chrome extension. That includes content scripts injected by extensions into webpages, but not sites that you loaded.
- hedora 3y agoI see. That’s pretty good. So, now the attack surface is reduced to the extension author exfiltrating data via burner domains that aren’t blocked by ublock, but that are explicitly added to legitimate web sites.
- thrdbndndn 3y agoNice extension! I installed the full version, but I have no idea what the speaker icon do. Would you mind to explain a little bit more?
- NikkiA 3y agoI think it just mutes reporting on that extension. I'm a little puzzled why we only get the speaker icon, yet the screenshots all show the blocking options.
- lapcat 3y ago> Browser extensions must be open-source. If you can't find the extension's sources, you can be sure it's malware. That's bullshit. My extensions are not malware. I sell upfront paid extensions to end users. As always, if you're not the customer, you're the product. That's the problem with all of these free extensions: they have no clear business model. I don't recall ever receiving an offer to acquire my extensions. I'm not sure why: perhaps because they're Safari, perhaps because they're upfront paid, perhaps because the user base is smaller than free extensions, or some combination of those factors. In any case, these scammers are looking for volume, as many users as possible, because the amount of money they can make per user is small, especially compared to how much I can make per user from a direct purchase.
- masijo 3y agoIf you don't mind me asking, how much revenue do you get per month from all your paid extensions?
- lapcat 3y agoI won't give exact numbers, but I make 6 figures per year, enough to support myself as a sole proprietor.
- kilroy123 3y agoDamn, I need to make an extension. Any advice on any good material for how to write a good extension?
- smallerfish 3y agohttps://www.buildingbrowserextensions.com/ https://www.buildingbrowserextensions.com/
- lapcat 3y ago> Damn, I need to make an extension. Well, I wouldn't recommend quitting your day job, if you have one. The indie lifestyle can be very difficult. > Any advice on any good material for how to write a good extension? reply I mostly just read the docs from the browser vendors.
- bandergirl 3y agoThe title is inflammatory. By allowing random JS or by selling the extension, developers do spy on you. It’s like inviting a tiger into your office and then suggesting that the ensuing damage isn’t your fault. Browser extensions won’t spy on you, if you use trusted extensions by trusted members of the community.
- blurker 3y agoYeah I came away feeling like this was clickbait. Based on the title I expected to read something about the app stores quietly injecting telemetry in your extension or something like that. Something outside of the developer's control or being done quietly by default as part of the standard packaging and delivery pipeline. What the author described was very much not that. What they described was developers making a conscious decision to add untrusted code to their extension without properly verifying it or following security best practices. A more accurate title would be something like "It's hard to trust browser extensions, developers are bombarded with offers of easy money and may negligently add malware/adware"
- deleted 3y ago[deleted]
- halfjoking 3y agoDevelopers who get paid for this know what they’re doing. Saying they don’t know is like saying a courier who delivers packages from Mexico never knew they were delivering narcotics. That defense doesn’t really hold up in court. Extension devs who do it should be banned from the store.
- jqpabc123 3y agoDevelopers who get paid for this know what they’re doing. Are you sure? Lots of developers are highly trained but poorly educated. It took at least a decade for a lot of them to catch on to the scam called "crypto" --- and some still haven't.
- stinos 3y agoNot sure if you're being sarcastic, but if the standard offering goes like (quote) "I want to introduce an exclusive... I'm thrilled to inform you that..." that should ring some bells for even my parents these days, let alone developers?
- thrdbndndn 3y agoThe article only talked about how to protect the author to not fall to such "scams", and therefore protect your users. But more often than not, the author of the extension was fully aware of all the consequence came with the deal, the money was just too good to say no.
- horsawlarway 3y agoYeah... the article is just lying to you. The developers are accepting cash offers to inject malware into their extension. They know damn well what they're doing, and the good ones... don't. The developers accepting these offers aren't some maligned, innocent party - they are the people spying on you...
- extraduder_ire 3y agoI don't think he got paid directly to give it up, but I doubt gorhill planned on anything malicious happening when he gave up his extension. That's the only famous example I can think of though.
- ajayyy 3y agoMozilla reviewers do very detailed reviews. Unlike Chrome, they sometimes do manual reviews, looking for potential XSS or similar problems, and will let you know the exact line causing it. The Chrome web store is almost unmoderated though.
- chatmasta 3y agoDo they review every update?
- elashri 3y agoYea, and they do that for recommended extensions on the Firefox store only. It does not apply to all extensions
- krono 3y agoThere's plenty of proof to the contrary for the majority of extensions, including their recommended ones. See this article (not by myself) and comment thread from two weeks ago for further details: https://www.coloursofosint.com/posts/Investigating-Firefox/ https://www.coloursofosint.com/posts/Investigating-Firefox/ https://news.ycombinator.com/item?id=37125402 https://news.ycombinator.com/item?id=37125402
- wintermutestwin 3y agoDon't browser extensions essentially represent the failure of the browser to provide features that users want/need? I find Firefox unusable out of the box due to their failure to implement vertical tabs (in fact, it seems that Mozilla actively hates vertical tabs because they make it so hard to turn off horizontal tabs) and so I am stuck with using Sidebery, which, like most of the very useful extensions, requires "Access your data for all websites." The best Mozilla can say about the security of their browser when using extensions (even ones that they recommend) is: "While there is an element of risk to installing any third-party software, there are a few simple best practices you can follow to reduce it. Is the extension made by a reputable developer? Are the user ratings high?" From: https://blog.mozilla.org/addons/2018/02/01/understanding-extension-permission-requests/ https://blog.mozilla.org/addons/2018/02/01/understanding-ext... I don't want to rely on reputation and user ratings as these are ephemeral and easily faked. I want a browser to include necessary features out of the box and I want their code to be independently audited. If this chaotic mess is simply because of the need to monetize I would gladly pay for a trustworthy, feature rich browser.
- deleted 3y ago[deleted]
- Analemma_ 3y agoI mean, this seems like a "damned if you do, damned if you don't" complaint for the browser makers. Hacker News is constantly bitching that browsers are too slow, too complicated, use too much memory, the attack surface is too big, etc. Imagine how much worse that would be if they also had to support every possible use case instead of shunting a lot of that off into extensions.
- wintermutestwin 3y agoI don't know how to balance that conflict, but I wonder if it would be possible to have a web configurator that lets you pick the features you want and then compiles the executable.
- pulvinar 3y ago
- horsawlarway 3y agoYeah... so I absolutely agree that browser extensions are a fairly large security risk, and that many of them monetize through unethical means. That said - The title as written is just complete bullshit. If the developers are taking monetization offers and injecting code in response - the developers are fucking spying on you. There's not some malicious way to monetize an upstanding developer's extension. Really - the title is bad enough I'd consider pulling this... It's just lying to get clicks.
- deleted 3y ago[deleted]
- vitonsky 3y agoI see the some people did not get point and thought it's a clickbate, so i've update post to explain the developer can be a bad engineer who failed to detect a scam and this is the potential problem of any extension. You may think you can detect any scam, but scam may be targeted and complex
- horsawlarway 3y agoIt's not that I didn't get the point, it's that the point is not interesting or worthy of the title. Anyone developing software who takes cash money to inject code they have not reviewed (or worse is remotely hosted and subject to change - although at least this is getting removed with manifest v3...) is actively participating in screwing over their users. Shoving your fingers in your ears and going "nah nah nah, I can't see it so I don't know" is bullshit. You took cash... to add code. You are actively complicit.
- NoZebra120vClip 3y agoThe first ad blocking software I ever used was literally a proxy. It would start a server on the local machine and I'd point my browser's proxy settings at it. Then it would filter URLs from a blacklist. I think the company was called AdBusters back then. This may indeed be the same: https://en.wikipedia.org/wiki/Adbusters https://en.wikipedia.org/wiki/Adbusters
- SubiculumCode 3y agoIn the early days I was excited by extensions, but through the years I've come to really accept that the most important security risk on our computers is the browser, and that it is too important to risk compromise to only the most well-known, vetted extensions: e.g. ublock origin, noscript. It seems there should be a way to allow a lot of customizability/power to these tools without actually letting the extension send data home or even see the actual data
- espe 3y agothat should also apply to vscode extensions and most other plugin systems. and this seems to get worse? one area where apple's strategy of copying the functionality of smaller extensions/apps makes sense security-wise..
- bezier-curve 3y agoI maintain an open source extension with just a few thousand users and have been receiving these offers every month for years. These people will eventually find someone desperate enough for money to do it, which is unnerving and a good reason to use something like pihole, as ad blockers can't inspect traffic from other extensions.
- chatmasta 3y agoI use Chrome for any sensitive browsing, and I only have one extension installed there: uBlock Origin. For development, I use Chrome Canary where I have dozens of extensions installed, since I don't enter any sensitive credentials into that browser. For leisure, I use Firefox where I have uBlock Origin and a few paywall circumvention extensions installed - not the safest, but I only log into pseudononymous accounts in that browser. An extension I will never install is one that interfaces with my password manager. I've seen way too many exploits that begin with a bug in such an extension to feel comfortable with it. I prefer the security of my clipboard, where I can copy/paste from my password manager - if my clipboard is compromised then at least only one password will be stolen, and a separate exploit would be required to even know into which website I entered the password. This does leave me vulnerable to phishing, since I don't get the automated URL->password retrieval, but I've never liked that feature of password manager extensions anyway.
- autoexec 3y ago> I use Chrome for any sensitive browsing You have a lot more faith that Google isn't collecting data on every last website you visit than I do.
- chatmasta 3y agoNah, I've just accepted it as part of life. If my bank is already using Google Analytics, what difference does it make if Chrome juices the data a bit more? And as far as tracking what content I view, I only use that browser for work, so I actually want it to learn about me (e.g. I have Google search history enabled on that account). Any browsing for leisure, medical, political, etc. purposes, I do in Firefox where I only log into pseudononymous accounts not associated with my main email or name. But I do disable as much Chrome telemetry as possible, including features like auto-suggest and pre-loading, and I don't "log in" to the browser with my Google account (despite the constantly changing dark patterns trying to trick me into doing that). It's not much but it's good enough.
- gsuuon 3y agoThe other problem is that it's not possible to request (as an extension author) or give (as a user) fine-grained permissions to extensions. You're only able to request very coarse permissions, often it's either you're giving up an insane amount of control over to extensions or the extension isn't allowed to do anything useful.
- beebeepka 3y agoThe weird things is that nobody cares about browser extensions on work machines. Companies go through all the trouble in the name of security, especially on windows, but almost nobody controls the sort of crap people, including developers, install on their browsers. Some extensions request access to everything, rendering the entire security dance moot. In fact, some of the worst offenders are people who absolutely should know better. I only know a handful of people who have agreed with me on this. Unbelievable.
- _23sd 3y agoBrowsers have the tools for companies to manage this. My workplace actually does restrict extensions to an annoyingly small allowlist. But I think it’s not on the radar for as many companies because the extension controls are moot if you aren’t restricting which browsers are allowed or if you don’t restrict access to corporate resources to managed devices.
- beebeepka 3y agoYour place sounds reasonable. I presume it's mostly banks and other such enterprises handling sensitive information. My wife has has to use FF with extensions disabled. Their IT made the right choices on this one
- gabrielsroka 3y ago> Browser extensions must be open-source. You download the source when you install the extension. It's a zip file. You can unzip it and examine it yourself. Even if the developer provides a GitHub repo, how do you know it's the same as the version in the extension store? Maybe there's a server component too, but again how would you know that the source provided is what's actually running on the server?
- kwar13 3y agoExactly. You can also look at the source code without installing it. I decided to check this out a couple weeks ago: https://kaveh.page/snippets/chrome-extensions-source-code https://kaveh.page/snippets/chrome-extensions-source-code
- kwar13 3y agoYou can look at the code of any extension before installing it. I started looking into this a couple weeks ago: https://kaveh.page/snippets/chrome-extensions-source-code https://kaveh.page/snippets/chrome-extensions-source-code
- medv 3y agoGoogle Chrome Store actually pretty good at detecting malware and spyware. Also forbids code downloading from external sources. So downloading from the store should be more secure.