9 ms·
Button Stealer
- kickofline 2y agogithub: https://github.com/anatolyzenkov/button-stealer https://github.com/anatolyzenkov/button-stealer
- neontomo 2y agonow add a leaderboard for most collected... btw i had a look at the code and it seems benign. no clue if there's a way to verify the same code is in the chrome extension store.
- stuffoverflow 2y agoOn windows the location of chrome's extensions is "AppData\Local\Google\Chrome\User Data\Default\Extensions". You can read the source code of all of your installed extensions there. This requires you to install the extension first. It is also possible to download the crx file of any extension from the chrome web store and just unzip it to inspect the source, though i'm not sure how to do it with the official chrome. Ungoogled chromium downloads the crx file if you press "add to chrome" and then cancel.
- whodev 2y agoI diff'd the chrome extension against the github repo and they are basically the same, outside of a few lines in the README.md missing and the manifest.json containing an update URL key to "https://clients2.google.com/service/update2/crx https://clients2.google.com/service/update2/crx".
- sweca 2y agoThis sounds like a great way to find inspiration for UI UX designs
- elitepleb 2y agoreminds me of https://adnauseam.io/ https://adnauseam.io/ 's clicked ad view https://adnauseam.io/img/adnauseam_vault.png https://adnauseam.io/img/adnauseam_vault.png
- erremerre 2y agoI love watching mine, and love watching the cost to advertisers. Modern problems require modern solutions!
- jer0me 2y ago“It's fun, useless, and free!”
- koito17 2y agoIs there a particular reason this uses Chrome-specific APIs instead of the standard WebExtensions API? I have considered experimenting with web extensions, but wondering what the practical limitations of the standard API are compared to the browser-specific APIs.
- purple-leafy 2y agochrome doesn’t support web extension API
- creesch 2y agoTechnically correct, but it is a bit more complex. The original web extension API is based on the chrome extension API. So most (there are some annoying exceptions at times) of the chrome extension API calls also work with very little adjustment on firefox. It becomes even easier when you use mozilla's polyfill library https://github.com/mozilla/webextension-polyfill https://github.com/mozilla/webextension-polyfill Then you can just target the promise based webextension syntax and as long as you still stick to the calls also available in chrome your extension works with very little effort in both browsers. Safari is a different story which basically amounts to Apple being Apple and sort of supporting webextensions but in such a roundabout way that it is barely worth it for the majority of extension devs.
- sn0wleppard 2y agoThere's some difference but a lot of overlap in the basic functionality - Firefox is compatible with all the chrome.* API calls I use in my own extension
- impure 2y agoICH WILL MEINE 5€!
- Hamuko 2y agoI'd be worried about installing these sorts of extensions in case someone decides to offer the developer a lucrative amount of money to buy it and then uses it for less-than-fun purposes. Not sure if they'd need additional permissions for it, but at least the current content script is ran against "https://*/\ https://*/\*" already.
- skybrian 2y agoThis is the app version of a phishing email. Give us access to everything on every website you visit, just for some eye candy.
- mavamaarten 2y agoBonzi buddy vibes
- purple-leafy 2y agoIssue with this “benign” extension is that it will be using “host_permissions”: “<all_urls>” In its manifest means it can basically do anything on any webpage you visit, scrape data etc. As an extension developer, no thanks. “Fun” pointless extensions like this that have no real utility, but funnily enough require broad permissions, are dangerous
- Refusing23 2y agojust like 'Grammarly' which is basically just a keylogger
- MrSS 2y agoGrammarly has to be able to connect back to their online service while the button addon could be implemented in a way that it can read every website but not send antyhing anywere (in theory, the addon could of course simulate a form and send data out through that or somehow). But yeah i tested grammarly for 5 minutes and found it crazy. there has to be a better way getting both worlds :|
- bargainbin 2y agoLocal software of course! But good luck getting funding for a product that doesn’t phone home every 5 seconds and present an opportunity to plague the user with ads “that they want to see”
- vstollen 2y agoI haven’t used it myself, but the LanguageTool browser extension might allow users to use a self-hosted or locally running instance.
- dspillett 2y agoIn DayJob we've had to block (actually block, because people didn't listen to being asked not to use it and similar tools) Grammarly because it sending text that could potentially include client data off to their servers for checking would have given us a nasty fail should a client request or conduct an audit. As an alternative there is LanguageTool which you can install locally. We have it running on a small VM that people can configure their installs to talk to, and block the public service end-point (as sending to that would be a big no-no for us for the same reason as Grammarly). It doesn't have all the features of Grammarly so isn't a complete drop-in replacement, but the self-hosted version works as well as the free features of Grammarly.
- peanut_worm 2y agocute idea but im not installing this malware lol
- ape4 2y agoIn addition to all the security concerns mentioned, you don't really need it. You can google or ask a chatBot to make you custom button.
- graypegg 2y agoI love the idea but the <all_urls> access is a bit scary. This could be recreated in a bookmarklet ideally, though it would require saving the button html snippets into a file that you'd have to make downloadable with some Blob weirdness.
- deleted 2y ago[deleted]
- odo1242 2y agoIs there a Firefox version?
- rgbrgb 2y agocool! i want this for safari please. is that an easy port?
- kmoser 2y agoDoes it store the HTML/CSS for creating the buttons so you can easily repurpose them (which would be quite useful), or are they stored as images (which would be fun but less useful)? If the latter, how difficult are they to extract from the page that shows them all?
- josefritzishere 2y agoWhy would you intall this? Who wants a collection of buttons?
- deleted 2y ago[deleted]
- pdjljl 2y ago[dead]
- coalio 2y agoI worked on something similar before that serves the same purpose, except that it steals css/scss and it's not an extension but rather a CLI tool, you can find it in github as coalio/rfscss
- petermcghee86 2y ago[dead]