65 ms·
uBlock Origin GPL code being stolen by team behind Honey browser extension
- slowmovintarget 2y agoIf any software ever deserved being sued into non-existence it is the Honey browser extension, and any other scam software they turn out (Pie Adblock in this case). https://www.youtube.com/watch?v=vc4yL3YTwWk https://www.youtube.com/watch?v=vc4yL3YTwWk
- tzs 2y agoI've seen a few ads from them on YouTube promoting their ad blocker, specifically touting that it gets around YouTube's efforts to block ad blockers. I thought it was interesting that YouTube, in the midst of trying to crack down on ad blockers, allows ads promoting an ad blocker that is specifically claiming to evade that crackdown.
- Drakim 2y agoI wonder if there could be anti-trust aspects to cracking down on such ads.
- stackskipton 2y agoNah, just Occam's Razor. Pie Inc. payments went through and it's cheaper for YouTube to run whatever instead of paying to people to curate such ads.
- throwaway48476 2y agoYoutube ads are less moderated than youtube videos. They know where the money is.
- chasebank 2y agoThe founders sold 5 years ago to PayPal. Do they just get to laugh on their way to the bank? Probably.
- manquer 2y agoYour comment implicitly absolves PayPal of responsibility. One thief sold to another , it is like credit card lists or botnets are sold on the dark web . PayPal is hardly innocent here , they knew what they were getting into , this is the core business model of not just honey but all of the coupon sites.
- iou 2y agoThis is the one worth watching, it’s a total scam and PayPal is fine with it apparently.
- s5300 2y ago[dead]
- ndriscoll 2y agoFrom what I've gathered, honey basically replaced affiliate codes with their own and then gave the user part of the commission back? Is there something they did that users should be unhappy about?
- xen0 2y agoIt seems the voucher codes they 'find' are not the result of them searching the Web. They are simply codes provided by partnered businesses and may be beaten by codes you can get by searching yourself. If true, then this is them outright lying to the user. And you know, if they don't find a coupon code for you, one might still be at least a little annoyed that the original 'salesman' didn't get their affiliate commission; it instead being pinched by another.
- ndriscoll 2y agoI think in addition to the coupon thing, they had/have some cash back points? In any case, as someone who filters affiliate links, I can't understand why anyone would want to preserve them. Making them useless by having the user's browser automatically inject one seems like an awesome feature and a great social good, even without the user getting part of it. Affiliate programs are a direct cause of a lot of the spam on the web. It should bother you if 10-30% of your price went to whoever last got you to click on a link.
- slowmovintarget 2y agoYeah, they pass on 80 cents of the $35 commission they get from Nord VPN when they hijack someone else's affiliate link. And it's 80 cents in "points." So you have to spend more to even use those. It's a scam in partnership with the on-line shops. The consumer loses, the reviewer using affiliate links loses, and it turns out the extension goes further by occasionally making up discounts that don't exist (this will be in the next video it seems), so the seller gets screwed, too!
- 14 2y agoWell some people actually do believe in giving credit to the person who helped them make an informed purchase. I have gone into a store and had a worker spend like 20 minutes showing me things. I wasn't ready to buy but when I was and came back I had another worker try and help me but said to them the other worker spend a lot of time helping the other day I would like to buy it through them and was sorry.
- twostorytower 2y agoThis video is just rage bait and weaponizing creators and their fans by singling out Honey and not providing any additional context. Anybody in the affiliate industry knows how last click attribution works. This isn't new or specific to Honey. CapitalOne Shopping, Rakuten, RetailMeNot...they all work the same way. Merchants partner with these shopping extensions knowing how they work, nobody forces them to do so. The affiliate networks (CJ, Impact, etc) are the ones who determine what attribution method to use, shopping extensions just comply. The vast majority of shopping sessions don't have any prior attribution and merchants fund all of these commissions (nothing is taken from a creator or a user). Yeah, it does seem like the codes Honey has have gotten worse in recent years, probably just a consequence of PayPal acquiring them and not giving it any attention (and layoffs). But the example MegaLag points out of finding a better code on a coupon website DOES THE SAME THING AS HONEY (overides the attribution). So are there some problems with the affiliate industry? Probably. But calling Honey a "scam" seems completely unfair and lacks critical thinking. It's saved me thousands of dollars over the years.
- mrguyorama 2y agoStop spamming the same bullshit apologism over and over and over Nobody cares that other companies and extensions do the same thing, they're bad too.
- twostorytower 2y agoI'm not saying this isn't a problem, it's just not a Honey-specific problem. If he actually wanted to influence change, he should cover the affiliate networks responsible for dictating this behavior (CJ, Impact, Rakuten, Awin, etc). The extensions are forced to comply by their rules.
- josephg 2y ago> I'm not saying this isn't a problem, it's just not a Honey-specific problem. You didn’t just say that. You said a whole lot of other things. You lead with the fact that it’s well known within the industry. The implication of your comment is that the companies did nothing wrong, and people are idiots for not knowing this stuff before. If that’s not your stance, you should make your stance more clear. If you instead simply said “people should also be angry at all these other extensions and companies, they’re complicit and just as bad” then nobody would be calling you out for astroturfing.
- deleted 2y ago[deleted]
- kurthr 2y agoI really wish PieAdblock was in the article headline, since it's more relevant. "UBlockOrigin GPL code stolen by Pie Adblock Extension and Honey team" Of course Pie is scummy, it is brought to you by the people behind Honey. In addition to stealing GPL Source the new over-hyped Adblocker that probably also steals (silently rewrites in the background) affiliate links, just like the old "coupon finder". No surprises!
- graemep 2y agoThe developers of the misused code can sue for breach of copyright. The people in breach in this case have money and are worth going after if there are a reasonable number of copies of the code illegally distributed.
- zb3 2y agoIf something is "heavily promoted by influencers", it's garbage. Would it make a difference if this garbage was GPL licensed?
- zb3 2y agoOh it gets even better: > Pie Adblock: Block Ads, Get Paid Really? Do people not understand how the economy works or something? Education failed so bad :(
- sodality2 2y agoFrom their home page: > Browse ad-free with Pie Adblock and earn cash rewards for the ads you choose to see. Sounds like they replace the ads with their own, paying you (and surely taking their cut). Sounds a lot like Brave Rewards, similar thing...
- entropicdrifter 2y agoI was gonna say the same thing. Brave browser all over again
- LordShredda 2y agoI would never install anything advertised on youtube. Not claiming that I'm an elitist, but the audience on youtube would not have the ability to differentiate between a chocolate bar and a landmine.
- starttoaster 2y agoNot sure where to start here. You could have found Honey advertised basically anywhere on the internet, not just YouTube. YouTube users are common across most of the developed world at this point, so it's probable that there are millions of YouTube users that are more intelligent than you or me. And what you said implies you do differing levels of due diligence for the services you sign up for depending on the platform you heard about them from, which is ill advised; regardless of where one found out about Honey, you should have questions about how their business works. Someone who has been around the block a couple times would have deduced that a business that clips coupons for you is doing something to make money, and since it's not obvious what that thing is, it's almost certainly something shady.
- max_ 2y agoWhy can't people just run businesses decently without deception & scams? I'm sure they can be profitable. This deceptive behaviour actually makes the business loose customers in the long term.
- deleted 2y ago[deleted]
- cjbgkagh 2y agoThe bad pushes out the good until you’re only left with bad. A system that tolerates bad actors like this will in time only have bad actors. It’s tolerated because it makes a large amount of money for a small number of people.
- jszymborski 2y agoThis is exactly it. When things are horrible around us, there is a strong temptation to throw ones hands up in apathy and let the rot fester. "Eh, Honey is probably selling my data but I got $5 off my new mattress, so wtv". We need to resist that call to apathy, stop acquiescing, and start demanding better of others. That, incidentally, often starts at demanding better of ourselves.
- cjbgkagh 2y agoI disagree that it’s down to the individuals. While individuals can throw themselves into the gears of the machine it is understandable why they do not. I see things in terms of a sharecropping analogy, feudal lords (corrupted government) allow the scammers to harvest the crop (victims) for a share of the proceeds. We cannot fix people to the point they are un-scammable and there does not exist a democratic force strong enough to fix the government. Almost all ads I’ve ever seen are for obvious scams, especially on twitter. You’d think the richest guy in history (possibly?) could afford not to allow industrial exploitation of his users but apparently not. You have gambling sites and binary auction scams that have a turnover that includes a significant percentage of suicides. I wish we had a democracy that could prevent this but we do not. While many of us here may be smart enough to avoid falling victim to these scams we have family members that we care about who are not so this still indirectly costs us wealth.
- deleted 2y ago[deleted]
- aaron695 2y ago[dead]
- gonesilent 2y agopaypal paid 2 billion for honey did all the devs leave?
- gkoberger 2y agoLooks like they sold in 2020 for $4Bn, and both founders left two years later in March 2022. One founder started Pie, which basically seems like Honey with a slightly different angle. The other founder became a VC.
- rvnx 2y agoIt looks more like Brave (the original idea), an adblocker that actually replaces ads and pays you rewards.
- Suppafly 2y agoAs if Honey isn't already under enough fire with half the youtube world releasing videos about their shady practices.
- nicce 2y agoSecond half advertises its existence in a positive way as they pay for influencers.
- jzb 2y agoIs really being "under fire" if it's just accurate reporting?
- BadHumans 2y agoTitle is misleading. The original team behind Honey has created a new company that is doing this and not Honey itself which is owned by Paypal.
- tantalor 2y agoDo we know when Honey started stealing affiliate links? Was it after the acquisition?
- throawayonthe 2y ago[dead]
- mfer 2y agoThe author of UBlockOrigin should contact the PayPal legal department (in a legal manner). That might be a more direct path dealing with the Honey business.
- philipwhiuk 2y agoThis is by people who used to work on Honey - they're not part of PayPal.
- Sephr 2y agoTo be fair, Honey could easily bypass the blocklist redistribution legal issue by downloading filter lists at runtime from the official source. Then they aren't redistributing the resources. Update: It looks like they're also using code from uBO without attribution or authorization. That's most likely illegal.
- Raed667 2y agoread the thread, people also found that it also stole code from uBO
- mainframed 2y agoI would be careful handing out legal advice as a non-legal expert, especially when it is about "bypassing legal issues". You might be doing someone a big disservice. @readers: Obligatory notice: Don't base your business decision on random internet comments.
- loeg 2y agoThis is excessive. Any fool taking legal advice from pseudonymous internet comments is getting what they paid for.
- mainframed 2y agoOk. Got it. Next time, I'll leave probably false legal advice unchallenged.
- loeg 2y agoIt's fine and good to disagree with/challenge wrong comments. But you don't need to do this meta commentary cautioning the mere act of commenting. If Sephr is wrong, just say that!
- mainframed 2y agoOk. You are right. I think he is likely wrong, but I'm not a lawyer either. Just someone who researched this a lot for my own projects/company. If that was true, all user-side aggregations would be considered as separate projects. I think it might be possible to circumvent the GPL license, when the URL to the list would be user-configurable and the program also worked without the list.
- moonshadow565 2y agoI don't think you can copyright lists of publicly available information (iirc there was some case with phone numbers before). That being said, they also stole code...
- onli 2y agoRight, or: maybe. Depends on where you are (or maybe better: where they are), and whether data collections fall under copyright or some other protection that is translateable enough for the gpl to apply. But if they really also used code that point is moot.
- deleted 2y ago[deleted]
- RobotToaster 2y agoDepends on the country https://en.wikipedia.org/wiki/Database_right https://en.wikipedia.org/wiki/Database_right
- moonshadow565 2y agoThanks for the list! It seems that unfortunately copyright applies to databases in EU.
- maxloh 2y agoMoreover, it doesn't seem like static linking to me. A similar example would be using a GPLv3 licensed JavaScript library in a website. What it implies to other HTML/JS/CSS code is controversial [0]. The FSF actually believed that they should not be "infected" [1], and the legal implications may need to be tested in court. [0]: https://opensource.stackexchange.com/q/4360/15873 https://opensource.stackexchange.com/q/4360/15873 [1]: https://www.gnu.org/licenses/gpl-faq.en.html#WMS https://www.gnu.org/licenses/gpl-faq.en.html#WMS
- darthwalsh 2y agoThe FSF question is about templates, but the chrome extension in question also seems to have copied nontrivial JS. I don't think chrome extensions can be modified by the user; there's probably some integrity check. So to be GPL compliant they need to publish source files to rebuild the extension?
- alsetmusic 2y agoThis isn’t the first time they’ve been accused of shady practices. > MegaLag also says Honey will hijack affiliate revenue from influencers. According to MegaLag, if you click on an affiliate link from an influencer, Honey will then swap in its own tracking link when you interact with its deal pop-up at check-out. That’s regardless of whether Honey found you a coupon or not, and it results in Honey getting the credit for the sale, rather than the YouTuber or website whose link led you there. https://www.theverge.com/2024/12/23/24328268/honey-coupon-code-browser-extension-scam-influencers-affiliate-marketing https://www.theverge.com/2024/12/23/24328268/honey-coupon-co...
- twostorytower 2y ago[flagged]
- chinathrow 2y agoI watched the video and I am pretty sure that the rage is warranted at this time. There is plenty of context given: Honey and their browser extension is swapping out cookies and lying about it to the end user - it does not matter if "everyone else is doing it as well". It's bad and it needs to stop.
- twostorytower 2y agoThey don't just swap out everyone's cookies. They comply their the affiliate network's "stand down" policies. Which means they don't actively try to poach commissions in the same shopping session. These are terms everyone agrees to, including creators. If it's the next day, most merchants don't pay out for referrals older than 24 hours anyways. So like I said, there are some legitimate problems with the affiliate industry, but the rage should be directed at the affiliate networks that dictate the terms. They could easily switch to first click attribution which would solve this problem.
- chinathrow 2y agoDid we watch the same video? Where one commission was fully wiped out by Honey vs it would have been paid out if Honey was not installed?
- shwaj 2y agoI know it’s not necessarily the same people, but it feels contradictory for this community to say “copyright infringement isn’t theft” when we’re talking about movies, but use the opposite language when talking about GPL source code.
- traverseda 2y agoYou can live in the gift economy or the money economy. Taking stuff from the gift economy and selling it is gross.
- shwaj 2y agoI agree completely, and yet I would still prefer language to be used consistently.
- traverseda 2y agoI think the "information want to be free" crowd is very consistent. They want the information to be free. They don't want artificial scarcity. Sure they'll use IP as a means to an end, but that doesn't mean they believe IP is a good idea in general. It's just one of few tools that exist to solve it. In an ideal world all software would be forced to be FOSS, and we'd have to come up with ways of funding it that aren't based on artificial scarcity.
- deleted 2y ago[deleted]
- drdeca 2y agoIt seems like a bit of a strong restriction to have in the law that if I distribute an executable (which people may reverse engineer, modify, redistribute as they wish) that I am obligated to provide the source code upon request. Like, what if I want to release a rather difficult puzzle in the form of an obfuscated executable and provide a reward to the first person who solves it? If I’m required to release the source code upon request, then that kind of spoils the puzzle. (Sure, I can say that anyone who gets the source code this way is ineligible for the prize, but how could I tell?) This is of course a somewhat silly and niche edge case. Still though, it doesn’t seem natural/appropriate for a law would prevent such a thing. Whereas, agreeing to only distribute modifications I make to some software written by others if I’m willing to distribute the source code to my modifications, well, that would just be an agreement I would be making, and seems unobjectionable. Though, I wouldn’t really claim that all IP is illegitimate. I think many IP protections go way too far and last too long, but, I think some amount of copyright and patents is probably a good idea, though for a much shorter duration. So maybe I’m not really in the camp being described. I think the freedoms described in the GPL are good. I guess one alternative could be to say that all software written “for a useful purpose” (or something like that) has to have the source code made available, and that could handle the puzzle case I mentioned? It does seem important to avoid the case where one needs to use some software for something but is prevented from modifying it due to not having the source code. So… maybe if one is only required to provide the source code if someone could reasonably be described as “needing” the software for something? (E.g. if you “need it in order to get your printer working”, or the like.)
- mx20 2y agoIs he correct? That you can't have GPL files in your project without all code adhering to it? I thought it has to be linked static. So just calling a GPLed js library likely wouldn't be enough. I think the law is muddy here and not clear at all, even if the code is directly bundled.
- mzajc 2y agoI am not a lawyer so I can't say with certainty, but judging by the exchange between Richard Stallman and Bruno Haible, the author of CLISP, it may well be required: https://sourceforge.net/p/clisp/clisp/ci/default/tree/doc/Why-CLISP-is-under-GPL https://sourceforge.net/p/clisp/clisp/ci/default/tree/doc/Wh...
- doubletwoyou 2y agoI think you might be thinking of the LGPL, where it’s fine to use a piece of code if you dynamically link to it (and maybe something about providing relinkable object files, but I’m not too clear about that). The GPL, on the other hand, mandates that any code that interacts with GPL’d code must be GPL’d, unless it can be easily replaced or such and such (i.e. your non GPL code calls a GPL binary via fork & exec or the like). I’m not an expert in this sort of thing, so a more knowledgeable person may chime in.
- mx20 2y agoBut if you create a plugin that calls (via mv2 api?) a separate GPL-licensed JavaScript file to block all ads on the page, and then use your own closed-source code to add your own ads in step 2, is it really integrated or just two separate programs bundled together?
- lizknope 2y agohttps://en.wikipedia.org/wiki/GNU_General_Public_License#Communicating_and_bundling_with_non-GPL_programs https://en.wikipedia.org/wiki/GNU_General_Public_License#Com... The mere act of communicating with other programs does not, by itself, require all software to be GPL; nor does distributing GPL software with non-GPL software. However, minor conditions must be followed that ensure the rights of GPL software are not restricted. The following is a quote from the gnu.org GPL FAQ, which describes to what extent software is allowed to communicate with and be bundled with GPL programs:[74] What is the difference between an "aggregate" and other kinds of "modified versions"? An "aggregate" consists of a number of separate programs, distributed together on the same CD-ROM or other media. The GPL permits you to create and distribute an aggregate, even when the licenses of the other software are non-free or GPL-incompatible. The only condition is that you cannot release the aggregate under a license that prohibits users from exercising rights that each program's individual license would grant them. Where's the line between two separate programs, and one program with two parts? This is a legal question, which ultimately judges will decide. We believe that a proper criterion depends both on the mechanism of communication (exec, pipes, rpc, function calls within a shared address space, etc.) and the semantics of the communication (what kinds of information are interchanged). If the modules are included in the same executable file, they are definitely combined in one program. If modules are designed to run linked together in a shared address space, that almost surely means combining them into one program. By contrast, pipes, sockets, and command-line arguments are communication mechanisms normally used between two separate programs. So when they are used for communication, the modules normally are separate programs. But if the semantics of the communication are intimate enough, exchanging complex internal data structures, that too could be a basis to consider the two parts as combined into a larger program. The FSF thus draws the line between "library" and "other program" via 1) "complexity" and "intimacy" of information exchange and 2) mechanism (rather than semantics), but resigns that the question is not clear-cut and that in complex situations, case law will decide.
- octacat 2y agoStrange, an addon that was written to steal income by replacing affiliate links with their own, is found to also steal the code.
- mulmen 2y agoThe headline says the team stole code, not that they stole it for Honey.
- 65 2y agoHow does Pie Adblock make money? It's free so I'm suspecting they're doing more affiliate marketing stealing or something similar to Honey.
- encroach 2y agoFrom the webstore extension overview: > Get Paid to See Ads — Opt-in to see a limited number of partner ads and earn rewards.
- moqmar 2y agoAfter what happened with Honey, I guess this probably means: they replace ads on pages with their own, pocket most of the money, and extort the sites who would have earned money with the ads into partnering with them.
- matt3210 2y agoIt wouldn’t surprise me if most companies steal GPL code. When code is closed source, how can anyone know?
- yuvalr1 2y agoThere are some indirect ways. Suspecting users can try the software to see if it has the exact same functionality or bugs as the copied GPL library. This is of course not a definite proof, but some amount of rare enough coincidences can be considered as a very strong sign for copying. Legal measures can be taken on account of these evidences. And of course there is always the option of a whistleblower.
- NikkiA 2y agoUsually 'strings' on the binary shows up tell-tale signs. Granted that means the 'smart' infringers are likely to slip through the sieve, but at that point they'll have to essentially be re-writing the code anyway, and lose most of the benefit that they'd get stealing the GPL code (they'd have to hand-roll any bug or security fixes back into their stolen-but-obscured GPL code)
- dbtablesorrows 2y agoNot if they can use an obfuscator?
- lizknope 2y agohttps://en.wikipedia.org/wiki/GNU_General_Public_License#Legal_status https://en.wikipedia.org/wiki/GNU_General_Public_License#Leg... There are cases here where companies used GPL code without releasing their changes. How do licenses of a source code check if the people using their code is complying with the license it uses? https://www.reddit.com/r/embedded/comments/18gie6l/how_do_licenses_of_a_source_code_check_if_the/ https://www.reddit.com/r/embedded/comments/18gie6l/how_do_li... The fastest way is often to just run the "Strings" program on the software. Often it will dump out a bunch of strings that match those in the Open Source project: Error Messages, Logging messages, etc. Sometimes if they're really sloppy it'll spit out the name of the GPL program/library directly and a version number. I often add magic arrays to my code. So.. if I find them in a binary blob... Have there been any lawsuits involving breach of open source licences? https://opensource.stackexchange.com/questions/11452/have-there-been-any-lawsuits-involving-breach-of-open-source-licences https://opensource.stackexchange.com/questions/11452/have-th...
- marcodiego 2y ago[flagged]
- phoe-krk 2y ago> They're not stealing, they're disrespecting a license. Breaking into someone's car and riding off isn't stealing, just disrespecting the concept of ownership.
- deleted 2y ago[deleted]
- Jolter 2y agoThe difference is that theft is a criminal offense, where you’ll be prosecuted by the state. Violation of a software license is not a criminal offense but a breach of contract, opening you up to civil suits. So, it’s up to the rights holder to file suit and drag you to court for damages.
- phoe-krk 2y agoOne breaks the criminal law, another breaks the civil law. Both break the law.
- manquer 2y agoBoth break the civil law , you can absolutely sue the thief for damages for lost property. Typically this is not done because it is not worth the lawyer expenses as recovery chances are pretty slim unless it is a kleptomaniac billionaire maybe , instead you claim insurance to recover on your losses. Similarly copyright theft is also same as any other property theft, you can charge under criminal law as well , typically success rate is not high , but people have gone to prison over pirating movies or bootlegging stuff etc
- Jolter 2y agoSo what’s the case law for violations of the GPL? Did anyone get criminally convicted prosecuted for violating any software license at all, and was anyone convicted? I’m only aware of civil suits in this regard.
- SamInTheShell 2y agoI thought config files can’t be copyrighted. The post talks about what appears to just be a config file.
- shultays 2y agoIt is the filter list, which are the things that defines ads and loaded by adblocker to block them.
- blackeyeblitzar 2y agoYea but who is going to do anything about it? What is the enforcement method?
- efitz 2y agoWow these people really just go all in on the unethical practices.
- Havoc 2y agoI guess honey is just going all out now?
- jazz9k 2y agoIf piracy isn't 'stealing' neither is this, since the original code is still available.
- ozgrakkurt 2y agoYou are not making money off the product when doing piracy. In this case they stole the code to make money off it which is very different
- jazz9k 2y agoMoney has nothing to do with it. The justification for piracy has always been that the original work is still there, so it's not considered theft. Not only is the original GPLd code still there, the owner of that code didn't have the money in their pocket, so nothing was actually 'stolen'. It's why I support using GPLd code in proprietary applications. This team just got sloppy and copy/pasted. They should have hired me and I would have made it virtually untracable.
- aunty_helen 2y agoPie also removed its footer reference to being the team that made Honey and then deleted all of the team photos from the who are we page. They seem to understand cookies and affiliate links well but aren’t versed in the way back machine. The ethical standards of everyone involved with Honey/Pie are deplorable and they should be outcast from the software industry.
- aunty_helen 2y agohttp://web.archive.org/web/20241223012824/https://pie.org/about http://web.archive.org/web/20241223012824/https://pie.org/ab... For context, this all started about 2 weeks ago with one of the best pieces of investigative journalism I've seen on youtube: https://www.youtube.com/watch?v=vc4yL3YTwWk https://www.youtube.com/watch?v=vc4yL3YTwWk And it's spiraling from there into lawsuits etc. I'm kinda glad PayPal bought them as they can't just shut down and file bankruptcy. Hopefully some of these creators will get paid out for lost revenue.
- HeyTomesei 2y agoGreat find. I noticed the photos disappeared yesterday, but didn't catch that footer reference change. Sadly, Ryan Hudson knows how to play the game and Pie (with its charming .org domain) is on a roll --- already hit 1M downloads just 9 months after its launch and grown to 10+ Engineers/20+ employees. Shameless. On the bright side, LegalEagle also called out Pie in the video. Hopefully that'll help shine a light on them.
- jzl 2y agoMinor quibble with the linked complaint: the GPL doesn’t require you to post source code, it just requires that you have to provide it when asked, and only to people using your software. (But you’re not allowed to restrict anything they do, like repost it.) Just follow the whole Redhat / CentOS drama for exhibit A in this behavior.
- hippycruncher22 2y ago[dead]
- kelseydh 2y agoGoogle removed chrome extensions that do cookie stuffing before: https://www.zdnet.com/article/google-removes-two-chrome-ad-blocker-extensions-caught-cookie-stuffing/ https://www.zdnet.com/article/google-removes-two-chrome-ad-b... PayPal's Honey extension should be pulled by Google for doing the exact same thing. There is no difference and Honey shouldn't get special treatment just because it's owned by PayPal. --- UPDATE: It's criminal wire fraud. Brian Dunning sentenced to 18 months jail for cookie stuffing: https://www.businessinsider.com/brian-dunning-ebay-and-affiliate-marketing-fraud-2014-8 https://www.businessinsider.com/brian-dunning-ebay-and-affil... “Cookie Stuffing" internet fraud schemer Jefferson Bruce McKittrick pleads guilty: https://www.justice.gov/usao-sdal/pr/cookie-stuffing-internet-fraud-schemer-pleads-guilty-0 https://www.justice.gov/usao-sdal/pr/cookie-stuffing-interne...
- maratc 2y agoAre you a lawyer? Asking because "cookie stuffing" (which is indeed criminal) refers to the practice of setting a ton of referral cookies for the sites the browser had no intention of visiting, just for the case it will visit them some time in the future. In my understanding it does not refer to setting a cookie for the site the browser is currently on.
- bayindirh 2y agoNo but, LegalEagle is, and he's suing for class action with a bunch of other lawyers and creators [0] [1]. [0]: https://www.youtube.com/watch?v=4H4sScCB1cY https://www.youtube.com/watch?v=4H4sScCB1cY [1]: https://eagleteam.law/honeycase/ https://eagleteam.law/honeycase/
- maratc 2y agoIs he suing for class action on the claims of cookie stuffing? I haven't found the actual case in either link (the second one is for "creators" only), so I can't get the answer myself.
- 2y ago
- kelseydh 2y agoSnopes looking real silly for this 2018 fact check: https://www.snopes.com/fact-check/honey-browser-extension/ https://www.snopes.com/fact-check/honey-browser-extension/
- zeveb 2y agoSnopes in 2018 and Snopes in 2008 were sadly two very different things. They used to be such a great resource!
- xp84 2y agoThey were always a protection racket against retailers, and I haven't seen any proof that they started stuffing their affiliate code in 100% of the time only recently. The racket is that they f*k with your campaigns by stealing codes typed by users of the extension, so even users who don't think they're sharing them end up sharing them with Honey. Imagine the fun when someone creates a valuable code for someone trusted and doesn't limit its usage sufficiently, and someone uses it on a Honey-infected machine. Now the whole Internet is getting a possibly loss-making discount! Honey then contacts the business and says "Gee, wouldn't you like us to stop doing that? Just pay us 3% on every sale any of our tens of millions of users buy and we'll let you blacklist any codes you like!"
- akimbostrawman 2y agoA fact checker being wrong? How is that possible!!!
- ziml77 2y ago2 years before PayPal bought Honey. It's possible that the extension was fine at the time. Even if it had always been hijacking the referral codes, I wouldn't consider that a scam from the perspective of the users.
- hotdogbaines 2y agolooks like they did a new piece about it: https://www.snopes.com/news/2024/12/30/honey-browser-extension-scam/ https://www.snopes.com/news/2024/12/30/honey-browser-extensi...
- ChoGGi 2y agoI'd only heard of Honey by way of random YouTube thumbnails, I assumed it was some sort of scam. Go figure they're connected to PayPal...
- Larrikin 2y agoIs there a better option to Honey? The extension has saved me a good bit of money over the years, especially on newer and independent sites that sometimes offer deep discounts for your first order. But it does seem like the coupon codes come from the community and there should be a community version of the extension.
- ragingroosevelt 2y agoHoney actually hides the best deals from you at the site's request. You'd be better off finding the codes yourself.
- Larrikin 2y agoI'd rather get 10% off automatically instead of 15% off if I have to spend 30 minutes on every single purchase trying dozens of dead codes from various sites. It being automated is the entire point.
- exabrial 2y agoPayPal Honey is also involved in lawsuit where it stole Referral Codes and replaced them with its own. Basically every dollar the company has made is basically illegal.
- weiichongy24 2y ago[dead]
- floppiplopp 2y agoI don't understand. Wanting everything for free and stealing stuff is just good capitalist praxis. Has been for centuries.