7 ms·
Et Tu, Grammarly?
- regularjack 2y agoEt toi
- dbushell 2y agoHow do you deal with hostile browser extensions?
- WJW 2y agoUninstall them?
- dbushell 2y agoIf only I could opt-out, disable, or uninstall those used by visitors to my website when the extension breaks it :(
- diggan 2y agoNot much you can do, user agents continue to act as agents for the users, meaning you can serve them stuff but beyond that it's up to them to dictate their experience, for better or worse. It really sucks when extensions do fudgy stuff in global space and sometimes break your stuff though, agree. Best approach I've found is to have a help page you can link to so people can go through the typical steps of "disabling all extensions, clearing cache, etc, etc" when things break in very unexpected way and you find no causes for it.
- dbushell 2y agoIndeed. It's the user's browser and experience, it's not up to the website owner. But it's frustrating to get bug reports when a 3rd party extension is the problem, not the website. Many visitors will just bounce blaming the website too.
- ziml77 2y agoWithout someone pointing the user to what the issue is, it's very difficult for the user to know it's an extension causing the problem. Many years ago I had performance issues with a site and the only reason I knew it was due to an extension is I dug into it with the dev tools and managed to identify Dashlane as the problem.
- netsharc 2y agoI guess you could figure out valid states for your page's DOM, and a few seconds after the page has finished loading, scan it for "hostile" elements and CSS styles, and delete them... Having this idea and opening a random page (from The Guardian) on DevTools, somehow somebody's inserted scripts and iframes pointing to twitter.com.
- kelvinjps10 2y agoBut wouldn't you brake their extensions if the user wanted them to work?
- eadmund 2y agoI don’t think that ‘hostile’ is really fair in this case, when ‘insufficiently competent’ will do (albeit at the cost of more syllables). I am not a fan of Grammarly or their technical model, but I don think it’s fair to attribute malice when it is adequately explained by stupidity. It’s been a long time since I did any front-end work: should both Grammarly’s extension and your own code use namespaced property names?
- dbushell 2y agoyep, it's in Grammarly's interest to namespace or scope their CSS in a way that doesn't conflict. Not doing it adequately goes both ways, website CSS could break their extension, or their extension could break the website.
- QuadmasterXLII 2y agoWe tried applying cunningham’s law widely and it created disastrous incentives. It’s better to assume profitable yet destructive incompetence is malice.
- chuckadams 2y agoAny sufficiently advanced stupidity is indistinguishable from malice.
- MartijnHols 2y agoUnfortunately browsers don't really provide good solutions for extensions that need to inject or change sites. Look at Google's owner in-browser translate extension, its DOM manipulation breaks many interactive apps as well. There are no tools available in browsers for it to not need to do that.
- amelius 2y agoAt this point, I'm not installing any browser extensions, period.
- bufferoverflow 2y agoBut our users do.
- gs17 2y agoOP's problem wasn't that they had it installed, it's that enough of their users did to make it a problem when it breaks the site's CSS.
- bmacho 2y agoBrowser extensions are the equivalent of running random .exe on your computer except that you have to trust every vendor protecting their keys forever due to the autoupdate.
- silvestrov 2y agoThe biggest problem with browser extensions is that the source code (both css and javascript) is not easy to read/check. There should be an easy "view source" for extensions inside Chrome and extensions should be mandated to ship non-minimized code.
- kelvinjps10 2y agoNot even ublock?
- Doctor_Fegg 2y agoAh, my favourite complaint for the community website I run. "I can't see any photos on the adverts page." Are you running an ad-blocker? "Yes." What do you think an ad-blocker does...
- deleted 2y ago[deleted]
- Aldipower 2y agoI've a similiar problem with Google Translate that breaks my web app. Users, using Google Translate, complaining my app is broken, but it was Google changing the state of my app from a higher meta level. Really bad practice.. I am trying to detect Google Translate and print a warning then.
- netsharc 2y agoMaybe related, from 2 days ago: https://www.pewresearch.org/decoded/2025/03/21/how-a-glitch-in-an-online-survey-replaced-the-word-yes-with-forks/ https://www.pewresearch.org/decoded/2025/03/21/how-a-glitch-... / https://news.ycombinator.com/item?id=43441880 https://news.ycombinator.com/item?id=43441880
- MartijnHols 2y agoWhile Google Translate's interference sucks, with current browser tools, I don't think they can really operate any other way. This is mostly because of cases where they need to translate a sentence like "[Click here] for more information". When translating it to another language, they may have to move the link to the end e.g. "For more information, [click here]". The only way to achieve that is to shuffle DOM elements around, which can cause interference with interactive apps. There's still a lot the Google Translate team can do to reduce the interference they cause, but I don't think they can fully eliminate it without some new browser APIs.
- kelvinjps10 2y agoBut they are the owners of a browser
- preinheimer 2y agoMy extension problem story is a bit different. We distribute an extension that makes it easy to switch between proxy servers for geolocation testing. I ran my worst client demo ever a few months ago. It was like our product simply didn’t work. A lot of pulled hair and frustrating debugging later we discovered that a recent update to the 1Password extension broke ours. They were subscribing to an auth event, but not returning, this timed out so our subscriber was never called. So our extension would tell the browser to change proxy servers, then sit ready to provide credentials, but the request would never come. 1Password’s support team was better than grammerly’s, but it’s hard to convince an unknown PM to prioritize something, especially if you’re speaking to them via a support team. We’ve since discovered that there’s some Russian extension you need for government websites that has the same issue.
- horsawlarway 2y agoYeah, similar boat here. 1pass still breaks opening the chrome sidepanel UI from content scripts in other extensions. They screw up the trusted flag that indicates the event is coming from a user interaction. Ultimately, as someone in the extension space for more than a decade now, Google is really at fault... Manifest v3 is just crappier than it should be in a LOT of ways (entirely outside the politics of the ad blocker changes - which is a whole different can o worms). Overall, I think the quality of the chromium codebase feels a lot lower than it used to.
- jFriedensreich 2y agoIts frightening to see how many screenshares and recordings contain that green infestation as default on every website, not just the obvious visual disturbance (am i the only one who thinks the green is ugly and clashes with most websites colors?) that does not seem to bother users but the privacy and obvious attack vectors that come with it. Chrome can enable extensions only when needed why does no one do this? Why is this not the default on every browser?
- the__alchemist 2y agoClarify?
- financetechbro 2y ago[flagged]
- echelon 2y agoI suppose they're concerned so many people are blindly installing Grammarly without a sandbox. I'm concerned too, but from the angle that writing on the internet is becoming less human, more robot protocol. Even when it's from humans. As if bots weren't enough of a problem, imagine when social media is just people clicking on buttons: "write a funny response", "write a comment in disagreement", "write 'same'", etc.
- ZeroTalent 2y ago> As if bots weren't enough of a problem, imagine when social media is just people clicking on buttons: "write a funny response", "write a comment in disagreement", "write 'same'", etc. There are already extensions for this purpose. replai.so and dozens others
- mrweasel 2y agoI count myself fairly lucky to have colleague that care about these sorts of things. We have had meeting halted because it was obvious that some participants had certain extensions installed, AI assistants of various types, and some colleagues aren't comfortable with information potentially being picked up by a third party. So the meeting is halted until the extension is disabled.
- vhantz 2y agoDo you know how they managed to inject stylesheets into every page bypassing CSP?
- deleted 2y ago[deleted]
- daquisu 2y agoIt is done by the extension without any fancy stuff. Extensions can load static js / css and bypass CSP with it, if it is declared in their manifest.json. Grammarly's manifest.json is here: https://gist.github.com/Daquisu/11eb1a7000b4141c4404edcc6e16b666 https://gist.github.com/Daquisu/11eb1a7000b4141c4404edcc6e16... For more advanced CSP bypass with extension, you can: 1. Inject JS code into any webpage with a CSP. 2. Create an event listener for your content script and reacting according to it. 3. Use your content script to communicate with the background script. 4. Use the background script to communicate with any website, including blocked websites by the CSP. Basically, any website <-> extension content script <-> background script <-> any website.
- deleted 2y ago[deleted]
- kstrauser 2y agoI passed this along to the engineering team.
- dbushell 2y agothanks!
- kstrauser 2y agoYou bet!
- stavros 2y agoThis is fairly unrealted, but it irks me when one-line fixes like this sit for ages in backlog hell. I want a company where developers go "might as well fix that now, it's faster than writing a ticket for it". I see people where I work not do this, and it drives me crazy. Our director of engineering will literally add tickets for himself to do things that would take less time to just do. At least I hear "I took a page from your book and messaged the person instead of adding a ticket for myself to message them" often, which is a good sign.
- quesera 2y ago> Our director of engineering will literally add tickets for himself to do things that would take less time to just do I've done this. It irks me too, but sometimes I'm in organizational mode, and sometimes I'm in execution mode. :) Also, I work in an environment[0] where all work is required to go through the formal tracker documentation flow (and all code changes must be approved by a second party). So the ticket step is non-optional, and in fact required before work can begin -- we name branches with the ticket ID, so that Pivotal[1] can track the GitHub lifecycle. [0] PCI-DSS, SOC 2, etc [1] RIP :(
- stavros 2y agoYeah, I guess if you're in a regulated environment, you have no choice. Most companies have no excuse, though!
- karaterobot 2y agoIf you're injecting scripts or styles into unknown pages, the least you can do is namespace your variables.
- tikhonj 2y agoHell, namespacing makes life easier even just for yourself. I wrote some browser automation in a previous role that was never going to be user-facing—it wasn't an extension—and it still proved useful to namespace things, both to clearly mark what we were inserting vs what was already there, and to avoid possible collisions.
- bryanrasmussen 2y agothis really pisses me off because about 5-6 months ago I was doing an interview for a job that of course I did not get because old, and I talked about an instagram / branding startup thing I was the CTO of and main programmer in 2014 and how I made this build system to make sure that css classes and JavaScript objects were properly namespaced and how we made sure there was no potential collisions and the way we made sure exactly what scripts needed to be loaded on the page based on which of our widgets were on the 3rd party client site etc. etc. and at the end of it the guy interviewing me said dismissively there are tools that do that and everybody does that nowadays which I sort of had to agree they probably did because who knows, I'm not really doing that thing any more, and now it turns out they don't even. on edit: fixed some grammar
- mopenstein 2y agoI wonder what would happen if you cut your salary requirements in half. Would they still reject you on your age or what? And if so, would they reject you if you slashed it in half again? And keep slashing until they hired you. Just as an experiment
- mvid 2y ago“There is no ageism, because you could work for free or at a loss!”
- emptysea 2y agoAt work we have a lot of sentry errors related to browser extensions doing weird stuff. Chrome’s Google translate is also notorious for breaking react based sites. It ends up being a tedious triage process to ignore each new extension issue. We use the client side filtering to reduce our ingest volume. In general we have to have a lot higher thresholds to handle the noise vs our backends.
- jgalt212 2y ago> At work we have a lot of sentry errors related to browser extensions doing weird stuff. Are you referring to the "Object captured as exception" error which Sentry refuses to give any guidance on? We just end of filtering these out client-side.
- emptysea 2y agoAh yeah I remember that one, but can’t remember the origin. A lot of times the reason sentry can’t do much is because the browser JS VMs have terrible/non-existent stack traces, especially true with things like unhandled rejected promises.
- MartijnHols 2y agoIt's not just noise though; clients are actually experiencing crashes and other issues because of it. I wrote an in-depth article on the Google Translate extension's interference of React (and other webapps): https://martijnhols.nl/blog/everything-about-google-translate-crashing-react https://martijnhols.nl/blog/everything-about-google-translat... It's no wonder frontend has a lot more errors, after all it has to support so many more client variations than a typical backend. It can be very hard to make a big webapp that works well for everyone.
- jgalt212 2y ago- Access your data for all websites - Display notifications to you - Access browser tabs > They could also, you know, not inject their code into every web page ever, unless the extension is actually used? I guess we know why Grammarly never has any problems raising more funding.
- MartijnHols 2y agoMakes me wonder if you can use this to hijack their plugin. At the very least you should be able to inject text into it, but you can probably render a pretty little login form as well, abusing the trust the user has in their extension. Is injecting elements into a document controlled by others really safe?
- echoangle 2y agoHow would this work? They are injecting CSS into your page, but you can't inject anything into the extension UI from a website. The only thing you could do would be to emulate the extension UI in your website, but for that you don't need to inject anything. You can just copy the design.
- MartijnHols 2y agoThe article mentions they inject a web component. I imagine a bad actor could add something to that. In this case at the very least the author could add a "I hacked your Grammarly extension" text just via CSS, but I'm sure you can go much further, even more so with other extensions (eg password managers).
- echoangle 2y agoBut you could also just add you own lookalike web component to you page that looks like the grammarly one. If people enter credentials there, it's user error.
- deleted 2y ago[deleted]
- lelandfe 2y agoI wonder what one variable could be injected to most break the web. I’m feeling: --primary-color: transparent
- xigoi 2y ago--serif: "Comic Sans MS"
- olevzhyn 2y agoHey. I’m an engineer at Grammarly Extension. First of all, I’m really sorry that our extension broke the UX on dbushell.com and caused the author to spend time and effort figuring this out. That was never intentional, and we are using various techniques to prevent this from happening. Unfortunately, that wasn’t enough. The article clearly shows that there’s room for improvement. We temporarily added an exception for dbushell.com as a quick fix. In the meantime, we’re working on a change to ensure proper style isolation; such issues must never be the case. Thank you!
- b0ner_t0ner 2y agoIs Grammarly hiring?
- kstrauser 2y agoWe are! https://www.grammarly.com/careers/jobs https://www.grammarly.com/careers/jobs
- nikolay 2y agoI am happy with Microsoft's free grammar checker extension - Microsoft Editor [0], which supports foreign languages as well... although I still pay for Grammarly. Microsoft's works more smoothly and on more sites, including Hacker New! [0]: https://chromewebstore.google.com/detail/microsoft-editor-spelling/gpaiobkfhnonedkhhfjpmhdalgeoebfa https://chromewebstore.google.com/detail/microsoft-editor-sp...