Open Menu
AllLocalCommunitiesAbout
lotide
AllLocalCommunitiesAbout
Login

Chrome extensions spying on 37M users' browsing data

⁨243⁩ ⁨likes⁩

Submitted ⁨⁨17⁩ ⁨hours⁩ ago⁩ by ⁨Beep@lemmus.org⁩ to ⁨technology@lemmy.world⁩

https://qcontinuum.substack.com/p/spying-chrome-extensions-287-extensions-495

source

Comments

Sort:hotnewtop
  • Armand1@lemmy.world ⁨16⁩ ⁨hours⁩ ago

    I’ve gone through the list a bit and out of the most popular ones that spied on you, most were adblocks, coupon finders or AI Chatbots.

    Some notable extensions:

    • Stylish. A theming extension, I used to use this back in the day!
    • Smarty. Some sort of coupon code thing like Honey
    • Video Ad Blocker Plus for YouTube™
    • Video Downloader PLUS
    • Karma - Another coupon thing
    • Audio editor online Audacity. Some sort of web-based Audacity clone?
    • GIMP online - Same sort of thing as above with GIMP
    • Ground News Bias Checker - To be fair it probably makes sense this one sends the URL you are visiting, as it’s purpose is to look up the bias of the publication you are looking at.

    Worth a read regardless.

    source
    • x00z@lemmy.world ⁨11⁩ ⁨hours⁩ ago

      Stylish is long known and the opensource Stylus fork is suggested. github.com/openstyles/stylus

      source
  • spaghettiwestern@sh.itjust.works ⁨13⁩ ⁨hours⁩ ago

    If a organization with a tiny fraction of Google’s resources can detect these extensions Google can too. There is only one reason malware extensions and Android apps are being distributed by Google - they make more money distributing malware than they would if they detected and blocked it.

    And these assholes pretend they are blocking app stores like F-Droid for “our protection”.

    source
    • x00z@lemmy.world ⁨11⁩ ⁨hours⁩ ago

      Google just shrugs and points to the little messagebox that pops up and explains almost nothing asking you for permission.

      source
      • spaghettiwestern@sh.itjust.works ⁨11⁩ ⁨hours⁩ ago

        I’ve disabled Google’s Play Protect after it deleted multiple apps I rarely use and all their settings and having to spend hours configuring them again. I know I can manually change individual app settings to prevent that from happening, but given all the years Google’s been distributing malware why trust them? The fact Google regularly distributes malware and then wants permission to scan my phone for malware is laughable.

        I avoid apps from the Google store because they can be downright dangerous, but I have few worries about that “dangerous” third party F-droid store.

        source
  • Armand1@lemmy.world ⁨17⁩ ⁨hours⁩ ago

    Great work to the investigators here. I’m going to comb through this list a little. See what things stand out.

    source
  • umbrella@lemmy.ml ⁨13⁩ ⁨hours⁩ ago

    using chrome

    source
    • protogen420@lemmy.blahaj.zone ⁨11⁩ ⁨hours⁩ ago

      and using non-free extensions as well

      source
  • Armand1@lemmy.world ⁨16⁩ ⁨hours⁩ ago

    Another interesting one. These extensions are all related:

    Image

    source
    • protogen420@lemmy.blahaj.zone ⁨11⁩ ⁨hours⁩ ago

      wow so many trade mark violations, so blantant that even a shit a automated system shouldve caught it, but no google is too busy selling ads and profiling users

      source
      • lobut@lemmy.ca ⁨8⁩ ⁨hours⁩ ago

        The thing I’ve heard about Google is that there isn’t as high of a career path for people that want to maintain software and keep it running well. If you can create a new app or service and it gets X downloads then you can ask for more money and a lot of SWEs will game that. So, far better to add to the graveyard than anything else.

        source
  • sundaymidnight@lemmy.world ⁨16⁩ ⁨hours⁩ ago

    for “pelotudos” (idiots)

    they can use Brave, it’s easy-peasy (not nuclear science)

    source
    • Blackfeathr@lemmy.world ⁨16⁩ ⁨hours⁩ ago

      Yeah the Brave CEO has donated to anti LGBTQ campaigns.

      No thanks

      source
      • sundaymidnight@lemmy.world ⁨1⁩ ⁨hour⁩ ago

        Hey, I don’t say that Brendan is perfect.

        source
      • NotAnotherLemmyUser@lemmy.world ⁨14⁩ ⁨hours⁩ ago

        Just to add a little context to this. The Brave CEO donated $1k to California’s Proposition 8 almost 20 years ago (in 2008). 6 years later he formally apologized for it and stepped down as the CEO of Mozilla.

        wikipedia.org/wiki/Brendan_Eich
        His apology is viewable on his website: brendaneich.com

        source
        • -> View More Comments
      • pivot_root@lemmy.world ⁨13⁩ ⁨hours⁩ ago

        He also created JavaScript, IIRC.

        Big no thanks.

        source
    • vollkorntomate@infosec.pub ⁨16⁩ ⁨hours⁩ ago

      And how exactly does this protect against spying extensions?

      source
    • pivot_root@lemmy.world ⁨13⁩ ⁨hours⁩ ago

      Using a reskinned Google Chrome protects you from malicious Chrome extensions how, exactly?

      source
      • sundaymidnight@lemmy.world ⁨1⁩ ⁨hour⁩ ago

        Brave users don’t use external addons (Brave provides native addons). Then, you use Brave without Chrome Webstore addons.

        source
    • Crackhappy@lemmy.world ⁨14⁩ ⁨hours⁩ ago

      Brave is in the list.

      source
    • prole@lemmy.blahaj.zone ⁨13⁩ ⁨hours⁩ ago

      Brave is shit

      source
    • MedicPigBabySaver@lemmy.world ⁨15⁩ ⁨hours⁩ ago

      No bueno.

      source