7 ms·
Google purges bad extensions from Chrome
- rip747 11y agoI don't understand why you can't block (or lockout) certain permissions for extensions. If an extension requests permission to browsing history, you should be able to install the extension by deny it access. this is the same problem that I see on Android.
- miander 11y agoWhen the extensions are removed from the Chrome Web Store are they removed from everyone's browsers automatically? I didn't see it mentioned here or in the article.
- unreal37 11y agoNo. Google uninstalling things from your computer without your permission? Now that would be news.
- james-skemp 11y agoActually I think the answer is yes. Or at least they're disabled. I forget the name but I had one that allowed for a custom new tab page. It had opt-out ads, but I otherwise loved it. It kept getting disabled after each fresh start of Chrome. Debated forking it but haven't yet. It might matter that I do have my extensions sync between machines. Extension is eventually disabled on the others as well. EDIT: "This extension violates the Chrome Web Store policy." The extension is Modern New Tab Page. The store page is gone, so no clue what policies are violated, what I need to fear, etcetera. I can still enable it, but it will be disabled at some point. Does it have questionable practices? Yes. There's a settings option but it's different than the settings I see by going to chrome://extensions/ as the sole option on the latter is to disable ads. EDIT 2: To be clear, this extension was blocked late last year, and is not part of this recent batch. At that time there were questions about whether there was a list as well. There was, like this time, no notification to impacted users.
- unreal37 11y agoHmm, disabling with a notice is not a bad middle-ground actually. For the worst offenders.
- james-skemp 11y agoIt's a horrible middle-ground. Google definitely dropped the ball with alerting users of a possible breach. If there's strong evidence a plugin was capturing and using credentials I need to know to change credentials.
- brettbl 11y agoWhats googles protocol for approving apps? how do they not notice the problems before the apps even hit the store?
- ocdtrekkie 11y agoShould say "Google does a lousy job purging bad extensions from Chrome". A: Because all of the malware I reported is still there. And B: Because actually policing your store for malware for once shouldn't be a news item.
- slacka 11y agoCould you give some examples of malware that you reported that are still there? What conditions do you use to classify extensions as malware?
- ocdtrekkie 11y agoA good example of Vosteran New Tab. Almost two million users, none or near none of which are consensual users. Nobody I've ever uninstalled that from ever intended to install it. It hijacks your new tab page and search. Interestingly enough, Vosteran also produces a rogue fork of Chrome which makes Vosteran's own search/ad platform built-in and unavoidable. Said rogue fork is also installed without users' permission. https://chrome.google.com/webstore/detail/vosteran-new-tab/oilkkkefbalmbfppgjmgjoefbclebkce https://chrome.google.com/webstore/detail/vosteran-new-tab/o... I invite you to peruse the first five pages of search results here and make your own assumptions about the legitimacy of all it's five star ratings: https://www.google.com/?gws_rd=ssl#q=vosteran https://www.google.com/?gws_rd=ssl#q=vosteran
- username223 11y agoHm, let's take a look at Vosteran. From Wikipedia[1]: "Vosteran is a browser hijacker that changes a browser's home page and default search provider to vosteran.com. This infection is essentially distributed bundled with other third-party applications. Vosteran carries the PUP virus. The identity of Vosteran is protected by privacyprotect.org from Australia." Okay, so it's malware. Let's check out their webpage[2]! Hm, they give a physical address at 28 Lilienbulm St. in Tel Aviv... as an image, to avoid search engines. Let's look at their "how-to-get-rid-of-this-crap-I-don't-want" process[3], which "shouldn't take more than 10 minutes": so they basically put their tentacles into any crevice they can find, and make it annoying to pry them out. Let's see if it's easy to see who runs this bit of evil... nope. They're amoral scum. [1] https://en.wikipedia.org/wiki/Browser_hijacking#Vosteran https://en.wikipedia.org/wiki/Browser_hijacking#Vosteran [2] http://www.vosteransearch.com/contact-us/ http://www.vosteransearch.com/contact-us/ [3] http://www.vosteransearch.com/how-to-remove/ http://www.vosteransearch.com/how-to-remove/
- wahsd 11y agoThat's amazing news ..... YEARS after it should have happened
- obisw4n 11y agoChrome extensions can do some really nasty things.. Just last year while doing adware research for extensions, I actually came across an extension monetization company who was silently installing google android apps to the users phone with no human interaction what so ever, I wrote a break down of this on my blog: http://extensiondefender.com/blog/red-alert-dangerous-exploit-poses-major-threat-to-all-android-users/ http://extensiondefender.com/blog/red-alert-dangerous-exploi...
- hackaflocka 11y agoChrome always gives this really scary warning that the extension will be able to read all my tabs etc. They need to sandbox everything so that I don't have to feel worried while installing extensions. Worry is not a good UX.
- wyclif 11y agoGoogle needs a better way to notify users when extensions are superseded. For instance, I used to use the Google Voice extension even though it was buggy as hell, and kept using it for too long because I didn't know about the much better Hangouts extension that replaced it (I had been using Hangouts for a while but never had the Chrome extension).
- xmodem 11y agoThis probably isn't a popular view for the HN crowd but at this point I'm convinced that for 90% of users, browser extensions are an anti-feature doing way more harm than good.
- username223 11y agoFor almost 100% of users, the "modern web" is an anti-feature doing way more harm than good. It's a giant pile of tracking scripts and animated "punch-the-monkey" graphics wasting users' power and bandwidth while stealing their personal data and providing nothing of value. Web browsers are creaking piles of bloat trying (badly) to support this disaster while pretending to be shinier than their competitors, or than last month's version of themselves. Browser extensions offer a whole new host of evils, along with a marginally effective way to fight back against the rising tsunami of web horrors. The web is mostly about harming users, so I can hardly blame them for grasping at whatever chance they have to defend themselves.
- Mahn 11y agoMuch like toolbars back in the day. I still think that browsers should just let extensions be fully disabled by default so only the power users who know what they are doing can enable them poking in settings.
- c0l0nelpanic 11y agoThis only addresses part of the problem. Chrome extensions are ONE method of injecting into a page. What about more advanced methods including code hooks, Proxy, LSP, TDI, WFP, etc... What is Chrome going to do about those?
- wiradikusuma 11y agoJust FYI, there are many cases of malware (presumably browser extensions) targeting online bankings in Indonesia recently. The typical flow is like this: 1. The user logs in to his/her online banking website. 2. The malware gets triggered and phones home with user's credentials. 3. The bad guy logs in using user's credentials in own computer. 4. The bad guy initiates bank transfer from user's account to his account. 4. The bad guy is presented with "enter auth code" to confirm the transaction. 5. The malware pops up "Verify your auth code" into user's computer. 6. Thinking "it must be new method from my bank", user types his/her auth code. 7. The auth code gets sent to the bad guy, allowing him to complete transaction. 8. Profit. Even tech savvy people can be a victim if he's being careless.
- 13 11y agoDoesn't even have to be that complicated, the malware can just rewrite the destination to the malware author's silently and wait for people to be sending money there anyway. It's a reasonably dangerous property of Google-style 2FA that they can be transposed without any warning. My bank attempts to get around this by only using SMS based tokens, and the first line of the SMS says exactly what is being sent and where.
- aianus 11y agoOn the other hand, it's much easier to reroute a cell phone number through social engineering than to steal TOTP secrets.
- 13 11y agoIs it really possible from an evil standpoint to get SMS rerouted to another number? I was looking into that a while ago (I wanted a prettier number, but didn't want to lose things associated with the old one) and the answer I got was that it's not something anybody can do. I get how the phone call rerouting stuff would go down, but not SMS rerouting.
- seanp2k2 11y ago
- angeNoble 11y agoDoes anyone know where one could find a list of offending plugins? I tried, but came up empty handed.
- obisw4n 11y agoI've been in contact with someone from Google Security and this was their answer: "I spoke to the team that maintains that list and they don't have plans to make it public, if you would be willing to share some ideas on how to better protect people from this unwanted software I would be happy to pass it on but due to the nature of the work (trying to stay one step ahead of bad guys) we probably won't be able to share anything back." I'm the author of this anti-adware addon called "Extension Defender" and it would greatly help my users if I could use their list, because while they extensions were removed from the Webstore, does that mean it was forcibly removed from their PC? Probably not. Plug: https://chrome.google.com/webstore/detail/extension-defender/lkakdehcmmnojcdalpkfgmhphnicaonm https://chrome.google.com/webstore/detail/extension-defender...
- zecg 11y agoI'd like this as well.
- aareet 11y agoI had the same problem. I'd also like to know whether an extension purged from the store will be automatically removed from Chrome if it is installed or would have to be manually removed.
- mmahemoff 11y ago"This extension will have access to your browsing history and private data on all websites". Which is usually accompanied by the developer apologising and explaining they have to declare this in order to provide the extension's core functionality. Users then learn to ignore these warnings, malicious extensions ensue. I'm glad Google is taking malicious extensions seriously, but purging is a difficult semi-manual effort when extensions can update any time. A lot more effective would be to bake security into the whole model. Extensions shouldn't need to see your entire browsing history on all sites just to enhance some links or do syntax highlighting. It should also be possible to request permissions on demand, and for certain URLs, instead of blanket-consenting before the extension is even installed. I know these things are a trade-off with simplicity, but should at least be there for orgs and individuals who want to take advantage of them.
- grrowl 11y agoUnfortunately it's hard to access /any/ information on a page without accessing /all/ information on a page. Unless the page can expose the data itself (say, through an API) an extension will need to access the DOM. Accessing the DOM means data leakage from that page to potentially any server.
- TazeTSchnitzel 11y agoSounds like Chrome's "security model" for extensions is just as awful as Android? Large, sweeping permissions categories rather than fine-grained control, and all-or-nothing acceptance.
- mmahemoff 11y agoPretty much the same, which is different to general websites, which do on-demand permissions (as with iOS model). Chrome extensions can request only access to specific URL regex's, so they can be fine-grained about location, but the actual permissions tend to be coarse-grained. And as a user, you can't change the URL regex (that's some low-hanging fruit right there - users should be able to edit the URL pattern for any extension). In some respects, Chrome apps are morphing to be general websites (e.g. with manifest.json and installing to home screen on Android), so hopefully things will move more in the direction of the web. There were also some hints towards on-demand permissions in the security talk at the most recent Chrome Web Summit, I'm not sure it's proceeding.
- userbinator 11y agoAren't extensions written in JavaScript? That alone sounds like it'd make it pretty easy to examine and remove any "unwanted functionality" from one, or to show that it's doing something it shouldn't be. It only takes one knowledgeable user to find out and spread the news... As an aside, I'm surprised at how willing most users seem to be to install any software, be it browser extensions or random apps on their phones/tablets/PCs. Especially in the case of deliberately malicious extensions mentioned in the article, I wonder if they were installed without the user ever considering "What is this for? Do I really need it?"
- CaveTech 11y agoTons of extensions serve the purpose of modifying actual pages to change/modify/add content. When users have many extensions, it's near impossible to determine which one is the bad actor without a lot of leg work. But people do figure it out and spread the news exactly how you describe. The problem is most people don't read the reviews and most casual internet users have no idea what's wrong if the functionality is added after the fact.
- jfoster 11y agoThere are lots of potential explanations which don't involve stupidity. Users may mistakenly assume apps/extensions are nowadays sufficiently sandboxed. Users may also be assuming that the Chrome Web Store is a somewhat reputable marketplace with any malicious software weeded out.
- tomjen3 11y ago>That alone sounds like it'd make it pretty easy to examine and remove Minified and obfuscated Javascript is not much easier to check than binary files and more difficult than e.g Java class files, at least without ProGuard.
- STRML 11y agoJust as a reference, you might like this tool - I've gotten great results with some really gnarly minified/obfuscated JS. http://www.jsnice.org/ http://www.jsnice.org/
- dankohn1 11y agoThis is fantastic news. The Quick Note Chrome extension from Diigo (now removed) submits every URL visited to a third-party server and those URLs are then crawled the next day. We just switched our 25 member customer service team to Chromeboxes and were very concerned to find soon after that an EC2-based crawler was querying private URLs of our platform. Because the Chrome Web Store had not banned bad actors like Diigo, we now blacklisted all Chrome extensions except for a very small number that I personally approve. Rather than feeling that ChromeOS was improving our security, we had our chief software architect spend most of the weekend figuring out who was targeting our platform. (All queries received 404 errors, but we remained concerned whether the rogue extension could read the submitted form credentials or the cookie store to get access.) Rogue extensions are wasting a huge amount of time and destroying trust in the Chrome platform. Here's some more detail on similar stories about Diigo: https://chrisa.wordpress.com/2014/08/25/chrome-extensions-going-rogue/ https://chrisa.wordpress.com/2014/08/25/chrome-extensions-go... https://mig5.net/content/awesome-screenshot-and-niki-bot https://mig5.net/content/awesome-screenshot-and-niki-bot I am thrilled to see Google finally acting to restore trust in their platform. Update: Google removed Diigo Quick Note, but still has Awesome Screenshot <https://chrome.google.com/webstore/search/diigo?hl=en-US> https://chrome.google.com/webstore/search/diigo?hl=en-US> which captures the identical data and sells it to third party crawlers.
- Istof 11y agosomewhat unrelated but if you email a private URL to a Microsoft email address, they will also crawl it, about once a month (I get an email anytime someone access it and MS bot is the only one accessing it). Not sure if Google also does that...
- kardos 11y agoThis is why I always put a user/pass on any private URL I don't think their URL scanners are clever enough to dig through emails and try user/pass combos
- sanemat 11y agoI think Awesome Screenshot is "bad" extension too, but purging from the store is too much.
- yawz 11y agoWell... Wouldn't it be useful to publish a list of the offending extensions?
- bad_user 11y ago> "You would expect that an extension that injects or replaces advertisements is malicious, but then you have AdBlock that creates an ad-free browsing experience and is technically very similar." AdBlock is very clear in what it does and users install it because they want to block ads, whereas users are usually not aware when an extension injects ads. As a note, the Awesome Screenshot extension for Firefox asks you if you want ads injected, probably because of Mozilla's review process, whereas the Chrome version does not. It's one thing for websites to be ripped of the opportunity to make money from your eyeballs, with your consent, it's quite another for those same websites to generate money unknowingly for an obscure third-party. We are probably talking about copyright infringement done for commercial for-profit reasons. Google is annoying me lately. I now use Firefox on my Android and I do that because AdBlock Plus and uBlock are working on it, whereas Chrome for Android still doesn't have plugins, probably because they don't want ad blockers in it.
- seanp2k2 11y agoYeah, but ABP also has white listed ads: http://techcrunch.com/2013/07/06/google-and-others-reportedly-pay-adblock-plus-to-show-you-ads-anyway/ http://techcrunch.com/2013/07/06/google-and-others-reportedl... Ghostery has a bit of a different model, but they're no saints: http://www.technologyreview.com/news/516156/a-popular-ad-blocker-also-helps-the-ad-industry/ http://www.technologyreview.com/news/516156/a-popular-ad-blo... I guess the lure of selling use data is just too great for any commercial entity to control the source of these as blockers. uBlock and PrivacyBadger are still clean AFAIK.
- username223 11y agoFrom what I've read, ABP are just plain extortionists: "those are nice 'acceptable' ads you have; shame if something were to happen to them." Ghostery's business model makes it a bit untrustworthy, but it works pretty well as far as I can tell. uBlock is "you get what you pay for" freeware, so you can trust it as long as not many people use it. PrivacyBadger is developed by a small number of honest-to-God privacy zealots (in the best possible sense), so it won't get sold out, but will probably lag behind the curve. I use a couple of them at once, block most JavaScript, usually run with cookies disabled, and pay a bit of attention to what's going on in the privacy news. For less tech-savvy relatives, I just install Ghostery and disable third-party cookies, since that seems least likely to break websites, and blocks most of the worst tracking. Oh, and hosts-block tynt. Those guys should drown in burning kerosene.
- pjmlp 11y agoBetter yet, disable all of them.
- lkbm 11y agoDisable all extensions? No more Tampermonkey, Postman, LastPass? Seems like a massive overkill. Extensions provide vital functionality.
- pjmlp 11y agoWhat functionality? Never heard any of those. Browsers are for interactive documents, for everything else there are native applications, even though I also do web development gigs.
- josteink 11y agoSo how long until AdBlock Plus and uBlock are "bad" extensions? Enjoy your walled garden. Soon enough the walls will be so high you wont even remember what a free browser felt like.
- ocdtrekkie 11y agoWell, AdBlock Plus is a bad extension. People who use it should feel like scum. Because they are scum. That being said, your walled garden notion is accurate. Chrome used "security" as an excuse to lock down the extensions platform to only their Web Store. But it's not any more secure, since there's plenty of malware in the Web Store. It was just an excuse to wall in their product.
- narrowrail 11y agoYou can manually install extensions, which is how I install mine (e.g. µMatrix). I'd rather not have to use the Chrome store (and I prefer Chromium , as well).
- amyjess 11y ago> You can manually install extensions Not on Chrome stable. You have to use beta, dev, or a Chromium build for that.
- tim333 11y agoI think you can on regular Chrome. Just tick the 'Developer Mode' box at the top of the extensions page.
- gergles 11y agoI don't think you can on Windows.
- sleazebreeze 11y agoDeveloper Mode in Chrome is most definitely available on Windows.
- wnevets 11y agoits too easy to bait and switch with chrome extensions. Authors can sneak malware into their code at any point and you have zero chance of stopping it
- stevenh 11y agoI've created a few Chrome extensions, and I constantly get bombarded with aggressive emails practically demanding that I accept financial compensation in exchange for adding whatever sketchy javascript snippet they want me to add. Some even have the nerve to follow up as if they are offended by my silence when I don't respond to them. I'm not sure how those people even got their hands on my email address. What infuriates me is that even extensions that are widely known to have succumbed to these sinister offers to include borderline malware in their extension, such as Hover Zoom, are not punished in the slightest even after being caught, or even required to remove the malicious javascript snippet. What the hell is the point of all these XSS prevention measures in modern browsers, such as reflected XSS prevention, CSP, script nonces, etc. when all you have to do to bypass all of them is make your own browser extension? Is the team at Google that handles Chrome extensions completely unable to communicate with the team that handles browser security? The left hand has forgotten that the right hand even exists. I nominate Google as the company that the movie The Cube was warning us about. If the suspiciously nameless author of this article wasn't paid by Google to write it, then he ripped himself off. If the author had performed the most basic research into the topic he was writing about, he would have learned that Firefox's approach to extensions is perfect and is the only reasonable solution to the security problems that exist with Chrome's extensions. An actual journalist writing about this topic would have swiftly concluded that Google should be lambasted for its blunders and mocked for not living up to Firefox's standards, rather than being borderline worshipped for barely doing anything to fix a horrific problem they openly invited in the first place.
- speik 11y agoAn extension I use regularly got zapped (Website Screenshot). There are definitely alternatives out there, but it's a little annoying that there was no indication as to WHY it was removed. Oh well.
- sandinmyjoints 11y ago> Preliminary results revealed that 5% of people accessing Google every day have been caught out by at least one malicious extension. How might they have detected what extensions are installed in their visitor's browsers? Is there a way to enumerate installed extensions? http://browserspy.dk/ http://browserspy.dk/ and https://panopticlick.eff.org/ https://panopticlick.eff.org/ detect plugins, but those aren't the same as extensions.
- kuschku 11y agoGoogle probably compares all the JS and HTML of the resulting page in-browser with the code that they originally delivered, allowing them to see if an extension or userscript manipulated it.
- fragmede 11y agoThe article mentions Google was involved in the research, so they just went by the number of downloads of malware extensions on their store.
- 27182818284 11y agoThe security model of chrome extensions is such that I only use one--and that's one from a well-known company that I already trust with sensitive items. I just can't talk myself into the "This extension will have access to your browsing history and private data on all websites" warning that appears beforehand, and it looks like with extensions sending private URLs away to be crawled, I was at least a little correct to worry.