Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
palant
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
palant
2y ago
Note : I am the author of this article. Apples and oranges. Android is supposed to isolate apps from each other (yes, theory). So a malicious app should only be able to steal data the user provides it with. On the other hand, a single mali
2.
▲
by
palant
2y ago
Note : I am the author of this article. MV3 makes it considerably harder to introduce a security vulnerability, but it doesn’t really help with outright malicious extensions. In the end this isn’t an issue which can be solved by technical
3.
▲
by
palant
2y ago
Note : I am the author of this article. That question is answered, in the last section of the article. And: yes, they are selling it, as they admit in the privacy policy.
4.
▲
by
palant
2y ago
As I said: “according to many credible witnesses, not all of them anonymous. Heck, some of it is even on video.”
5.
▲
by
palant
2y ago
What is there to be gained you ask? Well, there is currently a creep in a position of power at FSF who is actively making women and other people feel unwelcome, effectively pushing them out of the community. By removing him from this positi
6.
▲
by
palant
3y ago
As I said, one device is enough.
7.
▲
by
palant
3y ago
Note : I am the author of this article. They have at least one device with an unencrypted copy of their data, likely two or more. They only need this passphrase to set up sync. If they ever forget it, they reset sync, set a new passphrase
8.
▲
by
palant
3y ago
Note : I am the author of this article. Yes, they will probably ask Facebook then. Or check your web search history. There is more than one source for them to draw from. But you can shut down this huge source of your private information ea
9.
▲
by
palant
3y ago
Note : I am the author of this article. Firefox Sync encrypts all data on the client side before sending it. Chrome Sync can do the same if you know which settings to use. 1Password, Bitwarden, Dashlane – every password manager worth their
10.
▲
by
palant
3y ago
Funny thing is: declarative access to websites still allows for plenty of mischief if one wanted to do it. I’ve actually seen malicious extensions abuse that. Browsers might have to revisit the decision to ignore declarative access as far a
11.
▲
by
palant
3y ago
Note : I am the author of this article. Yes, they fixed this particular issue (and a few more), the article mentions it. But the update I published today explains why Chrome Sync is still very bad privacy-wise (as opposed to outright horri
12.
▲
by
palant
3y ago
Note : I am the author of this article. Every ad blocker gets full and complete access to all your data. It needs that kind of access in order to … tada … remove ads. It’s really simple: ads are on all websites, so an ad blocker needs ac
13.
▲
by
palant
3y ago
Note : I am the author of this article. They fixed this particular issue (and a few more), the article mentions it. But the update I published today explains why Chrome Sync is still very bad privacy-wise (as opposed to outright horrible w
14.
▲
by
palant
3y ago
Note : I’m the author of this article. I’m fairly certain that these users didn’t leave it at reviews. There is a “Report abuse” form which one can use and which was certainly used here. If only someone were actually looking at these submi
15.
▲
by
palant
3y ago
It wasn’t really intended. I originally looked at ad blockers since I know that most of them are shady, that’s how I immediately found the PCVARK ad blockers. I stumbled upon these extensions because I was trying to find more PCVARK softwar
16.
▲
by
palant
3y ago
Note : I am the author of this article. Yes, Chrome uses Safe Browsing to flag malicious extensions. But they seem to use it very sparingly for some reason.
17.
▲
by
palant
3y ago
Note : I am the author of this article. Yes, Mozilla doesn’t publish the source code. Back when I was reviewing add-ons there (a long time ago), I did compile the supplied source and compared it with the submitted one. It was sometimes awk
18.
▲
by
palant
3y ago
Note : I am the author of this article. I have no idea what it takes to get “featured” but having seen how pretty much any extension gets this tag, including plenty of malicious ones – it’s pretty meaningless.
19.
▲
by
palant
3y ago
Unfortunately, an extension in use is expected to behave very differently from one that was merely installed. That’s the crux with observing software in sandboxes in order to determine its behavior.
20.
▲
by
palant
3y ago
Note : I’m the author of this article. We aren’t talking about breaking out of the sandbox here, the extension sandbox stays intact. The problem is that this sandbox has plenty of privileges. And so Chrome attempts to restrict what code ru
21.
▲
by
palant
3y ago
As I said, outright malicious extensions will always find a way. I now discovered a newer variant of these extensions, this time using Manifest V3. And they still run arbitrary code: https://palant.info/2023/06/02&
22.
▲
by
palant
3y ago
Yes, much better to let 55 million users blame the browser for redirecting search queries, excessive ads, erratic behavior and data leaks. :-) Funny thing is: I can imagine Google being fine with everything on this list but the first point.
23.
▲
by
palant
3y ago
Back when I reviewed add-ons for Mozilla Add-ons, I did in fact verify that the source code produced the same build result as the extension submitted. Was tricky occasionally but usually worked well.
24.
▲
by
palant
3y ago
Note : I am the author of this article. Mozilla and Opera require source code to be uploaded along with the extension, there is some human component involved in the review there. My understanding is that the human review got considerably
25.
▲
by
palant
3y ago
Note : I am the author of this article. It’s easy: Google owns the browser, so they decide which websites are allowed to install extensions. And Google decided a while ago that the only way to ensure your safety is allowing only Chrome Web
26.
▲
by
palant
3y ago
Note : I am the author of this article. Well, Google has been introducing policy changes meant to restrict abuse of extension privileges for quite a while. It won’t help however as long as they don’t manage to enforce the policies effectiv
27.
▲
by
palant
3y ago
Note : I am the author of this article. Migration to Manifest V3 has been postponed, all these extensions (like most extensions in Chrome Web Store) are using Manifest V2. Note that the changes in Manifest V3 are meant to prevent security
28.
▲
by
palant
3y ago
Note : I am the author of this article. The Apple developer fee has little effect on malicious submissions, what it effectively does is preventing free (open source) software. You aren’t significantly safer, you are merely paying for softw
29.
▲
by
palant
4y ago
Note : I am the author of this article. Yes, nothing I wrote negates the need for other security precautions. Keeping around a software which is accessible from the internet while not installing any updates for it (the vulnerability in que
30.
▲
by
palant
4y ago
Neither are applications doing root CA installatin nonsense a fault of communication via a local web server. HTTPS isn’t required here, but they either have this hack in place for compatibility with decade old browsers – or they simply fail
More ›