Popular Google Chrome extensions are constantly tracking you by default
labs.detectify.com
labs.detectify.com
As someone who writes a lot of chrome extensions, I find that annoying, not to mention a bit insulting. Please provide the complete list of bad behaving extensions instead of implying we're mostly writing extensions to lure users into a trap.
There are so many cool things you can do with chrome extensions, which are largely unexplored yet. Actually, it reminds me the state of javascript in the early 2000. It was not uncommon then too to say javascript developers were only in to write malwares and javascript should be avoided as much as possible. What would the web look like today if we listened to them?
Now, the state of chrome permissions is indeed very bad. It is very restrictive by essence (you wouldn't have that many restrictions writing a desktop app, and you could do way more harm), but it makes everything looks suspicious. Do you need to access something to build a feature? Now user, when installing the extension, will catalog all the bad things you could do with this permission.
Worst part is, the perimeter of permissions is often poorly delimited. Do you want user to be able to use an extension that enhance their experience on a website of their choice? You have to ask to be able to edit just any website. You often reach the "this extension can read all your browser history" state when you couldn't care less.
I would gladly pay google to review my extension code and mark it as trusted. The confusion between good and bad developers must stop.
This at least empowers the Chrome developers to attack a defined problem, and it gives chrome users a tangible, clearly defined set of in-the-wild attacks to point to when complaining about Chrome's extension permission shortcomings. It also is an amount of work that is achievable by a small team, where an exhaustive outing would probably require the resources of a large organization.
[1] Particularly since they seem to have found evidence that these tracking companies are actively reaching out to Chrome extension developers on the dl and offering them commissions.
There is a trust issue here, not sure why it hits chrome extensions harder (although, I'm pretty sure the whole permissions system made people turn paranoid). We will probably need some kind of trusted party audit system to get further.
Also, the list of extensions they have should be published, IMO, even (and especially) if developers are not aware about it. This should be treated as vulnerabilities and disclosed so there's a chance to take action on it.
https://www.reddit.com/r/firefox/comments/3pwcey/firefox_ext...
Oh so horrid, like HN for example? I know! I'm only here because I'm forced to, too.
A much better place.
Edit: uBlock Origin is the one that doesn't suck, uBlock is to be avoided.
[1] https://chrome.google.com/webstore/detail/imagus/immpkjjlgap...
I have been non-trusting of many Scripts for years now, call me paranoid, but if Facebook actually has the capability to just track you via Facebook Scripts that are executed on every site you have the option to Log in with Facebook or share via Facebook directly from the site, why would they not do it?
Google also tries to keep you logged by all means possible.
I block their Scripts, only temporarily allow if I need them, I don't keep cookies for longer than my current session except for Fastmail, I use VPN, have no DNS-Leak and WebRTC Detection turned off (last I checked you could not turn WebRTC Detection off in Chrome and the Extensions promising to do that were not working).
And that's also why I use Mozilla Firefox. Not because it's the technically better browser, but I have trust in Mozilla and their API just allows capabilities Chrome isn't capable of (that's why there is no NoScript in Chrome and no, there is no NoScript-Alternative in Chrome with the same features and capabilities, look it up).
Back when I used both Chrome and Firefox side by side, Firefox for example would turn off some Add-Ons/Extensions in Private Browsing Mode, while Chrome would not. I guess we all can grasp what most likely was the reason for it (Add-Ons/Extensions should not be able to obtain information from the user if in private browsing).
I am not saying that everyone should do it this way, I even recognize I am not the normal user and this is not for everyone, but complaining about Google because of Data Collection is like complaining about Facebook and the information they have about people while using it heavily and putting sensitive information up on it willingly. Get over it ;)
I can agree to some parts of what you said.
Think about Android Application Permissions for example, I am not sure whether or not you now can revoke permissions one by one on your own (think I read something about this), but for how long was this not possible?
One Example? I have been disabling what Apps get access to on my Blackberry for I don't know how long. Forbid Whatsapp to have Access to the Camera? No Problem, if I want to make a photo from within Whatsapp it then says something that it isn't capable of doing so, just how it should be.
How a Browser behaves in private Browsing also is a browser-side issue. Whether or not the API allows Extension developers to give users the functionality NoScript for example provides to its users it also a browser-side issue.
See for example here (you won't see Google spearheading this cause) http://techcrunch.com/2015/08/14/mozilla-makes-private-brows...
The distinction between "This concerns only the Extensions" and "this concerns only the browser itself" is not as clear and easy as you say it is, especially in this case.
Since Google is all about obtaining information and using it, I don't think they are to be trusted in developing a browser that is highly concerned with user's privacy. Everybody has to make their own decision.
Also about firefox from the comments in this discussion by zetafunction: zetafunction 5 hours ago:
From the article:
Are Firefox extensions any better?
To be honest, no.But Google certainly is a company solely built upon obtaining user information and using that information as efficient as possibly, that is their right, and it is my right to not approve of this, state my opinion, and use something else / block their services :)
So, imagine if you were an elite hacker and I have an extension that I made in Google Chrome that asked for users authentication keys and I stored that in a database. Then you figured out where my database is located. If your best friend uses my chrome extension, would you suggest to your best friend to use my chrome extension?
It's been possible to disable multiple webrtc routes since M42[1]. uBlock exposes this option as a checkbox in its main settings.
> And that's also why I use Mozilla Firefox. Not because it's the technically better browser, but I have trust in Mozilla and their API just allows capabilities Chrome isn't capable of (that's why there is no NoScript in Chrome and no, there is no NoScript-Alternative in Chrome with the same features and capabilities, look it up).
The only thing Chrome/Chromium cannot block are inline script tags[2]. Inline script tags should apparently be considered cosmetic filtering according to [2].
Other than the above exception you can pretty close to blocking everything you could in Firefox with uBlock[3]/uMatrix[4]. Unless you're referring to something else? With uMatrix you can get basically the same granularity that you can with NoScript just in a much nicer looking interface (which is available for Firefox now as well).
> Back when I used both Chrome and Firefox side by side, Firefox for example would turn off some Add-Ons/Extensions in Private Browsing Mode, while Chrome would not. I guess we all can grasp what most likely was the reason for it (Add-Ons/Extensions should not be able to obtain information from the user if in private browsing).
Chrome extensions will by default NOT be allowed in incognito mode. I don't know what you observed but you must have explicitly allowed this behavior.
[1] https://code.google.com/p/chromium/issues/detail?id=457629 [2] https://github.com/gorhill/uBlock/wiki/Inline-script-tag-fil... [3] https://github.com/gorhill/uBlock [4] https://github.com/gorhill/uMatrix
That isn't actually their business model. They make money from people paying for ads not information. I've got friends in marketing and they'd love Google to sell them say a list of email address of high net worth investors which Google probably knows but they won't do that. They will let you pay to run ads aimed at certain groups but that's a different thing.
There are at least two possible reasons why Google won't do that:
a) they're doing the right thing or b) they're not stupid enough to dis-intermediate themselves that way
I think it's mostly "b". Selling the addresses is one-time revenue, selling ads targeted at high net worth investors is an ongoing annuity stream.
a) Acceptance, Image
The fact that they don't sell is the reason why many don't mind it as much. "So their automatic algorithms look for some key words in my mail and searches to target ads, I get better ads, they get money for clicks, what's the problem?"
Selling it would be a whole different story
b) Once you sold out, what then?
I guess that selling to thousands of companies you loose control over your information. x-many Companies have lists of high net worth investors for product category y from us, how to guarantee this information does not get out? Will be given to other companies/people? Will it be correctly used? How can we guarantee those x-many companies are storing that information securely? I can think of all kinds of issues with that business model.
Previously I would search the apps name + some obvious terms like malware but those results are too spammy to be helpful now. Extensions are very useful, so I'd hope there'd be some reaction from Google on this.
See https://github.com/chrisaljoudi/uBlock/wiki/Behind-the-scene..., which is applicable to both uBlock and uBlock Origin.
This is no longer true for the Chromium version. There were changes in Chromium which now prevent extensions from being able to inspect/block network requests made by other extensions.
It's quite a popular and valuable extension for web developers, I hope someone can explain how it works.
I've already dumped chrome/Google because it tracks everything possible about you, especially when signed in.
Chrome is basically a stable release from Google of the Chromium Browser (which in itself is an Open Source Project), as such Chrome is more tightly integrated with Google Services, Chromium should be the better choice considering not wanting to be tracked.
I think some systems (*BSD, GNU/Linux distributions) even only have Chromium available through their package systems, others possibly both.
This type of behavior is going to cause people to disable js entirely.
In Chrome's permissions they can read your browsing history.
Please stop spreading FUD.
Adblock Plus is not mentioned in the blog post, has a privacy policy and is open source. If you're worried about how it handles your data you can have a look at the code for yourself.
https://adblockplus.org/en/privacy https://github.com/adblockplus/adblockpluschrome
2. Review the source code.
3. Visit chrome://extensions and enable developer mode.
4. Click "Load unpacked extension" and point to the folder containing the extension source code you've reviewed.
C.f. https://developer.chrome.com/extensions/getstarted#unpacked
So a handful of developers (and their employers) have my full browser history. What could possibly go wrong?
They can take your passwords, though. If you install an extension that "can access your data on all sites", I hope your trust is well-founded.
Otherwise, I have inspected many seemingly innocent extensions like JaSON and REST Console (both meant to run in own tabs, without need to read/modify data on sites I visit, but which nevertheless request for these permissions!). I quickly noted that many other extensions did request for these perms as well... So, for now, for the ones I can't uninstall, I'll just disable them, and only opt-in (maybe in incognito), when I need to use them.
But now I'm wondering whether Firefox extensions are generally safe.
Are Firefox extensions any better?
To be honest, no.
There's potentially a security framework that could mitigate this but it's not an easy problem given the incentives to work round it.