WOT is selling your PII and browsing history
lifehacker.com
lifehacker.com
Also, WOT is not the only extension doing this, the company behind it has hundreds of other extensions and mobile apps that perform the same kind of data collection, capturing several percent of the entire Web traffic in total (in Germany alone, almost 3 million people were spied upon using this technique).
Browser vendors really need to change their attitude towards extensions, as they basically allow users to install malware/spyware in their browsers without performing any real certification / auditing. At the very least there should be a way for users to see a full audit log of the information that an extension sends to remote servers, as this is usually already enough to tell if the extension is sending more data than it should.
Also, anonymization should NEVER be done on the remote end, but always at the source, as there is no way to guarantee that it will happen otherwise (as WOT proves).
That's something I hear a lot in context of the WOT issue, but how should that work? There are thousands (maybe millions) of extensions with new versions all the time. I see only one way: Shut down extensions and only allow a few selected ones that get audited by the browsers.
However do we really want this?
> At the very least there should be a way for users to see a full audit log of the information that an extension sends to remote servers, as this is usually already enough to tell if the extension is sending more data than it should.
That helps experts analyze extensions, but it doesn't fix the problem of thousands of users installing some shady extension nobody looked at. WOT was even open source, yet nobody seemed to have bothered to look into it until recently.
Of course it's fine to argue that it's the users problem, but then I don't see why on one hand we're trying to harden browsers against all kinds of sophisticated attack vectors while at the same time giving malicious actors privileged access to all the users data via the App Store. And again, restricting the kind of access that an extension has to the users data would be a first step to amend the problem. Allowing users to report abuse in an effective way would be a second step. Being more strict with violators would be a third one, as today most extensions simply reapply for access after being deleted and often get included again (just wait and see, WOT will also make a reappearance).
Browser vendors have already increased restrictions on extensions to the point where it impedes the development and use of some security improving extensions. There may be some things that could be changed to improve transparency and end user control. But it is ultimately the end user's responsibility to determine what is and isn't appropriate for their use. Browser vendors don't have enough information to make that call.
> At the very least there should be a way for users to see a full audit log of the information that an extension sends to remote servers, as this is usually already enough to tell if the extension is sending more data than it should.
Which of the popular browser's don't have the ability to display network traffic? I've used the one in Chrome and the one in Firefox on multiple occasions.
Normally, the problem isn't detecting that an extension is sending data to a server. The problem is that people don't look for that and discover it. Or they discover it and tolerate it based on a hope that the data will never be misused. Cloudy judgement.
Please, name that company? Are you referring to "TOW Software" or some corporate overlord?
If you are using WOT in either Firefox or Chromium/Chrome you can just remove it without replacing it with anything. Both browsers cover that for you with Google's Safe Browsing[6][7].
[1]: https://addons.mozilla.org/en-Us/firefox/addon/wot-safe-brow...
[2]: https://chrome.google.com/webstore/detail/wot-web-of-trust-w...
[3]: http://techdows.com/2016/11/web-of-trust-add-on-removed.html (4/11/2016)
[4]: http://www.ghacks.net/2016/11/05/mozilla-and-google-remove-w... (5/11/2016)
[5]: https://www.reddit.com/r/news/comments/5bgnyr/weboftrust_rem... (6/11/2016)
> Reviewing our privacy policy to determine which changes need to be made in order to enhance and ensure that our users privacy rights are properly addressed.
'addressed' is not the same as 'respected'.
Come on people. You saved 9 characters in that post title.