OSX Chrome 55 Blocking non-store extensions without dev mode
github.com
github.com
This feels worse than simply pulling the extension from the Chrome Web Store. Google certainly isn't obligated to host this thing, but outright uninstalling it against my will seems like crossing a line.
There was a lot of hand-wringing when Chrome was released with automatic updates enabled by default, because it seemed reckless to grant Google the power to install (or uninstall) new software on our computers at their whim. Chickens might be roosting.
But every time I got to my grandmother's she has a thousand "default search ad engine this" and "ad injection improvement that" extensions that I need to remove. Those search engines have exactly the same homepage as google, to the colours, except the logo is square, not round. There is no way she can know.
It might just be they ran the numbers and my grandmother's not the only one.
I think maybe, just this once, reality should trump idealism. Let's keep a very close eye on them. But for now, "I'll allow it."
Ps: I know that "if there are unsigned extensions on your computer, you have bigger problems", but it's my grandmother. Security is a moving target, this is the step we take in Jan 2017. If it keeps her safe for a month, that's fine with me. We'll see how the malware adapts in Feb, and react accordingly.
But here if you have developer mode on they should never be allowed to do this. It's one thing to do it to a normal user (though if they really cared they would check to see if the extension was a normal non-spam extensions like this) but when a user as clicked that they are capable of understanding what extensions they have on then Google is in the wrong.
Sadly we are on HN are not the majority user of the products we love to discuss.
How would Chrome discern deliberately installed extensions from extensions the user has been tricked into installing?
You know. These adware "downloaders" that completely hose your browser unless you find the correc checkbox full of double negatives to check.
Then you're not talking about Chrome extensions and none of this applies.
One method to install an extension is the chrome web store.. the other methods are typically only used by developers (hence all the dev mode comments) and malware (hence all the "I can live with this" comments)
Given this fact, why would I want to use any Google product in the future or recommend Google to anyone? How can anyone trust Google Home or the Google self-driving car to not make similar compromises to usability and choice in the name of propping up Google's other business?
Edit: Nevermind, figured it out:
> As online advertising becomes ever more ubiquitous and unsanctioned, AdNauseam works to complete the cycle by automating Ad clicks universally and blindly on behalf of its users.
It doesn't just block ads, it also pretends to click them.
This is obviously very problematic for advertising networks which use a pay-per-click model, where sites are paid based on how many users click the ads. In fact, this behavior is very similar to a common type of fraud in the advertising world known as click fraud, which exploits the pay-per-click model to extract money from advertisers with "fake clicks" from bots.
Even though in this case it's being done not to defraud advertisers but to instead prevent ad networks from tracking what ads a user did click, I can see why Google might object.
because the world isn't black and white. i don't agree with every decision google makes, but i don't think there's a single company for which i agree with every decision.
i think its really a stretch to say that this single decision means that all google products are going to be terrible. google prioritizes its ad revenue over user experience sometimes. but if it still produces a product superior to its competitors, i'll choose that product. and if it produces an inferior one, i probably won't choose it.
explain how preventing non-Chrome Store extensions from being installed is a compromise on usability? If anything, usability is improved for most of the Chrome using population.
AdNauseum getting dropped from the Chrome store was the right move as it is a bot that commits click fraud. Advertisers pay good money for a targeted audience. If you don't want to see advertisement nor to be tracked, there are ways maintain privacy without being retaliatory.
Being optimistic, the conflict of interest over ad clicks may not be the only reason for this decision. Blindly and randomly following ad links seems like it would assist exploitation of browser vulnerabilities.
It's just like sending back business reply mail if you're not interested in the product. It's not fraud.
I can see a case for it being a bit like a DDOS attack. But I can't see a case for it being fraud.
1. The authors of the extension clearly intend to harm the ad industry. There's no expectation that anyone will look at any one fake ad click and say, "oh, that person's sick of ads... maybe we should change our strategy." There's no business-side interaction with fake clicks like there is with empty returned prepaid envelopes. The only impact anyone intends or expects from this extension is financial. The intent is to get advertisers to pay more for fewer sales.
2. This is automated, and by distributing an extension, automated on a (potentially) mass scale.
I hate ads and I'm the kind of person who would use that extension if I weren't already happy with ublock origin, regardless of whether it might be considered fraud. However, I think there's at least a passable argument that it could be. If the main reason for this removal is that Google views the extension as fraud, then banning the extension from the Chrome web store is fairly decent of Google compared to suing the developers.
Not at all, it is just trying to prevent tracking and profiling by obfuscating genuine clicks with noise. It is explicitly a reaction to ad firms ignoring do-not-track.
Financial disruption is the tool used by most forms of direct action[1]. The power imbalance between large businesses and the people affected by those businesses usually leads to problems being ignored for the sake of profit. When money is the metric that influences decisions, the only way to effect change is to disrupt the source of revenue.
Without going into fraud-or-not, this is the opposite of how it works. It responds to every single business "I'm interested in all your products". This potentially generates some costs for the business which sees a new interest on latest products and makes misguided related investments.
I'm even doing it on the phone, for the companies that keep calling me despite me telling them not to: I make them lose as much time and money as I can, by scheduling fake appointment with their salespeople
This is unwarranted wishful thinking. Clicking an ad doesn't necessarily imply interest.
> generates some costs
Yes. Hitting businesses in their profits is one of the only communication methods some businesses listen to.
I believe this is actually the only thing that a real honest click on the ad indicates. What else would it do?
> Hitting businesses in their profits
It's also illegal in other ways. Racketeering idea would potentially apply here - you're making the company pay to get rid of problem (meaningless clicks) which wouldn't exist if you didn't run the extension.
As I understand it, racketeering requires that a company is offering a (paid) solution to a problem they are responsible for - so it'd be racketeering if the makers of the extension sold a product to detect and filter out the fake clicks, for example.
The company that chose to display ads in the first place? Who is the root cause of the problem here, exactly?
If I "accidentally" visit my own website while I have this extension active it'll cause any adverts to be clicked and I'll earn money from them. Unless the plugin has a way to block the action on adverts that the browser user receives money from it's indistinguishable from deliberate click fraud - all Google knows is that the browser used a programmatic event instead of a user initiated click.
To that end I can see why Google might want to disabled it. I hope they'll also reach out to the developers to come up with a workable solution rather than just blocking it permanently though. Google have an opportunity to show they do actually care about privacy on the web here.
Though that obviously isn't sustainable when advertisers realise what's going on.
Is Chrome the user's agent, or is it Google's agent.
Either there is no law on the Internet - It seems be the reality of Internet being global and hardly enforceable - and in this case you do whatever you want and advertisers do whatever they want.
Or there is laws on the Internet, and advertisers are not respecting them. Privacy, damaging your devices via malware, not separation of contents vs. ads, EU laws being very protective, illegal targeting, etc. So, defending yourself against this is not fraud.
Serving me malware laden ads that ransom my PC, now that's criminal.
Scale and rapidity is the difference, in dollar terms, robo-clicking will cost them at least an order of magnitude more. I also don't think advertisers mind that you clicked on their ad in anger - as long as you saw it and it registered.
And they've been progressively making the developer mode harder to use as a backdoor for malicious extensions to install themselves, by only allowing them to run for the duration of the session. Firefox was actually the first to do this. And this is why the Extension is being 'removed' between sessions.
What is more interesting is why this particular extension was removed from the Chrome Web Store - It looks to be a fork of uBlock and lots of other Ad Blockers are still available in the store. So why is this particular one not allowed?
The only reason I know of that extensions have been removed from the store is if they violate the Single Purpose policy (https://developer.chrome.com/extensions/single_purpose) and normally only if they are doing something malicious (e.g. Claiming to be an extension that blocks ads, but actually also scraping data, injecting ads, or something like that). I know this extension is open source, but has anyone actually reviewed the code to make sure it isn't doing something malicious under the hood?
Edit: I looked at what AdNauseam does differently to normal Ad Blockers and I think where it is running afoul of the Single Purpose Policy is that it both blocks Ads AND clicks all the Ads. Now Google could be banning it from the store because it does 2 things and they should split those out into 2 separate extensions, or they are banning it because it is basically a means to commit Ad Fraud (fake clicks is a massive problem in the Ad industry). And blindly clicking every ad on a page doesn't seem like a safe thing to do personally...
I just visited the Chrome store and chose the first extension: https://chrome.google.com/webstore/detail/office-online/ndjp... It makes word documents AND spreadsheets?!
Hopefully you can see where I'm going... whatever's written in the policy is difficult to enforce literally. Someone has to make the distinction based upon the intent of that policy. A person has to draw the line. If Google have made the decision based on that policy, well that's their decision.
Reading https://developer.chrome.com/extensions/single_purpose (part 4) makes me thinking "disrupting ad networks" could be that single purpose. Then it'd cover blocking & clicking. Just like "Office Online"'s "edit office documents" covering both "word processing" and "spreadsheets".
There are loads of other Ad Blockers that do what this extension claims to do and they are all still available in the store - so all the conspiracy theories in this thread about google blocking it because it hurts their ad revenue seem bogus.
As I said, I've only seen extensions removed from the store that were doing something malicious - Something the person who installed the extension wouldn't reasonably expect it to be doing.
Google hurriedly announced Chrome when back in the days Microsoft was thinking of blocking ads.
Then they gave the user a never seen before simple to use User Experience/User Interface. Started marketing aggressively. Recently on iOS when using Gmail app and opening a link, it suggests me to install Google Chrome.
Google's game has always been user data.
> we are aware and preparing a statement and some workaround info to be released in a few hours (though, as you probably know, there is not much the average user can do in this case)
I guess, they are going to post it on HN too.
Anyway, thanks for the heads-up. AdNauseam is definitely an interesting extension.
There's still a (broken) link on the project's GitHub page: https://chrome.google.com/webstore/detail/adnauseam/hgfaciee....
Hopefully, this restriction doesn't exist in Chromium.
[1] https://developer.chrome.com/webstore/faq#faq-gen-29
[2] https://developer.chrome.com/webstore/faq#faq-listing-08
https://developer.mozilla.org/en-US/Add-ons/WebExtensions/Po...
I'm not entirely sure how I feel about that.
https://developer.mozilla.org/en-US/Add-ons/WebExtensions/Po...
But it doesn't make sense, why try and reduce the revenue of websites further than the personal non contribution of using an adblocker (which improves personal experience)
Do people really think websites will be able to run off donations, are people that naive?
Currently I believe that the people who don't mind dealing with ads are getting a better service, than the people paying for subscriptions directly.
I can't imagine it being that much of a problem in days of password managers and cookies...
"Currently I believe that the people who don't mind dealing with ads are getting a better service, than the people paying for subscriptions directly."
I subscribe to a bunch of newspapers (and I'm a 20-something tech guy), I don't really mind logging once when I'm on a new computer/phone/whatever, it's the same issue as google / facebook / twitter / ...
From the AdNauseam website:
> AdNauseam serves as a means of amplifying users' discontent with advertising networks that disregard privacy and facilitate bulk surveillance agendas.
> In light of the industry's failure to self-regulate or otherwise address the excesses of network tracking, AdNauseam allows individual users to take matters into their own hands, fighting back against unilateral surveillance.
AdNauseam's developers want to break the current Big data/surveillance-based advertising model. That is not the only possible model for advertising. Something like The Deck model, where there's no tracking or flashing jumping Punch the Monkey, just a static image link to the advertiser landing page, is a possibility.
FTA:
"Earlier this week, on Jan 1st 2017, we were informed by our users that Google had banned AdNauseam from its Chrome Web Store."
Chrome is uninstalling a manually-installed extension.
This situation is somewhat akin to OS X uninstalling Spotify.
Yes, Spotify and AdNauseum disrupt iTunes and Google, but I don't think it's a fair comparison because Spotify is a competitor (in that it provides music) whereas AdNauseum doesn't compete with any Google products, but just disrupts them.