Adobe angers Chrome users by bundling browser plugin with security update
arstechnica.com
arstechnica.com
> it's likely that the extension itself is harmless enough
That seems unlikely given Adobe's history of truly awful security flaws. It wasn't that long ago when they thought that it would be a good idea for their add-on to pre-render PDFs in RAM silently in the background, including executing any embedded code without any sandboxing. Combined with browsers' prefetching of urls in a page (so that it would load quicker in case you clicked it), this caused a number of rootkit and other malware infections - from links that people didn't even click in search results and URLs served up in advertising or in comments/forum posts.
The only permission needed by a PDF viewer should be 'display PDF document content'. It shouldn't need to read or change other data, manage downloads, or communicate with anything to display an e-book or document. If it does, it's probably not harmless.
Now I don't know that that is what they were using it for, whether they could have made a narrower permission request, and so on, but permissions are permissions because we want to permit them some of the time. I think it is counterproductive to dismiss requests before evaluating them. That's the kind of behavior that leads to kitchen-sink permission requests from the start (when users are most motivated to try something) because a developer doesn't trust that they'll get a reasonable targeted request tomorrow.
Another company collecting telemetry that you have to opt-out of. This needs to be illegal because often, by the time most people learn of the option, their information has already been snarfed.
Was slightly easier for Firefox (few entries in SQLite, iirc). However both browsers lock the data stored, so you had to force a restart as well.
It sucks, and nobody is happy with it, but at the end of the day it's the only thing that seems to be working.
It's terrifying. And while you could make a case for this "not being chrome's problem", the fact is that it's really hurting their user base, so they can't not do something about it.
The direction browsers are all taking is requiring them to be signed by the browser vendor, effectively making them gatekeepers (and you can't have a preference to disable it, because if you did you could just install a plugin by disabling the preference (i.e., edit the config file) and then install the plugin normally). That really sucks too, sadly.
Having said that, of course just because Sun may have started the practice doesn't mean Oracle gets a pass for merely continuing it.... unless there was some long, long terms sort of contractual things: which I highly doubt.
Do the right thing, and tell your family and friends to stay away from this malware.
They "suggest" by default to try out Macafee and Intel True Store (not sure about the name).
It was a Backchannel story about an "adtech" company in Philly: "The Perks Are Great. Just Don’t Ask Us What We Do."
Basically, a surprisingly large number of employees don't know or don't care about the ethics of what a small number of leaders in their company do. Others justify such actions to themselves in convoluted ways. Only a small number truly can't deal with it.
Oh and they're each the size of the original app.
Who signs off on this?
Can Google retaliate by removing their extension from the store?