Amazon says browser extension Honey is a security risk, now that PayPal owns it
theverge.com
theverge.com
1. Disabling Amazon's deep integration into Ubuntu's desktop search, is a security risk.
2. Android tablets that are not Amazon Fire are security risks
3. The reall MongoDb, if self hosted or hosted by Mongo/Atlas is a security risk, now that AWS provides it's own managed version
4. Using the "one-click" patented workflow on any other site than Amazon, is a security risk
Maybe the timing is suspicious on Amazon's part, but it does seem like a useful PSA as worded.
Maybe /safer/ doesn't get us all the way to safe, though.
PayPal themselves are in some folks' threat models (they've mismanaged a few things over the years), though.
They've been audited by at least one security firm per the article, and their privacy policy https://www.joinhoney.com/privacy says "We do not sell your personal information. Ever."
Anyway they only have one permission on firefox and the usage for that permission Mozilla mentions is exactly what they do. https://support.mozilla.org/en-US/kb/permission-request-mess...
That said, even if it is the example use case for that lone Firefox permission, that's a hugely broad permission and I'd be hesitant with any extension that asked for it.
As for security audits and privacy policies, I'd be concerned if they didn't do their diligence on that front. It doesn't impact my paranoid skepticism of a startup one bad/dumb pivot away from changing their minds and injecting ads or selling personal data because their business model wasn't working. At least on that side of the equation, PayPal buying them does possibly increase some trust measures with the company as it should be less likely that PayPal would allow such a pivot. (Though PayPal themselves don't have a history of being the best stewards of their ancillary products, and healthy skepticism there abounds as well.)