I no longer trust The Great Suspender
dafoster.net
dafoster.net
On a daily basis, I will get requests to sell the extension. Once or twice a week, I will receive an offer to add "a couple lines of code" to my extension which are always generously described as "allowed in the Chrome Web Store" by little fly-by-night organizations that only even have a landing page half the time and usually have throwaway-looking gmail accounts. Out of curiosity, I've asked a few what their code does and they never fully describe it, but it either collects analytics to ship home (my extension runs on all sites, so it's appetizing to them!) or places paid results at the top of any search results, for which I can make "thousands of dollars a month based on the number of North American users I have".
Here is an example email I received yesterday. It's a good example of how they call it "an SDK" and looks like one of the more legit ones (they registered a domain to send email from, at least).
We at [redacted] are considering purchasing the complete license and ownership of the extensions which have 50K+ active users, may I know if you would be interested in selling? If so, - what is your estimated price?
Regarding the SDK monetization which we discussed earlier, as it is not distractive and is compatible with any other monetization. We have straightforward terms and provide support for your users agreement. Our partners generate 3-20 K USD monthly with our solution for the browser extensions.
As a kind reminder, we are [redacted] — a reputable global peer-to-peer ethical proxy network. All our clients are big reputable companies, we authorize their business before providing any proxy plans.
Look forward to your further feedback and discussing further details of our financial proposal for your Software in a short Zoom call or here by emails.
Finally, I am also hounded by teams at Microsoft and Apple, who want me to port the extension to their new plugin ecosystems so it can be featured/showcased. I worked with Apple on one similar thing for an extension and it caused such a huge jump in support and feature requests from users that I was overwhelmed, so I am not keen to do it again until I have more free time. They can't understand why I don't want to grow by tens of thousands of users a week, but I'm just one person and don't make money from it whatsoever.Trying to sandbox an extension that can modify arbitrary webpages in arbitrary ways is near futile.
There could also be hierarchies of extension permissions, because they don't all need to be able to do everything.
Just don't let them create script elements, or add any URLs that don't come from within the extension bundle itself. Browsers already have to do a ton of bookkeeping to track the origins of requests anyway. Doesn't seem hard, you just have to be thorough.
For example, you could patch some of the original script of the page and wait for it to be run.
https://chrome.google.com/webstore/detail/recipe-filter/ahlc...
The added benefit with AnyList is that you can import ingredients directly into your grocery list from the extension. Been a huge time saver for me
If you're not paying attention you can miss that it really needs 4 cups.
I normally abhor "social" features being tacked on when they aren't useful but I'd pay for all the apps over again for this feature. Thankfully the API is pretty straightforward. This repo of mine [0] is super dated but it was still working the last time I played with Paprika's API.
I've toyed around with setting up a little web app that my friends can log-in with their paprika creds (I know, I know, but I'd tell them to use a 1-off password for this) so that they can use the web app either push or pull recipes from each other.
Thankfully you can send the full paprikarecipe file via email and import it but it's a little clunky and things like Discord (which my friends use to chat) doesn't like file extensions over 12 characters (IIRC) so it just cuts off the rest of the extension characters leaving you with a file you can't open (without fixing the extension). I have some initial work to setup an AWS SES address that people can send recipes to that will then drop a preview and link to download (not an attachment, it would be hosted on S3) the recipe into a "recipes" Discord channel we use but it's still a WIP.
I thought that was the paid Cloud Sync feature was for. Does it not work for that?
My wife and I work around that by simply using the same paprika account for cloud sync...
Paprika is a huge time and sanity saver for me - it'd be totally possible, but much harder for me to cook for big events without it!
This isn't universal, of course. But not all payment comes in liquid form!
... said the venue owner to the musician.
It’s a frighteningly common invit^H^H^H^H^H^H exploitation providing free labour to owners of gathering places benefitting from that labour (like bars and browsers and operating systems and social networks, etc).
It's not an iron-clad given that the musician provides value to a venue.
Musicians who are confident they can bring business to a venue negotiate with confidence and get paid.
Those who play for free are ones who don't have that confidence.
What you accept is what you cost. That's the market rate.
How about this argument. Say I have a restaurant. Typically that means there is some landlord, and I pay them utilities and rent in exchange for using the space. Now some guitar-strumming, crooning ape wants to perform in the same space. If he and I are to be considered part of the same organization, we are on the same level of the "org chart". We are sharing the space and doing our thing. Why would I pay him anything? He should pay part of the rent and utilities. Or, why not the other way around?
Let's reverse it. Suppose a musician has a venue where he performs every night, and people come. Paying people. Suppose I want sell hot-dogs and sandwiches there, and he lets me do that. Why the fuck should he also pay me anything? He would be right to ask me to pay some sort of rent.
Now if I give the hot dogs and sandwiches for free, so that many more people come, and those people pay to get into this music venue, then there is a case that I'm increasing the business, and doing it out of my pocket. Still, that is my problem; I shouldn't be doing such a thing. Maybe I know what I'm doing! Or maybe I'm trying out new product to see how people like it or whatever (market research).
Because a music venue without musicians insn't
The "open mic" is on Tuesday nights, because nobody goes there then, so there is no harm to the business, and the people who come to have open mic fun might buy drinks.
If the bar had no drinks, it could hardly be called a bar. Similarly, a resturant with no food is hardly a resturant.
In that meantime, where the reason to go there is missing, these are all just rooms with the potential to be something later. The same goes for the music venue; it's just a big room that could be a music venue if there were actual musicians there.
But the implied flow of money doesn't follow from that.
Suppose I own an empty space with a little stage, a PA sound system, and some 100 chairs. I put a down payment on this place, paid for equipment and upgrades and have to pay property taxes, utilities and mortgage. If nothing happens there, I lose money out of my own pocket. I intend for it to be a music venue. I meet the definition of a music venue owner.
Some musicians have contacted me and would like to have a concert there.
Should anyone pay anyone? Who should pay whom?
How is this for logic: "A house isn't a home without a family! If you want me to move into this house with my wife and three kids to make it a home, you're gonna have to pay me!"
For many musicians it is not a career, but a hobby. A outlet for creativity. (That is me) In which case we choose venues that are like us. Our most recent gig was at our local Musicians Club https://youtu.be/URwzKL8pjQo?t=819
For others it is a important part of their income, so they should be paid.
Who should pay? If the punters pay a door charge the band should get it (that is the tradition here) if not then, yes, the owner of the venue pays it.
If the venue owner does the approaching (as in the context of the post raising this sub-thread) like Apple, Microsoft or Google approaching extension developers) it's questionable.
If the musician (or the extensions developer) approaches the venue owner, it's an entirely different story.
One has exploitation written all over it, the other not so much.
The context of the great-great-...-parent post suggests the exploitative version.
The situation being called out, is the very situation that flows from your hypothetical restaurant owner's contemptuous disregard for the "guitar-strumming, crooning ape".
The one thing that makes the context different is if the venue wants very specific musicians, and all of their choices are pros who expect to get paid. The venue can't get any of the musicians it wants without paying and that's that.
If a venue is not picky about musicians, it can easily get free ones. So many free ones that if three of them cancel, it can still call a fourth to come over.
I disagree that an alternative exists. Pay them for their time. They're enriching your business, or at the very least, providing you with their time and expertise.
> If a venue is not picky about musicians, it can easily get free ones
The way you talk about musicians (see also; you "ape" comment earlier) sounds like you don't value them as people.
What? Not necessarily at all. Say I have a bar that is completely dead on a Wednesday night, due to it being Wednesday night and it being in some off part of town.
I could advertise that I have some free jam space for musicians, a drum kit and a PA with a few microphones and maybe some guitar/bass amp or speaker cabinet. Maybe people will show up to make some noise. Those same people (and maybe a few of their friends) will buy a few drinks, and that's where the "enriching my business" part comes in.
Nobody is required to buy a drink, and so this is a better offer than them having to actually rent equipment and room.
Owners are allowed to do a lot of things that would be considered exploitative in an employment relationship: they can work excessive hours, below minimum wage, etc.. If they're a genuine owner getting their share of the upside, it's fair enough.
> Now if I give the hot dogs and sandwiches for free, so that many more people come, and those people pay to get into this music venue, then there is a case that I'm increasing the business, and doing it out of my pocket. Still, that is my problem; I shouldn't be doing such a thing. Maybe I know what I'm doing! Or maybe I'm trying out new product to see how people like it or whatever (market research).
You're not allowed to do form relationships that are indistinguishable from illegally-exploitative employment, for the same reason you're not allowed to run the shell game even if you do it 100% honestly. You'll find a lot of similar rules around charities that don't make sense on the surface, but are the only way to have a regulatory regime that protects people: you're not allowed to volunteer for or donate to the same organisation you work for, volunteers aren't allowed to be paid, volunteers can't do the exact same activities that they do for the charity but for a non-charity business...
So your analogy doesn't work.
This is what capitalism looks like, folks. Someone "built it" so they now privately "own it", no matter how big it gets. It's not put into the hands of an organization. The profit motive is quite strong, which is why someone can be "corrupted" by very tempting messages like this. If you had a lake or a forest privately owned by one or two people, and they had a lot of debts, they could easily sell it to polluters and loggers.
Some people scoff and say "socialism has been tried, it never works." I admit that socialism simply trades one class of elites (the capitalists with a lot of shares) for another (the bureaucrats with a lot of political clout). BUT! I would like to say that socialism is not the only alternative. The other alternative is decentralized systems with no private ownership. I'm talking about science, open source software, and so on. There can be a Merkle tree of version updates (e.g. git version control) and each one can have various reputable organizations (like Zagat for software) building their reputation vetting it. Then, each community would run their own app store (think Wordpress plugins) which would work with these reputable organizations. There would be no heroes, no celebrities, no tweets at 3 am to 5 million people, no pulling from repos without peer review, no scientists instantly believed after publishing on arxiv.org .
Congratulations for building a popular extension, fancy_pantser. You live in a world where you it's really bad to "criticize the profit", and where building it means you are responsible for it no matter how big it gets, but then we are all depending on your integrity and ability to rebuff life-changing amounts of money to not mine our data. We can pass laws to punish people after the fact, or we can gradually change our culture by rejecting "immediate gratification" of updates that are not vetted, just as corporations have done with bleeding edge vs stable Linux distros etc. Unfortunately, the Web has made it so that anything can be updated at any time, with no sysadmins or reviewers in the loop. It's a wonder more malware isn't silently everywhere already.
aka anarchy. that turns out to be worse.
The 'project' maintaining the software may be centralized, but all its users "own" the software in the sense that the don't need to ask permission to the maintainer, and they can create their own modifications.
You can have each individual community choose what OpenStreetMap tiles to use, what to censor etc.
Like HN does. What if HN was kicked off a host? They would put the backups somewhere else and repoint the DNS.
What if ICE seized their domain? Then we could move domain name resolution to a DHT.
What if AT&T refused to carry it or charge extra? The signal could route packets along other lines. No single point of failure.
It’s not just about banning 0% or 100% but the prices and friction imposed by privately owned rentseeking infrastructure monopolies. Why in a span of less than 10 years, VOIP has caused international calls that used to cost $3 a minute to turn free and have video!
The weird thing is that when A wants to connect woth B you think there has to be a one-size-fits all C that can block it.
No it is not!
Mackknovist Ukraine, Spanish Republic, and Zapitista country now...
All were/are quite different. Worse than what?
That’s why there will be a third party in the USA that unites disaffected progressives on the left with disaffected paleoconservatives on the right. A lot of people are fed up with the divisions.
I welcome counterpoints and debate but as you can see — there are just silent downvotes instead
Do you think people on HN want to engage with your comments when you're saying they're foolishly clinging to a religious belief?
By the way, this was a decent point: "[W]e are all depending on your integrity and ability to rebuff life-changing amounts of money to not mine our data." Maybe this thread would be different if you stayed with points like that instead of accusing people of harboring religious beliefs that pulls the wool over our eyes, preventing us from seeing things your way.
To be fair you inserted "foolishly clinging", and are now blaming them for something they did not actually say.'
Capitalism is highly akin to religion - they're not the first and will not be the last to draw that comparison, and plenty of words have already been written on the topic. If your response to reading "capitalism is a national religion" is to assume you're being insulted, perhaps consider that the statement may be more true than you think.
There is unlikely to be a third party in USA as the system is designed to have two parties.
There may be a third party that forces the Dems and GoP to unite, back to two...
It's a fair comment, but only if you actually read it.
Please don't use Hacker News for political or ideological battle. It tramples curiosity.
I am not accusing you of being that person, not anyone else. I am just tired of people not seeing that upholding the current situation is as political as criticizing it. This discussion made me try to put it in words.
The cost of using this extension is your information, and there are other products available that do the same thing at a lower cost. Based on the most fundamental concept of economics (supply and demand), "The Great Suspender" should fail as a product very quickly.
I feel like this is another prong in the story about threats to sustainability of open source done the way it used to/has been done previously.
It is. It’s very easy to generate big money with ad replacement or proxies.
During interview it became clear that their "product" was actually bundled malware that replaced google's and other ads in the browser. Evidently hot founder guy was using this startup as cash cow for his other ventures.
There was some noise in the press about it a couple years later and founder guy defended himself saying he sold the company and wasn't responsible, except it was already malware when I interviewed and he was still owner so I know it's bullshit.
This seems like a fairly benign monetization scheme, it’ll hurt some sites that depend on ad revenue but not any more than adblockers.
Monetization is the process of converting user value into money. If you don't provide any value it's not monetization it's just mining.
In my opinion extensions have to be one of the worst sources of spyware these days. I am now extremely conservative with what extensions I use, and definitely would only use extensions from open source projects or companies that I trust.
Something needs to change. As long as extensions have such weak sandboxing along with such poor app review, Google/Mozilla etc will keep willingly shipping spyware unbeknownst to their users.
At least some mechanism of creating and verifying reproducible builds would go a long way.
Paying $0.20 per user to buy that seems extremely low.
Also, on the sandboxing/app review of extensions, does anybody know how well Apple vets Safari extensions? (I guess that could be hard if the evil parts are time-triggered, certainly if the code also is obfuscated (possibly in the name of minification)
Ghostery anyone?
https://www.reddit.com/r/privacy/comments/59wiln/is_ghostery...
I completely agree. There are a number of features I would really like to use in Firefox that are available only as extensions and I continue to resist installing them.
In fact, the only extension I use is uBlock origin - which is based on a fairly rich social and community history behind that project and its author ...
And uBlock Origin is in that list.
We need to pull people together who have a passion for making the world's computers just work and build a brand around simple extensions and apps that are TRULY FREE. As in, they don't have features removed that you can only unlock through a paid version, they don't have ads, they don't sell tracking data, source is open, and anyone can support them through optional donations, but they don't nag you for anything.
Stallman distinguished between free as in freedom and free as in beer. I don't think he went far enough.
I'm more radical because we are users first, all of us, and only by using great software are we able to be makers.
And I think about my typical experiences as a user. Often, using a piece of software that was pretty great, then suddenly out of nowhere, a popup, it was a free trial and the full version costs some exhorbitant amount. Or the software that was suddenly bought out and shut down. Or the "five star" app that is already full of spam.
Then I contrast that with those programs that just don't ask for anything. You keep expecting it, but it's just genuinely something truly free that works. They weren't optimizing revenue, they were optimizing function. That feeling of finding that perfect FOSS or community developed app, it's just sublime.
Some user had a problem they wanted to solve, once they solved it, it was just a gift to the world, implicitly asking people at most to think about paying it forward.
We should make stuff that emulates our ideal experiences, not our worst experiences. We should spread that same kind of joy we've felt. If one in a thousand pays it forward, the options spread. The oak tree doesn't waste time trying to extract revenue from every squirrel, it knows one in a thousand will bury an acorn somewhere and build the forest.
And it's especially needed now. There was a time in the early internet where there was just abundant freeware on the internet. Postcardware, donationware, people genuinely trying to make an entire open source ecosystem.
Then we got app stores. "Curated," but not for that ultimate sublime user experience. Curated for sustainable profit back to the marketplace. Curated to make the biggest revenue earners find the exact bottom line of scumminess without getting banned, and encourage them to duplicate that model, then inspire copycats flooding the entire app ecosystem.
I know the rebuttal, devs need to get paid. Sure, I'm not an absolutist; this path isn't for everyone or every project. But I've worked with some people who make many of their contributions as free as possible, and they include some incredibly talented and hardworking folks who might be a little bit crazy. The thing that unites them all is that they're passionate about making the world a better place. They are lucky to have the freedom to do it, but it's still praiseworthy that they use that freedom for everyone, when it'd be easy not to bother.
I know there are free cycles in the system out there where people code out of a desire to help. Just need to have a unifying purpose, a call to action, that's how so many of the great movements like open source originally started. Just have to have 1% of people believe in it, then so many incredible things happen.
Absent any counterargument, I stand by the premise that app stores and extension marketplaces are teeming with junk, that curation has failed as a model.
It wasn't always like this. It doesn't have to be like this.
We just need to build something better.
Maybe the above path isn't the way. Ok, what do you think would be a better way to fix the current system?
Do they ask you to do that for free or is there a monetary amount they tack on?
First, respond to every inquiry by telling them the price is USD$70,000,000.00. And stick to that price. Many of these sleazy companies get their leads from the same "lead generators," who will eventually take you off their lists because they know your terms are unreasonable. It doesn't work for everyone, but when I did it to spammers trying to buy my mailing list, it significantly reduced the volume of inquiries.
Second, put a page on your web site listing all of the offending companies, with links to the letter you received.
Apr 1, 2021 - Company X promised $3-5k/month if I alter your search results. Link.
Apr 3, 2021 - Company Y promised $1-5k/month if I promote thier product on other people's web pages. Link.
A lot of people on HN will claim "O, noes! Lawyers! Libel!" I wouldn't worry about it. These people don't have the money for lawyers, are usually in geographies without legal systems, and don't want their names and other information exposed in a public legal filing. Plus, all you're doing is stating facts.
There's a W C Fields joke that ends, "Madame, we've already established what sort of woman you are, now we're just haggling over price."
If they actually do come up with $120,000,000 - will at that point nobody will be surprised that you cashed out. They might be mad, but they won't blame you.
"It'd take more than 10-SWE-years to build a clone, so we should take his offer"?
Similar to why Disney paid billions for Star Wars: the company was easily capable of replicating the product; the issue was replicating the brand. That brand has a proven track record of multi-generational appeal.
These creative endeavours have a soul, or an essence, for want of a better term. You can replicate a game or a movie and it will feel utterly soulless compared to the original, even if you can't visibly notice a difference.
You could reproduce Minecraft but even the most infinitesimal divergence from the original will make it feel fake. Maybe the controls have a different 'feel', or the way the scene is rendered feels a bit off. It's just not Minecraft any more. There are just so many quirks and details that will be lost in the translation, or even patched over if they're seen as bugs.
It's no different if you ported a game from Unity to Unreal and then to CryEngine. I'm sure that with a blind comparison you would be able to 'feel' the difference.
And the same for films. The way these things were created has a lot of influence over the end result.
On the other hand, it's exactly what can make a remake or remaster so successful. The Resident Evil 2 and 3 remakes that followed Resi 7 were phenomenal! Not totally faithful to the originals, didn't try to be...they just took an older game and gave it a new life.
People don't go to Starbucks because it's the best, they go to Starbucks because mocha frappucinos in Lima and London taste exactly the same. Any divergence, even an infinitesimal one, makes the frap feel fake.
The secret ingredient isn't orange peel, it's $4 billion a year in marketing.
https://www.businessinsider.com/what-happened-to-the-cocaine...
According to Business Insider, the beverage company has a deal with the Drug Enforcement Administration to get coca leaves so that the world can get its Coca-Cola fix. The DEA lets Coca-Cola import coca leaves from Peru and Bolivia in order to get the part of its secret recipe, which it hides behind the term "natural flavors" on the ingredients list.
I mean how many kids do you see walking around in "Cube World" T-shirts? CastleMiner? FortressCraft? Take your pick: https://www.reddit.com/r/Minecraft/comments/lx5g3/complete_l...
The looks on people's faces are incredible.
People still blamed me.
Libel is for false statements. If you've got a real email from the company then it's not false.
There are differences: in the USA the statement is assumed true, and must be proved false if libel is to succeed. In the UK the statement is presumed to be false, and the libel will succeed unless proved true.
I wonder what the GDPR has to say about publishing a private email?
I imagine either party in an email conversation have the right to publish the email, unless some terms were agreed in advance or the subject is expressly personal.
Say, $5 per active user; non-exclusive license: I can maintain my fork of the extension, and use any of the code in new projects.
Aww man, I'm really sad to here that RecipeFilter won't be coming to Safari anytime soon. I really got my hopes up after it was in the keynote!
Since Apple distributes extensions in the App Store, have you though about charging a buck or two for the Safari version? I know everyone says this, but I'd pay...
Once you burn your reputation by "selling out" the first time. Who will trust your new forked version?
Rhetorical questions: Do you want to support this thing? How much time does it take? Is this effort you want to spend? Are you not monetising this for a purpose? Are you happy with that purpose (obviously yes)? Do you still enjoy spending time on it? Do you see that time as well spent? Are the expectations from your side still being met? Are the expectations from everyone else still reasonable?
After all those questions, the basic answer is probably: you don't want to monetise it because it will wreck the actual purpose for which its intended or alternatively there isn't much of monetisation possibility due to its nature. But you can't spend more time on it because you have other Things to Do, like making money from other ways.
(At least this is my impression based on my experience)
Eventually the photo hosting service itself solved the problem that my extension was solving, but pretty much everyone who'd installed the extension still had it installed.
At some point, a company offered to buy it from me for a couple thousand dollars -- I was 18, and it seemed like a miracle! They asked me to add some code to the extension, and I assumed their intentions were good. I added their code, which I now realize was some sort of tracking/advertising program...and my extension promptly got taken down by Google.
Quite the learning experience!
There's a sensible middle ground here. Take the paternalistic approach that (generally) protects people like my mum. Add settings that allow people like you and me to turn off updates or roll backwards. Push the people controlling the updates (like the Chrome store) to better protect their users.
I don’t like automatic updates and generally keep them disabled. Software upgrades tend to reduce functionality and instead force unnecessary UX redesigns on users, so I’d rather avoid them. I wish developers had the [EDIT: incentive] to release security patches independently from functionality changes, but few do that anymore, sadly.
You do realize it's not competence developers are lacking, it's resources that are finite, do you?
So off to analytics they would go. "X thousand users are using IE8. We're converting at X%. Removing support for IE8 just means these people will shop elsewhere and we'll lose X thousand pounds a month. You need to support IE8."
Believe me, I wish it was as simple as saying developers are "part of the problem," because it would be an easy fix. But try selling that (without a huuuuge struggle!) to the person who holds the purse strings.
Sadly the new features usually only came on new sites. It's much easier to push it through when you're not cutting off an existing income stream.
The failure is not that of Internet Explorer, but rather the OS in which it runs, which has a faulty security model. No operating system should trust executables with everything by default.
We all seem to forget that computing has changed drastically in the last decade.
That said, in that era it was often assumed (more so than now) that software the user installed himself is trusted.
If you make something available for people to toggle that improves their experience, people are going to take advantage of that even if they don't really grasp or decide to ignore the consequences. In the case of updates the improved experience is not being nagged or forced to restart an application or the whole OS. And unfortunately the only way to really gatekeep that control to people who know what they're doing is giving it enterprise pricing.
This is an assertion which begs many questions.
Who are these users? What do you mean by "generally"? What do you mean by "poor"? What do you mean with "managing software"? Which software specifically? Why is "managing software" hard? What are specific case where this might be true? Is this statement falsifiable?
For instance, how does age, social background, education level, language, culture,... factor into the experience of "managing software"? Sure, the problem can't be software itself in it's entirety?
See, statements like these tend to break down once you start digging into the murky nuances and specificities of reality.
Moreover, accepting them at face value tends to reinforce a belief which isn't based on fact: that the users of digital technology can't manage their devices, and therefore shouldn't be confronted with managing their devices.
... which is then translated and implemented in interfaces and systems that simply lack the functionality that gives users fine grained control over what is or isn't installed.
Over a longer term, this promotes a form of "lazy thinking" in which users simply don't question what happens under the hood of their devices. Sure, people are aware of the many issues concerning privacy, personal data, security and so on. But ask them how they could make a meaningful change, and the answers will be limited to what's possible within the limitations of what the device offers.
A great example of this would be people using a post-it to cover the camera in the laptop bezel.
People don't know what happens inside their machine, they don't trust what happens on their machine, and there's no meaningful possibility to look under the hood and come to a proper understanding... so they revert to the next sensible thing they have: taping a post-it over the lens.
The post-it doesn't solve the underlying issue - a lack of understanding which was cultivated - but it does solve a particular symptom: the inability to control what that camera does.
Demographics don't change the fact that if you don't automatically update software, many users simply won't. That's bad.
The internet is global, sometimes I think things get lost in translation.
I'm challenging your initial assertion that "people are poor at managing software". That's not enough of an explanation to support the second part of your claim:
> and as long as it works they'll happily and probably ignorantly run something that is not secure already and needs an update.
Are they poor at managing software because they are ignorantly running insecure software? Or are they ignorantly running insecure software because they are poor at managing software?
The replies so far take the entire context out of the picture and reframes the issue to "Users use their devices the 'wrong way'." and this can only be solved through technological advances.
I'm here questioning and challenging those assertions.
The collective Internet has been through this before and (mostly) learned its lesson. People don't run updates when it's not shoved down their throat. And it's not a small segment of people. And it hasn't changed. Look at how many hacks still happen because of servers and apps that aren't patched for known vulnerabilities. Or the prevalence of cryptojacking which is still largely based on known vulnerabilities that already have patches available - indicating it's successful enough that people keep doing it.
Most users don't question what happens under the hood of their devices because they don't care. They have other things to care about that actually mean something to them besides the nuances of the day to day maintenance of their devices. There does not exist an effective way of making people care about things like this, let alone educating the masses on how to appropriately choose which commit hash of their favorite browser extension they should really be on. How many security newsletters do you really expect the average person to be subscribed to in order to make informed decisions about these things?
Hell my "Update" notification on Chrome is red this morning and I'm at least in the top 10% of security-conscious folks in the world (it's really not a high bar).
I'm not saying automatic updates are without their problems - I'm in a thread on HN about that exact thing. But trying to claim it's somehow about sociodemographic issues and the answer is solving that and going back to selectively running updates is just ignoring the lessons of the past.
Users are "I, and everyone else I know".
Generally is "unless we need a feature".
Poor is "do not install updates to our software".
Managing software is "install updates".
Software is any software we use that provides updates, which is all of it.
Managing software is hard because doing it manually would require checking the website of every piece of software you've ever downloaded at regular intervals, where regular could be as frequently as minutes for security-critical tools.
If I ever downgrade my software and lock it to a specific version, I am now managing it manually, and all of the above applies.
I honestly don't think there are unquestioned assumptions here, because the task of keeping security-critical software up to date manually is nearly impossible for any user.
Vetting could be better with a lot of companies as well; remember not so long ago when Windows Defender decided a critical system file was malware and broke a ton of systems?
Verification. Vetting. Gradual release. Automatically disable extensions if they changed ownership, or if there's suspicious activity on the account of the owner (e.g. new login in another country).
And they need to take a MUCH harder stance on malware. Right now they're not even acknowledging there's a problem, let alone acting on it.
"Google will withhold $1 per user of your ad revenue forever. If your extension is found to contain malware, you forfeit all the $1's. Decisions on malware'y ness shall be made by XYZ malware researchers."
Allow a developer to get back their $1 when a user uninstalls the extension, or the developer stops making the extension. Also give the developer a certificate anytime showing how many $1's you hold of theirs (they could use that to get a loan from someone willing to trust them not to distribute malware).
Or not use chrome
Download and unpacking from github is a pita, I'd need to do this to each of my computers seperately
Switch to Chromium and use a package manager to stay up to date. Don't freeze updates, especially on your browser.
Security is often in tension with convenience/usability (as in this case).
Concretely: I don't update to the latest MacOS day of release. I do update after a few weeks of "no significant issues reported" (or I'll update manually faster if I learn of a serious exploit). I still haven't updated to BigSur as some of the software that I rely on doesn't work on BigSur yet, so I'm on the latest patch of Catalina.
But I install MacOS patch releases as soon as they are offered. It has never caused me a problem I am aware of, and I don't want to miss out on security patches, or even just bugfixes and perf improvements.
Heck, I actually just upgraded a MacBook that was still on 10.12, which was EOL'd. But I upgraded it because it was EOL'd, and wasn't getting patch releases for security fixes, and I want those patch releases as soon as they are released!
I don't know what x.0 software updates you're talking about (Chrome or Mac), but my comment never mentioned any. You don't seem to know that browser vendors don't really do those like OS vendors do. Either way, you can still avoid those while gettong security updates.
In my memory, there hasn't been a breaking auto-update in Chrome in years, but there have been hundreds of 0-days. The numbers don't really work out for the tradeoff you claim to be making.
I prefer automatic updates that are presented to the user for action, sadly feature update/release notes are often hidden or content-free (cf. Google's apps' updates on the Play Store) and downgrading path varies heavily with OS (easy on Linux, impossible on iOS).
Many users are going to change configuration because some tutorial on the internet somewhere tells them to do it, without totally understanding what they are doing, and are unlikely to revisit this configuration again ever. (Heck, I have done that with some configurations I don't totally understand, and don't even remember what I did and will never revisit to change back).
But it might be a fine way to do it.
But in analysis there is a shift from "can we blame someone else [users who ignored our advice] if the ecosystem ends up very insecure", to "how do we actually keep the ecosystem secure, not just have someone to blame when it isn't?" Doing the latter while also providing for user flexibility and autonomy can be a challenge for sure.
I have plenty of things I want to complain about when it comes to Google's user-adversity but mandatory automatic updates is definitely not one of them.
If you're a technical user and really know (or really think that you know) what you're doing there are ways to effectively freeze a given version of an extension.
- Auto Refresh Premium, static.trckljanalytic.com
- Stream Video Downloader, static.trckpath.com
- Custom Feed for Facebook, api.trackized.com
- Notifications for Instagram, pc.findanalytic.com
- Flash Video Downloader, static.trackivation.com
- Ratings Preview for YouTube, cdn.webtraanalytica.com
Copied from https://github.com/greatsuspender/thegreatsuspender/issues/1...
Another loser in this whole game is the honest hobby extension developers, who have to deal with the power-users who might promote their extensions not wanting to bother for fear of not being able to keep a watch for potential malicious updates for all of them.
Chrome has features to dissuade users from installing extensions from outside the Chrome Web Store. If you load an unpacked extension, Chrome will issue an ominous warning (something like “this extension is untrusted, click here to uninstall”) on every launch.
One could argue this is for security, but this change was implemented around the same time that Google disabled the ability to self-host extensions that install into Chrome. Really this is a mechanism to shut out independent extension developers from any potential plausible third-party distribution method that doesn’t rely on the Chrome Web Store (which Google controls and aggressively moderates.)
Use Firefox.
Firefox has similar restrictions... you have to side load through Developer Options. If you’re not a developer, you will be questioning why you’re doing this and the less-technically inclined will simply never do it (like my wife)
And it is not entirely nefarious as you suggest. It limits the damage that sideloaded extensions did roughly 2010 and earlier. The WebExtension API was another assault on extensions. These days, chrome and Firefox have essentially closed a huge attack vector even though extensions are a shadow of their former selves. I was a skeptic for a long time (why should power users pay for the faults of everyone else?) but no more. Kudos.
Availability is part of security, and the most secure system is disconnected from the internet and powered off. Why are we cheering our software becoming less useful in the name of safety? The switch to WebExtensions was a monstrous loss of functionality!
Firefox also permits self-hosting extensions signed through their store, providing more freedom for extension developers.
I'm not sure what screen "Developer Options" is referring to, but you can load add-ons directly from your hard drive with no fuss from the Add-ons page (though you must be running the Nightly or Developer version of Firefox). Click the gear icon right above your list of installed add-ons (this is also the menu that lets you disable auto-updates).
That's hardly what "Use Firefox" implied.
As for the developer edition, it's literally the version that they expect web developers to use; it's not half-baked software by any means.
https://wiki.mozilla.org/Add-ons/Extension_Signing#Unbranded...
(I wrote most the extensions I installed for my own bespoke use, built locally as zip files and installed via "Install Add-on From File...", and I don't have a problem trusting myself.)
* Unless it was explicitly revoked (updates do not revoke the signature) or Mozilla broke something that affects everything.
Extensions these days go through a rigorous review process, and Google regularly shuts down / imposes arbitrary restrictions against extensions due to changing policies.
I understand the importance of strong moderation to protect users from malicious extensions, but I believe Google is using that as an excuse to further lock down their store, increasing barriers to entry and making it harder for developers to build software to extend the most popular browser in the world without Google's blessing.
You're right...it won't let me update it now without a lot of justifications on their privacy tab. However, it is still published. The status is "Status: Published - unlisted", so I can't search for it, but I can go direct to the store url for it.
Yet the large actors still publish malicious updates to extensions. ¯\_(ツ)_/¯
Fortunately for me, I can re-do my extension to use the JS postMessage api which won't require hardly any permissions, and thus, not much to review.
That's google's shtick. They do the same if you unlock bootloader on your android phone. Black nag screen with scary text on every reboot.
I've been sideloading vimium and thegreatsuspender for years and I haven't seen this message ever. Not on Mac nor Linux.
Quite similar to what happened to Nano Adblocker/Defender a few months ago.
It is really a shame that basic functionality like this isn't built into more browsers and we have to rely on extensions to fill the gaps just to keep memory usage under control for tab-a-holics like myself. :(
I still sometimes use extensions like Great Suspender to give more control over the process (e.g. to suspend more aggressively on RAM-constrained machines or where the user uses a lot of tabs).
Since this news came out I have switched to "Auto Tab Discard".
chrome://discards/ has some advanced options (in Chromium-based browsers).
Funnily enough, Google mentions The Great Suspender as inspiration for this feature in the August 2015 changelog: https://developers.google.com/web/updates/2015/09/tab-discar...
> We actually had a great chat with the author of the Great Suspender extension while developing tab discarding and they're glad to see us natively tackling this problem in ways that are more efficient than an extension might be able to, such as losing the state of your user inactions.
The way I see it, extension developers get to come up with innovative new features first, and then the first-party vendors like Apple, Google, and Microsoft take note and eventually do just that: Integrate it into their own products.
For example: The Great Suspender → Sleeping Tabs [experimental] (Microsoft/Edge); Flux → Night Shift (Apple/iOS); Growl → macOS Notifications (Apple/macOS); Swype → iOS Built-in Keyboard (Apple/iOS); etc
Edit: Fix formatting.
Edit: OneTab[2] is also pretty good when you have lots of tabs open for research or work.
[0] https://github.com/greatsuspender/thegreatsuspender/issues/1...
Sharing bookmarks, is not the same as "sharing it with anyone in the world" - without any notification.
I used to use TGS excessively and TabsOutliner has completely changed my workflow. Now I just sort tabs into categories and then kill the entire window until I am in that context.
It sorta looks dated, but I find it amazing:
https://chrome.google.com/webstore/detail/tabs-outliner/eggk...
For dev tools and such, I set a whitelist of the sites they're allowed to run on, using that same extension details page. There's no need for your JSON formatter etc. to run on every single page you visit. Also speeds up browsing.
Now that I write that, I'm not sure how permissions and upgrades go together. If an extension that had tight permissions relaxes them I'd get notified before they took effect, right?
> Pray that the shady developer doesn’t issue a malicious update to The Great Suspender later. (There’s no sensible way to disable updates of an individual extension.)
Does Debian ship packages for individual browser extensions?
I mean, if they do I'm sure it's not scalable and-- after spending time reading debuild manual-- a giant, archaic pain in the ass.
On the other hand, all these app delivery systems are so damned pernicious and require constant vigilance. We may have arrived at a moment in time where this is actually a difficult decision:
* pay somebody a living wage to burrow down into Debian's WoT bureaucracy and add at least a selection of this functionality without phoning home
* continue playing the most tedious game of whackamole with a whackamole game that mines all our data in order to learn how best to beat all users at whackamole
They do, for a couple of more notable ones (HTTPS Everywhere, uBlock Origin, Proxy Switcher, etc.) [0]
> I mean, if they do I'm sure it's not scalable and-- after spending time reading debuild manual-- a giant, archaic pain in the ass.
The biggest problem is to find a person to be a maintainer that is willing to keep up with the upstream development.
[0] https://packages.debian.org/search?keywords=webext-&searchon...
> The biggest problem is to find a person to be a maintainer that is willing to keep up with the upstream development.
That sounds like the kind of job someone does in return for money.
What are the odds of one dependency being taken over by a shady anonymous entity?
We have seen bad updates breaking the entire Javascript ecosystem, but they were not intentional.
All it takes to inject a bad dependency is a burned out developer willing to delegate his free project to someone else...
Upgrading manually regularly: Good idea.
Having a cronjob to do it automatically without user intervention: Bad idea.
Without automatic updates, you might be more inclined to put off a patch which turns out to be urgent. Or you might be more likely to lose track of which patches have been applied across your various systems.
So in practical terms, my experience is that vanishingly few people will behave differently than an auto-update system would behave, except in rare occasions like a malicious update making the headlines. We definitely need a solution for rejecting malicious updates, but I feel backing away from auto updates throws the baby out with the bathwater and would be a net-negative change for the industry and for users.
I don't envy Chrome leadership's decision or having that problem to solve.
So it's not that auto-update is flatly a bad idea, it's more that it's a trade-off that sometimes makes security issues almost evaporate, and sometimes makes them impossible to dodge.
While researching, I found many users reporting that forced updates of software installed by Snap caused many problems and I decided against using it; I was able to install Certbot via a good old-fashioned RPM from EPEL.
I also removed Snap from a different Ubuntu server which had recently been upgraded to 20.04 (I wasn't using LXD on that server so there was no need for it).
1. https://community.letsencrypt.org/t/how-to-install-certbot-w...
FWIW, I've been allowing Apt and Yum package managers to automatically update for about 8 years without any problems. The only manual OS updating I do is for a set of physical (non-virtual) servers that are operational 24/7.
Saw your article via HN.
As an easier permanent fix, just uninstall The Great Suspender and install Auto Tab Discard (https://add0n.com/tab-discard.html). It does the same thing.
It's available on:
Firefox - Auto Tab Discard – Get this Extension for Firefox (en-US)(https://addons.mozilla.org/en-US/firefox/addon/auto-tab-disc...)
Edge - Auto Tab Discard - Microsoft Edge Addons (https://microsoftedge.microsoft.com/addons/detail/auto-tab-d...)
or even if you're still using Chrome - Auto Tab Discard - Chrome Web Store (https://chrome.google.com/webstore/detail/auto-tab-discard/j...)
From the website it sounds like the favicon is changed. So the tab doesn’t go away it’s just on pause
Google: “ a discarded tab doesn't go anywhere. We kill it but it's still visible on the Chrome tab strip. If you navigate back to a tab that's been discarded, it'll reload when clicked. Form content, scroll position and so on are saved and restored the same way they would be during forward/backward tab navigation.”
In the future this will be updated to also use a serializer for discarded tabs.
Tab discarding is just a more efficient, native implementation of what Great Suspender aimed to do in the first place.
I'd much rather have a way to just stop all JS on a "suspended" tab so that FF doesn't burn 20% CPU on tabs that aren't even visible. (Yes I'm aware that JS timers, etc operate at reduced frequency for unfocused tabs. I'm talking about stopping them entirely.) Discarding may be more efficient for the browser but it's less efficient for me the user, so I don't use it.
Tab discarding does have the slight advantage that it remembers what you typed in on the page and where you were scrolled (but nonetheless still causes a reload).
What you are asking for regarding slowing the performance of background JS is something browsers already do: https://stackoverflow.com/questions/15871942/how-do-browsers...
Making that behaviour more aggressive seems like it is liable to cause significant problems to the user experience with minimal benefits. E.g. background media playback would likely be broken, notifications, etc. Whereas you could simply use bookmarks instead of open tabs to get the same effect (EDIT: actually tab discarding would already be better than that method as you note).
As I wrote:
>>(Yes I'm aware that JS timers, etc operate at reduced frequency for unfocused tabs. I'm talking about stopping them entirely.)
>Making that behaviour more aggressive seems like it is liable to cause significant problems to the user experience with minimal benefits. E.g. background media playback would likely be broken, notifications, etc.
I want none of those things from the "suspended" tabs.
>Whereas you could simply use bookmarks instead of open tabs to get the same effect
How? Do you mean I would load the bookmark into a new tab when I wanted to visit it? That not only has the same problem that I described for discarded tabs (have to wait for a page load), but is even worse because it loses all the context that discarded tabs do retain. Not to mention the annoyance of maintaining bookmarks for arbitrary tab groups that I just happen to have open.
It's by the same dev too but it uses Chrome's Native Tab Discarding feature and I found it way more efficient (at the time I started using it a few years ago - haven't compared recently).
[1] https://chrome.google.com/webstore/detail/the-great-discarde...
That's something that worries me, whenever I install a software with trusted privileges.
Software companies can sell their products -- and user base -- to other companies without notice.
And it can be even worse in the free software world: think about all the updates that happen when you type `apt-get|yum|brew|npm|pip update`. What are the odds of a single dependency being taken over by a shady anonymous entity?
It would be an interesting exercise to try and build an open source organisation around developing and publishing extensions in the open.
Unfortunately, I’m not sure that a reasonable UI for something like this would be feasible without everyone just being trained to click Approve. Some kind of review process could work but that’d put it back in needing Google to admit that they need to pay humans to operate a service.
Whether they are lowballing candidates with that offer, I can't say.
Actually it does appear that the owner was changed from "deanoemcke" to "thegreatsuspender" (the new mystery owner) on the Chrome Web Store page.
I agree that warning when updating an extension if the stated owner has changed would be valuable.
Edit: looks like it works in Chrome as well.
Package managers are nice for the lazy, but then we get stuff like this:
https://qz.com/646467/how-one-programmer-broke-the-internet-...
Actually you might be pulling a bunch of malicious updates in 2-3 modules deep in your dependency tree anytime.
As a society we should be moving away from a culture of “immediate” updates eg on Twitter etc. And go towards more “peer review” like in science. Otherwise we are putting responsibility on every individual to verify all sides of the story and get informed. They don’t and society gets more and more dicided. Imagine if a scientist tweeted at 3am and half their followers instantly believed them. Or if an open source contributor’s pull request was instantly accepted and pulled overnight by everyone. That’s why USA and other countries are now so divided politically. Individual responsibility of 100% of the downstream nodes is strange to outsource responsibility to.
I wrote about this back in 2012 predicting what would happen:
What happened to the notion of using stable, centralized package repositories like Debian’s or Red Hat’s in order to build one’s software? I did a lot of Free Software development in the early millennium, then was away from the scene for a few years, and when I came back this desire for convenience above all else really baffles me.
https://qbix.com/blog/2021/01/15/open-source-communities/
https://qbix.com/blog/2018/01/17/modern-security-practices-f...
I'm now framing the problem as "inauthentic speech".
> ...go towards more “peer review” like in science.
Ditto journalism and reporting.
This is a universal problem. The core solution remains the same.
Cite your sources
Show your work
Sign your name
WRT John Walker's screed, I really thought certificates and web of trust would have become the norm by now. Anything unsigned would be treated as gossip or worse. Certs could be revoked as needed.Further, every trusted digital relationship would start with a key exchange. Vs relying on username and password. eg Banks would issue me a Secure Enclave of some sort, like a USB fob.
I'd like to understand why this didn't happen. My best guess is "Worse is better" enabled predators and parasites. Which has been acceptable during the gold rush.
You’ve Changed: Detecting Malicious Browser Extensions through their Update Deltas
The review doesn't take much time. What I look for:
1. The manifest for what network endpoints the extension is allowed to call.
2. Any URL in the code that is external to the extension.
3. Any remote network function (fetch/XHR/links) and traceback to the call sites.
4. Whether there is any obfuscated code or not.
If anything found in those spots seems fishy / unclear, I don't install the extension.Takes a few minutes, but catches most of the threat vectors. Skimming the code also gives me a sense of what sort of developer is behind the extension. Some code clearly shows a developer cares about privacy and / or security, which unconsciously adds karma for that dev in my book.
Like others above, I don't use many extensions, but those I use I have to trust.
https://www.windowscentral.com/microsoft-edge-canary-can-put...
Are there any potential downsides to this? I was also curious how does loading this format avoid updates?
Workaround to reopen a page is just to cut'n'paste the original URL from a parameter at the end of the TGS URL.
I've been using large tab sessions ever since Opera 5 in the early 2000s. Back then I'd have 20-50 tabs or so. These days I have sessions of 500 active tabs and 500 suspended. It's great. I have full text tab search, and since my sessions last years, I know the general location of all important tabs. ALso, since I use a single process brower and NoScript, all those 500+ tabs take under <3 GB of ram.
It's matter of taste, but it's no new trend. Tabs, and tab users, have been around for 20 years now.
For example, last week I was shopping for a very specific, very expensive ceramic thrust bearing. I had 20+ pages open from 10+ suppliers and documentation sources. I needed those open all week while we decided on which one to buy. This was a minor background task, so I also had 60 other tabs open for my normal work flow.
Just because people use a tool differently than you doesn't make them wrong.
Back in the days of social bookmarks (like del.icio.us) pretty much everyone had a "toread" folder. The main problem is that you have to remember to delete them after reading them. That's not really a problem for good articles you remember reading, but the crap articles you don't remember, or quit reading are easy to forget to delete from the bookmarks. So, you end up reading the same crap articles several times. With a tab, you close the window and you're done. With bookmarks, you have to close the window, go through your bookmarks, find the one that was crap that you have already forgotten and delete it.
There's several other advantages to tabs too:
Like the fact that they're naturally organized by window based on the task you're doing.
You'll see them more often, and thus be reminded more often.
They save context, like forwards and back history, and information you may have typed in, or a UI you may have manipulated.
It's also the best way to browse image galleries: middle click everything into new tabs, navigate them with the keyboard, and close them as you go. Beats clunky JavaScript lightboxes.
I routinely research several related topics for a project, and I will need 10-30 tabs per topic open at once. Surprisingly, chrome manages to handle 100+ tabs on my system with out issue.
You should see my desktop
TLDR: A popular extension was quietly sold off to an unknown party that subsequently added tracking/analytics. Not specifically malware, but not trustworthy either.
Did I miss anything?
[0]: https://www.reddit.com/r/KyleTaylor/comments/jowlt2/open_sou...
Google never really cared about user privacy at all.