Emails a browser extension developer gets from scammers
sponsor.ajay.app
sponsor.ajay.app
They're given so much power so quickly. Users agree to 'view and modify website data' not realizing that the app can now run arbitrary code on their gmail/banking/whatever accounts to report all information including passwords. For all the concern over application security, little is talked about here.
Browser extensions are also super important. They stand as the only tool for users to take back control over their experience from companies that are in the interest of manipulating them for profit whenever they can. They are uniquely our agents here.
Still, each extension is a potential huge vulnerability. It's tough to find a balance here.
I would say this is false. Browsers can run arbitrary code on your machine. Extensions can't even access local files. If we are just talking about site information like cookies I would agree.
https://chrome.google.com/webstore/detail/local-explorer-fil...
>HOW TO SET UP
>For security reason, Google has made a policy to not allow webpages to read-write local resource on hard drives. So we need an integration between the Chrome Extension and File System (Windows Explorer, Mac OS Finder) using an external software. To install both, just follow the simple steps described in http://www.vnprodev.com/browser-extensions/local-explorer-in...
On a different note, Chrome "apps" historically have had higher access that allowed some file access (I forget the details), but as far as I can remember extensions have not had any ever. Though since you can communicate between apps and extensions, it was possible to install both and work around it a bit. I'm not sure if that has changed since I last toyed around with this though (it has been a couple years at least).
Now the result is that to implement "backspace for back", your extension needs to be able to load arbitrary JS on every domain.
Those "real extension frameworks" had even more permissions, often to run arbitrary local code as the user.
the problem is that the hive mind has no clue, and downvotes like maniacs facts it doesn't like. here's a previously discussion of what means the read all extension permission https://news.ycombinator.com/item?id=21336246 with all the factual, sourced post downvoted and a chain of people with finger in their hears singing lalalala
_of course_ I rarely bring up the topic anymore; once enough people get burned they'll learn on their own anyway, I guess.
This resulted, among other things, in an almost universal degradation of performance and usability of Windows XP/Vista for ... our parents and grandparents, basically.
I now feel officially elderly, Cheers for that. Lol.
They should also add some monitoring regarding domains extensions talk to. Or even make developers add a description of outgoing requests from extensions somehow.
Which is slightly amusing because I must be getting enough traffic for them to want to find me.
(Well at least until the search engines get better at detecting gray? hat SEO)
However, it's a tragedy of the commons failure? (Is there any short word for that)
Just one link.
Peer-to-peer proxy doesn’t mean a botnet, at least not how I think most people think that to mean. Rather they are routing traffic through residential IPs for a number of customers. $25-45/1000 users sounds exactly within the margins of a VPN provider (they even mention hola.org in the 3rd email, which is $2.99/m per ‘premium’ user or free if you become a node in the network) and residential proxies are also commonly used for scraping and other IP-sensitive work, again within those margins.
I didn’t find the code sample to be obfuscated, it was actually quite clear. It establishes a web socket with a server and simply passes requests through an endpoint, I.e. literally just a proxy.
All that said, it’s definitely shady to put this in your extension without users knowing. But, if you need to monetize something free, and make at least a good effort to inform users or allow them to opt out, and we trust infatica doesn’t allow illegal use of its proxy network, then I don’t really see the problem.
There’s a real need for residential IPs, no market to give each user $.025 and I can’t really fault someone for making a business out of this.
Edit: I also find irony that the author labels datos.live a “scammer” when in fact they are a very legitimate business engaged in similar data collection to what Google already does. ...The same author who published an extension (in the Chrome Store) for YouTube
Google "residential proxies for sale" and follow the rabbit hole down...
But, there is a strict business need for these proxies. If you plan to fight giants, the first thing you need is their data. And you can’t get it without proxies.
Sure, that’s another subject for debate; whether scraping/crawling is ethical itself.
This is the same reason how websites claim to “comply” with the GDPR with a cookie consent prompt that only allows you to accept (and declining is hard/impossible).
On the business side, there’s a real need to be able to scrape say LinkedIn or Amazon, which necessitates rotating IPs to avoid getting blocked. The legal precedent currently incentivizes this sort of behavior between both parties.
Mentioned also, however, is that criminals can use the technology to advance fraud.
The real user/owner would get a captcha and be fine for most big sites.
*not sticking up for any of these companies, but I have required residential proxies in the past to scrape Google PLAs.
You are very far off the mark.
Because the ones who used one's residential IP as a proxy, accessed a very illegal website? And the the police visit the IP address?
https://nakedsecurity.sophos.com/2018/07/05/tor-linked-nonpr...
https://www.techdirt.com/articles/20160406/08211234116/law-e...
https://www.itnews.com.au/news/tor-exit-node-operator-raided...
https://www.lowendtalk.com/discussion/6283/raided-for-runnin...
https://community.torproject.org/relay/community-resources/e...
Nothing really prevents same thing happening when it's VPN service's exit node (except maybe the fact that people doing illegal things would usually choose tor over VPN provider (though more technical ones are likely using both)).
Try signing up for a luminati account, they do pretty good KYC. Besides, the prices are probably going to keep most criminals far away.
I don't think it would be an exaggeration to say that the number of "users" of extensions running these service that know that their computer is being used to make web requests on behalf of the highest bidder is 0. The number of Hoola users that know how it works is also probably below 10%.
https://media.discordapp.net/attachments/609441389423493128/...
Privacy Policy
The creator of "Twitter 'Likes' Hider" has zero interest in tracking you. Your privacy is sacrosanct. No data will be kept, tracked, transferred, sold, traded, nor even coveted in any respect, from now until the end of time.
From: victoria@monetization-providers.com
Subject: Monetise Your Chrome Extension
I came across your extension on the Google chrome store and wanted to reach out to you to offer a way to increase revenue earnings from your extension. We are providing our partners with Bing landers and feeds that pays really well on extensions for search. It can earn up to $800 a month per 5000 users, and it is a premium product by invitation only. If your extension does not have search this is not a problem with a simple update this can be added, furthermore it is completely acceptable by google chrome store.
If this is something you would be interested in, I would be glad to schedule a call to discuss this with you! Also if you are looking to sell your extension we can discuss this opportunity as we buy extensions.
Victoria Jude
Business Development Manager
The sending domain was registered yesterday.
90% are just bots and automated attacks
If s/he doesn't click unsubscribe, maybe they've been talking with the wrong address, so they could continue with trying to find another address to the developer?
If you're referring to deliverability of emails in the context of email spam filters then no. Having an unsubscribe option on repeated, unanswered solicitations would be helpful. The emails are not spam, and in the first email chain they are rather straightforward about their proposal and methods. I'm not sure what the scam actually is here.. people offering money for dev to scam users out of bandwidth? I do think it's noble of dev ignore the solicitation and provide exposure to this market however.
This is what capitalism looks like, folks. Someone "built it" so they now privately "own it", no matter how big it gets. It's not put into the hands of an organization. The profit motive is quite strong, which is why someone can be "corrupted" by very tempting messages like this. If you had a lake or a forest privately owned by one or two people, and they had a lot of debts, they could easily sell it to polluters and loggers.
Some people scoff and say "socialism has been tried, it never works." I admit that socialism simply trades one class of elites (the capitalists with a lot of shares) for another (the bureaucrats with a lot of political clout). BUT! I would like to say that socialism is not the only alternative. The other alternative is decentralized systems with no private ownership. I'm talking about science, open source software, and so on. There can be a Merkle tree of version updates (e.g. git version control) and each one can have various reputable organizations (like Zagat for software) building their reputation vetting it. Then, each community would run their own app store (think Wordpress plugins) which would work with these reputable organizations. There would be no heroes, no celebrities, no tweets at 3 am to 5 million people, no pulling from repos without peer review, no scientists instantly believed after publishing on arxiv.org . Congratulations for building a popular extension. You live in a world where you it's really bad to "criticize the profit", and where building it means you are responsible for it no matter how big it gets, but then we are all depending on your integrity and ability to rebuff life-changing amounts of money to not mine our data. We can pass laws to punish people after the fact, or we can gradually change our culture by rejecting "immediate gratification" of updates that are not vetted, just as corporations have done with bleeding edge vs stable Linux distros etc. Unfortunately, the Web has made it so that anything can be updated at any time, with no sysadmins or reviewers in the loop. It's a wonder more malware isn't silently everywhere already.
I'm not sure what you mean. There is a security check in place for Chrome extensions. Are you saying that it's inadequate or that it is security theater only? Because it sounds like you're implying that no security exists whatsoever.
https://security.stackexchange.com/questions/15259/worst-cas...
Some self-awareness would serve you.