Temptations of an open-source Chrome extension developer (2021)
github.com
github.com
I had a small side project extension, ~25,000 installs & free to use. I got enough inbound interest trying to "help me monetize" that I thought it would be worth cataloguing all the different unsavory avenues: https://mattfrisbie.substack.com/p/the-ugly-business-of-mone...
It's currently not economically possible to listen to user's conversations, transcribe them to text, and serve ads based on that. It would cost orders of magnitude more in processing power than you could get from the extra sales.
This might change in the future, of course
Google had (and has afaik) significant challenges implementing multiple wake-word detection for precisely this reason.
Transcribing a couple of words accurately on-device without a major performance penalty (so that it can be running in the background always) is just _barely_ coming out now.
Of course running it 24/7 in the background would ruin my battery, you would have to be smarter than that.
Anedoctally I belive Meta does something like that because I consistently get ads on Instagram about topics I talk with a friend on Whatsapp and sometimes that is done completely via audio messages. Though I might be wrong and leaked the topics in text messages among other possibilities.
I think it can be economically feasible. They can have a model optimized for their topics which can be orders of magnitude faster than general-purpose speech recognition. Low accuracy probably wouldn't be an issue as they are able to fine tune the user topics of interest via its interactions with the ads (e.g. click rate, time spent before scroll).
[1] How much more money will a $100B ad business make if they improved tracking accuracy by %1? It's some positive number, but significantly less than $1B.
It's picking up pennies in front of a steamroller. You'd have to be a truly desperate PM to consider it.
[1] Still all the legal risks of holding that data, but they are easier to mitigate.
Don’t get me wrong it’s shitty and gross. But they are different things.
I'm just glad we are not there yet.
> When music plays nearby, your phone compares a few seconds of music to its on-device library to try to recognize the song. This processing happens on your phone and is private to you.
https://support.google.com/pixelphone/answer/7535326?hl=en&s...
Imperceptible to human hearing, but readily picked up by a listening mic. In fact, there are static analysis tools for picking out apps that access such API's in FDroid, along with taking measures to feed said apps dummy data. At least for Android anyway.
30% on Android 13 is absolutely not believable, both from personal experiences and data collected.
Even some old games I paid for are gone from the Play Store too. Like, I paid for Puffle Launch and it's just plain gone from my library.
Edit: ahah, I was looking in the wrong spot! Its still in my "not installed" list, just not in my "family library". Either way, not compatible with any device I own.
I just found https://archive.org/details/PuffleLaunchAPK and https://archive.org/details/PuffleLaunchAmazonAPK (both point to each other), with a note that says that the latter generally works and the former crashes. I can verify this; on my (Android 8, 32-bit compatible) device the Play version crashes with:
08-10 14:55:03.864 25995 25995 E linker : ERROR: OOPS: 0 cannot map library 'libmono.so'. no vspace available.
08-10 14:55:03.864 25995 25995 D AndroidRuntime: Shutting down VM
...
08-10 14:55:03.865 25995 25995 E AndroidRuntime: FATAL EXCEPTION: main
08-10 14:55:03.865 25995 25995 E AndroidRuntime: Process: com.disney.PuffleLaunch, PID: 25995
08-10 14:55:03.865 25995 25995 E AndroidRuntime: java.lang.UnsatisfiedLinkError: Bad JNI version returned from JNI_OnLoad in "/data/app/com.disney.PuffleLaunch-rjdXjIyhGz7STdfxQ9xH2g==/lib/arm/libmono.so": 0
I'm always on the lookout for old interesting games, and maybe there are workarounds for the other titles in your library too. What's the list?One problem is that some games aren't just incompatible, but also were enshittified with ads and nonsense after I paid for them (before they were killed altogether).
Offhand, the ones I remember: a paid version of Angry Birds Space, Amazing Alex (Rovio's excellent take on The Incredible Machine), Swords and Soldiers (fortunately there's a Steam version of that), Noodlecake's "Wave Wave", Pool Break Pro, and some classic ports like Dead Space, Spy vs Spy, and Ur-Quan Master, but there are better non-mobile ways to play those games.
The word "just" doesn't belong in that sentence. The ad companies being able to know things about you without actually listening to you is even more scary.
Evil-Ad-Company Neo: "You're telling me I can know things about my customers by secretly listening to them?"
Evil-Ad-Company Morpheus: "No Neo, I'm telling you that with the right license agreements, data sharing partnerships, and algorithms, you wont need to secretly listen to them."
Advertising is evil.
- I use ad blockers for my browser on both mobile and PC
- pay for the ad free version of all of my streaming providers
- don’t use apps that have ads and don’t have a method to pay to get rid of them
Modern advertising is not just "showing a product to induce demand". Car adverts don't just highlight functionality, they use mass market analytics to play emotionally driven messaging and visuals so that you associate that feeling with the car ad.
Do you know what Bernays called what services he offered before the word got tarnished?
Propaganda.
It explores the power fear has to shape behavior.
and then bernays' nephew started netflix
Googling X is a voluntary act to search for X.
Speaking about X with a friend, while the phone sits in a bag nearby, has exactly zero connotations of wanting to search for X.
Sure, there are varying degrees of this evil, but IMO even the least-objectionable advertising out there still can't be called "good".
In my experience, the case where advertising gets you to buy something that ends up being materially useful, that you would not have bought (or found a substitute for) without that advertising, is the exception, not the rule.
Oh, and to address your specific example: if you search "best diapers", and get shown ads for diapers, that absolutely is evil, because some ad-presentation algorithm is pushing you toward whatever diapers will generate the most money for the ad network, likely not toward which diapers are best. Not to mention that "best" often means different things to different people, and the ad networks only care about that insofar it increases their profit.
I've heard somewhere that ads are rich people screaming "give me money".
(i know, i know, but i like it)
> To me, that's evil.
Bill Hicks on marketing: https://www.youtube.com/watch?v=tHEOGrkhDp0
That makes me think of this Paul Graham piece on "the PR industry, lurking like a huge, quiet submarine beneath the news." [0]
> If you really want to be a critical reader, it turns out you have to step back one step further, and ask not just whether the author is telling the truth, but why he's writing about this subject at all.
Followed quickly by being hopelessly naïve about the future:
> Whatever its flaws, the writing you find online is authentic. It's not mystery meat cooked up out of scraps of pitch letters and press releases, and pressed into molds of zippy journalese. It's people writing what they think.
Surprisingly though, for some reason I don’t find podcast ads to be as offensive.
People are spending money because they see that they are getting value from something. If people didn't want it or thought it was worthless they would not buy it.
Thinking something is "worthless" and not wanting something are opinions. A lot of modern advertising attempts to change peoples' opinions, so that they do want something, and think something has worth. It's just like propaganda, which actively attempts to sway peoples' opinions.
Of course, there's only so far you can take this. Convincing anyone who isn't seriously mentally impaired that a sandwich made with literal shit isn't worthless is probably not going to work. But away from the extreme end, there's a lot of room to manipulate people.
Target Sends Coupons to Pregnant Girl and Unawares Dad Explodes
https://www.workplaceethicsadvice.com/2012/02/target-sends-c...
> Pole had identified about 25 products that, when analyzed together, allowed him to assign each shopper a "pregnancy prediction" score. More important, he could also estimate her due date to within a small window, so Target could send coupons timed to very specific stages of her pregnancy.
And things just get worse from there, as companies figure out more and more ways they can extract information from the information they have about you, and share it with each other.
After that, we just wait. We know we have you. It’s just a matter of time till you need a product like ours (you’re already our target demo), or an impulse buy occurs.
Without evening knowing it. You’ve been manipulated into trusting our brand, and you’ll think it was all an organic choice.
Nothing malicious or dangerous here.. move along.
but what are you protecting yourself from? What's the threat model?
I like to think I'm immune (the only ad I've ever taken up was years ago for Privacy(.com), and only because I then knew about it later, and could choose to pursue it on my own), but I wouldn't be surprised if at some point before I started being allergic to every type of advertisement imaginable, some ads managed to get my attention for one reason or another. (maybe subliminal messaging's done something before, I dunno.)
I'm not too concerned about it since I know it's been kept to a minimum, so at this point basically everything I've done is something I actually wanted to do, there are no concerns about having been manipulated. But that's just because I've managed to avoid seeing targeted ads almost whatsoever.
Not whether it's something in the world that's ever been marketed at all, because literally everything has.
With prolific cases as Robodebt and the Toeslagen Affaire, we can only hope these automated scoring systems remain isolated from governmental overreach.[3][4]
[1]: https://themarkup.org/privacy/2023/06/08/from-heavy-purchase...
[2]: https://themarkup.org/privacy/2023/06/23/how-your-attention-...
[3]: https://en.m.wikipedia.org/wiki/Robodebt_scheme
[4]: https://en.m.wikipedia.org/wiki/Dutch_childcare_benefits_sca...
Then there is the fact that a large amount of data about me is being stored, possibly insecurely for people with even less scruples to analyse. I have very little to hide (white, middle class, straight, male, cis, no criminal activity beyond some unlicensed TV/film access, etc – there is little or nothing about me that would be frightening for anyone else to know) but there are many out there who do have things that could be (unfairly) held against them with terrible consequences. Consider women in Texas where there is effectively a reward/bounty program to encourage snitching on those who have had, or are considering, an abortion, or people in law enforcement who don't want certain groups to be able to derive their home address with any accuracy, people in one or more closets through fear of being ostracised from their family/community and left pennyless & without support, and so forth. I grew up with friends who were gay when it was still effectively illegal to be, despite what the Sexual Offences Act (1967) said, and when getting beaten up for being gay was almost acceptable (“act more straight, and it wouldn't have happened”: something a friend was once told by a policeman that saw no cause for arrest) – the fear of consequences from collected information “getting out” and/or being used to derive other information (true or otherwise) is real and for many people not at all irrational.
Back to my icky feelings, which are perhaps a little bit less rational: I wouldn't be happy with someone following me between shops, watching what I'm perusing, then to the pub and noting who I was there with, then back to my home, in order to be able to serve me relevant ads (perhaps for shoes that would be more comfortable for that much walking? or for condoms because they noticed I was accompanied by a female friend, and you never know, right, nudge nudge wink wink), and I'm not happy about the same happening in a more virtual environment. How do I trust that is really (or only) why I'm being followed? And I how do I know who else my stalker is selling news of my activity to?
[actually, the “I have little or nothing to fear” isn't entirely right – any of us could suffer from plain old identity theft in various ways]
This has been true for years to the extent that the nature of your purchases can tell a lot about you. https://www.forbes.com/sites/kashmirhill/2012/02/16/how-targ...
I just did a virtual visit with a doctor that used a video conferencing service that work without an app on iOS and just used Safari. I had to give the page explicit permission to use my microphone
I open them to get my increasing amount of cash.
That data must be valuable???
Someone else on HN called it "elegant" last week.
What a biased, myopic comment. As if ad companies are a grassroots movement against centralisation. As if ad tech is not in the hands of the powerful few tech companies.
They have defended ads in 2021 as well. I wonder where they work. I mean, somebody must be writing the backend for all these ad companies.
One is actively censored and you can go to jail for, the other isn't even on the legislative agenda. There are semi-understandable reasons, but it's far from entirely non-hypocritical.
- Do you trust your constituency to make up their own minds or not?
- Who are you trying to protect?
- From what?
- From whom?
And this is without even mentioning online advertising as a (seemingly increasing) vector of scams, frauds, malware and viruses.Now, add in psychological effects - "synchronicity", "frequency illusion" ("Baader-Meinhof"), "recency illusion", confirmation bias, etc... I'd expect a fair bit of compounding*.
Then, add in simple use of statistics, statistical inference, etc. and basic tracking of user navigation around the web, on a given website, etc.
I've had these experiences, perhaps one or two times a year, on average. Experiences where I was VERY surprised by ads presented. Experiences that would easily suggest a microphone must have been on when it shouldn't have been. Sometimes, I realized I'd used someone else's device in a way that could be tied to me. Other times, while some "leaps" would be involved, I could basically deduce myself that someone who had looked for information on some "X", and information on some "Y", might really be thinking about some "Z" that isn't easily arrived at from either X or Y in vacuo.
Spying, in the sense you suggest, can't be ruled out by the above. But, I would ask - why even spy? Is a company like "meta" really going to get much more useful (from their perspective) info by doing so? Particularly given the COST? It's becoming more realistic, arguably, but, really, these companies have had more than enough info on just about anyone for well over a decade to keep their algorithms and such well-occupied.
People gladly hand over tons of data constantly ... with full awareness and intentionality, and otherwise. The vast majority have no idea what statistical inference and other techniques can suggest based on seemingly obliquely connected info. Further, most users are so accustomed to "cookies" and other hidden types of tracking, and ignoring EULAs** ... really, it's hard for me to imagine a good case for doing anything more ... "invasive" and ... legally / otherwise dubious.
Edit: mostly came back to add one of my favorite (ab)uses of (statistical) inference:
(also, added the bit below about EULAs)
* Outweighing significantly, I'd suggest, other quirks of human perception, memory, etc. that may diminish awareness and recognition of potentially related events. I write "suggest" mainly because I don't have ready refs to offer this second and don't have time to dig a couple up ... IIRC, the research that exists strongly favors compounding, though, of course, this could be argued to be influenced itself by human psychology (including social and economic factors, e.g., "publish or perish" etc.).
** Jargon buried in legalese, what a genius way to get just about anyone to agree to just about anything! If only John, King of England (in 1215), had been more skilled in the ways of the EULA - perhaps "King Charles III" would be emperor of the world now. Oh utopia denied ... kek.
While that is a positive take that could explain it, I am not convinced by that number crunch. 2/situations per year, per person, that is still "a lot" to be considered plausible statistical coincidence.
You had the conversation with someone and that someone googled/shopped/amaozned/clicked it. Or did before already, you don’t initiate every conversation in your life after all.
Now go and try getting a denial that they are not using the fact that you share a wifi with someone as parts of the recipe for the recommendation cake.
And, it looks like that feature still exists: https://www.facebook.com/business/help/170456843145568
"Upload a list of emails to create a custom audience"
Seems easy enough.
It’s a really creepy feature though that can easily be abused.
> I'm a fan of [extension name] and I really like how convenient and useful it is.
> Have you considered offering promotional spots to those interested in promoting their products on your extension? I'm interested in promoting my own extension on [extension name] and would love to discuss this possibility with you.
> Let me know if you're open to this.
I have a website, I'm sure it's worth money to someone. If someone were to offer me $1000? Piss off, i've paid more than that in hosting costs in the 15 odd years I've run it. 10K? Sounds compelling, I'll have to think about it. $1M? Fuck all of my online friends, I'm taking the money and cutting contact.
It would be shit and I'd probably regret it, but it's a lot of money. But this kind of corruption is everywhere, and worst of all, it's permeated in politics. But subtly, in the form of campaign contributions, lavish parties and vacations, connections (i.e. lavish positions in company boards during or after a tenure in politics), never in the form of wads of cash passing hands.
I’ve been emailed several tempting cash offers from shady people who presumably want to steal everyone’s data or worse. I sometimes wish I had never put my name on it so I could just take the money without harming my reputation, but I did, so I’m stuck with being honourable. On the plus side I will always be able to say that I never sold out.
[0] https://chrome.google.com/webstore/detail/json-formatter/bcj...
[1] low effort tbh
Recently I’ve had a serious sounding offer to inject an ad, i.e. a one-off ad would open in a new tab when the extension updates, for $3K a pop, which I just ignored, then he emailed again saying $4K, then just yesterday he emailed again with a bunch of emoji and said what about $8K.
It’s tempting, but it would still be selling out my users, who may be ungrateful little brats but I could never do that to them, I value their approval too much.
The dev for uBlock origin must have received million and maybe tens of millions dollar offers, yet they refuse so much as token donations.
What is the ad for? If it is a US equivalent to Great Ormand Street Hospital or some other worthy thing, then why not! I suspect it isn't and you will be offered quite a lot more vapid dollars because your user demographic is ... nerdy and installs addons 8) That is worth a lot more than 0.4c per head.
It may be that the ad offers are not as unpleasant as we might make them out to be but you do need to live - up to you. However I suspect they are just as genuine as the crap that lands in my Inbox, sometimes.
I recommend not describing your users as brats - https://en.wikipedia.org/wiki/Gerald_Ratner
I've got a few set-and-forget extensions I haven't uploaded a new package for in 5+ years but I have periodically had to log in (per email warning) and check a new box e.g. assert I'm not collecting user data or pledge compliance with a new privacy directive.
Violation reference ID: Yellow Zinc
Violation:
Description provided is insufficient to understand the functionality of the item.
I filled in all the new mandatory fields and had chatgpt rewrite the description about 10 times in increasingly simple language but it was rejected every time with the same reason. Since it only had like 20 installs I gave up trying to get it republished.
I'm the founder of Streak where we directly monetize our extension (as do others like Grammarly). Have you tried directly asking your users for $ given the effort you put in?
Most FOSS android apps asking for donations do that: Sometimes a button in the donation-nag "I already donated", but pretty much every time a setting "stop asking, I either already donated or won’t donate".
In this view, trying to make money from it corrupts the noble mission.
Agreed, making money from charity doesn’t make sense.
Business revolves around secrecy and restrictions.
Whereas open-source revolves around transparency and freedoms…
Good thing nobody said that.
> The developer gets joy and gratitude,
Your average free software doesn't get very much joy and gratitude back from users either.
> they can live a happy life. Why bring money into it. Money does not make happy.
If the implication was too subtle, the idea is that when you spend a lot of time making something valuable, it should go towards obtaining food and shelter and the other benefits of a living wage.
And those things do make happy.
Money is an important type of value, especially the context of labor.
And, let me phrase this very precisely: there isn't an obvious non-monetary value they're getting back that comes close to the effort they put in.
You mentioned joy and gratitude but again I'm not sure how much of that they get back in this situation, plus there is the flip side of lots of complaints.
Some extensions are monetizable by honestly asking users to pay for access. Mine just isn’t. It’s only as popular as it is because it’s free and open source and promises total privacy.
why can't there be a method for making sure that such trust cannot be abused? Is this a tractable problem at all?
Which browser are you using?
Alas, the presence of this kind of reproducible build system would bring needed clarity to the chaotic ad blocker market, and the lack of that clarity works in Google's favor as an advertising company, so sadly I doubt they'd do such a thing.
Here you have to trust both developer's code and Google's build system. Can you verify all of the developer's codes? And can you verify how privacy-trustworthy Google's build system is? At the other side, you have to trust developer's code and developer's build.
I didn't mean which one you "should trust more" at all in my comment above. Please read again. What I mean is the first sentence here.
I will never do this because violating privacy goes against the core of my beliefs, but there is a conflict I can't seem to work out. On the one hand, I KNOW that the vast majority of users prefer to sell their privacy than pay a single penny. They would gladly click on a "sell my data" over a "pay money" button any day of the week. I know this because I have interacted with enough users to know these things. Many users will suffer a fit when things are not free but won't lose any sleep over giving away their personal details. Again, I speak of the majority and in general terms
On the other hand, I want the internet to be a place where unscroupulous actors don't flourish. Most people don't expect to get things for free in the real world, why should the internet be any different? Why does everyone (myself included) always look for free stuff on the internet?
The worst bit of it all is that in the end, the only people interested in spending money online are data thieves and advertisers. Everyone else is giving their soul. Developers are somehow expected to work for free so that this entire edifice can stand
In order for me to pay you, I at a minimum have to do some amount of mental gymnastics to convince myself that it's worth it for me to pay you. This has a perceived cost even if the money spent is trivial. This is why people who take money in small increments - i.e. mobile games, arcade operators, casinos, and so on[0] have you buy a large amount of some scrip that they control, and then make it so easy to spend it that you might accidentally do so.
Nobody is thinking "I'd buy this, but only if I can leave no record of ownership[1]", they're thinking, "is it actually worth buying". Identity and privacy isn't a thing that people actually account for when making purchases - mostly because it's never actually mentioned[2] in the terms of purchase. It's snuck in. So the choice is just "the free one" and "the $2 one", where the value of the $2 extension can never hope to overcome the mental transaction costs.
[0] Nintendo and Microsoft used to do this around the Wii and 360 eras. While on the Wii it was 1 point equals 1 penny/yen, Xbox did something nasty and made it 80 points equals 1 dollar.
[1] That would mean that setting up a new computer or browser profile loses you all your existing extensions that you paid for.
[2] I do not consider legal disclaimers to be adequate notice, and neither should you. Dropping a clause in a EULA is the equivalent of dropping rohypnol in your drink.
And also unlike cash a service can keep billing you.
And, for better or worse, the risk is partially put on the business in the form of increased cost (or payment service denial) when a credit card transaction is considered too risky (charge backs).
Also there is a fair amount of friction to giving payment info than say pulling out your wallet or phone (but this is improving with “digital wallets”).
You don't know that because no one is given a clear choice like you present (and even saying "data" is opaque to joe average user). And this is what regulations like EU's and CA's should be enforcing. Imagine if the choice was: We have this data about you (a comprehensive list of all the fruits of our creepy stalking: a,b,c,d, etc...), if you let us violate your privacy in a myriad of ways, we will let you have this little trinket for free. Otherwise, it will cost you x. How many people would select privacy violation?
>Most people don't expect to get things for free in the real world, why should the internet be any different? Why does everyone (myself included) always look for free stuff on the internet?
Most of the internet is communication in some form or another. I get a lot of communication for free in the real world. My question is: why does everyone assume that the purpose of the internet is their platform to get rich selling trinkets to clueless natives? Maybe some things are better off run as a non-profit?
Unfortunately under the GDPR we are not going to find out how many people would choose this option. It isn't legal, in the EU, to refuse someone access if they say no to your data collection.
[1] At least according to some countries' DPAs, and as long as the price is "fair".
From your link, almost at the top: "The cookie wall is a mechanism where the user has only one option to access the website: accept the processing of the cookies. The cookie wall is prohibited.". So no, requiring users to agree to data collection, per your article, is prohibited.
The article makes a distinction between cookie wall (accept or no access) and paywall[1] (accept or pay). The former is prohibited, the latter has been okay'd by several national DPAs.
> The Austrian, French and Danish DPAs have already indicated that the paywall system is a valid solution as long as the subscription to the site has a modest and fair cost so that it does not constrain the user’s free choice.
> The Spanish DPA indirectly shared its position implying that cookie walls can be used as long as the user has been clearly informed of the two available options for accessing the service: 1. accepting the use of cookies; or 2. another alternative, “not necessarily free of charge“, that doesn’t require giving consent to cookies.
[1] Not to be confused with the "hard" paywall (pay or no access) we see on some publications. They've just called it like that for lack of a better term.
Especially because I bet so many of those sites would set X to be much higher than the value of the data.
When it comes to what people chose to do with their own data though I don't feel a moral obligation to push my views though. If they truly want to opt in and save the $20 (or however much the data is worth in the app) then taking that choice away because I disagree with how they should treat their privacy information is hardly much better than forcing them to because of the same reason. The main difference for me being whether or not I profit off it but, given choice in each case, that really doesn't matter to how the user weighs the situation.
Even though many people assume it's this way, this choice hardly ever happens in practice. You allude to this yourself. In reality, the choices are usually between paying for something and they still sell your data, and getting it free and they really sell your data.
The majority of paid services have privacy policies, terms of service and user agreements that spell out how they sell data just as much. At best, you might expect that they are a bit more selective in who they sell to, since they're not as desperate for cash flow. However the impact to you is greater - they now have your credit card, address, full name, phone number (all vulnerable to hacks and leaks) and it's harder to lie about these things than with a free account. So the data they collect is more valuable, hence the temptation is higher as well.
Moreover, the paid services have consumer-hostile subscription systems rife with dark patterns. It's needlessly tedious to cancel a service if you decide you don't like it, and even free trials demand a credit card.
Transparency is very low about what is actually done with your money as well. Many services operate at a loss, and the customer charge is just a fig leaf while the real money comes from investors. Arguably, the paid model is a sham for some companies and their real exit is to collect data for a years and then get bought by some data aggregator. On the other end of the spectrum you have people fishing for suckers with ridiculously inflated prices.
For these reasons the choice of paying money is tainted by lack of trust, it is not just consumers being stingy and entitled. Lack of trust can quickly bog down any market.
I don't really blame the industry here, though. It's a bit like California in 1848 - you can hardly blame people for picking up the gold that's just lying around. The real problem is that we don't have the tools, infrastructure and regulatory frameworks that let users see and control how their data is used. If people really want to sell their data in lieu of payment, then let them. But currently, most users are not aware exactly what data gets collected and how much it is worth - they're not able to rationally decide that paying $5 for an app is better than being mined for $20 worth of your data.
+ track change of ownership
+ some distributed review system
+ better sandboxing
+ no forced autoupdates
+ A few other things
World of Warcraft has an in game ui addon modding system built in that ends up suffering from these same problems. It’s so damn frustrating to see addon developers sell out their fans to a super shady spyware company for like $3/month (and the alternative is $0)
I could understand betraying people for a life-changing amount of money, but £20 is 5-20 minutes’ worth of pay for a competent SWE…
Have some trusted organization or group (like Google or Mozilla themselves) who run audits on extensions to "certify" they don't have any malware. Additionally, the extensions are all 100% open-source, so if the "trusted organization" is compromised (or just bad at their job), they'll get caught and people will stop using them.
This isn't foolproof. Adware can be hidden from even the auditor or the auditor can be compromised but nobody finds out. It's also expensive and time-consuming, especially for extensions with a lot of complex code, so many popular extensions which perfectly-fine are still not certified. Updates are delayed and discouraged because the diff always has to be audited as well. Lastly (and something which can easily be overlooked), the auditors can be biased towards approving some extensions (like those who pay them) while not approving others: extensions code won't be approved if their code is too hard to read or they are later in the review queue, but the line at which code is considered "too hard to read" and their position in the queue could easily be influenced by cash.
Nonetheless, web extensions are a good type of software to audit, compared to other software like apps. They're often much smaller and simpler, users need much less, and they operate in a very-trusted domain (all web browing, including in banks and other confidential sites. Compare this to apps on a sandboxed phone, or programs running in user mode on a computer, the damage is still there but it's much less)
And it works. At least to keep the worst off Apples App Store. Mostly. Googles play store is apparently much more linient. And contains lots of horrible apps.
But the costs, as you mention, are real too. So much, that many, including myself, simply forego Apple as target at first. Sure, it's the more popular platform and it has more people willing to pay. But the review hurdles aren't worth it in the beginning.
From all the data I have, people will definitely pay for extension functionality, though lots of people will write negative reviews unfortunately.
I also use ExtensionPay myself in my own extensions and have found this to be true. I try to get the people who pay and have a good experience to write reviews since they’re so underrepresented in written reviews.
Hey There,
I wanted to reach out and see if <website.com> accepts guest post contributions or link insertion in existing posts? If so, I'd love to hear more about your guidelines and any specific topics of interest.
Thank you for your time, and I'm looking forward to your response.
Best Regards,
These ones are definitely spammed out en-masse, my site doesn't even have a blog.My site also has some Windows software downloads on it, and I occasionally get emails for bundling dodgy installers. Most of these tend to be "residential proxy" services looking to sell access to users' internet connections.
I wonder what these people are thinking? Like, TOR operators know the risks with connection sharing - most particularly: pedos using their service to share CSAM. But everyday people?! They have no idea until one day they get v&.
Not condoning it of course, it is still an ugly practice.
I also get these emails but run a WordPress site. I was convinced they would fingerprint websites and mail those to these sites only.
It was on my todo to see if I could hide the fingerprint of WordPress.
But now that you mention this, it's obvious it wouldn't do much. In hindsight, I could have know these spammer would just spam everybody in bulk.
Sounds like a challenge to hide the wordpressyness entirely though, it's got a huge surface area.
---
Subject: Found a security vulnerability on your website.
Hi Team, I am Harris, a security researcher, and I have found a security vulnerability in your website outside a bug bounty program.
I can disclose all the vulnerabilities found and their proper fixes too, to make your website more secure.
Companies I helped have always been generous and helped me back with rewards in amounts they think are appropriate to the issues I have found. If you appreciate my help, I'd be happy to receive a bonus payment via PayPal, Bitcoin, Payoneer, or Bank Transfer.
Waiting for a positive response from your end.
Thanks and Regards,
Harris A
Certified Ethical Hacker
I just ignored them and that was it.
They feed in so much context that it does appear to be a real person and it ends up wasting a lot of time and honestly it's quite hurtful. We spend a lot of time sharing our stuff and these fake connections are a major turnoff.
Recently we encountered a wave of "awards shortlist" sort of emails written by AI with deep context that will cosider us for award for one easy payment! Except they always forget to tune the topic as we're not running software security service, we cover web scraping.
I feel like AI will kill email communication between strangers. It's getting so exhausting.
I believe most legitimate visitors send an email shortly after visiting a page with the address while spam emails often have a much longer lead time with new addresses (it takes time to get scraped, put in a database, and then get used).
However this does mean that extended communication on that address and saved addresses will not work well.
That's kinda lame because now you have to have a backend setup, just so you can charge for some features.
If we approach it from that angle, then your extension can only restrict access to it's features via a round trip to your own servers to validate access and/or show a checkout view to purchase access.
Some of the difficulty around securing extensions boils down to the fact that Javascript permissions could be better. Websites do a decent job of sandboxing the website, but sandboxing within websites (without relying on iframes) is much more difficult.
Per-site permissions and click-to-activate are also really useful features here. It's easy to forget how recent they are. But it would be good to go further if possible and having barriers in front of exfiltration would be a big part of that -- there are many browser permissions that would become less dangerous if you could know for sure that the data they generate can't get off your device. I just think it would be really difficult to try and build browser permissions around that in a user-legible way.
There are lots of business models to choose from
- subscription
- affiliate links
- sponsors
- one time charge, this one is tricky as restricting access requires a back-end that needs ongoing maintenance and server costs
[edit: formatting, spelling]Extension devs know the rules of the game up front and have no expectation of profit.
It's wonderful that people are willing to share their knowledge and time for free - why not let it be the way it is?
Project being maintained by a single dev being another, there needs to be incentive to keep the project going and not abondon or sell out.
If a browser extension is allowed to use license keys (not sure on the various store rules i.r.t. browser extensions), you could create a timed license key that is cryptographically signed.
No back-end required for that.
Everyone has a price, and when everything is going smoothly, that price goes up.
There is no way for monetization to solve this, because the two potential customers are not purchasing the same product.
If monetization was better, it would just end up like Google Play, with adtech spam crowding out the "legitimately" monetized apps.
Dracionian restrictions on web access (like requiring a prompt whenever an extension wants to upload/download data) might help a little.
https://developer.chrome.com/docs/webstore/money/
"The web has come a long way in the 11 years since we launched the Chrome Web Store. Back then, we wanted to provide a way for developers to monetize their Web Store items. But in the years since, the ecosystem has grown and developers now have many payment-handling options available to them."
So there are monetization opportunities, just like any other distribution channel.
I'm not sure I advise doing it, but you can go to about:addons and hit the gear icon and you can uncheck "Update Addons Automatically". Even better, click on an extension and under the "details" tab there's an option per-addon to set whether you want automatic updates or not, so you can disable updates just for the one addon you don't trust (or enable updates just for the one addon you do trust).
Also, want to run older version of an extension? The Mozilla Addons page for each extension has a list of every release and you can download each version independently as a signed XPI file if you want to sideload it.
The big thing I wish Mozilla would add is self-compiled releases like F-Droid does, especially since their ill-advised signing process means it's hard for users to compile an extension from source -- it's way too easy for a submitted extension to deviate from its source code. But that (admittedly large) issue aside, Firefox offers a lot of control for users who want to manage their own extension versions. Forced automatic updates are a Chrome problem.
"I’m sure you get business proposals all the time, so I’ll get straight to the point. I hope what I’m proposing is a little different and might actually interest you. I like Hover Zoom+ as a great alternative to it’s bigger brother Hover Zoom that lost its glamour over the last couple of months.
We're conducting a DNS error research and we’re interested in small amounts of anonymous data that you might be able to provide via your Chrome extension. Our research has been going on for years and Google has never had the slightest problem with it.
- Compatible with Google’s strict policies
- No personal user data
- No ads, no malware
The data we’re interested in are basically just DNS errors:
- NXD – Non Existent Domain - the domain that a user entered that resulted in a DNS error.
- A time stamp – when it happened.
- GEO – where it happened (USA, UK, RU etc.).
- A unique randomly generated user ID (can be hashed, not traceable back to the user). Please, don’t confuse this with the user IP address.
And that’s all. You can either use our script or collect the data on your own and send it to us via an FTP server, API etc. There’s a lot of different ways we can do this. We pay on a monthly basis. The payments depend on user GEOs, but it would be in thousands of dollars per year.
Is this worth at least a brief discussion? Looking forward to hearing from you.
A while back I reached out to you regarding a DNS error research our company conducts. Hover Zoom+ would be an ideal medium for our research. In return, this could become a solid new revenue stream for you.
Our method has been going on for years and we’ve never had the slightest problem with Google. We pay regularly on a monthly basis. For you it would be in tens of thousands of dollars per year - the amount depends on your users base and data quality.
If you’re concerned about including third party scripts, there’s still a lot of ways we can make this work.
Please let me know if this is worth a brief discussion to you."
Therefore, there is likely some business interest at best, or anti-user behavior at worst.
It's not hard to write a script that ostensibly does one thing but very sneakily carries information about another thing. For example, write a bad 'hashing' function? Piece of cake.
Always follow the gradient of ATP.
The incentives seem entirely misaligned in the extension space.
My personal opinion is that you shouldn't be allowed to transfer an extension between owners without prior approval and vetting of the new ownership structure. This should deliberately be harder than just setting up a new extension, because new listings won't have reviews or trust associated with it. I'm saying this as the person who occasionally gets caught on the business end of some of these policies[1] and knows how much of a pain it is to navigate bureaucracy. The underground extension sales marketplace is incredibly sketchy and plays fast and loose with user trust.
[0] Joke's on them, our AMO listing is already flagged for machine-generated code (because we use Rust/WASM), so our extension submissions only get approved if Mozilla is able to reproduce our builds byte-for-byte.
[1] https://ruffle.rs/blog/2023/04/23/mozilla-extension-postmort...
1. Make a legitimately useful Minecraft Bukkit plugin.
2. Wait for lots of installs.
3. Add a well-hidden backdoor that makes me "op" (admin) on any server I choose.
4. Surprise some mean op on a public server by suddenly banning him.
I got through step 2 then decided to stop there.
I found one that was simple enough, but it would ping home to check if there were any updates as well. Now it could have been just the developer trying to add a useful feature, but the cynic in me believes it's so that they could get IP addresses of the servers running the plugin.
It also had a debug command that wasn't authenticated that let you print the contents of any motd file in a folder. Except it didn't escape strings properly, so you could `../...` to escape out of that directory and print any file.
I have no idea if the author actually exploited this, or if they were a naive 14 year old writing their first plugin. If they were trying to exploit, I don't know which file they were going to print the contents of, but it definitely made me very suspicious.
That's hilarious and showcases how un-sandboxed those plugins are.
Beyond ancient anarchy servers, right now the Minecraft mod community has been dealing with several supply chain attacks, deserialization vulnerabilities, and so on.
The first one that happened to me: I have a domain name and someone emailed me to let me know, as a courtesy, that someone was buying similar Chinese domain names and did I want to get them first. I thought that was nice that they were notifying me ... oh wait, they're just trying to get me to buy their domain names.
People contact me about redesigning my website, buying my website, exchanging links, straight up spamming my website. It's really strange.
> Recommended extensions differ from other extensions that are regularly reviewed by Firefox staff in that they are curated extensions that meet the highest standards of security, functionality, and user experience. Firefox staff thoroughly evaluate each extension before it receives Recommended status.
https://support.mozilla.org/en-US/kb/recommended-extensions-...
If your browser doesn't have a code vetting process for extensions, I'm not interested in your browser.
It means taking malware seriously, even if that means you have to pay human beings to vet code manually. I realize that Google wants to avoid paying human beings at all costs, but too bad.
They do allow minification for compression, and I don't know what stops someone from uploading different source code from the shipped addon.
https://support.mozilla.org/en-US/kb/recommended-extensions-...
One of them straight up offered $10k, whether that was a real offer or not I don't know because I never replied to any of them.
I've since taken down the extension as I'm no longer maintaining it, but weirdly I still get these emails, albeit less frequently.
What I'd like to know is, how many different entities are represented in this compilation? Since everything is redacted, it's not easy to tell. I was surprised that there are so many offers by, seemingly, so many different scumbags. I mean people.
For those curious, here's the GitHub repo of my extension: https://github.com/mohnish/rearrange-tabs
cd .mozilla/firefox/$profile
git init
git add extensions
git commit -am init
echo '*.xpi diff=zip' >>.gitattributes
echo '[diff "zip"]' >>.git/config
echo ' textconv = unzip -c -a' >>.git/config
which at least lets you take a peek at what kind of nefarious updates you're getting.The profiles that you use for Metamask, don't install any extensions into those beyond MM.
"It's lowercase-italics 'r', lowercase-italics 'e', lowercase-italics 'd', lowercase-italics 'a', lowercase-italics 'c', lowercase-italics 't', lowercase-italics 'e', lowercase-italics 'd'"
"Ha, ha, your name is 'redacted'?"
"No"
No intention of "monetizing" as there is no non-shady way to monetize this feature. I perhaps don't maintain it as much as I could (sorry Windows and Linux users), but on the upside it is so little work that I'm never tempted.
[1] https://chrome.google.com/webstore/detail/tab-to-windowpopup...
> I'm reaching out to discuss a unique monetization opportunity for your extension, <name>, through our exclusive Premium Bing Hosted Product. > I'm thrilled to let you know that this invitation-only product offers the chance to earn as much as $500 per month for every 1000 users. Given that your extension has a user base of 10K, you stand to make up to $5000 monthly just by integrating the search functionality into your extension. This could be a significant source of passive income, and I truly believe it's an opportunity you won't want to pass up.
I... I... I know the 10 installs are all basically /my devices/...
Fake extensions created under burner dev accounts (w/ fake identities), astroturf the installs like crazy. Use ChatGPT to write the code, pump it out like chocolate out of Willy Wonka's Fudge Sludgefest.
Sell to scammers/info scalpers for a flat fee via a non-refundable route under a semi-reputable escrow, rinse and repeat.
The one downside is if you do that to somebody bad, and you've left any personal info out by accident....
Additionally, it's highly unethical. Don't do this. But it seems like 'easy money', the whole 'curse of maybe getting doxxed and XYZ from a sufficiently-motivated data thief' aside.
Maybe mark as spam and move on.
Some people have no shame at all. It's like the caricature of the Devil from a Sunday Morning cartoon, offering you riches and power untold for the low, low price of your soul.
Like dude, how do you know what Ghostery is and don't get why people use it?
I get that it's noble to hold a position of 'no way, I will never monetize, I am a shining white knight' but lets be real, we all gotta eat. If you choose not to then that's great, Im glad but please; monetization !== shady shit.
There's just an overlap.
They also provided several options for sending the data, just to guarantee that the extension couldn't be compromised by their code. This one stood out from the rest for me. Curious though if I'm missing some way that this could be used for nefarious purposes though. Full text of the proposal below:
------
I’m sure you get business proposals all the time, so I’ll get straight to the point. I hope what I’m proposing is a little different and might actually interest you. I like Hover Zoom+ as a great alternative to it’s bigger brother Hover Zoom that lost its glamour over the last couple of months.
We're conducting a DNS error research and we’re interested in small amounts of anonymous data that you might be able to provide via your Chrome extension. Our research has been going on for years and Google has never had the slightest problem with it.
Compatible with Google’s strict policies No personal user data No ads, no malware The data we’re interested in are basically just DNS errors:
NXD – Non Existent Domain - the domain that a user entered that resulted in a DNS error. A time stamp – when it happened. GEO – where it happened (USA, UK, RU etc.). A unique randomly generated user ID (can be hashed, not traceable back to the user). Please, don’t confuse this with the user IP address. And that’s all. You can either use our script or collect the data on your own and send it to us via an FTP server, API etc. There’s a lot of different ways we can do this. We pay on a monthly basis. The payments depend on user GEOs, but it would be in thousands of dollars per year.
Is this worth at least a brief discussion? Looking forward to hearing from you.
A while back I reached out to you regarding a DNS error research our company conducts. Hover Zoom+ would be an ideal medium for our research. In return, this could become a solid new revenue stream for you.
Our method has been going on for years and we’ve never had the slightest problem with Google. We pay regularly on a monthly basis. For you it would be in tens of thousands of dollars per year - the amount depends on your users base and data quality.
If you’re concerned about including third party scripts, there’s still a lot of ways we can make this work.
Please let me know if this is worth a brief discussion to you.
I don't know what they actually intended to use this data for, but its telling that they don't mention that in their proposal.
These days I pretty much only install open source extensions. Ironically I was using Imagus, just switched to HoverZoom+ thanks to this post.
If this is true (and its a huge if, again, I heard it in the context of a rumor), just makes them more of a stand up developer!
Some good discussion in that thread too :)
Shameless self promotion - Open source chrome tab search way more powerful than the newish built in search (supports quotes, negative searches, things like host:example.com, etc).
https://chrome.google.com/webstore/detail/tabasco/apnefdpgai...
Blog post from an ex-Chrome extension DevRel: https://dotproto.com/2023/06/06/a-warning-about.html
A rather popular app for macOS got purchased by some shady company and they updated it to include a botnet SDK. I'm guessing a lot of the potential buyers here have similar intents.
It’s pretty concerning, does someone here know an extension that would block or signal other extension’s misbehavior?
Any chances ublock does it already ?
All cards on the table: Google does a not-great job of protecting against intentional malicious changes last I checked, i.e. they'll pass through a lot of new extensions and extension updates that do shady stuff behind the scenes. But without some lockdown on arbitrary code execution (which Mv3 provides), the problem is theoretically impossible to solve.
What you're describing is the migration path from v2 to v3. "Detect if the extension downloads and executes arbitrary code, and ban it if it does" is isomorphic to "deprecate the eval arbitrary code permission, cease supporting it in the store, and provide an alternative declarative model to get some of the behavior back;" it's what Google is trying to do.
Then it's a non-starter for the manifest format supported by the chrome web store. Because Google's goal is to automate as much as possible.
Don't forget, the mere act of requesting data from an external uncontrolled third-party source is leaking user information. Under Mv3, those leaks are fully documented.
0. Prefer extensions that work locally, no data sent out anywhere.
1. Keep an extension audit profile, meant for testing them a bit.
2. Use different extensions for my main daily driver profile, shopping comparison profile, etc.
2. The audit profile also has bookmarks of the extensions I'm using and others for later review, or looking back, helps me declutter the main profile a bit.
3. Use https://chrome-stats.com/ to check the extensions' pedigree, they have a trust meter based on the amount of permissions asked, how long has the developer been around, etc.
4. Do your own review on what goes out with developer tools on requests, especially if the extension needs permission to a control domain. Many will tell you in the Privacy Policy that they don't collect anything PERSONAL, but need to process your data somehow, and from an initial look you can't really tell it's a service or the extension itself doing it. Lack of clear wording is key here.
5. Some mask the control domain using a subdomain of a cloud platform to host the app, so it looks more trustable, and tell they only send telemetry data there.
6. Prefer stuff that's also on github, but don't trust blindly: some developers have just posted a boilerplate hello world there.
Two related anecdotes:
1. The Glarity extension (AI GPT autocomplete stuff) is open source, you can find it on github too, it explicitly said it worked only with your OpenAI API key only, yet when installing it, it just worked and I was getting GPT-powered summaries. They have their own service, where they relay all your input, but there is no documentation of it anywhere. I didn't double check if those requests stopped once you added your own API key. That was months ago, now just checked before posting, still no news from them on that functionality. While I can ascribe this to just general sloppiness, there've been some repos with serious accusations of stolen keys (lencx/nofwl)
2. I've had login data leaked with a shopping extension, where Chrome alerted me and disabled it. That was in 2021. It was pulled from the store. Months later I start getting login notifications in my email to some websites I use with my 'shopping/price compare' profile. They were attempts from Russia. The websites alerted to my email yet let session go through, since I don't use 2fa. It seems they were scanning for some saved credit card or something.