lemmy.mixdown.ca
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
vitonsky@programming.dev to Technology@lemmy.worldEnglish · 2 years ago

Browser extensions spy on you, even if its developers don't

vitonsky.net

external-link
message-square
16
link
fedilink
163
external-link

Browser extensions spy on you, even if its developers don't

vitonsky.net

vitonsky@programming.dev to Technology@lemmy.worldEnglish · 2 years ago
message-square
16
link
fedilink
I've developed a few browser extensions, and every week I receive numerous emails with "revenue offer". Some experienced developers know that offers like these will inject malware into the browsers of your users, but scammers who make these offers will not tell you about it. They offer "integrations" that don't look so suspicious. Imagine how many developers have accepted these offers. Then look at the number of extensions in your browser and think about how much risk there is that you have an extension with malware.
  • redditReallySucks@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    46
    arrow-down
    1
    ·
    edit-2
    2 years ago

    Or maybe only install extensions from trusted sources developers.

    • 2Xtreme21@lemmy.world
      link
      fedilink
      English
      arrow-up
      33
      arrow-down
      2
      ·
      2 years ago

      I think the point is that even if an extension comes from a trusted source, the developer could fairly easily push out an update that turns the extension into malware. Check the GitHub link in another comment below where the developer posts the solicitation emails he gets on a regular basis offering to monetize his extension. He isn’t selling out, but maybe not every dev is as willing as he is to forgo a potentially lucrative offer.

      • RdVortex@lemmy.world
        link
        fedilink
        English
        arrow-up
        10
        ·
        edit-2
        2 years ago

        And there are cases where this has already happened: https://www.bleepingcomputer.com/news/security/-particle-chrome-extension-sold-to-new-dev-who-immediately-turns-it-into-adware/ There are probably more recent cases too, but this was the first one I could find.

    • TheEntity@kbin.social
      link
      fedilink
      arrow-up
      14
      arrow-down
      1
      ·
      2 years ago

      To be specific: from trusted developers. Installing them only from the official repository (is it still possible to reasonably install them any other way?) won’t help if a dev sells such an addon. On the other hand I cannot imagine someone like Raymond Hill (the uBlock Origin dev) doing it, considering his track record.

      • redditReallySucks@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        2
        ·
        2 years ago

        Yeah, that’s what I meant.

Technology@lemmy.world

technology@lemmy.world

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !technology@lemmy.world

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


  • @L4s@lemmy.world
  • @autotldr@lemmings.world
  • @PipedLinkBot@feddit.rocks
  • @wikibot@lemmy.world
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 3.84K users / day
  • 9.81K users / week
  • 18.1K users / month
  • 20.6K users / 6 months
  • 1 local subscriber
  • 69.9K subscribers
  • 10.3K Posts
  • 410K Comments
  • Modlog
  • mods:
  • L3s@lemmy.world
  • enu@lemmy.world
  • L4sBot@lemmy.world
  • Technopagan@lemmy.world
  • L3s@hackingne.ws
  • L4s@hackingne.ws
  • BE: 0.19.11
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org