TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

“Stylish” browser extension steals all your internet history

484 pointsby mbayealmost 7 years ago

39 comments

mcjiggerlogalmost 7 years ago
This is a huge problem for the extension ecosystem in general. Who originally publishes an extension may not be the same entity that is pushing you updates in two years time, and there&#x27;s no way as a user to know this.<p>I publish a few extensions [1] [2] [3] and have been contacted multiple times by companies asking to buy them for several thousand dollars. They told me the going rate was 0.20 USD per user. You can imagine what kind of deals are being made when the extension has a million plus users.<p>When pushed for exactly why they wanted to buy the extensions, which are in no way monetizable, they gave vague answers about &quot;user insights&quot;. I can guarantee there will be many other major extensions that have sold out their users.<p>[1] <a href="https:&#x2F;&#x2F;chrome.google.com&#x2F;webstore&#x2F;detail&#x2F;old-reddit-redirect&#x2F;dneaehbmnbhcippjikoajpoabadpodje" rel="nofollow">https:&#x2F;&#x2F;chrome.google.com&#x2F;webstore&#x2F;detail&#x2F;old-reddit-redirec...</a><p>[2] <a href="https:&#x2F;&#x2F;chrome.google.com&#x2F;webstore&#x2F;detail&#x2F;break-timer&#x2F;hklkdbpicdmlpoiellngedpejjkmapei&#x2F;reviews" rel="nofollow">https:&#x2F;&#x2F;chrome.google.com&#x2F;webstore&#x2F;detail&#x2F;break-timer&#x2F;hklkdb...</a><p>[3] <a href="https:&#x2F;&#x2F;chrome.google.com&#x2F;webstore&#x2F;detail&#x2F;reddit-comment-collapser&#x2F;njmimaecgocggclbecipdimilidimlpl" rel="nofollow">https:&#x2F;&#x2F;chrome.google.com&#x2F;webstore&#x2F;detail&#x2F;reddit-comment-col...</a>
评论 #17448726 未加载
评论 #17448598 未加载
评论 #17448448 未加载
评论 #17449174 未加载
评论 #17450720 未加载
评论 #17448374 未加载
评论 #17448612 未加载
评论 #17449236 未加载
评论 #17449582 未加载
Zrenalmost 7 years ago
I&#x27;ve gotten annoyed enough to just copy the source from most of my extensions (located at `~&#x2F;.config&#x2F;google-chrome&#x2F;Default&#x2F;Extensions&#x2F;`), remove the update stuff from the `metadata.json` and load them as developer extensions so they never update.<p>It&#x27;s easy enough to update them + audit the code when something breaks. The hardest part is downloading the new code (.crx) without installing it, I had to write javascript I paste into the console. StackOverflow can unzip a crx by striping the first 306 bytes.<p>I forked Stylish v1.5.2 a year ago before I heared of Stylus, but I&#x27;ve no need to to switch since the original extension was pretty good. <a href="https:&#x2F;&#x2F;github.com&#x2F;Zren&#x2F;chrome-extension-stylish#fork" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;Zren&#x2F;chrome-extension-stylish#fork</a>
评论 #17486080 未加载
评论 #17452327 未加载
评论 #17450659 未加载
psergeantalmost 7 years ago
Offices in the UK. I would encourage anyone in the EU who used this to file a GDPR complaint.
评论 #17448353 未加载
评论 #17449091 未加载
评论 #17448242 未加载
评论 #17449547 未加载
TheCapeGreekalmost 7 years ago
As others have said, immediately switch to Stylus. While we&#x27;re at it stop using Ghostery as well since they were bought by an ad company. Use Privacy Badger or a decent alternative (noscript + heavy&#x2F;custom uBlock lists should work just fine)
评论 #17448279 未加载
评论 #17449176 未加载
评论 #17451342 未加载
评论 #17454386 未加载
评论 #17450114 未加载
评论 #17448367 未加载
mappualmost 7 years ago
I discussed this problem (in a bit inflammatory way) last month: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=17242003" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=17242003</a><p>It&#x27;s particularly annoying, because I do have this Stylish extension installed (using css ::after rules to tag HN users)<p>EDIT: You can submit an abuse report when uninstalling a Chrome extension.
评论 #17448106 未加载
eastendguyalmost 7 years ago
This reminds of the &quot;WOT, Web of Trust&quot; (haha) privacy issue in 2016: Reporters (disguising as business men) were offered data that includes the surfing habits of three million German citizens. This data was, at least partly, collected by the “Web of trust” (WOT) browser extensions. The reporters were able to use this data to identify the browsing habits of individual persons – including high-ranking German and EU politicians.<p>English: <a href="https:&#x2F;&#x2F;ocr.space&#x2F;blog&#x2F;2016&#x2F;11&#x2F;wot-browser-extension-collects-habits.html" rel="nofollow">https:&#x2F;&#x2F;ocr.space&#x2F;blog&#x2F;2016&#x2F;11&#x2F;wot-browser-extension-collect...</a>
评论 #17448335 未加载
dannywalmost 7 years ago
Google needs to take action here. From requiring re-confirming permissions every time a significant privacy policy change is made, or just by nuking SimilarWeb altogether from the web App Store.
评论 #17448254 未加载
_fh5nalmost 7 years ago
It took me less than a minute to install Stylus and import all my userstyles from Stylish.
评论 #17450198 未加载
trio333almost 7 years ago
Always the same cycle.<p>1&#x2F; New great product is built. People love it.<p>2&#x2F; Once enough people use it, start monetizing in shady ways, annoying users just not too much or they leave.<p>3&#x2F; Very annoyed users switch to another product back to 1&#x2F;
评论 #17448341 未加载
评论 #17448583 未加载
ssivarkalmost 7 years ago
Most browser extensions seem to require access to one&#x27;s browsing history and keystrokes, even for legitimate functioning. Is there any way to ensure that they do only what they claim to do, and don&#x27;t abuse the permissions? (Apart from verifying the source code, because clearly, lines of junk code &gt;&gt; interested eyeballs).<p>For example, would it be reasonable to enforce that an extension only acts locally, and cannot communicate with any external server? (I guess allowing arbitrary local modifications essentially allows the extension to execute arbitrary javascript code, including communicating with arbitrary remote entities?)
评论 #17448338 未加载
评论 #17448377 未加载
mjgoekealmost 7 years ago
For those actively using Stylish and needing to switch:<p>&#x27;&quot;Stylus&quot; is a fork of the popular Stylish extension which can be used to restyle the web. Not &quot;ish&quot;, but &quot;us&quot;, as in &quot;us&quot; the actual users. Stylus is a fork of Stylish that is based on the source code of version 1.5.2, which was the most up-to-date version before the original developer stopped working on the project. The objective in creating Stylus was to remove any and all analytics, and return to a more user-friendly UI. We recognize that the ability to transfer your database from Stylish is important, so this is the one and only feature we&#x27;ve implemented from the new version.&#x27; [1]<p>[1] <a href="https:&#x2F;&#x2F;add0n.com&#x2F;stylus.html" rel="nofollow">https:&#x2F;&#x2F;add0n.com&#x2F;stylus.html</a> and <a href="https:&#x2F;&#x2F;github.com&#x2F;openstyles&#x2F;stylus" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;openstyles&#x2F;stylus</a>
HelenePhisheralmost 7 years ago
Tampermonkey seems to be a good alternative as well and is available for all major browsers.<p>Does anyone have information on if the Safari Stylish Addon does the same shady things? It&#x27;s available in the official App Store and was approved by Apple it seems.
评论 #17451632 未加载
naileralmost 7 years ago
Just filed this Firefox bug: <a href="https:&#x2F;&#x2F;bugzilla.mozilla.org&#x2F;show_bug.cgi?id=1472948" rel="nofollow">https:&#x2F;&#x2F;bugzilla.mozilla.org&#x2F;show_bug.cgi?id=1472948</a>
评论 #17453210 未加载
roadbeatsalmost 7 years ago
Meanwhile a simple and open source bookmarking extension was taken down with no notice, no information (<a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=17440358" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=17440358</a>).
tripzilchalmost 7 years ago
Well, shit. I installed this extension a few months ago, because <i>multiple</i> people HN recommended it.<p>Tried it out, but found a different way to restyle and adjust sites to my tastes (uBlock and custom Greasemonkey) that I found easier. Then forgot about it.<p>And now it turns out this thing has been slurping my Internet history for months.<p>No downvotes, nobody calling them on it, just happy oblivious HN users that carelessly install random browser extensions and then recommend them to other people. Urgh.
_bxg1almost 7 years ago
This has been going on for <i>years</i> and Google has done nothing about it. These days I don&#x27;t use any extensions where a major organization&#x27;s reputation doesn&#x27;t depend on them not becoming spyware. Truly a shame; I used to get a lot of benefit out of extensions, including a similar one named Stylebot, but now I don&#x27;t trust anything other than Adblock Plus and the React Developer Tools to not covertly become malicious.
评论 #17450759 未加载
therealmarvalmost 7 years ago
report stylish to Google <a href="https:&#x2F;&#x2F;chrome.google.com&#x2F;webstore&#x2F;report&#x2F;fjnbnpbmkenffdnngjfgmeleoegfcffe" rel="nofollow">https:&#x2F;&#x2F;chrome.google.com&#x2F;webstore&#x2F;report&#x2F;fjnbnpbmkenffdnngj...</a>
alexanderbyalmost 7 years ago
Dark Reader (which generates dark themes dynamically) added support for static CSS so that style sheets could be migrated <a href="http:&#x2F;&#x2F;darkreader.org&#x2F;blog&#x2F;stylish&#x2F;" rel="nofollow">http:&#x2F;&#x2F;darkreader.org&#x2F;blog&#x2F;stylish&#x2F;</a>
mholtalmost 7 years ago
Dangit - I just installed it yesterday to block Twitter&#x27;s annoying timeline additions (&quot;So-and-so liked such-and-such&quot;) which don&#x27;t honor the account&#x27;s word filter&#x2F;blacklist. Any alternatives out there that are better?
评论 #17449927 未加载
评论 #17458382 未加载
O1111OOOalmost 7 years ago
10 months ago, I discovered and recommended <i>stylish</i> on a post titled: &quot;Show HN: Make Medium Readable Again&quot;[0]. I have only ever used it for a single site: medium.<p>It&#x27;s times like these I wish I could go back and edit&#x2F;update an old post with new info. I feel like I got stabbed in the back... which happens way too often in tech these days no matter how careful you are.<p>[0] <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=15123638" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=15123638</a>
fishtopheralmost 7 years ago
In what is certainly a complete coincidence, the Stylish Firefox extension threw up an &quot;agree to our new TOS &#x27;effective May 22, 2018.&#x27;&quot; modal for me today..
aplc0ralmost 7 years ago
It appears Firefox has already moved on this. Came home today and was warned that Stylish was an unsafe extension, and I can no longer find it listed as an available add-on.
SSchickalmost 7 years ago
I actually ran into this issue previously when for some reason I got a request on a `hidden` (very cryptic URL listed nowhere) diagnostic endpoint on one of our APIs. I ended up identifying stylish as the culprit, at first I disabled the tracking option (which is opt out and probably violates GDPR), a few weeks later I installed stylus.<p>I also reported it around the same time and gave it a 1&#x2F;5 star rating but google had no interest in the report it seems.
franga2000almost 7 years ago
I&#x27;ve been lucky enough to have never had an extension installed when it was sold, so I don&#x27;t know that this isn&#x27;t already the case, but if it isn&#x27;t, I believe it should be: Whenever an extension changes hands (is transfered to another account), the user should be notified in the same way they would be if it requested new permissions. Along with a rule that accounts are non-transferable, of course.
lifthrasiiralmost 7 years ago
tl;dr: Use Stylus [1]. Use Stylus. Use Stylus.<p>I guess there should be an addon that notifies users for any ownership changes to browser addons they use. Or is there?<p>[1] <a href="https:&#x2F;&#x2F;github.com&#x2F;openstyles&#x2F;stylus" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;openstyles&#x2F;stylus</a>
评论 #17448823 未加载
评论 #17448248 未加载
评论 #17530849 未加载
评论 #17448569 未加载
评论 #17448128 未加载
评论 #17448103 未加载
评论 #17448678 未加载
captn3m0almost 7 years ago
Found same issue with Pricee the other day, not sure how to report: <a href="https:&#x2F;&#x2F;addons.mozilla.org&#x2F;en-US&#x2F;firefox&#x2F;addon&#x2F;pricee-search-engine&#x2F;" rel="nofollow">https:&#x2F;&#x2F;addons.mozilla.org&#x2F;en-US&#x2F;firefox&#x2F;addon&#x2F;pricee-search...</a>
Sephralmost 7 years ago
The culprit in question tried to do the same thing to a Voice Search Chrome extension in the past[1].<p>[1] <a href="https:&#x2F;&#x2F;twitter.com&#x2F;sephr&#x2F;status&#x2F;1014240895095300096" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;sephr&#x2F;status&#x2F;1014240895095300096</a>
stratigosalmost 7 years ago
Ugh! After so many years, I now have to view a white-themed internet again. I forgot how painful and blindy websites are!<p>Pls redesign the whole internet to be dark themed, so we dont need add ons like this to fix the world. Thanks!
garganzolalmost 7 years ago
So it boils down to trust anyway. No way a code signing certificate can impose that trust. At the end of the day, it all goes back to human stance towards other beings in this world and own dignity.
Bromsklossalmost 7 years ago
Since &quot;youtube-dl does not include support for services that specialize in infringing copyright&quot;, is there a fork, or addition, without this restriction?
kup0almost 7 years ago
Is there an alternative to userstyles.org for hosting styles? That site is run by the Stylish folks, and I have removed my account and styles from it.
评论 #17496211 未加载
yuberalmost 7 years ago
I wonder if Stylish is also able to data-mine the websites you visited while in incognito mode, since extensions don&#x27;t work there.<p>Does anybody have an idea?
eurticketalmost 7 years ago
Is there a system in place to update everyone on new ownership changes and implementation of anti user-good practices like this?
seba_dos1almost 7 years ago
Isn&#x27;t it a common knowledge? People were massively switching to Stylus long time ago.
评论 #17451268 未加载
pdimitaralmost 7 years ago
Sadly Stylus is not in the Safari&#x27;s plugins store.<p>Any alternatives for Mac users?
评论 #17451075 未加载
评论 #17496223 未加载
评论 #17479346 未加载
ccnafralmost 7 years ago
It&#x27;s not actually stealing if it&#x27;s in the ToS, is it?
评论 #17448696 未加载
akerroalmost 7 years ago
Dont google and mozilla review source code of addons?
评论 #17448317 未加载
评论 #17449231 未加载
sahin-boydasalmost 7 years ago
Are There any response from Stylish developer?
IngvarLynnalmost 7 years ago
&quot;OneTab&quot; is another popular extension with the same issue. Switched to ff+&quot;tabs aside&quot; since then.
评论 #17452766 未加载
评论 #17451598 未加载