TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

“Stylish” extension with 2M downloads banned for tracking every site visit

29 pointsby jhackalmost 7 years ago

4 comments

dagenixalmost 7 years ago
This type of thing seems to keep happening. And there doesn&#x27;t seem to be a good solution. Browser vendors don&#x27;t want to scrutinize every extension available on their platforms since there is no financial incentive to. Notably, I don&#x27;t think extension authors want browser vendors to scrutinize their extensions as that would delay getting out updates and fixes. Users want vendors to catch all the bad stuff, but would probably be outraged on behalf of their favorite extension the second any review process went away (ie: users want the magical no downside approach).<p>So, it&#x27;s not really clear to me than anyone really wants a real review process created.<p>However, any extension which becomes popular instantly is put under pressure to sell to someone else who wants to do this type of nonsense. Of course, the extension author may not know which companies that want to buy their work want to viloate user privacy and which don&#x27;t - they just have an offer to pay for their work. So, even the authors that sell aren&#x27;t necessarily doing anything wrong (at least not intentionally).<p>And there doesn&#x27;t really seem to be a way for browser vendors to alert users when ownership of an extension changes - they may not even know, and even if they did, it seems unlikely that most users would know what to do with that information.<p>There just doesn&#x27;t seem to be anyone in this whole process that really has an incentive to make things better. It seems like the only reasonable advice is to avoid extensions or only use extensions from major companies - which is kinda sad advice.
评论 #17476041 未加载
LinuxBenderalmost 7 years ago
Could they have captured banking or other financial or sensitive data?<p>The author used burp, but couldn&#x27;t you also validate what is collected more explicitly by viewing the xpi contents for that add-on?
评论 #17477750 未加载
JdeBPalmost 7 years ago
Still open discussion of the original, of which this is a news report:<p>* <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=17447816" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=17447816</a>
stephengilliealmost 7 years ago
It&#x27;s remarkable that uMatrix and uBlock Origin haven&#x27;t sold out yet. What will we do if&#x2F;when they do?
评论 #17476424 未加载
评论 #17476426 未加载