TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

I no longer trust The Great Suspender

889 点作者 davidfstr超过 4 年前

57 条评论

fancy_pantser超过 4 年前
As the developer of a pretty popular &quot;utility&quot; browser extension, I&#x27;ve been shocked by the volume of email I get every week about it.<p>On a daily basis, I will get requests to sell the extension. Once or twice a week, I will receive an offer to add &quot;a couple lines of code&quot; to my extension which are always generously described as &quot;allowed in the Chrome Web Store&quot; by little fly-by-night organizations that only even have a landing page half the time and usually have throwaway-looking gmail accounts. Out of curiosity, I&#x27;ve asked a few what their code does and they never fully describe it, but it either collects analytics to ship home (my extension runs on all sites, so it&#x27;s appetizing to them!) or places paid results at the top of any search results, for which I can make &quot;thousands of dollars a month based on the number of North American users I have&quot;.<p>Here is an example email I received yesterday. It&#x27;s a good example of how they call it &quot;an SDK&quot; and looks like one of the more legit ones (they registered a domain to send email from, at least).<p><pre><code> We at [redacted] are considering purchasing the complete license and ownership of the extensions which have 50K+ active users, may I know if you would be interested in selling? If so, - what is your estimated price? Regarding the SDK monetization which we discussed earlier, as it is not distractive and is compatible with any other monetization. We have straightforward terms and provide support for your users agreement. Our partners generate 3-20 K USD monthly with our solution for the browser extensions. As a kind reminder, we are [redacted] — a reputable global peer-to-peer ethical proxy network. All our clients are big reputable companies, we authorize their business before providing any proxy plans. Look forward to your further feedback and discussing further details of our financial proposal for your Software in a short Zoom call or here by emails. </code></pre> Finally, I am also hounded by teams at Microsoft and Apple, who want me to port the extension to their new plugin ecosystems so it can be featured&#x2F;showcased. I worked with Apple on one similar thing for an extension and it caused such a huge jump in support and feature requests from users that I was overwhelmed, so I am not keen to do it again until I have more free time. They can&#x27;t understand why I don&#x27;t want to grow by tens of thousands of users a week, but I&#x27;m just one person and don&#x27;t make money from it whatsoever.
评论 #25849135 未加载
评论 #25848888 未加载
评论 #25848733 未加载
评论 #25868038 未加载
评论 #25848514 未加载
评论 #25849301 未加载
评论 #25849278 未加载
评论 #25848442 未加载
评论 #25855784 未加载
评论 #25852535 未加载
评论 #25851025 未加载
评论 #25852115 未加载
评论 #25852931 未加载
评论 #25849096 未加载
评论 #25848463 未加载
评论 #25880620 未加载
评论 #25852906 未加载
评论 #25848445 未加载
评论 #25848531 未加载
bijant超过 4 年前
This is really Google&#x27;s fault. They make it impossible to turn off automatic updates for Chrome extensions from their store. That would be kind-of-ok if they actually had a rigorous approval process. But they don&#x27;t. The Chrome Web Store has become one of the prime Vectors for malware. The only way to be safe is to exclusively download releases from the extensions github repo and to manually install them.
评论 #25846916 未加载
评论 #25848753 未加载
评论 #25850429 未加载
评论 #25848391 未加载
评论 #25848364 未加载
评论 #25847618 未加载
评论 #25848139 未加载
评论 #25846876 未加载
kburman超过 4 年前
Here&#x27;s list of other extensions which have been recently flagged by community for similar behaviour<p>- Auto Refresh Premium, static.trckljanalytic.com<p>- Stream Video Downloader, static.trckpath.com<p>- Custom Feed for Facebook, api.trackized.com<p>- Notifications for Instagram, pc.findanalytic.com<p>- Flash Video Downloader, static.trackivation.com<p>- Ratings Preview for YouTube, cdn.webtraanalytica.com<p>Copied from <a href="https:&#x2F;&#x2F;github.com&#x2F;greatsuspender&#x2F;thegreatsuspender&#x2F;issues&#x2F;1263#issuecomment-760600299" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;greatsuspender&#x2F;thegreatsuspender&#x2F;issues&#x2F;1...</a>
评论 #25851312 未加载
评论 #25849018 未加载
评论 #25848413 未加载
评论 #25848721 未加载
评论 #25849951 未加载
评论 #25851014 未加载
AlphaWeaver超过 4 年前
Quick note about the workaround mentioned in this article - the suggestion to download the last known good version of the extension and sideload it is a good one, but it has some problems on Chrome.<p>Chrome has features to dissuade users from installing extensions from outside the Chrome Web Store. If you load an unpacked extension, Chrome will issue an ominous warning (something like “this extension is untrusted, click here to uninstall”) on every launch.<p>One could argue this is for security, but this change was implemented around the same time that Google disabled the ability to self-host extensions that install into Chrome. Really this is a mechanism to shut out independent extension developers from any potential plausible third-party distribution method that doesn’t rely on the Chrome Web Store (which Google controls and aggressively moderates.)<p>Use Firefox.
评论 #25847228 未加载
评论 #25847816 未加载
评论 #25850677 未加载
评论 #25847320 未加载
评论 #25849196 未加载
评论 #25847947 未加载
评论 #25853948 未加载
评论 #25847711 未加载
Centigonal超过 4 年前
More discussion on GitHub: <a href="https:&#x2F;&#x2F;github.com&#x2F;greatsuspender&#x2F;thegreatsuspender&#x2F;issues&#x2F;1263" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;greatsuspender&#x2F;thegreatsuspender&#x2F;issues&#x2F;1...</a><p>Quite similar to what happened to Nano Adblocker&#x2F;Defender a few months ago.
评论 #25846773 未加载
评论 #25847406 未加载
alyandon超过 4 年前
The MS Edge dev channel has a basic form of tab suspending built into it now. Based on my non-rigorous testing it seems to actually save more memory than TGS ever did so I just removed the extension entirely.<p>It is really a shame that basic functionality like this isn&#x27;t built into more browsers and we have to rely on extensions to fill the gaps just to keep memory usage under control for tab-a-holics like myself. :(
评论 #25848144 未加载
评论 #25847085 未加载
评论 #25849282 未加载
评论 #25851164 未加载
imedadel超过 4 年前
I recently switched to Auto Tab Discard.[1] It uses the browser&#x27;s built-in tab suspending. It doesn&#x27;t have all the features of TGS, though.<p>Edit: OneTab[2] is also pretty good when you have lots of tabs open for research or work.<p>[1]: <a href="https:&#x2F;&#x2F;github.com&#x2F;rNeomy&#x2F;auto-tab-discard" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;rNeomy&#x2F;auto-tab-discard</a><p>[2]: <a href="https:&#x2F;&#x2F;www.one-tab.com&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.one-tab.com&#x2F;</a>
评论 #25855349 未加载
评论 #25854119 未加载
评论 #25848261 未加载
评论 #25848111 未加载
Androider超过 4 年前
In Chrome, make sure you set your less frequently used extensions to run &quot;On click&quot; instead of &quot;On all sites&quot;. Extensions -&gt; extension details -&gt; Site access.<p>For dev tools and such, I set a whitelist of the sites they&#x27;re allowed to run on, using that same extension details page. There&#x27;s no need for your JSON formatter etc. to run on every single page you visit. Also speeds up browsing.
brundolf超过 4 年前
Among other things, this is why when people say &quot;HN doesn&#x27;t need a dark mode, just use an extension&quot;, that isn&#x27;t a valid solution. For years now I&#x27;ve refused to install any extensions that aren&#x27;t too-big-to-compromise (which in practice - for me - means AdBlock Plus and maybe React Dev Tools), and that should be everyone&#x27;s policy. Any extension whose compromise wouldn&#x27;t damage the reputation of a billion-dollar organization is simply too juicy of an attack vector.
评论 #25850622 未加载
评论 #25853566 未加载
jancsika超过 4 年前
&gt; Disable analytics tracking by opening the extension options for The Great Suspender and checking the box “Automatic deactivation of any kind of tracking”.<p>&gt; Pray that the shady developer doesn’t issue a malicious update to The Great Suspender later. (There’s no sensible way to disable updates of an individual extension.)<p>Does Debian ship packages for individual browser extensions?<p>I mean, if they do I&#x27;m sure it&#x27;s not scalable and-- after spending time reading debuild manual-- a giant, archaic pain in the ass.<p>On the other hand, all these app delivery systems are so damned pernicious and require constant vigilance. We may have arrived at a moment in time where this is actually a difficult decision:<p>* pay somebody a living wage to burrow down into Debian&#x27;s WoT bureaucracy and add at least a selection of this functionality <i>without</i> phoning home<p>* continue playing the most tedious game of whackamole with a whackamole game that mines all our data in order to learn how best to beat all users at whackamole
评论 #25848525 未加载
评论 #25848091 未加载
mkj超过 4 年前
It seems auto-updating browser extensions are riskier than leaving them non-updated?
评论 #25846842 未加载
评论 #25849696 未加载
评论 #25846830 未加载
skrowl超过 4 年前
Just sent him this email:<p>Saw your article via HN.<p>As an easier permanent fix, just uninstall The Great Suspender and install Auto Tab Discard (<a href="https:&#x2F;&#x2F;add0n.com&#x2F;tab-discard.html" rel="nofollow">https:&#x2F;&#x2F;add0n.com&#x2F;tab-discard.html</a>). It does the same thing.<p>It&#x27;s available on:<p>Firefox - Auto Tab Discard – Get this Extension for Firefox (en-US)(<a href="https:&#x2F;&#x2F;addons.mozilla.org&#x2F;en-US&#x2F;firefox&#x2F;addon&#x2F;auto-tab-discard&#x2F;" rel="nofollow">https:&#x2F;&#x2F;addons.mozilla.org&#x2F;en-US&#x2F;firefox&#x2F;addon&#x2F;auto-tab-disc...</a>)<p>Edge - Auto Tab Discard - Microsoft Edge Addons (<a href="https:&#x2F;&#x2F;microsoftedge.microsoft.com&#x2F;addons&#x2F;detail&#x2F;auto-tab-discard&#x2F;nfkkljlcjnkngcmdpcammanncbhkndfe" rel="nofollow">https:&#x2F;&#x2F;microsoftedge.microsoft.com&#x2F;addons&#x2F;detail&#x2F;auto-tab-d...</a>)<p>or even if you&#x27;re still using Chrome - Auto Tab Discard - Chrome Web Store (<a href="https:&#x2F;&#x2F;chrome.google.com&#x2F;webstore&#x2F;detail&#x2F;auto-tab-discard&#x2F;jhnleheckmknfcgijgkadoemagpecfol" rel="nofollow">https:&#x2F;&#x2F;chrome.google.com&#x2F;webstore&#x2F;detail&#x2F;auto-tab-discard&#x2F;j...</a>)
评论 #25847346 未加载
评论 #25848158 未加载
评论 #25847642 未加载
asadkn超过 4 年前
I have always used The Great Discarder instead [1]<p>It&#x27;s by the same dev too but it uses Chrome&#x27;s Native Tab Discarding feature and I found it way more efficient (at the time I started using it a few years ago - haven&#x27;t compared recently).<p>[1] <a href="https:&#x2F;&#x2F;chrome.google.com&#x2F;webstore&#x2F;detail&#x2F;the-great-discarder&#x2F;jlipbpadkjcklpeiajndiijbeieicbdh?hl=en" rel="nofollow">https:&#x2F;&#x2F;chrome.google.com&#x2F;webstore&#x2F;detail&#x2F;the-great-discarde...</a>
评论 #25847510 未加载
评论 #25848288 未加载
AQXt超过 4 年前
&gt; Apparently recent versions of this extension have been taken over by a shady anonymous entity...<p>That&#x27;s something that worries me, whenever I install a software with trusted privileges.<p>Software companies can sell their products -- and user base -- to other companies without notice.<p>And it can be even worse in the free software world: think about all the updates that happen when you type `apt-get|yum|brew|npm|pip update`. What are the odds of a single dependency being taken over by a shady anonymous entity?
评论 #25847640 未加载
acdha超过 4 年前
This is why I stopped using extensions in any browser years ago unless it came from a trusted company I pay directly (i.e. 1Password). The broken economic model means that the developers always have pressure to cash in on a popular extension and Google has set things up to make abuse fast and easy with automatic silent updates and their usual skimping on human review. By the time the news about TGS came out most users already had the next release installed.
评论 #25851226 未加载
评论 #25854166 未加载
tyingq超过 4 年前
I&#x27;m now curious how much money the original developer was paid to hand it over. I imagine he&#x2F;she knew what the buyer&#x27;s plan was.
评论 #25847674 未加载
aitchnyu超过 4 年前
Why didnt browsers start warning users when an extension updated after changing owners?
评论 #25851218 未加载
twunde超过 4 年前
For those interested in understanding the security of Chrome extensions, duo introduced CRXcavator (<a href="https:&#x2F;&#x2F;crxcavator.io&#x2F;" rel="nofollow">https:&#x2F;&#x2F;crxcavator.io&#x2F;</a>) a while back, which does some risk scoring around permissions. It is chrome-only, and it doesn&#x27;t protect against this type of attack specifically, although you can look at the Potential External Communication section for possible issues.
frob超过 4 年前
Google Chrome now has tab grouping. In Beta, you can click on the group name and collapse the tabs. Based on their reload times, it seems chrome suspends the tabs in the background when you collapse the group.
评论 #25850304 未加载
评论 #25850044 未加载
EGreg超过 4 年前
And this is why we need to rethink how we do software distribution.<p>Package managers are nice for the lazy, but then we get stuff like this:<p><a href="https:&#x2F;&#x2F;qz.com&#x2F;646467&#x2F;how-one-programmer-broke-the-internet-by-deleting-a-tiny-piece-of-code&#x2F;amp&#x2F;" rel="nofollow">https:&#x2F;&#x2F;qz.com&#x2F;646467&#x2F;how-one-programmer-broke-the-internet-...</a><p>Actually you might be pulling a bunch of malicious updates in 2-3 modules deep in your dependency tree anytime.<p>As a society we should be moving away from a culture of “immediate” updates eg on Twitter etc. And go towards more “peer review” like in science. Otherwise we are putting responsibility on every individual to verify all sides of the story and get informed. They don’t and society gets more and more dicided. Imagine if a scientist tweeted at 3am and half their followers instantly believed them. Or if an open source contributor’s pull request was instantly accepted and pulled overnight by everyone. That’s why USA and other countries are now so divided politically. Individual responsibility of 100% of the downstream nodes is strange to outsource responsibility to.<p>I wrote about this back in 2012 predicting what would happen:<p><a href="https:&#x2F;&#x2F;magarshak.com&#x2F;blog&#x2F;?p=114" rel="nofollow">https:&#x2F;&#x2F;magarshak.com&#x2F;blog&#x2F;?p=114</a>
评论 #25846935 未加载
评论 #25847521 未加载
MarioMan超过 4 年前
There was a recent paper published at ACM CCS 2020 that attempts to identify malicious changes to extension updates. Might be worth a read.<p>You’ve Changed: Detecting Malicious Browser Extensions through their Update Deltas<p><a href="https:&#x2F;&#x2F;dl.acm.org&#x2F;doi&#x2F;10.1145&#x2F;3372297.3423343" rel="nofollow">https:&#x2F;&#x2F;dl.acm.org&#x2F;doi&#x2F;10.1145&#x2F;3372297.3423343</a>
asgrdz超过 4 年前
I disable automatic updates for all extensions, as well as personally reviewing the source of every extension before installation.<p>The review doesn&#x27;t take much time. What I look for:<p><pre><code> 1. The manifest for what network endpoints the extension is allowed to call. 2. Any URL in the code that is external to the extension. 3. Any remote network function (fetch&#x2F;XHR&#x2F;links) and traceback to the call sites. 4. Whether there is any obfuscated code or not. </code></pre> If anything found in those spots seems fishy &#x2F; unclear, I don&#x27;t install the extension.<p>Takes a few minutes, but catches most of the threat vectors. Skimming the code also gives me a sense of what sort of developer is behind the extension. Some code clearly shows a developer cares about privacy and &#x2F; or security, which unconsciously adds karma for that dev in my book.<p>Like others above, I don&#x27;t use many extensions, but those I use I have to trust.
weakboi超过 4 年前
Ironically, I tracked the real world identity of someone using stolen credit cards in my ecom site BECAUSE he posted a tutorial&#x2F;how-to on YouTube showing the vulnerability tool (script kiddie), under his real name. SMH. This won&#x27;t stop this information from being disseminated, but it may save some idiots from themselves.
qwerty456127超过 4 年前
By the way, is there an extension (I&#x27;m interested in both Firefox and Chrome) which would force all the new (background) tabs to be created in the suspended state (like if you had opened them in background and then restarted the browser) and only start loading after you actually open them?
评论 #25863920 未加载
评论 #25852138 未加载
评论 #25850824 未加载
dstick超过 4 年前
More detailed information can be found here: <a href="https:&#x2F;&#x2F;github.com&#x2F;greatsuspender&#x2F;thegreatsuspender&#x2F;issues&#x2F;1263" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;greatsuspender&#x2F;thegreatsuspender&#x2F;issues&#x2F;1...</a>
SiteRelEnby超过 4 年前
Either the second or third time it lost all my tabs was when I stopped trusting it.
orliesaurus超过 4 年前
Lifehack: export your suspended tabs as a flat file through the interface, uninstall the add on, then follow the downgrade as the blog suggests, at the end reimport your tabs from the flat file
Aardwolf超过 4 年前
Doesn&#x27;t chrome already suspend background tabs without plugin? At least I&#x27;m unable to properly have browser games running unless they&#x27;re in a visible tab.
评论 #25847057 未加载
mtoddsmith超过 4 年前
Seems there should be an extension which checks other extensions for nefarious activity or notifies you of the events that are mentioned in the article.
StellarTabi超过 4 年前
The lack of user control, lock files, granularity of controls over browser extensions has gone too far.
nojito超过 4 年前
Sleeping Tabs is a feature on MS Edge.<p><a href="https:&#x2F;&#x2F;www.windowscentral.com&#x2F;microsoft-edge-canary-can-put-your-tabs-sleep-save-memory" rel="nofollow">https:&#x2F;&#x2F;www.windowscentral.com&#x2F;microsoft-edge-canary-can-put...</a>
albertgoeswoof超过 4 年前
Or you can use <a href="https:&#x2F;&#x2F;www.one-tab.com&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.one-tab.com&#x2F;</a> or <a href="https:&#x2F;&#x2F;tab.bz" rel="nofollow">https:&#x2F;&#x2F;tab.bz</a> for a similar-ish use case
facorreia超过 4 年前
That&#x27;s why I don&#x27;t trust Chrome extensions. There have been too many instances of a popular instance being taken over to run malware. I don&#x27;t think Google&#x27;s handling of these security issues has been adequate.
nakodari超过 4 年前
Thanks for this! I&#x27;ve been using this extension for a long time and just removed it today. Honestly, with Macbook Air M1 there is no need for suspending tabs any more because the battery life is amazing, so that also helps.
bogomipz超过 4 年前
Did anyone Download the latest good version of The Great Suspender7.1.6) from GitHub and load it as an unpacked extension per the article?<p>Are there any potential downsides to this? I was also curious how does loading this format avoid updates?
wintermutestwin超过 4 年前
At this point, I would gladly pay good money for a browser that prevented ads and tracking, provided most of the standard plugin functionality oob and vetted the rest. This whole mess is a massive time suck.
评论 #25851821 未加载
评论 #25848848 未加载
jonas_kgomo超过 4 年前
I&#x27;ve been using Sidekick,it has done a lot for me in terms of substituting extensions like TGS, It has its own tool for tab grouping and sessions, plus adblock. It has been good for productivity
jakobpb超过 4 年前
Uh, just use Firefox. Problem solved for both functionality and security.
mikhailfranco超过 4 年前
Looks like the &#x27;last known good&#x27; version 7.1.6 is now blocked by the TGS server.<p>Workaround to reopen a page is just to cut&#x27;n&#x27;paste the original URL from a parameter at the end of the TGS URL.
评论 #25868765 未加载
vmception超过 4 年前
Uninstalled and reported.
AlexCoventry超过 4 年前
Is there a tool which will automatically reload <i>all</i> your extensions from disk, as described in the OP? Seems like a sensible default, from a security perspective.
TheRealPomax超过 4 年前
Is there a reason this extension still exists, given that tabs get heavily deprioritized when not in focus, and have been for many, many versions now?
评论 #25847990 未加载
评论 #25849298 未加载
mendelmaleh超过 4 年前
I expected this to be about Jack Dorsey&#x2F;twitter xD
Paul-ish超过 4 年前
I keep most of my extensions disabled most of the time. A lot of the extensions have particular uses and don&#x27;t always need to be active.
lanius超过 4 年前
I&#x27;m glad I decided to go with 32 GB of RAM for my current PC build. No longer need to close any tabs!
peanut_worm超过 4 年前
Why do people keep 100s of tabs open at a time? I get irritated if I have more than 8 open.
评论 #25847130 未加载
评论 #25847414 未加载
评论 #25849320 未加载
评论 #25847422 未加载
评论 #25851081 未加载
评论 #25847080 未加载
评论 #25848130 未加载
评论 #25847734 未加载
jeromeparadis超过 4 年前
There&#x27;s a reason why I don&#x27;t install any extension except a password manager.
MacroChip超过 4 年前
Does this extension add functionality beyond Chrome&#x27;s existing tab suspension?
pjmlp超过 4 年前
I just don&#x27;t use extensions, so no need to worry about such scenarios.
bugfix超过 4 年前
Wow, my Chrome RAM usage went from about 2GB to 8GB after removing TGS.
otterpro超过 4 年前
Wow, this is why just recently my Macbook pro was registering high CPU usage even when all tabs were asleep using Great Suspender. For some reason, Chrome was registering high CPU usage, and I thought it was some Chrome bug.
评论 #25848173 未加载
cwwc超过 4 年前
Lifesaver. Much obliged, davidfstr.
istorical超过 4 年前
anyone able to compare Tiny Suspender and Auto Tab Discard?
angryasian超过 4 年前
there really needs to be a better bookmarking solution.
iamspoilt超过 4 年前
Uninstalled. Period.
tra3超过 4 年前
A reddit link, from the blog post [0] has all the details for those who don&#x27;t use chrome.<p>TLDR: A popular extension was quietly sold off to an unknown party that subsequently added tracking&#x2F;analytics. Not specifically malware, but not trustworthy either.<p>Did I miss anything?<p>[0]: <a href="https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;KyleTaylor&#x2F;comments&#x2F;jowlt2&#x2F;open_source_development_the_great_suspender_saga&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;KyleTaylor&#x2F;comments&#x2F;jowlt2&#x2F;open_sou...</a>
tus88超过 4 年前
&quot;Shady&quot; take-over of plugins&#x2F;apps is just a big a suspicious fail as allowing apps to gain access to all contacts on mobile phones.<p>Google never really cared about user privacy at all.