TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Amazon Assistant lets Amazon track your every move on the web

178 点作者 staktrace大约 4 年前

13 条评论

ctvo大约 4 年前
Excellent article by the author.<p>The subtle point of delegating everything to remote services is your user doesn&#x27;t need to know when you&#x27;ve modify behavior. If Amazon were to bundle the content, you&#x27;d need to explicitly update your extension.<p>You&#x27;re delegating to Amazon that they&#x27;ll continue to respect your privacy (no claims were made they weren&#x27;t), but also their systems are secure, and will continue to be. This is too much trust to give any entity. No thanks.<p>From Amazon&#x27;s perspective, they probably have more than one team working on the extension. A coordinated deployment process at scale is painful. Allowing each team to deploy to its own endpoint and communicate with other components via message passing (events) is exactly how you&#x27;d expect a company that grew up on SOA to design.
TedDoesntTalk大约 4 年前
&gt; Putting these JavaScript files into the extension would have been possible with almost no code changes<p>The AMO team at Firefox used to outright ban addons with remote script injection. I guess it matters who you are -- like on the Apple App Store, big names just need to pull the right strings or call the right people for a free pass. Rules are not applied equally. The playing field is NOT level.
评论 #26392961 未加载
评论 #26395892 未加载
pkaye大约 4 年前
The assistant should play the tune of &quot;Every Breath You Take&quot; by The Police when its doing this.
评论 #26393520 未加载
评论 #26392972 未加载
评论 #26394696 未加载
antattack大约 4 年前
Seems to me that browser extensions need better access control. Why isn&#x27;t it possible to restrict it to just amazon.com itself, for example?
评论 #26391599 未加载
评论 #26391419 未加载
评论 #26395089 未加载
评论 #26390610 未加载
drewda大约 4 年前
Wasn&#x27;t this the shtick of the &quot;toolbar&quot; plugins offered by AOL, Yahoo, and even Google at one point over the years?
评论 #26391344 未加载
评论 #26393271 未加载
mgdev大约 4 年前
I designed this. I won&#x27;t speak to any past or current practices, but I will say this: Amazon is obsessive about protecting customer privacy.
评论 #26395994 未加载
评论 #26396037 未加载
评论 #26395877 未加载
tobib大约 4 年前
Oh my. Who in their right mind would install that?!<p>I just setup pihole today because it&#x27;s so difficult to avoid being spied on wherever you go.
评论 #26401144 未加载
unhba大约 4 年前
It will be interesting to see how the developers of this extension respond to Google’s roll out of extensions Manifest V3 - the new specification could almost be directly targeting them: with service worker replacing background script there will no longer be a concealed window to mount those iframes. Thanks to the author for this write-up
propogandist大约 4 年前
here&#x27;s a campaign [1] where Amazon was paying $5 credit to get this spyware installed on the browser. These campaigns have been going on for years.<p>[1] <a href="https:&#x2F;&#x2F;slickdeals.net&#x2F;e&#x2F;14668013-select-amazon-member-earn-5-amazon-credit-with-amazon-assistant" rel="nofollow">https:&#x2F;&#x2F;slickdeals.net&#x2F;e&#x2F;14668013-select-amazon-member-earn-...</a>
EastSmith大约 4 年前
Is there a need for iframes to exists <i>today</i>? Can we somehow block them?
joshgoldman大约 4 年前
This place is becoming like Reddit with the conspiracy theories
评论 #26394649 未加载
评论 #26393986 未加载
kevinsundar大约 4 年前
This is clickbait. The authors argument is that the extension has enough privileges to track you, not that it actually does.<p>For example, uBlock Origin has similar privileges but I doubt the author would bat an eye.<p>EDIT: I take back my comment :)
评论 #26391032 未加载
KoftaBob大约 4 年前
&quot;Still, I was astonished to discover that Amazon built the perfect machinery to let them track any Amazon Assistant user or all of them: what they view and for how long, what they search on the web, what accounts they are logged into and more.<p>Amazon could also mess with the web experience at will and for example hijack competitors’ web shops. Amazon Assistant log with a borg eye Image credits: Amazon, nicubunu, OpenClipart<p>Mind you, I’m not saying that Amazon is currently doing any of this.&quot;<p>This goes for any browser extension you install if you don&#x27;t limit which websites it&#x27;s allowed to read data from.<p>In both the title and beginning paragraph, the author essentially describes the privacy risks that would apply to any browser extension, but words it in a way that implies Amazon is actively abusing those privacy holes, before finding any evidence for it.<p>I really wish people would stop giving views to blatantly manipulative and slimy clickbait like this.
评论 #26389389 未加载
评论 #26390485 未加载
评论 #26390408 未加载