Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'd like to hear more about your experience. Was it a previously straight-laced extension that, upon acquiring a decent user base, then decided to update with ad injections? What function did the extension serve? If it did start serving ads after an update, did the update also ask for additional permissions, or did it zealously ask for more than it needed originally, if its function did not legitimately call for that sort of access?


I had installed a Safari extension that was designed to let me auto-reload a tab on a sechedule. I never really used it. I can't think of the name.

One day it updated itself and started replacing IAB sized HTML containers with ads. I only noticed because I was doing testing with Safari and the player I expected to be loading was being replaced by an ad.


I'd be completely comfortable with calling that malware.


I was also using YAGBE. From what I can tell yah they hit a critical mass and decided to add in ads. No permission changes as far as I can tell. I think I filed a ticket with Google a while ago... it seems like a serious security flaw to me.


I used YAGBE (Yet Another Google Bookmarks Extension) and it was really nice until it pulled this trick. No additional permissions were asked for IIRC, so it probably asked for what it needed at first.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: