Check Your Browser Extensions: Many Now Hide Adware And Malware

Check Your Browser Extensions: Many Now Hide Adware And Malware

Bad news: : a lot of browser extensions are either injecting ads into the sites you visit, or are tracking your entire browsing history — possibly without you knowing. Here’s what’s going on.

As Ars Technica notes, a lot of now-dubious extensions started as good, honest, independent software that was subsequently purchased by adware companies. Then, through automatic updates, they added tracking features and/or ad injection and have been collecting data ever since. This isn’t difficult to pull off, since many extensions a href=”https://www.lifehacker.com.au/2013/03/ask-lh-why-do-chrome-extensions-need-to-access-all-my-data/”>already required permissions that were needlessly broad. They may have checkboxes in the settings that let you turn this behaviour off, or they may have disclosures located on the extension’s download page. But if you didn’t read the fine print or downloaded the extension before it updated, you probably had no idea this was happening.

From the How-To Geek’s explainer:

These extensions are “allowed” to engage in this tracking behaviour because they “disclose” it on their description page, or at some point in their options panel. For instance, the HoverZoom extension, which has a million users, says the following in their description page, at the very bottom:

“Hover Zoom uses anonymous usage statistics. This can be disabled in the options page without losing any features as well. By leaving this feature enabled, the user authorise the collection, transfer and use of anonymous usage data, including but not limited to transferring to third parties.”

Where exactly in this description does it explain that they are going to track every single page you visit and send the URL back to a third party, which pays them for your data? In fact, they claim everywhere that they are sponsored through affiliate links, completely ignoring the fact that they are spying on you. Yeah, that’s right, they are also injecting ads all over the place. But which do you care more about, an ad showing up on a page, or them taking your entire browsing history and sending it back to somebody else?

This particular extension has had a long history of bad behaviour, going back quite some time. The developer has recently been caught collecting browsing data including form data… but he was also caught last year selling data on what you typed in to another company. They’ve added a privacy policy now that explains in further depth what is going on, but if you have to read a privacy policy to figure out that you are being spied on, you’ve got another problem.

To sum up, a million people are being spied on by this one extension alone. And that’s just one of these extensions — there are a lot more doing the same thing.

The How-To Geek is putting together a solid list of extensions that exhibit this behaviour, including many that we’ve featured on Lifehacker (before they became adware), including Hover Zoom, CrxMouse, Hola Unblocker, SmoothGestures, and lots of others. Google has already removed a few of the higher-profile offenders, but as long as its policies allow for this, it will continue to be a problem. Mozilla has a few extensions that fall into this category too, though it seems to be less of a prominent issue for Firefox users.

I highly recommend reading the full article over at How-To Geek. It has a lot more detail on what happened and how to investigate the extensions you have installed. In addition, you should check out the list and see if you’re using any of the extensions on it.

Warning: Your Browser Extensions Are Spying On You [How-To Geek]

List of Tracking Extensions [How-To Geek Discussions]

Adware Vendors Buy Chrome Extensions to Send Ad- and Malware-Filled Updates [Ars Technica]


The Cheapest NBN 50 Plans

Here are the cheapest plans available for Australia’s most popular NBN speed tier.

At Lifehacker, we independently select and write about stuff we love and think you'll like too. We have affiliate and advertising partnerships, which means we may collect a share of sales or other compensation from the links on this page. BTW – prices are accurate and items in stock at the time of posting.

Comments


One response to “Check Your Browser Extensions: Many Now Hide Adware And Malware”