Closed henvic closed 9 years ago
BTW, there is a paragraph in this Chrome extension description:
We are always trying to find a way to continuously improve JavaScript Errors Notifier, thus we've chosen Fairshare and Intenta as our trusted partner, which will collect the usage statistics from your browser. It's anonymous and will not include any of your privacy data. We concern about your data security as you always do. Please learn more about Fairshare privacy policy at https://fairsharelabs.com/analytics. Anyway, there is also alternative extension version, that does not collect any statistics: https://goo.gl/IRbqnY
If you think that it will be better when this extension will be banned for 86k users... then I'm not sure that you're enough smart to continue discussing this issue with you.
Intenta and FairShare are well known and trusted partners. In the same way Google Analytics collects users activity on 70% of web sites that they visit.
Your description there says it's anonymous and won't include any privacy data. This is a blatantly lie.
People, just like me, will download and use it in good faith without knowing it is sending all the links they browse to to your analytics web service with a token to uniquely identify.
Of course you know you can retrieve personal identifying information on links such as account ids, usernames, emails, purchase orders, photo links, and more.
It's one thing to add such scripts to your own site. It's another to add a script that inconspicuously sends private data for all sites you browse to the analytics account of someone when you install an extension that has nothing to do with it. And yeah, I know many - if not most - sites use some kind of analytics service but they don't do like it.
non-https links will be even sent entirely unencrypted allowing man-in-the-middle attacks as well (e.g., private network links might end up on the Internet not only for you; and, of course, you always get the private sensitive data you claim you don't).
PS: You certainly have an attitude problem. Trying to play down this by saying you have something on the fine print and implying I am dumb? Really?
This is no better than Lenovo shipping laptops with adware that hijacks HTTPS connections.
I've sent feature request to Intenta to use SSL, if they'll not change protocol I'll disconnect extension from their service.
Intenta and FairShare works with statistics information in the same way. Read this https://www.fairsharelabs.com/privacy
Anyway, there is also alternative extension version, that does not collect any statistics: https://goo.gl/IRbqnY
Fair improvement.
Henrique, sorry, but I can't fix your paranoya. I have much more important things to do.
Thanks. No need to worry about me, though. I am not going to bother you anymore.
PS: something smells fishy for Gmail, what a hilarious coincidence, isn't it? :smile:
@barbushin Sorry man, this isn't a localized issue. It's quite necessary to look after your personal concerns over one impression and consider real facts to deal with this situation.
Suppose that if me, employed on one organisation that is supposed to be compliance with HIPAA statements, became a target on a trial, because while I was debugging one app of ours, it leaked data about medical issues of some patient.
You'll, then, explain to them that they are over reacting about this situation?
No, you'll not.
@mateusleon But why you can't just use alternative extension version, that does not collect any statistics: https://goo.gl/IRbqnY?
Google has policies for the Chrome Web Store and this extension doesn't abide by it. I have highlighting just a few points below.
People usually are nice to each other and abide by them. This is why we can have nice things.
Don't deceive your users.
We’ve found that most unwanted software displays one or more of the same basic characteristics:
Thanks @henvic. Your post proves my point.
But there is a paragraph in description explaining Intenta and FairShare usage. What is wrong?
BTW, there is one more extension with 864k users that is also integrated with FairShare https://chrome.google.com/webstore/detail/speakit/pgeolalilifpodheeocdmbhehgnkkbak
And this one, 240k users https://chrome.google.com/webstore/detail/fb-color-changer/kfmpgofbpmkihnamkhcoohnmipjkfjph
And this one about Intenta https://chrome.google.com/webstore/detail/chrome-currency-converter/anbfhidldjknonaihbalghlebaijealk
And this also https://chrome.google.com/webstore/detail/screen-shader/fmlboobidmkelggdainpknloccojpppi
After refusing the offers of multiple fishy ad and url gathering companies, I have partnered with a good-hearted startup named Intenta who use anonymous url data to improve the relevancy of ads on the internet. So basically if you are, for example, looking to buy a book, and Intenta is partnered with a company that sells the same book for a smaller price, then you might later see their ads for the cheaper book instead of other less relevant ads, so you get some good deals and save a bit of money while I get paid a few cents for my +400 hours of work on Screen Shader.
Installing an ad-blocker, of course, will nullify intenta's effects for those who don't want good deals when shopping online.
I've forced Intenta to use SSL for statistics data requests https://github.com/netplenish/intenta-extension-sdk/releases/tag/2.0.4
Released JEN v2.1.24 that works over SSL.
hey @barbushin , i see you have mentioned the removal of FairShare & Intenta ... can you link the commits?
hey
FairShare integration was not in GitHub, it was added to code manually(to manifest.json) before uploading to WebStore, so there is no commits about it.
but you can review source code of last extension version by yourself, just search directory with name jafmfknfnkoekkdocjiaipcnmkklaajd
on your hard drive
And yes, it was completely removed.
@barbushin awesome news... out of curiosity, why the change of heart?
Have you considered other means to monetize?
This decision is about -$5000 of my yearly income, but, anyway, it makes me feel better :)
Right now I'm developing some errors and logs tracking/monitoring/aggregation/reporting/managing service for web-developers. I hope to get release in this Summer, so I will try to announce it inside JavaScript Errors Notifier. It will be not aggressive AD message displayed inside JEN error popup only once, and then it will be automatically removed if user will not be interested to click it.
Hello,
I have just posted on Hacker News and reported your extension to Chrome's webstore team after freaking out when I was debugging a web service of mine with Charles and found some strange requests.
Please, don't take this as a hateful message. I really enjoy your extension, but it's just too invasive. I know you say it collects data on the fine print at the store, but most of the extensions that does so anonymize the data first. I myself maintain some CLI tools and had to create a anonymizer to avoid collecting more data than user's would be comfortable sharing. https://github.com/node-gh/gh/blob/master/lib/cmd-anonymizer.js
Feel free to contact me if you have questions or need help.
Sorry for not trying to contact you first, but my first reaction was to alert people and find out more. Just then I realized it was almost certainly not intentional.
My link to the Hacker News post is https://news.ycombinator.com/item?id=10309432