Skip to content

Comment on We busted a fake Chrome extension that was trying to steal data

Comments

Well, that was a fun way to find out you have a malicious app installed in your browser.

It would be nice to have an overview of what exactly was exported to know the impact of this breach (without having to use reveal(x) myself).

cwsOP

It was sending off URLs visited by the host machine. Browsing history, essentially, which could be benign except that when your machine is inside a corp network you might be visiting all kinds of internal resources with URLs that shouldn’t be public/with sensitive info included in the resource locator, GET/POST contents, etc

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.