Skip to content

Comment on Browser extensions spy on you, even if its developers don't

Comments

Browser extensions must be open-source. If you can't find the extension's sources, you can be sure it's malware.

That's bullshit. My extensions are not malware. I sell upfront paid extensions to end users. As always, if you're not the customer, you're the product. That's the problem with all of these free extensions: they have no clear business model.

I don't recall ever receiving an offer to acquire my extensions. I'm not sure why: perhaps because they're Safari, perhaps because they're upfront paid, perhaps because the user base is smaller than free extensions, or some combination of those factors. In any case, these scammers are looking for volume, as many users as possible, because the amount of money they can make per user is small, especially compared to how much I can make per user from a direct purchase.

If you don't mind me asking, how much revenue do you get per month from all your paid extensions?

I won't give exact numbers, but I make 6 figures per year, enough to support myself as a sole proprietor.

Damn, I need to make an extension. Any advice on any good material for how to write a good extension?

Damn, I need to make an extension.

Well, I wouldn't recommend quitting your day job, if you have one. The indie lifestyle can be very difficult.

Any advice on any good material for how to write a good extension? reply

I mostly just read the docs from the browser vendors.

I quit my day job two weeks ago to join the indie lifestyle, so too late. :)

In that case, you can email me if you need a little extension help.

My extensions are not malware. I sell upfront paid extensions to end users. As always, if you're not the customer, you're the product

While I appreciate your point about the business model, your statement that your extensions are not malware is not verifiable.

your statement that your extensions are not malware is not verifiable.

Well, my "malware" had its 5th anniversary earlier this year. So I must be one of the world's greatest malware authors.

Not to mention that I scammed a bunch of members of the tech media into publishing recommendations of my malware.

To be clear, I am not attacking or accusing you of anything - I am just having a conversation about trust in an environment where the vast majority of big players have demonstrated that they shouldn't be trusted.

I am just having a conversation about trust

It all comes down to trust, I think, not source code. How many of the "open source only" proponents have read and analyzed the source code? How many of them have verified that the shipping product is exactly the same as the source? Almost nobody, I suspect.

A relatively small number of people actually work on open source, even with the biggest, most popular projects. The number of eyeballs on the source is a lot smaller than you might expect.

the vast majority of big players have demonstrated that they shouldn't be trusted

I'm not a big player, just an indie dev.

As always, if you're not the customer, you're the product.

All too often you can be the customer and still be the product. It's great if you genuinely aren't selling out your paying users, but you're increasingly the outlier there

That's the problem with all of these free extensions: they have no clear business model.

Not every extension needs a business model. Many exist just because someone was passionate enough about a problem to come up with a solution and they were happy to share what works for them with others. Not everything has to be about getting rich. Many of the best things aren't.

Not every extension needs a business model. Many exist just because someone was passionate enough about a problem to come up with a solution and they were happy to share what works for them with others. Not everything has to be about getting rich. Many of the best things aren't.

True, but just as money can run out, so can passion. And everyone needs to make a living somehow.

Most of the big open source projects have corporate funding and engineers who are paid to work on them. I continue to be puzzled about how Raymond Hill, the developer of uBlock Origin, makes a living, and how he has time to continue to work on the extension. Does anyone know?

Note that even Hill's passion wanes. "The uBlock project official repository was transferred to Chris Aljoudi by original developer Raymond Hill in April 2015, due to frustration of dealing with requests." https://en.wikipedia.org/wiki/UBlock_Origin?#uBlock This is how uBlock became uBlock Origin, and Hill's trust in Aljoudi turned out to be misplaced. Open source is no savior.

More recently, Hill said this: "What would actually help is that people help to completely investigate existing issues instead of keep asking me to add yet more features. Turns out people willing to step in the code to investigate and pinpoint exactly where is an issue (or that there is no issue) is incredibly rare." https://www.reddit.com/r/uBlockOrigin/comments/i240ds/commen...

Thus, I still think a business model is important, even crucial. Without sustainable funding, the future of any software project becomes highly questionable.

As always, if you're not the customer, you're the product.

FOSS is the exception to that rule.

It's not, though. Free extensions are most likely to sell out. Notice what the author did not say: "If you can find the extension's sources, you can be sure it's not malware."

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.