Hacker Timesnew | past | comments | ask | show | jobs | submitlogin

Can anyone fathom a potentially benign reason Amazon might do this?


Read the article. The configuration from amazon is only set up to gather https data on amazon sites. Because the configuration was sent over http, he used a man in the middle attack to change it to a wildcard, and gather all https data.

Amazon wasn't being evil, just incompetent. Never attribute to malice what can adequately be explained by stupidity...


So logging every single URL you visit and every search you make on Google isn't evil? This is the kind of nasty extension that your browser warns you about when you open a private/incognito window. I realize you were just talking about the HTTPS aspect of it, but your parent asked about the generic "this".

It's pretty clear they "might do this" so they can data-mine your browsing activity, which is now associated with your account, and serve you more targeted ads and product recommendations. So I guess we have to extend your catch-phrase with "...and never attribute to stupidity what can be adequately explained by greed."


> every single URL you visit and every search you make on Google isn't evil

No, it's not evil, it's the the point of the extension -- to do product search.

If you don't like the product, you don't have to use it, but you can't say you want it, and then say it's evil for doing exactly what it says on the tin.


No, keep reading. It is more targeted than that. It sniffs the results of your Google searches , and sends the result over HTTP (not HTTPS) to Alexa. (See "It reports contents of certain websites you visit to Alexa") It knows you are searching Google because they have a special whitelist that detects when you are visiting Google's URLs, even the encrypted ones.

This behavior looks premeditated to me.


What about the script that they inject to every page you ever visit? Its completely useless - it contains an empty script and does nothing at all. What reason would they have to add this?

That simple empty script allows them, at any point in the future, to remotely inject scripts that'll have full permissions over any website you visit, without having to push an extension update or have it as part of their core extension code.

They can also choose to send it to specific individuals, or only for specific websites (their script URL gets the visited page as an query string argument), making something like this extremely difficult to detect.

And of course, this could also be abused by someone who hacks their servers. He could, for example, inject a script that sends the user/password whenever you login to a bank or paypal.

Having remote code execute on every page you ever visit is either extremely stupid or an extremely smart way to spy on people without being detected. When the code is part of the extension itself and not remote it: 1) has to be signed (making abuse harder for a malicious hacker) and 2) can be more easily audited, as all users of the extension would get the "spying code" (making abuse harder for a malicious company)

edit: wording


that saying is only good if you are talking about an individual, not a company...


I don't see even that intended purpose as benign in any way, though.


Not entirely benign, but understandable: above all else, Amazon wants to know exactly what search results Google shows you for particular queries, so they can better understand Google's ranking policies.

They can't otherwise scrape search results as you, and getting the info as an anonymous user isn't nearly as valuable. So they need you, via an extension or toolbar, to (perhaps inadvertently) opt-in to letting them collect the data 'over your shoulder'.


The code injected into every page could be for some interaction with Amazon affiliates code...


ignorance


Then why would they state : "The Amazon Browser Apps may also collect information about the websites you view"


I'd wager that's standard boilerplate for just about any extension that can manipulate the DOM.


Never attribute to malice what you can attribute to incompetence.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: