• 0 Posts
  • 5 Comments
Joined 3 years ago
cake
Cake day: July 12th, 2023

help-circle

  • This feels like a good post to mention AdNauseam! For anyone who wants an adblocker that helps more than just you! It basically blocks ads but also sends a click request to every ad that should have been loaded. The data being sent with this request contains spoofed garbage data that makes the tracking data sets lose value. It also keeps a funny metric on how much the estimated cost for your clicks is :)


  • Basically same,

    • Linux and Graphene
    • IronFox/Zen Browser with Adnauseam, Sponsorblock, DeArrow and ClearURLs
    • Mullvad VPN with AdBlock (off because of Adnauseam).
    • GrayJay instead of YouTube.
    • SimpMusic + Locally downloaded songs for music.
    • Local media server for movies

    Only places i have yet to tighten privacy (AFAIK) is email and chats (did make a burner acc on Discord and deleted the old one though). I dont use social media apart from the fediverse. All those accounts are deleted.

    Update:

    I do use K9 Mail and Thunderbird for email clients and F-droid and Aurora Store as an app store replacement.


  • Your comment seems very dismissive in the way you phrase this as intended behaviour. A security flaw like this can impossibly be intended behaviour.

    In my previous comment i also say thats calling it malware is a bit far-fetched but the security issues are absolutely there and should not be dismissed as “intended behaviour”. Especially not by a company like Anthropic.

    I am not well versed in extension development but is there anything stopping me from making an open source extension and just defining the ID as one of the three in the article? It most likely couldnt be released via the chrome addon store but if it is installed outside of thar? And how are these IDs read after install, could it potentially be altered by something from the outside?

    I immediately see so many flaws with this implementation it is worrying that a company the size of Anthropic does this.


  • Even if this was an opt-in feature the implementation is still terrible and a massive security hole. If id wanted the desktop app entirely and solely for this purpose i still would not expect my browser extension to have full access to my computer. I understand the app does, not the browser extension.

    No matter how you twist and turn this situation Anthtopic has still introduced a major security issue in their application. It might be a bit far to call it malware immediately but it sure does open up a massive attack vector to take advantage of.

    The fact that the end user is not even informed or have a choice about this makes it all the more problematic and Anthropic not commenting on it makes me think its either intentional or at the very least already known.