Site icon WinCert

Stylish extension banned for tracking site visits

<p>Stylish&comma; an extension for Chrome&comma; Firefox and Opera browsers has just been banned for tracking users and sending their browser data to remote servers&period; This popular extension had more than 2 million downloads before it was pulled by Mozilla&comma; Google&comma; and Opera&period;<&sol;p>&NewLine;<p><img class&equals;"alignnone wp-image-2657 size-full" title&equals;"stylish" src&equals;"https&colon;&sol;&sol;www&period;wincert&period;net&sol;wp-content&sol;uploads&sol;2018&sol;07&sol;statistics&period;jpg" alt&equals;"stylish" width&equals;"640" height&equals;"423" &sol;><&sol;p>&NewLine;<p>With the Stylish extension&comma; users were able to customize the look and feel of various websites within their browser&period; Some of the features include changing black on white to white on black site themes&comma; changing normal pictures to black and white or removing Facebook and Twitter news feeds&period;<&sol;p>&NewLine;<p>According to software engineer Robert Heaton&comma; back in January 2017&comma; this extension started collecting browser activity data and sending it back to its servers&period; Collected user data contained unique identifiers that could be used to link email addresses or other attributes with users&period;<&sol;p>&NewLine;<p>Heaton discovered the tracking code with a Burp Suite&comma; a comprehensive security testing tool mainly used to identify vulnerabilities affecting web applications&period; He found that Stylish extension was sending a large amount of obfuscated data to userstyles&period;org that was a site from the new Stylish owner&period; After Heaton has decoded the data that was sent to remote servers he discovered that Stylish was collecting Google Search results along with the history of visited URL&&num;8217&semi;s&period;<&sol;p>&NewLine;<p>According to Heaton&comma; Stylish has been collecting the browser history from Chrome users since January 2017&comma; while Firefox users were started being tracked only a couple of months later&comma; since March 2017&period; Even though the data collection was disclosed in the privacy notice&comma; it hasn&&num;8217&semi;t caught much attention by Mozilla&comma; Opera&comma; and Google&comma; along with the two million users that were using Stylish extension&period;<&sol;p>&NewLine;<p>This event reminds us that Browser makers don&&num;8217&semi;t do a detailed check of extensions they host in their stores and that we should pay more attention before using them&period;<&sol;p>&NewLine;

Exit mobile version