Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Application Security

End of Bibblio RCM includes -->
7/6/2018
08:05 AM
Larry Loeb
Larry Loeb
Larry Loeb

Google, Firefox Pull Stylish After Report Shows How Data Is Collected

A security researcher showed how the Stylish browser extension sent personal data and search results back to the parent company, and this forced Mozilla and Google to yank it off their stores.

It started out as a way to make the Internet look the way you wished it to. But it ended up spying on what you were doing on it, and sending the information to a marketing company.

Welcome to 2018.

The Stylish Chrome and Firefox browser extension gave users a way to change how they viewed sites. They had user-made skins that would give bright websites a dark background, could undo user-disliked UI changes, and or even add graphics to please the user's sensibilities. It even had a CSS editor that could remove unwanted parts of a page.

A user could change things around to the way they wanted things to look.

The Google Chrome page for Stylish before it was pulled\r\n(Source: Google)\r\n
The Google Chrome page for Stylish before it was pulled
\r\n(Source: Google)\r\n

But since January 2017, the websites visited by the 2 million users of the extension have been recorded. The original owner and creator of Stylish sold it in August 2016 to someone that resold it to SimilarWeb. The intent of SimilarWeb has not exactly been a secret. But the exact way the company was going to do things has not been clear.

However, security researcher Robert Heaton stumbled upon what the extension was actually doing, and started to yell rather loudly. He found that all of the URLs of accessed pages were being sent to the company, including the full results of Google searches.

As Heaton put it:

The SimilarWeb family's promotional literature lists "Market Solutions To See All Your Competitors' Traffic" amongst its interests. I'm starting to feel like I might have become the product. I understand that it probably isn't SimilarWeb company policy to threaten to show their users' browsing history to their mothers and rabbis unless they hand over a big pile of cash. But it wasn't Equifax company policy to lose all those Social Security Numbers either.

This led to Mozilla taking active blocking against the extension.

Mozilla software engineer Andreas Wagner wrote in the bug report : "We decided to block [Stylish] because of violation of data practices outlined in the review policy." Another user noted that "it will be disabled, not removed. Users will get a warning though with a request to (optionally) restart the browser."


Boost your understanding of new cybersecurity approaches at Light Reading's Automating Seamless Security event on October 17 in Chicago! Service providers and enterprise receive FREE passes. All others can save 20% off passes using the code LR20 today!

Also, the Stylish Firefox add-on page has been removed.

The Stylish Chrome Web Store page currently gives a "404" error, so they have taken action as well.

There is an open source alternative named Stylus that can do most of what Stylish could do. "It is a fork of Stylish that is based on the source code of version 1.5.2, which was the most up-to-date version before the original developer stopped working on the project," according to Stylus.

It's available for Chrome, Firefox and Opera browsers.

Related posts:

— Larry Loeb has written for many of the last century's major "dead tree" computer magazines, having been, among other things, a consulting editor for BYTE magazine and senior editor for the launch of WebWeek.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Incorporating a Prevention Mindset into Threat Detection and Response
Threat detection and response systems, by definition, are reactive because they have to wait for damage to be done before finding the attack. With a prevention-mindset, security teams can proactively anticipate the attacker's next move, rather than reacting to specific threats or trying to detect the latest techniques in real-time. The report covers areas enterprises should focus on: What positive response looks like. Improving security hygiene. Combining preventive actions with red team efforts.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2022-1813
PUBLISHED: 2022-05-22
OS Command Injection in GitHub repository yogeshojha/rengine prior to 1.2.0.
CVE-2022-1809
PUBLISHED: 2022-05-21
Access of Uninitialized Pointer in GitHub repository radareorg/radare2 prior to 5.7.0.
CVE-2022-31267
PUBLISHED: 2022-05-21
Gitblit 1.9.2 allows privilege escalation via the Config User Service: a control character can be placed in a profile data field, such as an emailAddress%3Atext '[email protected]\n\trole = "#admin"' value.
CVE-2022-31268
PUBLISHED: 2022-05-21
A Path Traversal vulnerability in Gitblit 1.9.3 can lead to reading website files via /resources//../ (e.g., followed by a WEB-INF or META-INF pathname).
CVE-2022-31264
PUBLISHED: 2022-05-21
Solana solana_rbpf before 0.2.29 has an addition integer overflow via invalid ELF program headers. elf.rs has a panic via a malformed eBPF program.