little-rat
crxmon
little-rat | crxmon | |
---|---|---|
8 | 2 | |
2,001 | 24 | |
- | - | |
6.9 | 8.3 | |
7 months ago | 2 months ago | |
JavaScript | TypeScript | |
MIT License | - |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
little-rat
-
Detect when your installed Chrome extensions have changed owners
Great idea! We need a lot more visibility into what extensions are doing. I made little-rat [1] last year, to detect network calls coming from other extensions. Love to see more tools like yours!
[1] https://github.com/dnakov/little-rat
-
Browser extensions spy on you, even if its developers don't
It says 1.0 in the extensions manager, but it was downloaded fresh this evening by clicking on the 'ZIP' link in your readme.md on here:
https://github.com/dnakov/little-rat/tree/main
-
uBlock Origin Lite now available on Firefox
2: https://github.com/dnakov/little-rat
-
Little Rat Chrome extension works Caught Midnight Lizard monitoring my browsing
I recently installed the Little Rat chrome extension, which I found here on HackerNews.
https://github.com/dnakov/little-rat
And what I found is that the Midnight Lizard chrome extension is monitoring my browsing-- sending home screenshots.
You can see examples here: https://ibb.co/JQvgt3p
Apparently my browsing data is being ingested by a company called "Mark Monitor Inc." (based on WhoIs search for the domain the data is sent to -- https://www.whois.com/whois/ytimg.com )
-
Show HN: Little Rat – Chrome extension monitors network calls of all extensions
Nifty - but please do this more carefully:
https://github.com/dnakov/little-rat/blob/main/popup.js#L36
I do not want to have to worry about whether another extension can inject xss into yours with a crafted request/id/name.
crxmon
-
Detect when your installed Chrome extensions have changed owners
> How is this even possible that Google allows this? Is this really true?
Yes, you only need to upload the key (meaning, include a `key.pem` in your packed zip file) on first upload. [0]
However, I'm not sure if Google will allow you to upload with a _different_ key. Since the extension would change, I'm not sure what would happen, both to the webstore page (does the previous one 301 to the new one?) and to existing extensions (do they stop auto-updating?).
> This weekend Chrome decided to disable all these extensions on just one machine
There is a trick for this, if you are loading an unpacked extension. Simply edit `manifest.json` in the unpacked extension directory, to add a `"key": ""`. You can do this with any extension from the store, since you can extract the public key from a .crx file [1]. When you load an extension this way, the ID will be the same as the "real" extension.
[0] https://groups.google.com/a/chromium.org/g/chromium-extensio...
[1] https://github.com/milesrichardson/crxmon/blob/4dae445b05b76...
What are some alternatives?
uBOL-home - uBO Lite home (MV3)
webextensions - Charter and administrivia for the WebExtensions Community Group (WECG)
youtube-chapters-in-player - Web extension that shows YouTube chapters right in the player.
murder - Large scale server deploys using BitTorrent and the BitTornado library
uBlock-Safari - uBlock Origin - An efficient blocker for Chromium, Firefox, and Safari. Fast and lean.
hosts - 🔒 Consolidating and extending hosts files from several well-curated sources. Optionally pick extensions for porn, social media, and other categories.
example-chrome-extension - Example Chrome Extension - open source examples for Chrome extension APIs
AdGuardSDNSFilter - AdGuard DNS filter
AdGuardHome - Network-wide ads & trackers blocking DNS server
hoverzoom - Google Chrome extension for zooming images on mouse hover
AdGuardDNS - Public DNS resolver that protects you from ad trackers
cname-trackers - This repository contains a list of popular CNAME trackers