Privacy - Wat niemand over je mag weten

Populaire app voor steam verzamelt privacy gevoelige informatie over browsing activiteit

21-09-2017, 08:57 door Anoniem, 3 reacties
Steam Inventory helper.
https://steamcommunity.com/groups/SteamInventoryHelper

Sinds kort (nieuwe update van SIH), verzamelt deze chrome plugin info over al je browsing activiteit.
Zie ook: https://www.reddit.com/r/GlobalOffensive/comments/70xofs/warning_trusted_steam_inventory_helper_now/



I have just analyzed the current code of Steam Inventory Helper. Step by step what it does:

On every single page you visit, SIH executes code at document_start (meaning as soon as the page is opened). It even executes on your about:blank page and in all sub-frames on the currently visited site! The code executed is js/common/frame.js

manifest.json : https://pastebin.com/QUWJ2TG3
js/common/frame.js (slightly unobsfucated: https://pastebin.com/4BLeJr5m )

The code in this file does: Monitor when you are entering the site, where you are coming from on this site, when you are leaving the site, when you are clicking something, when you are moving your mouse (which they even failed to do properly), when you are having focus in an input, and you are pressing a key! It is not monitoring what you type. But when you click something, and it is a link, it will send the link URL to a background script.

This background script is located in /js/common/connectivity.js (https://pastebin.com/RsUDkDNQ).

What this script does is very nasty. First of all, it monitors EVERY SINGLE HTTP request you make. https://gyazo.com/174961cee2cf3cb9fdb4830efb669e63 It will then send to their own server a summary of this HTTP request if some condition is met (promoteButter?).

From this point, everything is a bit messy in their code and I will have to check a bit deeper.

Bottom line is: they are monitoring what sites you visit and may be sending a lot of your online activity to their own server. I couldn't figure out when they do it, yet, but it seems to be for promotional stuff. More importantly, in the future, even if what they do now is legit, you will not be informed about any changes to their permissions, because it basically already has every permission it can get in that regard. Therefore I strongly suggest uninstalling and reporting this extension.

TLDR: Uninstall ASAP.
Reacties (3)
21-09-2017, 12:17 door Anoniem
Meerdere 1 ster reviews op de chrome market te zien voor deze app,. vraag me af hoe lang het duurt voordat google het verwijderd.
21-09-2017, 14:53 door Anoniem
Jammer dat de steam software zelf niet onder de loep wordt genomen, die heeft namelijk ook wel privacy leaks inzitten. Zo merk je meteen dat httpS niet aanwezig is. En ik vraag mij af waar de chat gesprekken naartoe gaan. Biljven ze voor altijd bewaard of worden deze na x aantal tijd definitief verwijderd? Soms heb ik het gevoel dat steam een facebook clone is, maar dan alleen gericht op games en zonder trackers die overal worden verspreid zoals wat facebook wel doet. Maar weet je, ik heb echt geen flauw benul wat steam allemaal doet met je persoonlijke gegevens, omdat ik gewoon nergens informatie daarover kan vinden buiten de privacy beleid van steam.
28-09-2017, 09:02 door Anoniem
Staat nog steeds op google's markt zo te zien.
Reageren

Deze posting is gelocked. Reageren is niet meer mogelijk.