Hacker News new | ask | show | jobs
by throwaway81523 163 days ago
Apparently this thing got approved for the chrome store, which confirms that "store" approvals are near worthless for malware filtering.
2 comments

It's not malware. Marketing companies stealing commission from each other isn't malware. Giving the user less than the best possible deal isn't malware. It doesn't even upload your cookies to see if you're a tester - it does that on the client.
If I click on an affiliate link that I want to use and the extension changes that without me knowing, that’s malware for me. The intent of the user may be to use a specific affiliate link.
What's the ratio of people deliberately clicking affiliate links, to people who just click links and have no clue what an affiliate link even is?

I already thought Honey was scummy so I never used it in the first place, but I honestly don't get the particular outrage over these specific practices. You're already using the extension to effectively scam online stores, by using coupons the company gave to somebody else, not you. I see it as barely more ethical than doing that old trick of generating your own manufacturer coupons. Probably it's a lot more legal, but ethically it's in the same ballpark.

> What's the ratio of people deliberately clicking affiliate links, to people who just click links and have no clue what an affiliate link even is?

I don't know what the ratio is, but I do know it doesn't matter in this context, it's still malware.

People may well want to deliberately support a creator (influencer) they like.
That's not how malware is defined - Windows ain't malware just because they occasionally make Edge open instead of what you thought were your default browser. The malware definition is way more specific than simply software that doesn't always follow user intent.
It actually does fall under the definition malware. Specifically, Honey hijacks affiliate marketing tags and replaces them with their own. This falls under the definition of the “spyware” category of malware.
Spyware is software that sends information about the user (browsing history, etc) to a 3rd party.

Many affiliate browser extensions do indeed do this, as an extra revenue stream. In fact, I'd recommend never installing a coupon browser extension. But replacing one number with another does not meet the above definition of spyware.

See Spyware: https://en.wikipedia.org/wiki/Malware

"Programs designed to monitor users' web browsing, display unsolicited advertisements, *or redirect affiliate marketing revenues* are called spyware."

it is textbook definition of malware. what's the argument for sending a users coupon code to a server regardless of sharing setting?
Because it's the whole point of the extension? If that's malware, so is Microsoft Windows. And Ubuntu.
one point of view is why bother with any of this, google knows exactly what honey is doing, they could remove honey from chrome with the stroke of a pen, and that would be that.