top 50 comments

sorted by: hot top controversial new old
[–] 131 points 4 months ago* (last edited 4 months ago) (14 children)

This blog is on the malwarebytes website. Malwarebytes says in thr post thst its not fair to call this spyware. This was brought up on the windows side as well.

What is really going on: claude desktop is installing the hooks for the claude browser extension. If you install the browser extension, claude desktop can control the browser. This is the intended behavior so you can have an agent do something like "in the morning, access these three sites, pull down the data and create a newsletter for me" or "please check flight costs throughout the day on these sites" or whatever you want to access the browser for.

This is the whole reason you install claude desktop, to automate your computer.

  • source
  • hideshow 20 child comments
  • [–] 53 points 4 months ago

    The article says that is the intended use, I agree this is just bad implementation, but it's bad because it not only allows control one way, from the app to the browser, it also allows it the other way: browser extensions with an ID that matches one of the allowed ones can access userspace, without asking. That is a huge attack surface that is installed without any consent.

  • source
  • parent
  • [–] 22 points 4 months ago* (last edited 4 months ago) (1 child)

    I agree that this doesn’t rise to the level of “spyware,” but it is extra sneaky/slimy, and it absolutely, IMO, makes your system less secure for no good reason. They could just have a prompt in the UI the first time you attempt to use a feature that requires the native messaging host, which says something like “we need to install extra software to communicate with Chrome, OK?” This is the ethical thing to do.

    It’s especially sketchy that they’re preemptively installing it in the right directories for multiple Chromium-based browsers, even ones that aren’t installed on your system.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 2 points 4 months ago (1 child)

    Its not sketchy just lazy. One observation i have made eith anthropic is that they are great at amking a model but louzy at app development. There apps tend to have that "scientist learned python to help them at work" vibe. Which is always a security nightmare.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 12 points 4 months ago (6 children)

    I disagree, it’s definitely sketchy. Going out of your way to install the messaging host for a half dozen different Chromium forks is going out of your way do something behind the user’s back; it’s the opposite of lazy.

  • source
  • parent
  • hideshow 7 child comments
  • load more comments (5 replies)
  • [–] 8 points 4 months ago

    It also uses your credentials to do so and doesn't ask any permissions for any of it including whatever else it wants to do outside the browser sandbox where it lives. Anthropic can easily remedy the situation but they didn't set it up that way. And the question is why.

    Not calling it spyware is like not calling McDonald's "food". While technically true, it's just how it works.

    I don't think it's actually doing anything nefarious yet. fwiw.

  • source
  • parent
  • [–] 6 points 4 months ago (1 child)

    This is a little disengenuous...the browser extension ≠ the desktop app. Some people install the app and only use the chat feature. Some use cowork but would never want to use the browser extension. Assuming that installing a desktop app means you should also want the browser extension is just bad logic.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 3 points 4 months ago (1 child)

    Side question, are the typos intentional?

  • source
  • parent
  • hideshow 2 child comments
  • load more comments (8 replies)
    [–] 34 points 4 months ago (2 children)

    American softwar company spying on its users...more news at 8

  • source
  • hideshow 3 child comments
  • [–] 11 points 4 months ago (1 child)
  • load more comments (1 reply)
    [–] 15 points 4 months ago (1 child)

    You guys use AI? That's bad for you.

  • source
  • hideshow 2 child comments
  • [–] 5 points 4 months ago (1 child)

    I didn’t read the article, but imo better criticism would be how bad Claude engineering has been these past few weeks.

    Theo did a video walking through just how bad Claude’s desktop app is. Like it’s embarrassingly bad for a company that claims to have a model so powerful that it spits out zero-day exploits like a vending machine.

    https://m.youtube.com/watch?v=WkHdkwDQJ5o

  • source
  • hideshow 2 child comments
  • [–] 4 points 4 months ago

    Spyware installs spyware

  • source
  • [–] 3 points 4 months ago
    load more comments
    view more: next ›