I’ve noticed that dark reader on occasion phones home to darkreader.org, also with a increasing amount of sponsored links on their page. So what does everyone think, are they safe right now or should they not be trusted?

  • Nix@merv.news
    link
    fedilink
    English
    arrow-up
    28
    ·
    edit-2
    10 months ago

    The coder of Hover Zoom+ publishes all the offers he gets to sell his users data. Here’s an offer that mentions their partnership with Dark Reader:

    1/25/2021

    We’d love to have redacted sponsor Hover Zoom+ in a similar manner to how we’re partnering with Dark Reader. See attached for how that partnership has come to life, but we’re honestly super flexible on implementation. We’d essentially love to pay you in exchange for helping us drive users to redacted.

    https://github.com/extesy/hoverzoom/discussions/670

    Based on this it seems like Dark Reader has sold out to some type of partnership of some kind. If they did agree to start selling users data without informing their users would they even publish this code on their github? They could easily publish code that didn’t include the code in the extension to track their users.

    Im going to try emailing them and I think I’ll be looking for an alternative

    Edit: I went to their website to find an email to contact them and wow. I know they want people to download their app but this is excessive I cant dismiss this giant button to download the app and when I accidentally clicked it, it became wayy bigger and doesn’t hide

    Edit 2: they replied

    I’ve never heard about Hover Zoom. At the moment we only partner with Honey and DuckDuckGo, you can see their banners and install their products. We don’t collect any data. Best Regards, Redacted

    Follow up email:

    The dates reflect with Toucan, again, we had installation links to their app. Last year their product was shut down. Some time ago it was acquired by a bigger company.

    I then asked mentioned your concern about the extension periodically phoning home and they replied:

    The extension periodically checks if there are new blog posts on the website and displays the latest news in the News section https://darkreader.org/blog/ Best, Redacted

    Seems alright imo

    • ReversalHatchery@beehaw.org
      link
      fedilink
      arrow-up
      2
      ·
      edit-2
      10 months ago

      I think what they replied in your 4th edit is a bit more than odd. Are they doing free advertisement for those others?

      • Nix@merv.news
        link
        fedilink
        English
        arrow-up
        2
        ·
        10 months ago

        No, the others are people who support their OpenCollective. They put the links there basically to say “these people support me, you can too”

  • sturlabragason@lemmy.world
    link
    fedilink
    arrow-up
    8
    ·
    10 months ago

    I like how everyone is just going fucking nuts in this thread; combing over the code, contacting the maintainer, running a Wireshark trace on it. Good work everyone!

  • Mikelius@lemmy.ml
    link
    fedilink
    arrow-up
    8
    ·
    10 months ago

    Just ran a Wireshark on it for 12 hours. The only thing it ever does is a frequent ping to their home site, but includes no useful data other than an IP address if you’re not on VPN. I wouldn’t worry about it personally. If it’s a big deal, DNS block darkreader.org or block pings to it through your firewall… Chances are it’s just to download the latest css rules when they have them or something.

  • Zerush@lemmy.ml
    link
    fedilink
    arrow-up
    7
    arrow-down
    1
    ·
    edit-2
    10 months ago

    Normally it isn’t a problem if an app phones home to its homepage, eg, looking for updates. I think that DarkReader is trustworth. But it’s anyway good to use the less extensions possible, because they always add a privacy flaw to the browser as any third party app. In Vivaldi instead of the Dark Reader i use the own Dark Mode in flags, it has also an ivert filter, among others, in the Page Actions menu.

    • nixx1338@feddit.nl
      link
      fedilink
      arrow-up
      2
      ·
      10 months ago

      The recommended action when your CPU can’t handle it is to switch the mode to Filter or Filter+ instead of Dynamic. It’s not as good looking but it does darken the website at least.

  • Raisin8659@monyet.cc
    link
    fedilink
    English
    arrow-up
    1
    ·
    10 months ago

    Since I am not in anyway inclined to go read their code, I probably will just trust FF’s “recommended” flag until there is an obvious problem. Of course, when it is like that, then it’s too late. I tried the “Dark theme” on FF for a little bit, switch back to using Dark Reader in no time.

  • GlitzyArmrest@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    ·
    10 months ago

    A valid question that got me thinking. It’s probably relatively straight forward to use something like TamperMonkey instead especially if you only care about a few sites being in dark mode. Might be worth looking into as an alternative.

  • kraniax@lemmy.wtf
    link
    fedilink
    arrow-up
    1
    arrow-down
    1
    ·
    10 months ago

    Personally I don’t like this kind of extensions since they affect your browser’s fingerprint. But yeah, it looks bad.