Eblogtip.com
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions

Archives

  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • December 2022

Categories

  • News
  • Technology
  • Uncategorized
eBlogTip
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions
  • News

Top open source project Moq slammed for secretly collecting user data

  • August 10, 2023
Total
0
Shares
0
0
0


Popular open source (OS) project Moq just got updated to include a not-so-open-source addition in the form of a series of DLLs designed to collect hashes of user email addresses.

The changes were first reported on by BleepingComputer, which notes that the project sees around 100,000 daily downloads on average, having amassed more than 476 million since its inception.

From version 4.20.0, Moq started including SponsorLink, a project shipped as closed-source that takes away from one of Moq’s key benefits – the fact that it’s an OS project.

Moq bundles in a closed-source project

One of Moq’s owners, Daniel Cazzulino, noted by BleepingComputer to also be a maintainer of the SponsorLink project, quietly pushed the update earlier this month. While perfectly reasonable, the change went largely unannounced, and existing users committing themselves to the open-source project may not be aware without reading the small print.

The SponsorLink DLLs, which collect hashes of email addresses to send to SponsorLink’s CDN, contain obfuscated code that goes against Moq’s open-source principles.

In the days that followed the update, GitHub became awash with criticism of the move, with many disgruntled users calling the update a GDPR breach. Others pointed out that an obfuscated package could potentially hide some activity from unaware users. One user called the move a “moqery.”

In light of the backlash, Cazzulino has confirmed that “the actual email is never sent when performing the sponsoring check,” which can be verified by “running Fiddler to see what kind of traffic is happening.”

Cazzulino continues: “The email on your local machine is hashed with SHA256, then Base62-encoded. The resulting opaque string (which can never reveal the originating email) is the only thing used.”

Furthermore, suspending or uninstalling the app deletes all records associated with a user’s account.

In a further update, version 4.20.2 looks to have reversed the change, though for many, the reputational damage could have been enough to put them off.


Source link

Total
0
Shares
Share 0
Tweet 0
Pin it 0
Previous Article
  • Technology

Lyft takes a page from Uber’s playbook: Ads

  • August 10, 2023
View Post
Next Article
  • Technology

Instagram’s code reveals a ‘Meta Verified’ feed filter, but company denies active test

  • August 10, 2023
View Post
You May Also Like
View Post
  • News

Baldur’s Gate 3 players still haven’t found a secret 2-hour section, according to Astarion’s voice actor

  • September 21, 2023
View Post
  • News

GitHub expands Copilot Chat access to individual users

  • September 21, 2023
View Post
  • News

The Callisto Protocol creator Glen Schofield is leaving to ‘pursue new opportunities’

  • September 21, 2023
View Post
  • News

Netflix and Disney reportedly step in to help end WGA strike, but writers aren’t buying it

  • September 21, 2023
View Post
  • News

Marvel’s Spider-Man 2 swings into a release-ready state and goes gold

  • September 21, 2023
View Post
  • News

Nvidia DLSS 3.5 comes to Cyberpunk 2077 today – just in time for the big 2.0 update

  • September 21, 2023
View Post
  • News

Tomb Raider developer Crystal Dynamics has laid off 10 employees “due to an internal restructuring”

  • September 21, 2023
View Post
  • News

A new Horizon Zero Dawn board game will act as a prequel to Forbidden West

  • September 21, 2023

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

eBlogTip.com
  • Categories

Input your search keywords and press Enter.