in ,

Amazon takes a swipe at PayPal's $ 4 billion acquisition, Ars Technica

Amazon takes a swipe at PayPal's $ 4 billion acquisition, Ars Technica


Days before Christmas, at the height of the last-minute holiday shopping rush, an ominous message appeared onAmazon.com. It warned shoppers who used a popular browser extension calledHoneythat the service, which promises to track prices and discount codes, was “a security risk.”

“Honey tracks your private shopping behavior, collects data like your order history and items saved, and can read or change any of your data on any website you visit,” the message read. “To keep your data private and secure, uninstall this extension immediately.” It was followed by a hyperlink where users could learn how to do so. Screenshots of the warning were posted to forums and social media by Honey users, like Ryan Hutchins, an editor atPolitico.

Honey isn’t some obscure browser extension from an unknown developer. Founded in (**********************************************************, the Los Angeles-based startup now boasts over million users. It finds discount codes to save shoppers money at tens of thousands of online retailers, including Amazon. In November, PayPalagreed to purchaseHoney for an eye-popping $ 4 billion, its largest deal ever. The acquisition was completed this week.

Amazon’s warning, which began appearing on December (******************************************************************, confused and angered many of Honey’s users, some of whom complained on its official social media channels. The browser extension has been compatible with Amazon since it was founded, and it is a significant part of Honey’s appeal. Amazon is one of the mostpopular retailersin the world and the place wheremost Americansbegin when looking for a product online.

Amazon declined to explain why it decided to label Honey a security risk so suddenly last month. “Our goal is to warn customers about browser extensions that collect personal shopping data without their knowledge or consent,” a spokesperson for the company said in a statement. They declined to answer follow-up questions about the basis for that claim.

When people install the Honey extension in their browser, they consent to the companyterms of useandprivacy and security policy. While thesekinds of agreementscan be dense and difficult for the average person to interpret, Honey does not appear to be collecting consumer information without asking , as Amazon implied to WIRED. Its privacy policy states that it does not “track your search engine history, emails, or your browsing on any site that is not a retail website.”

“We only use data in ways that directly benefit Honey members — helping people save money and time — and in ways they would expect. Our commitment is clearly spelled out in our privacy and security policy, ”a spokesperson for Honey told WIRED.

Honey also says that it does not sell theshopping datait gleans from customers. The company makes money by charging some retailers a small percentage of sales made with the coupons it finds — but Amazon has never been one of them.

Is there something you think we should know about these companies? Email the writer at[email protected]. Signal: 966 – – (******************************************************. WIRED protects the confidentiality of its sources, but if you wish to conceal your identity, here are the instructions for using

SecureDrop. You can also mail us materials at (Third Street, Suite) *******************************************************, San Francisco, CA 94107.

Amazon’s security warning last month caught Honey by surprise, and the company scrambled to respond. It was forced to temporarily disable several of Honey’s features — like Droplist, which tracks the price of specific items — to prevent the message from appearing to more people. The changes weren’t announced in an official blog post or message to users.

“We’re aware that Droplist and other Honey features were not available on Amazon for a period of time. We know these are tools that people love and worked quickly to restore the functionality. Our extension is not — and has never been — a security risk and is safe to use, ”a Honey spokesperson said.

Browser extensions can be incredibly invasive, and it’s still a good practiceto be wary of any that you install in your browser. Amazon warned Honey users that the extension can “read or change any of your data on any website you visit,” but this is a basic functionality of many extensions — which is why installing only ones you can trust is important. In fact, Amazon has a browser extension of its own called

Amazon Assistant. It also tracks prices, just like Honey, and allows you to compare items on other retailers to those on Amazon. When users install Amazon Assistant from the Chrome Store, Google also notifies them it can “read and change all your data on the websites you visit.”

Honey says it regularly engages with security firms to assess its protections. Last summer, researchers from the cybersecurity firm Risk Based Securitydocumenteda vulnerability in Honey’s extension that malicious websites could exploit to steal user information. But the bug did not concern Honey’s own data-collection practices, and it was patched on Firefox and Google Chrome in early (******************************************************, according to Risk Based Security. “If ever an individual or independent researcher contacts us about a potential vulnerability, we engage with that person to understand and remedy the issue (if there is one),” the Honey spokesperson said.

There’s still the possibility that Amazon found a legitimate security problem with Honey, but it won’t say what. WIRED also reached out to Google and Firefox, which each host extension stores for their popular web browsers, but neither company could immediately comment.

Amazon is extremely protective of its shopping and customer data. While Honey may not have been a concern when it was only a small startup, it’s now owned by the financial behemoth PayPal, which used to be part of eBay, an Amazon competitor. Amazon stilldoesn’t acceptPayPal as a direct payment option. In the ecommerce world, there’s no incentive to play nice.

More Great WIRED Stories

    Hollywood bets on a future of

      quick clips and tiny screens

  • Mind control for the masses – (no implant needed
  • Here’s what the world will look like in … right
  • ?****************** (Internet deception is here to stay – (what do we do now?The war vet, the dating site, and the phone call from hell

  • AI Will AI as a field“hit the wall” soon? Plus, thelatest news on artificial intelligence
  • **************************** 🏃🏽‍♀️ Want the best tools to get healthy? Check out our Gear team’s picks for the best fitness trackers, (running gear(includingshoesandsocks), andbest headphones
  • () ****************************************************************** (*********************************************(********************************************** (Read More) () ************************************************
  • What do you think?

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    GIPHY App Key not set. Please check settings

    Facebook's PR feels broken, hacker news

    Facebook's PR feels broken, hacker news

    Inside TASBot's semi-secret, probably legal effort to control the Nintendo Switch, Ars Technica

    Inside TASBot's semi-secret, probably legal effort to control the Nintendo Switch, Ars Technica