Posted on

Browser push notifications turned into an advertising channel

A website used to disappear when you closed the tab.

Push notifications changed that.

Once a browser grants a site notification permission, the site can send alerts later even when the user is not actively reading the page. That makes notifications genuinely useful for chat messages, breaking news, deliveries, calendars, monitoring tools, and other time-sensitive events.

It also creates a durable advertising channel out of a single permission click.

Chrome’s current notification guidance reflects the abuse problem directly. Users can block sites from sending notifications, and Chrome may automatically remove notification permission from sites it considers disruptive. It can also block notifications from sites marked abusive or misleading.

That is a strong clue about the economic temptation built into the feature.

Permission has a scope problem

A user may click Allow because they expect one kind of alert.

A news reader expects important headlines. A customer expects shipping updates. A web-app user expects messages related to the service.

The technical permission, however, creates a channel. The browser does not understand the social bargain behind every future notification.

A site can therefore begin with useful alerts and gradually fill the channel with coupons, urgency tricks, affiliate offers, fake warnings, or promotional material the user never imagined when granting access.

The user did technically approve notifications.

That does not make every later use equally expected.

The valuable asset is interruption

Push advertising differs from a banner sitting quietly on a webpage.

The notification leaves the site and enters the operating environment: desktop corner, notification center, lock screen, or mobile alert stack.

That interruption is the commodity.

Once enough sites compete for it, browsers have to become permission managers and abuse filters rather than passive delivery pipes.

Chrome’s increasingly aggressive controls are an example of the platform absorbing the cleanup cost.

The broader Spam Empires lesson is that industrial promotion constantly searches for channels with higher attention than ordinary ads.

A browser notification began as a way for useful sites to tell you something happened.

The moment marketers realized it could also say SALE ENDS IN 17 MINUTES, the permission prompt became part of the battlefield.

Posted on

Malicious browser extensions promoted as useful everyday utilities

A browser extension can earn installation with a job so ordinary that almost nobody treats it like software with privileges.

Convert a file. Change the new-tab page. Find coupons. Translate text. Take screenshots. Adjust volume.

The function may fit in one sentence.

The permissions may not.

Google’s Chrome documentation explains that extensions can request access ranging from bookmarks and browsing history to data on every website a user visits. Some permission levels can allow an extension to read or modify page data, observe tabs, or interact with information copied by the user.

See Google’s guide to extension permissions.

Convenience does not define the permission boundary

A utility can genuinely perform the advertised task and still ask for more access than that task seems to require.

That is why the install screen matters.

The browser is not merely asking whether the extension sounds useful. It is asking whether the publisher should receive the listed capabilities.

A malicious or compromised extension can abuse broad access after installation, while the visible feature continues working normally enough to avoid suspicion.

Google’s guidance tells users to install extensions only from publishers they trust and to pay attention to requested permissions. Chrome Safe Browsing also checks installed extensions against known unsafe items.

See Google’s extension installation guidance and Safe Browsing documentation.

Evaluate the publisher and the scope

Before installing a browser utility, ask whether its permissions make sense for its function.

A screenshot tool may need access to the current page. A simple calculator should have a much harder time explaining why it needs to read data across every site you visit.

Check the publisher, store history, update history, reviews, and whether the requested permissions changed unexpectedly in a recent update. Remove extensions you no longer use.

The danger is not that browser extensions are inherently untrustworthy.

It is that a tiny convenience can quietly become one of the most privileged pieces of software in the browser.

The icon may occupy sixteen pixels.

The permission grant can cover nearly everything behind it.