05/10/2020

Holiday shoppers warned that Honey, a popular browser extension, was a “security risk.”

Enlarge/ The Amazon logo at the entrance of a logistics center in France, July 2019.
110 with 65 posters participating
Days before Christmas, at the height of the last-minute holiday shopping rush, an ominous message appeared on Amazon.com. It warned shoppers who used a popular browser extension called Honey that the service, which promises to track prices and discount codes, was a security risk.
Honey tracks your private shopping behavior, collects data like your order history and items saved, and can read or change any of your data on any website you visit, the message read. To keep your data private and secure, uninstall this extension immediately. It was followed by a hyperlink where users could learn how to do so. Screenshots of the warning were posted to forums and social media by Honey users, like Ryan Hutchins, an editor at Politico.
[/tweet id]
Honey isnt some obscure browser extension from an unknown developer. Founded in 2012, the Los Angeles-based startup now boasts over 17 million users. It finds discount codes to save shoppers money at tens of thousands of online retailers, including Amazon. In November, PayPal agreed to purchase Honey for an eye-popping $4 billion, its largest deal ever. The acquisition was completed this week.
Amazons warning, which began appearing on December 20, confused and angered many of Honeys users, some of whom complained on its official social media channels. The browser extension has been compatible with Amazon since it was founded, and it is a significant part of Honeys appeal. Amazon is one of the most popular retailers in the world and the place where most Americans begin when looking for a product online.
Amazon declined to explain why it decided to label Honey a security risk so suddenly last month. Our goal is to warn customers about browser extensions that collect personal shopping data without their knowledge or consent, a spokesperson for the company said in a statement. They declined to answer follow-up questions about the basis for that claim.
When people install the Honey extension in their browser, they consent to the companys terms of use and privacy and security policy. While these kinds of agreements can be dense and difficult for the average person to interpret, Honey doesnt appear to be collecting consumer information without asking, as Amazon implied to WIRED. Its privacy policy states that it doesnt track your search engine history, emails, or your browsing on any site that is not a retail website.
We only use data in ways that directly benefit Honey membershelping people save money and timeand in ways they would expect. Our commitment is clearly spelled out in our privacy and security policy, a spokesperson for Honey told WIRED.
Honey also says that it doesnt sell the shopping data it gleans from customers. The company makes money by charging some retailers a small percentage of sales made with the coupons it findsbut Amazon has never been one of them.
Amazons security warning last month caught Honey by surprise, and the company scrambled to respond. It was forced to temporarily disable several of Honeys featureslike Droplist, which tracks the price of specific itemsto prevent the message from appearing to more people. The changes werent announced in an official blog post or message to users.
Were aware that Droplist and other Honey features were not available on Amazon for a period of time. We know these are tools that people love and worked quickly to restore the functionality. Our extension is notand has never beena security risk and is safe to use, a Honey spokesperson said.
Browser extensions can be incredibly invasive, and its still a good practice to be wary of any that you install in your browser. Amazon warned Honey users that the extension can read or change any of your data on any website you visit, but this is a basic functionality of many extensionswhich is why installing only ones you can trust is important. In fact, Amazon has a browser extension of its own called Amazon Assistant. It also tracks prices, just like Honey, and allows you to compare items on other retailers to those on Amazon. When users install Amazon Assistant from the Chrome Store, Google also notifies them it can read and change all your data on the websites you visit.
Honey says it regularly engages with security firms to assess its protections. Last summer, researchers from the cybersecurity firm Risk Based Security documented a vulnerability in Honeys extension that malicious websites could exploit to steal user information. But the bug didnt concern Honeys own data-collection practices, and it was patched on Firefox and Google Chrome in early 2019, according to Risk Based Security. If ever an individual or independent researcher contacts us about a potential vulnerability, we engage with that person to understand and remedy the issue (if there is one), the Honey spokesperson said.
Theres still the possibility that Amazon found a legitimate security problem with Honey, but it wont say what. WIRED also reached out to Google and Firefox, which each host extension stores for their popular web browsers, but neither company could immediately comment.
Amazon is extremely protective of its shopping and customer data. While Honey may not have been a concern when it was only a small startup, its now owned by the financial behemoth PayPal, which used to be part of eBay, an Amazon competitor. Amazon still doesnt accept PayPal as a direct payment option. In the ecommerce world, theres no incentive to play nice.This story originally appeared on wired.com.