No shit
Who would expect otherwise?
Generative AI assistants packaged up as browser extensions harvest personal data with minimal safeguards, researchers warn. Some of these extensions may violate their own privacy commitments and potentially run afoul of US regulations, such as HIPAA and FERPA, by collecting and funneling away health and student data. A group …
No, it's the same people, constantly, that rail against 'government spying!' but are the first to sign up to give their free data, by the bucket load, to corporations. From 23andMe to Google to Apple, they'll pull out their cellphone to give their buying habits to Apple Pay but complain if there is even a whiff of government oversight.
I don't know, but if I were a US resident given the current government over there I'd say my reservations about giving my data away have been completely validated. When both the president and the oligarch who bought the election for him are notoriously petty and vindictive, the less info about anyone they have access to the better.
There is hardly any science in the gathering of too much data from a web browser extension, you just need a metaphorical shovel instead of a spatula, but yes, making your plugin bloated in order to steal and monetise personal information[1] is an affront to engineering.
[1] unless the end user explicitly installed the extension in order that his data be snarfed, of course: supplying the customer with a system that fits his requirements, no matter how strange or self-defeating those requirements may seem, is a sine qua non of good engineering.
Most end users are clueless to what they are enabling.
All Terms and Conditions are TLDR for all users, everyone knows it including the ne'er do wells that write these 13 pages of BS terms that are hard to understand, even for the author.
Also, dressing up extensions to sound like they belong to something else, is yet another classic TTP for shite bags to harvest data from you.
The mind boggles.
I am beginning to wonder whether there is any point to even attempting to keep my 'personal' information secret. There are so many applications, add-ons and insecure sites out there, not to mention hackers who can guess / use old passwords to obtain sensitive information (see '23 and Me' alleged hack - he just used an old password to gain access ) the only way to keep ones personal secrets actually secret seems to be to not actually own or use a computer at all.
(And as for 'accidentally' including the senior editor of 'The Atlantic' journal on your high level military 'confab' on Signal, well, words fail me.)
If you should ever wish to witness confusion, bluster and even some anger ("how dare YOU ask of US.."), when someone offering a straightforward service insists that you install their app instead of using their website, politely but firmly inquire about the necessity of each of the app's permissions and their assurances against datarape of your device.
Web sites are rarely better, but with No Script etc you have at least *some* visibility and control.
The only privacy risk that Google would ever be worried about is whether someone else is going to disregard privacy as badly as they do and possibly use all that slurped data to compete with what they do with it.