Elektrine lite

← Feed

@matthiasott@mastodon.social

Post #1450244

2026-04-20 15:11 UTC

Can confirm this for Arc, Brave, Edge, Chromium, and Vivaldi on my machine: #Anthropic secretly installs spyware when you install Claude Desktop https://www.thatprivacyguy.com/blog/anthropic-spyware/

Replies (28)

  • @crazyeddie@mastodon.social 2026-04-20 17:21

    @matthiasott@mastodon.social Only one of these IDs seems to point at anything valid and it's Claude. Supposedly you can search for the gibberish after chrome:// at the extension store and that extension will pop up. This only works for the second ID in the list. https://chromewebstore.google.com/search/dihbgbndebgnbjfmelmegjepbnkhlgni https://chromewebstore.google.com/search/fcoeoabgfenejglbffodgkkbkcdhcgfn https://chromewebstore.google.com/search/dngcpimnedloihjnnfngkgjoidhnaolf My guess is that the other two are debug versions or something. They could be doing something nefarious but more likely this is just them being stupid.

    Open ##1450243

  • @matthiasott@mastodon.social 2026-04-20 15:56

    Even Claude says this is bad. ¯\_(ツ)_/¯ Maybe you should have asked your country of geniuses in a vending machine before deploying this… 😉

    Open ##1988890

  • @ManyRoads@mstdn.social 2026-04-20 15:27

    @matthiasott All the more why running your own AI (on your machine) makes sense. I am pretty certain every Cloud-Based AI gathers personal info and uses it.

    Open ##1988891

  • @matthiasott Wild.

    Open ##1988904

  • @saxnot@chaos.social 2026-04-20 15:54

    @matthiasott what does the manifest do when none of the three whitelisted extensions are installed? The article says on the authors machine it does nothing

    Open ##1988905

  • @NewCancerbero@masto.es 2026-04-20 16:07

    @matthiasott Thank very much for this important information. I think than all software for run A.I.'s (very bad if is cloud A.I.) violate the privacy of user. You can run the A.I. offline in local enviroment, with Open A.I., Lemonade, Ollama or other, but not is solution. All this software have hiden logs with the interaction between user and A.I., when you are online again, the hiden logs be send for this software. But nothing is impossible, we only go to find this log and delete her information. ;)

    Open ##1988908

  • @MHowell@kolektiva.social 2026-04-20 16:16

    @matthiasott Question for the Fediverse: Is the website "That Privacy Guy!" a reboot of "That One Privacy Site" that published the very detailed VPN comparison table? https://web.archive.org/web/20170107044454/https://thatoneprivacysite.net/vpn-comparison-chart/

    Open ##1988909

  • @macronaut@mas.to 2026-04-20 16:33

    @matthiasott why are these browsers allowing this level of access without the explicit consent of the person!? Is Anthropic exploiting a bug in Chromium/browsers don’t can do this?

    Open ##1988910

  • @matthiasott simple solution = fuck Claude and its desktop.

    Open ##1988915

  • @yazilim@mastodon.social 2026-04-20 17:34

    @froq makaleyi incele bu doğru mu?

    Open ##1988917

  • @sl007@digitalcourage.social 2026-04-20 17:46

    @matthiasott Claude installs spyware? ^ FYI @digitalcourage PS I did already nominate an evil git platform. Anyone else ? :digitalcourage: https://bigbrotherawards.de/nominieren

    Open ##1988921

  • @masukomi@connectified.com 2026-04-20 17:46

    @matthiasott Confirmed on most of those and Opera too.

    Open ##1988922

  • @matthiasott lolololololol And these are the AI "good guys," right? Burn it all down

    Open ##1988923

  • @tsyum@thepit.social 2026-04-20 18:03

    @matthiasott how is *anyone* surprised?

    Open ##1988924

  • @mirabilos@toot.mirbsd.org 2026-04-20 18:04

    @matthiasott this leaves the question of why did you install the Klau-de fashtech in the first place?

    Open ##1988925

  • @neilvandyke@mastodon.online 2026-04-20 18:36

    @matthiasott This is one of the reasons that the "installed" parts of Claude on my laptop run only within a VM sandbox, and are generally distrusted.

    Open ##1988926

  • @js@mastodon.nl 2026-04-20 19:49

    @matthiasott SHOCKED!

    Open ##1988927

  • @rich@mastodon.gamedev.place 2026-04-20 20:23

    @matthiasott by now, can we just assume any new software does this. 😕 it saves time.

    Open ##1988928

  • @matthiasott Burn them all down: the data centers, the billionnaires, the tech bros, their allies, the nations, everything. Fuckin fed up...

    Open ##1988929

  • @Luna@mastodon.world 2026-04-20 22:46

    @matthiasott Another good reason to boycott them.

    Open ##1988930

  • @gbsills@social.vivaldi.net 2026-04-20 23:15

    @matthiasott Is anyone surprised?

    Open ##1988931

  • @AnnieG@mementomori.social 2026-04-20 23:43

    @matthiasott So, if I understand correctly, this is not so much the fault of the browsers, which are traditionally built to trust this set-up in order to function the way we expect; it's that the Claude desktop install violates an implicit (or is it explicit?) understanding in commercial software that such files/permissions should be disclosed to the user at the time of installation, and require approval. Which means it's really not the fault of the various browsers, whatever one may think of one or another... It's just Anthropic behaving as expected.

    Open ##1988932

  • @rinsuki@mstdn.rinsuki.net 2026-04-21 01:59

    @matthiasott Isn't it normal? I've never heard of anyone being asked for consent when installing NativeMessagingHosts, since it didnt do anything without helper extension, and browser will ask you like "hey this extension can talk with your installed native apps is it ok" when you are installing helper extension who can talk with NativeMessagingHosts, so i thought it was fine and normal

    Open ##1988939

  • @OrionKidder@mas.to 2026-04-21 04:50

    @matthiasott Of course. I don't know why I didn't just assume this.

    Open ##1988940

  • @retrosponge@kind.social 2026-04-21 05:46

    @matthiasott You mean a company in an industry that is fueled by wide-scale content theft can't be trusted!

    Open ##1988941

  • @aura@gts.foxsnuggl.es 2026-04-21 10:52

    @matthiasott this is a normal thing that normal software does???

    Open ##1988942

  • @outofcontrol@phpc.social 2026-04-21 13:41

    @matthiasott @afilina This isn’t specific to anthropic, 1Password and I believe Bitwarden also do this. More transparency is always good.

    Open ##1988945

  • @heri@net.miaumuh.ch 2026-04-22 10:26

    @matthiasott and what to do against it? Is it enough to just uninstall Claude?

    Open ##1988946