Just started using paywall bypass plugin - BPC. Honestly, love it so far. I found that both their github and gitlab are blocked. I found that tool at gitflic.ru

Never, used this repository or the extension before. Curious, if people from the community use it and how secure they would consider this?

  • gigachad@sh.itjust.works
    link
    fedilink
    arrow-up
    13
    ·
    edit-2
    4 days ago

    I am using it. I found it very suspicious it is hosted on a Russian website at first. However because of copyright violations the author couldn’t leave the extension on a server the US/EU can access.
    The extension clearly states which websites it is accessing and you can look through the whole list. I did that a while ago and found nothing suspicious. I trust the author, but you can never know for sure.

    • CmdrShepard42@lemm.ee
      link
      fedilink
      arrow-up
      3
      arrow-down
      3
      ·
      4 days ago

      Copyright violations for a browser extension that simply bypasses paywalls? Sound fishy as tools like Ublock Origin can do the same and have been well known for years and faced no takedown requests.

      • gigachad@sh.itjust.works
        link
        fedilink
        arrow-up
        4
        ·
        4 days ago

        Bypass Paywall Clean was the defacto standard for bypassing paywall until it got taken down. It can reliably bypass the paywalls of hundreds of different international news agencies. If you can achieve that with a UBlock script I will be very happy if you could share it.

  • thesohoriots@lemmy.world
    link
    fedilink
    English
    arrow-up
    3
    ·
    5 days ago

    I use it as an imported list, and as others mentioned, it was repeatedly subject to legal action and takedowns so the creator had to flee the mainstream. Wasn’t a fan of the new site either, but it’s the best we’ve got.

  • tal@lemmy.today
    link
    fedilink
    English
    arrow-up
    1
    ·
    edit-2
    4 days ago

    The plugin does, unless things have changed since it left GitHub, request permission on a by-website basis in Firefox. I kind of doubt that most people are reviewing that (large) list, but that’s probably about as restrictive as one could reasonably do something like this.

    The TLD of the source domain is probably more-or-less irrelevant as security. If someone were trying to set up malware, if they were willing to go through even the barest of efforts, they’d be more likely to do it through a VPN on a “legitimate-looking” domain; that’s one of the lowest-effort ways to increase the credibility of malware. As I recall, Jia Tan did that on GitHub.

    EDIT: Hmm. That does kind of suggest that Firefox might benefit from a plugin model where plugins could only have permission to process the “current page” when a button is clicked, which I’d guess would likely work for Bypass Paywalls Clean, even if it’s not how it works today. Some plugins, like Behind The Overlay, could reasonably function in such a manner.