[nvda-addons] Re: Important notice: Blind Extra add-on is hereby blacklisted forever

  • From: Shaun Everiss <sm.everiss@xxxxxxxxx>
  • To: nvda-addons@xxxxxxxxxxxxx
  • Date: Sat, 12 Nov 2016 11:50:01 +1300

In the case of the translate addon.
blindaudiogames.com owned by ian reed has something called jgt, an addon for translating japanese games.
You need an account to access the server with the translations.
He actually pays for the translations out of his pocket, but since most stuff will eventually be stored on his server unless its a new game he doesn't need to get things all the time.
Its not a definitive translater addon but for those playing games it works well enough.
Though it goes without saying that this is a donation based addon, cost wise its quite cheap but its all based on what is stored on there.
Another addon that hasn't been reviewed is the if interpriters addon by nick stocton that showed up on an nvda folder full of other questionable content and it is still used and still works.



On 12/11/2016 7:43 a.m., Joseph Lee wrote:

Dear members of the NVDA add-ons community,



Some of you may have heard of an add-on called Blind Extra which supposedly
allows easy access to additional software products. I'm sorry to inform you
that this add-on shall enter the Hall of Blacklisted Add-ons with no chance
of leaving that place for all eternity. Here's why:



A few days ago, I and Derek Riemer were alerted to two reports of this
add-on breaking numerous security issues. One involved renaming files to
something else without the user noticing it, and the second was remote
access where someone gained access to a user's computer and sent Skype
messages. Prior to that, some users asked Derek and I to perform a scan of
this add-on, and another user told us that this add-on does odd things,
including suspicious activity and downloading files.



In case of the remote access incident, the user who was affected by this
alerted Derek and I to this issue on a Skype group. After some exchanges
where the hacker (under the ID of the affected user) wrote messages that
were quite suspicious, we determined that it is best to blacklist this
add-on which was partly responsible for this incident.



Thus, I would like to request the community do the following:



1.       Remove Blind Extra immediately.

2.       Keep Blind Extra in the list of blacklisted add-ons (this makes it
the second add-on to meet this fate, with the first being Instant Translate;
in case of Instant Translate, people report that the situation has improved,
but due to volatility of the services used, it'll remain an add-on under our
careful watch).

3.       Do not accept review requests from the author of Blind Extra (we
only know this person as 'Ahmed").



Also, I'd like to remind the community to be vigilant when installing
add-ons - add-ons can do amazing and powerful things, including what you
read above.



Thank you.

Cheers,

Joseph


----------------------------------------------------------------
NVDA add-ons: A list to discuss add-on code enhancements and for reporting bugs.
Community addons are available from: http://addons.nvda-project.org
To send a message to the list: nvda-addons@xxxxxxxxxxxxx
To change your list settings/unsubscribe: 
//www.freelists.org/list/nvda-addons
To contact list moderators: nvda-addons-moderators@xxxxxxxxxxxxx

Other related posts: