Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
Windows Tipps & SecurityLernen Sie Linux-Befehle mit Webminal direkt im Browser(24.09.2026 um 08:00 Uhr)
•
Sicherheitslücken (CVE)USN-8811-1: urllib3 vulnerability(24.09.2026 um 03:39 Uhr)
•••
Sichere ProgrammierungYour Agent Has Observability. It Doesn't Have Evals.(24.09.2026 um 07:43 Uhr)
••
Sichere ProgrammierungProtocol Upgrade Compatibility Review: Robinhood(24.09.2026 um 07:45 Uhr)
•
Sichere ProgrammierungYour tests share your blind spots. Readers don't.(24.09.2026 um 07:52 Uhr)
•
Sichere ProgrammierungYour AI agent has more permissions than your users(24.09.2026 um 07:54 Uhr)
••
Windows Tipps & SecurityLernen Sie Linux-Befehle mit Webminal direkt im Browser(24.09.2026 um 08:00 Uhr)
•
Sicherheitslücken (CVE)USN-8811-1: urllib3 vulnerability(24.09.2026 um 03:39 Uhr)
•••
Sichere ProgrammierungYour Agent Has Observability. It Doesn't Have Evals.(24.09.2026 um 07:43 Uhr)
••
Sichere ProgrammierungProtocol Upgrade Compatibility Review: Robinhood(24.09.2026 um 07:45 Uhr)
•
Sichere ProgrammierungYour tests share your blind spots. Readers don't.(24.09.2026 um 07:52 Uhr)
•
Sichere ProgrammierungYour AI agent has more permissions than your users(24.09.2026 um 07:54 Uhr)
••
Intelligence View
⚡ tsecurity.de Intelligence

The Case Against New Tab Hijacking (And How to Do It Right)

The Case Against New Tab Hijacking (And How to Do It Right) "New tab hijacking" is the dark pattern of replacing someone's new tab without clearly communicating what you're doing, why, or how to undo it. You've probably experienced it:…

0
↗ Quelle (dev.to)
Reagiere als Erste:r — dein Feedback zählt!




The Case Against New Tab Hijacking (And How to Do It Right)



"New tab hijacking" is the dark pattern of replacing someone's new tab without clearly communicating what you're doing, why, or how to undo it. You've probably experienced it: you install some extension for an unrelated purpose, and suddenly your new tab is full of sponsored links and tracking pixels.



This is not what I built. But building a new tab extension that people actually want forced me to think carefully about the ethics of this space.






Why new tab extensions have a bad reputation



There's a graveyard of new tab extensions that were:




  • Bundled with other software without user consent

  • Stuffed with ads that impersonated useful content

  • Monetized through user data collection

  • Difficult or impossible to remove



Browsers now require explicit user permission to replace the new tab (chrome_url_overrides.newtab), which helps. But the reputation damage is done. Users are rightfully suspicious.






What "doing it right" looks like



I built Weather & Clock Dashboard with these principles:






1. Be obvious about what you're doing



The description says clearly: "Replaces your new tab page." No buried disclosures, no dark patterns.






2. Make it easy to disable



In Firefox: Right-click your extension → Manage Extension → turn off "Replace new tab page." Three clicks. I document this in the extension.






3. Don't monetize the new tab



No ads, no sponsored links, no "promoted content." The new tab is the user's space, not a billboard.






4. Don't track what you don't need



I don't collect analytics on what searches you run or how long you spend on the new tab. Weather data is fetched directly from Open-Meteo — it goes nowhere else.






5. Let the user customize it



My extension defaults to a reasonable state but lets users change:




  • Temperature units (°C/°F)

  • World clock timezones

  • Default search engine

  • Theme (dark/light/auto)



This is important for trust. A new tab that forces its defaults on you feels like something taking over your browser. One that responds to your preferences feels like a tool.






The permission dialogue as a trust signal



Firefox shows users exactly what permissions an extension requests at install time. For Weather & Clock Dashboard:





  • Access your data for all websites: No.


  • Read and modify browser history: No.


  • Exchange messages with programs other than Firefox: No.


  • Store unlimited data in your browser: Actually yes — but storage is the least scary permission, and it's just for saving your preferences locally.



Minimal permissions aren't just ethical, they're a marketing advantage. Users who see a lean permission list are more likely to install.






The AMO review adds credibility



Mozilla's human review process means an actual person looked at my code before it was published. This is a meaningful signal. The Chrome Web Store is largely automated; AMO has real reviewers.



I take that seriously. Every external request is documented, every permission is justified, and the source code is readable without a build step.






Conclusion



The new tab is valuable screen real estate that the user grants you access to. Treat it with respect.



If your new tab extension:




  • Does what it says

  • Doesn't monetize the user's attention without consent

  • Can be disabled in three clicks

  • Asks for minimal permissions



...you're doing it right.



Weather & Clock Dashboard is my attempt at this. Weather, clocks, search. Nothing else.

SOC Incident Playbook: Remote Code Execution (RCE) Defense
title: Detect Exploitation - The Case Against New Tab Hijacking (And How to Do It Right)
id: 6f4e1be1-c4f9-4ca8-9b04-3795a45d73c5
status: experimental
description: Automatisch generierte SIEM-Erkennungsregel basierend auf CTI Intelligence
references:
  - https://tsecurity.de/
author: iShareStuff CTI Automated Detection Engine
date: 2026-09-24
logsource:
  category: network_connection
  product: any
detection:
  selection:
      CommandLine|contains:
        - 'exploit'
  condition: selection
falsepositives:
  - Legitime administrative Zugriffe oder Penetrationstests
level: high
tags:
  - attack.initial_access
rule CTI_Threat_Indicator {
    meta:
        author = "iShareStuff CTI Automated Detection Engine"
        date = "2026-09-24"
        description = "YARA Signature for "
    strings:
        $str = "The Case Against New Tab Hijac" ascii wide
    condition:
        any of them
}
tsecurity.de Cognitive Threat RAG
Fokus-Vektor:

Kognitive Analyse für identifizierte Bedrohung: Erhöhte Bedrohungslage im Bereich The Case Against New Tab Hijacking (And .... Basierend auf 368k Vektor-Korrelationen werden sofortige Isolationsmaßnahmen für betroffene Endpunkte empfohlen.

🛡️ Angriffsfläche & Exposure

Netzwerk/Remote-Zugriff ohne Vorauthentifizierung möglich.

⚡ Empfohlene Sofortmaßnahmen
  • 1. Perimeter-Inspektion: Relevante Portfreigaben und exponierte Endpunkte unverzüglich scannen.
  • 2. Patch-Applikation: Hersteller-Hotfix einspielen oder betroffene Daemons in isolierte DMZ-Segmente überführen.
  • 3. Telemetrie & EDR-Alerts: Prozessaufrufe und Child-Processes auf anomale Shell-Spawns überwachen.
🔗 Semantisch verwandte Zero-Days MariaDB 11.7 VEC
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten The Case Against New Tab Hijacking (And How to Do It Right)

Thematisch verwandte Begriffe: Case, Against, Hijacking, Right · 6 Treffer

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-96676 | A vulnerability was identified in Fast FAC1900R 20190827_2.0.2. The impa…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen

tsecurity.de Live Threat Radar

🔴 LIVE RADAR
MONITORING
AKTIV
CVE-DATENBANK
LIVE
🔍
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel • Rechts: nächster Artikel • unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel TTP ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger • Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick