# The Honey Files Expose Major Fraud!

Source: https://www.youtube.com/watch?v=qCGT_CKGgFE
Recap page: https://rapidrecap.app/video/qCGT_CKGgFE
Generated: 2026-01-10T15:26:00.206+00:00

---
## Quick Overview

The Honey extension appears to intentionally hide or ignore stand-down rules designed to prevent affiliates from poaching commissions, as evidenced by the discovery of an internal rule file ('ssd.json') that explicitly lists affiliate networks but fails to enforce stand-down rules for those networks, suggesting a deliberate effort to mislead both users and partners regarding commission attribution.

**Key Points:**
- Honey's internal stand-down rules file ('ssd.json') explicitly lists affiliate networks like CJ, Linkshare, Rakuten, Awin, and Swagbucks, indicating awareness of affiliate tracking mechanisms (03:56, 03:41).
- The 'base' rules in 'ssd.json' set the user point threshold ('uP') to 501 and user age check ('uA') to 259,200,000 milliseconds (approximately 8 months), which are relatively low thresholds compared to the 20,000 points required for Recruited Links (LS) (02:36, 02:21).
- The rules also feature a 'GA' array containing tracking identifiers like 'CONTID', '_s_vi_', '_ga', 'networkGroup', and '_gid' associated with affiliate networks, suggesting deep tracking of user activity across domains (02:59).
- When testing with an affiliate link (e.g., Newegg via Rakuten's LinkShare), Honey's extension immediately shows 'Honey is disabled on this site' (03:38, 15:15), while an account with high points and age receives cash back, showing differential treatment.
- An older archived version of the stand-down rules (Honey-4.0.18-2014-12-16.zip) from 2014 shows no 'gca' or 'bl' rules, suggesting these compliance checks were added later, potentially as a reaction to past issues (03:59, 03:40).
- The explicit stand-down rules found in the code (e.g., for CJ, Linkshare, Rakuten, Awin, Swagbucks) conflict with the observed behavior where the extension fails to stand down when an affiliate link is clicked (15:11, 15:54), implying the rules are either not being enforced or are being overridden.
- Security researcher Ben Edelman's findings suggest that Honey developers are aware of these rules but may be intentionally circumventing them to maintain lucrative affiliate partnerships (03:34, 03:48).

![Screenshot at 03:56: The video reveals an internal JSON file \('ssd.json'\) containing base rules and explicit affiliate network stand-down patterns \(regexes for CJ, Linkshare, Rakuten, Awin, Swagbucks\), which contradicts the observed behavior where Honey fails to stand down on affiliate links.](https://ss.rapidrecap.app/screens/qCGT_CKGgFE/00-03-56.jpg)

**Context:** The video presents an investigation into the internal workings and compliance practices of the Honey browser extension, particularly focusing on its stand-down policy for affiliate links. The investigation centers on evidence obtained by a security researcher, Ben Edelman, who analyzed Honey's internal configuration files ('ssd.json') and network requests, revealing discrepancies between stated compliance rules and observed extension behavior, especially concerning affiliate network tracking.

## Detailed Analysis

The video exposes evidence suggesting that Honey intentionally circumvents its own stand-down rules, which are designed to prevent affiliate poaching and maintain compliance with affiliate network terms. The main evidence presented is an internal configuration file, 'ssd.json', which lists several major affiliate networks (CJ, Linkshare, Rakuten, Awin, Swagbucks) under its 'affiliates' section (02:59). This file also contains 'base' rules setting user point thresholds ('uP': 501) and user age checks ('uA': 2592000000, or ~8 months) that must be met for an account to be considered 'legitimate' (02:21). However, testing by the presenter showed that when using an affiliate link (e.g., Newegg via LinkShare), Honey's extension would pop up a message stating it was 'disabled on this site' (15:15), even though the internal rules for those networks existed and the user met the base criteria. Furthermore, the stand-down rules in the JSON file, which include specific regex patterns for affiliate domains, appear to be ignored in practice, as demonstrated when the presenter clicked an affiliate link for Newegg and Honey offered cash back instead of standing down (15:54). The analysis of older archived versions of the rules (from 2014) shows that certain rules, like those for 'gca' (presumably Google AdSense related) and 'bl', were not present initially, suggesting rules were added or changed over time, possibly to address known issues or hide behavior. Ben Edelman, the security researcher whose work is referenced, confirmed that the rules indicate an intent to monitor user activity and that the rules are not being uniformly applied, suggesting a deliberate choice to selectively enforce rules that benefit Honey's revenue streams (e.g., allowing engagement with its own PayPal/Honey ecosystem while standing down on network affiliate links). This selective enforcement, combined with the existence of the stand-down rules, points to a conscious decision to violate partner agreements to protect their own data collection and revenue streams.

### Investigation Setup

- The presenter investigates Honey's compliance with affiliate network rules, specifically focusing on stand-down policies, using internal configuration files ('ssd.json') and network traffic monitoring (00:02, 01:19).

### Stand-Down Rules Analysis

- The 'ssd.json' file reveals explicit stand-down rules targeting major affiliate networks (CJ, Linkshare, Rakuten, Awin, Swagbucks) with a 1-hour TTL (3600 seconds) (02:37, 16:37).

### Base Rule Requirements

- The base rules dictate that a legitimate shopper must be logged in, have an account older than 30+ days (approx. 259,200,000 ms old), and possess over 500 cashback points (02:22, 02:31).

### Observed Behavior vs. Rules

- When testing with an affiliate link (e.g., Newegg), Honey displays 'Honey is disabled on this site,' suggesting stand-down, yet the internal rules indicate it should still be active unless other conditions are met (15:15, 15:54).

### Evidence of Intentional Non-Compliance

- The presenter shows that when using an affiliate link (like Rakuten's link for Click & Grow), Honey does not stand down, contradicting the rules which should apply to those URLs (23:36).

### Affiliate Network Rules

- Examining affiliate terms (like Nike's via Awin) confirms rules against using non-authorized coupon codes, suggesting Honey's actions violate these agreements (11:34, 12:22).

### Expert Commentary

- Security researcher Ben Edelman confirms that the observed behavior (selectively ignoring rules based on user status/cookies) is intentional, designed to conceal behavior and potentially violate wire fraud statutes (03:44, 03:53).

![Screenshot at 00:01: Thumbnail showing five influencers controlled by the Honey logo, suggesting manipulation \(0:01\).](https://ss.rapidrecap.app/screens/qCGT_CKGgFE/00-00-01.jpg)
![Screenshot at 00:02: Screenshot of browser developer tools showing an SSD cookie value 'afc-howl-shortcircuit', indicating a mechanism related to stand-down rules \(0:02\).](https://ss.rapidrecap.app/screens/qCGT_CKGgFE/00-00-02.jpg)
![Screenshot at 00:04: Flowchart illustrating the decision path when an affiliate link is detected, leading to a circuit breaker check \(0:24\).](https://ss.rapidrecap.app/screens/qCGT_CKGgFE/00-00-04.jpg)
![Screenshot at 01:20: Ryan Hudson's AMA post on Reddit, where he claims to provide missing context about Honey \(1:20\).](https://ss.rapidrecap.app/screens/qCGT_CKGgFE/00-01-20.jpg)
![Screenshot at 04:44: Spreadsheet data showing affiliate network details, including 'UGC Allowed' set to FALSE for many major brands \(4:43\).](https://ss.rapidrecap.app/screens/qCGT_CKGgFE/00-04-44.jpg)
