5 ms·
I don't agree with the article at all. Chrome is being completely honest with the user. If a youtube extension asks permission to "read data from all websites"
by _nedR 10y ago
I don't agree with the article at all.
Chrome is being completely honest with the user. If a youtube extension asks permission to "read data from all websites" you must ask yourself and the developer why it needs access to all websites and not just youtube. A good extension must enumerate all the permissions it demands and give good reasons why it needs each of them. If an extension seeks new permissions, then consent must be sought from the user before update . This is obviously the correct approach(How it affects the extension developer's revenue\user-adoption is unimportant). Chrome's model is comparable to the security model of Android and iOS. Sure its not perfect, But its much better than the firefox model which is comparable to Windows 98.
Also i don't understand the whole shifting of responsibility jibe. Does Mozilla review every extension and every update in their store? Do they accept responsibility if malicious code is downloaded from their store?
To conclude , i would like firefox's stringent app review process and chrome's fine-grained permissions and sandbox model.
Edit: I want to point out that this article is really looking after the interests of the developer, and not after the interests of the user.
Edit 2 : Also to add: Sandboxing is simply good security practice. Even if the author is not malicious, but in case an extension is exploited due to a bug, the damage done by a well-sandboxed extension is limited by the permissions granted. In firefox such an exploit could hoover all your data, credit card info & passwords from all your websites and data from you harddrive as well.
- Manishearth 10y ago> Chrome is being completely honest with the user. The article is not advocating otherwise. A lot of extensions need that permission, even though they only need it to do something much more specific. Adblock uses it to read (but not transmit) your webpages, and remove sections. Password managers use it to scan (but not transmit) webpage content, and fill certain form fields. If there is a review process (which Firefox already has in place), then you can actually give out permissions like this. You can ensure that the data read from the webpage is never sent to the server, and useful things like that. I believe the proposal for webextensions in Firefox is to have certain kinds of extensions get auto-approved, the ones which need simple, sandboxable permissions (not "read all my webpages"). Extensions that need more permissions will need review, and they can request semantic permissions instead of just "give me all your data and trust I don't do anything bad with it", which is bad and has already lead to issues in the past where a Chrome extension developer sells their extension which is then used to transmit malware. > To conclude , i would like firefox's stringent app review process and chrome's fine-grained permissions and sandbox model. The article is proposing finer grained permissions than Chrome.
- _nedR 10y ago>A lot of extensions need that permission, even though they only need it to do something much more specific. Adblock uses it to read (but not transmit) your webpages, and remove sections. Password managers use it to scan (but not transmit) webpage content, and fill certain form fields. Yes. But the user should be made aware of the consequence of their action. Do they realize that installing a password manager means granting access to all their data to a third party. Is this author reliable? What do other users think of the author? Has anyone reviewed the code for this? These are all questions potential users should ask. >they can request semantic permissions instead of just "give me all your data and trust I don't do anything bad with it", which is bad and has already lead to issues in the past where a Chrome extension developer sells their extension which is then used to transmit malware. A lot of things cannot be controlled either by review process or sandboxing. What if your extension has a web-component ( say your password manager backs up passwords to the cloud)? Mozilla cannot review your server code. A sandbox won't protect resources you have already given access to, but it will limit the damage done. >The article is proposing finer grained permissions than Chrome. I have reread the article and haven't found anything that backs this assertion. Indeed the author seems to say : Mozilla vouches for me, so you trust me with all your stuff too. From article : 'Wouldn’t it be a better idea to keep doing that so that the installation prompt can simply say: “Hey, we made sure that this extension is doing what it says, want to install it?”' Edit : I agree that some form of review is needed for extensions. Simple sandboxing alone is not enough. But article doesn't seem to support sandboxing.
- Manishearth 10y ago> Yes. But the user should be made aware of the consequence of their action. Do they realize that installing a password manager means granting access to all their data to a third party. Is this author reliable? What do other users think of the author? Has anyone reviewed the code for this? These are all questions potential users should ask. No. That is the point I and the article am making. If the addon store has a review process in place (again, Firefox has this), it is possible to verify that the password manager is not leaking data to the third party. The answer to "has anyone reviewed the code for this" is yes. > What if your extension has a web-component ( say your password manager backs up passwords to the cloud)? Mozilla cannot review your server code. Yes, in which case they can say that it grants access to all your passwords. A password manager that encrypts it correctly won't need to. These are semantic permissions, so you can differentiate between the two. > I have reread the article and haven't found anything that backs this assertion. Indeed the author seems to say : Mozilla vouches for me, so you trust me with all your stuff too. From article : "For example, a reviewer could determine whether the extension is merely modifying webpage behavior or actually extracting data from it. " -- this is exactly more finer grained than "can access everything". Addons that don't need any sort of access permission can still be sandboxed to not be allowed to access them. It's not clearly spelt out in the article, but from what I've heard/read the system is planned to be something like "If you don't need any dangerous permissions, you don't need review and we will sandbox you. If you need something that can be abused, there will be a review component." This article proposes that the review component be used to further improve the UX of the permissions displayed to the user. You bring up a valid point about trusting the reviewers. Remember that since this is more finer grained, Chrome's coarser machine-verifiable sandboxing permission levels will still exist underneath. It would be interesting to expose a mode where it shows the "if you don't trust the reviewers, these are the software-enforced permissions the app has". > : Sandboxing is simply good security practice. Even if the author is not malicious, but in case an extension is exploited due to a bug, the damage done by a well-sandboxed extension is limited by the permissions granted. In firefox such an exploit could hoover all your data, credit card info & passwords from all your websites and data from you harddrive as well. The article doesn't say it's going to avoid sandboxing. It's building a finer-grained semantic system on top of the existing review process and sandboxing system. > Edit: I want to point out that this article is really looking after the interests of the developer, and not after the interests of the user. How? An addon review process is explicitly worse for developers. This article is all about exposing better UX for permissions, for the user. So that they don't get desensitized to overly broad permission requests. I feel that you're lacking some context on the proposal here; but I'm not sure what.
- pfg 10y agoThe article does make a good point regarding warning fatigue, which was one of the main reasons why Android is moving towards a permission system similar to what iOS does, i.e. ask for permission only when needed, and degrade gracefully if the permission is not granted. The previous system of showing a gigantic list of required permissions probably caused most users to a) blindly accept the permissions or b) not install some apps out of fear. That model is probably not that good a fit for browser extensions. There might be a couple of permissions where this would work, but the biggest issue is definitely the "Read and change all your data on the websites you visit." permission, and that's not really something you could work around with using on-demand prompts. The idea of combining code reviews with an explanation of the required permissions provided by the developer and vetted by the reviewers sounds interesting, but it's not clear to me whether a model like that would work in practice.
- zeta0134 10y agoI think the biggest trouble is that the vast majority of useful browser extensions need to read and/or modify the content of web pages. Often both. So the ability to "Read and change all your data on the websites you visit" is a really common use case for extensions in general. I'd love to see some user controls on extensions. A great many ad blockers have a feature built in that allows you to disable them on particular websites to work around cases where the blocker has broken the site inadvertently. I want to see this in reverse: I'd like to be able to very easily say to my browser, "OK, this youtube extension can run on youtube.com, and also on *.tumbler.com to make some change to embedded youtube players on people's blogs, but nowhere else." This isn't even particularly advanced to implement: the extension can simply be disabled by default, and either prompt to activate through some browser-controlled trigger, or wait until the user turns the extension on. I think that would stand a fair, usable middle ground between the more common all-or-nothing approach to that particular permission.
- pfg 10y agoThat's a great idea. The implementation could look similar to how Firefox handles plugins today, offering the option to "Always activate", "Ask to activate", and a way to say "Always allow for this domain". Other permissions could still be handled with the iOS or Android approach.