5 ms·
Why does it seem like browser extensions are ignored in all of these discussions? For example, right now the Honey Chrome extension has permission to "Read and
by trevor-e 8y ago
Why does it seem like browser extensions are ignored in all of these discussions? For example, right now the Honey Chrome extension has permission to "Read and change all your data on the websites you visit". They could be doing anything with that, I'm just crossing my fingers that they find me good deals and don't abuse my data.
Chrome actually acknowledges this: "Warning: Google Chrome cannot prevent extensions from recording your browsing history. To disable this extension in incognito mode, unselect this option."
Related question: why can't we restrict the domains that Chrome extensions can read data from?
- murukesh_s 8y agoYa I think an option to ask permission per website should be there..it could be subtle like an orange icon that you need to manually click the first time to give permission to that domain
- paradite 8y agoI have developed Chrome extensions. You can specify the domains that your extension runs on (via regex like syntax). However, I am not sure if Chrome surfaces this information to its users.
- MBCook 8y agoThat’s not an issue in iOS/Safari because extensions can’t do that kind of thing. I’ve seen other people complain about this for chrome. I saw people justifying it by saying that that permission is necessary if you want to interact with the page directly (hide/show content, etc.). Doesn’t mean the extensions are to be using it, but it may be necessary. Much like GPS data for a weather app.
- saagarjha 8y agoSafari extensions can do the same, both on macOS on iOS (though significantly reduced, since loading the extension requires user interaction).
- MBCook 8y agoMy understanding was you couldn’t even have extensions on iOS, except for ad blocker style things which are explicitly limited by API to prevent blocker from knowing what it was blocking due to tracking concerns. I may be wrong about safari on Mac iOS.
- saagarjha 8y agoNo, there are extensions for both macOS and iOS. For iOS the user needs to explicitly tap the extension for each page they want it work on, while on macOS it can run on every page once it’s been approved.
- dschuetz 8y agoGPS data for a weather app is not necessary, because it's way to precise for its purpose. Most of the time I need to know how the weather is elsewhere, or how the weather is going to be today. How does precise (to a meter) GPS data help me there exactly?
- acdha 8y agoNot to the meter but we get plenty of rainstorms where a half mile makes the difference between wet and dry, and Dark Sky’s push alerts are surprisingly useful.
- throwaway2048 8y agoThere isn't weather stations every half mile.
- ClassyJacket 8y agoIrrelevant, radar has accuracy at that level.
- acdha 8y agoThey use radar and software to predict storm growth and trajectories. Next time you look at a radar map ask yourself the physical size represented by one pixel: in much of the United States it should be something like 150m.
- tripzilch 8y agoI use a precipitation radar app that tells me with fair amount of accuracy whether/how heavily it's going to rain 15-90 minutes from now. It often does matter what part of the city you're on. Since we bike everywhere to get around, it's kind of nice to get an idea whether waiting another 10 minutes to leave avoids the heaviest part of a shower, or better just bite the bullet because it's only getting worse in the next hour. Although now that I think of it, I have its location locked to my home address because I didn't feel like being tracked :) It generally works well enough within ~3km or so, and I compensate the hit in accuracy by looking at the sky and drops/splashes in puddles/windows/cars (it's much harder to judge the intensity of rain by trying to spot droplets in mid-air). I don't need the longer term forecast quite as much to have an app for it, for that I just use a bookmark to my local news weather page.
- O_H_E 8y agoDevelopers could specify that their extensions work on certain domains only, but apparently the user can't
- endless1234 8y ago>Related question: why can't we restrict the domains that Chrome extensions can read data from? The extensions can do this. E.g. a Strava extension would on install say it has access to *.strava.com (and possibly other domains).
- kkarakk 8y agothat's hardly practical, the point of most extensions is that they stay with you as you browse the web to enhance the functionality of websites. a coupon tracker like honey that only works on amazon.com would obviously be superceded by a coupon tracker that worked everywhere on the web. users would just keep adding permissions to access websites until the whole thing became an exercise in frustration
- mrmr1993 8y agoI've always thought the permissions model of Chrome/Firefox/Edge extensions is a bit upside-down: extensions need permissions to access data, perform actions in the browser, and modify/contact specific or arbitrary URLs, but there are no permissions to prevent them from being abused in combination. A data-flow permissions model would go a long way to improving privacy when using extensions. For example, Vimium (which I've worked on in the past) needs access to every page so it can add its key bindings, most browser functionality so it can trigger it when the appropriate key is pressed, and history, tabs, etc. so that commands for opening these work correctly. This combination gives Vimium full permission to harvest data and send it to arbitrary URLs, open tabs to random spammy URLs, and generally invade the user's privacy in any way that an extension possibly could, if it so desired. As an alternative, it would be nice to have some kind of data source marker (user-provided to extension, user-provided to webpage, webpage data, browser data, hardcoded data) and then flow permissions around these, so you can have permissions like: - open tabs/make requests/load images/etc. with user-provided URLs - open tabs/make requests/load images/etc. with URLs found in/derived from webpage URLs (in the same origin) - open tabs/make requests/load images/etc. to URLs with a hardcoded origin - include some kind of browser information in a request to one of the above types - include data a user has provided to a webpage in a request to one of the above types - include webpage data in a request to one of the above types - inject browser data into a webpage with a specific/arbitrary URL - etc. By separating permissions for what requests extensions can make, what data can be included in requests, what webpages they can affect, and what behaviours they can trigger, it should be very easy to see what an extension is/could be doing. Sadly, this would be very technically challenging to implement, there doesn't seem to be much appetite for it, and there's a real danger of overcomplicating the permissions model so that it becomes unusable. Just my €0.02.