4 ms·
I've always thought the permissions model of Chrome/Firefox/Edge extensions is a bit upside-down: extensions need permissions to access data, perform actions in
by mrmr1993 8y ago
I've always thought the permissions model of Chrome/Firefox/Edge extensions is a bit upside-down: extensions need permissions to access data, perform actions in the browser, and modify/contact specific or arbitrary URLs, but there are no permissions to prevent them from being abused in combination. A data-flow permissions model would go a long way to improving privacy when using extensions.
For example, Vimium (which I've worked on in the past) needs access to every page so it can add its key bindings, most browser functionality so it can trigger it when the appropriate key is pressed, and history, tabs, etc. so that commands for opening these work correctly. This combination gives Vimium full permission to harvest data and send it to arbitrary URLs, open tabs to random spammy URLs, and generally invade the user's privacy in any way that an extension possibly could, if it so desired.
As an alternative, it would be nice to have some kind of data source marker (user-provided to extension, user-provided to webpage, webpage data, browser data, hardcoded data) and then flow permissions around these, so you can have permissions like:
- open tabs/make requests/load images/etc. with user-provided URLs
- open tabs/make requests/load images/etc. with URLs found in/derived from webpage URLs (in the same origin)
- open tabs/make requests/load images/etc. to URLs with a hardcoded origin
- include some kind of browser information in a request to one of the above types
- include data a user has provided to a webpage in a request to one of the above types
- include webpage data in a request to one of the above types
- inject browser data into a webpage with a specific/arbitrary URL
- etc.
By separating permissions for what requests extensions can make, what data can be included in requests, what webpages they can affect, and what behaviours they can trigger, it should be very easy to see what an extension is/could be doing. Sadly, this would be very technically challenging to implement, there doesn't seem to be much appetite for it, and there's a real danger of overcomplicating the permissions model so that it becomes unusable.
Just my €0.02.