4 ms·
Can someone explain to me why it isn't possible to simply give users the option to influence whether an extension can make a request to a remote server? This w
by user812 8y ago
Can someone explain to me why it isn't possible to simply give users the option to influence whether an extension can make a request to a remote server?
This way one could simply disallow extensions to do anything that isn't happeninging locally.
- Ajedi32 8y agoWhen an extension has the ability to inject arbitrary JS into a page, it's not easy to determine whether any given request is being triggered by the host page or by the extension.
- rictic 8y agoIt's trickier than it seems. To take just one example, suppose you have an extension that modifies pages to insert a related link (e.g. an extension that tries to infer a hacker news user's reddit account and link to it from their HN profile page). The extension needs permission to modify documents on the hacker news domain. But if it can insert an <a> tag, what's to stop it from inserting an invisible <img href> tag, which could be used to exfiltrate data? Or even just inserting an <a> tag with an onClick handler, or a javascript: url?
- andrenotgiant 8y agoRight - or even trickier... Imagine Google manages to block extensions from inserting <img> tags that reference other domains as a way of exfiltrating data... There are so many other ways to do it: Say you have an extension that ONLY wants access to mail.google.com. It might feel safer because it can't load in any third party scripts. But it can just as easily SEND data from your account as an email which it promptly deletes. Same goes for LinkedIn, Facebook, HN, any interactive website can be used to exfiltrate data.