6 ms·
Maybe it's time for the browsers to put more effort into extension network security. 1) Every extension has to declare up front what urls it needs to communica
by petagonoral 8y ago
Maybe it's time for the browsers to put more effort into extension network security.
1) Every extension has to declare up front what urls it needs to communicate to.
2) Every extension has to provide schema of any data it intends to send out of browser.
3) Browser locally logs all this comms.
4) Browser blocks anything which doesn't match strict key values & value values and doesn't leave browser in plain text.
- Chazprime 8y agoLast year several coworkers had installed a fake Postman Chrome extension that contained adware. We all reported it to Google, and on inspection others had left reviews to that effect, but Google took over six months to remove it.
- 2sk21 8y agoThis is terrifying - Postman is very widely used.
- duxup 8y agoRelated question, What would you use a Postman Chrome Extension... for? Rather than say just... use Postman? I'm not disagreeing with the use, just wondering how they use it compared to Postman itself. I'm a n00b web dev, I just want to know how others work and why.
- delecti 8y agoI can't speak to Postman specifically, because I barely use it enough for it to make a difference. But in a more general sense, I tend to prefer <thing> in a browser over <thing> but in its own window. It means one fewer program filling my taskbar.
- duxup 8y agoI can see that, but for me it's more: - Dork with code/ routes in one window and/or dorking around with the front end code. - Postman (the stand alone program) in another window to check what the return from the server really is or what the API is doing now. So I've got it on it's on dedicated space (not all the time but often enough).
- delecti 8y agoI very rarely have only a single browser window, and I'm not coding in a browser anyway, so that's not actually a huge factor in the decision. I agree with using windows to easily switch between tweak and test.
- cpv 8y ago"What would you use a Postman Chrome Extension... for" If I'm not mistaken, it started as a browser extension.
- tytho 8y agoI believe the extension can be used in conjunction with the app to let the app use the cookies in your browser session, but to be honest, I've only seen others do it, and it was back in the day when Postman was just a "Chrome App" and not a detached application. Maybe that functionality exists in the new Postman app without the chrome extension.
- czardoz 8y ago> Related question, What would you use a Postman Chrome Extension... for? Postman started off as a Chrome Extension (ran in a chrome tab), and then became a Chrome App. The standalone apps for desktops came later. A lot of people use the chrome extension because it's convenient. Source: I worked at Postman until about a year ago.
- mmmagnum 8y agoThe Chrome Extension has the 'interceptor' feature which listens to ALL network requests made in the browser on a particular page and pipes it to the Postman App. This was very neat for me to debug my requests. However, the standalone app doesn't have that feature (yet). So I will continue to use the Chrome Extension version until they have that feature available in the Standalone app.
- jordache 8y agoFor some idiotic reason the native version of Postman does not support authentication against corp proxies. As a result, when using it at work, behind a corp proxy that requires authentication, the native postman doesn't work! The only version that works is the Chrome App Postman, which simply uses the Chrome network stack, which obviously works behind the proxy. Boooo to Postman.
- Cub3 8y agoA friend of mine works for a large bank and isn't allowed to install desktop applications but has chrome installed so can 'sneak in' certain apps through browser extensions. Eg. whatsapp, 1password
- simion314 8y agoMozilla and Google should look at the top extensions and implement the popular ones as official extensions(or for some may be worth building them inside the browser), Reader mode is now part of some browsers so you do not need an extensions. Mozilla could implement ad blocking extensions and give the user the option to use custom block list(so Mozilla is not accused of becoming a gate keeper).
- johnchristopher 8y agoOr maybe not: the Firefox version of the pocket extension is badly baked (you have to wait for the adding animation to disappear otherwise it gets cancelled. The previous version was "click and it's added in the background"). The Chrome version is more usable. The great firefox redesign at the beginning of the century was about slimming down Mozilla the navigator and let extensions extend the browser. Is that the pendulum going back and forth ?
- Retric 8y agoI think the minimum browser changes over time, but without adding and removing features it's hard to discover what that minimum is. For example, some form of add or at least popup blocking should be included, but that does not preclude useful addons from customizing the experience.
- simion314 8y agoI was suggestion official extensions, so you could not install or disable them, the reason I mentioned some could be put directly in the browser is if the same functionality can't be done by a pure extension or it would be much efficient directly in the browser. I completely agree that you should be able to disable/unintall Mozilla extensions and replace them if you want with different ones(maybe you know of a better reader mode or a better ad blocker extension) In fact this extension may not even be installed , just be part of Mozilla code base so any update will be reviewed
- gowld 8y agoWhy are Mozilla and Google the only poeple you trust to maintain extensions? Why don't you or I implement the popular extensions in a user-respecting way?
- codedokode 8y agoThen every extension will require access to Facebook so that the user can share something there.
- rovr138 8y agoThey provide a URL for this - https://www.facebook.com/share.php?u=https://news.ycombinator.com/ https://www.facebook.com/share.php?u=https://news.ycombinato...
- rovr138 8y ago> 1) Every extension has to declare up front what urls it needs to communicate to. I believe Firefox has this. The rest are great ideas. Would love to see a way to log these.
- gambler 8y agoThe explanation of what each permission really does and why they are necessary are traditionally horrible, so even I, having developed a plugin once, have no clue what is reasonable and what is not.
- tracker1 8y agoLike realizing that the "flashlight app" needs camera permissions because the light is tethered to the camera permission.
- vezycash 8y agoWhat I actually need is the ability to deny / revoke access to particular URLs
- diegoperini 8y agoFor Android, it is extremely easy to do that via an app called NoRoot Firewall. What it does is it creates a VPN server on localhost and routes all traffic to that. When an app wants to connect to a host, it shows a notification which when clicked, you can see the URL/ip and the app name. Then, you decide whether you accept the connection or not. It supports permanent blacklisting and whitelisting as well. Since a browser like Opera can integrate a proprietary VPN without messing with OS network settings, doing the same on other browsers should be possible.
- vezycash 8y agoThis notification method will get the Vista UAC treatment - approve all or demy all. Because it's annoying. Have you used ever Kaspersky?
- dmitrygr 8y agoit actually doesn't because you can actually make a rule, and then the application will falollow it from that point on with no more notifications. The rule can include wild cards for parts of the hostname, or the IP address, or the port, or both
- 8y ago
- sp332 8y agoBookmarking extensions need access to all webpages though. Only #3 would potentially show something suspicious.
- saagarjha 8y agoThis shouldn’t require arbitrary network access, though. You can read the content of pages and have access to browsing history locally.
- sp332 8y agoRight, if someone is using Facebook Messenger in a browser, the message history could be scraped.
- icebraining 8y agoA bookmarking extension can use the activeTab permission, which gives them access only when the user clicks on the extension button and only to the current tab: https://developer.mozilla.org/en-US/docs/Mozilla/Add-ons/WebExtensions/manifest.json/permissions#activeTab_permission https://developer.mozilla.org/en-US/docs/Mozilla/Add-ons/Web...
- sp332 8y agoThat's a great feature. Maybe not something people would want on a personal shopper extension though, which is another type of extension that might have done the sraping. It's more convenient to just have a price alert activate when I look at an item on Amazon than having to push a button every time.
- icebraining 8y agoTechnically you can do that just with the webNavigation (allows you to see the URLs loaded) and the notifications (to alert the user).
- VMG 8y ago> 4) Browser blocks anything which doesn't match strict key values & value values and doesn't leave browser in plain text. It is not that hard to leak out arbitrary info in strings or even numbers
- nothrabannosir 8y agoOr in the timing pattern of polling a URL. 1 sec pause: 0, 2 sec pause: 1. This is a losing battle. Don't engage.
- domoritz 8y agoAny kind of enforcement would already be a huge benefit over the status quo and make things too annoying for at least half of the attackers.
- antidesitter 8y agoWhat is a losing battle? Security?
- monsieurbanana 8y agoI mean...
- admiralEyebrows 8y agoExtensions. I agree with Santosh83, no extensions except ublock.
- zentiggr 8y agoI'd be fine with uMatrix as basic browser feature. Barely use anything else ever.
- TeMPOraL 8y ago"Security" through throwing homework-level challenges at extension programmers? Yes.
- skizm 8y agoCan browser extensions block other browser extensions from communicating with an outside URL (or outside URLs in a block list)?
- vkou 8y ago> 2) Every extension has to provide schema of any data it intends to send out of browser. Just because I supplied a schema does not mean I'm not exfiltrating sensitive data, in a way that would not be obvious from the logs.
- petagonoral 8y agoHow many extensions _need_ to send data outbound? Before approving extensions for store/signing, the schema can be checked and if it's not tight enough - rejected.
- akerro 8y agoThere was a browser addon (client-side) that was encrypting facebook messages but facebook banned it.
- brokenmachine 8y agoNo using maths on messages! Just read more ads!
- rapind 8y agoAgreed, but #3 is adding another attack vector, and the implementation matters and could be complicated.
- interlocutor 8y agoNo, not secure enough. Remember ActiveX? The security policy of ActiveX was, the browser asks the user if he wants to install the ActiveX. If the user says yes, anything that happens afterwards is the users responsibility. What you're suggesting is not that much better. Do you expect your grandma to be able to review the permission list for the browser extension? Browser extensions are the modern day ActiveX. Yes, lots of them are very useful. But you could say the same about ActiveX controls too.
- bostik 8y ago> policy of ActiveX was, the browser asks the user Therein lies the problem. The entire industry has, ever since windows 3.1 (!), done their best to condition users with a single and highly destructive mindset: "Press OK to make the annoying window go away." The only way around this, and I'm not saying this lightly, would be to make the pushers and vendors CRIMINALLY AND PERSONALLY liable for the damage they cause to end users. Once we see the third or fourth offender nailed through their genitals, head down, on the town hall wall, the message will start to get through.
- tracker1 8y agoA lot of it happens in countries other than country of origin... and extradition is difficult and often expensive. Though, I wouldn't mind seeing the people that write rogue extensions that harm people get doxed.
- petagonoral 8y agoNo, I expect browser staff/interested technical parties to review extension before publication. Why would your grandma review it?