3 ms·
As much as I've defended this change, I agree with you. The only justification I could see is that it might require an extra permission in an extension's manif
by SquareWheel 7y ago
As much as I've defended this change, I agree with you. The only justification I could see is that it might require an extra permission in an extension's manifest, but even that I'm not sure of.
If this is part of a longer-term plan to deprecate webRequest and completely remove that ability, then they should say so now.
- SquareWheel 7y agoThis might create a confusing link loop, but a dev commented to explain this rationale now. https://twitter.com/justinschuh/status/1138889508512866304 https://twitter.com/justinschuh/status/1138889508512866304
- snowwolf 7y agoSo lets take an alternative look at this. The justification is that this improves privacy, security and performance. For who? I use 2 extensions, an Ad Blocker (uBlock Origin) and Password Manager. uBlock Origin has over 10M installs and the author has stated publicly that they cannot effectively do what they do if this change goes ahead. I can guarantee that uBlock Origin does more to protect my privacy, security and performance than this change. How many people have been affected by malicious extensions? I seriously doubt it's greater than 10M. So to improve the privacy, security and performance for a few, they are going to make it worse for the many. Surely there are better solutions to tackle this problem? Maintain the API but add in additional checks/vetting for any extensions that use it.
- dfabulich 7y agohttps://www.vice.com/en_us/article/zmdxxj/the-hack-millions-of-people-are-installing-themselves https://www.vice.com/en_us/article/zmdxxj/the-hack-millions-... > Last year, hackers phished Chris Pederick, who runs Chrome Web Developer, an extension with over one million users. Once they had grabbed Pederick’s developer login details, they swapped his extension on the Chrome Web Store with their own malicious version, designed to inject adverts into users’ browsers. Then in September, someone loaded the popular Chrome extension for file sharing service MEGA with code that could steal login details for Amazon, GitHub, Microsoft, and Google accounts, as well as pinch cryptocurrency keys. And a malicious browser extension appears to be behind a recent dump of private Facebook messages. Once hackers gain control over the extension, through hacking, coercion, or otherwise, they can replace code as they see fit. There's a lot more where that came from. Aside from hacking the extensions, a couple of years ago there were severe issues with people buying control of popular extensions and then converting them into malware.
- tedivm 7y agoThat's a problem that would have been solved with requiring 2fa.
- snowwolf 7y agoSo there's a few things to unpack here. > with their own malicious version, designed to inject adverts into users’ browsers Your very first example wouldn't be prevented by these changes. > 42% of malicious extensions use the Web Request API So 58% don't event need the Web Request API to do something malicious. So these changes don't really improve safety at all. > hacking the extensions, buying control of popular extensions Both these scenarios need to be addressed at a different level. Things like enforcing 2-factor for high value extension authors (> 100K installs or something). Also remember Google operate a walled garden here. No extension can be published on the store without being vetted. They should be identifying high profile/value extensions and subjecting them to additional checks. For me, and I'm sure many people, my biggest threat vector is ads. They threaten my security (malicious/malware laden ads), my privacy (tracking), and performance (slow, bloated ads). My ad blocker protects me every day from this threat vector. Google are now definitively weakening mine and a lot of other peoples protection in order to improve the security of the few. To me this does not seem like a reasonable compromise, especially when there are alternative ways to address their concerns. And I'm sorry, but I really don't trust the motivations of a company that makes billions of dollars a year off online advertising, that has publicly stated that Ad Blocking is a threat to their business model, to then be making a change that just so happens to cripple Ad Blockers.
- SquareWheel 7y ago>uBlock Origin has over 10M installs and the author has stated publicly that they cannot effectively do what they do if this change goes ahead. With the new changes to the spec outlined in this post, this may not be true anymore. Rules can now be updated with an extension update, network headers can be blocked, and the number of rules has been increased. I don't know exactly what other features may be needed, but I imagine this helps close the gap. We'd have to hear from gorhill to know more.
- danShumway 7y agoIf you're curious, here's Gorhill's reaction immediately after Chrome announced they were planning to support dynamic rules. None of the updates seem to have changed his position that this would cripple Ublock Origin. https://github.com/uBlockOrigin/uBlock-issues/issues/338#issuecomment-464340152 https://github.com/uBlockOrigin/uBlock-issues/issues/338#iss... > I don't know exactly what other features may be needed I know this sounds like a dismissive, catch-22 answer, but the big thing missing is being able to run arbitrary code to decide whether or not a request should be blocked. And that is something the Chrome team has been pretty clear that they are not going to compromise on. Right now, people are compiling lists of different filter capabilities they want, but (at best) that is only going to close the gap some of the way to what ad blockers are currently doing. Ultimately this puts Chrome in the position where every time a developer comes up with an interesting strategy for blocking ads or filtering/redirecting web traffic, they'll need to go to Google and ask them for permission to do it. The fundamental functionality block is the thing Google wants to block -- arbitrary, developer-defined logic. This is not nearly as complicated of a situation as Google is making it out to be. Google is arguing that developers should not have the ability to arbitrarily block requests, and developers (particularly ad block developers) are arguing that they should. Gorhill's position is that matching algorithms are fundamentally not powerful enough to support a healthy ad blocking ecosystem.