2 ms·
So there's a few things to unpack here. > with their own malicious version, designed to inject adverts into users’ browsers Your very first example wouldn't b
by snowwolf 7y ago
So there's a few things to unpack here.
> with their own malicious version, designed to inject adverts into users’ browsers
Your very first example wouldn't be prevented by these changes.
> 42% of malicious extensions use the Web Request API
So 58% don't event need the Web Request API to do something malicious. So these changes don't really improve safety at all.
> hacking the extensions, buying control of popular extensions
Both these scenarios need to be addressed at a different level. Things like enforcing 2-factor for high value extension authors (> 100K installs or something). Also remember Google operate a walled garden here. No extension can be published on the store without being vetted. They should be identifying high profile/value extensions and subjecting them to additional checks.
For me, and I'm sure many people, my biggest threat vector is ads. They threaten my security (malicious/malware laden ads), my privacy (tracking), and performance (slow, bloated ads). My ad blocker protects me every day from this threat vector. Google are now definitively weakening mine and a lot of other peoples protection in order to improve the security of the few. To me this does not seem like a reasonable compromise, especially when there are alternative ways to address their concerns.
And I'm sorry, but I really don't trust the motivations of a company that makes billions of dollars a year off online advertising, that has publicly stated that Ad Blocking is a threat to their business model, to then be making a change that just so happens to cripple Ad Blockers.