5 ms·
What are your thoughts about it being an open source extension?
by lightswitch05 7y ago
What are your thoughts about it being an open source extension?
- nickjj 7y ago> What are your thoughts about the being an open source extension? It being open source doesn't guarantee what you see on GitHub is the code that the extension uses. I'm not saying this author is acting maliciously but a very common attack is to say something is open source, point to the repo but in reality the code running in the extension is unrelated to that repo. This often happens with packages installed by popular package managers. The home page of the package will be linked to GitHub so it appears to be open source but the package itself has different code because most of these package hosting sites don't pull in code directly from GitHub. The package author can publish code from a private closed source copy of the code sitting on their dev box and no one would ever know unless they looked at the source code after installing the package. Now, when it comes to Chrome extensions I do believe there's ways to check out the source code of any extension you use, so you could double check it there but then you have to worry about the extension getting updated too.
- gruez 7y ago>I'm not saying this author is acting maliciously but a very common attack is to say something is open source, point to the repo but in reality the code running in the extension is unrelated to that repo. The extension is small enough that you can inspect it yourself. Also, AMO addons are code-inspected by reviewers, unlike the chrome store. >Now, when it comes to Chrome extensions I do believe there's ways to check out the source code of any extension you use, so you could double check it there but then you have to worry about the extension getting updated too. That's why I disable addon updates for "uncommon" addons.
- nickjj 7y ago> The extension is small enough that you can inspect it yourself. Also, AMO addons are code-inspected by reviewers, unlike the chrome store. I've never been involved with performing code reviews for Chrome or FF extensions but I'm not sure this type of attack would be detected by a reviewer. Because if all they do is take the HTML response and send it over to some web back-end with an ajax request, that looks innocent enough to any reviewer. For example, under what grounds would a reviewer flag that ajax request as malicious and prevent the extension from being published? It's not possible for them to know what purpose that data has for the extension unless they are really doing a deep dive on each review and take the extension's purpose into account based on their opinion of what it "should" do based on its description. I'd love to hear back from anyone who happens to review extensions for either browser.
- commoner 7y ago> if all they do is take the HTML response and send it over to some web back-end with an ajax request This extension does not do that. Most extensions with the "Access your data for all websites" permission also do not do that. The permission is required to scan data (in this case, links) in the websites visited by the browser, and does not mean that the data in the website would necessarily be sent to a server. Neat URL processes the links locally. You can inspect the source code of any WebExtension you have installed by downloading the package, renaming it to the .zip extension, and unzipping it (as .xpi files are equivalent to .zip files). For Firefox add-ons, right-click the "Add to Firefox" button on the extension listing, and click "Save Link As...". The code is not minified or obfuscated. https://addons.mozilla.org/en-US/firefox/addon/neat-url/ https://addons.mozilla.org/en-US/firefox/addon/neat-url/
- commoner 7y agoSmall correction: you don't need to install the WebExtension to inspect it. You can just download and unzip it.
- gruez 7y ago>Because if all they do is take the HTML response and send it over to some web back-end with an ajax request, that looks innocent enough to any reviewer. For example, under what grounds would a reviewer flag that ajax request as malicious and prevent the extension from being published? It's not possible for them to know what purpose that data has for the extension unless they are really doing a deep dive on each review and take the extension's purpose into account based on their opinion of what it "should" do based on its description. I think you're giving the reviewers too little credit. There's no plausible reason why you'd need to send urls to a server to perform such a trivial transformation. Also, a search of BMO[1] shows that addons are regularly being found to breach these policies and blacklisted. [1] https://bugzilla.mozilla.org/buglist.cgi?product=Toolkit&component=Blocklist%20Policy%20Requests https://bugzilla.mozilla.org/buglist.cgi?product=Toolkit&com... control-f for "Add-ons collecting ancillary data".
- blattimwind 7y ago> Because if all they do is take the HTML response and send it over to some web back-end with an ajax request, that looks innocent enough to any reviewer. That's extremely not innocent for ANY browser extension.
- slightwinder 7y ago> Also, AMO addons are code-inspected by reviewers, unlike the chrome store. Are they still? Last I remember they started auto-accepting addons which passed the automatic tests and just maybe review them at a later point. Which could happen anytime between tommorow and next year. In the meanwhile the unsecure addon is floating around, endangering users. There now is also this message: "This is not a Recommended Extension. Make sure you trust it before installing." This kinda indicates the user is on it's own with such extensions, and there is no review at all?