4 ms·
> Because if all they do is take the HTML response and send it over to some web back-end with an ajax request, that looks innocent enough to any reviewer. That
by blattimwind 7y ago
> Because if all they do is take the HTML response and send it over to some web back-end with an ajax request, that looks innocent enough to any reviewer.
That's extremely not innocent for ANY browser extension.
- nkrisc 7y agoYeah, that alone should be a huge red flag unless it's something the add-on explicitly advertises, like it's doing translation or something.
- nickjj 7y agoThat was just a broad example. What if it got a list of every link on a page and sent that and then claimed it did that to better improve the extension by figuring out which query params aren't necessary and claimed that these links help train their app / extension. That seems reasonable on paper, but it's a wildly over the top violation of your privacy and is only slightly less invasive than an entire page response. I don't think the above example would get denied by a reviewer and it still uses the same "can read and modify" permissions as the current extension in its current form.
- gruez 7y agoThen it'd probably need a privacy policy and/or disclaimer in the addon description, which in turn would cause people to find out and downrate it to obscurity.
- nickjj 7y agoAre you saying it wouldn't get accepted during the review unless it had that in the description? That seems like a dangerous rule to live by if an extension is allowed to collect all of that information and it's auto-opt-in based on it existing somewhere buried in a privacy policy or long description. We really only ever notice the permission setting because the browser puts that in front of us before agreeing to install it and it's usually a 1 liner like "hey, this extension can access everything about your browsing history".