4 ms·
Exactly. What Chrome and Firefox should do, is bundle their own analytics program into the extensions program, make these analytics available via AMO or Chrome
by bgdam 6y ago
Exactly. What Chrome and Firefox should do, is bundle their own analytics program into the extensions program, make these analytics available via AMO or Chrome Web Store (already has a very basic version), and remove the ability for extensions to perform outgoing network requests unless the user explicitly whitelists the extension. Even then, show big scary warnings about extensions given this permission being able to steal your bank passwords, just to keep the less tech-savvy informed.
- Thorrez 6y agoOne thing extensions commonly do is modify the page. If an extension can modify the page, it can insert an <img> which will cause a network request to happen. How do you plan to prevent this? Prevent extensions from modifying the page?
- AznHisoka 6y agoSame suggestion applies. Show users the warning that extensions can modify your page and have users explicitly approve of it.
- pornel 6y agoAnd they already do that. The problem is, almost every extension has a legitimate need to read and/or modify the page, so people click through this permission warning like Vista's UAC.