3 ms·
> However, the vast majority of the malicious extensions (245 out of the 295 extensions) were simplistic utilities that had no other function than to apply a cu
by benjaminjackman 6y ago
> However, the vast majority of the malicious extensions (245 out of the 295 extensions) were simplistic utilities that had no other function than to apply a custom background for Chrome's "new tab" page.
So I have to make my own browser extensions just for one purpose, to set my own custom url for the newtab page. This is also a problem in firefox. It's quite unfortunate that browsers have moved so far from being user-agents, or at least somewhat attentive to the needs of more sophisticated users that instead of getting more robust tooling for user style sheets, custom javascript, apis to block or modify requests we are either forced into sketchy extensions that replicate the basic functionality or can't even do that because it's outright blocked.
Heck firefox has what seem to be perpetually unfixable bugs with bookmarklets not working on CSP[1] sites (for example github) which contradicts the spec and which never seem to be prioritized for being fixed.
1: https://stackoverflow.com/questions/19822716/javascript-bookmarklet-on-site-with-csp-in-firefox https://stackoverflow.com/questions/19822716/javascript-book...
- kevingadd 6y agoSpecs are wrong sometimes, and I think there's an argument to be made that the spec is wrong here. Firefox's policy re: bookmarklets on CSP sites is probably the best choice for protecting ordinary computer users, bookmarklets and javascript: urls are a common attack vector for targeting high-value websites like discord, slack and gmail (with the caveat that browsers have slowly locked down those attacks). Just open the developer console on discord sometime, they show an enormous message telling you not to paste stuff in there. I do think it would be worthwhile to have some sort of power user mode to override that for bookmarklets, but I can understand not wanting to invest resources in building it.