4 ms·
I sure as hell won't install a browser extension if its source code isn't publicly available; I don't see how the government should or even could protect us fro
by archduck 6y ago
I sure as hell won't install a browser extension if its source code isn't publicly available; I don't see how the government should or even could protect us from every update made to all of the software packages I import (even if the punishment for malware is severe); and large corporations may be able to get their hands on source code, but I don't trust them either. The FSF may be stuck in the '80s in some ways, but their fundamental principles are solid. I much prefer their vision to one that has users "freed" from source code, trusting large and opaque companies and government agencies, whose interests may not align with mine, to shield me from malicious actors, of which there are many. Honestly, if anyone is stuck in the past and not relevant anymore, it's not the FSF; it's people who downplay malicious actors, fail to recognize that software is often tiny, or updated frequently, or written by someone anonymous or outside of US jurisdiction whose behavior we can't punish with US law. A lot of software is made up of forks too, and not many software forks end up useless like in his anecdote about his company forking Windows... Yeah, this dude obviously hasn't been keeping up to speed since his retirement.
- dt3ft 6y agoHow much time on average do you spend on reviewing the source code of a given browser extension before you install it? Also, how do you make sure that the published source code is 1:1 with what you are actually installing?
- qlk1123 6y agoWhy did this post get downvoted? they are fair enough questions to "given enough eyeballs, all bugs are shallow", especially for browser plugins.
- someperson 6y agoYou don't need to do a thorough code review to benefit from the source code: the Chrome/Chromium web browser allows the user to load unpacked extensions directly from any folder. So simply git clone the extension, have a quick look at the recently opened (and closed) issues/PRs for any red flags, git checkout the most recent tag, and load it as unpacked. Then you are guaranteed to have the source code of exactly the extension you're running, and have done a reasonable amount due diligence for malware. And if you're interested at any point in the future you can do a code review. It's a simple strategy. Here's an example: https://github.com/igrigorik/videospeed https://github.com/igrigorik/videospeed