4 ms·
I don't get how one is supposed to stay secure with the current way extensions work: all you have access to is a button that only installs and runs an extension
by Grom_PE 3y ago
I don't get how one is supposed to stay secure with the current way extensions work:
all you have access to is a button that only installs and runs an extension, and
at any point of time, it may automatically update with malicious code after the author has agreed to transfer control to someone else for an enticing sum of money. It happened several times before.
To fix this, I've made my own UserJS that changes the "install" button into "download CRX",
then I unpack the CRX file and remove the autoupdate URL from it so the code stays as it was when I last looked at it.
Sometimes the extension's job is not worth having an extra extension installed (each spawns its own separate background process) so I paste the code into a userscript or a conglomerate extension instead.
The chromium-based browser I use, Vivaldi, prevents injecting user scripts into "chrome.google.com" so I have to change the string in the browser binary to something like "chrame.google.com". Then it works.