4 ms·
You're doing a very admirable thing, and this helps dispel the little voiced but commonly held perception that "everybody sells out" when they get big.
by imoreno 3y ago
You're doing a very admirable thing, and this helps dispel the little voiced but commonly held perception that "everybody sells out" when they get big.
- btown 3y agouBlock Origin is also an incredible success story here!
- chii 3y agoand you are essentially trusting the moral integrity of the current maintainer. why can't there be a method for making sure that such trust cannot be abused? Is this a tractable problem at all?
- PNewling 3y agoYou'd still have to rely on the trust of the original maintainer, but they could set up something like a warrant canary[0], but for if they sold it or if they added tracking items. [0] https://en.wikipedia.org/wiki/Warrant_canary https://en.wikipedia.org/wiki/Warrant_canary
- chii 3y agowarrant canary assumes the maintainer is under coercion. But if the maintainer is untrustworthy, their warrant canary also won't be trustworthy, since it's trivial for the "sale" and the new maintainers to continue the existing warrant canary as though nothing has happened.
- eipi10_hn 3y agoI don't think there's a solution for it after all. At the end of the day, you need to trust someone / something, unless you are the one who writes the whole code. Which browser are you using?
- chii 3y agoBlockchain technology! ;D
- btown 3y agoI do think that reproducible builds would make a lot of sense for open-source browser extensions. Google could say "if you want your extension to get a Trusted Build tag, put the source code on Github, and we'll run the build script for you to ensure that the code submitted for store review is built from the code from a specific Git commit." And from a security perspective this would be better than what we have, which is zero guarantee that an "open source" extension even matches its stated repository. I'd trust the integrity of Google's automated build systems more than an independent developer with nothing to lose and everything to gain by sneaking in a third-party script. Alas, the presence of this kind of reproducible build system would bring needed clarity to the chaotic ad blocker market, and the lack of that clarity works in Google's favor as an advertising company, so sadly I doubt they'd do such a thing.
- eipi10_hn 3y agoYes, that's what I mean, at the end of the day, you have to trust somebody / something. Here you have to trust both developer's code and Google's build system. Can you verify all of the developer's codes? And can you verify how privacy-trustworthy Google's build system is? At the other side, you have to trust developer's code and developer's build. I didn't mean which one you "should trust more" at all in my comment above. Please read again. What I mean is the first sentence here.
- YeBanKo 3y agoThere is a method. Designing plugin and system API in such a way that allows users a granular control over plugins or apps permissions and network activity.
- chii 3y agoBut that doesn't solve the problem of a plugin developer selling out. Under the granular permission control, your existing, granted permissions _should_ be revoked, but there's no way you could know to revoke it.
- YeBanKo 3y agoSomething like a plugin is a fairly well defined thing and ideally should not need a lot of permissions. E.g. an ad blocker has a simple flow: occasionally update filters from a number of specified endpoints and then match and block web pages’ request urls against downloaded lists. Between update it should have zero web traffic and filter updates are expected to be from known whitelisted sources and asymmetrical in size: very few bytes sends and a lot received. If all of a sudden after an update your plugin wants to send a bunch of data to a new URL you know immediately something is fishy. With respect to granularity, in this case the plugin might not even need to know the entire URL but just the host/domain name - this makes it less attractive to adtech.
- paulryanrogers 3y agoYet the very same author turned over the OG uBlock to a shady character, having to launch a competitor to take back the momentum. To this day there is still confusion among normies.
- gorhill 3y agoI didn't turn over the extension in the Chrome Webstore, I always have been the owner of it since I first published uBlock in June 2014.
- paulryanrogers 3y agoThanks for clarifying. I stand corrected. Curious if you've secured the trademark? Seems someone has tried with #78022486