50 ms·
Browser extensions are underrated: the promise of hackable software (2019)
- cranberryturkey 3y agoproblem is you can't sell them.
- aloisdg 3y agois this really a problem? Being strictly open without monetization is a feature. You can still open a Liberapay if you want
- cranberryturkey 3y agoopen a what?
- sgift 3y agohttps://en.wikipedia.org/wiki/Liberapay https://en.wikipedia.org/wiki/Liberapay - Platform for recurring donations/OSS funding.
- mettamage 3y agoI use them for personal things
- seanwilson 3y agoThey're not highly visible, but there's quite a few paid extensions. Chrome used to have payments built into the Chrome Web Store before they deprecated it a few years ago (https://developer.chrome.com/docs/webstore/cws-payments-deprecation https://developer.chrome.com/docs/webstore/cws-payments-depr...). You've always been able to add your own payment system. I sell a freeium extension with payments going through Paddle (I guessed Google might deprecate their payment system so didn't risk it!). Gumroad and Lemon Squeezy are other examples you could use, where they both have simple license key checking web APIs.
- senkora 3y agoSafari extensions are an exception here. They are distributed through the Mac OS App store, often as an optional part of a desktop App that can then be enabled within Safari.
- lapcat 3y ago> problem is you can't sell them. I actually make a living selling browser extensions in the iOS and Mac App Store. Apple users are willing to pay. I used to sell my extension in the Chrome Web Store, until Google eliminated Chrome Web Store Payments (mentioned by another commenter). However, even with Google's payment system, my sales were extremely low; thus it wasn't worth my time to implement my own payment system in the Chrome Web Store. Apparently Firefox also used to have a payment system for add-ons but eliminated it. This is purely a choice by the browsers. Chrome and Firefox have chosen to demonetize extensions. Safari has chosen to monetize extensions.
- everybodyknows 3y agoNeeds [2019].
- Retr0id 3y agoDoes it? Has the browser extension landscape changed significantly since then?
- solardev 3y agoWhatever happened to manifest v3?
- sp0rk 3y agoIt's just a Hacker News convention to include the year in parentheses if the article isn't freshly published. It doesn't have anything to do with the content of the article itself.
- Retr0id 3y agoSure, but it's generally only done when that added context is important. I think this article could easily have been written yesterday.
- lapcat 3y ago> Sure, but it's generally only done when that added context is important. No, it's almost always done, unless someone forgets. Currently in the top 3 pages of HN there are 12 submissions with (20XY) at the end of the title. It's extremely common.
- dboreham 3y agoNo support on mobile devices is the big drawback.
- blibble 3y agoseems to be a Chrome thing (gee I wonder why) safari and firefox support them
- temp0826 3y agoFirefox on iOS definitely does not support extensions. Switched to Orion and couldn't be happier.
- Retr0id 3y agoMobile Firefox supports extensions just fine.
- tecleandor 3y agoThat's getting better, for sure. The bad part: on mobile you don't have access to the whole API you have on desktop. For example, on mobile there's no access to your history. (I wanted to do an extension that cleaned older stuff from my history...)
- davidy123 3y agoYou have to jump through extra hoops, at least. I was able to install my own custom, unpublished extension easily with Kiwi.
- rz2k 3y agoOn iOS/iPadOS Firefox and Chrome extensions seem to mostly work in the Orion browser.
- rekoil 3y agoLots of options on Android, and for iOS there's Orion.
- isodev 3y ago
- account-5 3y agoI quite like bookmarklets, easy to write. Tried a userscript but couldn't get into it. Never tried an extension, wouldn't know where to start.
- lstamour 3y agoStart with ChatGPT or a sample extension. The unfortunate part of web browser extensions is that, like the treadmill of web frameworks and app development, browsers can’t seem to stop changing and tweaking how extensions work and remove perfectly good functionality. So you end up sometimes having to rewrite an extension or its manifest with very little assistance from browser makers. But at least you don’t need to learn XUL any longer, so not all changes are bad ;-)
- notzane 3y agoI made this extension fully using chatGPT to diagnose some layout issues. It’s super simple but chatGPT was definitely useful setting up the chrome boilerplate (and commenting what each option meant). Make sure you ask it to target the most recent version, they recently changed (to v3?) and it seems chatGPT prefers writing for the old version. https://github.com/notzane/red-box-outline https://github.com/notzane/red-box-outline
- ustad 3y agoCheck out Firefox examples on github, you’ll like it, I’ve had great experience learning from them to add nifty features to my browser: https://github.com/mdn/webextensions-examples https://github.com/mdn/webextensions-examples
- olejorgenb 3y agoHow do you "compile" the bookmarklets? I know of https://bookmarkl.ink/ https://bookmarkl.ink/ but then we're back trusting some third-party service again. I get that it's not rocket science, but this is definitively a small hurdle to overcome.
- account-5 3y ago
- deleted 3y ago[deleted]
- PaulDavisThe1st 3y ago> Browser extensions remind us what it’s like to have deep control over how we use our computers. Uh. Linux users would like a word here. But more generally, there's a significant component of this that seems isomorphous to the question I was trying to discuss in a post I wrote several years ago called "Is Open Source a diversion from what users really want?" There seems to be much more excitement about ways to "hack" software that do not involve build systems than the complete, open-ended and (theoretically) unbounded access provided by FLOSS. It's not hard to see some obvious reasons why that would be true, but still a little disappointing. I tried to discuss that here, specifically in the contrast between Reaper's provision of scripting-but-closed-source versus Ardour's scripting-but-open-source. https://discourse.ardour.org/t/is-open-source-a-diversion-from-what-users-really-want/102665 https://discourse.ardour.org/t/is-open-source-a-diversion-fr...
- Retr0id 3y ago> Uh. Linux users would like a word here. As a Linux user, I disagree. It's not quite the same. Yes, I could recompile my kernel if I wanted to. I can recompile most of userspace too. But it's a hassle, especially if you want to diverge from upstream, and maintain that divergence on a long-term basis. You can do some fun hacks with LD_PRELOAD et al, but it's nowhere near the degree of flexibility and ease of access of browser extensions. I am allowed to modify all the software as I see fit (and that's excellent), but the friction of actually doing so is (comparatively) high.
- capitainenemo 3y agoI feel gentoo reduces that hassle a fair amount since you can just toss the patches in and the distro pulls them in on updates. So long as you're not messing with APIs it's not too bad in terms of bitrot. ... I suppose you could do the same thing with debian too. You'd just need to maintain an overlay repo that rebuilds off the upstream deb sources for the packages you touched. At that point you're pretty much doing the same thing distro's volunteer maintainer is doing. Take an upstream package, add tweaks, rebuild them automatically with tweaks on the next upstream release.
- monkellipse 3y agoI love the idea of browser extensions but they don’t appear to be worth the security/privacy risk for my use cases. I wonder how many others are like me and too paranoid to risk extensions at all?
- extesy 3y agoAt all? Not even ublock origin? That would actually go against your stated goal of security/privacy.
- monkellipse 3y agoCorrect, none. I use Pihole for blocking. But the bigger point I think is that security conscious users are hesitant to employ extensions in general, even if some folks are ok with a couple select extensions they are still spooked by the general field.
- seagulls 3y agoDNS blocking has not been effective for probably close to a decade, with domain-fronting, L7 adware/spyware, fingerprinting and other trickery. Parent comment correctly characterized the lack of UBO as a net security/privacy loss.
- Hackbraten 3y agoI use only very few extensions. If they're open source, then instead of installing them from the browser's store, I maintain them as AUR packages. [1] That way I force myself to build them from source. My habit is also to inspect the changes between upstream releases. It's mostly spot checks, but it's better than nothing. [1]: https://aur.archlinux.org/packages?O=0&SeB=nd&K=firefox-extension https://aur.archlinux.org/packages?O=0&SeB=nd&K=firefox-exte...
- swozey 3y agoI honestly can't imagine not using extensions. I'm 39 and have been on the web since Netscape etc in the early 90s and I honestly care more about the extensions than I do anything the browser actually does. Like, if there were no extensions I don't think I'd care at all if I used Firefox, Chrome, Opera, etc. But Chrome and Firefox have this massive, massive ecosystem of productitivy improving extensions. I'll give an example since I'm tooting so loudly about this, my job entails a lot of R&D and distributing knowledge to other engineers in a concise manner. I use an app called hypothesis- https://web.hypothes.is/ https://web.hypothes.is/ which is very popular in research groups. What it does is it lets me essentially annotate websites. So for instance I have an application with a front end UI, instead of writing readmes with no interaction to the front end UI I can actually annotate each page like a how-to, or a help doc. You go to that specific URL and get notified that there's a hypothesis doc on it to read. When I used to work at a k8s distro company I used it to help teach people how to deploy clusters, etc. Another one is Dark Reader that makes every single website dark mode.. Ublock I can't even remember a time of my life not using to block ads.. I do have null stuff via cloudflare dns as well but still use ublock everywhere since it's also a massive security improvement blocking chaotic javascript. It's amazing for training situations. https://web.hypothes.is/ https://web.hypothes.is/
- throwaway63467 3y agoMany popular browser extensions were bought up by data brokers that use them to exfiltrate browser history, so not sure if they’re underrated, I think you have to be pretty careful as the extension security/privacy model is/was pretty awful. I e.g. know screenshotting extensions (Awesome Screenshot) that would vacuum up your browser history and send it to a data broker in Israel. So probably better to have that as a native browser feature.
- deleted 3y ago[deleted]
- jwells89 3y agoYes. Because of this and the lack of fine-grained permissions mentioned by a sibling comment, I tend to use desktop apps where I can instead of extensions, keeping my extensions list quite slim — basically all I install are FOSS extensions by “big” known-good authors (e.g. Raymond Hill) or projects that aren’t going to sell out. Of course risks exist with desktop apps too, but historically this kind of buy-and-exfiltrate scheme is comparatively rare with desktop apps, particularly on macOS where signed apps are sandboxed and can’t do a whole lot without user permissions.
- seanwilson 3y ago> I tend to use desktop apps where I can instead of extensions How locked down are desktop apps now on Mac, Windows and Linux? I haven't kept up. Do they still a lot of access by default to do malicious things with? I recently saw someone install the Adobe Acrobat desktop app and it installed its own extension inside of Chrome without asking. Games can have scary DRM as well. Chrome extensions can't read/write to arbitrary places on your hard disk without asking for example and you can isolate them within separate profiles. Not saying they're perfect but there is robust sandboxing of what they're allowed to do. I'm curious how this compares to an Electron-based desktop app i.e. which is running Chrome on the inside but with the standard restrictions Chrome places on tabs and extensions unlocked.
- 3y ago
- seanwilson 3y agoI wish browser extensions had more fine-grained permissions but it's a tricky problem verifying if software is using permissions maliciously (see the Obfuscated C Code Contest and the Underhand C Contest) and how to communicate nuanced permissions to users (most users don't read and/or understand tech stuff, and can be easily mislead). A tip in Chrome that I never see mentioned if you want to be extra safe when trying extensions: - Go to Profiles > Add profile > Continue without account - Install any extensions you feel like in this profile and they're completely isolated from the tabs logins, history, cookies and so on in your regular profile. Similarly, you can run Chrome Beta or Chrome Canary for installing extensions into, alongside regular Chrome. E.g. you can install 10s of potentially risky web development extensions into this profile (they usually need a lot of access to do what they need to do), and keep them sandboxed away from the profile where you do your personal banking or login to work websites. It's not practical for every extension, but I do this for my web development stuff and only use a couple of extensions for personal stuff. I sell a browser extension where the permission I really want to ask for is "can only observe the network traffic it sends/receives in its own tabs" but I'm lumped with having to ask for the "read and write all your data" permission, but I make sure to share the above tip in the description (shameless plug: https://chromewebstore.google.com/detail/checkbot-seo-web-speed-se/dagohlmlhagincbfilmkadjgmdnkjinl https://chromewebstore.google.com/detail/checkbot-seo-web-sp...).
- imhoguy 3y agoFirefox user here, I wish Multi-Account Containers had a way to disable extensions per container. I don't need any on my banking site. Sure I could use separate Profile but UX hurts here.
- SushiHippie 3y agoYep firefox profile UX is sadly not good. But I just bind different firefox profiles to different keybinds in my WM
- thisislife2 3y agoYeah, as you figured out, a separate profile is currently the only workaround. In case you aren't aware, there is an easy way to quickly launch it though in Firefox or Pale Moon - go to about:profiles and you can easily create / launch any profiles quickly in a new window.
- silvestrov 3y agoI think what we need the most is a "view source" for browser extensions installed from the store: make it easy to view the source and to extract the browser extension into a folder. Make it easy to find out which web pages they access and which they modified. Minimized/encrypted code in extensions should be forbidden. It should be very easy to read the code. E.g. this extensions says "records user activity", but what is that really: https://chromewebstore.google.com/detail/coffeelings/hcbddpppkcnfjifbcfnhmelpemdoepkk https://chromewebstore.google.com/detail/coffeelings/hcbddpp...
- deleted 3y ago[deleted]
- a13o 3y agoIn chrome go to chrome://extensions, enable developer mode, and now you can view source for any extension in devtools. The content scripts are already available in the regular web page's devtools without enabling developer mode. The total list of websites is available in the installation popup for the extension. The chrome web store already bans code obfuscation. minification is allowed as there's no meaningful way to enforce the quality of variable names
- Fogest 3y agoIt is very annoying to try and follow through minified code. I've tried to view the source and see what some extensions are doing but it can be a bit of a painful process. You can at least sometimes figure out what kind of GET/POST requests the extension may be making, but it's much more time consuming to try and ensure everything is safe. The other problem is that the extensions can update. You typically get zero notification an extension was updated. Most extensions start off safe, but later get sold and used to farm data.
- redder23 3y agoThere is a button to format the code for minified files.
- fabian2k 3y agoThey're much too big of a target now for spy- or malware. They have too much access to everything we do in a browser. And you can't just evaluate them once, they auto-update silently and you never know when they might be bought by a malicious actor. I use a very limited set of extensions I trust like uBlock origin and Bitwarden. Also some developer extensions, but usually not on my main browser. Everything else is just not worth the risk for me.
- empiricus 3y agoIs there a way to use browser extensions safely? Any extension that looks interesting needs access to everything I see on the screen (and even modify it), which to me seems a huge security risk. My understanding is that random extension is able to read and send somewhere almost all my data when I read my email, do online banking, etc. Do I understand correctly the situation?
- Hackbraten 3y agoYou're free to use only extensions which are open source. So you can build them yourself, and also spot check changes in the code whenever there's a new upstream release.
- gsuuon 3y agoThat'd help, but a problem is they could still go closed-source and you wouldn't know - the store itself has no concept of open or closed source so it's not like you could check an "uninstall if it goes closed source" box. Maybe there's room for a browser extension that hosts other browser extensions but with a much better security model than what Google allows.
- dvdkon 3y agoI think that'd be a great idea, an "FDroid for extensions": A store that serves exactly the code in the repo. Sadly I don't think Chrome/Firefox allow building this as an extension itself.
- Hackbraten 3y agoYou don’t have to use the store to install and update the extension. You monitor the upstream GitHub release feed, and build and install the extension yourself on every update.
- gsuuon 3y agoThis would make a great host extension - just add new extensions to the list and it automatically pull/build/installs the extension.
- Sophira 3y ago> Today, it requires a big jump to go from using browser extensions to creating them: you need to learn a fair amount of web development to get started, and you can’t easily develop extensions in the browser itself. What if there were a quick way to get started developing and sharing extensions in the browser? You could imagine smoothly transitioning from editing a website in the developer tools to publishing a small extension. They're not full extensions, but userscripts and user styles go a long way, and extensions exist that allow people to create/use them in the browser (eg. Tampermonkey[0] and Stylus[1].) I consider them incredibly important, even though they can't do as much as extensions. [0] https://www.tampermonkey.net/ https://www.tampermonkey.net/ [1] https://chrome.google.com/webstore/detail/stylus/clngdbkpkpeebahjckkjfobafhncgmne https://chrome.google.com/webstore/detail/stylus/clngdbkpkpe...
- remram 3y agoUserscripts are underrated! I use them for all kinds of things, like fixing GitHub's useless landing page (taking me to my repositories instead), make the Mastodon "follow" button work (by hardcoding my instance's domain), block useless results from Google search results (stackshare and the like), redirect from the YouTube "short" view to the normal video video view, remove the stupid whitespace to the right of Gmail's scrollbar, etc.
- sanitycheck 3y agoI've used Tampermonkey for a couple of moderately complex things and it does work well... I didn't come across a particularly nice way to use an external editor or integrate it with a normal dev workflow though, I wonder if anyone has tricks to share? I'm fairly satisfied with editing in VS Code, using a tsconfig.json with strict mode and checkJs turned on, then using JSDoc for typing. The ugly bit is the manual copy-paste into the Tampermonkey code area each time.
- dvdkon 3y agoI don't use Tampermonkey (it's not FLOSS), but I'm pretty sure Violentmonkey autoreloads script files when that script was installed from a local file (maybe I had to enable it somewhere).
- mcoliver 3y agoI run a browser automation extension that only does actions on certain sites (clipping coupons for grocery store sites and credit card offers rewards). I created it this way specifically because I am terrified of extensions that want to read and write all sites. And you should be too. I wish the chrome store gave badges to extensions like mine to make people more aware, give a filter when searching for new extensions, and to encourage least permissive development. The chrome store extension rules are also unevenly enforced. Take a look at the source code for something like 1password. It is full of obfuscation and completely unintelligible which is against the store rules. I base64 encoded a single string that was my json dict in an otherwise completely readable js file and it went through on one publish but a few versions later was red flagged.
- jlawrence6809 3y agoI built a chrome extension that is featured on the chrome web store[1] and the number of requests I get from shady data brokers looking to buy my extension and fill it with spyware is really concerning. A naive dev could build something cool and sell it off to someone thinking they'll maintain if for them but instead just cause a hazard for users. Google seems to do a decent job of reviewing the use of permissions but some extensions like mine really need access to everything on the page so I can only imagine what a data broker could do with it. Be careful what you install. [1] https://chromewebstore.google.com/detail/css-selector-helper/gddgceinofapfodcekopkjjelkbjodin https://chromewebstore.google.com/detail/css-selector-helper...
- swozey 3y agoCool extension. I love when devs open source stuff that makes their lives easier.
- jlawrence6809 3y agoThanks! Here is the repo if you have any issues/suggestions: https://github.com/jlawrence6809/CSS-Selector-Helper-for-Chrome https://github.com/jlawrence6809/CSS-Selector-Helper-for-Chr...
- swozey 3y agoHow far did you have to deviate from the demo extension to make this? I've written themes for vscode and intellij but never done an actual extension because it's js/ts and I don't really enjoy writing those. I really wish they had a DSL for extensions to allow them to be more broadly written. Like, I feel like I have to basically learn js to learn to write a chrome extension and I'm a go/rust dev who will use it literally nowhere and I just want to make the AWS console not suck, for instance. But I keep trying to will someone like me into existence to make this extension and nobody is appearing lmao.
- jlawrence6809 3y ago
- zubairq 3y agoI think that metamask is an example of a great add on that proves how great browser extensions are. Also, I think that the most popular browser extensions like metamask will eventually become built into every browser
- latchkey 3y agoMM terrifies me as an extension. I run it in its own separate browser profile with no other extensions installed. My fear is actually that another extension can hijack MM.
- swozey 3y agoI program (not js/ts), use a massive number extensions and consider myself an absolute power user of them and refuse to ever use a browser WITHOUT the chrome/firefox extension ecosystem, I've written themes for Chrome and VScode, but I'm still here- (like pink/cyan? get on in! https://marketplace.visualstudio.com/items?itemName=mikejk8s.pink-cyan https://marketplace.visualstudio.com/items?itemName=mikejk8s...). I have no idea via the Chrome prompts what extensions are able to do, read, see, access, etc. "Allowed to access data on all websites" - Is this literally all data? Like what I'm typing? Like does it know when I go URL to URL? it is just reading the assets? Is there a chrome API that limits their access that I can see? What do I actually need to worry about? I have a video zoomer that lets me zoom in on any video on any website, do I need to literally audit each extension myself and make sure it's not mirroring my data elsewhere or something? I have no idea. How would a non technical user know any of this?
- Rapzid 3y agoI'm pretty sure it's as bad as it sounds haha. Like another user mentioned because of this I only trust a few key extensions(and like that user uBlock, Bitwarden, etc) with this sorta access. I'd be very wary of those scrapy screen/session recording startups if for no other reason than they could be particularly vulnerable to supply chain attacks.
- swozey 3y agoYeah I always go to the source/project URL in the chrome store and IDEALLY it's a github repo with a bunch of contribs but I'm sure I've played loose with a few that had no other options. I just had one big extension I use get bought by someone last week when it updated. I gotta dig through that now.. I used to hide that extension update popup screen but now I'm glad I didn't.
- Gigachad 3y agoNot only is it theoretically as bad as it sounds, its as bad as it sounds in reality as well. Most of the top extensions get sold to ad companies and silently start sucking up all of your browsing data to sell on. Some of them start injecting their own adverts and tracker scripts on to pages, some of them are outright stealing your credentials. And you realistically have no way to sort the good from the bad. Especially when the good silently get sold to the bad and automatically updated.
- mg 3y agoI prefer bookmarklets because they - Are easy to edit - Are inactive until clicked - Work in all browsers - Work on mobile - Integrate nicely into the UI. I can move them around, put them into any bookmark folder, assign shortcuts. I wrote this bookmarlet editor which makes it easy to convert between clean code and a bookmarklet: https://www.gibney.org/bookmarklet_editor https://www.gibney.org/bookmarklet_editor
- dugite-code 3y agoWell that's a handy site you have there. Last time I fiddled with bookmarklets they didn't work on Firefox for Android, but now they do. This is going to be handy combining it with my Node-red instance. Got any good bookmarklets you want to share?
- mg 3y agoYou can click on the question mark and then, when you click on one of the examples, it will fill the code area with the code for that bookmarklet.
- madacol 3y agoedit any text on webpage javascript: (function() { document.body.contentEditable = true; document.body.spellcheck = false; })(); Open on wayback machine javascript:location.href='https://web.archive.org/web/*/'+document.location.href.replace(/\/$/, ''); Others that are longer https://github.com/madacol/web-automation/tree/master/bookmarklets https://github.com/madacol/web-automation/tree/master/bookma...
- madacol 3y agoAn interesting one I made recently is related to a game published a couple of days ago here in HN called "infinite craft" https://neal.fun/infinite-craft/ https://neal.fun/infinite-craft/ The game does not have any save mechanism, so I made a bookmarklet that loads and autosaves to localStorage ``` javascript:(function(){ const exportState = () => JSON.stringify({ discoveries: window.$nuxt.$root.$children[2].$children[0].$children[0]._data.discoveries, elements: window.$nuxt.$root.$children[2].$children[0].$children[0]._data.elements }); const importState = (state) => { const { discoveries, elements } = JSON.parse(state); const gameInstance = window.$nuxt.$root.$children[2].$children[0].$children[0]._data; gameInstance.discoveries = discoveries; gameInstance.elements = elements; }; /* Set up a MutationObserver to listen for changes in the DOM and automatically export the current state. */ const observer = new MutationObserver((mutations) => { const state = exportState(); localStorage.setItem('gameState', state); }); /* Start observing DOM changes to auto-save the game state. */ const startObserving = () => { const targetNode = document.querySelector('.sidebar'); observer.observe(targetNode, { childList: true, subtree: true }); }; /* Check for a saved state in localStorage and import it if available. */ const savedState = localStorage.getItem('gameState'); if (savedState) importState(savedState); else localStorage.setItem('gameState', exportState() ); startObserving(); })(); ```
- redder23 3y agoTalking about how bad Google is limiting ad blocker, then going ahead and saying "I use Chrome extensions" I am assuming that means in Chrome. Its your fault then. Move to Brave (has ad Blocker without limitations build in, you can use all Chrome extensions) or Firefox or whatever browser but if you continue to use Googles shit then you are helping them kill what makes extensions great. They do not even support extensions on mobiles, obviously with the excuse of performance but its so most people who are actually on mobile can't block ads and otherwise remove commercial toxicity from the web.
- sidwyn 3y ago> Compatibility: Because extensions hook into websites in unsupported ways, updates to websites often result in extensions temporarily breaking, and extension authors scrambling to fix them. Has anyone who's built a browser extension solved this?
- mcoliver 3y agoThe best you can do is get an early warning by running your extension via an automation framework and getting alerts on errors then publishing a fix and waiting for approval from Google. Too many unknown unknowns. You're searching for an element to modify or take an action on based on the text content/class/id/aria-label/type? Someone changed apple to train. Or completely changes the element hierarchy. How would you predict or recognize that to modify your logic and be certain it works before publishing to your hundreds/thousands/millions of users?
- gymbeaux 3y agoI've had some ideas for browser extensions over the years, most recently a few months ago. I remember looking at Mozilla docs for making a Firefox browser extension and, as a SWE w/10 YoE (mostly fullstack web), I was left confused. The documentation felt incomplete and I left the article with more questions than I had before.
- akkartik 3y agoJust the framing of "browser extensions" is extremely problematic in the year 2024. Most browser extensions by weight are Google Chrome extensions. Google Chrome is unambiguously demonstrating that no API is safe in its quest to juice revenues. Anybody who builds extensions using Chrome's APIs should be very aware that they're quite possibly putting effort into something a juggernaut will stomp away without a second thought. I don't care to live in strategically lost situations like this, so I think the conversation should be about Firefox extensions. Which also don't have a great track record (the transition to Google Chrome compatibility a few short years ago still annoys me greatly), but are a qualitatively better counter-party to deal with.
- swozey 3y agoHas Firefox fixed its syncing feature? You used to have to literally move a profile file around. I remember working in IT a long time ago and Firefox was an absolute nightmare to deal with corporately. But then, back then, we couldn't control Chrome extension installations..
- emodendroket 3y ago> Most browser extensions by weight are Google Chrome extensions. Google Chrome is unambiguously demonstrating that no API is safe in its quest to juice revenues. Anybody who builds extensions using Chrome's APIs should be very aware that they're quite possibly putting effort into something a juggernaut will stomp away without a second thought. How unlike developing for literally any other environment.
- 3y ago
- mosselman 3y agoI wanted to build an internal company extension, but for that (chrome) you still need to go through the review process with Google and it is even worse than Apple’s App Store reviews.
- fritzo 3y agoWould it be too much friction to host internally and require your users to "load unpacked"?
- julienreszka 3y agoIt's really not hard I doubt it's a big friction
- mosselman 3y agoIt would mean re-loading manually at every update no? Otherwise it would be great. Any pointers?
- narag 3y agoQui prodest is the question you must ask when you hear the usual points against, mostly security. It's not that every person that dislike extensions or repeat the same arguments is paid by "them", but it's a little shocking seeing so many negative opinions in a forum called Hacker News. This comment: https://news.ycombinator.com/item?id=39251996 https://news.ycombinator.com/item?id=39251996 by Retr0id hits the nail in the head. It's not that we cannot modify the software, but there are so many layers of inconvenience... what about modifying and recompiling the browsers themselves? They're so big now. The solution would be extensions. But no. Security.
- juxtapose 3y agoThe whole article reads like an ode to Emacs. :-)
- dividendpayee 3y agoThere was a good article from John Loeber a few months back about browser extensions: https://loeber.substack.com/p/9-15-years-of-market-gaps-for-browsers https://loeber.substack.com/p/9-15-years-of-market-gaps-for-... He had the same point, where it feels like browser extensions are a big, somehow under-appreciated market. Browsers are huge platforms -- creating add-ons and making them more capable should be a popular, value-generating thing to do! But for a number of (developer) UX/UI issues, that just hasn't been the case. I hope this changes!
- drakerossman 3y agoA somewhat-shameless plug here, since I've released this just yesterday: Browser Extension for Hacker News written in Rust WASM: https://github.com/drakerossman/hackernews-userscript https://github.com/drakerossman/hackernews-userscript It has filtering capabilities (filter in title, link, text, or username via regex) and softhide (hide all the items on a page without pulling others from the next page).
- ulrischa 3y agoAnd especially Bookmarklets are underrated. They can do many things where no extensions are necessary.
- prakhar897 3y agoTangential: What tooling do you use to develop Extensions. I used React and couldn't find something any testing libraries which works on background and content scripts.
- quicon 3y ago"Computing is still young, and platforms are changing quickly. Modern browser extensions and smartphone platforms have only been around for about a decade. These platforms will evolve, and there will be new platforms after them, and we will get to collectively decide how open they will be." I really like this final comment. As a non expert in computing, I also often think about how young is this field, and I fantasize about how it will evolve, hopefully towards a more accessible and open ecosistem.
- lxgr 3y ago> we will get to collectively decide how open they will be. The author is way more optimistic than me here. I'd love if that were the case, but with the way the wind is blowing, I doubt that it'll be a collective decision between users and the big tech companies running today's computing platforms. If anything, it'll come through regulation. It's highly unlikely that e.g. iOS or Android will suddenly and out of their own initiative open up their APIs in a way that would allow building anything like "reading mode"/distraction removers, ad blockers, data extraction allowing mashups between different apps etc. Google's main customers aren't Android users, but app developers who run in-app ads and sell in-app purchases; the same is to a large extent also true for Apple (although DMA-like changes might shake up things a bit, and their reasoning for not introducing such apps will likely be security and platform integrity, not ads).
- ww520 3y agoOne benefit I would add is that cross platform support is great for browser extensions. Browsers already run on different OS's and devices. Browser API and extension API are fairly uniform among the major browsers. It's close to the cross platform support of general websites. As an experiment I develop my latest browser extension on Firefox [1], Chrome, and Edge [2] at the same time to see how difficult it is to share the same code base. The difference is minuscule, like less than 0.01%. Chrome and Edge are essentially the same. Firefox is a bit behind in Manifest V3 support and needs a few lines Firefox specific API calls. The manifest files have a few differences. Overall, sharing the same code base is very feasible. [1] https://addons.mozilla.org/en-US/firefox/addon/one-page-favorites/ https://addons.mozilla.org/en-US/firefox/addon/one-page-favo... [2] https://microsoftedge.microsoft.com/addons/detail/one-page-favorites/gnhomonbmcfhbfgbloacgnpgjcefbanm https://microsoftedge.microsoft.com/addons/detail/one-page-f... Edit: You might ask where the Chrome version. Well, I had a heck of time to create a new Google account for deployment. Stay tune.
- gklitt 3y agoPost author here! I wrote this post five years ago. Since then, my conviction in the value of customizable software has only grown, but I've also updated my thinking in a few ways: 1) AI AI is rapidly getting better at coding. Current AI is often bad at high-level architecture but is capable of making small local tweaks. Seems like a good fit for the kind of code you need to write a browser extension! I'm exploring this direction; wrote more about it in "Malleable software in the age of LLMs" [1] 2) Security Having talked to people who worked on various extension platforms including the browser extensions API, I see more clearly than I did five years ago that security is often the key bottleneck to deploying extension platforms meant for mass adoption. Anytime you want everyday computer users to be installing invasive extensions to important software from untrusted third parties, it's gonna be challenging to protect them. That said, I still think that conversations around extensions tend to focus too much on security at the expense of all else. Customizability is important enough that it may be worth prioritizing it over security in some cases. I also think there are many reasonable paths forward here. One is to exchange extensions with trusted parties -- e.g, coworkers or friends -- rather than installing from random people on the internet. Another might be to only build your own extensions; perhaps that'll become more viable with AI-assisted programming, although that introduces its own new security issues. And finally, I've met a few people who have smart ideas for architecting software in a way that helps resolve the core tensions; see [2] for an example. 3) Backend access as a key limitation I've increasingly realized that the fact that browser extensions can only access client code in a fairly server-centric web means that many deep customizations are out of reach. Perhaps you can't read the data you want, or there's not a write API to do the thing you need. While I'm optimistic about what extensions can do within the boundary of the client, this is an inherent limitation of the platform. At Ink & Switch (the research lab I now work for), we're working towards local-first [3] software: collaborative software where the data and the code lives on your device. Among other benefits like privacy, we think this is the right foundation for more powerful extensions, since your data and the app code aren't locked away on a server. [1] https://www.geoffreylitt.com/2023/03/25/llm-end-user-programming https://www.geoffreylitt.com/2023/03/25/llm-end-user-program... [2] https://www.wildbuilt.world/p/inverting-three-key-relationships https://www.wildbuilt.world/p/inverting-three-key-relationsh... [3] https://www.inkandswitch.com/local-first/ https://www.inkandswitch.com/local-first/
- feldrim 3y agoBrowser extensions, if we use the analogy as apps running within browser as an OS, are lacking simple capacities to manage the risks. Just like any app a user can install on their devices, extensions extend the attack surface. As we cannot avoid the risk by removing all of them, we can just allow users to have more control on them regardless of the browser they use. I suggested[0] using standard management APIs provided by browsers, therefore the ecosystem can use them as building blocks for FOSS and/or commercial tools. That's a very naïve idea but why not? 0. https://zaferbalkan.com/2023/10/03/browser-extension-api.html https://zaferbalkan.com/2023/10/03/browser-extension-api.htm...
- bmacho 3y agoBrowser extensions are bad. Don't create them. Don't use them. Use Tampermonkey/userscript instead.
- breadchris 3y agoWhat has always blown my mind is the lack of documentation/open source projects. With such powerful data we come across while browsing the web, it would only make sense to me there would be more tools to use an extend in this space. Browsing history is especially under valued. Even though the data technically exists, it is quite difficult to retrieve pages that have been visited, imo because of poor UX. Most people keep every Internet journey opened in hopes they will remember to return to it. I have been taking a stab at improving the UX with a history browser extension [1] which I have found myself legitimately finding value in using (a first for my personal projects lol). [1] https://github.com/lunabrain-ai/lunabrain/tree/main/js/extension https://github.com/lunabrain-ai/lunabrain/tree/main/js/exten...
- poisonborz 3y agoMore like overrated. An extension can't be better, can't offer more than what the host application allows. All these developers hang on by a thread. Compared to OS APIs, in-app APIs are more unstable. Goals, profit incentives affect a single application much harsher than how a wider ecosystem would react. It's good that they exist, but at most they are viewed as a necessary annoyance by their hosts. Chrome I won't even need to mention, but winds could turn anytime on something like VSCode as well. Sure, Webkit and VSCode are both open source and forkable along with their extension support, but any later development would rot compatibility until, and if, a popular fork emerges.
- GeekyBear 3y agoThe web has become unusable without extensions like uBlock Origin, but extensions can contain malware. I have moved over to only using extensions that have gone through Mozilla's manual code review necessary to become part of their "recommended extensions" program. > Before an extension receives Recommended status, it undergoes rigorous technical review by staff security experts https://support.mozilla.org/en-US/kb/recommended-extensions-program https://support.mozilla.org/en-US/kb/recommended-extensions-...
- quickthrower2 3y agoI love browser extensions both as a user and as a hacker. The elephant in the room is browser extensions are not a web standard and Google or Firefox can make a breaking change to you at any time “for security”. Also Chrome can boot you out of the store or ask for 100 point ID check in the future. Extensions are great but a web standard for them would be even better.
- lapcat 3y agoThey're working on that: https://www.w3.org/community/webextensions/ https://www.w3.org/community/webextensions/
- deleted 3y ago[deleted]
- kjkjadksj 3y agoI love working with hackable software. I kind of attack it at the source level vs writing for the browser however. For example, say there’s some tool on a git repo. I will shamelessly clone it and build off of it to my own liking. Maybe I add another 1% to the code base, or maybe that repo becomes 1% of a codebase I write on my own. These are tools I could never share however, because of the rampant plagiarism I am doing, and the fact I don’t much care about getting it to run on different systems beyond my own. That being said fast and loose coding like this is a very powerful way to iterate on personal projects that never need to be anything but. I wish more things were actually hackable especially mobile or appliance hardware. Companies never like giving the power users the reigns for some reason.
- BenjiWiebe 3y agoPlagiarism? The vast majority of codebases I've seen on GitHub specifically allow you to do what you are doing. No need to make it sound like a bad thing.
- dang 3y agoDiscussed at the time: Browser extensions are underrated: the promise of hackable software - https://news.ycombinator.com/item?id=20556382 https://news.ycombinator.com/item?id=20556382 - July 2019 (186 comments)
- sn0n 3y agoMeanwhile beaker has become archived and "lives on in" bluesky and solid is vaporware afaict... Ouch.
- cc101 3y agoIt's possible that some here might confuse Web Extensions with Safari App Extensions. Safari App Extensions are not the same as Web Extensions. App extensions are written in native code (Objective C or Swift); they operate within Apple's sandbox; their data is saved within Apple's secure file system; and if they are sold via the Apple App Store, they are reviewed and approved by Apple. One never has absolute assurance that an app is proof against attack, but until I learn otherwise, I think Safari App Extensions are safe.
- atum47 3y agoBack when Facebook was fun i paid 5 dollars to write a cross text extension. Back then i was doing a lot of those jokes where you get a popular saying, strike one word and write another one to make it funny. What was funny to me is the fact the Facebook started to revert my posts when using this. I remember recording a video about it, don't know if i still have it though.
- AlienRobot 3y agoBrowsers REALLY have to fix the "read all your data" problem. Even with domain limitations, if you use an extension for a site, that means you use that site a lot, so you probably even have an account on it. I think extensions should declare a bunch of CSS selectors that they need data access to, and if an element doesn't match those selectors, then all attributes and .innerText/.innerHTML should return undefined. I don't care if normal people can't understand what CSS selectors are. Just hide it in "view technical details" box or something.
- ggm 3y agoNot chrome on android. Super annoying. Using the chrome-like alternates isn't the same.
- smudge-ai 3y agoWhile I fully agree with the hacker ethos of this post, a major issue I have with extensions today is that they're hard to trust. Chrome updates them automatically in most cases, which means a malicious update can easily slip by undetected. There are hordes of data companies looking to buy popular extensions or pay their authors to sneak spyware or other trackers in. The risk surface is massive, which is sad because I believe extensions are also one of the best modalities for extending what people can do online.
- deepsun 3y agoSame thing with NPM/PIP dependencies (they can launch arbitrary code and clean up after, unlike Java deps from maven that just copy immutable archives).
- iansinnott 3y agoEntirely agree, although as a developer the auto updating is definitely a feature. Since it lets you assume users are all on the same version. It is definitely a risk for users though. You can also "opt out" of automatic updates, but the process is a bit involved. 1. Locate the extension on disk 2. Copy it to some other location 3. Add it as a developer extension via the "Load unpacked" button in the extensions screen. I would also advocate for extensions being open source, but of course most of them are not.
- smudge-ai 3y agoGreat points. I'm the author of a few extensions and I do agree that it's nice to see the vast majority of users end up on the same version within a day. I think a reasonable middle-ground would be for Chrome to confirm that you want to perform the update if a privacy-sensitive change is made. For example: "This extension would now also like access to X/Y/Z. Confirm update?". Even that would only be a small step in the right direction, though, since plenty of apps already have broad enough privacy settings to inject scripts on any page with no change needed to the app manifest's permissions.
- dannysuarezpab 3y agoI really like your article I agree with your point that extensions are tools for extend current software functionalities and see beyond the creators... Currently Im working on a Gmail and Outlook extension for email called Mailverse that add superpowers to the current email clients.
- adamsiem 3y agoScripting + Raycast / Alfred
- w3news 3y agoI love to build extensions. Such a nice thing they made website source easy to read and manipulate for your own usage, and can even share your modifications to build an extension. It is just like your newspaper, you can write on it, cut precies out, etc. You can do with the site what you want for yourself. The newspaper designed also it how they like, but you can also grap your scissors and pen to change it for yourself.
- pknerd 3y agoI have a few ideas that depend on Chrome extensions, the issue is, I do not know how to monetize them either via Ads or some sort of in-app purchases.
- anonzzzies 3y agoDo they work on mobile yet, all of them? Without that, it is not so useful for me as real investment of my time to make them; 60% of my screen time I wouldn’t be able to use them.