19 ms·
Detect when your installed Chrome extensions have changed owners
- maurice2k 3y agoQuestion is if this extension detects having changed owners itself? Maybe something else, not an extension, would be better suited for that kind of check, although of course more complex I guess.
- kosolam 3y agoYep. Maybe a website that tracks them and sends email or other notifications
- mfrisbie 3y agoCreator here. It does self-detect (chrome.management.getAll() returns all installed extensions), but fair point.
- jaredsohn 3y agoThis is how you make an extension that you can resell for big bucks. People looking to buy extensions will need to buy popular extension checkers first so they can do so undetected. /s
- dsp_person 3y agoWon't the damage be done by the time you detect it? Extensions auto-update by default and there are only hacky ways to prevent this. This has always bothered me since just because I trust an extension now, doesn't mean I'll trust the next update that gets automatically applied.
- abhinavk 3y agoThankfully Firefox has per-extension toggle for auto-update.
- dsp_person 3y agoOh nice, TIL. Another push for me to switch to ff
- re 3y agoAt least I think it's pretty rare for a sold extension to be turn malicious in a way that it could do permanent damage, such as stealing your passwords. It's usually more along the lines of excessively invasive tracking or injecting their own ads; while I absolutely wouldn't want that normally, I probably wouldn't lose sleep over it if I learned that it had happened for 24 hours before I uninstalled the extension. That being said I would definitely like a better solution to this problem.
- snerdapp 3y agoGreat work! I hope Google/Mozilla and others will built this functionality into the browser itself someday so the user can make an informed decision.
- int_19h 3y agoThis should be something built-in for every browser, and updates should be automatically disabled as soon as owner changes.
- harkinian 3y agoExtension updates shouldn't be automatic to begin with imo.
- Chabsff 3y agoUnfortunately, it's been established for a long time now that users cannot be trusted to perform updates by themselves, no matter how naggy you get about it, even for the most critical of security fixes. Automatic updates, again unfortunately, are critical to safety.
- Blackthorn 3y agoUsers often don't want to perform updates because the updated version is worse in some way. That it has a security impact is unfortunate, but that's how it is.
- harkinian 3y agoI had an extension update itself and partially stop working. There's no way to go back to a previous version unless you happen to back up the old files.
- jasonjayr 3y agoAnd these automatic updates are often abused to remove or change features, or generally "enshitify" things. Which breaks trust and we are back to square one.
- woliveirajr 3y agoCritical to the user safety? Well, that's not a problem. Critical to the safety of some site/other users? Then the problem is a bit deeper, as my computer/software shouldn't be able to affect someone else.
- josefresco 3y agoTo combat this wouldn't malicious extension buyers simply keep the developer name the same? Or is developer name strictly policed by the Chrome Extension store?
- Sephr 3y agoThis would likely be against the Chrome Web Store terms of service.
- chatmasta 3y agoThey could just purchase Extension Author LLC with the extension being one of its assets, and there would be no need to notify Google of the change in control.
- ytx 3y agoAlso there's not much practical defense to an unscrupulous extension author "exiting" with an under-the-table password transfer or "oops we got hacked" to a shady buyer. <tinfoil hat> One could imagine a nefarious state actor offering the author of e.g. uBlock $XX million to get access to a lot of browsers. Not sure about the economics, but more niche extensions could probably be targeted for a lot cheaper.
- usrusr 3y agoTrue, but at least it would require the exiting party to not have any illusions about what they are doing. I'd be surprised to hear that most extension takeover bids are open about their plans.
- Uehreka 3y agoMy guess is that most extension takeovers happen because the developer was making no money from the extension, not a lot of money at their dayjob, maintaining the extension was sucking up all their free time and maybe they also got an unexpected bill or were hurting for cash. Not that those are good reasons to sell out your users, but they’re the kinds of circumstances that you can easily imagine happening.
- screamingninja 3y agoHow will I know when this extension changes owners?
- barryrandall 3y agoWith a change detector change detector.
- jaredsohn 3y agoCould install another extension change detector and hope they don't both change owners at the same time.
- odyssey7 3y agoHow many change detectors to mitigate against 51% attacks? Realistically, even with this extension functioning as advertised, there are still plenty of related risks. E.g., a software company could disguise its motives early on and convert its product into malware at a later date, or the developer could be paid by a 3rd party to add certain features.
- p0w3n3d 3y agoAn extension to detect that other extensions have changed their owners. What happens when this extension changes its owners?
- wetpaws 3y ago[dead]
- michael9423 3y agoThat will clearly require a new extension that monitors "Under new Management".
- bossyTeacher 3y agoGlad someone noticed that
- p0w3n3d 3y agoTbh one can always install it locally (as a local extension)
- bmacho 3y agoPro tip: don't use chrome extensions. They are a trivial and huge security risk. Similar how random exe was some years ago, only much worse. Use tampermonkey scripts instead. Tampermonkey scripts are - open source and easily modifiable - permissions are firmly controlled - you can disable auto update
- 1231232131231 3y agoJust install extensions directly from github/gitlab/whatever. No auto-updates (probably) and it's open source.
- CobrastanJorji 3y agoBut I want to use extensions! Extensions do so many useful things that go beyond what scripts with fewer permissions can do. I want a utility that handles screenshotting sections of pages. I want a thingy that tracks the price history of products on Amazon so I know if something is real on sale or fake on sale. I want a thing that makes ssh sessions clickable for my weird internal ssh thingy. I want the stupid and experimental web mashup extensions that add weird stuff like "a chat room for every website you visit so you can chat with other people using that website." Well, okay, I don't want that last one, but I want it to exist.
- FredPret 3y agoThese things worked well when the internet was a toy. Now it's no longer a good idea because that same browser is also: - your bank, - likely your point of contact with the government / tax folk - the place you do your shopping - the portal for most of your communications with the rest of the world
- bossyTeacher 3y agoThe price for convenience is security. If you are willing to hand your digital life to others, you will gain the convenience that you seek. You are seeking to become a digital king by gaining digital servants that handle every aspect of your life. The day one of them betrays you, it will be painful for you at the very least
- codedokode 3y agoI never install extensions because nobody checks them and it is a security risk. Also, they might contain telemetry and spyware.
- odyssey7 3y agoIs this an issue that's worse for Chrome than for other browsers? The only browser extension I use is HonorLock, an exam proctoring software that I'm required to use. Its extension is for Chrome only, so I use Chrome from time to time out of the requirement to use HonorLock. If I visit the install link in Safari, it tells me to install Chrome: https://app.honorlock.com/install/extension https://app.honorlock.com/install/extension I'm wondering if there's something unique about Chrome's extensions that both supports HonorLock's use case and makes this submission's linked resource more helpful.
- ponector 3y agoOnly use honorlock? How can you live without AdBlock?
- deleted 3y ago[deleted]
- codazoda 3y agoSounds like Chrome isn't their daily driver. Firefox blocks a lot of ads by default in Strict mode. That's what I use, so I haven't used AdBlock for a long time. I also have a Pi-hole on my home network.
- odyssey7 3y agoYep, you got it. I just generally don't use Chrome unless I'm taking an exam that requires it.
- deleted 3y ago[deleted]
- harkinian 3y agoIt's just that Chrome is the most popular browser and thus the chosen extension attack vector.
- helf 3y ago[dead]
- deleted 3y ago[deleted]
- chatmasta 3y agoThe extension ID is derived from a private key that the developer uploads with the first upload to the app store, and the ID will change if any subsequent uploads include a different key.pem in their zip file (but if there is no key.pem then the extension ID will remain the same). Therefore, if the extension ID changes, it's possible the owner changed. However, it's also of course possible (and even likely) that the original owner might transfer the private key to the new owner. And since Google doesn't require each upload include the private key, then the new owner could push changes without even needing access to that key. I find the extension ecosystem fascinating and I'm also working on some tools for this space ([0]: warning, WIP hobby code). For example, I want to create a GitHub repo that targets a specific extension, tracks its updates, and pushes each one as a change to the repo. And then I can run static analyzers on the code after each update, and also some runtime taint analysis I've been experimenting with (e.g. tracing user inputs into dangerous sinks like eval or postMessage). [0] https://github.com/milesrichardson/crxmon https://github.com/milesrichardson/crxmon
- thisislife2 3y agoOne of my Opera (Presto web engine, European owned) extension was featured on the front page and became very popular. Somebody wanted to purchase it from me for a good amount. During the negotiation, I said I would take down the extension and provide all source code to them so they could distribute it themselves. They said they expected me to hand over my Opera extension account credential too to them. Long story short, I backed out. So yeah, I support your assertion that while something like this is somewhat useful, a better thing would be some kind of malware scanner for extensions.
- croon 3y agoWhile I too would back out from anything requiring giving away credentials, is there no other way to transfer ownership? A charitable interpretation could be that they wanted to also buy the "popularity" of the extension simply for discoverability. But it's equally easy to envision nefarious reasons of course.
- deleted 3y ago
- FredPret 3y agoI installed adblock many years ago and loved it. Then I got a new machine and had to reinstall it. For the first time I had a look at those permissions. Insanity. It's only logical that it should be able to see what I see to block the ads, but I never stopped to think about that. Now I have a pihole and zero extensions.
- ralphist 3y agoSafari has a special interface for content blockers to work without any permissions. They provide blocklists and the browser does the blocking itself. [1] Don't know if that's an option in Firefox. https://developer.apple.com/documentation/safariservices/creating_a_content_blocker/ https://developer.apple.com/documentation/safariservices/cre...
- Scion9066 3y agoYep, Firefox and Chrome have declarativeNetRequest: https://developer.mozilla.org/en-US/docs/Mozilla/Add-ons/WebExtensions/API/declarativeNetRequest https://developer.mozilla.org/en-US/docs/Mozilla/Add-ons/Web... Ublock Origin Lite uses it for example. (It's also the thing everyone is angry at Chrome for as their 'plan to kill ad blockers' by replacing the current blocking APIs with declarativeNetRequest.)
- danShumway 3y agoThis is kind of an important point with Manifest V3: having more permission options is a good thing. It's good that declarativeNetRequest exists. Active Tab permissions are cool, I love being able to scope extensions to specific domains. Non-persistent background pages are a nice performance/security feature. The only problem with Manifest V3 is that Google is shutting down everything else and removing other APIs. Safari's extension model kind of goes in its own direction, but it's based on similar principles to Manifest V3 and my contention with it is the same -- it's not a problem that you can build a permission-less adblocker in Safari, that's good. It's a problem that you have to, because getting rid of those permissions makes adblockers slightly less effective, which may or may not be worth it for every user. I can say with relative certainty that there is no adblocker on Safari that is as powerful as uBlock Origin on Firefox. People bundle criticism of Chrome under the Manifest V3 label but aside from some more techy-type complaints around how Service Workers are being handled, in my experience at least a lot of Manifest V3 is really good. What's not good is that Chrome used Manifest V3 as an opportunity to get rid of a lot of other important APIs. So you don't see the same criticism levied at Mozilla because with Firefox you get most of the same benefits of Manifest V3 (and some additional benefits, Firefox's event-system is imo a better way to handle temporary background pages than Chrome's service-worker system) without the downsides of Chrome removing blocking web requests for the extensions that need them. I'm using Manifest V3 for private extensions that I maintain for myself on Firefox. Manifest V3 is great and I enjoy trying to cut down my permissions as much as I can even though I'm basically just running the code myself. But none of my private extensions would work in Chrome or Safari or would be portable to either browser; they lack the APIs that I need and don't have any realistic equivalents.
- redbell 3y agoThis is really useful, although, as another commenter said, this should be a built-in feature. A question I got regarding this extension, as I didn't take a deep dive into the source code yet: Does it automatically notify you (not necessary in real-time but at least in startup) of ownership change or you need to manually trigger a check command? A few months ago, a story on this topic was trending: https://news.ycombinator.com/item?id=36233068 https://news.ycombinator.com/item?id=36233068 From the top comment of the above story: "I think it would behoove Firefox and Chrome to change their policies around automatic extension upgrades in these scenarios: if an extension discloses a change in ownership, then upgrades should require user approval. If an extension fails to disclose a change in ownership, then users should be able to report it as malicious." As a side note, probably the title should be prefixed by "Show HN"
- mfrisbie 3y agoCreator here. A check automatically runs every hour, and if there are any changes detected, a badge appears over the extension icon. I decided anything more than that was too invasive.
- redbell 3y agoIndeed, periodic checks with a well-thought-out interval do make sense. Well done!
- jtriangle 3y agoIt would be much better to at least have the option to automatically disable an extension with changed ownership instead. The majority of owner changes are going to be malicious, so the action taken should account for that.
- efreak 3y agoAre extensions allowed to disable other extensions? That seems like it would be a poor design. If the feature was part of the browser, then sure, but not as an extension.
- 3y ago
- INTPenis 3y agoWeird thought here but maybe the distributor of chrome extensions should not allow one extension to change owner? Doesn't make sense to me. I don't use chrome though. I wonder how Firefox handles it.
- bombcar 3y agoWould be hilarious if taken to the extreme - you’d get a notification on every share sold of Google ;)
- Retr0id 3y agoIt'd be neat if there was a way to install an extension from git, including getting notified of updates and an easy way to install said updates. The current UX around installing extensions "out-of-band" is poor (in both firefox and chrome), I wonder what it'd take to improve things.
- iggldiggl 3y ago> The current UX around installing extensions "out-of-band" is poor (in both firefox and chrome), I wonder what it'd take to improve things. The problem is that that experience isn't poor because of neglect, it's poor because you're intentionally not supposed to do that kind of thing unless you're developing and testing an add-on yourself. (I don't know how Chrome arrived at that state, with Firefox the justification was that if the user can do that sort of thing [install random unsigned add-ons] easily, then so can ad-ware [browser toolbars and other spyware stuff].)
- Retr0id 3y agoRight, I'm aware of that tension - It's the problem to be solved.
- bhpm 3y agoTracking the ownership of your Chrome extensions sounds exhausting, especially if you're someone who just wants to surf the damn web and are not some kind of super nerd.
- ptx 3y agoFor Firefox extensions, Mozilla has a "recommended extensions program" [0] which involves "rigorous technical review by staff security experts" before extensions are included, but it's not clear from their support article if every update is reviewed before it's published. If they do review every update, that would this problem at least for the more popular extensions, although I wonder how much delay it introduces when an extension needs an urgent security update. [0] https://support.mozilla.org/en-US/kb/recommended-extensions-program https://support.mozilla.org/en-US/kb/recommended-extensions-...
- numbsafari 3y agoIt's almost as if you wish there was some kind of onerous "marketplace" where participation had rules and there was some kind of enforcement taking place, and organizations that break the rules could, no matter how popular or well known, be banned if they repeatedly violate the rules of the marketplace, or work to subvert the marketplace's function.
- thisislife2 3y agoJust sounds good in theory: - More malicious apps found in Mac App Store that are stealing user data - https://appleinsider.com/articles/18/09/07/more-malicious-apps-found-in-mac-app-store-that-are-stealing-user-data https://appleinsider.com/articles/18/09/07/more-malicious-ap... - How 18 Malware Apps Snuck Into Apple's App Store - https://www.wired.com/story/apple-app-store-malware-click-fraud/ https://www.wired.com/story/apple-app-store-malware-click-fr... ...
- jjtheblunt 3y agoDo the links you provide mean it’s partially working not only in theory but for real?
- numbsafari 3y agoThe existence of crime isn’t a logical reason for eliminating law enforcement. Having a choice of marketplaces… imagine if Mozilla gave you that! A corollary… just because one piece of software has fewer reported CVEs, doesn’t mean it is more secure.
- mska 3y agoI'm currently working on an extension as well ([0]) and share the same concerns many have mentioned about extensions here. I'd like to highlight another dimension concerning the Browser APIs ([1]). Handling the permissions necessary for certain API functionalities and the corresponding warning messages can be somewhat confusing. For instance, our extension uses "chrome.devtools.panels" to open a new window within DevTools. This API doesn't require any permissions by itself. Yet, for messaging across the popup, content, and DevTools windows, we're required to use activeTab and sendMessage APIs. The DevTools window operates in its unique context, almost like a tab within another tab. For example, updating the URL in the active tab doesn't directly update the DevTools window but triggers an event. Messaging across these different contexts requires the "https://*/ https://*/*" host permission, without which Chrome and Firefox won't send the messages between these isolated windows. We made this permission optional, the DevTools Panel is activated only upon receiving explicit user consent. However, the permission prompt's messaging is something like "This extension requires access to all your data," which sounds very alarming. We don't access any data nor that we want to, but requiring that permission is mandatory since the message APIs won't work without them. This is just one example of the many undocumented complexities within Chrome's documentation. Similar pitfalls exist with message exchanges between the background service and content scripts. Sometimes you don't know why your API call doesn't work even though you think you have the required permission and asking for more permissions show very alarming messages to users. I think that a more granular permission approach, made specific to API functionalities rather than broad permissions that cover a list of APIs, would significantly help user experience. For example, requesting permission for the "sendMessage API" with a clear explanation would be far more informative for users than the general "All host https:/// https:///" permissions. There's also the issue of building for different browser. The same browser API calls can have different permissions requirement on Chrome and Firefox which makes the development process more difficult and more confusing for users since the same extension requires different permissions on different browsers. [0] https://divmagic.com https://divmagic.com [1] https://developer.chrome.com/docs/extensions/reference/api https://developer.chrome.com/docs/extensions/reference/api
- xer0x 3y agoThank you for creating this! Extensions have maliciously shared my credentials, and I appreciate whoever made this.
- mfrisbie 3y agoCreator here - you bet! It's a big problem.
- advael 3y agoI think this is illustrative of how the economy gets more scammy the faster and more secretly ownership of a product, company, or brand can change hands To me, this cuts at a fundamental logic we take for granted in the paradigm of Intellectual Property: That a brand is a fungible commodity that can be sold, like any other good or service. We treat this as a transfer of ownership of some property, but I think it makes more sense to treat this as a form of fraud. A name or brand is a signal people and businesses use to indicate who made something, and its chief value is the trust that's been built by the people running whatever operation carries that brand. The fact that it is not only legal but common practice to buy a brand explicitly for this trust in the operation is, from my perspective, obviously a big part of why everything is so scammy
- ryandrake 3y agoWait till you see the brand landscape in groceries and consumer goods. A few companies owning hundreds[1] of brands of everyday items. What company is actually behind Brand X? You pretty much need a database/app to remember as you're shopping. This is likely done deliberately to obfuscate and confuse. I always thought it would be a sensible law to make a company that displays a brand on a product also display their company name as-or-more prominently next to that brand, so people know who is actually making those products. 1: https://capitaloneshopping.com/blog/11-companies-that-own-everything-904b28425120 https://capitaloneshopping.com/blog/11-companies-that-own-ev...
- advael 3y agoYes, I think consumer brands for things like food are exactly the way this trend started, and the aggregation of them has been gradual but led to lower quality and more scamminess throughout
- lencastre 3y agoShrinkflation!
- donmcronald 3y ago
- tech234a 3y agoI've also used Extensions Update Notifier [1] in the past, which has the option to disable extensions on every update. It hasn't been updated since 2016, but recent reviews say it still works. It doesn't detect ownership changes though. [1]: https://chromewebstore.google.com/detail/extensions-update-notifie/nlldbplhbaopldicmcoogopmkonpebjm https://chromewebstore.google.com/detail/extensions-update-n...
- bossyTeacher 3y agoNo one has said yet? Can't believe this, HN! Ok, I will be the one to say it: A extension watcher is great but what happens when THIS extension itself changes owners? Who watches the watcher?
- xg15 3y agoDoes it check itself too? I.e. notify you if its own ownership has changed?
- 8organicbits 3y agoIt looks like the current code does. But this provides little assurance as the new owner could update the code to behave differently. Since the checks run after the update is installed, you can't rely on it.
- whatgoodisaroad 3y agoKeep in mind, in the really malicious cases where an extension has changed hands, they often just sell the credentials to the Google developer account, so this won't detect those cases.
- SunlitCat 3y agoIs selling the whole developer account even allowed?
- Etheryte 3y agoMany things are sold that are not allowed to be sold, hasn't stopped criminals yet.
- qwertox 3y agoBut are these developers initially criminals? I doubt so. And putting at risk associated accounts (same phone number for registration, recovery email address) isn't a comfortable game to play for most normal developers.
- asadotzler 3y agowell, selling your installed base to someone you know to be evil may not be criminal, but it's certainly sleazy.
- r00fus 3y agoBeing sleazy is rewarded in capitalism.
- artyom 3y agoAll you need is to send your password, and a quick session to set up 2FA with the buyer's methods, update recovery settings, etc. As long as you don't use that account for anything else, it's seamless. Legalese isn't going to stop that.
- Animats 3y agoWhen an extension changes owners, that name should be dead for a year. That would be useful for domains, too.
- infogulch 3y agoI'm quite sympathetic to the stated goal, and the technical limitations are understandable, but the fact that it sends a list of all your extensions to an extension-oriented ad network is a bit sus... > Why does this need an external server? - Browsers have special rules about modifying extension marketplace domains. For example, you cannot set declarative_net_request rules for chromewebstore.google.com. Therefore, this extension delegates the developer info checking to the ExBoost [1] API server. [1]: https://www.extensionboost.com/ https://www.extensionboost.com/ > What Is ExBoost? - ExBoost is a collaborative network of browser extensions that want more users and more reviews. > How does ExBoost work? - Extensions add ExBoost slots inside their UI. These slots will show promotions for similar extensions, or reminders to review your extension.
- chatmasta 3y agoIt looks like Extboost is also a project by OP. The charitable explanation would be that they used its API server because they already had the data they needed to scrape an extension's metadata (i.e. its owner) given an extension ID.
- Andrews54757 3y agoI've developed some small extensions for fun. A couple of weeks ago I got an email from ExBoost with the subject "Collaboration To Grow Our Extensions." They wanted me to include their code in my extensions. I quote: "You show mine, I show yours. Zero cost, all win." I thought it was suspicious and junked the email. It didn't seem any different from the other spam emails I got from scammers.
- mrtesthah 3y agoI don’t even understand why Google allows an extension to have its owner changed while remaining installed and active on users’ machines. Changing the owner should automatically disable the extension worldwide and require manual user re-approval, at the very least.
- somenewdev 3y ago[flagged]
- somenewdev 3y ago[flagged]
- mcapodici 3y agoA lot of extensions are only used occasionally, so it would be nice to have them off by default, but be able to launch a session with just that extension for when needed, which may/may not be incognito.
- rKarpinski 3y agoA few months ago I made a free open source extension to speedup youtube ads that I shared here & hit the front page. Within a week a guy (who commented on my show hn thread) copied it and promoted his version on reddit which went viral and has 300k+ Users [1] But why copy a free open source extension instead of just contributing a pr? Well... a few weeks later he was trying to sell it on multiple sites for 5 figures. Maybe they still own it but I couldn't help but notice that the registered developer for his extension on the chrome store has also changed since it was originally published. [1] https://github.com/rkk3/ad-accelerator/blob/main/lessons_post.md https://github.com/rkk3/ad-accelerator/blob/main/lessons_pos...
- 93po 3y agothat must feel crappy, sorry to hear that happened
- gxs 3y agoAnd this is how you end up with the IP laws we have today. This sucks man, at least this only cost you potential earnings (that it sounds like you weren’t pursuing) vs any actual money. I wonder if in theory, should you want to, there’d be any legal recourse.
- fireattack 3y agoHe copied OP's idea, not their code AFAIK.
- PradeetPatel 3y agoEven if they copied OP's code, depending on the FOSS license it might not be illegal. As someone who grew up in India, this practice is actually quite common and not exactly frowned up. When you have multiple products that perform similar functions, whoever can sell them the best will gain market dominance. OP did not pursue the monetization path chosen by his competitor and lost out only on potential income, this might be a good lesson in entrepreneurship and IP management.
- 3y ago
- artyom 3y agoThis is no joke. I've owned a quite popular open source Chrome extension for years. The amount of total donations wouldn't pay for a month of coffee. But oh boy, the number of times and insane numbers I was offered to sell the extension for obviously nefarious purposes (some of them outright explicit). I rejected them all but nobody in their sane mind would really expect the moral virtue of the original developer to be the only security and privacy framework for this scenario.
- artyom 3y agoAlso: the really nefarious ones wouldn't be detected by the tool from the post, as they demand that the developer account is also transferred with the purchase, not just extension ownership (including the user base) and the code.
- user3939382 3y agoThis should just be a feature in Chrome. They should be disabled when owners change if you have this option enabled, which should probably be the default, and you get prompted to ask if you want to enable it. Ideally ownership change should require an accompanying statement explaining the change which is then presented to users in this process.
- paulryanrogers 3y agoCould be hard to vet. Maybe it could be based on email address change? Or changing email requires paying the dev fee again, and if the financial info differs then prompt end users?
- zubairq 3y agoCould a variation of this be used so that it is possible for a popular chrome extension like Metamask to be hacked so that a compromised update could be installed automatically and then everyone's crypto gets stolen?
- Sophira 3y agoThis is a cool idea! However, I have a couple of reservations: 1. Firstly, the JavaScript code in the release version of the extension is 12MiB. This is a lot of code, with much of it in a bundled form, making it very difficult (if not almost impossible) to verify them against the originals in the case of React, lodash, etc. 2. It seems like the code uses an external API[0] to find the current owners of the installed extensions. While I appreciate that this may be one of the only ways to do it (since I imagine Google themselves would not appreciate an extension programmatically accessing the Chrome Web Store to find the current owners) - and as far as I can see from the published code, it doesn't send any identifying data beyond what a normal Web request does, hence why I'm not identifying the site by name here - I would still urge caution as it might still cause alarm to someone examining their Web traffic and seeing a suspicious domain name, as the sort of person who would be interested in this extension is more likely to also the sort of person who would watch their Web traffic closely. (I know I do.) In general, though, I love this idea and I hope it raises awareness of new owners looking to monetise existing extensions, and does something to reduce the likelihood of it occurring. [edit: Actually, on further investigation, it looks like the developer of this extension is also the developer behind ExtensionBoost[1] (the site that's hosting the API mentioned above), so there's no need to hide the name any more. Note that this may also indicate that the developer is using this to gather lists of installed extensions, to allow them to indicate 'related' extensions by popularity in ExBoost - but it's important to note that this is just speculation on my part!] [0] https://github.com/classvsoftware/under-new-management/blob/3db0bf06a30ee65bcbc4cecc6c23f2688e7aa671/src/background.ts#L27 https://github.com/classvsoftware/under-new-management/blob/... [1] https://www.extensionboost.com/ https://www.extensionboost.com/
- thih9 3y agoIf you don't trust the owner, you shouldn't install an extension in the first place. And if every owner is at risk, the store should have a way of protecting against that. This extension sounds like a good temporary measure; still, the overwhelming majority of Chrome users won't install it. The actual fix should happen elsewhere.
- prmoustache 3y agoI am not a chrome extension user but I am gobsmacked that it wouldn't be the default behavior of Chrome in the first place. What happens in Mozillaland, can the owner/developer account of an extension change?
- npace12 3y agoGreat idea! We need a lot more visibility into what extensions are doing. I made little-rat [1] last year, to detect network calls coming from other extensions. Love to see more tools like yours! [1] https://github.com/dnakov/little-rat https://github.com/dnakov/little-rat
- 1970-01-01 3y agoGreat seeing my thoughts turned into real software! https://news.ycombinator.com/item?id=37053194 https://news.ycombinator.com/item?id=37053194
- fudged71 3y agoIs there any way that this extension could look backwards in time, before [this] extension is installed?