5 ms·
I am absolutely flabbergasted at the fact that Chrome extension security is the way it is, considering how much Google spends to keep chrome secure. How is it,
by _fw 2y ago
I am absolutely flabbergasted at the fact that Chrome extension security is the way it is, considering how much Google spends to keep chrome secure.
How is it, in 2024, users can still blindly install malicious software directly into their browser from a web store with Google’s name at the top of it?
This goes to show even the most cautious and conscientious of users can get caught out by their extension changing hands. What, is Google expecting us to review our extensions, and their permissions, and their authors, and their authors’ associated businesses, every time we want to use our computer?
Additionally, are we even able to review the source code of extensions if they are not open source?
- timabdulla 2y agoYou can unpack and view the code of any extension after you've installed it. There's even a rule against obfuscation, though I'm not sure how enforced that is. A Chrome extension is basically a zip archive with a bunch of JavaScript inside. There's no safeguarding of the code within.
- Raed667 2y ago> There's even a rule against obfuscation Does that only cover the background/web-worker or does it also include the UI parts (popup, content-ui, dev-tools...) ? That would make using something like React or Vue almost impossible.
- timabdulla 2y agoThere's no rule against minification, which I assume is what you're referring to when you say it would make using React or Vue impossible. There's a difference between minification and obfuscation, but again, I'm not sure how they adjudicate it or how much they enforce it.
- hysan 2y ago> There's even a rule against obfuscation This is definitely not enforced. I’ve downloaded multiple extensions in the past when I wanted to learn how they worked. All of them were obfuscated. edit: saw the below comment and editing before this gets questioned. I’m not talking about minification. It was definitely obfuscation.
- rKarpinski 2y ago> I am absolutely flabbergasted at the fact that Chrome extension security is the way it is, considering how much Google spends to keep chrome secure. It's crazy and it's not even a "Google Scale" problem. There are only around 2,000 extensions that are popular (100k+ users) and the co-ordinated malicious activity is super blatant. > Additionally, are we even able to review the source code of extensions if they are not open source? Yes and you can even do this without installing the code by downloading the zip file (that contains the extension code) by using the extensionId + a get request (or using a browser)
- zb3 2y ago> This goes to show even the most cautious and conscientious of users can get caught out by their extension changing hands That's why on chromium I only install extensions that have their source on GitHub, as unpacked extensions.
- throwaway48476 2y agoGoogles ad business is pop-ups and fake download buttons. What makes you think they care about user security vs making money?
- rKarpinski 2y agoThey care about making money, but malicious extensions: damage the Google/Chrome brand, often are directly distorting the search experience and it opens them up to long tail liability (think Cambridge Analytica). The problem is the organization isn't set up to promote people for proactively managing these risks. Similar to why Twitter never got rid of the bots
- gruez 2y ago>They care about making money, but malicious extensions: damage the Google/Chrome brand, often are directly distorting the search experience and it opens them up to long tail liability (think Cambridge Analytica). More importantly, they're not getting paid for any of the malicious addons. Sure, they might be getting a cut when they show fake download button (because they run the ad network), but what are they getting when sensor tower exfiltrates your browsing history? At best they're helping their competitors get better targeting data.
- rKarpinski 2y agoDisagree, they are getting paid. Fake views, Fake clicks, Fake users on their platforms inflating the numbers. Making money off them didn't incentivize the grifts from coming about, but it slows down getting rid of it
- gruez 2y ago>Fake views, Fake clicks, Fake users on their platforms inflating the numbers. ??? How does this apply to a malicious third party addon?
- 2y ago
- deleted 2y ago[deleted]