7 ms·
How do you deal with hostile browser extensions?
by dbushell 2y ago
How do you deal with hostile browser extensions?
- WJW 2y agoUninstall them?
- dbushell 2y agoIf only I could opt-out, disable, or uninstall those used by visitors to my website when the extension breaks it :(
- diggan 2y agoNot much you can do, user agents continue to act as agents for the users, meaning you can serve them stuff but beyond that it's up to them to dictate their experience, for better or worse. It really sucks when extensions do fudgy stuff in global space and sometimes break your stuff though, agree. Best approach I've found is to have a help page you can link to so people can go through the typical steps of "disabling all extensions, clearing cache, etc, etc" when things break in very unexpected way and you find no causes for it.
- dbushell 2y agoIndeed. It's the user's browser and experience, it's not up to the website owner. But it's frustrating to get bug reports when a 3rd party extension is the problem, not the website. Many visitors will just bounce blaming the website too.
- ziml77 2y agoWithout someone pointing the user to what the issue is, it's very difficult for the user to know it's an extension causing the problem. Many years ago I had performance issues with a site and the only reason I knew it was due to an extension is I dug into it with the dev tools and managed to identify Dashlane as the problem.
- netsharc 2y agoI guess you could figure out valid states for your page's DOM, and a few seconds after the page has finished loading, scan it for "hostile" elements and CSS styles, and delete them... Having this idea and opening a random page (from The Guardian) on DevTools, somehow somebody's inserted scripts and iframes pointing to twitter.com.
- kelvinjps10 2y agoBut wouldn't you brake their extensions if the user wanted them to work?
- eadmund 2y agoI don’t think that ‘hostile’ is really fair in this case, when ‘insufficiently competent’ will do (albeit at the cost of more syllables). I am not a fan of Grammarly or their technical model, but I don think it’s fair to attribute malice when it is adequately explained by stupidity. It’s been a long time since I did any front-end work: should both Grammarly’s extension and your own code use namespaced property names?
- dbushell 2y agoyep, it's in Grammarly's interest to namespace or scope their CSS in a way that doesn't conflict. Not doing it adequately goes both ways, website CSS could break their extension, or their extension could break the website.
- QuadmasterXLII 2y agoWe tried applying cunningham’s law widely and it created disastrous incentives. It’s better to assume profitable yet destructive incompetence is malice.
- chuckadams 2y agoAny sufficiently advanced stupidity is indistinguishable from malice.
- MartijnHols 2y agoUnfortunately browsers don't really provide good solutions for extensions that need to inject or change sites. Look at Google's owner in-browser translate extension, its DOM manipulation breaks many interactive apps as well. There are no tools available in browsers for it to not need to do that.
- amelius 2y agoAt this point, I'm not installing any browser extensions, period.
- bufferoverflow 2y agoBut our users do.
- gs17 2y agoOP's problem wasn't that they had it installed, it's that enough of their users did to make it a problem when it breaks the site's CSS.
- bmacho 2y agoBrowser extensions are the equivalent of running random .exe on your computer except that you have to trust every vendor protecting their keys forever due to the autoupdate.
- silvestrov 2y agoThe biggest problem with browser extensions is that the source code (both css and javascript) is not easy to read/check. There should be an easy "view source" for extensions inside Chrome and extensions should be mandated to ship non-minimized code.
- kelvinjps10 2y agoNot even ublock?
- Doctor_Fegg 2y agoAh, my favourite complaint for the community website I run. "I can't see any photos on the adverts page." Are you running an ad-blocker? "Yes." What do you think an ad-blocker does...