4 ms·
This sort of abusive, insecure extension poisons the well for all extension developers. Now, I wish to submit a couple of feature requests to the Chrome team.
by taway2012 13y ago
This sort of abusive, insecure extension poisons the well for all extension developers. Now, I wish to submit a couple of feature requests to the Chrome team.
1) I wish there was a way by which an extension could declare its access patterns in much more fine-grained manner (kinda like CORS headers). Then I can prove to my users that my extension cannot do the sort of ugly crap that Amazon is doing.
2) Second is an API to expose details of an XMLHTTPRequest's (or maybe even 'document' object's) SSL server certificate. Even a binary blob will do: I can parse it in JS. Without this, you can't do "certificate pinning" for extensions.
Chrome extension permissions are too coarse-grain. Why is DOM write permission not separated from DOM read perms?
If Google doesn't crack down on abusive extensions like this, they risk users losing trust in the Chrome "brand". Just my 2 cents.
- mtkd 13y agoIt's a surprise that there hasn't been more exploits through major extensions - or maybe they've just not been discovered yet - either by a malicious developer or a repo being compromised. I keep them mostly disabled - just can't fathom why a simple extension (e.g. to pretty print JSON) seems to need the access levels on the install warnings.
- philips 13y agoOn point #2 I would love to be able to be able to use a self-signed certificate and pin it for my extension. The cert I use for my backend doesn't need to be part of the existing trusted CA infrastructure if I control the clients.
- Scaevolus 13y agoMore extensions should use fine-grained URL permissions-- far too many request access to "all data on all websites" when they could only run on their own domains: https://developer.chrome.com/extensions/permission_warnings.html https://developer.chrome.com/extensions/permission_warnings.... A way for users to restrict some permissions of an app would be good, but a UX/support problem when they disable something that breaks core functionality.
- groby_b 13y agoThat's for the extension devs to handle. I'm personally in favor of the following: 1) Users can enable or disable any permission they like 2) This is transparent to developers - i.e. if you access geolocation, you'll always get one. It just won't be the right one if you don't have permission. 3) The extension is allowed to query which permissions I've given. So devs can handle blocked permissions more gracefully if they choose.
- Hello71 13y agoSo... we've come full circle. Extensions can still say "nope, you need to give me ALL permissions".
- jonknee 13y agoMost extensions don't need much access, but this one does price comparisons as you browse. How else would it work unless it knows what you browse? Perhaps using activeTab could work, that might even be something I would use. http://developer.chrome.com/extensions/activeTab.html http://developer.chrome.com/extensions/activeTab.html At least these extensions are .js files that you can read and that Chrome does tell you what it can access (and lets you see that after they are installed). A lot better than the situation for desktop software.
- sytelus 13y agoChrome looks more and more insecure browser day by day. If the Chrome team gets their act together just not to show saved passwords in clear text I would say it would be big win for all its unsuspecting users.