3 ms·
I am displeased by this change. Although the Firefox version of my extension is more work to develop, I will be pouring most of my resources into that in the fu
by taway2012 13y ago
I am displeased by this change. Although the Firefox version of my extension is more work to develop, I will be pouring most of my resources into that in the future.
I currently have a product that uses a Chrome extension to work. I am privately beta'ing it out by hosting it on my own website.
Because I don't want to be killed with negative reviews of my unpolished first version in the Chrome store.
Now I am forced to show my work and suffer brickbats in public even before I finish it. WTF.
Second
=======
And post-Snowden, the Chrome web store publication process is LESS secure for my users than me hosting the app myself. In the Chrome store, you send Google your raw source (possibly minimized) files. They will sign it and push a blob to the end user. https://developers.google.com/chrome/web-store/docs/publish https://developers.google.com/chrome/web-store/docs/publish
AFAIK, there is no way for the end user to have any assurance that the file being pushed by Google was the file that the developer intended to push.
With a privately-served version, the equivalent of a secret key created by the developer needs to be compromised to push updates.
Please correct me if I'm mistaken about this.
- ender7 13y agoIIRC, the CWS allows you to distribute alphas and betas to a specific set of users.
- taway2012 13y agoYeah, I looked into that. There doesn't seem to be a way to have a "hidden" extension whose URL isn't public, but which can be downloaded without signing into a Google account. That sucks for people in my network who are being kind enough to test my software. Instead of just messaging them on Facebook/Twitter/Skype/Email/SMS/iMessage/Linkedin with a URL, I need to find out their Google account and add it to a dashboard and they need to be logged in before they download.
- SudoNick 13y agoSnowden or no Snowden, a security focused developer wouldn't want someone else signing on their behalf or someone else controlling availability and updating. A security focused user wouldn't want to see that either.