10 ms·
Google enforcing Web store only extensions for Chrome
- jasonlingx 13y agoFollowing the same rationale, downloading of executables via Chrome should be restricted to those from Google approved publishers only.
- blueskin_ 13y agoDon't give them ideas.
- derefr 13y agoNote that downloading of executables via Chrome is mostly already restricted to those from Microsoft- or Apple-approved publishers, because of SmartScreen/Gatekeeper. (And Linux has a culture of looking for things in package management before hunting down an executable on the web, so you basically get the same effect there through convention.)
- nivla 13y ago>Microsoft- or Apple-approved publishers, because of SmartScreen/Gatekeeper. and the ones not found suspicious by Google's safe scan.[1] I remember once Chrome not letting me download a new version of Light table because it was found suspicious. Actually it will let you download it but will delet it as soon as it is done downloaded. [1]http://www.nbcnews.com/id/46330156/ns/technology_and_science-security/ http://www.nbcnews.com/id/46330156/ns/technology_and_science...
- coloncapitald 13y agoIf you want to keep any extensions that you didn't install from Web Store, use the dev channel[1] of Chrome and they will work just fine. I use an extension and they warned me one month back to either install their Web Store version will fewer functionality or move to dev channel. [1] http://www.chromium.org/getting-involved/dev-channel http://www.chromium.org/getting-involved/dev-channel
- simias 13y agoWhy don't they simply give me a config flag to change the behaviour? I understand what they are trying to do but it annoys me to have to use non-stable releases just so that I can use a couple of useful extensions not available from the store.
- blueskin_ 13y agoDidn't you get the memo? Choice and customisability is decadent and goes against the wishes of Big Google. Why would you even need to customise a telesc^H^H^H^H^H^H Chrome Install anyway? Big Google knows best.
- TazeTSchnitzel 13y agoLarry Page Is Watching You
- coloncapitald 13y agoI'm curious. Which useful extensions are you talking about and why are they not listed in webstore? The one extension that I mentioned has two versions. The non-webstore version doesn't abide to Google's T&C [lets you download Youtube videos].
- simias 13y agoSome devs don't bother to put their extensions in the store, for instance this extension to play music files embedded in image files on 4chan: http://dnsev.github.io/4cs/ http://dnsev.github.io/4cs/ I doubt it violates any T&C but I could be wrong.
- xtracto 13y agoNothing that OllyDBG and a free weekend cannot fix ;) When/If this affects me, it will be an entertaining challenge to create a crack which disables the "allowed to install?" instruction. Seems quite simple.
- zimbatm 13y agoThere are extensions that are legitimate but can't be installed from Google's Play store because it breaks policy. For example YouTube options (https://spoi.com/software/yto/ https://spoi.com/software/yto/), or the LastPass binary extension (might be wrong on that one). Thanks to the toolbar-installing software on windows it gives a legitimate reason to Google to close the system down a bit more.
- iriche 13y agoGoing to be interesting to see how DICE is going to react with their BattleLog
- pixelcort 13y agoI worry we are heading towards a day when all electronic devices are jailed, and you have to jump through hoops to own and use "development" devices. It's like we're taking away pens and pencils, since they can be used to mess up books, instead of teaching more people how to write.
- octo_t 13y agoThe real analogy is that we're taking away pencils because writing in the wrong book can cause you to lose all your money and cause months of problems. And these books are disguised as your own diary, cookbooks, maps and the TV guide.
- blueskin_ 13y agoNo, it's like taking away books because you can give yourself a papercut, or pencils because you can stab yourself with one - if you use common sense, you won't.
- doesnt_know 13y agoAs someone who has worked in the mobile pc support industry, what HN users would call "common sense" isn't really that common. I don't think developers and power users truly understand how common the huge gap is between them and non-technical users. I've given sessions on things as simple as mouse movement and basic GUI file management with drag and drop is a challenge. Don't get me wrong, I absolutely do not support "walled gardens" that are now becoming common and I don't think they are the solution to this problem. Power should always be left in the hands of the user, the solution is education. This is of course a social issue and one of gigantic scale. There are so many strong political hurdles to overcome that I'm not surprised that the industry has taken the approach it currently has.
- userbinator 13y ago> Power should always be left in the hands of the user, the solution is education. 100% agreement. Of course, in some ways the industry doesn't want users to be educated, since then they would be hard to get to be under their control.
- mehrdada 13y ago> Why couldn’t this problem be solved by having a setting/option to load extensions that are not hosted in the Chrome Web Store? Unlike modern mobile operating systems, Windows does not sandbox applications. Hence we wouldn’t be able to differentiate between a user opting in to this setting versus a malicious native app overriding the user’s setting. Sounds a bit BS to me. In what reasonable threat model the attacker can run arbitrary code on the user's system, but will need a Chrome extension to do nasty things? The attacker could just replace the Chrome binary altogether, for instance. I understand that there can be conceivable security benefits as a result of this change, but I think the real motivation is control, not security.
- est 13y ago> solved by having a setting/option to load extensions that are not hosted in the Chrome Web Store It is the current solution. Unzip, go to extensions, enable developer mode, load extension. Which IMHO is much more dangerous than downloading crx
- derefr 13y agoIt's a lot more of a hassle, though, to ask users to keep an extracted directory sitting around which Chrome basically symbolically links to, than to just download a .crx, drop it on the extensions window, and then delete that .crx. Even I still get confused sometimes, as a chrome-app developer, when I move a project folder and Chrome suddenly can't find my extension. It goes against how we think of "deploying to test" in any other development workflow.
- captainmuon 13y agoRight, so thats why .exe installers for extensions will now be popping up, which is not exactly better security-wise.
- derefr 13y agoThis is defense-in-depth. Sometimes, the goal is to get a chrome extension installed. (One that, for example, creates pop-up advertisements at random intervals to generate grey-market PPM revenue for the extension author.) Windows (and it's inevitably Windows) knows enough to realize "hey, this Chrome isn't the Chrome that was here yesterday." Signed binaries and SmartScreen work together well enough that even when Chrome is installed to a user-writable directory, it'll get punted if a virus actually changes it. But if a virus can get a perfectly valid program, with every reason to already be on the system, to do something that program already has permission to do... then it can circumvent the OS's strictures against running novel-and-unknown scripts and binaries.
- blueskin_ 13y agoYet again Google try to prevent users from gaining the same hacker mentality that created Google in the first place.
- jrockway 13y agoI doubt this is the reason. The reason is that less-educated users are being tricked into installing extensions they don't want and that make using their computer miserable for them. Meanwhile, anyone that wants to write their own extension need only click a checkbox.
- captainmuon 13y agoBut how does this protect against bad extensions? I mean they are installed along other programs as AdWare anyway, can't they just install themselves in developer or enterpise mode?
- jrockway 13y agoI assume this interacts with Windows in some way to make that more difficult, but I don't use Windows much so I don't know. According to the docs, the change doesn't apply to Linux or OS X.
- blueskin_ 13y agoThen why not just make it a hidden option behind a huge "THIS MAY CAUSE BAD THINGS TO HAPPEN" warning to frighten them like Firefox do? ...because Google hate user customisability.
- jrockway 13y agoI don't know. If you actually care you can probably ask on the mailing list; it is an open-source project after all. (This week I read about attacks convincing users to open the dev console and paste Javascript code in there. Users will do anything as long as it harms their account or their computer, it seems.)
- merlish 13y agoI'm not saying it's great news, but I really can see where they're coming from for this. Note that they're only doing this for Windows. As someone who occasionally is roped in to providing tech support for a sibling who keeps installing malware - someone who is going to fall for those repackaged versions of VLC, or one of those 'your computer has viruses, click here to install Super Security 3000' or whatever* - I can tell you that malware for Chrome along the lines of browser toolbars and ad injectors are real and out there in the wild and being installed automatically by these kinds of things. The computer has Norton Internet Security, of course. Which does sweet FA as far as I can tell. * Note to self: Install AdBlock on that computer.
- eponeponepon 13y agoOh dear. Yet another garden firmly walled.
- wreegab 13y ago"Firmly" is a bit much, given you can install an extension manually using "Developer mode".
- eponeponepon 13y agoBut if I have customers, and either don't want to or can't use the Play store, then I have to ask them to do that too, and most of them won't, so I am effectively walled off from any sales. (disclaimer: I don't have any customers and I don't produce any Chrome extensions - just engaging in speculation)
- noir_lord 13y agoI wonder if Chromium will enforce this behaviour (which is pretty anti-user) or will have an opt out. I use both Chrome and Firefox interchangeably anyway so not using Chrome won't be a hardship.
- captainmuon 13y agoDoes anyone know how this is supposed to protect users against AdWare and other bad extensions? I mean these are installed along other applications with a setup program anyway. Can't the installer just activate developer mode? I guess there is a warning that shows up, but people will just ignore it (and once you've clicked through the UAC prompt the installer can do anything anyway, like hide the warning). And there is also the enterprise mode, can't the malicious installer just use that?
- sergiotapia 13y agoYep, this is the last straw for me. The final drop of water that overflowed the cup. I'm switching back to Firefox and will make a conscious decision to start deleting all my Google data. The tin foil conspiracy theorists were right all along it seems, I'll do my best to support companies that fight for my privacy and are open source. Firefox, I'm sorry I ever left you - happy to be back.
- el_duderino 13y agoYou'll be back man. Trust me. I've tried numerous times to go back to FF, but you enjoy the speed + ridiculous amount of available popular snooping extensions more than anything. I know you're in a different state of mind atm, but you will be back to Chrome within a couple weeks.
- ubercow13 13y agoIn what way is firefox still slower than chrome? Just, IME that hasn't been the case for ages now
- sergiotapia 13y agoI have an i7 3770K 16GB DDR3 RAM and an SSD - any performance difference I may or may not perceive between the browsers is negligible. At this point I cannot in good faith support a company such as Google.
- epmatsw 13y agoSnooping extensions?
- nsmartt 13y agoComing back to Firefox from Chromium was a wonderful experience for me. The majority of extensions I used on Chromium were inferior to their Firefox counterparts, due largely to limitations of the extension API. Aside from that, load speeds are fine, the devtools are phenomenal, and everything is great. I actually enjoy using my browser.
- chii 13y agoplease correct me if i m wrong, but is the only way to work around this is to unpack the extension and use the developer mode? Or did i just miss something easy - like turning a flag on somewhere? There are a few critical extensions, like youtube center (and a couple i've written myself) that aren't on the store.
- jessaustin 13y agoUse the beta channel, or use chromium.
- pavanky 13y agoNot sure if everyone is reading the entire article. Here are two relevant points. > we’re enforcing the following changes starting in Chrome 33 Beta and stable channels for Windows > Users can only install extensions hosted in the Chrome Web store, except for installs via enterprise policy or developer mode This only affects Windows. Users who want to install extensions can still do so but the process has been made a little bit more explicit (i.e. do it via developer mode). It sounds like this step was done to protect naive users who are not aware they are downloading malicious extensions. Please point out if I am wrong in my assumptions.
- bad_user 13y agoI'm a little disappointed with Google. I understand the rationale behind this decision, however instead of improving their browser's permissions system, instead of doing a better job reviewing all those crappy extensions that turn to mallware over night (e.g. Window Resizer - and btw, Mozilla is doing a much better job), instead of all of that, they decide to drop the ability to install extensions from third-party source. I predict a similar change will also come for Android. Because grandmas need protection of course. For several months now I have been torn between Chrome and Firefox, not able to decide which I like better, switching back and forth depending on mood. Well, I guess this settles it. I was already using Firefox on my Android exclusively, because it's the only mobile browser that has extensions, whereas Google decided that extensions are a nuisance on Android and even if they don't admit it, they probably hate the idea of AdBlock making it to Android. Chrome has had a positive effect on the marketplace, but now the negative effects are starting to show up. Adobe for instance decided to drop the support they had for Flash on Linux and only support Chrome, so at present and going forward, if you want the latest Flash on Linux, you've got to use Chrome. My answer was just to disable it of course. But do we really want a monoculture? Haven't we had enough with IExplorer 5/6? Are we really that dumb? Either way, at the very least Chrome fans should start using Chromium, because the Chrome binary is not open-source and if you use it, you won't realize the true difference/cost between it and the competition. For example the PDF reader bundled in Chrome is something proprietary, whereas Mozilla bundled a PDF reader that's open-source, built in Javascript and that also works in Chromium - you see, whenever Mozilla does something, it usually benefits everybody.
- jsight 13y ago> I predict a similar change will also come for Android. Because grandmas need protection of course. I'm not sure what this means. This is the way it has always worked in Android. In order to install apps from third-party sources, you have to enable developer mode. It's easy to do (just check a box in the right place), and is a reasonable precaution, IMO. Most of the malware that is available for Android comes from third-party sources.
- ryanackley 13y agoI don't really understand the righteous indignation. The only way you can presently install a Chrome extension outside of the web store is by going to chrome://extensions in your browser, then dragging and dropping a crx file (packaged extension) onto this page. Chrome will stop allowing this. Why is that a big deal? If this makes you mad, vote with your feet. Firefox is a great browser.
- RealGeek 13y agoThere are a lot of windows application bundling malacious chrome extensions, Firefox and IE plugins with the windows installer. They are installed automatically with explicit permissions from users. Moreover, if you remove the adware from chrome extension settings, it gets installed again automatically upon your next reboot. I believe this policy shall reduce such abuse.
- d0ugie 13y agoIs there a way to search the Chrome Web Store for all extensions and apps only made by "Google, Inc." as is possible to do on Google Play?
- d0ugie 13y agoIs there a way to search the Chrome Web Store for all extensions and apps only made by "Google, Inc." as is possible to do on Google Play?