Live data from Hacker News

Let's build a Chrome extension that steals as much data as possible

mattfrisbie.substack.com

241–250 of 320 posts

Re: Let's build a Chrome extension that steals as much data as possible

#246
post #63

Earlier quoted context omitted.

> Wait until you see what’s possible with executables! The most important thing is whay you tell the user - Windows says "We don't know where Trojan.exe came from, it could be a virus, are you sure you want to run it?" Chrome says: "You downloaded Trojan.exe from our store, we manage it and check it for viruses. It only asks for harmless permission, install it!" One is warning you, the other is entrapment.

> It only asks for harmless permission, install it! I see it asking for two very scary permissions, two somewhat scary permissions, and one annoying one?

I think the problem is that you don't actually know what the permission is for. It isn't in relation to anything. It's a blanket permission. But almost everything asks for some kind of blanket permission when you install it. Your only option is to say yes. For mobile apps, things have got better and a lot of things ask for their blanket permission later on in the piece. In many cases, it's still not in relation to anything. When they are in relation to something, you're usually not granting permission to do the thing you want to do, you're granting permission to do anything like what you want to do.

The user isn't giving informed consent, because even if, like you, they are informed about what the worst case is for granting this permission, they have no reasonable knowledge about whether the worst case is likely, even knowing that they've been asked to give permission. The questions are simply too generic for informed consent to be possible. (Mobile apps are getting better here as well, but there's still a long way to go.)

So the permissions aren't actually about managing your risks; they're about managing Google's risks.

Post reply on HN