Live data from Hacker News

Google to reject Chrome extensions outside of Chrome Web Store

techcrunch.com

51–60 of 71 posts

Re: Google to reject Chrome extensions outside of Chrome Web Store

#51
post #38

Very disappointing if there is no workaround available to the "ordinary" user. Enough to make me fully question whether I want to use Chrome at all. Question: what is the situation with ChromeOS? If this applies to ChromeOS then it is essentially in the same locked down, anti-competitive state that the Apple app store is in. It is the main reason I avoid Apple devices and would pretty much put ChromeOS devices on the…

"Question: what is the situation with ChromeOS?"

I don't know, but why would anyone even consider running ChromeOS? The fact that you have to sign in (with a Google account) gives Google unprecedented opportunity to track your activity in the OS. Even something as simple as printing to your desktop printer requires sending your documents via Google's cloud print service.

Imagine having to sign in to Windows or your Mac with your email address and having to remain signed in always to use the OS. Most of us would be horrified. I'm just astonished by how little comment is made of Google's insatiable appetite to track and record online behaviour.

Re: Google to reject Chrome extensions outside of Chrome Web Store

#52
post #15

Earlier quoted context omitted.

Firefox, Chromium.

I think Mozilla may be headed in the same direction. Add-on File Registration System: http://www.ghacks.net/2013/11/01/mozillas-add-file-registrat... Merging of AMO with Firefox Marketplace: http://www.ghacks.net/2013/10/26/thunderbird-seamonkey-kicke...

Doubtful. Mozilla has repeatedly gone out of their way to ensure that their services aren't strictly reliant on a centralized source. Firefox Sync allows you to set up your own sync server. Persona allows you to set up your own authentication server. Firefox OS allows you to set up your own first-class app store. Locking down Firefox add-ons in the same manner as Chrome would be highly out-of-character.

Re: Google to reject Chrome extensions outside of Chrome Web Store

#53
post #49
post #42

Earlier quoted context omitted.

The alleged reasoning is to stop malware. A signed certificate must come from an authority willing to put their own reputation on the line, but Google does not need to be the only such authority.

So the extension being installed on some malicious site would have a popup talking about security certificates and such, and asking the user whether they want to proceed? You and I might think twice, but most users just click "Yes". Signed certificates would not be adequate to protect the average user.

The idea is that the browser would only accept signed certificates, and only those certificates which the signing authority has not revoked. So long as the signing authority is in a trusted list, the user would see no Yes/No option at all. It would simply install, or be rejected outright with an explanation of why.

It would be like limiting web browsing to HTTPS only, except you would not be given the option to click through for unsigned certificates.

Re: Google to reject Chrome extensions outside of Chrome Web Store

#54
post #29

This has made me very, very irritated. I was quite upset at the initial change to preventing installation of third party extensions via a download, but then I realised it was for the best. However, to fully remove the ability to install third party extensions is just ludicrous. I develop a small Chrome application for internal use at my workplace. The staff love it, it helps them do their jobs a lot quicker. I don't…

The original article says they will continue to support "installs via Enterprise policy", whatever that means exactly.

Re: Google to reject Chrome extensions outside of Chrome Web Store

#55
post #53
post #49

Earlier quoted context omitted.

So the extension being installed on some malicious site would have a popup talking about security certificates and such, and asking the user whether they want to proceed? You and I might think twice, but most users just click "Yes". Signed certificates would not be adequate to protect the average user.

The idea is that the browser would only accept signed certificates, and only those certificates which the signing authority has not revoked. So long as the signing authority is in a trusted list, the user would see no Yes/No option at all. It would simply install, or be rejected outright with an explanation of why. It would be like limiting web browsing to HTTPS only, except you would not be given the option to click…

So then Google could still revoke the certificates of any ad blocking software.

Re: Google to reject Chrome extensions outside of Chrome Web Store

#56
post #38

Very disappointing if there is no workaround available to the "ordinary" user. Enough to make me fully question whether I want to use Chrome at all. Question: what is the situation with ChromeOS? If this applies to ChromeOS then it is essentially in the same locked down, anti-competitive state that the Apple app store is in. It is the main reason I avoid Apple devices and would pretty much put ChromeOS devices on the…

"Question: what is the situation with ChromeOS?" I don't know, but why would anyone even consider running ChromeOS? The fact that you have to sign in (with a Google account) gives Google unprecedented opportunity to track your activity in the OS. Even something as simple as printing to your desktop printer requires sending your documents via Google's cloud print service. Imagine having to sign in to Windows or your M…

Being constantly signed in also gives you a lot of advantages. Not everybody has a huge distain for being signed in. There are plenty of people who PREFER a simpler OS with a simpler UI that doesn't get viruses or trojans, running on hardware cheaper than an iPad.

Re: Google to reject Chrome extensions outside of Chrome Web Store

#57
post #42
post #41

Earlier quoted context omitted.

Would a signed certificate approach allow them to deny extensions, or not? If yes, they could still deny ad blockers that way. If no, it is a weaker form of security than this is.

The alleged reasoning is to stop malware. A signed certificate must come from an authority willing to put their own reputation on the line, but Google does not need to be the only such authority.

Great! I am the "Definitely Not A Malware Author" certificate authority and I have signed this "Definitely Not Malware" extension.

Re: Google to reject Chrome extensions outside of Chrome Web Store

#59
post #38

Very disappointing if there is no workaround available to the "ordinary" user. Enough to make me fully question whether I want to use Chrome at all. Question: what is the situation with ChromeOS? If this applies to ChromeOS then it is essentially in the same locked down, anti-competitive state that the Apple app store is in. It is the main reason I avoid Apple devices and would pretty much put ChromeOS devices on the…

"Question: what is the situation with ChromeOS?" I don't know, but why would anyone even consider running ChromeOS? The fact that you have to sign in (with a Google account) gives Google unprecedented opportunity to track your activity in the OS. Even something as simple as printing to your desktop printer requires sending your documents via Google's cloud print service. Imagine having to sign in to Windows or your M…

I am not concerned about "tracking" very much. I'm not sure what the giant issue is that you and others have with that (ie: exactly where and what is the harm you perceive, in concrete terms?).

Btw, new versions of Windows all but force users to sign in with an email address and then proceed store all documents by default in SkyDrive. Skype is turned on and signing out is not allowed, thus you are every minute constantly advertising your presence and activity to Microsoft. Plus even searching your hard drive sends the query to Bing and shows ads to you as a result. So I am not sure Windows is on track to be much better than ChromeOS in that regard.

But while I don't mind the "tracking", I consider freedom essential. An operating system must allow the freedom to develop applications that are hostile to the interests of the platform owner. That is the only defence against a descent into a monopolistic kind of dark ages. Eg: imagine if FireFox had never been allowed to run on Windows? We'd probably still be using IE6. New disruptive technologies can only develop when they have the freedom to do so, and it is rarely in the interests of the incumbents for it to happen. So this is what I care about far more than the implications for privacy and tracking etc.

Re: Google to reject Chrome extensions outside of Chrome Web Store

#60
post #44

Earlier quoted context omitted.

And Firefox will be there with open arms :)

Funded almost solely by Google.

Microsoft would probably be more than happy to take Google's place there, even if Firefox does compete with IE.
Post reply on HN