Live data from Hacker News

Google to reject Chrome extensions outside of Chrome Web Store

techcrunch.com

61–70 of 71 posts

Re: Google to reject Chrome extensions outside of Chrome Web Store

#61
post #10

There's a comment on the Chromium blog [1] (via magicalist's comment [2]) that nails this: if security is all they cared about, a signed certificate is all that's necessary. Knowing that option exists and persisting with their store-only approach means they must have an ulterior motive of some sort, most likely control and money. Ad blockers that target Google Ads will be no more, as well as anything else that the us…

Another option would be to allow untrusted extensions like the Android setting for "Allow untrusted sources" for installing apps.

Of course the problem with that route is preventing any unwanted-extension installer from maliciously enabling that option itself.

Re: Google to reject Chrome extensions outside of Chrome Web Store

#62
post #42

Earlier quoted context omitted.

The alleged reasoning is to stop malware. A signed certificate must come from an authority willing to put their own reputation on the line, but Google does not need to be the only such authority.

Great! I am the "Definitely Not A Malware Author" certificate authority and I have signed this "Definitely Not Malware" extension.

Not quite. The DNAMA would quickly lose hard-won reputation once DNM was shown to be malware. Google not being the only CA doesn't mean everyone gets to be a CA.

Re: Google to reject Chrome extensions outside of Chrome Web Store

#63
post #62

Earlier quoted context omitted.

Great! I am the "Definitely Not A Malware Author" certificate authority and I have signed this "Definitely Not Malware" extension.

Not quite. The DNAMA would quickly lose hard-won reputation once DNM was shown to be malware. Google not being the only CA doesn't mean everyone gets to be a CA.

> Not quite. The DNAMA would quickly lose hard-won reputation once DNM was shown to be malware.

No problem. I am a completely different "Definitely Not A Malware Author 2" certificate authority and I have signed this "Definitely Not Malware" extension.

> Google not being the only CA doesn't mean everyone gets to be a CA.

Oh. In that case who gets to decide who gets to be a CA?

Re: Google to reject Chrome extensions outside of Chrome Web Store

#64
post #6

Naturally, extensions that block certain kinds of Google ads (such as Youtube ads) are not allowed in the Chrome Web Store.

Seriously? What about https://chrome.google.com/webstore/detail/adblock-plus/cfhdo... (AdBlock Plus), for instance?

Re: Google to reject Chrome extensions outside of Chrome Web Store

#65
post #62

Earlier quoted context omitted.

Not quite. The DNAMA would quickly lose hard-won reputation once DNM was shown to be malware. Google not being the only CA doesn't mean everyone gets to be a CA.

> Not quite. The DNAMA would quickly lose hard-won reputation once DNM was shown to be malware. No problem. I am a completely different "Definitely Not A Malware Author 2" certificate authority and I have signed this "Definitely Not Malware" extension. > Google not being the only CA doesn't mean everyone gets to be a CA. Oh. In that case who gets to decide who gets to be a CA?

Who decides who gets to be a CA for SSL certs? Similar process. Somehow my browser doesn't recognize a CA that would allow any random person to pretend to be Facebook.

Re: Google to reject Chrome extensions outside of Chrome Web Store

#66
post #38

Very disappointing if there is no workaround available to the "ordinary" user. Enough to make me fully question whether I want to use Chrome at all. Question: what is the situation with ChromeOS? If this applies to ChromeOS then it is essentially in the same locked down, anti-competitive state that the Apple app store is in. It is the main reason I avoid Apple devices and would pretty much put ChromeOS devices on the…

Blogpost says this change is only for Windows stable/beta. The workaround for the "ordinary" user is to use dev/canary. Btw, if you're a ordinary user, do you care where you get the extension from?

Re: Google to reject Chrome extensions outside of Chrome Web Store

#67
post #6

Naturally, extensions that block certain kinds of Google ads (such as Youtube ads) are not allowed in the Chrome Web Store.

Seriously? What about https://chrome.google.com/webstore/detail/adblock-plus/cfhdo... (AdBlock Plus), for instance?

Adblock Plus by default whitelists Google ads.

https://easylist-downloads.adblockplus.org/exceptionrules.tx...

Re: Google to reject Chrome extensions outside of Chrome Web Store

#68
People who commented until now don't know how blessed is this measure. If you're a programmer, you probably don't get lots of malware in your computer, but if you ever had to use the same Windows PC as your uncle, mother or brother-in-law, even for a short time, you would know how bad it is to see huge amounts of malware and changed home pages, new tab pages, default search engines, everything messed up inside Chrome.

I don't know how these people get all these malwares, but is a fact that they get them installed. And if you don't have a better solution, Google at least has a temporary potentially good one.

Re: Google to reject Chrome extensions outside of Chrome Web Store

#69

Earlier quoted context omitted.

> Not quite. The DNAMA would quickly lose hard-won reputation once DNM was shown to be malware. No problem. I am a completely different "Definitely Not A Malware Author 2" certificate authority and I have signed this "Definitely Not Malware" extension. > Google not being the only CA doesn't mean everyone gets to be a CA. Oh. In that case who gets to decide who gets to be a CA?

Who decides who gets to be a CA for SSL certs? Similar process. Somehow my browser doesn't recognize a CA that would allow any random person to pretend to be Facebook.

The web browser authors/distributors decide what root CAs will be included in their browsers. So in this case concerning Chrome, Google decides.

Which means Google is still in charge, ultimately.

Which means that this digital signature scheme hasn't actually accomplished anything.

Re: Google to reject Chrome extensions outside of Chrome Web Store

#70

Earlier quoted context omitted.

Who decides who gets to be a CA for SSL certs? Similar process. Somehow my browser doesn't recognize a CA that would allow any random person to pretend to be Facebook.

The web browser authors/distributors decide what root CAs will be included in their browsers. So in this case concerning Chrome, Google decides. Which means Google is still in charge, ultimately. Which means that this digital signature scheme hasn't actually accomplished anything.

Google controls the entire browser, meaning they are in absolute control, ultimately. They could inject code into your banking web sites, they could block all the porn, whatever they want.

The idea isn't that the certificates would wrest control away from Google, it's that they wouldn't be able to use "omg the malwares" as a shield for their intentions. If there's a root CA that's handing out certs for malware extensions then sure, pull the plug, but if the root CA is handing out certs for ad blockers and Google pulls the plug then it'll be plain as day what they're doing.

Heck, all the browsers nowadays use extensions of some sort, maybe they could form a consortium for extension certifications so no one company would be in complete control. You could bet Mozilla would keep that sort of behavior in check, at least.

Post reply on HN