Earlier quoted context omitted.
It sounds like you would need the ability to access all the data on the page but not be able to phone home. Enforcing that sounds like a nightmare.
Right now extensions can provide a regex of the URLs that they will be enabled on. Obviously a malicious developer will just say "all" though.
Google purges bad extensions from Chrome
61–70 of 93 posts
Re: Google purges bad extensions from Chrome
#62http://extensiondefender.com/blog/red-alert-dangerous-exploi...
Re: Google purges bad extensions from Chrome
#63This is fantastic news. The Quick Note Chrome extension from Diigo (now removed) submits every URL visited to a third-party server and those URLs are then crawled the next day. We just switched our 25 member customer service team to Chromeboxes and were very concerned to find soon after that an EC2-based crawler was querying private URLs of our platform. Because the Chrome Web Store had not banned bad actors like Dii…
Re: Google purges bad extensions from Chrome
#64Earlier quoted context omitted.
> You can manually install extensions Not on Chrome stable. You have to use beta, dev, or a Chromium build for that.
I think you can on regular Chrome. Just tick the 'Developer Mode' box at the top of the extensions page.
Re: Google purges bad extensions from Chrome
#65Better yet, disable all of them.
Disable all extensions? No more Tampermonkey, Postman, LastPass? Seems like a massive overkill. Extensions provide vital functionality.
Browsers are for interactive documents, for everything else there are native applications, even though I also do web development gigs.
Re: Google purges bad extensions from Chrome
#66Should say "Google does a lousy job purging bad extensions from Chrome". A: Because all of the malware I reported is still there. And B: Because actually policing your store for malware for once shouldn't be a news item.
Re: Google purges bad extensions from Chrome
#67Earlier quoted context omitted.
Right now extensions can provide a regex of the URLs that they will be enabled on. Obviously a malicious developer will just say "all" though.
Please tell me that it actually displays a regex to the end user during installation and asks them to read and approve it.
Re: Google purges bad extensions from Chrome
#68Just FYI, there are many cases of malware (presumably browser extensions) targeting online bankings in Indonesia recently. The typical flow is like this: 1. The user logs in to his/her online banking website. 2. The malware gets triggered and phones home with user's credentials. 3. The bad guy logs in using user's credentials in own computer. 4. The bad guy initiates bank transfer from user's account to his account.…
Ew, bank fail. My bank will send me a 2FA code to my phone, it'll explain what it's for first. So the message will say 'you're trying to send $200 to xyz at date yxz. Enter this code'. You'd then have to go to a screen on your computer with that particular transaction, find it, and enter the code. You don't suddenly get some kind of authentication pop up, and know to enter a particular code that authorises anything t…
Extensions are Apps.
Without a meaningfully robust (and mandatory) security model and some basic security audits to prevent over-reaching security defaults/requests, you might as well be running Windows XP.
Re: Google purges bad extensions from Chrome
#69Should say "Google does a lousy job purging bad extensions from Chrome". A: Because all of the malware I reported is still there. And B: Because actually policing your store for malware for once shouldn't be a news item.
Could you give some examples of malware that you reported that are still there? What conditions do you use to classify extensions as malware?
Interestingly enough, Vosteran also produces a rogue fork of Chrome which makes Vosteran's own search/ad platform built-in and unavoidable. Said rogue fork is also installed without users' permission.
https://chrome.google.com/webstore/detail/vosteran-new-tab/o...
I invite you to peruse the first five pages of search results here and make your own assumptions about the legitimacy of all it's five star ratings: https://www.google.com/?gws_rd=ssl#q=vosteran
Re: Google purges bad extensions from Chrome
#70So how long until AdBlock Plus and uBlock are "bad" extensions? Enjoy your walled garden. Soon enough the walls will be so high you wont even remember what a free browser felt like.
That being said, your walled garden notion is accurate. Chrome used "security" as an excuse to lock down the extensions platform to only their Web Store. But it's not any more secure, since there's plenty of malware in the Web Store. It was just an excuse to wall in their product.