Live data from Hacker News

Google enforcing Web store only extensions for Chrome

sites.google.com

11–20 of 84 posts

Re: Google enforcing Web store only extensions for Chrome

#11

I worry we are heading towards a day when all electronic devices are jailed, and you have to jump through hoops to own and use "development" devices. It's like we're taking away pens and pencils, since they can be used to mess up books, instead of teaching more people how to write.

Google, Apple and MS, sure, but that's just Linux's gain.

Yes, the "Year Of The Linux Desktop" joke is as funny as ever, but I definitely foresee a split in computing into passive consumers with no idea how things work and hackers who need full access to the things they own and want to experiment, learn and create.

Re: Google enforcing Web store only extensions for Chrome

#13
post #5

If you want to keep any extensions that you didn't install from Web Store, use the dev channel[1] of Chrome and they will work just fine. I use an extension and they warned me one month back to either install their Web Store version will fewer functionality or move to dev channel. [1] http://www.chromium.org/getting-involved/dev-channel

Why don't they simply give me a config flag to change the behaviour? I understand what they are trying to do but it annoys me to have to use non-stable releases just so that I can use a couple of useful extensions not available from the store.

Didn't you get the memo? Choice and customisability is decadent and goes against the wishes of Big Google. Why would you even need to customise a telesc^H^H^H^H^H^H Chrome Install anyway? Big Google knows best.

Re: Google enforcing Web store only extensions for Chrome

#15
post #7

> Why couldn’t this problem be solved by having a setting/option to load extensions that are not hosted in the Chrome Web Store? Unlike modern mobile operating systems, Windows does not sandbox applications. Hence we wouldn’t be able to differentiate between a user opting in to this setting versus a malicious native app overriding the user’s setting. Sounds a bit BS to me. In what reasonable threat model the attacker…

This is defense-in-depth. Sometimes, the goal is to get a chrome extension installed. (One that, for example, creates pop-up advertisements at random intervals to generate grey-market PPM revenue for the extension author.) Windows (and it's inevitably Windows) knows enough to realize "hey, this Chrome isn't the Chrome that was here yesterday." Signed binaries and SmartScreen work together well enough that even when Chrome is installed to a user-writable directory, it'll get punted if a virus actually changes it.

But if a virus can get a perfectly valid program, with every reason to already be on the system, to do something that program already has permission to do... then it can circumvent the OS's strictures against running novel-and-unknown scripts and binaries.

Re: Google enforcing Web store only extensions for Chrome

#16

I worry we are heading towards a day when all electronic devices are jailed, and you have to jump through hoops to own and use "development" devices. It's like we're taking away pens and pencils, since they can be used to mess up books, instead of teaching more people how to write.

Heading towards - we are already there. The majority of devices sold on the market last year are locked and rootless. Only the PC is still holding the line but giving slowly.

Smartphones, Consoles, Smart TVs, Tablets - locked by default.

Re: Google enforcing Web store only extensions for Chrome

#17
post #8
post #7

> Why couldn’t this problem be solved by having a setting/option to load extensions that are not hosted in the Chrome Web Store? Unlike modern mobile operating systems, Windows does not sandbox applications. Hence we wouldn’t be able to differentiate between a user opting in to this setting versus a malicious native app overriding the user’s setting. Sounds a bit BS to me. In what reasonable threat model the attacker…

> solved by having a setting/option to load extensions that are not hosted in the Chrome Web Store It is the current solution. Unzip, go to extensions, enable developer mode, load extension. Which IMHO is much more dangerous than downloading crx

It's a lot more of a hassle, though, to ask users to keep an extracted directory sitting around which Chrome basically symbolically links to, than to just download a .crx, drop it on the extensions window, and then delete that .crx.

Even I still get confused sometimes, as a chrome-app developer, when I move a project folder and Chrome suddenly can't find my extension. It goes against how we think of "deploying to test" in any other development workflow.

Re: Google enforcing Web store only extensions for Chrome

#18
post #7

> Why couldn’t this problem be solved by having a setting/option to load extensions that are not hosted in the Chrome Web Store? Unlike modern mobile operating systems, Windows does not sandbox applications. Hence we wouldn’t be able to differentiate between a user opting in to this setting versus a malicious native app overriding the user’s setting. Sounds a bit BS to me. In what reasonable threat model the attacker…

Extracting banking information? Session intercept, credentials theft - you need some form of cooperation with the user and the browser to get them.

Re: Google enforcing Web store only extensions for Chrome

#19
post #5

Earlier quoted context omitted.

Why don't they simply give me a config flag to change the behaviour? I understand what they are trying to do but it annoys me to have to use non-stable releases just so that I can use a couple of useful extensions not available from the store.

Didn't you get the memo? Choice and customisability is decadent and goes against the wishes of Big Google. Why would you even need to customise a telesc^H^H^H^H^H^H Chrome Install anyway? Big Google knows best.

Larry Page Is Watching You

Re: Google enforcing Web store only extensions for Chrome

#20
post #10

I worry we are heading towards a day when all electronic devices are jailed, and you have to jump through hoops to own and use "development" devices. It's like we're taking away pens and pencils, since they can be used to mess up books, instead of teaching more people how to write.

The real analogy is that we're taking away pencils because writing in the wrong book can cause you to lose all your money and cause months of problems. And these books are disguised as your own diary, cookbooks, maps and the TV guide.

No, it's like taking away books because you can give yourself a papercut, or pencils because you can stab yourself with one - if you use common sense, you won't.
Post reply on HN