Earlier quoted context omitted.
It's worth noting that the Chrome Web Store is currently full of malware and most malware I see on PCs was installed via the Chrome Web Store. By design, HTTPS does not protect your privacy at all if you have extensions that violate it, since they see what you see after TLS termination. So this is a huge deal, Google is already bad at it, but I can't fault them for heavily restricting extension install: Currently the…
You're confusing two things: laxness strictness scale carefulness/competence carelessness / incompetence scale Google tries to do this with automated processes and minimum wage drones, which results in both million dollar extensions being bump AND widespread malware being let through.
Do you have an alternative suggestion for how they could do it better?