Live data from Hacker News

Our Chrome Extension Is Safe

blog.pushbullet.com

141–150 of 206 posts

Re: Our Chrome Extension Is Safe

#141

Earlier quoted context omitted.

It's worth noting that the Chrome Web Store is currently full of malware and most malware I see on PCs was installed via the Chrome Web Store. By design, HTTPS does not protect your privacy at all if you have extensions that violate it, since they see what you see after TLS termination. So this is a huge deal, Google is already bad at it, but I can't fault them for heavily restricting extension install: Currently the…

You do realize that the original Pushbullet issue arose from Google trying to be even more strict and reduce the amount of malware, right? And even with all that, as you mention, CWS is still full of malware. What hope does any other store then have to create a malware free web store if even Google can't? And if they allow installation from anywhere, do you realize that whatever state we are in now, it would be order…

> What hope does any other store then have to create a malware free web store if even Google can't?

I think you're giving Google too much credit here. For years nearly every single extension, no matter how targeted the purpose, has told me "This extension will have access to all your data on all your web pages". It is such a no brainer to do a little better than that but they tolerated it for years.

In a few cases I looked into why developers requested that kind of permissions and the answer was that Chrome permissions weren't designed well enough to allow narrower permissions. So Google has no excuses here. They control the browser and the store.

Re: Our Chrome Extension Is Safe

#142
There's a great moderately-popular opensource extension providing a desktop-quality image viewer interface: zoom, rotate, stretch by default, all that jazz. Specifically, ‘there is’ this extension for Firefox. It was also there for Chrome, but the dev received the same crappy letter and didn't feel like playing the guessing game. New CRXes are still made available on the site.

Since Big G's treatment of extension developers is incompatible with their self-respect, I wholeheartedly support devs who decide to dump the web store—despite me making some use of two Chrome-based browsers.

Re: Our Chrome Extension Is Safe

#143

Earlier quoted context omitted.

At least it’s possible to side load extensions in Chrome. I’ve been more disappointed in Firefox, which doesn’t allow this at all, even in the developer release. The only thing similar to side loading that is allowed is a temporary debug process, which loads an addon but only until the browser is restarted.

You can! It's far more annoying, but I've been running a few that I've made for myself In `about:config`, set `xpinstall.signatures.required` to false, and then you can an unsigned bundled extension locally and they'll persist like normal extensions.

It looks like that doesn’t work in the regular version of Firefox – only Nightly, Developer, or one of the unbranded versions. Is that true in your experience?

Re: Our Chrome Extension Is Safe

#144

You know this wouldn't be so much of an issue if Chrome didn't disable the ability to install extensions outside of the web store. As an extension developer its absolutely infuriating to realize that: 1. There is no way to install extensions outside the web store 2. Google won't approve anything to the web store. 3. The vast majority of people use Chrome vs other browsers. ------ I get it, Chrome is Google's browser…

It's worth noting that the Chrome Web Store is currently full of malware and most malware I see on PCs was installed via the Chrome Web Store. By design, HTTPS does not protect your privacy at all if you have extensions that violate it, since they see what you see after TLS termination. So this is a huge deal, Google is already bad at it, but I can't fault them for heavily restricting extension install: Currently the…

So it's the usual: make it available unrestricted on launch so that idiots build on your platform, look how many apps/extension we have. Once the market is captured, sorry is closed now, for we must protect our users.

Re: Our Chrome Extension Is Safe

#145
This is exactly what PushBullet was hoping would happen, so I don't know why they're surprised. Everyone loves a good "Google's algorithms are destroying my livelihood and I have no recourse" story... Why? Because it's fucking compelling and, to people outside of Google, it provokes a strong emotional reaction.

Nobody wants their life and livelihood to be fucked over by an algorithm, especially when there is no recourse. These stories almost always end with some random person at Google "fixing something, really sorry" with no explanation. This is how Google operates, and I think they actually try to cultivate this image of themselves. It adds to their mystique and helps them hire bright engineers.

What can I do? Same as last time this came up, the best thing you can do is just to not use Google properties or software, and turn on your adblocker.

Re: Our Chrome Extension Is Safe

#146

You know this wouldn't be so much of an issue if Chrome didn't disable the ability to install extensions outside of the web store. As an extension developer its absolutely infuriating to realize that: 1. There is no way to install extensions outside the web store 2. Google won't approve anything to the web store. 3. The vast majority of people use Chrome vs other browsers. ------ I get it, Chrome is Google's browser…

> However Chromium is open source and it's still impossible to do so.

I don't know if it's true that the official Chromium or Chrome don't allow sideloading at all—but the rather popular ‘Ungoogled Chromium’ build certainly does (in fact, it probably still doesn't work with the web store directly): https://ungoogled-software.github.io/ungoogled-chromium-bina...

However, the security of these builds may be questionable.

Re: Our Chrome Extension Is Safe

#147

Earlier quoted context omitted.

You can! It's far more annoying, but I've been running a few that I've made for myself In `about:config`, set `xpinstall.signatures.required` to false, and then you can an unsigned bundled extension locally and they'll persist like normal extensions.

It looks like that doesn’t work in the regular version of Firefox – only Nightly, Developer, or one of the unbranded versions. Is that true in your experience?

You're correct, this doesn't work on stable or beta releases.

Re: Our Chrome Extension Is Safe

#148

Earlier quoted context omitted.

Maybe just maybe, you will consider Firefox. 1. Same or better performance 2. Open source for real not just (pretending to be) Open Source 3. More transparent process 4. No business conflicts Support Firefox if you care about the open web

I use firefox as my primary browser, but I have recently ran into issues with several sites that I need to use. Whenever I contact support, they tell me their site requires Chrome. As it is, I have a Winblows box for gaming only that I put Chrome on, but one day, I am going to be remote and needing Chrome. I don't want google's tentacles on my work laptop, but am starting to worry that I have no choice...

You can use the Ungoogled Chromium builds, which also remove the remaining creepy misfeatures that Chromium has: https://ungoogled-software.github.io/ungoogled-chromium-bina...

The builds themselves may potentially be insecure, but they're rather popular among the security-conscious target audience, so I hope someone would notice if they go bad.

Re: Our Chrome Extension Is Safe

#149
post #146

You know this wouldn't be so much of an issue if Chrome didn't disable the ability to install extensions outside of the web store. As an extension developer its absolutely infuriating to realize that: 1. There is no way to install extensions outside the web store 2. Google won't approve anything to the web store. 3. The vast majority of people use Chrome vs other browsers. ------ I get it, Chrome is Google's browser…

> However Chromium is open source and it's still impossible to do so. I don't know if it's true that the official Chromium or Chrome don't allow sideloading at all—but the rather popular ‘Ungoogled Chromium’ build certainly does (in fact, it probably still doesn't work with the web store directly): https://ungoogled-software.github.io/ungoogled-chromium-bina... However, the security of these builds may be questionabl…

You can absolutely load unpacked extensions on Chrome, it's just not as convenient.

Re: Our Chrome Extension Is Safe

#150

You know this wouldn't be so much of an issue if Chrome didn't disable the ability to install extensions outside of the web store. As an extension developer its absolutely infuriating to realize that: 1. There is no way to install extensions outside the web store 2. Google won't approve anything to the web store. 3. The vast majority of people use Chrome vs other browsers. ------ I get it, Chrome is Google's browser…

This was made particularly clear to me when I tried to install AdNauseam [1] on Chrome. Google removed the extension from their web store (imagine doing something the user wants, like messing with Google ads, terrible!) so you have to sideload it via the developer options. Now I get a popup every time I open Chrome telling me that there's a dangerous extension with a single click uninstall button.

Firefox has its issues (the signing requirements because of malware and invasive antivirus companies suck but I can understand why they exist) but their addons aren't discriminated against. There's addons listing porn sites on there, something for which Google would remove the extension on sight, there's addons that mess with Google and their ads, and the list goes on. The browser is no longer independent from Mozilla, but it still remains much more free than Chrome.

[1]: https://adnauseam.io/, it's an addon that clicks every ad while still hiding them to fight back against advertisements and break the profile ad companies construct around your interests.

Post reply on HN