Live data from Hacker News

Our Chrome Extension Is Safe

blog.pushbullet.com

161–170 of 206 posts

Re: Our Chrome Extension Is Safe

#161
So, judging from the discussion on Twitter, there is basically a single guy at Google handling issues like that.

> FWIW Tweeting at other Googlers will probably just get them to me – not that I have a problem with that. At the moment there isn't really a better way, and as a single human I don't scale well. TBH we have systemic issues to work through to improve the comms process here

https://twitter.com/DotProto/status/1261058935085101058

> I'm literally the only one for extensions.

https://twitter.com/DotProto/status/1261155320740499456

Re: Our Chrome Extension Is Safe

#162

Earlier quoted context omitted.

You're confusing two things: laxness strictness scale carefulness/competence carelessness / incompetence scale Google tries to do this with automated processes and minimum wage drones, which results in both million dollar extensions being bump AND widespread malware being let through.

> Google tries to do this with automated processes and minimum wage drones Do you have an alternative suggestion for how they could do it better?

$1000 yearly subscription for the store membership for human curated content.

Re: Our Chrome Extension Is Safe

#163

Earlier quoted context omitted.

You can! It's far more annoying, but I've been running a few that I've made for myself In `about:config`, set `xpinstall.signatures.required` to false, and then you can an unsigned bundled extension locally and they'll persist like normal extensions.

It looks like that doesn’t work in the regular version of Firefox – only Nightly, Developer, or one of the unbranded versions. Is that true in your experience?

Yes, I forgot about this but I'm using the Developer version as my main browser because of that.

Re: Our Chrome Extension Is Safe

#164

Earlier quoted context omitted.

Which sites? Name and shame. If you absolutely must use Chromium you can use Brave instead. It doesn't solve the extensions issue discussed here but at least it cuts out most of the Google garbage.

Not the GP, but here's some: • Slack, for audio/video calls • Microsoft Teams, for audio calls (the video portion technically works if you fake the user agent) • Skype for Web, for audio/video calls (although it occasionally decides to work if you fake the user agent, it usually breaks) Slack is a problem for me. I have to boot up a VM when someone wants to call me on Slack.

If it's a linux VM it could boot up quite fast right?

Re: Our Chrome Extension Is Safe

#165
post #161

So, judging from the discussion on Twitter, there is basically a single guy at Google handling issues like that. > FWIW Tweeting at other Googlers will probably just get them to me – not that I have a problem with that. At the moment there isn't really a better way, and as a single human I don't scale well. TBH we have systemic issues to work through to improve the comms process here https://twitter.com/DotProto/stat…

I had an epiphany 5-10 years ago about technological advancement. An article on here was posted that bart workers would be obsoleted. That it would save so much money. That bart could be more efficient.

The solution was for users of bart to self service.

Which got me thinking: so much of technological advancement isn't about reducing inefficiency, its about making other people bear the cost of that inefficiency. Someone that is proficient in navigating a subway map - someone that is doing it daily - can do so much quicker than people that are unfamiliar. Despite it potentially being more efficient to keep the person used to doing these things day in and day out employed, (some) technologists still insist on eliminating them because that's more efficient when looking at the smaller picture.

This is basically what Google is doing here. They are making other people and organizations bear the burden of their inefficiencies.

Re: Our Chrome Extension Is Safe

#166
post #161

So, judging from the discussion on Twitter, there is basically a single guy at Google handling issues like that. > FWIW Tweeting at other Googlers will probably just get them to me – not that I have a problem with that. At the moment there isn't really a better way, and as a single human I don't scale well. TBH we have systemic issues to work through to improve the comms process here https://twitter.com/DotProto/stat…

How does that explain:

> Yeah, that's where I'm still catching up. The changes you've made look good at first blush, so I'm a little lost on the follow-up rejection. I'm going to open an appeal to get a second opinion. https://twitter.com/DotProto/status/1260623259315265538

If it's one person why would they be confused why the follow up submission was also rejected? And why would they be "appealing it" to themselves?

There's clearly more than one person involved here. I think they mean they are the only one dealing with customers.

I have a feeling the main review team is disconnected from customers, outside of an appeals system managed by a single person at their discretion. Which still leaves the situation with no clear transparency to developers, as again it's still not clear how their process works or whether any of this is being addressed.

Re: Our Chrome Extension Is Safe

#167

Earlier quoted context omitted.

> Google tries to do this with automated processes and minimum wage drones Do you have an alternative suggestion for how they could do it better?

Yes, but it involves spending more money.

Not necessarily?

Eg you could sell developer support at $10k/annum with a 3h SLA for escalation to a senior eng. Serious companies with business that rely on chrome plugins would purchase in a second.

Re: Our Chrome Extension Is Safe

#168

Earlier quoted context omitted.

> Google tries to do this with automated processes and minimum wage drones Do you have an alternative suggestion for how they could do it better?

$1000 yearly subscription for the store membership for human curated content.

Apple can do it for $99 a year (plus thirty percent of course). Their system is by no means perfect, but there absolutely is less bullshit malware on their market vs google chrome.

Re: Our Chrome Extension Is Safe

#169

You know this wouldn't be so much of an issue if Chrome didn't disable the ability to install extensions outside of the web store. As an extension developer its absolutely infuriating to realize that: 1. There is no way to install extensions outside the web store 2. Google won't approve anything to the web store. 3. The vast majority of people use Chrome vs other browsers. ------ I get it, Chrome is Google's browser…

edit: nvm

Re: Our Chrome Extension Is Safe

#170

You know this wouldn't be so much of an issue if Chrome didn't disable the ability to install extensions outside of the web store. As an extension developer its absolutely infuriating to realize that: 1. There is no way to install extensions outside the web store 2. Google won't approve anything to the web store. 3. The vast majority of people use Chrome vs other browsers. ------ I get it, Chrome is Google's browser…

Is it closed to all types of new extensions? Or just certain kinds requiring certain permissions or in certain groups? I hadn't heard about this.

You can still install them on Chrome by downloading a directory and loading it via the extensions page (you have to keep the directory around though).

Firefox allows you to install .xpi packages directly, just by opening the xpi and clicking "install", after enabling the option to do so in about:debugging (unless you use a development version of Firefox then it's automatically supported). No directory/zips extraction required.

Post reply on HN