Live data from Hacker News

Our Chrome Extension Is Safe

blog.pushbullet.com

171–180 of 206 posts

Re: Our Chrome Extension Is Safe

#171

Earlier quoted context omitted.

Maybe just maybe, you will consider Firefox. 1. Same or better performance 2. Open source for real not just (pretending to be) Open Source 3. More transparent process 4. No business conflicts Support Firefox if you care about the open web

I use firefox as my primary browser, but I have recently ran into issues with several sites that I need to use. Whenever I contact support, they tell me their site requires Chrome. As it is, I have a Winblows box for gaming only that I put Chrome on, but one day, I am going to be remote and needing Chrome. I don't want google's tentacles on my work laptop, but am starting to worry that I have no choice...

Ironic. Back in the days when IE was king, we thought that all that's needed for a truly open web is open standards. Now Google has demonstrated how you can have open standards, but still create and maintain a monoculture around them, simply by evolving them so fast that any competition can't keep up.

Re: Our Chrome Extension Is Safe

#172
post #161

So, judging from the discussion on Twitter, there is basically a single guy at Google handling issues like that. > FWIW Tweeting at other Googlers will probably just get them to me – not that I have a problem with that. At the moment there isn't really a better way, and as a single human I don't scale well. TBH we have systemic issues to work through to improve the comms process here https://twitter.com/DotProto/stat…

I had an epiphany 5-10 years ago about technological advancement. An article on here was posted that bart workers would be obsoleted. That it would save so much money. That bart could be more efficient. The solution was for users of bart to self service. Which got me thinking: so much of technological advancement isn't about reducing inefficiency, its about making other people bear the cost of that inefficiency. Some…

It's troubling, I agree. I think more systems thinking helps to address this kind of mindset. Take into account not only the direct costs but the indirect costs, and much of the economic activity we take for granted evaporates. Just as an immediately obvious example, I think most of the direct profit from the petroleum industry is going to end up allocated towards climate change remediation, at least within an order of magnitude.

Re: Our Chrome Extension Is Safe

#173

You know this wouldn't be so much of an issue if Chrome didn't disable the ability to install extensions outside of the web store. As an extension developer its absolutely infuriating to realize that: 1. There is no way to install extensions outside the web store 2. Google won't approve anything to the web store. 3. The vast majority of people use Chrome vs other browsers. ------ I get it, Chrome is Google's browser…

I think it's just closed for new submissions of apps, right? I hadn't heard anything about extensions.

Re: Our Chrome Extension Is Safe

#174
post #161

So, judging from the discussion on Twitter, there is basically a single guy at Google handling issues like that. > FWIW Tweeting at other Googlers will probably just get them to me – not that I have a problem with that. At the moment there isn't really a better way, and as a single human I don't scale well. TBH we have systemic issues to work through to improve the comms process here https://twitter.com/DotProto/stat…

I had an epiphany 5-10 years ago about technological advancement. An article on here was posted that bart workers would be obsoleted. That it would save so much money. That bart could be more efficient. The solution was for users of bart to self service. Which got me thinking: so much of technological advancement isn't about reducing inefficiency, its about making other people bear the cost of that inefficiency. Some…

That's very true. I have an example to do with government. Previously client organisations would have submitted paper forms containing hundreds of fields and then at the government end these had to be manually read and entered into their software in a time consuming data entry process. At the client end, the tediousness of data entry had generally long been eliminated by their own software overprinting the forms, although periodically the government would issue new batches of forms which for no good reason altered the margins/fonts or whatever, necessitating software upgrades. Then government had the bright idea of moving the process online. The new "improved" setup involved the clients having to fill in an online web form rather than a paper one. This obviously solved the data entry problem at the government end by transferring it to the clients. No allowance was made for client software with any kind of api or anything like that, it all had to be done manually with usernames and passwords and confirmation of T&As boxes and screen after screen of boxes to fill in, manually. The automated logout ensured that login had to happen every single time a form was entered and for good measure a captcha was added to "add assurance that the forms were submitted by humans". Doubtless this was all viewed as a great success at the government in terms of increasing efficiency and offering an enhanced service to their clients

Re: Our Chrome Extension Is Safe

#175
post #161

So, judging from the discussion on Twitter, there is basically a single guy at Google handling issues like that. > FWIW Tweeting at other Googlers will probably just get them to me – not that I have a problem with that. At the moment there isn't really a better way, and as a single human I don't scale well. TBH we have systemic issues to work through to improve the comms process here https://twitter.com/DotProto/stat…

I had an epiphany 5-10 years ago about technological advancement. An article on here was posted that bart workers would be obsoleted. That it would save so much money. That bart could be more efficient. The solution was for users of bart to self service. Which got me thinking: so much of technological advancement isn't about reducing inefficiency, its about making other people bear the cost of that inefficiency. Some…

Say what you want about Amazon, but they've encultured the best approach I've seen so far.

They constantly try to automate and make things more efficient, but they also assume they will constantly screw up for someone, somewhere, at scale.

So they back it with an empowered human CSR team, who do their best to make customers happy. They then (apparently) measure the rate of screw ups continuously, and iterate on their processes until they can drive that rate close to zero.

So essentially, Bezos realized that the way to excel was to (a) move fast, (b) break things, (c) apologize (and pay painfully!) when you break things, (d) do your best not to break things in the same way again.

I feel like Google (as a whole, some teams / products aside!) doesn't really grok (c).

Which may work for customer acquisition, but not so well for retention.

Re: Our Chrome Extension Is Safe

#176
post #168

Earlier quoted context omitted.

$1000 yearly subscription for the store membership for human curated content.

Apple can do it for $99 a year (plus thirty percent of course). Their system is by no means perfect, but there absolutely is less bullshit malware on their market vs google chrome.

I think the parent meant that the Chrome user would pay $1k/year for human-curated extensions.

Re: Our Chrome Extension Is Safe

#177

Earlier quoted context omitted.

Yes, you can do so through the about:debugging page.

But you can do the same for Chrome in Developer Mode. What's the difference?

Unsigned extensions only work on Firefox Nightly and Developer, not Stable or Beta, regardless of what you set in about:config.

Re: Our Chrome Extension Is Safe

#178

Earlier quoted context omitted.

1) Chromium is open-source as well. 2) Like 90% of Mozilla revenue comes from contract with Google. 3) Not sure what community-owned means here, but one could submit useful patch to both Chromium and Mozilla teams and have it accepted into main codebase. 4) Decisions for both products are not made by a community, but by internal full-time employees who are subordinates of CEO. Mozilla CEO knows the company absolutely…

1. No, it is not. Chromium relies on binaries as well as calling Google's web services whose code you cannot read. That is why ungoogled-chromium is a thing 2. Not sure what your point is here. Mozilla needs to make money to maintain and improve its advocacy work 3. See point 1. You don't own or control Google's web services nor its domains therefore you have no full control of the build process if Google decides to…

> Not sure what your point is here. Mozilla needs to make money to maintain and improve its advocacy work

I think the point is that Google could one day just say "hmm, we don't care about being the default search engine on Firefox anymore", decide to not renew the contract, and there's goes Mozilla's biggest source of revenue. With Firefox's market share as low as it is, I wouldn't be surprised to see it happen.

It's a bit risky when a large chunk of your revenue comes from a single company, and it's incredibly risky when that company is essentially a competitor.

Re: Our Chrome Extension Is Safe

#179

You know this wouldn't be so much of an issue if Chrome didn't disable the ability to install extensions outside of the web store. As an extension developer its absolutely infuriating to realize that: 1. There is no way to install extensions outside the web store 2. Google won't approve anything to the web store. 3. The vast majority of people use Chrome vs other browsers. ------ I get it, Chrome is Google's browser…

This was made particularly clear to me when I tried to install AdNauseam [1] on Chrome. Google removed the extension from their web store (imagine doing something the user wants, like messing with Google ads, terrible!) so you have to sideload it via the developer options. Now I get a popup every time I open Chrome telling me that there's a dangerous extension with a single click uninstall button. Firefox has its iss…

On chrome you can actually create your own signing key, and then self sign the unpacked extension directory using your key. To remove the pop-up you then need to set up a group policy (on Windows) to trust your self signed extensions. End result is this popup doesn't come up at launch.

I think this is so hidden (and not really documented well) as a "fix" that must have been added for companies that use their own internal extensions that don't publish them on the web store.

If you can't figure it out from that description I can try to publish a step-by-step on how to accomplish this

Re: Our Chrome Extension Is Safe

#180

Earlier quoted context omitted.

It's worth noting that the Chrome Web Store is currently full of malware and most malware I see on PCs was installed via the Chrome Web Store. By design, HTTPS does not protect your privacy at all if you have extensions that violate it, since they see what you see after TLS termination. So this is a huge deal, Google is already bad at it, but I can't fault them for heavily restricting extension install: Currently the…

So it's the usual: make it available unrestricted on launch so that idiots build on your platform, look how many apps/extension we have. Once the market is captured, sorry is closed now, for we must protect our users.

Even if that's how it ended up, I doubt that was the plan. I think a lot of Google products, especially those from 10+ years ago, start out built for people like themselves: highly tech literate software engineers. As long as that is true enough, extensions are great and useful, and the users are mostly skeptical/aware enough to avoid installing malware. Now the average chrome user is the same person that filled their IE browser window with banzai buddy toolbars.
Post reply on HN