Live data from Hacker News

Our Chrome Extension Is Safe

blog.pushbullet.com

181–190 of 206 posts

Re: Our Chrome Extension Is Safe

#181

You know this wouldn't be so much of an issue if Chrome didn't disable the ability to install extensions outside of the web store. As an extension developer its absolutely infuriating to realize that: 1. There is no way to install extensions outside the web store 2. Google won't approve anything to the web store. 3. The vast majority of people use Chrome vs other browsers. ------ I get it, Chrome is Google's browser…

What's your extension ID?

Re: Our Chrome Extension Is Safe

#182
post #94

You know this wouldn't be so much of an issue if Chrome didn't disable the ability to install extensions outside of the web store. As an extension developer its absolutely infuriating to realize that: 1. There is no way to install extensions outside the web store 2. Google won't approve anything to the web store. 3. The vast majority of people use Chrome vs other browsers. ------ I get it, Chrome is Google's browser…

Funnily enough, I was actually trying to figure this out today. I created a very basic Extension, to modify the new tab page (as it's something you can't set in G Suite the way we'd like it). I wanted to deploy it our G Suite users, and saw there was an option to deploy via a URL. So I packaged it up in Chrome, put the .crx in an public S3 bucket and set it to force install. Unfortunately it did nothing... is this no…

Self-hosting is def an option. Check out "Managing Extensions in Your Enterprise" https://support.google.com/chrome/a/answer/9296680?hl=en. That's probably the single best resource for hosting your own extensions and installing them on managed devices.

Re: Our Chrome Extension Is Safe

#183
post #120
post #113

Earlier quoted context omitted.

You certainly can with G Suite-managed accounts. https://support.google.com/chrome/a/answer/6306504?hl=en Edit: You seem to say this did nothing for you? Well, good luck troubleshooting.

Yeah, pointed it to the crx, set it to force install and nothing happens. If I install the crx locally it works fine. No way of seeing any logs to troubleshoot, pinged a message to our reseller but that method is looking like a dead end.

You may be able to reach out to the Chrome Enterprise Browser Support team for assistance. https://support.google.com/chrome/a/answer/4594885?hl=en

Re: Our Chrome Extension Is Safe

#184
post #180

Earlier quoted context omitted.

So it's the usual: make it available unrestricted on launch so that idiots build on your platform, look how many apps/extension we have. Once the market is captured, sorry is closed now, for we must protect our users.

Even if that's how it ended up, I doubt that was the plan. I think a lot of Google products, especially those from 10+ years ago, start out built for people like themselves: highly tech literate software engineers. As long as that is true enough, extensions are great and useful, and the users are mostly skeptical/aware enough to avoid installing malware. Now the average chrome user is the same person that filled thei…

It also doesn't help that dodgy folks started buying trusted extensions. One update of a trusted extension and you're just as bad off as installing a dodgy one in the first place.

Re: Our Chrome Extension Is Safe

#185
post #108

Earlier quoted context omitted.

You can’t have your users “Load Unpacked...”? That always works for me.

For testing sure, but this needs to go to just over 1000 people. The only example I can find online on deploying via URL is this: https://support.securly.com/hc/en-us/articles/360036540753-H... Can't see many official docs on it at all. Now I've gone the Developer route I can see you can create internal apps without having to get them approved so think that's my best option now.

This white paper may help https://support.google.com/chrome/a/answer/9296680?hl=en

At some point I want to put together a simple Node.js server and ExtensionSettings policy to demo a basic working setup, but unfortunately that's back-of-the-bus level backseat at the moment.

https://cloud.google.com/docs/chrome-enterprise/policies/?po...

Re: Our Chrome Extension Is Safe

#186

You know this wouldn't be so much of an issue if Chrome didn't disable the ability to install extensions outside of the web store. As an extension developer its absolutely infuriating to realize that: 1. There is no way to install extensions outside the web store 2. Google won't approve anything to the web store. 3. The vast majority of people use Chrome vs other browsers. ------ I get it, Chrome is Google's browser…

I think it's just closed for new submissions of apps, right? I hadn't heard anything about extensions.

Correct, apps are depreciated and you can still upload new extensions.

Re: Our Chrome Extension Is Safe

#187
post #139

Earlier quoted context omitted.

Makes you wonder - was there even a problem in the first place? Or were they just trying to silently kill this extension but failed due to this going viral? I understand they were using a very broad wildcard for permission on websites they could access. I'm glad they narrowed that down. But after they did, they still needed this to blow up in order to get an actual response.

> Makes you wonder - was there even a problem in the first place? YES. > I understand they were using a very broad wildcard for permission on websites they could access That is a problem.

But we still don't know if that was the actual reason the app got pulled, as if that were the case it should have been trivial for a computer to notice it was fixed; do you not see how that sucks?

Re: Our Chrome Extension Is Safe

#188
post #175

Earlier quoted context omitted.

I had an epiphany 5-10 years ago about technological advancement. An article on here was posted that bart workers would be obsoleted. That it would save so much money. That bart could be more efficient. The solution was for users of bart to self service. Which got me thinking: so much of technological advancement isn't about reducing inefficiency, its about making other people bear the cost of that inefficiency. Some…

Say what you want about Amazon, but they've encultured the best approach I've seen so far. They constantly try to automate and make things more efficient, but they also assume they will constantly screw up for someone, somewhere, at scale. So they back it with an empowered human CSR team, who do their best to make customers happy. They then (apparently) measure the rate of screw ups continuously, and iterate on their…

Amazon actually takes your money and also has competitors (high street etc). I think that partly explains some of the differences in their approach to your point (c). I think that Amazon also delegates a lot of the pain you're talking about onto their employees rather than their bottom line. BTW I speak as a complete hypocrite who is a happy Amazon customer.

Re: Our Chrome Extension Is Safe

#189
post #180

Earlier quoted context omitted.

So it's the usual: make it available unrestricted on launch so that idiots build on your platform, look how many apps/extension we have. Once the market is captured, sorry is closed now, for we must protect our users.

Even if that's how it ended up, I doubt that was the plan. I think a lot of Google products, especially those from 10+ years ago, start out built for people like themselves: highly tech literate software engineers. As long as that is true enough, extensions are great and useful, and the users are mostly skeptical/aware enough to avoid installing malware. Now the average chrome user is the same person that filled thei…

It never is the plan, I would say. Great products like chrome are made by people that are driven by the idea of making a great product, for the user. But after that is proven, given some time, the shareholders take over and priorities shift.

Re: Our Chrome Extension Is Safe

#190
> Apologies to Pushbullet for the rejection after addressed the original violation

Wait, what?

So you have an completly black box ultimatum, and even if you somehow magically guess what needs to be done, if you do it, they can still reject you?

That's worse than debugging IE6.

That's dishonest.

Post reply on HN