Live data from Hacker News

Our Chrome Extension Is Safe

blog.pushbullet.com

191–200 of 206 posts

Re: Our Chrome Extension Is Safe

#191

Earlier quoted context omitted.

This is still something of a problem of Chrome's own creation though. The reason Chrome can't be much, much more restrictive about what extensions get placed in the store is because there is no alternative. The less important your store is, the more exclusive (and safer) it can be. Look at Linux with package managers like AUR. If a package isn't included in the official Arch repos, I generally don't mind. I can go in…

I don't think their priority is making a specific area where users are free from malware; they're trying to make it hard for malware overall to integrate with Chrome. Adding a supported path for software to integrate with Chrome (allowing extensions not through the store) where they can't block malware would be giving up on that goal.

> they're trying to make it hard for malware overall to integrate with Chrome

That's a reasonable argument, and you're probably right about their motivations. But I'm not convinced that's a realistic goal, because the definition of malware/spyware changes depending on the context/user.

The big reason moderation doesn't scale is because you're forced to balance everybody's needs at the same time -- you can't optimize for any particular user. If the end-consequence of an exclusive web store is that it's much harder for the Chrome team to ban shifty apps without everyone on Twitter asking for a bullet-pointed list explaining why, then the Chrome team isn't really making the world that much safer.

In general, I would advocate that it's better to try and build safe spaces rather than safe worlds. That's kind of a pragmatic philosophy: I'm having a hard time thinking of an existing safe world that I think runs well. All of the major app stores (including Apple's) have malware problems to at least a certain degree. Most giant social networks are not doing a good job of moderating content. Package managers for languages like Node and Ruby are running into the same issues.

Maybe the web itself? But the web doesn't get its safety from moderation, it gets its safety because of sandboxing.

If I'm thinking purely as a consumer, what I really want is an extension store where I know 100% that everything on it is fine. I don't want to have to think or read reviews or look up the author before I install an extension. I want it to be clear when I'm being safe and when I'm doing something dangerous. I suspect that's what a lot of consumers want, and I just don't see any realistic path for Chrome to provide that with their current strategy.

I get that "somebody might choose to leave the safe space and install malware anyway" feels bad, but if the consequence of avoiding that is, "everybody gets kind of substandard protection all the time", maybe it's worth questioning whether Chrome's malware goals are worth pursuing in the first place.

Re: Our Chrome Extension Is Safe

#192
post #176
post #168

Earlier quoted context omitted.

Apple can do it for $99 a year (plus thirty percent of course). Their system is by no means perfect, but there absolutely is less bullshit malware on their market vs google chrome.

I think the parent meant that the Chrome user would pay $1k/year for human-curated extensions.

This is kind of strange thought isn't it? At that rate even if people were inclined to pay its affordable to what 10% of the US or a fraction of 1% of the world.

Why would it even cost that much? You could literally use the actual chrome store for curation and make a white list of the top 100 extensions that aren't skeevy or run by skeevy people and pull in updates periodically after checking that it hadn't become obvious malware or been sold.

If you imagine that such a list would consume meager resources per person using it a million people paying 1 dollar would probably pay more than it would cost to run it. It would be easier to convince a million people to pay a dollar than it would be to convince anyone to pay a thousand per year for chrome extensions while they are using computers and OS which cost them less combined.

Re: Our Chrome Extension Is Safe

#193
post #166
post #161

So, judging from the discussion on Twitter, there is basically a single guy at Google handling issues like that. > FWIW Tweeting at other Googlers will probably just get them to me – not that I have a problem with that. At the moment there isn't really a better way, and as a single human I don't scale well. TBH we have systemic issues to work through to improve the comms process here https://twitter.com/DotProto/stat…

How does that explain: > Yeah, that's where I'm still catching up. The changes you've made look good at first blush, so I'm a little lost on the follow-up rejection. I'm going to open an appeal to get a second opinion. https://twitter.com/DotProto/status/1260623259315265538 If it's one person why would they be confused why the follow up submission was also rejected? And why would they be "appealing it" to themselves?…

Expanding the original quote for more context:

Jack: This exchange was nice to read. But why couldn't it have been initiated and had via the official channels? After a couple back and forwards with the automated responses the system should hook in a developer advocate like yourself instead of the dev having to go beg on twitter...

Simeon: I'm literally the only one for extensions. Generally speaking [Developer Advocates] aren't a super populated role

Re: Our Chrome Extension Is Safe

#194

Earlier quoted context omitted.

Which sites? Name and shame. If you absolutely must use Chromium you can use Brave instead. It doesn't solve the extensions issue discussed here but at least it cuts out most of the Google garbage.

> Which sites? Name and shame. Or even better, report them to https://webcompat.com

Netflix limits video quality on Firefox although you can trick it with an extension. Then there is the fact that hardware accelerated decoding for Linux/X11 hasn't hit yet.

https://bugzilla.mozilla.org/show_bug.cgi?id=1619523

Anyway one valid solution is to add one or more app shortcuts that effectively run chrome/chromium --app=url and collectively treat these chrome specific apps as such. Instead of opening a new tab just click the icon on your bar.

This doesn't quite handle for example links however one could use https://addons.mozilla.org/en-US/firefox/addon/open-in-chrom... to click on links and send them to chrome for known problematic sites.

This is still way better than in the early firefox/IE days.

Re: Our Chrome Extension Is Safe

#195

What happened to the iOS app? I have it, but it isn't available in the US App Store anymore, nor is it linked to from the site's page anymore. https://apps.apple.com/us/app/pushbullet/id810352052

They unpublished it after refusing to allow a "Sign in with Apple" option on their login page. https://old.reddit.com/r/PushBullet/comments/eirc1m/not_avai... The dev said the iOS side of things are irrelevant for them anyway since most of their users are on Android, which is frankly disheartening since there's no alternative for iPhone users with linux desktops now

> most of their users are on Android

To me, Android PushBullet killer feature is notification sync (though I moved to KDE Connect once it came out), so I never had any reason to install their iOS app. For iOS, only Bluetooth devices can access notifications - BTW I made a script for Linux for that: https://github.com/pzmarzly/ancs4linux

Rest of the features seem to be possible to replicate with Firefox or Chrome for iOS, plus iCloud, plus pushover.net.

Re: Our Chrome Extension Is Safe

#196

Earlier quoted context omitted.

> Which sites? Name and shame. Or even better, report them to https://webcompat.com

Netflix limits video quality on Firefox although you can trick it with an extension. Then there is the fact that hardware accelerated decoding for Linux/X11 hasn't hit yet. https://bugzilla.mozilla.org/show_bug.cgi?id=1619523 Anyway one valid solution is to add one or more app shortcuts that effectively run chrome/chromium --app=url and collectively treat these chrome specific apps as such. Instead of opening a new t…

Netflix limits video quality on Netflix and Chrome to 720p in the same way (except for ChromeOS), so I'm not sure that really fits your argument.

Re: Our Chrome Extension Is Safe

#197
post #166

Earlier quoted context omitted.

How does that explain: > Yeah, that's where I'm still catching up. The changes you've made look good at first blush, so I'm a little lost on the follow-up rejection. I'm going to open an appeal to get a second opinion. https://twitter.com/DotProto/status/1260623259315265538 If it's one person why would they be confused why the follow up submission was also rejected? And why would they be "appealing it" to themselves?…

Expanding the original quote for more context: Jack: This exchange was nice to read. But why couldn't it have been initiated and had via the official channels? After a couple back and forwards with the automated responses the system should hook in a developer advocate like yourself instead of the dev having to go beg on twitter... Simeon: I'm literally the only one for extensions. Generally speaking [Developer Advoca…

I would read that as there is only one Google Developer Advocate, but there are other (probably outsourced) moderators.

The moderation process is the one that's broken, and it's inevitable it will be because moderation processes don't scale.

Re: Our Chrome Extension Is Safe

#198

As a Firefox fan, I really hope it happens again and again. It's good for the web as a whole when Chrome fails and Firefox doesn't. As a technical person, you should be advocating the use of (real, community owned) open source browsers not just whatever the majority uses. I feel that Google's monopoly on the browser market for desktops will be more and more endangered as they (for legitimate business reasons) refuse…

Firefox's extension signing has failed in similar ways.

Re: Our Chrome Extension Is Safe

#199

I don't think this is proper use of Chrome extensions, and it hearkens back to the days of search toolbars, like the Ask and Yahoo toolbars being installed by Java. https://www.pcworld.com/article/2940688/java-installer-ditch... As a user I want my browser's extension support to be more like Visual Studio Code's than like Atom's. Visual Studio Code has fine grained permissions, and prevents extensions from going thro…

What are you talking about re VS Code?

I maintain an extension which provides a language server. I don't have to register intentions. I get the whole api and I even run a bundled executable which has full read/write/execute access to all your files...

Re: Our Chrome Extension Is Safe

#200
post #161

So, judging from the discussion on Twitter, there is basically a single guy at Google handling issues like that. > FWIW Tweeting at other Googlers will probably just get them to me – not that I have a problem with that. At the moment there isn't really a better way, and as a single human I don't scale well. TBH we have systemic issues to work through to improve the comms process here https://twitter.com/DotProto/stat…

Google has one person handling extensions for the chrome store. One person. Just needed to say this to myself and let it soak in. This very much relates to my growing thinking that I need to port stuff away from Google for good.
Post reply on HN