Live data from Hacker News

Google enforcing Web store only extensions for Chrome

sites.google.com

41–50 of 84 posts

Re: Google enforcing Web store only extensions for Chrome

#41
post #7

> Why couldn’t this problem be solved by having a setting/option to load extensions that are not hosted in the Chrome Web Store? Unlike modern mobile operating systems, Windows does not sandbox applications. Hence we wouldn’t be able to differentiate between a user opting in to this setting versus a malicious native app overriding the user’s setting. Sounds a bit BS to me. In what reasonable threat model the attacker…

Because it is BS. The drag and drop "security feature" for external extensions was more than enough to protect against the vast majority of "evil extensions" (which I believe was a small amount to begin with, and Google never even bothered to show us any numbers behind these "scary external extensions that are totally going to destroy the world if we don't do this", before they even implemented the drag and drop rest…

W3C doesn't dictate what features browsers have or do not have, they're concerned with web standards. The MPAA joined to make sure DRM showed up in HTML5, not to tell Google to take out ad blockers.

If Google removes ad blockers it will be because Google's revenue is based on ads, not because the MPAA or the W3C told them to.

Re: Google enforcing Web store only extensions for Chrome

#42
Does anyone know how this is supposed to protect users against AdWare and other bad extensions? I mean these are installed along other applications with a setup program anyway. Can't the installer just activate developer mode?

I guess there is a warning that shows up, but people will just ignore it (and once you've clicked through the UAC prompt the installer can do anything anyway, like hide the warning). And there is also the enterprise mode, can't the malicious installer just use that?

Re: Google enforcing Web store only extensions for Chrome

#43
post #28

If you want to keep any extensions that you didn't install from Web Store, use the dev channel[1] of Chrome and they will work just fine. I use an extension and they warned me one month back to either install their Web Store version will fewer functionality or move to dev channel. [1] http://www.chromium.org/getting-involved/dev-channel

Or just use a browser that doesn't restrict what you can do to it. Like Firefox.

Firefox isn't that much better.

Re: Google enforcing Web store only extensions for Chrome

#44

Earlier quoted context omitted.

I doubt this is the reason. The reason is that less-educated users are being tricked into installing extensions they don't want and that make using their computer miserable for them. Meanwhile, anyone that wants to write their own extension need only click a checkbox.

But how does this protect against bad extensions? I mean they are installed along other programs as AdWare anyway, can't they just install themselves in developer or enterpise mode?

I assume this interacts with Windows in some way to make that more difficult, but I don't use Windows much so I don't know. According to the docs, the change doesn't apply to Linux or OS X.

Re: Google enforcing Web store only extensions for Chrome

#45
post #21

Following the same rationale, downloading of executables via Chrome should be restricted to those from Google approved publishers only.

Note that downloading of executables via Chrome is mostly already restricted to those from Microsoft- or Apple-approved publishers, because of SmartScreen/Gatekeeper. (And Linux has a culture of looking for things in package management before hunting down an executable on the web, so you basically get the same effect there through convention.)

>Microsoft- or Apple-approved publishers, because of SmartScreen/Gatekeeper.

and the ones not found suspicious by Google's safe scan.[1] I remember once Chrome not letting me download a new version of Light table because it was found suspicious. Actually it will let you download it but will delet it as soon as it is done downloaded.

[1]http://www.nbcnews.com/id/46330156/ns/technology_and_science...

Re: Google enforcing Web store only extensions for Chrome

#46
post #41

Earlier quoted context omitted.

Because it is BS. The drag and drop "security feature" for external extensions was more than enough to protect against the vast majority of "evil extensions" (which I believe was a small amount to begin with, and Google never even bothered to show us any numbers behind these "scary external extensions that are totally going to destroy the world if we don't do this", before they even implemented the drag and drop rest…

W3C doesn't dictate what features browsers have or do not have, they're concerned with web standards. The MPAA joined to make sure DRM showed up in HTML5, not to tell Google to take out ad blockers. If Google removes ad blockers it will be because Google's revenue is based on ads, not because the MPAA or the W3C told them to.

I think that's a little naive. Google sells Hollywood movies and tv shows in their Play store.

Re: Google enforcing Web store only extensions for Chrome

#47
Yep, this is the last straw for me. The final drop of water that overflowed the cup.

I'm switching back to Firefox and will make a conscious decision to start deleting all my Google data. The tin foil conspiracy theorists were right all along it seems, I'll do my best to support companies that fight for my privacy and are open source.

Firefox, I'm sorry I ever left you - happy to be back.

Re: Google enforcing Web store only extensions for Chrome

#48

Yep, this is the last straw for me. The final drop of water that overflowed the cup. I'm switching back to Firefox and will make a conscious decision to start deleting all my Google data. The tin foil conspiracy theorists were right all along it seems, I'll do my best to support companies that fight for my privacy and are open source. Firefox, I'm sorry I ever left you - happy to be back.

You'll be back man. Trust me. I've tried numerous times to go back to FF, but you enjoy the speed + ridiculous amount of available popular snooping extensions more than anything.

I know you're in a different state of mind atm, but you will be back to Chrome within a couple weeks.

Re: Google enforcing Web store only extensions for Chrome

#49

Yep, this is the last straw for me. The final drop of water that overflowed the cup. I'm switching back to Firefox and will make a conscious decision to start deleting all my Google data. The tin foil conspiracy theorists were right all along it seems, I'll do my best to support companies that fight for my privacy and are open source. Firefox, I'm sorry I ever left you - happy to be back.

Install Chromium. It's chrome without the spyware.

https://download-chromium.appspot.com/

Re: Google enforcing Web store only extensions for Chrome

#50
post #33

Earlier quoted context omitted.

Google, Apple and MS, sure, but that's just Linux's gain. Yes, the "Year Of The Linux Desktop" joke is as funny as ever, but I definitely foresee a split in computing into passive consumers with no idea how things work and hackers who need full access to the things they own and want to experiment, learn and create.

I'm not sure Apple and Microsoft fit that bill yet. They divide their empires into three separate concerns: walled garden consumer devices (phones, tablets), open enterprise/desktop and media. it's pretty easy to get into the internals of OSX and Windows still. In fact it's been made easier over the years. I can still push apps to our customers on Windows and Mac desktops like I could in 1993. Google on the other han…

I can still push apps to our customers on Windows and Mac desktops like I could in 1993.

Well, on OS X, you'd better have a $99/year developer program account or you cannot sign software. For most users it's a hasse to either disable Gatekeeper or to discover Ctrl/right-click to circumvent it.

Of course, signing software is good. But I'd rather like to accept/verify a key on a vendor-basis and have that used to validate updates. E.g. APT with GPG signing does this pretty well and makes installing signed software via e.g. Ubuntu's PPAs pretty nice.

Linux (and FreeBSD possibly!) will never hit the desktop hard

I agree. And this is why it is important that organisations such as Mozilla and CyanogenMod exist and are well-funded. As long as they keep up with their counterparts, people and vendors will have a choice.

Post reply on HN