← Back to context

Comment by pmdr

1 year ago

I think people should be able to do whatever they want on their own machine. If the setting is there, then let me use it for whatever extension I see fit. Sure, make it harder to do so, but don't treat users like children. I can't even screenshot banking apps on my own damn Android phone now.

It's not about you being able to do whatever you want on your machine. It's extension authors being able to. Malicious Chrome extensions are a huge problem.

  • On the off chance that Google is truly benevolent and was just worried about users' security, then they could have easily hidden the required network-reading functionality behind a flag or "developer mode", or only allowed it for a small set of manually-audited extensions like uBlock Origin.

    The fact that they provided absolutely none of these alternatives isn't a coincidence. Google is a for-profit company with 300+ billion of annual revenue, a giant chunk of which comes from their advertisement services. It's a blatant conflict of interest and there's no good reason to believe that they're acting in good faith here.

    • > then they could have easily hidden the required network-reading functionality behind a flag or "developer mode"

      For all intents and purposes, that's basically equivalent to deleting uBlock Origin for 99.9% of the 29M users it currently has.

      > only allowed it for a small set of manually-audited extensions like uBlock Origin

      That would most definitely lead to accusation of favoritism. That would be just as annoying of a pipeline to maintain.

      > The fact that they provided absolutely none of these alternatives isn't a coincidence

      They delayed the release 3 times, it was first announced in 2020. The whole time, they were taking feedback and making changes. They made a ton of changes that made MV3 adblockers possible.

    • If they really were concerned about user security, they'd do a better job blocking scammy & misleading ads instead. uBO basically _saves_ users from installing dubious Chrome extensions and other malware only because they show up as ads or other annoyances.

  • Don't they have a vetting process for extensions? Even if they don't, you, the (power)user should be able to manually turn on whatever you want, should you so desire. What's stunning is that we're moving away from this, for our "security." And by then "use Firefox/something else" won't be helpful when entire websites will refuse to work on anything else but Chrome.

    • > Don't they have a vetting process for extensions?

      No.

      > Even if they don't, you, the (power)user should be able to manually turn on whatever you want, should you so desire.

      It's not as simple as that. As long as it is possible for extensions to have no-holds-barred access to your browser then they'll make that a condition of use, and unsophisticated users (approximately everyone) will just say "eh ok".

      Browser extensions are a particularly dangerous case because they auto-update by default. It is very common for popular extensions to get sold to bad actors who then update them to inject ads into everything you view, or worse.

      If you make it impossible for extensions to do that, then they can no longer make it a condition of installation.

      3 replies →

    • Not really, no.

      Putting security in scare quotes doesn’t make the actual risk go away. This is a blatant anti ad block move, but you aren’t making reasonable arguments either.

      3 replies →

Do you think Firefox should let me install an unsigned extension?

  • Absolutely. I have no idea if their store requires signing, but in any case, I think you should be able to sideload your own extensions after being lectured on how it might be dangerous. I'm not saying it should be easy, though.