Comment by IshKebab

1 year ago

It's not about you being able to do whatever you want on your machine. It's extension authors being able to. Malicious Chrome extensions are a huge problem.

On the off chance that Google is truly benevolent and was just worried about users' security, then they could have easily hidden the required network-reading functionality behind a flag or "developer mode", or only allowed it for a small set of manually-audited extensions like uBlock Origin.

The fact that they provided absolutely none of these alternatives isn't a coincidence. Google is a for-profit company with 300+ billion of annual revenue, a giant chunk of which comes from their advertisement services. It's a blatant conflict of interest and there's no good reason to believe that they're acting in good faith here.

  • > then they could have easily hidden the required network-reading functionality behind a flag or "developer mode"

    For all intents and purposes, that's basically equivalent to deleting uBlock Origin for 99.9% of the 29M users it currently has.

    > only allowed it for a small set of manually-audited extensions like uBlock Origin

    That would most definitely lead to accusation of favoritism. That would be just as annoying of a pipeline to maintain.

    > The fact that they provided absolutely none of these alternatives isn't a coincidence

    They delayed the release 3 times, it was first announced in 2020. The whole time, they were taking feedback and making changes. They made a ton of changes that made MV3 adblockers possible.

  • If they really were concerned about user security, they'd do a better job blocking scammy & misleading ads instead. uBO basically _saves_ users from installing dubious Chrome extensions and other malware only because they show up as ads or other annoyances.

Don't they have a vetting process for extensions? Even if they don't, you, the (power)user should be able to manually turn on whatever you want, should you so desire. What's stunning is that we're moving away from this, for our "security." And by then "use Firefox/something else" won't be helpful when entire websites will refuse to work on anything else but Chrome.

  • > Don't they have a vetting process for extensions?

    No.

    > Even if they don't, you, the (power)user should be able to manually turn on whatever you want, should you so desire.

    It's not as simple as that. As long as it is possible for extensions to have no-holds-barred access to your browser then they'll make that a condition of use, and unsophisticated users (approximately everyone) will just say "eh ok".

    Browser extensions are a particularly dangerous case because they auto-update by default. It is very common for popular extensions to get sold to bad actors who then update them to inject ads into everything you view, or worse.

    If you make it impossible for extensions to do that, then they can no longer make it a condition of installation.

    • > It's not as simple as that. As long as it is possible for extensions to have no-holds-barred access to your browser then they'll make that a condition of use, and unsophisticated users (approximately everyone) will just say "eh ok".

      Then make it complicated enough so the user has to click through several screens, type in that they know what they're doing and be warned that if extension/website X asks them to do Y, they're getting f'd and should stop. Beyond that, it's their fault.

      Why can't we treat browsers like we used to treat PCs? Why do we have to have to make them so "safe" like we did with phones? Tons of scams happen on phones now, so it didn't quite work out, but we still gave up a lot.

      Personally, I'm rarely a Chrome user. I'm most afraid of stuff not working in non-Chromium browsers, though.

      2 replies →

  • Not really, no.

    Putting security in scare quotes doesn’t make the actual risk go away. This is a blatant anti ad block move, but you aren’t making reasonable arguments either.

    • I'm not sure how not being able to use websites without Chrome is unreasonable, though. If it hasn't come to that already, it will soon.

      One can find reasonable use cases for every security measure that takes away freedom. That doesn't mean that all such decisions are balanced, and I'm advocating that the user be the one deciding their level of security, knowingly. That's the most important part being taken away, actually. Until there's palpable resistance (or even doubt or endless debate), those taking things away have no reason to stop.

      2 replies →