Skip to content

Comment on Think Twice Before Installing Any Chrome Extensionparent

Comments

That really is the least they should be doing. For contrast, here's Mozilla's policy for addons.mozilla.org: https://addons.mozilla.org/en-US/developers/docs/policies/re...

Chrome supposedly has a better security model (not to say that FF's is bad), but if it gets in the way so much that users are in the habit of allowing all extensions access to everything, then it's not really better.

And specifically, Mozilla's review process includes a "No Surprises" principle that covers cases like this one:

https://blog.mozilla.com/addons/2009/05/01/no-surprises/

"Changes to default home page and search preferences, as well as settings of other installed add-ons, must be related to the core functionality of the add-on. If this relation can be established, you must adhere to the following requirements when making changes to these settings: The add-on description must clearly state what changes the add-on makes. All changes must be ‘opt-in’, meaning the user must take non-default action to enact the change. Uninstalling the add-on restores the user’s original settings if they were changed."

Some things that could be improved upon is better sandbox. Too many extensions seems to need my data on all sites. Maybe some extensions could work just as well with a copy of the DOM instead of the DOM itself?

And a policy that extensions must not be minified and some buttons on the extension view to read the source code with syntax highlighting and all.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.