Yeah... so I absolutely agree that browser extensions are a fairly large security risk, and that many of them monetize through unethical means.
That said - The title as written is just complete bullshit.
If the developers are taking monetization offers and injecting code in response - the developers are fucking spying on you. There's not some malicious way to monetize an upstanding developer's extension.
Really - the title is bad enough I'd consider pulling this... It's just lying to get clicks.
I see the some people did not get point and thought it's a clickbate, so i've update post to explain the developer can be a bad engineer who failed to detect a scam and this is the potential problem of any extension.
You may think you can detect any scam, but scam may be targeted and complex
It's not that I didn't get the point, it's that the point is not interesting or worthy of the title.
Anyone developing software who takes cash money to inject code they have not reviewed (or worse is remotely hosted and subject to change - although at least this is getting removed with manifest v3...) is actively participating in screwing over their users.
Shoving your fingers in your ears and going "nah nah nah, I can't see it so I don't know" is bullshit. You took cash... to add code. You are actively complicit.
Comments
Yeah... so I absolutely agree that browser extensions are a fairly large security risk, and that many of them monetize through unethical means.
That said - The title as written is just complete bullshit.
If the developers are taking monetization offers and injecting code in response - the developers are fucking spying on you. There's not some malicious way to monetize an upstanding developer's extension.
Really - the title is bad enough I'd consider pulling this... It's just lying to get clicks.
I see the some people did not get point and thought it's a clickbate, so i've update post to explain the developer can be a bad engineer who failed to detect a scam and this is the potential problem of any extension.
You may think you can detect any scam, but scam may be targeted and complex
It's not that I didn't get the point, it's that the point is not interesting or worthy of the title.
Anyone developing software who takes cash money to inject code they have not reviewed (or worse is remotely hosted and subject to change - although at least this is getting removed with manifest v3...) is actively participating in screwing over their users.
Shoving your fingers in your ears and going "nah nah nah, I can't see it so I don't know" is bullshit. You took cash... to add code. You are actively complicit.