Skip to content

Comment on Chrome.userScripts API requires developer mode

Comments

I have no clue why people are so shocked about this. Being able to run arbitrary code makes extensions nearly impossible to audit. There are so many malicious extensions out there, surely there has to be some checks on them. How else would the chrome extension store be able to prevent apps like Honey from harvesting all of your personal data?

Also, users can check one box in chrome settings in order to go around this. It’s a bit too easy to bypass IMO.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.