• corbin@infosec.pubOP
    link
    fedilink
    arrow-up
    7
    arrow-down
    1
    ·
    1 year ago

    There are malicious extensions found in the chrome web store pretty frequently, and if I was making one, I would definitely use the API that lets me man-in-the-middle all network requests. So google’s statement that 40% or whatever of malicious extensions use that API seems plausible to me.

    You could definitely make the argument that Google should just do a better job of reviewing extensions, but that alone also wouldn’t be a 100% solution. Google definitely messed up with the original rule limits, though. If chrome is more optimized then surely it must be able to handle just as many (if not more) rules than uBO.

    • jol
      link
      fedilink
      arrow-up
      2
      ·
      1 year ago

      You could implement a permissions system that is comprehensive and granular enough to not allow random extensions to intercept network requests. Also, basically Google is then admitting their extension moderation is crap.