Hacker News .hnnew | past | comments | ask | show | jobs | submitlogin

> Browser extensions up until this point have been a massive security hole

No, that's a very misleading use of the term "security hole". By that definition, every piece of software on your computer is a "massive security" risk. Heck, even Chrome itself is a massive security hole since it can see the content of every page you visit.

I think it's worth reacting strongly to this argument because it's exactly the kind of statement that muddies the waters to convincing people that they shouldn't have the option of having full control of their own devices.

And I'm not saying there haven't been huge security issues with extensions. Just as there have been massive issues with any manner of software downloaded and installed. But requiring them to be open source and needing explicit user approval before install (unlike in older IE versions) addressed those issues pretty well, imo.

Edit: I would like to see changes that make it easier to observe when an extension is active and/or communicating with third party servers and/or writing to local storage for later transmittal (if that's possible).



> By that definition, every piece of software on your computer is a "massive security" risk.

Well, yes. There’s a reason sandboxing is coming more and more to the desktop.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: