For every site you visit, there is a POST to
https://api2.poperblocker.com/view/update
which contains information about each visited page. Example of information sent in the POST (I randomly clicked on an entry in the front page of Hacker News): us=576
ver=1.0
sver=1
nid=chrome
h=e[...]6
tid=1478271585985
u=https%3A%2F%2Fthehftguy.wordpress.com%2F2016%2F11%2F01%2Fdocker-in-production-an-history-of-failure%2F&p=https%3A%2F%2Fnews.ycombinator.com%2F
rd=https%3A%2F%2Fnews.ycombinator.com%2F
ch=2
The information above is double-encoded using atob before being sent in a POST. The `h` value stays the same i each POSTs.The privacy policy of the extension used to be complete nonsense, a copy-pasta of the text found on the front page of (probably unrelated) site `whatarecookies.com`.
Looks like they changed it though[2], it is now a large image of pure-text HTML[3], which appears to be borrowed a lot from (coincidence!) WOT's own Privacy Policy's page.[4] I will assume using an image may be to purposefully make it more difficult to find out the copy-pasta.
The review I had left a few weeks ago for the extension -- in which I informed of the above -- seems to be gone.
[1] https://chrome.google.com/webstore/detail/poper-blocker/bkkb...
[2] http://www.poperblocker.com/privacy.html
For example I don't use any browser extensions because I don't have time to inspect their code after every update.
I wonder why both Google and Mozilla don't write this at the front page of their extension stores?
EDIT: I realize there are (probably) fewer authors involved there.
https://blog.mozilla.org/addons/2016/08/19/a-simpler-add-on-...
https://blog.mozilla.org/addons/2010/02/15/the-add-on-review...
All the AI experts in the world won't be able to solve the halting problem. What you're asking for is impossible.
You don't need perfect performance, you only need to stay ahead of most of the attempts. Fighting fraud is similar -- it's not possible to stop 100%, but you can get close, and try to make it easy to minimize/undo the damage done by the false negatives.
Also, many of these checks can be done by the browser in situ, so an extension that suddenly changes its behavior can be flagged for review. And pre-release malware scans can be run on banks of actual hardware that simulates different dates and locations.
Sure, there will be an arms race, but that's better than an anarchical free for all.