You're right about me being a security nut. But I don't think it is unwarranted to be paranoid about letting an extension have those permissions. Especially when the extension can auto update without my permission. There's no way for me to stop the extension from updating in the options.
You viewed the source code, but the extension checks for an update every couple hours and updates itself. You might trust the developer to not do anything bad, or not accidentally leak his private key for the extension. The only way to stop it from updating itself is to go to the manifest file and removing the update url.
I'm tired of the anti-security comments that come up against people commenting about bad security practices, even though they're restrictive and paranoid. This is the case when you need to be paranoid. A quick google search give me this[1]
Ever let someone's code have access to everything on every webpage, including all of your financial and personal ones you use? Well you're doing it right now. The only way I'd be okay with letting extensions access and change contents of webpages if they specify the website url they're going to access, and those are the only websites they can access (Reddit Enhancement Suite does this)
I appreciate the developer's time on this and don't mean to disparage their effort. But, how many developers are you going to keep trusting this way? You can't normalize every extension having those permissions! Read and change, not just read all websites.
You know enough to look for the source and check it out. But what about the users who don't know how to do so or can't read code? Even if they can, can they discern malicious code from harmless code? Will you say the same thing you said to me to a user with no understanding of how these things work?
I'd actually love to know how you got to the source code in three clicks. Wish it was that easy to view an extension's source other than digging through the chrome internal data folders.
And I don't think cargo culting is the correct term, or bike shedding. I'd say something to do with tin foil hats would be more appropriate.
[1]: https://arstechnica.com/security/2015/04/google-kills-200-ad...