Or if you have 2FA enabled for sends, just intercept the send POST with an address of your choice, but display the user's originally input address on the confirmation screen. To make it even more confusing, keep a list of transactions:intended accounts so any time the user looks on _any_ bitcoin site it shows the transaction was going to the right account.
Also, two extensions come in handy: "Chrome extension source viewer" [1] and "Extensions Update Notifier" [2] (self-descriptive titles). The second one can automatically disable extensions when they're updated.
They're honestly a little annoying if you have more than a handful of extensions since they lack some essential features (e.g. viewing a code diff from the previous version), but at least they're open source! :)
[1]: https://chrome.google.com/webstore/detail/chrome-extension-s...
[2]: https://chrome.google.com/webstore/detail/extensions-update-...
(there are other conclusions one could reach from this, such as the disadvantages of being your own uninsured bank)
And his SSH key had both the username and hostname set to that alias ("frosty@frosty"), which is how they connected him to Silk Road.
Specifically, it was this question: https://stackoverflow.com/questions/15445285/how-can-i-conne...
Things that could go wrong:
* The author could wake up in a bad mood one day and decide to push a malicious update.
* The author's computer could be compromised, and someone could steal the signing keys and publish a malicious version of the extension.
* The author could get bored of the extension and transfer ownership to someone who offers to maintain it for them, but who turns out to be malicious.
* The author could be in need of some cash and could decide to accept one of the many offers they no doubt get from shady parties to buy their extension.
I'm sure the author of this extension would never do any of these things... but I'm not sure enough to risk it. :/
The only way to find out is to run the extension in Chrome and inspect it with the debugger.
Firefox also had to learn about the vulnerability of Firefox extensions the hard way, but training users to scrutinize permissions would be a great opportunity.
It's also on the list of issues to fix: https://github.com/thebaer/MMRA/issues/15
It is sadly true that most extensions which do anything useful end up needing to request permission to all web sites. And that's why I mostly refuse to use extensions...