The other side of this is the many complaints in HN threads about restrictions on what extensions can do and which ones are allowed. I can't say whether chrome's extension library strikes the right balance, but I think it's a difficult tradeoff.
Instead of just outright limiting extensions you could give users the choice. Give us an option to make it impossible for extensions to send out data for example.
Exactly. What Chrome and Firefox should do, is bundle their own analytics program into the extensions program, make these analytics available via AMO or Chrome Web Store (already has a very basic version), and remove the ability for extensions to perform outgoing network requests unless the user explicitly whitelists the extension. Even then, show big scary warnings about extensions given this permission being able to steal your bank passwords, just to keep the less tech-savvy informed.
One thing extensions commonly do is modify the page. If an extension can modify the page, it can insert an <img> which will cause a network request to happen. How do you plan to prevent this? Prevent extensions from modifying the page?
Same suggestion applies. Show users the warning that extensions can modify your page and have users explicitly approve of it.
And they already do that. The problem is, almost every extension has a legitimate need to read and/or modify the page, so people click through this permission warning like Vista's UAC.
I do notice that almost all of the extensions I use have no need to make http requests nor modify the dom (e.g. to add tracking <img> or css url()). I wonder what other methods there are to exfiltrate info beyond that.
What extensions are those?
Maybe also introduce a paranoia button where every request can be vetted in its context, so every request you get to see the code and a button permit or not.
The main issue people complain about is that it takes months for Google to review extensions and they shut down extensions randomly without giving reasons, not the amount of permissions.
A solution would be that browser maker always check what are the most popular extensions and implement those feature in browsers so you get security and performance. It is more work for the browser maker but you do it for the popular extension (if you care about your users and not about yourself - this applies to GNOME too)
Remember pdfjs? Performance will be the same.
Pdf.js is great for majority of users IMO. A good example is readability, is part of many browsers now by default so you don't have to hunt for a good and trustworthy extension.