but you can't. See the last part of my comment: "they can inject arbitrary scripts into pages to make requests for them".
>either way, if it is not a solvable problem, there is a major problem in the design.
Not really. It's like complaining that debuggers can impersonate programs they attach themselves to.
disallow that behavior?
You could also just pull that code but it might change based on request origin...
That's irrelevant. If you can make changes to the page, you can exfiltrate data. The security model for addons isn't designed with restricting an addon's network activity in mind, see my other post: https://news.ycombinator.com/item?id=25623281
This ends up effect as magically determining where it’ll call, with a lot less work.
And this was Google Play verified with a million downloads.
this addon connects to:
* https://484044b296.execute-api.us-east-1.amazonaws.comIt doesn't have to be as overt making it look like a proxy (eg. a endpoint that makes arbitrary http requests on behalf of the caller). It can be as simple as changing the endpoint for the spying service from https://evil.example.com/api/ to https://484044b296.execute-api.us-east-1.amazonaws.com/evil/...
> Some more investigation would be required in some cases.
The point is that the "nutrition facts label" doesn't really do anything because it's trivial to bypass. If it becomes widespread I guarantee every malicious addon maker would adopt this tactic.
One might not like Google analytics, but at least you know exactly what you’re going to get when someone calls analytics.google.com.
Is it even possible or would the sandbox prevent such an extension from functioning?
I wish I could block per-app connections on Linux like Little Snitch appear to allow on Mac.
However, if you allow everything to 80/443, the extensions would still be able to connect to their servers. Maybe the browsers should add the ability to allow/deny connections per extension.
https://github.com/gustavo-iniguez-goya/opensnitch/issues/21
Great idea!