Kinda off-topic: with enough eyes all bugs are shallow, but does that really help when Google prefers playing whack-a-mole to doing the right thing?
Kinda off-topic: with enough eyes all bugs are shallow, but does that really help when Google prefers playing whack-a-mole to doing the right thing?
Alert people that they should rotate their passwords?
The last one is so crucial. Had I not read that LWN post, I would never have noticed that the extension didn't just run adware fraud but also snooped passwords. Seriously, fuck Google and their disgusting zero communication attitude.
It can't be fixed without crippling the system. You can't sandbox permissions because the most basic and useful tools require full access to every website.
The only way I can think of is having all extension developers required to have their identity verified and from a country that follows some common law so that google can take legal action against malware developers.
I shouldn't be forced to run someone else's code to look at a publication. That's the entire point behind using something as ugly as XML (or it's simplified child, HTML) to begin with: this is supposed to be a document markup language. A method of annotating what an author would _like_ to have happen when rendering the data.
I seriously loath the fetish of creating pixel perfect displays which treat the end user as an actively hostile element; a passive consumer, rather than someone empowered to use the data for their own enlightenment in the manor their preferences prefer. (Font size, screen reader, dark / light mode, etc)
It's not really the same issue.
If you are visiting a site that uses its own JavaScript, you can probably assume that if it's run by someone trustworthy, the script isn't going to try stealing your passwords or credit card number. There shouldn't be any reason for the web page to have access to anything that you're not providing it with anyway.
A browser extension (like an ad blocker) can access the content on every page you visit. That could be your bank, email account, social media - anything. If you have a malicious browser extension, it can see everything you do.
A man can dream, I guess.
Gentoo has a nice system, "Gentoo Linux Security Advisories", where you can periodically run a program called glsa-check which lets you know if you have packages installed that have security problems, what the problems are, and points to more info (like CVEs). You can even have it upgrade stuff on its own if you don't want to think about it. Something like this would be a nice feature for browser extensions.