Now extensions are a "security threat". Here we go...
Google has nigh-on monopoly power over the browser ecosystem. Also, extensions are by-and-large malware. Making people aware that extensions are mostly malware helps Google to consolidate its monopoly; but also (obviously) helps people to avoid malware.
We don't want Google to control the Internet, and we don't want browsers to be full of malware. That's a dilemma. It has no obvious solution. But it's better to be aware of the dilemma — and so realize there is no easy solution — than to ignorantly push for one side or the other to "win."
Google could be educating users to make their own responsible decisions, but it's far more profitable to keep them uninformed and feed them propaganda to maintain the paranoia that lets it monetise and take control away from them. Being ultimately an ad company, it thrives on deception.
and so realize there is no easy solution — than to ignorantly push for one side or the other to "win."
Twenty years ago, what Apple Google Microsoft do today with their software would be widely considered adware/spyware. One side has already won the battle; we can't let it win the war.
"Give me liberty or give me death," as the famous saying goes.
The solution doesn't necessitate removing extensions, it just means potentially constraining the API surface of extensions in order to mitigate the attack surface.
Extension users do want the extensions to interact with pages, often including cross-origin requests. That is what extensions are for and they won't work with restricting API surface.
Why wouldn't this same idea apply to any other extension? You are right, everything is potential malware (the two extensions you mentioned included). There is nothing magical about the two extensions you mentioned.
And 1000s of eyeballs are on those works.
When is the last time you checked out the UBO Git?
That's actually the complete list of plugins I have, uBlock Origin, Privacy Badger, SponsorBlock and RES.
Every extension you install should be carefully vetted and only enabled as long as absolutely necessary. It's the top malware vector I see today.
Also, not all extensions run on every single site. Also, some extensions actually help in blocking malware, crypto-trackers etc so the potential upsides are also great.
This is not where I want computing to go, and we're all just playing cat-and-mouse games feigning "security" when really "we" just don't trust the "plebs" to administer their own machines and keep themselves safe. This is arguably where Android is already, so one need only look there to see the future of computing and how the browser and "security" is being used as a trojan horse to get there.
If you go to the average non-technical user's Chrome extensions tab, they have 10-12 extensions. 7 of them are actively malicious.
This isn't like a "hey, freedom allows you the freedom to make mistakes" thing. This is a "good practice hasn't even been attempted here, and it's the top vector of all bad things ever" thing.
It's fine for browser extensions to exist, they serve a purpose. However, all existing extension stores should probably delist the entirety of their collection, solely re-accept extensions which an actual software engineer has reviewed, and make it much harder than one click to inadvertently install one when a website asks you to.