Even in Web3, the Rule Is “Convenience Uber Alles”
twitter.com
twitter.com
Now you gave the MetaMask devs control over all your future browsing sessions. Your bank account, your emails (if you use a webmailer like gmail), your social media ...
You trust them to a) not ever have a malicious dev on board or a dev who forgets to take their medicine. And b) they will never make a mistake so someone can get malicious code into your MetaMask instance or take it over via a security bug.
Why aren't content access permissions for extensions domain based?
You either have to grant access to all sites, grant access to a predefined list of sites, or not install the extension.
I want certain extensions to only have access to certain sites that I get to decide because it is my computer.