Think twice before installing Chrome extensions
securelist.com
securelist.com
The user can review some information about access permissions but so many extensions make the same plea: "i know that my extension is using lots of permissions, but it's totally safe".
Much like Windows and Android, the endless alerts about permissions and confirmations, while perhaps holding real information, end up becoming little more than noise.
Combine that with a free-fire zone where apparently little moderation or pruning occurs... it's bad news waiting to happen.
(edit: I'm a Chrome user in addition to FF and I use a lot of extensions... they are super useful, but I have serious concerns about this)
A better behavior would be selective approval. Extension asks for permissions for X, Y, and Z. You allow X and Z but deny Y. Any features affected fall back to an alternate state or are disabled. User is given clear access to control the permission states and clear feedback as to which permissions affect which features. Information about feature dependencies is available prior to install, particularly if they are arbitrary dependencies like "send us all your personal info or the software does nothing."
Is this going to happen? Probably not. Application-level firewalls help somewhat, in some cases, for expert users. Sometimes "use different software" helps, but there are many cases where that's not viable.
It may seem like a hard machine learning problem, but it seems to me that one could catch the most blatant offenders easily-- changing background colors at \.facebook.com should not require the ability to communicate with malwarehost.com or the ability to read data across all websites.
Combine this with the fact that most extensions people install are not* malicious, and you already have a decent training corpus (to treat this as a one-class classifier)
Edit: escape characters
For example, the new permissions API can be used to request permissions at runtime, rather that install time:
http://code.google.com/chrome/extensions/permissions.html
And the new webRequest API can be used by many extensions in lieu of content scripts:
http://code.google.com/chrome/extensions/webRequest.html
There's a lot more we have planned though. Personally, I would like to eventually get to a world where many extensions - in particular the ones that novice users usually see - require no warnings at all. I think that can be done by putting access to most elevated privileges behind explicit user gestures (like clicking a button or invoking a keyboard shortcut).
In general, balancing utility and security in a browser extension system turns out to be a very, um, interesting design problem. But I think we have some good, new ideas coming. Now, just need to implement them.
Do you discuss this problem space with the Android Market/Play team? It seems to have not only a lot of overlap in terms of problem domain, but likely a lot of overlap in terms of actual users.
Does anyone know how actively moderated the Chrome Extensions store is?
I know recently Google made all developers use a credit card to verify names better, but this seems more of a reactive safety measure, i.e. after lots of people get hacked, Google can provide prosecutors with information.
What color scheme does your text editor have? Is it evil and fear mongering?