Can someone give an example of what a good number would be? How many dynamic rules are currently used?
> Also, extension developers are limited in what regular expressions they can use, along with other technical limitations.
Does this meaningfully impact rules? Just curious.
> According to Firefox’s Add-on Operations Manager, most malicious extension that manage to get through the security review process, are usually interested in simply observing the conversation between your browser and whatever websites you visit. The malicious activity happens elsewhere, after the data has already been read. So in their mind, what would really help security is a more thorough review process, but that’s not something Google says it has plans for.
I don't see how one follows from the other. Attackers are using malicious extensions to eavesdrop on networks... therefore we need better reviews and not restricted APIs? I get why you might want to advocate for the latter over the former, but certainly it seems like restricting APIs also has positive impact.