Time to check if you ran any of these malicious Chrome extensions
arstechnica.com
arstechnica.com
If you train your developers that you are willing to unilaterally and suddenly disable published extensions for editorial, non-security-related reasons (which the article's screenshots indicate was the excuse) - and that it's completely expected that such an action might occur on Christmas, and a well-founded one based on history - that's a poor developer experience.
And on top of that, if Google has the ability for an OAuth app to get extension upload permissions, without screaming as part of the OAuth authorization process "This will provide third parties unrelated to Google the ability to update extensions. Be sure that this is intended." - then that is bad OAuth design that exacerbates the above problem.
If you're designing a software supply chain, and you have a choice to allow updates over API, the onus is on you to either ensure your authentication UX causes spear phishing targets to think twice before they let themselves get pwned. And I get that there are certainly different teams working on the OAuth frontend and the Chrome Web Store backend - but if the backend team doesn't have the willpower and/or ability to have red-teamed this exact spear phishing situation, and have escalated their security concerns to the frontend team, that's an organizational failure.
> GraphQL Network Inspector
It's been fully patched since: https://github.com/warrenday/graphql-network-inspector/issue...
Amazing.
Which is why you shouldn't use them.
Installed programs are the weakest link in the security of an OS like windows - should users not use programs? Users are just as likely to download a sketchy program as a sketchy extension, is that not even more severe of a risk?
User education and better marketplace policing are the solution, not silly blanket statements like that.
I agree with this however that would limit just about all software unless it has been properly and deeply inspected by people paid to do just this. If I go through the project pages of all the software that comes with Linux I know I will not find code reviews at each artifact release version that has been reviewed by the NCC group, Google project zero, etc... FWIW it could be said that most of the software in use today is untrusted in that regard, even the most commonly used browsers. Some may think browsers have so many eyes on them that a subtle weakness could not be introduced but I also disagree with that. A more widely used application is an even bigger juicy delicious target for nation state actors to get employed and introduce multiple subtle changes that work in conjunction with one another and OS design flaws. I would wager that every browser has malicious actors either contributing subtle weaknesses or possibly sleeping until they are given orders.
What do you think - what is more risky: a) manual update (and risk of 0day attacks) or b) auto-update (and risk supply-chain attacks)?