Chrome 25 to disable silent extension installation actively and retroactively
thenextweb.com
thenextweb.com
https://blog.mozilla.org/addons/2011/08/11/strengthening-use...
In principle, given Chrome is often installed as the current user, there is nothing to stop any other user program from changing Chrome in any way it sees fit, simply adding an extension and marking it "user accepted" in whatever way.
Microsoft has had trouble with this kind of thing for years, as I say.
Because of this, stopping sideloading is all about delicate balancing of incentives. "Carrots and sticks" so to speak.
We want to make it easy and effective for people to do the good thing (carrots), and hard and dangerous enough to dissuade them from doing bad things (sticks).
Previously our approach was to provide easy APIs [1] to install extensions into Chrome that we controlled. The result was that the Chrome team could monitor usage and see if it got out of hand.
Unfortunately, as Chrome became more popular, it did in fact get out of hand. So what you see here is us basically adding a few sticks, trying to reduce overall bad behavior. (We're also working on other things in other areas so that we don't just push the bad behavior into harder to monitor channels).
[1] http://developer.chrome.com/extensions/external_extensions.h...
Also, where do you store the blacklist? Remember that the bad guy can just modify it to remove his entry. Or he can modify Chrome itself to not check the blacklist.
There are a long series of escalations you may propose here (encrypt the profile, try to detect changes, store the profile on the server, add a developer key system, etc). I'm just going to summarize and say there is no perfect solution to this problem. You can make bad behavior somewhat harder, but you cannot eliminate it without true application isolation.
At each escalation you increase the complexity of the product, make genuine features harder to introduce, add bugs, and make the experience for legitimate developers worse. It's a challenging environment to write software in.
That said, the team has some pretty clever ideas in development for future releases. We fight on.
this looks like a proper (if a bit delayed) measure to me.
Wow. Version numbers are a joke these days.
This is blocking the sort of extensions that get installed with other desktop software. So, like, for whatever god damn reason Microsoft thinks it needs to install Office addons into Firefox when I install Office. That wouldn't fly in Chrome now.
There aren't really plugins for JS apps though there are obviously WinRT specific APIs and some CSS models that are only implemented in IE...
ActiveX failed back when Microsoft had a monopoly on practically all end-user systems. Now, with Android devices and iPads and Mac laptops some people actually use and so on, how well could it possibly work these days?
http://en.wikipedia.org/wiki/MediaWiki:Abusefilter-warning-s...
Administrators on the English Wikipedia set up a filter to simply block edits which were tainted by that bug.
According to the article, it is still possible to package extensions with a software installer, but now when the user runs their browser they will be asked to confirm that they want the extensions to be added.
So it isn't really blocking those extensions, which I think is a good thing.
As someone else commented below, Firefox has blocked this for a while now. So this will no longer fly in any major desktop browser (except perhaps IE, but in your example it's made by the same company installing the addon ;)