Are Browser Plugins a Necessary? Evil?

Are Browser Plugins a Necessary? Evil?

This weekend, I was doing a little 'housekeeping', and went through an old machine. I was looking at my Google Chrome Browser, and pulled up all the plugins. What to my surprise did I see on a VPN plug in: A red triangle with an exclamation point and the words, "This extension contains malware." ..............(Yessss the Irony is strong with this one).

My mind immediately thought several things at the same time: 

  • Who does quality/screening for plugins in the store? What does this process look like?
  • How can you know enough about my browser to feed me this warning (I am pretty sure I wouldn't have downloaded this if the warning had been there previously)?
  • What else do you know about my plugins? My browsing history?
  • Why didn't Elton John go with 'John Elton'?
  • Where's my Adderall?

So I started to review a few other plugins, and saw something that I found 'concerning'. Many/most plugins were asking for a LOT of permissions to install, so they could 'function properly'.

What exactly is 'a lot'? Well, take a look at the screenshot above from this VPN Chrome extension:

  1. Read and change all your data on the websites you visit
  2. Display notifications
  3. Manage your apps, extensions and themes

WHY would I ever give a plugin the ability to read and CHANGE my data on the sites I visit?! Or manage my other apps, extensions and themes (keep in mind that this particular plugin was supposed to keep my communications private and secure)?

The answer is.....Because apparently we don't get a choice. Any extension that interacts with websites will almost always require “Read and change all your data on the websites you visit” permission. 

Our good friends over at howtogeek.com also explained that Chrome is one of the few browsers that asks for your permission, instead of just blindly installing it.

Chrome has a permission system for its extensions, while Firefox and Internet Explorer don’t. Every Firefox and Internet Explorer extension has full access to the entire browser, and can do anything it wants.

OK...so Explorer, Firefox, all Chromium based browsers, etc. are just installing extensions without even asking me for my permission or telling me what they are able to do. Huh, good to know. Time to go dig out my Netscape 3.0 floppy disk.

So what should you do when faced with this scary warning? Theoretically, don't worry (LMAO). Any 'store' that offers browser extensions should have a screening criteria monitored by the company, and the ability to remove bad extensions. Obviously, the reality is different.

(One day, when I get around to telling how hard it was to get my Zombie Scanning App approved by the Apple Store, you'll really appreciate this irony. I was rejected several times for making false promises that the hardware was not really capable of scanning a person to see if they were a zombie. It took numerous emails to explain the history of zombies, and that they were, in fact, not real. It's a good story, but back to the show).

The 'best practice' is the usual when installing software. Ask if you really need it, is there an alternative? And is it worth the risk? May want to run some anti-virus/malware scans on your device after installing it - just to be safe.

Something to think about when you're not freaking out about all the others...




要查看或添加评论,请登录

Aaron Birnbaum的更多文章

  • OWASP API #1 BOLA

    OWASP API #1 BOLA

    I thought about doing a breakdown of the OWASP Top 10 for beginners and then thought – ‘that’s’ been done to death’…

    1 条评论
  • Job seekers Beware!

    Job seekers Beware!

    A friend of mine has been looking for a job and interviewing. He received this offer letter, which he realized was a…

    3 条评论
  • Funny Scammer Story

    Funny Scammer Story

    Surprise, there are scammers on LinkedIn! Most of them are annoying, and they always try to take you to another…

    2 条评论
  • "Find out for yourself." The Genius of Michael Crichton

    "Find out for yourself." The Genius of Michael Crichton

    “Right now, scientists are in exactly the same position as Renaissance painters, commissioned to make the portrait the…

    1 条评论
  • Making a change...again

    Making a change...again

    Note: I wanted to wait to write this, but the buzz is starting to build and I'm very excited about the addition to…

    10 条评论
  • My sister knew how to network better than the pros.

    My sister knew how to network better than the pros.

    When my sister got married, she and her husband chose a very nice wedding song by Genesis, 'Follow You, Follow Me. I…

  • Diversity - wait hear me out.

    Diversity - wait hear me out.

    Here's my problem with discussions around employment diversity: Some people (like me) don't look at a person's skin…

    9 条评论
  • Dilemma of the day:

    Dilemma of the day:

    #1 - For the record I am absolutely against the exploitation of children. #2 - I am also in favor of due process and a…

  • I'm Back...

    I'm Back...

    So, as many of my devoted, wonderful, brilliant followers may have observed. I kind of disappeared for a while.

    26 条评论
  • Using LinkedIn to SPAM and annoy people is NOT a good idea.

    Using LinkedIn to SPAM and annoy people is NOT a good idea.

    I am so tired of being invited to people that have no relationship to me, offer no benefit and take up my time reading…

    4 条评论

社区洞察

其他会员也浏览了