Hacker News new | ask | show | jobs
by thfuran 1113 days ago
How would you allow changing page contents with a narrow permission?
1 comments

I also have a Chrome extension that needs access to page content on all pages, for the purpose of making text easier to read.

I could see distinguishing between extensions that in any way exfiltrate data from the pages you view, versus extensions that process the DOM and do something locally, but never send the data anywhere.

This requires a bit closer vetting than Google currently does, I think. To demonstrate that all processing happens locally, we encourage our users to load various websites with our extension toggled off, then go into airplane mode, and then turn our extension on. This doesn't strictly guarantee that we're not separately exfiltrating data (we aren't), but it does prove that our core process happens locally.

There are hundreds of thousands of extensions, and none of them make Google any money. Hard to see how they could justify any serious manual review.
Yeah, it could make sense for them to structure their extension framework so that developers could work with website data in a sandbox, if their use case allows for it. That would enable developers who don't need to send data to a server for processing to prove that the data never leaves the user's machine.