Hacker News new | ask | show | jobs
by haburka 926 days ago
I have no clue why people are so shocked about this. Being able to run arbitrary code makes extensions nearly impossible to audit. There are so many malicious extensions out there, surely there has to be some checks on them. How else would the chrome extension store be able to prevent apps like Honey from harvesting all of your personal data?

Also, users can check one box in chrome settings in order to go around this. It’s a bit too easy to bypass IMO.