Q: Is there any reason to be concerned with Chrome extensions?
One of the many reasons that Google’s Chrome browser has become the most popular browser in the world includes the ability to add new functionality through extensions. The vast majority of the more than 180,000 available extensions at the Chrome Web Store are free, making them very popular with web browsers.
How extensions can be dangerous
A browser is your window to the online world and, despite all the security that Google has built into Chrome, allowing anything into your browser can potentially allow others to monitor everything you’re doing or modify what you’ll actually see as you’re surfing the web.
Google, as well as all the other browser companies, have created processes to scan and review extensions before they become available, but they’ll never be able to catch everything, so it’s always “downloader beware.”
Thankfully, the instances of truly malicious browser extensions is rare, and when Google detects that an extension has become malicious, it automatically disables its use on all Chrome browsers.
Good extensions gone bad
Since a large number of extension developers are individuals or small companies, if they get hacked or decide to sell their code to a third party, what the extension actually does can start to change.
Google recently tightened their guidelines for extension developers, making it more difficult for hidden code to sneak by their review process.
Steps to evaluate extensions
There’s no simple way to validate an extension, but there are several steps you can take to help you feel more comfortable with the developer before deciding to install it.
Look to see what version it is, which indicates how long the extension has been around — the higher the version number, the longer it has been around.
Look to see how many users have installed the extension and how many reviews it has, then read some of the reviews. If either of these numbers are very low, you should be very cautious.
I’d also check out the developer to see if it’s someone you have heard of — this is done by clicking on the name next to the “Offered By” just below the name of the extension.
Is the developer an individual or a company? Do they reside in a foreign country that’s known to be an adversary of the U. S.? Have they created other extensions? Can you find them on social media?
If you feel comfortable after reviewing everything, the final step is pay attention to what the app says it can do when you click on the “Add to Chrome” button. If you don’t like what you read, you can simply click on “Cancel.”
Get the urge to purge
If you’re not actively using an extension, it’s always best to remove it. You can see and remove any of your extensions by typing chrome://extensions where you would typically type in a web address.