Tightening of extension submission rules in the Chrome Web Store

Google Inc. announced regarding the tightening of extension submission rules in the Chrome Web Store. The first part of the changes relates to the Strobe project, which involved reviewing the methods used by third-party application and extension developers to access services related to a user's Google account or data on Android devices.

In addition to the previously presented new Gmail data handling rules and access restrictions to SMS and call lists for apps on Google Play, Google has announced a similar initiative for Chrome extensions. The main goal of changing the rules is to combat the practice of extensions requesting excessive permissions — currently, extensions often request the maximum possible permissions, which are not truly necessary. As a result, users become desensitized and stop paying attention to the requested permissions, creating a conducive environment for malicious extensions.

This summer, changes are planned to be made to the Chrome Web Store rules, requiring extension developers to request access only to those extended capabilities that are genuinely necessary for the stated functionality. Moreover, if several types of permissions can be used to achieve the intended purpose, the developer must utilize the permission that provides access to the least amount of data. Previously, such behavior was described as a recommendation, but it will now be converted into mandatory requirements, and extensions will not be accepted into the store if these are not met.

The situations in which extension developers are required to publish data processing rules have also been expanded. In addition to extensions that explicitly handle personal and confidential data, rules for processing personal data must also be published by extensions that handle any user content and any personal communications.

By the beginning of next year, is scheduled Google Drive API access rules are becoming stricter — users will be able to explicitly control what data can be shared and which applications can be granted access, as well as verify applications and view installed bindings.

The second part of the changes concerns protection against abuses involving the installation of unwanted extensions, which are often used for fraudulent activities. Last year, a ban was introduced on installing extensions upon request from third-party websites without going through the extension catalog. This step reduced complaints about unwanted installation of extensions by 18%. Now, there are plans to ban some other tricks used to install extensions deceitfully.

Starting July 1, extensions that are promoted using dishonest methods will begin to be removed from the catalog. In particular, extensions that use misleading interactive elements, such as deceptive activation buttons or forms that are not clearly marked as leading to the installation of an extension, will be removed. Extensions that obscure information about marketing support or try to hide their true purpose on the Chrome Web Store page will also be removed.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster