15 votes

The Great Suspender and the problem of malware being introduced into open-source browser extensions

3 comments

  1. skybrian
    Link
    A partial fix would be for the browser vendors to build extensions directly from Github (or other repo host), based on release tags. This would ensure that that the code that users are running...

    A partial fix would be for the browser vendors to build extensions directly from Github (or other repo host), based on release tags. This would ensure that that the code that users are running matches the source. (Along with how Manifest V3 forbids running remotely downloaded JavaScript.)

    It would add transparency, but the ownership issue would get pushed one step back. Who gets to approve changes and tag releases? This power could also be sold.

    10 votes
  2. [2]
    iii
    Link
    If you need an alternative, I hear that The Marvellous Suspender is a fork before the malware was inserted. I do use Auto Tab Discard though instead. The Great Suspender is still in the...

    If you need an alternative, I hear that The Marvellous Suspender is a fork before the malware was inserted.

    I do use Auto Tab Discard though instead.

    The Great Suspender is still in the recommended sidebar I was gonna make a pull request to remove it, but found out that edits should be made through the site. Anyway we can get that removed? Although It isn't that big of a deal since The Great Suspender has already been removed on the chrome store.

    4 votes
    1. cfabbro
      Link Parent
      Done. Thanks for pointing it out.

      Anyway we can get that removed?

      Done. Thanks for pointing it out.

      2 votes