Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

there is a trick for at least chrome before 85, where if you install the google-made extension "suspicious site reporter" it will show the full url including protocol (which you can't even do with flags so it tampers with something internally which means they don't have to do this at all)


Asking a user to install "suspicious site reporter" in order to send a bug report is going to throw up a few problems.


I highly doubt a non-default extension has extra permissions that aren't available to regular extensions...

Can anyone reproduce this?


The extension ID is literally hard coded in the code of the scheme hiding code. https://source.chromium.org/chromium/chromium/src/+/master:c...


How a proprietary extension can get preferential features illustrates that chromium is open source in name only.


Hardly. If you look at firefox's source, you will find several extensions that are hard-coded for special handling. This is not new.


True, but the distance between Firefox source and Firefox is config+compile.

You cannot compile Chrome. I've heard that Chromium can be compiled and run, but I've never actually seen it, or hear of anyone using that professionally.


I'm not sure what your point is... You thought it was weird that an extension would get preferential treatment, and I pointed out that this is true for Firefox also.


My point is that you are correct.

There are other factors at play which mitigate the preferential treatment, but it's definitely there in Firefox as well.


I looked into it several months ago and it looks like that extension is whitelisted to do it. If you try to repack the crx file and install it, the address bar doesn't get changed.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: