Vivaldi's biggest security vulnerability: the Chrome store

    but I personally don't think it would be too great a loss if 90% of the cruft currently occupying the store were to disappear.

    And yet, this exact scenario would still have played out. That's the point. Even when you've significantly reduced users choices, and put up barriers to entry, the exact same problem exists, and you still haven't taken away the burden from the user needing to do their own research and determine whom they want to trust. Being open source, being developed by formerly trustworthy developers, etc. malware still creeps in, even in the absence of a change in ownership (see NoScript). Your 90% reduced store being safe is an illusion. The same risks still exist, and users still have to do the same work.

    Even if someone audits the code, you can never be sure they made a good enough job and didn’t overlook something. The only way to make sure an extension is 100% safe is to audit every bit of code yourself – initially and after every update. Don’t know whether you are capable of that. Anyhow, the only realistic option remaining is to forego the use of extensions and being content with the inbuilt tools Vivaldi provides.

    Exactly. And nobody is, certainly not while keeping up-to-date. It will always be on users to keep themselves aware of the third-party tools they use and determine their own level of risk vs reward, no matter what controls are put in place. Security & privacy cannot be offloaded.

  • I already made my point about making the perfect the enemy of the good. It's pointless to wear a seatbelt because you could get hit by a train or spontaneously combust. Adios.

  • And I'm saying, it's not even good. There's no benefit but the warm fuzzy feeling, users still have to do the exact same work. This exact scenario would still happen. The difference is less choice for users, and more barriers for authors. Hasta luego.

  • @BoneTone Are you deaf? I said ADIOS

    What is the way forward for Vivaldi?

    Short term: Just give the user a warning about the dangers of extensions, and the Chrome store's lack of vetting, when he brings up the Chrome store. Or something. Long term: Get a Vivaldi extension store, or collaborate with other browsers (such as Brave and Edge) to make an extension store.

  But in English, the masculine form usually doubles as the gender-neutral form

