Skip to main content

Google could safely bring extensions to Chrome for Android. Here's how!

When it comes to the web browser on your phone, security is the first and most important consideration. But it's still possible to safely incorporate browser extensions for Chrome.

Almost everybody uses Google Chrome for their web browser. Yeah, I know plenty of people who don't, and I have used different browsers from time to time myself, but the point still stands: Chrome is the world's leading browser across both desktop and mobile, which makes it the best Android web browser.

The biggest reason for this is that it's installed by default. If you decide you want to buy the very best Android phone, you set it up and see a Chrome icon front and center. You know immediately that the little multicolored ball is for browsing the web. But Chrome is also a decent web browser in its own right and has a good set of features and some of the best experts in the industry keeping the data you store inside the app secure. (Remember, there is a difference between security and privacy, so don't @ me!)

Many folks, myself included, have one big gripe when it comes to Chrome for Android, though: the lack of Android Chrome extensions support. There are plenty of other browsers, even ones built of the Chromium source code, that support extensions, so why can't Chrome? Google is no help because if you ask, you get the same answer the Chrome team has placed in the developer FAQ:

Chrome apps and extensions are currently not supported on Chrome for Android. We have no plans to announce at this time.

That's not very useful. We know they aren't supported, but maybe we would like to know why they are not supported.

There are two camps when it comes to why. The first is Google is afraid that uBlock Origin would kill its business model. The second is Android's permissions, and file access rules make including extensions impossible. I'm in a third camp and think both are incorrect answers.

Blocking ads in the browser can hurt the website you're visiting but has minimal effect on Google's bottom line.

Adblocking software in Chrome doesn't hurt Google on mobile. It can make life difficult for individual websites that depend on ad revenue to stay afloat. But Android is an app-driven ecosystem. Google can collect more than enough data about you and your habits through all the apps you use, so missing a bit of extra data through Chrome isn't really going to put much of a dent in Google's business.

Android's permission and file access rules are a bit of a mess, but that doesn't mean there isn't a safe way to include browser extension support. It only means there are two ways to do it — the right way and the wrong way. Most web browsers that include extensions probably do it the wrong way. I say probably because there isn't much documentation about private APIs that extensions might be using or how the extension permission model fits into Android's overall permissions. However, one company is doing it right and takes the time to fully document everything: Mozilla.

Firefox for Android isn't the best browser. I hate saying that as much as a lot of you hate hearing it, but it's true. Firefox uses its own rendering engine so things can get a little wonky, the app can be sluggish, and the settings are just as confusing as Chrome's. But Firefox does incorporate extensions safely and thoughtfully.

Browser extensions can't do anything the browser itself isn't allowed to do.

A browser extension can't act on the operating system in any way that the browser itself can't also do. That's the Android permission model at play. If you deny Firefox access to your files and folders, an extension designed to find and save memes isn't going to work because it can't access anything except Firefox's private data folders, which no other app can read. It would be like putting something in a locked box then throwing the key into the ocean.

However, a browser does ask for a pretty wide range of permissions, at least one that didn't come pre-installed. It has full admin rights (looking at you, Samsung Internet Browser) so theoretically, an extension that stays within those boundaries can work as advertised.

This isn't always the case. Plenty of Firefox extensions just won't work on the Android version, and the debug log will tell the developer that it's using an "ANDROID INCOMPATIBLE API" when it tries to run and fails. If you're a developer and are curious about which Firefox internal APIs work on Android and which don't, here's the documentation you want to read first.

The rabbit hole has been opened, though, because many extensions only run in the browser space (like an ad blocker, which is what everyone really wants), so the Android permission model doesn't come into play. Instead, these extensions use the browser's private APIs — rules and instructions that the browser, and only the browser, have to keep the house in order. This is where Mozilla and Firefox stand out.

Mozilla has its own Recommended Extensions Program that showcases extensions that it feels are worthy of your attention. Part of the requirements to be in this program are that your extension isn't trying to do anything shady and works exactly as advertised. Seeing the source code of a browser extension is easy, so checking for malicious intent is equally easy.

Not every extension in this program will work with Firefox for Android because not every Firefox API is included in Firefox for Android. Chrome is the same way — the codebase for Chrome on a Mac, a Windows PC, or a smartphone is the same. But depending on what you are building it for, the end product is slightly different.

Mozilla has a curated list of extensions for mobile users to choose from.

What Mozilla does is allow users to install compatible extensions that are part of its recommended list. It knows these extensions work as advertised and can be trusted. Maybe other browsers have a similar way of policing extensions, but Mozilla makes it really easy to find the docs about how this all works. I'm not saying Brave is bad or that Yandex is bad; I'm saying Firefox gives me the information to know how it all works.

There's no reason why Chrome for Android doesn't work the same way. In fact, it should work the same way — if Google really cares about browser security, giving Chrome users access to safe extensions would steer users away from using products that may not be as secure as Chrome. It's possible, and we can literally see a great way to do it from Mozilla.

Instead, Google goes out of it's way to make sure extensions can't work on mobile devices. It's right in the makefile if you're building Chromium for mobile:

declare_args() 
  enable_extensions = !is_android && !is_ios && !is_fuchsia

That means enable extensions unless the target is Android, iOS, or Fuchsia — so no extensions in Chrome for Google's next operating system, either. A developer building a Chromium-based web browser for Android needs to find this bit of code and alter it before they build the app if they want to include extension support on any level.

Google can safely support extensions in Chrome for Android. Why it doesn't will probably remain a mystery.

Now that we see it's possible to include extension support for Chrome on mobile securely, we're back to the question of why Google won't do it. We'll probably never know the real answer to that one. I hope it's not a loss of ad revenue because that means VPNs are next in line. Don't worry, that's not the reason and your mobile VPN client is safe.



Source: androidcentral

Popular posts from this blog

The hidden cost of food delivery

Noah Lichtenstein Contributor Share on Twitter Noah Lichtenstein is the founder and managing partner of Crossover , a diversified private technology fund backed by institutional investors, technology execs and professional athletes and entertainers. More posts by this contributor What Studying Students Teaches Us About Great Apps I’ll admit it: When it comes to food, I’m lazy. There are dozens of great dining options within a few blocks of my home, yet I still end up ordering food through delivery apps four or five times per week. With the growing coronavirus pandemic closing restaurants and consumers self-isolating, it is likely we will see a spike in food delivery much like the 20% jump China reported during the peak of its crisis. With the food delivery sector rocketing toward a projected $365 billion by the end of the decade, I’m clearly not the only one turning to delivery apps even before the pandemic hit. Thanks to technology (and VC funding) we can get a ri

Cyber Monday Canada: Last-minute deals for everyone on your list

Best Cyber Monday Canada deals: Smart Home Audio Phones, Tablets & Accessories Wearables Laptops & PC Components Amazon products Gaming Televisions Cameras Lifestyle & Kitchen Toys & Kids Cyber Monday Canada is here, and retailers are rolling out the red carpet for customers who want to shop for everything from tech to kitchenware to games and everything in between. Unlike years past, Cyber Monday Canada deals look a bit different than normal. Instead of retailers trying to pack their stores with as many shoppers as possible, we're seeing tons of online deals that you can take advantage of from the comfort of your home. We've rounded up our favorites below, so feel free to browse through the best of what Canada Cyber Monday has to offer! This list is being updated with new Cyber Monday deals all the time, so check back often. Spotlight deals It's a Switch Nintendo Switch Fortnite Edition bundle $399.95 at Amazon It's a Switch.

iPhone 13 Pro vs. iPhone 15 Pro Buyer's Guide: 50+ Differences Compared

The iPhone 15 Pro brings over 50 new features and improvements to Apple's high-end smartphones compared to the iPhone 13 Pro, which was released two years prior. This buyer's guide breaks down every major difference you should be aware of between the two generations and helps you to decide whether it's worth upgrading. The ‌iPhone 13‌ Pro debuted in 2021, introducing a brighter display with ProMotion technology for refresh rates up to 120Hz, the A15 Bionic chip, a telephoto camera with 3x optical zoom, Macro photography and photographic styles, Cinematic mode for recording videos with shallow depth of field, ProRes video recording, a 1TB storage option, and five hours of additional battery life. The ‌iPhone 13‌ Pro was discontinued upon the announcement of the iPhone 14 Pro in 2022, but it is still possible to get hold of it second-hand. Our guide helps to answer the question of how to decide which of these two iPhone models is best for you and serves as a way to c

Slack’s new integration deal with AWS could also be about tweaking Microsoft

Slack and Amazon announced a big integration late yesterday afternoon. As part of the deal, Slack will use Amazon Chime for its call feature, while reiterating its commitment to use AWS as its preferred cloud provider to run its infrastructure. At the same time, AWS has agreed to use Slack for internal communications. Make no mistake, this is a big deal as the SaaS communications tool increases its ties with AWS, but this agreement could also be about slighting Microsoft and its rival Teams product by making a deal with a cloud rival. In the past Slack CEO Stewart Butterfield has had choice words for Microsoft saying the Redmond technology giant sees his company as an “existential threat.” Whether that’s true or not — Teams is but one piece of a huge technology company — it’s impossible not to look at the deal in this context. Aligning more deeply with AWS sends a message to Microsoft, whose Azure infrastructure services compete with AWS. Butterfield didn’t say that of course