/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Google's Manifest V3 rules for Chrome extensions won't stop malware, but will hurt innovation, reduce capabilities, and harm performance

Electronic Frontier Foundation

Context & Ripple Effects

This EFF critique lands at the end of a long tightening cycle on Chrome's extension platform. Google first cut off inline installation from third-party sites in 2018, then in 2019 moved to limit extension access to personal data and restrict Chrome's ad blocking to enterprise users (new extension and Drive API policies; enterprise-only ad blocking), with Mozilla publicly refusing to follow Google's Manifest V3 implementation because it hinders ad blockers. The 2024 disablement of Manifest V2 extensions (starting with Beta, Dev, and Canary channels) made the transition real for developers, and the EFF's assessment now frames what that transition actually bought: per the organization, the new rules won't stop malware while hurting innovation, reducing capabilities, and harming performance.

The significance is that the security rationale for Manifest V3 is being challenged by a major digital-rights group just as the old framework is being switched off — leaving developers and users with reduced capability and no demonstrated malware benefit.

First-order effects

  • Extension developers shipping on Chrome must live within Manifest V3's reduced capabilities — with content blockers hit hardest, since Google already restricted current ad blocking to enterprise users despite negative feedback.
  • Chrome users lose functioning extensions as Manifest V2 builds are disabled channel by channel, while the EFF's analysis says the change delivers no malware protection in exchange.

Second-order effects

  • Mozilla's stated divergence from Google's Manifest V3 implementation becomes a competitive differentiator, giving Firefox a claim as the home for ad blockers and power-user extensions that Chrome can no longer run well.
  • Developers maintaining cross-browser extensions must split effort between two API models or de-scope Chrome versions, raising costs across the extension ecosystem Google's own Web Store spam rules already pressure.

Third-order effects

  • If the pattern holds, browser extensibility consolidates around whatever the dominant vendor's platform priorities allow — capability decisions justified as security set the ceiling for the whole add-on ecosystem, with rivals like Mozilla forced to choose between compatibility and capability.
  • A repeated sequence of restriction-first policy changes (inline installs, data access, ad blocking, framework retirement) points toward regulatory or antitrust scrutiny of how much control a single browser vendor exercises over its complementary developer ecosystem.

The trend: Browser vendors are trading extension capability for platform control under a security rationale, and the gap between Google's Chrome and Mozilla's Firefox is widening into the industry's main fault line for ad blocking and user-side tools.

Discussion

  • @eff @eff on x
    According to Google, Manifest V3 will improve privacy, security and performance. We fundamentally disagree. These changes won't stop malicious extensions, but *will* hurt innovation, reduce extension capabilities, and harm real world performance. https://www.eff.org/...
  • @pixeldetracking @pixeldetracking on x
    A reminder that Chrome is a Google Spyware https://twitter.com/...
  • @eff @eff on x
    Forcing all extensions to be rewritten for Google's requirements without corresponding benefits to users is a fundamentally user-hostile move by Google. https://www.eff.org/...
  • @eff @eff on x
    Chrome continues to be the only major browser without meaningful built-in tracking protection. Web extensions need more freedom to operate on their own, which means first-class access to browser APIs and persistent memory. https://www.eff.org/...
  • @pixeldetracking @pixeldetracking on x
    « If Google decides that privacy extensions can only work in one specific way, it will be permanently tipping the scales in favor of ads and trackers. » https://www.eff.org/...
  • @eff @eff on x
    We shouldn't rely on browser developers to think of all the needs of the diverse Web, and we don't have to: that's the beauty of extensions. https://www.eff.org/...
  • @pkedrosky Paul Kedrosky on x
    Google has a weird relationship with browser extensions, and it's about to get much worse. As someone who relies heavily on extensions, this is very disappointing. Google's Manifest V3 Still Hurts Privacy, Security, and Innovation https://www.eff.org/...