Another day, another Google cull: Chocolate Factory axes 49 malicious Chrome extensions from web store

Sandtitz

Re: Just a naive idea

"Surely apps should have a limited set of domains they can talk to, set up in some manifest."

How would that help?

The anonymous perps would just use meaningless domain names or S3 buckets for data transfer - listed in the manifest.

