HomeSecurityGoogle: Strengthens user data protection, with new rules on...

Google: Strengthens user data protection with new rules for Chrome extensions

GoogleAs part of a general effort to enhance the security and protection of its users, Google announced that it will implement some new rules that will concern Chrome extensions, Google Drive APIs, and third-party applications that access Drive.

The move is part of a broader initiative by Google to protect user data. This initiative is called Project Strobe and was launched after the discovery of a bug in Google+ that exposed the personal information of about 500,000 users.

Essentially, with Project Strobe, Google is trying to limit the amount of data that third-party applications have access to through Google services and tools.

So, Google announced that it will implement two new rules that will apply to Chrome.

The first rule relates to the permissions that Chrome extensions request in order to install. Extensions usually request access to various data.

“We require extensions to only request access to the data that is necessary to implement their functionality,” Google said. If they need access to more than one category of data, they should be as few as possible.

Google has already advised developers to use this approach when building their extensions, but now it's requiring it across the entire Chrome Web Store.

The company will review all extensions before they are released, and if it finds a problem or something that violates the new rules, it will notify developersto fix it. Corrections to the permissions they request from users can be made within 90 days. If the necessary corrections are not made, the extensions will be removed from the Web Store.

The goal is to put a stop to the permissions requested by developers that give them access to a large amount of data. This is because there are malicious hackers who exploit this and can deceive users and misuse personal information.

Privacy Policies

The second rule that Google wants to enforce will concern privacy policies. All extensions that handle “personal communications and user-provided content” will have to have a privacy policy that describes exactly how the extension developer handles and stores the data that has been collected.

Until now, the company required extensions that handle personal and sensitive user data to publish their privacy policies. “Now, we’re expanding this category to include extensions that handle personal communications and user-provided content,” Google said.

The new rules will go into effect in the fall. Google will provide more details about the new rules over the summer so developers have time to prepare their updates.

New rules for the DRIVE API as well

New rules will also apply to the Google Drive API and third-party applications that access Drive.

The goal is to limit which apps can have broad access to user data through the Drive APIs. Only “certain types” of apps will have full access to a user’s Drive account.

With the new rules, users will be able to choose which personal filesa third-party app can access.

Google did not provide further information about the types of apps that will be able to access the files, but said it would notify developers whose apps do not fit the new rules so they can make changes.

This rule is very similar to the one Google implemented on Gmail last October, which limited the types of apps that could access a user's Inbox.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS