I think the problem could be solved by modifying the UI in the browser in such a way that you don't allow the webpage to create a similar popup because there would be a visual barrier that clearly indicates when the popup is part of the browser itself and when it's not.
To install a chrome extension you have manually install it by clicking "ok", even after that if it accesses your private browsing data (which is the only thing Chrome extension has access to) you will get a second warning, making sure you understand this. Even after that, Chrome extension runs on its own process, seperate from each tabs (which runs in its own process). And each of those process runs on its own sandbox.
Lets even leave all that out of consideration, and that javascript is being used by some very popular websites, includeing huffpo, independent and some random sites I encountered but don't remember right now.
The guy from DS is just crying fowl.
I filed a related bug a year ago at Mozilla: https://bugzilla.mozilla.org/show_bug.cgi?id=497388 but it didn't get anyone busy (no offense). We probably have to wait until browser extensions are more common place and these kind of UI vulnerabilities get exploited on a regular basis.
Thanks in advance for any answer.
I'm not buying this feigned innocence. It's like listening to Zynga say giving Farmville credits for users to sign up for trial offers is perfectly legitimate. They know perfectly well the revenue generated by getting thousands of users to sign up for free trials of stuff that is impossible to stop before the bill gets charged to your card is generating more money than legitimate ads/networks.
You're using illegitimate ad networks because it pays a higher CPM period. Just admit to it so we can blackhole your domain without bullshitting us.
And no, we didn't review the javascript bar that was placed at the top of all our pages but as soon as we saw what it looked like, we removed it.
And what illegitimate ad networks?? We use Google Adwords and Federated Media!
Don't go making accusations like that until you've got your facts straight.
And seriously, where did you get such distrust and anger? Ridiculous.
Separate issue then, the 'Next Article' module that flys-in on the bottom of the page has a huge resemblance to that of the NYT:
http://web9.twitpic.com/img/129290515-1749ba53a25d83649eeb9b...
The idea/functionality is one thing, but the design elements seem to be a direct lift (border, shading, text language and style).
It's got a new look now, whadya think? :)
Can I just say again, how impressed I am at how quickly you responded to all this and took appropriate measures. I could see this locked up in processes and such for days at other organizations.
Wasn't there even an IE6 hack that spoofed "this browser has critical updates" and updated the browser to IE7?