Virustotal Scan Browser Extension to Prevent Malicious extension Installs!


Virustotal Scan Browser Extension to Prevent Malicious extension Installs. Require the Use of VirusTotal (https://www.virustotal.com/gui/home/upload ) to scan browser extensions before installation to prevent malicious or infected extensions from being installed !!

I am honestly confused by what you are asking, I don’t even know where to begin.

You mean your idea is to make VirusTotal website as a built-in extension partnered under Brave available as a button somewhere in the menu? This idea is good for iOS, Android, and Computers,

But at what cost… Im not sure if Brave pals are ready to ask to shake hand with someone as the devs/managers of VirusTotal, cuz - they are still a big corporation.

But i dont know anything deep about VirusTotal, so its even less to add about, yet i technically understand the mention.

Being able to Scan all browser extensions with anti virus /anti malware program “VirusTotal” before installing them into your browser !! Do you not understand browser extensions can contain viruses and malware and backdoors encoded into them ??

I understand that, but I did not understand how you asked it.

But if you’re going to be rude, I’m going to step away. Good luck though.

@CANADA_EH1

My view > GitHub member ‘chewybone’ is correct:

https://github.com/brave/brave-browser/issues/7200#issuecomment-3787902813

There should be a Brave Browser setting, so the user can Allow / Deny extension updates.

Otherwise, the user is responsiible for policing the extension safety issues.

This would mean automatically uploading potentially sensitive files to VirusTotal, a service which makes all submitted files/URLs publicly available. Not sure this should be in a privacy focused browser.

If you are asking for ONLY browser extensions to be scanned right as they are downloaded so no sensitive personal information is sent, well I’d kind of argue that’s a suggestion better suited for the Chrome Webstore, since that’s where Brave get their extensions from.

In addition to my above point, I saw many news articles about malicious browser extensions and the problem seems to be more so that there is a malicious update pushed to a otherwise safe extension, so that limits the effectiveness of only scanning at first download, because either you risk submitting personal information or risk not actually making it effective since the malicious update is only downloaded later.

So overall I don’t think this could be implemented properly. However, I really like that there are users actually thinking about how Brave’s security against phishing/malware could be improved further. Even though this suggestion has some problems, this is a good starting point and shows that there is an actual demand for better security not just in Brave but in all browsers.