Your Browser Extensions Are Probably Spying on You — Let's Fix That
Open your browser right now and count how many extensions are sitting in your toolbar. If you're like most people, there are somewhere between three and fifteen little icons up there, a bunch of which you installed years ago and haven't thought about since. Some you use daily. Some you couldn't even name without hovering over them.
Here's the uncomfortable truth: browser extensions are one of the most overlooked attack surfaces in everyday computing. They sit between you and everything you do online — every site you visit, every form you fill out, every purchase you make. And a significant chunk of them are monetizing that access in ways most users would find pretty alarming.
We spent a few weeks going deep on this — reading privacy policies, checking permissions, and poking around in the extension stores — so here's the honest picture.
Why Extensions Are Such a Privacy Risk
When you install a browser extension and click "Add to Chrome" (or Firefox, or Edge), you're usually greeted with a permissions dialog that most people dismiss without reading. Those permissions are not ceremonial. They're real access grants.
"Read and change all your data on the websites you visit" — that's the big one. It sounds scary because it is scary. An extension with that permission can technically see every page you load, every form you type into, and every click you make. It can inject content into pages, redirect links, and harvest data. Most extensions that request this permission have legitimate reasons for needing it. But some absolutely do not, and the dialog doesn't tell you the difference.
The business model problem is real, too. Extensions are hard to monetize. Developers build something useful and free, get a bunch of installs, and then eventually need to make money somehow. The options are: charge for it (most users won't pay), show ads (annoying), or sell the data they're collecting (lucrative and invisible). That third option has led to some genuinely gross situations — including extensions with millions of users quietly logging browsing history and selling it to data brokers.
In 2023 and into 2024, security researchers have flagged multiple extensions on the Chrome Web Store that were doing exactly this, sometimes for years before getting pulled. The store's vetting process is better than it used to be, but it's not airtight.
The Red Flags to Watch For
Before you install anything new, here's what should give you pause:
Permissions that don't match the function. A color picker extension doesn't need to read your data on all websites. A coupon finder does need broad access — but you should decide if that trade-off is worth it to you.
No clear business model. If an extension is free, has no premium tier, and doesn't explain how it makes money, that's a flag. Developers need to eat. If you can't figure out how they're doing it, the product might be you.
Vague or missing privacy policies. Legitimate extensions, especially ones with meaningful permissions, should have a clear privacy policy. If there isn't one, or it's three sentences that say nothing, walk away.
Extensions you didn't intentionally install. Some software bundles browser extensions as part of their install process, often with opt-out checkboxes that are easy to miss. Do a regular audit of what's in your browser.
Ownership changes. An extension you've trusted for years can get sold to a new company — one with very different intentions. There's no automatic notification when this happens. It's worth periodically checking if the developer behind your favorite extension is still the original team.
Extensions We Actually Trust (And Use)
Okay, enough doom. There are genuinely great extensions out there, built by reputable teams with clear purposes. Here are the ones we feel comfortable recommending:
uBlock Origin — The gold standard for ad and tracker blocking. It's open source, has been independently audited, and the developer (Raymond Hill) has a long, transparent track record. The permissions it requests are broad but necessary for what it does, and the code is there for anyone to inspect. This is the one extension we'd call genuinely essential.
Bitwarden — If you use Bitwarden as your password manager (and you should be using some password manager), the browser extension is well-built and trustworthy. Open source, with a solid security track record. The permissions are significant, but the function requires them.
1Password (extension) — Same category as Bitwarden. If you're in the 1Password ecosystem, the extension is solid. Paid product with a transparent business model — they make money from subscriptions, not your data.
Privacy Badger — Built by the Electronic Frontier Foundation (EFF), which is about as credible a non-profit as you'll find in the digital rights space. It learns to block invisible trackers as you browse. No sketchy business model, clear mission.
Dark Reader — A genuinely useful dark mode extension for sites that don't have one built in. It's open source and has been around long enough to have a strong community track record. Permissions are broad, but it's one of the more trustworthy examples of an extension that legitimately needs them.
Extensions We'd Approach With Caution
We're not going to name-and-shame specific products, but here are categories worth being skeptical about:
Coupon and cashback extensions — Tools like Honey and similar services are extremely popular, but they require sweeping access to your browsing to function. The business model involves affiliate commissions and data. Some users are fine with that trade-off; others aren't. Just go in with eyes open.
Free VPN extensions — A VPN extension is not a real VPN, first of all. It only routes browser traffic, not your whole connection. And many free VPN extensions have troubling privacy records. If you want a VPN, pay for a reputable standalone service.
PDF tools and converters — This category is littered with low-quality or outright malicious extensions. Many request full browsing data access with no credible reason to need it. Use a desktop tool or a trusted web service instead.
Doing a Quick Extension Audit
Here's a five-minute exercise worth doing today: open your extensions manager (chrome://extensions in Chrome, about:addons in Firefox), go through each one, and ask yourself three questions: Do I still use this? Do I know who made it? Do the permissions make sense for what it does?
Anything you can't answer confidently — remove it. Extensions you haven't used in six months are just risk with no upside. You can always reinstall something if you miss it.
The goal isn't to strip your browser down to nothing. Extensions genuinely make browsing better when they're the right ones. It's just worth being intentional about what you're inviting into your digital life — and occasionally checking whether it's still behaving itself.