Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I don't like "ecosystems" where a gatekeeper decides what we can and can't do with our own devices, browsers, etc. That's different from a software repository guarding users against malicious updates, e.g. due to compromised extension publishing account. The blast radius on extensions with permissions like that is huge, they could steal all of our session cookies and login info, for example.

My comment was a bit harsh, and that harshness wasn't aimed at authors of this extension. I'm merely asking Mozilla to be more proactive with extensions that are extremely security sensitive, but also further their own purported mission, like this one.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: