Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Well we're in a thread about the CLI being compromised. I've never heard of a sandboxed browser extension being compromised.


You don't need to compromise the extension but that sure is another drawback of installing more software than actually needed. You could exploit the password manager extension from inside the browser and that way get access to the password manager since you created a direct path to it weakening the otherwise strong browser security.

The browser should stay isolated and seperate from anything on the device instead of integrating "dog doors" in the software with the no1 biggest attack surface of any modern device.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: