4 ms·
> Note: obfuscation is a red flag And why is this? Unless the extension source is already public, I don't see any reason why anyone would not use obfuscation
by gnaman 6y ago
> Note: obfuscation is a red flag
And why is this? Unless the extension source is already public, I don't see any reason why anyone would not use obfuscation
- unethical_ban 6y agoThere is no reason /to/ use obfuscation in good faith if the code is open source.
- megous 6y agoI've found extensions doing malicious things that were not obfuscated, by inspecting the code. Obfuscated code is just not worth installing at all. Too much work, for little benefit, to review it, when alternatives exist.
- tobylane 6y agoThen it’s a sign that they haven’t open sourced their extension, which is a red flag. Minification may be acceptable though pointless.
- blindm 6y agoNote: Obfuscation is NOT the same as minification, and I don't mean minification when using the word obfuscation!
- eyelidlessness 6y agoMinification isn’t necessarily pointless, depending on the tooling used. While the JS doesn’t have a wire cost, it does have a parsing and execution cost. Optimizing compilers like (say) Google Closure Compiler can significantly improve runtime cost, which is definitely a benefit for extension users. That said, any extension using those tools without source code available and build verification should definitely be viewed with suspicion.
- blindm 6y ago> And why is this? I'm not saying all obfuscation is necessarily bad, just something to look out for if you're trying to sleuth around for malicious intent by the addon's author. Typically if you want to hide the fact you are collecting the browsing secrets of the addon's user, you would use some form of obfuscation (in order to have the addon in good standing by Mozilla and to stop a simple sweep by people like myself who first look for things like http:/https: in the source). Note: Obfuscation is NOT the same as minification, and I don't mean minification when using the word obfuscation!