3 ms·
TFA is a github page, friend. If you truly care about compromise as stated, just build the add-on from source. No reason to point to nonexistent future threat v
by _underfl0w_ 6y ago
TFA is a github page, friend. If you truly care about compromise as stated, just build the add-on from source. No reason to point to nonexistent future threat vectors.
- michaelmrose 6y agoDo you remember Stylish? It was a very popular firefox/chrome addon with 2 million users which was sold to an ad company that started using it to siphon off users data. https://arstechnica.com/information-technology/2018/07/stylish-extension-with-2m-downloads-banished-for-tracking-every-site-visit/ https://arstechnica.com/information-technology/2018/07/styli... The threat isn't nonexistent and having the source doesn't help as much as you might imagine. Most people can't read the source in any meaningful way and those that can might still trivially miss something malicious. In practice its only as safe as the meaningful analysis by skilled hands makes it in actuality. Realistically you would be lucky if someone notices several months after it started siphoning off your data and only if its egregious enough to get it kicked off of the extensions store.