4 ms·
I think the most realistic threat model right now is "subverted browser extension", which is effectively equivalent to internet-wide XSS. Luckily I've only bee
by ipsin 5y ago
I think the most realistic threat model right now is "subverted browser extension", which is effectively equivalent to internet-wide XSS. Luckily I've only been hit once, and with adware, but it's a risk.
- junon 5y agoA browser extension is not a threat model, I'm not sure what you mean.
- klyrs 5y agoBrowser extensions are an attack surface, examination of which is a key aspect of threat modeling.
- krageon 5y agoIt depends on whether or not your threat model includes threats likely to exploit this attack surface. I'm assuming this is why GP said that a browser extension isn't a threat model.