5 ms·
Yes, that was their first iteration. If you think that this went any better than communicating via a local web server, well… https://palant.info/2023/01/09/touc
by palant 4y ago
Yes, that was their first iteration. If you think that this went any better than communicating via a local web server, well… https://palant.info/2023/01/09/touchen-nxkey-the-keylogging-anti-keylogger-solution/#abusing-touchen-extension-to-attack-banking-websites https://palant.info/2023/01/09/touchen-nxkey-the-keylogging-...
- xnyanta 4y agoThat isn't the fault of the native messaging host transport mechanism though. I'm just saying there are transport alternatives that are more secure than the Root CA installation nonsense the apps in your submission employ.
- palant 4y agoNeither are applications doing root CA installatin nonsense a fault of communication via a local web server. HTTPS isn’t required here, but they either have this hack in place for compatibility with decade old browsers – or they simply failed to revisit it.