4 ms·
You can't protect the users this way: the attacker will create a custom Chromium build and lure the user to download and execute it. At that point the user will
by syntern 13y ago
You can't protect the users this way: the attacker will create a custom Chromium build and lure the user to download and execute it. At that point the user will be pawned either way.
- chrisrhoden 13y agoIf you're getting a user to download and execute a piece of software, why bother going beyond that?
- awj 13y agoThat's a ridiculous argument. If the attacker could do that why would they even bother with XSS attacks based on developer tools?
- aboodman 13y agoThe argument would be that the custom build of Chrome (or other malicious software) is harder to create, but not so much harder so as to be not worth doing for the attacker.