3 ms·
This is welcome news. I audit each addon/extension/plugin I download. I spotted some dodgy plugins in the past that logged traffic and sent it back to a remote
by getdavidhiggins 12y ago
This is welcome news. I audit each addon/extension/plugin I download. I spotted some dodgy plugins in the past that logged traffic and sent it back to a remote server. Not cool. Others would simply not have time to manually audit, so this news is fantastic. I learned the hard way that Firefox addons are pretty lax in terms of sandbox features. Why are plugins allowed talk to the public Internet? Such a massive security hole.
- stevenh 12y agoI know that of all the major browsers, Firefox's extension ecosystem is the most secure due to the strict rules and ruthless approval process. It's nice that they are now going even farther with it. It blows my mind that Chrome puts so much work into preventing XSS, complete with built-in reflected XSS prevention and special restrictive HTTP headers, but then turns around and gives anyone with an extension carte blanche to circumvent all of it.