Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I love the idea but giving "root access" to an extension that's "not monitored for security" is a non-starter. I wish Mozilla would step in and do something good for a change.


Would you like an "ecosystem" where you can't publish anything that the gatekeeper doesn't like?

I believe there's one over there <looks at Apple>.


I don't like "ecosystems" where a gatekeeper decides what we can and can't do with our own devices, browsers, etc. That's different from a software repository guarding users against malicious updates, e.g. due to compromised extension publishing account. The blast radius on extensions with permissions like that is huge, they could steal all of our session cookies and login info, for example.

My comment was a bit harsh, and that harshness wasn't aimed at authors of this extension. I'm merely asking Mozilla to be more proactive with extensions that are extremely security sensitive, but also further their own purported mission, like this one.


Check out this feature from Firefox then: https://bugzilla.mozilla.org/show_bug.cgi?id=1783015 Apparently can be turned on with the following:

cookiebanners.service.mode = 1 cookiebanners.service.mode.privateBrowsing = 1 cookiebanners.ui.desktop.enabled = true




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: