Earlier quoted context omitted.
Seems like a very juicy target. These extensions should not store any data without a master password that you input every time. What if someone stole the signing key, and submitted an update to Chrome store, even for a little? Oh wait that is only for Chrome Apps. For extensions, they can literally update themselves anytime. Someone would just have to steal the certificate. If an extension that reads all data uses a…
>Oh wait that is only for Chrome Apps. For extensions, they can literally update themselves anytime. Someone would just have to steal the certificate. Mozilla reviews signed extension updates. Something tells me uBO is one of the most scrutinized given how very many users it has. >If an extension that reads all data uses a CDN (like CloudFlare) that CDN can execute a MITM attack against it and download new code, that…
I have seen Metamask update itself randomly, and it has access to read every website