Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Except the add on can inject js into webpages that you have open and let the page make connections outside the extension sandbox.


Also it’s pretty easy to just proxy requests through a whitelisted server side site so https://good.com is all that shows but it requests good.com?dest=https://evil.com


Calling a website good.com doesn't make it good. A site with open redirects is a bad site.


Is that why Mozilla is blocking all addons on mobile (except for the selected 11)? They need to fix that shit or start adding useful features to Firefox... Not sure why they arent blocking all extensions on desktop too if they are so bad though.


They're already bleeding market share badly to the Chromium family, and doing that would be quite a thick nail to their popularity coffin...


Ah, that’s clearly a big issue. Never mind.




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: