all 17 comments

sorted by: hot top controversial new old
[–] 44 points 2 years ago* (last edited 2 years ago) (2 children)

Or maybe only install extensions from trusted sources developers.

  • source
  • hideshow 4 child comments
  • [–] 32 points 2 years ago (1 child)

    I think the point is that even if an extension comes from a trusted source, the developer could fairly easily push out an update that turns the extension into malware. Check the GitHub link in another comment below where the developer posts the solicitation emails he gets on a regular basis offering to monetize his extension. He isn’t selling out, but maybe not every dev is as willing as he is to forgo a potentially lucrative offer.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 13 points 2 years ago (1 child)

    To be specific: from trusted developers. Installing them only from the official repository (is it still possible to reasonably install them any other way?) won't help if a dev sells such an addon. On the other hand I cannot imagine someone like Raymond Hill (the uBlock Origin dev) doing it, considering his track record.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 16 points 2 years ago

    Firefox will disable extensions in private mode if you want to

  • source
  • [–] 9 points 2 years ago* (last edited 2 years ago) (1 child)

    I think i remember a post not to far back with a similar topic. Not sure if it was from the developer of the hooverzoom extension itself, but it definitly referenced some offers they collected.

    edit: just noticed, that the article also references the offers (ref. https://github.com/extesy/hoverzoom/discussions/670 )

  • source
  • hideshow 2 child comments
  • [–] 9 points 2 years ago

    To add to the blog post, if you use user scripts, utilize your manager's blacklist and learn REGEX.

    If needed, use Group Policy, Regedit or .plists on macOS to blacklist domains to prevent an extension from running on them. As an example, I use Shutup.css to block comments online, but on something like Lemmy, I want to see comments as that's primarily how content is created and adding it to my extension domain blacklist prevents the extension from running on the website or any lemmy domains.

  • source
  • [–] 8 points 2 years ago

    It’s interesting to read as I never thought about the vulnerability these extensions are.

    I guess you should limit the number of extensions you have.

  • source
  • [–] 7 points 2 years ago (1 child)

    Exactly why most enterprise organizations disable them. You should too if you’re doing anything sensitive data.

  • source
  • hideshow 2 child comments
  • [+] 7 points 2 years ago
    [–] 4 points 2 years ago (1 child)

    I thought my ISP already had this data and is selling it. Should I go make sure all my extensions are 100% kosher?

  • source
  • hideshow 2 child comments