• Kangae_Hishiryo@scribe.disroot.org
    link
    fedilink
    English
    arrow-up
    1
    ·
    20 hours ago

    Handing third-party extensions blanket permissions to inspect and modify live plaintext traffic across all tabs creates a massive MITM exfiltration surface. Moving rule matching to declarativeNetRequest enforces least privilege by executing filters in the native engine without exposing sensitive network payloads to extension code.

    You’re doing a false equivalence here.

    It’s not about blanket permission vs. almost no permissions.

    You can have granular ACLs (which are being hindered by MV3), or OCap/CapSec, or even other security and permissions approaches.

    They’re or incompetent or malevolous, these are the only two options left when you think a bit about it.