lawks

joined 1 week ago
[–] lawks@aussie.zone 1 points 10 minutes ago

I'll be sure to tell my employer that my services are no longer need because some jerk on Lemmy thinks that File.readAsArrayBuffer() and SubtleCrypto.encrypt() packaged up in an extension that needs no special permissions, no companion app, and is limited to activating on a single named website, is like totally gonna scan my whole hard drive, man, what a drag.

You really are a dunce.

[–] lawks@aussie.zone 0 points 3 hours ago* (last edited 3 hours ago) (2 children)

So you don't understand that, either? When your only argument is insult, that's ad hominem. You never addressed any of the valid criticism of your fear mongering, other than to repeat the same misinformation.

You're calling me wrong because you think I'm "full of it" without being able point to anything that's factually incorrect about what I've said.

[–] lawks@aussie.zone 0 points 3 hours ago

Which don't exist unless you install them, too, which OP's extension wouldn't need. You're chronically unable to focus on the context, aren't you?

[–] lawks@aussie.zone 0 points 3 hours ago (4 children)

Sticking with the ad hominem, eh? Not the brightest choice.

[–] lawks@aussie.zone 0 points 4 hours ago (6 children)

You can call someone "full of it" and put as many cute little emojis as you like, but if you can't articulate a coherent argument about what you think they've said is factually incorrect, you may not be the brilliant bullshit detector you think you are. And repeating the insult with nothing of substance to back up the assertion just reduces your argument to ad hominem.

[–] lawks@aussie.zone 0 points 5 hours ago (2 children)

Still going. I never saw the very first edit of your content, but the bullshit is still there:

They can snoop / manipulate across tabs or even scan the local drive and execute system commands... when given the access.

Extensions cannot scan local drives, other programs that one installs in addition can. like I already explained, OP wouldn't need a companion program, so you're incapable of admitting (or maybe understanding?) that you're spreading baseless FUD about OP's proposed idea.

[–] lawks@aussie.zone 0 points 8 hours ago* (last edited 8 hours ago) (12 children)

> Says they wrote an extension 3 years ago but doesn't seem to know about decade-old isolation.
> Tries to tell everyone that extensions like OP's can run system commands, despite their use case not having any need to do so.
> Accuses others of being full of it.

Jog on, mate.

[–] lawks@aussie.zone 0 points 8 hours ago (14 children)

If you think installing a downloaded program alongside your browser is a "💩 semantic distinction" from a bit of script running inside your browsers sandboxing, then it's clear you either don't know what you're talking about, or you'd rather continue to to spread FUD than concede on basic facts.

[–] lawks@aussie.zone 0 points 8 hours ago (16 children)

I know what native messaging is, and I'm not "full of it" because native messaging does exactly nothing at all unless the user explicitly installs software at the system level to receive those messages and act upon them. If the user doesn't know the difference between installing an extension in a browser and downloading & executing local programs, that's an education problem, but having to do some separate installation step is a useful security obstacle. It's much safer compared to old school extensions.

Also, Firefox Quantum came out in 2017, which used the manifest permissions system (wasn't Chrome ahead of them?), so the tech you were originally talking about is older than 9 years, not 3.

[–] lawks@aussie.zone 4 points 8 hours ago

It seems that ignorance abounds in this post's comments. People are apparently unaware that one can write an extension that has no more privileges than a normal web page, and unlike a page, the code cannot change on every load. Your idea is good. I'd recommend not using any minification or obfuscation in the extension, and keep it as brief as is possible, for maximum transparency.

In a parallel situation, I've always been wary of hosted password managers' web interfaces like those of Lastpass, 1Password, and even Bitwarden, because one has to accept the code served at every access is clean. Ultimately, one enters their master password/secret keys, as plain text, into a web page that's difficult to audit & unlikely to be, on every view. Whereas offline/client-side encryption outside the transmission medium is far more trustworthy (e.g. KeePass).

[–] lawks@aussie.zone 0 points 9 hours ago (18 children)

When was the last time you wrote an extension? Long gone are the days when they could run system commands, and permissions must be declared in the manifest or they cannot be used, so if they aren't in there, they're not being used.

view more: next ›