logoalt Hacker News

b112yesterday at 9:28 PM3 repliesview on HN

Maybe, but how long are the extension ids? And if they are random, how long to scan a trillion random alphanumeric ids, to find matches?

I presume the extension knows when it wants to access resources of its own. But random javascript, doesn't.


Replies

maples37yesterday at 9:35 PM

The extension IDs are UUIDs/GUIDs, so 128 bits of entropy. No site is going to be able to successfully scan that full range.

show 2 replies