logoalt Hacker News

LiamPowelltoday at 12:53 AM2 repliesview on HN

Extensions never had to be given unsandboxed access to everything. That's a choice that they actively made.


Replies

getpokedagaintoday at 1:56 AM

I mean I don't think some sort of "access control" within the editor is going to really address this. People edit sensitive text in their code editor and no matter what that is going to be available to most useful extensions. Even if you don't lose a credential or get some arbitrary script running to mine crypto on your machine you could have an extension function as a key logger and exfil code you really think is valuable.

show 2 replies
wutwutwattoday at 12:58 AM

its easy to complain, words are cheap. fork it and change it if you don't like it

show 2 replies