Hacker News new | ask | show | jobs
by Santosh83 3136 days ago
Yes, but your parent is afraid that an extension's account may be hacked. Now that going forward Mozilla will be doing only minimal manual code review on AMO, this is not an entirely fanciful concern.

We talk about reducing the attack surface of every other program out there, but funnily enough, almost no one mentions reducing the attack surface of the single program that's more exposed than almost any other to exploits: the web browser.

On the contrary we pile it with addon after addon and even the browser makers have long succumbed to feature creep.