Hacker News new | ask | show | jobs
by dnedic 1131 days ago
Except it's open source and anyone can audit the code any time.
1 comments

If the developer's extension store account were compromised or sold, they'd push an update to you that stole your data before you could react.
You don't have to auto-update extensions.