Hacker News new | ask | show | jobs
by jhdias 535 days ago
We read the source code.
3 comments

I suggest looking into the Obfusicated C contest before relying on your own reading of code to verify lack of malicious intent.
Then it auto-updates.
I highly recommend turning off auto updates on browser extensions.
Then we blindly trust that someone else is still reading the new version’s code and will raise the alarm if something bad happens.
There's no source provided in the repo? It seems to just be a discussion of how to download the xpi from somewhere else.