On Tue, Jul 22, 2014 at 4:47 AM, Aymeric Vitte <[email protected]> wrote:
> Indeed extensions can be mitmed as easily as js code Browser extensions are digitally signed by their authors, so no, they are in no way as vulnerable to a MitM attack as JS served over plaintext HTTP: https://security.stackexchange.com/questions/34412/signing-a-browser-extension > the big difference is that it's easy for any skilled js people to check > what is doing the js code As pointed out with your 400kB wad of JS, that's not true, but probably beside the point... while it can be difficult for extensions I believe. > Extensions provide an alternative way to package HTML/JS which allows for digital signatures of the entire archive, so no, it's really just a more secure way of distributing the same thing. You should be using a browser extension for Peersm, not some web page served over plaintext HTTP. -- Tony Arcieri
-- Liberationtech is public & archives are searchable on Google. Violations of list guidelines will get you moderated: https://mailman.stanford.edu/mailman/listinfo/liberationtech. Unsubscribe, change to digest, or change password by emailing moderator at [email protected].
