On Tue, Jul 22, 2014 at 4:47 AM, Aymeric Vitte <[email protected]>
wrote:

> Indeed extensions can be mitmed as easily as js code


Browser extensions are digitally signed by their authors, so no, they are
in no way as vulnerable to a MitM attack as JS served over plaintext HTTP:

https://security.stackexchange.com/questions/34412/signing-a-browser-extension


> the big difference is that it's easy for any skilled js people to check
> what is doing the js code


As pointed out with your 400kB wad of JS, that's not true, but probably
beside the point...

while it can be difficult for extensions I believe.
>

Extensions provide an alternative way to package HTML/JS which allows for
digital signatures of the entire archive, so no, it's really just a more
secure way of distributing the same thing.

You should be using a browser extension for Peersm, not some web page
served over plaintext HTTP.

-- 
Tony Arcieri
-- 
Liberationtech is public & archives are searchable on Google. Violations of 
list guidelines will get you moderated: 
https://mailman.stanford.edu/mailman/listinfo/liberationtech. Unsubscribe, 
change to digest, or change password by emailing moderator at 
[email protected].

Reply via email to