Conversation

> App security for other platforms generally involves code analysis to see what it does, rather than denying access to APIs. But Google made a decision to restrict APIs ... oh, you would simply statically analyze the javascript to know if it's bad. intriguing
3
55
there's an appeal to the code review processes of app stores, like they're good. and then i see infosec people playing along like this is tractable
2
26
Replying to
The approach of moving to a declarative content filtering API instead of extensions using invasive access to every web page is an important improvement even if you trust the developers of the extensions. They're currently opening up weaknesses in the site isolation sandbox.
1
1
Replying to and
Exploiting an extension can be an easy way to escape from the site isolation sandbox and get control of other sites. They also introduce side channels and defeat work being done on network key isolation partitioning for connection pools, cache, etc. since they don't bother.
1
2
Replying to and
It's a given that journalists usually have a weak grasp of the subject matter and are heavily influenced by press releases and marketing. Seems particularly bad for tech journalism and especially anything to do with privacy or security. They paraphrase marketing / press releases.
1