Skip to content

Comment on Show HN: Run unknown shell script with a line-by-line confirmation promptparent

Comments

I think the most realistic threat model right now is "subverted browser extension", which is effectively equivalent to internet-wide XSS. Luckily I've only been hit once, and with adware, but it's a risk.

A browser extension is not a threat model, I'm not sure what you mean.

Browser extensions are an attack surface, examination of which is a key aspect of threat modeling.

It depends on whether or not your threat model includes threats likely to exploit this attack surface. I'm assuming this is why GP said that a browser extension isn't a threat model.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.