Not unless their JS has ajax calls in it. But technically yeah they could, but, it's a pretty stupid fucken idea considering it would be found out almost immediately and suddenly it has become a blacklisted addon, their reputation has been destroyed etc.
Additionally you could just not update the addon ever if you're OK with it right now.
Seems fair enough to me, so it's basically the shareware security model where any application that carries malware instantly loses its reputation, even though it is technically able to do so. Interesting to see this carried over to web apps.
Comments
Not unless their JS has ajax calls in it. But technically yeah they could, but, it's a pretty stupid fucken idea considering it would be found out almost immediately and suddenly it has become a blacklisted addon, their reputation has been destroyed etc.
Additionally you could just not update the addon ever if you're OK with it right now.
Seems fair enough to me, so it's basically the shareware security model where any application that carries malware instantly loses its reputation, even though it is technically able to do so. Interesting to see this carried over to web apps.