Skip to main content

This is a refreshingly good look at why extensions with both full privileged access and dynamic script + style execution are a really bad idea, greatly weakening the CSP on every site:

How insecure is Avast Secure Browser?

Injecting arbitrary scripts and styles ought to require an extra permission and be selectively allowed on a per-site basis.

How insecure is Avast Secure Browser? - Almost Secure:

in reply to Seirdy

As for how my stance on privileged extensions interacts with adblocking:

A layered approach to content blocking

This entry was edited (2 months ago)
in reply to Seirdy

@Seirdy sticking my fingers firmly in my ears and rotating every element on your site 1deg