Did you know attackers can inject extensions into your employee machines in even of a compromise of their account? Look into controlling this in Edge and Chrome.
Comments
Log in with your Bluesky account to leave a comment
A chrome extension is basically a root kit if it has certain permissions.
Lots of modern apps use tokens that are stored in local storage and or included in the headers. An extension can just read those things as if it was a part of the app.
I'm still deeply disturbed that more than 20yrs after we all realized how dangerous browser extensions are, we still do not have a security framework standard for browsers to better sandbox them.
Comments
Lots of modern apps use tokens that are stored in local storage and or included in the headers. An extension can just read those things as if it was a part of the app.
Useful for good… scary if abused.
The internet is full of horrors, and security is an emotion.
https://wink.messengergeek.com/uploads/default/original/3X/5/8/58a4dcedb7328dd7f85eecebf37c38b9dcdabd1f.jpeg
I kept my Limewire tidy 🤌