←back to thread

424 points riffraff | 1 comments | | HN request time: 0.333s | source
Show context
bmacho ◴[] No.44345300[source]
A web extension is an unnecessary security risk. A userscript will do it just fine.

edit: one of my previous attempt: https://news.ycombinator.com/item?id=35229211

I actually have made it extensible, with closely coupled source of rules and domains; but then I lost it Edge forgot all my userscripts :(

replies(6): >>44345337 #>>44345619 #>>44345836 #>>44346890 #>>44348908 #>>44349239 #
londons_explore ◴[] No.44345337[source]
User scripts have super wide permissions. For example a user script scoped to YouTube.com can make payments from any cards you have saved in Google pay.

And most user scripts are so long a typical user won't be able to spot a couple of malicious lines amongst 10k lines of minified webpacked libraries.

replies(2): >>44345369 #>>44345394 #
bmacho ◴[] No.44345369[source]
> And most user scripts are so long a typical user won't be able to spot a couple of malicious lines amongst 10k lines of minified webpacked libraries.

Exactly!

That's why you should use 3 lines for it instead, that are

   - inspectable
   - not updateable by the Chinese/Russians
   - written by you anyway
replies(1): >>44346404 #
danielspace23[dead post] ◴[] No.44346404[source]
[flagged]
1. Muromec ◴[] No.44346845[source]
Critique and distrust of an (authoritarian) government is not racism.