Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Except they, naturally, found that all this sandboxing was a tad too restrictive, and ended up adding Apple-esque exceptions for their own code.

And in doing so, a critical vulnerability:

https://www.mozilla.org/en-US/security/advisories/mfsa2015-7...



They are not "Apple-esque exceptions for their own code". All JS code running as browser extensions have those permissions.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: