TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Malicious extensions circumvent Google's remote code ban

30 点作者 campuscodi4 个月前

2 条评论

rasz4 个月前
On one hand yes those are malicious extensions. On the other Google policy states any code not originating from Google server is remote code, even code on my own hard drive. Its my computer and I should have ultimate choice. No amount of headers send by the server should be able to override My User Agent behavior against my will.<p>Its hard to easily reconcile those two points of view, but solution other than Google has the final say has to be found. If I wanted a nanny I would be using Apple products.
评论 #42776819 未加载
评论 #42776095 未加载
AlgebraFox4 个月前
Android apps can anytime do remote code execution. GrapheneOS even offers controls to restrict Dynamic Code Loading per app. But Google somehow cares only about RCE in browser extensions?
评论 #42783796 未加载