Google did it again.

  • orclev@lemmy.world
    link
    fedilink
    English
    arrow-up
    4
    ·
    1 year ago

    Hmm, not having read up on the tech, what’s stopping someone from making a Firefox plugin that just spoofs fake data back? It’s all done client side if I’m understanding, so everything necessary to do so must be available. Only wrinkle I could see is if they have signing and ship the cert with Chrome and regularly rotate it. It’s still not impossible in that case, just more annoying.

    • underisk@lemmy.ml
      link
      fedilink
      English
      arrow-up
      2
      ·
      1 year ago

      My understanding is vague but the sandbox environment is cryptographically integrity checked in some fashion that makes the spoofing you’re suggesting difficult or impossible.