Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The latter poses some security problems, though, which the native messaging API avoids (e.g. random websites being able to connect to the native application and pretending to be your extension).


When random websites connect to your application, you can (and should) inspect Referer header and filter out unwanted ones.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: