[tor-talk] Download Helper

Lunar lunar at torproject.org
Sun Jan 5 23:44:58 UTC 2014


Olivier Cornu:
> I haven't checked the project in the last couple years, yet in the past GM
> had to deal with significant security issues.
> As so many projects it grew from a few hacks and ended much wider than ever
> intended, with the usual design and coding scars. But the main obstacle was
> that it introduced a new level of privilege between embedded javascript and
> chrome code, which was not intended to exist in firefox and impossible to
> enforce in pure javascript. It was long the case that, although relatively
> safe when used properly, it could quickly be used in unsafe ways -- even in
> good faith.

Thanks for raising these aspects I did not consider earlier on. :)

-- 
Lunar                                             <lunar at torproject.org>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 836 bytes
Desc: Digital signature
URL: <http://lists.torproject.org/pipermail/tor-talk/attachments/20140106/f7af8250/attachment.sig>


More information about the tor-talk mailing list