Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

In the end, you have to trust the browser.

google chrome sends all my pages to translation and what-not. I have to completely trust it. that's why i never use the compiled version but the chromium one only (hence not having access to any addon via the addon site, have to do some manual work there)

Even besides the browser, how many computers don't I see the skype button next to phone numbers? would you trust skype is behaving and not sending your data to their servers? did you remember to disable this add-on for ssl pages?



You're conflating different issues.

A browser based on an open-source codebase with many people auditing its source-code and network traffic (there was much paranoia about Chrome when it was released). And even in that case, you have the choice to use a completely open-source browser that has a different stance on user privacy (Firefox).

An NPAPI plugin that can be easily disabled.

A third-party BOX MITM all your secure connections without your knowledge.

I don't think the above are comparable in magnitude.


You're right--the third is the worst by far. And this proves that you can't trust a pre-installed, commercial browser until it has been thoroughly audited by independent researchers.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: