logoalt Hacker News

hvb2yesterday at 8:53 AM1 replyview on HN

I'm having a hard time finding a thread where people don't complain about npm when the real issue is packages being compromised.

Swap packages for extensions in the above and let me know how that's different


Replies

ThunderSizzleyesterday at 10:41 AM

But what's your argument? That phone-based extensions are more vulnerable somehow than desktop extensions?

If anything, wouldn't a phone extension be more sandboxed than most desktop environments?