Skip to content

Find a generic way to disable extensions on security critical websites (e.g. banks) #2

@karlicoss

Description

@karlicoss

Since extension is sending urls to the backend, it's potentially not secure to do so on websites like banks. While extension supports blacklisting it's not really great to rely on user to do so.

Perhaps some of these lists https://github.com/cbuijs/shallalist would be a good start, unclear how often is it updated though.

Also need to add a UI explanation if the link is blacklisted; and an option to whitelist urls from the 'default' lists in case user really really wants it.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestsecuritySecurity/privacy critical things

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions