Post #3848384
2026-07-16 02:44 UTC
@soatok@furry.engineer @ww@xyzzy.link @hazelnoot@enby.life @DefuseSec@infosec.exchange would the extension decrypt and render in the DOM or the extension though?
Like, can malicious JS use the extension as a decryption oracle?
Replies (1)
-
@azonenberg@ioc.exchange 2026-07-16 02:45
@soatok@furry.engineer @ww@xyzzy.link @hazelnoot@enby.life @DefuseSec@infosec.exchange or is it a one way pipe, ciphertext in then both decrypted *and rendered* in the extension so the main page never sees plaintext?