Andromxda 🇺🇦🇵🇸🇹🇼@lemmy.dbzer0.com to Technology@beehaw.orgEnglish · edit-22 months agoGoogle Chrome ships a default, hidden extension that allows code on *.google.com access to private APIs, including your current CPU usagefedi.simonwillison.netexternal-linkmessage-square13fedilinkarrow-up1199arrow-down10file-textcross-posted to: technology@lemmy.world
arrow-up1199arrow-down1external-linkGoogle Chrome ships a default, hidden extension that allows code on *.google.com access to private APIs, including your current CPU usagefedi.simonwillison.netAndromxda 🇺🇦🇵🇸🇹🇼@lemmy.dbzer0.com to Technology@beehaw.orgEnglish · edit-22 months agomessage-square13fedilinkfile-textcross-posted to: technology@lemmy.world
minus-squareabbadon420@lemm.eelinkfedilinkarrow-up13·2 months agoHere’s the plan. You write an extension for chrome that makes chrome think all traffic from [cryptominingcentral.com] is actually from *.google.com. Make folks install the plugin via the tried and tested methods like phishing. … profit
minus-squareauthorinthedark@lemmy.sdf.orglinkfedilinkEnglisharrow-up13·2 months agocouldn’t you do that anyway if you can get people to install an extension? taking advantage of this for crypto mining purposes feels like extra steps
Here’s the plan. You write an extension for chrome that makes chrome think all traffic from [cryptominingcentral.com] is actually from *.google.com. Make folks install the plugin via the tried and tested methods like phishing. … profit
couldn’t you do that anyway if you can get people to install an extension? taking advantage of this for crypto mining purposes feels like extra steps