Extension is really just another web page with more system privileges than normal web pages. It can communicate with servers and peek your current webpage’s data without your permission. From this perspective it’s less secure than a normal webpage.
The narrative on Nostr is if you centralize your private key risk to a single extension that you trust, then you don’t have to trust individual Nostr clients. Meaning you still need to pick one extension that you trust. Extensions are not intrinsically safer.
Thank you; that makes sense. Those extended permissions are why I’ve still never put my primary nsec anywhere besides the client I generated it within. And I only add extensions to a browser other than the one I use for day to day use.
Appreciate the thoughtful reply 🙏
You are welcome and your secuirty awareness is very good.
Thread collapsed
Thread collapsed