-
Notifications
You must be signed in to change notification settings - Fork 18
Description
So, your marketing website lists Edward Snowden himself as as example of somebody who might be using this add-on. Therefore I'm assuming you claim protection against an adversary who could potentially get websites such as facebook.com to do their bidding.
As far as I can tell this extension does everything via content scripts that share the DOM context with the surrounding webpage, has the user type their messages into the same DOM structure Facebook has access to, and even stores the encryption key in a DOM attribute.
What's to stop a Facebook employee subpoenaed by a government (or just any evil employee) from adding a little extra function to the chat part at facebook.com to grab and store your messages as you're typing them before they get encrypted, or just steal the entire encryption key?