Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Most users will click straight through the approval though, like when they granted it full permissions at install.

And is the signing actually effective anyway? There's very little mention of it online, and as far as I can see it isn't covered in the official guide for publishing extensions.

Is it even possible to have proper signing keys stored locally or air-gapped?



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: