タグ

Jetpackとsecurityに関するmollifierのブックマーク (6)

  • Toolness

    Over the past several years, I’d been watching educational YouTube videos while on an elliptical in a gym. During the pandemic, however, gyms closed down, and I had to figure out what to do. Late last year I bought a cheap exercise bike that I’m actually very satisfied with. Instead of watching videos on my phone or tablet, I can just roll my bike in front of my computer monitor and watch whatever

    mollifier
    mollifier 2009/07/29
    ざっと読んだ
  • Jetpackのセキュリティ性(続報 その2) - hogehoge @teramako

    Jetpackのセキュリティ性(続報)の続き 進展があったのでご報告。 https://bugzilla.mozilla.org/show_bug.cgi?id=494779 開発者であるAtulさんが昨日書き込んでいて、 開発版(trunk)ではChrome特権なしで動くようになっている ブログに実装の背景を書くよ Jetpackの次のバージョンから有効になるよ って感じの報告を書いてくれている(と思う。誤読があるかも) そういえばセキュリティとは関係ないけど、バグからみで長いオブジェクト名は省略してしまえ! ってか?のコメント欄でid:nanto_viさんが書き込んでいくれている内容をbugzillaに報告したほうが良いのかなと思っている。

    Jetpackのセキュリティ性(続報 その2) - hogehoge @teramako
    mollifier
    mollifier 2009/07/25
    "開発版(trunk)ではChrome特権なしで動くようになっている" "ブログに実装の背景を書くよ" -- 読みたい
  • JetpackとGreasemonkeyが似ていると言われる件 - hogehoge @teramako

    たしかに両者は似ているところもあるのだが... 正直、僕はそんなに似ていると言いたくない。何か誤解を与えそうで怖いからだ。 いろいろと書く前に言葉の定義 Jetpack 拡張体 Greasemonkey 拡張体 JetpackScript Jetpackのエンジンで動作するスクリプト UserScript(ユーザスクリプト) Greasemonkeyのエンジンで動作するスクリプト 似ているところ Jetpack, Greasemonkey どちらも拡張機能であること どちらもスクリプトのエンジンであること JetpackScript, UserScript インストール/アンインストールにFirefox自体の再起動が必要ない JavaScriptで記述 制限を緩和するためのAPIがある 値を保持するためのAPI クロスサイトなXMLHttpRequest 似てないところ Jetpack

    JetpackとGreasemonkeyが似ていると言われる件 - hogehoge @teramako
    mollifier
    mollifier 2009/06/02
    "とりあえず、僕としては今のところ他人のJetpackScriptをインストールすることをお勧めしない" -- まあGreasemonkeyも昔はアレだったわけで、今後に期待。今は人柱用か
  • Jetpackのセキュリティ性(続報) - hogehoge @teramako

    Jetpackのセキュリティ性の続き どうも待っているのは性に合わないようで、バグ登録してみた https://bugzilla.mozilla.org/show_bug.cgi?id=494779 *1 Jetpackのセキュリティ性で挙げた、XPCOMが利用可能なことに対する言及し、 do not require write access to the file system do not require Places access Labs/Extensions2/Target Add-ons - MozillaWiki に違反しているのでは? という内容だ(少なくともそのつもりで書いた。拙い英語なので分かりにくいかもしれないが。) 対して、プロダクト・リーダーのAza Raskinさん*2から返答があり、 最初は制限をとても強くして開発していたが、当初はJetpackAPI実装する

    Jetpackのセキュリティ性(続報) - hogehoge @teramako
    mollifier
    mollifier 2009/05/26
    "最終的にはXPCOMは使えなくなると思われる" -- 興味深い
  • Jetpackのセキュリティ性 - hogehoge @teramako

    Mozilla Jetpackについて調べたいことの続き。 Secure Provides access to only the privileges needed, with security issues always be presented in social-terms, and not technical-terms Short and easy to review code ensures that potential security issues are shallow, and review times short Mozilla Labs Jetpack | Exploring new ways to extend and personalize the Web とのことだが、しかし、穴があるのではないかと思った。 XPCOMの使用が可能 Componentsへのアク

    Jetpackのセキュリティ性 - hogehoge @teramako
    mollifier
    mollifier 2009/05/22
    どんどん問題提起していけば良いと思う。まだ立ち上がったばっかりのプロジェクトだし。
  • 1