

The article says that is the intended use, I agree this is just bad implementation, but it’s bad because it not only allows control one way, from the app to the browser, it also allows it the other way: browser extensions with an ID that matches one of the allowed ones can access userspace, without asking. That is a huge attack surface that is installed without any consent.



He’s not a bystander though, he is encouraging racist ideas and thoughts. I see spreading hate as a bad thing, and the fact that Alex Jones or this guy got rich off it makes me actually more angry, not impressed by his hustle.