DEV Community

Discussion on: What browser extensions do you use?

 
alexcavazos profile image
Alex Cavazos

It enables CORS requests from any website to any domain making you vulnerable to CSRF and session hijacking. CORS is enabled on browsers because its a security standard.

Thread Thread
 
juanfrank77 profile image
Juan F Gonzalez

Hahahaha @rsa is right. That extension is meant for developing purposes, meaning I'm not going to have it turned on everytime for the reasons you mentioned.