This is a heavily interactive web application, and JavaScript is required. Simple HTML interfaces are possible, but that is not what this is.
Post
Mikhail Shcherbakov
yu5k3.bsky.social
did:plc:qq3avcx6txafxkhgncoxqwol
Looks like now's the right time to finally dive in! The threat model for extensions looks promising for BB. postMessage() alone opens up new attack variations that don't exist in classic client-side apps 💡
Let's see what I can find in this space 👀
2025-07-23T09:56:42.364Z