Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Plugin found to collect browser sessions #1904

Closed
aading opened this issue Jan 29, 2025 · 2 comments
Closed

Plugin found to collect browser sessions #1904

aading opened this issue Jan 29, 2025 · 2 comments

Comments

@aading
Copy link

aading commented Jan 29, 2025

During our security review, it was found to collect browser session data which potentially can lead to security risks, do you have a page or section talk about the data you collect and what permission do you need for this plugin?

@Mottie
Copy link
Member

Mottie commented Jan 29, 2025

Our privacy-policy

@tophf
Copy link
Member

tophf commented Jan 30, 2025

Stylus has never "collected" anything, so I suspect a mistake in your methodology. Please elaborate.

It's hard to argue in face of broad and vague accusations... The closest thing I can think of is the local style cache that stores the last 1000 visited URLs for faster startup of the extension's background script, but it's not used anywhere else and will never be used anywhere else, because our extension exists exactly because we rejected a data collection company that took over the original Stylish extension. I already thought of either removing the cache altogether by rewriting the way the main styles are stored or by using a hash instead of the URL.

@tophf tophf closed this as completed Jan 31, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants