Or is this idle speculation.
Or is this idle speculation.
In other words, you have to trust Google to not insert such a trojan by itself and to not bow down to the U.S. government should it try to secretly force Google to do so.
You also have to trust that their security is good enough to prevent third parties from covertly performing such a feat.
That's not say that Google should not be trusted or should be trusted less than other parties, but that's the threat.
This is not an unrealistic example.
"Accidentally" logging keys is possible, as Google can modify the content of the JS on request – for example, in case of being served an NSL, Google can be forced to modify the JS to log that.
Source?
As you are doing automated updates, Google can just add Analytics to the browser, and even publish it as something "good".