Hacker News new | ask | show | jobs
by wglb 3973 days ago
Hindsight and all that but still, this is not a good idea.

Do you mean the browser, or just this particular feature?

Recommended reading: http://lcamtuf.coredump.cx/postxss/ and http://lcamtuf.coredump.cx/tangled/.

If you do choose to read them, I recommend doing it earlier in the day--fitful sleep has been observed after evening reading of the above.

1 comments

I'm aware of those. It's the 'inband/out-of-band' problem of old rearing its ugly head again, if you mix code/control and data in one stream it's asking for trouble.