Hacker News new | ask | show | jobs
by animeweedlord 3674 days ago
There are any number of ways to deanonymize users once javascript is running, not to mention the greater possibility of escaping the sandbox. It's a damned if you do, damned if you don't scenario.

I know they're trying to serve users that can't be expected to play the whitelisting game, but they really should be stricter here. It's already trivial to differentiate a Tor user from a regular one, they might as well set the most secure defaults possible.