Hacker News new | ask | show | jobs
by bn-usd-mistake 2856 days ago
It doesn't because Same-origin protects data on example.com, not on the embedding page (in your example). It is not a security measure that aims to prevent the issue mentioned by the grand parent post