Hacker News new | ask | show | jobs
by 6ue7nNMEEbHcM 2607 days ago
Hi, sorry for a bit of off-topic but perhaps someone could tell me if I'm wrong here. I clicked on this article on medium.com and it shows me a dialog from Google asking if I want to continue browsing medium.com authenticated with my Google account. It shows there my name and e-mail address. I find it a bit concerning. Can medium.com technically walk through the DOM of that page to harvest my personal data such as e-mail address and send it to medium.com with some API call? I guess it must be filled by some .js code linked from google domains. Scary to see my e-mail address appear on random web page I entered.
1 comments

Medium doesn't have access to that part, even though you see it on your screen. It use an iframe, which in the past, was accessible, but now with crossdomain policy and all that, the iframe content is no longer accessible.