Hacker News new | ask | show | jobs
by purec 1857 days ago
Hey, thanks for reading! I wish I could have gone into detail with more of the headers but as you probably saw that was a 13 minute read going into one of them... and that could have been repeating for at least another 10.

I can see why they allowed scripts for SVG's but I completely agree with you that scripts should never be executed for <img>. The potential for exploits far outweighs the benefit of it.