Hacker News new | ask | show | jobs
by bawolff 1779 days ago
True, however when people pop an alert from a cross origin iframe for a bug bounty, 80% of the time they're pretending to be on the parent origin when they aren't and get sad when their report is rejected.