Hacker News new | ask | show | jobs
by todd3834 1020 days ago
Perhaps they meant CSP
1 comments

I did say it wrong, but my point was that the site doesn't segment off each "site" into a different subdomain or any other ruleset that would allow the same origin policy to restrict access.

As it is with this site, the messages can get "stolen" by any other site on the same domain, which can be anything since anyone can upload one and direct a victim to them.