Hacker News new | ask | show | jobs
by ppergame 923 days ago
Each browser tab and cross-origin iframe is its own process sandbox. Web security operates on domain boundaries.

If your webmail provider or bank is serving malware or user generated content under the same origin as the frontend, they have self-owned beyond the browser’s capacity to help.