Hacker News new | ask | show | jobs
In the DOM We Trust: The Hidden Dangers of Reading the DOM on the Web [pdf] (trouge.net)
1 points by ArneVogel 158 days ago
1 comments

As a neophyte, I failed to see them demonstrate injection. They seem to model what injection would mean, but not show how the threat actor got into the flow.

Probably for non neophytes who this is aimed at, that's a given.