|
|
|
|
|
by tyrust
24 days ago
|
|
Why doesn't the article contain proof of either attack in action? I would be surprised if the second attack worked after what must be at least a couple layers of markdown/html conversion and spam filtering. disclaimer: work at Google, but far removed from YouTube |
|
But still, it would require a user interaction to click on the link to leak data - and google should acknowledge it as an issue, because an attacker should never be able to generate a link they control in a trusted/secure environment.