Hacker News new | ask | show | jobs
by jdjb 4102 days ago
I use NoScript as well (and I wish more people would) but to be fair I doubt the users who were part of the botnet even noticed it at all. It's only github who would've benefited from these users running NoScript.
1 comments

Yeah, it was obviously a lighthearted comment, but the larger issue is that every web user is running someone else's untrusted code on every website they visit. Frankly I'm surprised these kinds of attacks aren't more common. NoScript helps mitigate this issue, and while it has lots of other incidental bonuses that a nerd like myself cares about, I freely admit it results in a worse end-user experience for almost everyone else.
They could have done a similar attack with an <IMG> tag. Or do you block images too?
Erm, you don't? I suggest you read the Basilisk FAQ before you get into real trouble...

http://ansible.uk/writing/c-b-faq.html

Something like Request Policy could cover this