Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This also sneaks past CORS. I'm thinking _that's_ a problem.


Why do you think this bypasses CORS?


Well, it bypasses the spirit, which was to exert some control over what got loaded into the browser via the back door. Now, malicious code can just come in the front door.


If anything it's a useful demonstration of how CORS is more theater than security for anything beyond the most trivial scenarios.


I wonder how hard it would be to come up with a "containerization" mechanism for the web so as to separate scripts/resources better.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: