4 ms·
Maybe not everyone is aware so I want to point out these issues: 1. Don't use it if the page is over SSL (it'll include external JS over HTTP which means that
by grumpyfart 17y ago
Maybe not everyone is aware so I want to point out these issues:
1. Don't use it if the page is over SSL (it'll include external JS over HTTP which means that you are vulnerable to MITM)
2. Don't use it if the website carries "sessionid"s over URL
3. Keep in mind that arc90's JS can actually read the cookies (I'm not saying they are but they can). That means if someone hack into their systems they can access to cookies in used websites. (think XSS). Obviously by using it you trust instapaper guys with your account in the active website.
Developers of Readability should point out these security issues clearly in their website.
- nixme 17y agos/instapaper/arc90/g ?
- grumpyfart 17y agoyou are right, edited.
- telemachos 17y agoYou missed one in #3.
- grumpyfart 17y agoI can't edit it any more, I think because of it's been a while. Anyway I'm sure people will figure out.
- MHordecki 17y agoWith Readability Redux (extension for Chrome) JS is stored locally, so it probably addresses those issues.
- grumpyfart 17y agoSounds nice, I'll look into that.