6 ms·
I don't see how this is an attack unless you load random third party stylesheets yourself. It's the webmaster's role to ensure that css sheets included on the w
by nukeop 9y ago
I don't see how this is an attack unless you load random third party stylesheets yourself. It's the webmaster's role to ensure that css sheets included on the website do not contact dodgy third party domains.
It also won't work on vanilla html inputs, it has to be controlled by javascript in which case the javascript already has access to this information anyway (and much more).