4 ms·
Alternative interpretation: Iframes are so overpowered and such an edge case for the browser's security models that they cause constant issues with the rest of
by zethraeus 8y ago
Alternative interpretation: Iframes are so overpowered and such an edge case for the browser's security models that they cause constant issues with the rest of the reasonable browser spec.
- unilynx 8y agoIframes will never go away. But we need a way to tell a browser "if you embed this page into an iframe, it needs to be the topmost content, no transform/translate/visibility or anything". Social/login iframe would set that flag, and it would prevent the clickjacks and attacks like this.
- deleted 8y ago[deleted]
- user5994461 8y agoAll websites are supposed to set the header X-Frame-Options: DENY to block iframes. It's a solved problem.
- empyrical 8y agoThat doesn't solve the issue of clickjacking attempts on pages meant to be in iframes (FB like buttons are in iframes)
- unilynx 8y agoThat solves clickjacking for things which don't want to be iframed, but not for things like the Like button or login buttons which specifically need to be embedded into an existing page (and they were the attack vector for this article)
- jstewartmobile 8y agoiframes have been a "no-no" since web 1.0. Still no up-front browser setting for disabling them. I wonder why...