3 ms·
This is just how the web (e.g. iframes, XSS) works in general.
by abider 5y ago
This is just how the web (e.g. iframes, XSS) works in general.
- krferriter 5y agoRight. But if I include an arbitrary link to a cryptocurrency mining script in my comment right here, hackernews' website won't load it into your browser and start executing it as soon as you view this comment, with no interaction needed from you. If they did, that would be bad.
- abider 5y agoOh yeah, sure. I think we're on the same page here. It's literally no different than an XSS vulnerability (done on purpose or otherwise), which basically boils down to: yeah, don't do that.