Hacker News new | past | comments | ask | show | jobs | submit login

Maybe not everyone is aware so I want to point out these issues:

1. Don't use it if the page is over SSL (it'll include external JS over HTTP which means that you are vulnerable to MITM)

2. Don't use it if the website carries "sessionid"s over URL

3. Keep in mind that arc90's JS can actually read the cookies (I'm not saying they are but they can). That means if someone hack into their systems they can access to cookies in used websites. (think XSS). Obviously by using it you trust instapaper guys with your account in the active website.

Developers of Readability should point out these security issues clearly in their website.




With Readability Redux (extension for Chrome) JS is stored locally, so it probably addresses those issues.


Sounds nice, I'll look into that.


s/instapaper/arc90/g ?


you are right, edited.


You missed one in #3.


I can't edit it any more, I think because of it's been a while. Anyway I'm sure people will figure out.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: