Hacker News new | past | comments | ask | show | jobs | submit login

This seems to have some fairly scary security implications if used maliciously, but I can't think of a good way to protect against this.

Does anyone know of a browser extension to limit access to the history API?




I started using NoScript a while back, just to see what the web is like without Javascript. My plan was to uninstall it when it got too annoying, but to my surprise it's actually not bad at all. I'm quite lax in whitelisting domains I actually trust, but even then it's nice that it doesn't load Javascript from all other umpteen domains, which is often the case.

Of course it's a very blunt weapon for blocking abuse like what's described in this blog post, but for sure it works.


In my mind, not giving the user opt-in control over this setting is a bug in the browser.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: