Hacker News new | past | comments | ask | show | jobs | submit login

[deleted]



> How is this different from reading link colors / setting a:visited behaviors to see where you've been?

this is completely different thing. I don't read your visited links, i read your current URL in window. and they fixed it, I recall.


It only shows what FB pages have been visited - If I go to /egor.homakov and then type that in for my match string, it says that's my username.

How is this different from reading link colors / setting a:visited behaviors to see where you've been? (I don't remember if browsers have fixed that "bug" or not, it's an old exploit.)


The :visited privacy-related leak is fixed in Firefox, at least: see http://dbaron.org/mozilla/visited-privacy and https://bugzilla.mozilla.org/show_bug.cgi?id=147777 for sources.


ha, there is a NOT SAFE FOR WORK demo i made for :visited :D

http://homakov.github.com/ex.html




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: