Hacker News new | past | comments | ask | show | jobs | submit login

There's a very good reason to run NoScript: most web developers still don't understand CSRF, and hence many web applications are vulnerable to CSRF attacks. Running NoScript prevents untrusted sites from exploiting CSRF holes in sites that you care about.

That said I don't personally run NoScript (I use Safari), but I totally understand people who do.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: