Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I did understand the point he was trying to make, but to me that's a poor analogy. This self-XSS prevention is a temporary solution. Facebook probably thought they had enough of people reporting dev console self-XSS so they took the initiative.

Netflix is not abusing "for your security" to do awful things. How? I just don't see it. I see that as an accusation, putting Netflix and Facebook's temporary solution in the same category as NSA's excuse is bad. I might be unfair to the author for not reading the entire post (well technically I read most of it, except Crockford and afterward I gave a quick glance), I will admit that's my failure, but that argument doesn't appeal to me at all.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: