Skip to content

Comment on XSS vulnerability found in Githubparent

Comments

> I can't use Chrome because it doesn't have NoScript, and I end up routinely visiting domains that I didn't even realize have some foreign-loaded script that pops up some crappy survey over the page ("please give us your private info under the guise of providing site feedback we intend to ignore!"), or pops up a flash ad, or who knows what. The web is too irritating to use anymore without it. (And Flashblock.)

Have a look at https://chrome.google.com/extensions/detail/odjhifogjcknibka... its basically noscript with some restrictions

This is unrelated, but how did Google manage to produce such awful URLs? Is this just a base-26 encoded GUID? If so, they could've saved a few characters: http://www.wolframalpha.com/input/?i=0xED11C880FA5611DDA6040...

Not that this is something you'd want to do in the first place, because it's hideous.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.