Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> naming and shaming the advertising network that is allowing this exploit through

The person who found and reported the exploit said this particular exploit did not originate from an ad server[1].

Without disabling javascript, I have always argued that merely disabling 3rd-party iframe tags is a good first move[2]: significantly less breakage than disabling javascript, yet this will effectively step up security/privacy protection.

In the current case, the person who found it confirmed that just blocking 3rd-party frame tags would have foiled the exploit.[3]

[1] https://news.ycombinator.com/item?id=10021894

[2] https://github.com/gorhill/uBlock/wiki/Dynamic-filtering:-Be...

[3] https://news.ycombinator.com/item?id=10022096



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: