> naming and shaming the advertising network that is allowing this exploit through
The person who found and reported the exploit said this particular exploit did not originate from an ad server[1].
Without disabling javascript, I have always argued that merely disabling 3rd-party iframe tags is a good first move[2]: significantly less breakage than disabling javascript, yet this will effectively step up security/privacy protection.
In the current case, the person who found it confirmed that just blocking 3rd-party frame tags would have foiled the exploit.[3]
The person who found and reported the exploit said this particular exploit did not originate from an ad server[1].
Without disabling javascript, I have always argued that merely disabling 3rd-party iframe tags is a good first move[2]: significantly less breakage than disabling javascript, yet this will effectively step up security/privacy protection.
In the current case, the person who found it confirmed that just blocking 3rd-party frame tags would have foiled the exploit.[3]
[1] https://news.ycombinator.com/item?id=10021894
[2] https://github.com/gorhill/uBlock/wiki/Dynamic-filtering:-Be...
[3] https://news.ycombinator.com/item?id=10022096