Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I think that is treading down a slippery slope. Here, http://jsfiddle.net/a2zK5/ , I have used Imgur to host a bit of javascript; this could be a blob or anything for that matter but this is only an example. It's not Imgur's fault that this was uploaded, but if it got popular then the easiest thing to do would be to block all request to the site.

The real issue isn't what we don't allow/block, but what we do allow/let pass.



How would you go about fixing this vulnerability? Is MrGrim aware of it?




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: