Re: [whatwg] Disabling document.domain setting on iframe@sandbox (especially with allow-same-origin)

On 8/2/13 6:55 PM, Ian Hickson wrote:
> How does it solve it? (What _is_ the "mail.google.com vs
> calendar.google.com case"?)

The case is when mail.google.com tries to attack calendar.google.com, 
and they can't be in different processes as mitigation because you never 
know when they'll both set domain to "google.com"...

-Boris

Received on Saturday, 3 August 2013 01:18:12 UTC