Re: Sandboxed iframes (was Re: Seamless iframes + CSS3 selectors = bad idea)

> And if developers start using the example that is given in the spec, then a
> lot of people (devs often just follow documentation without thinking
> twice) will miss the fact that attackers can inject a link instead of an
> iframe.

+1 .. that example is really broken.


Received on Sunday, 6 December 2009 08:48:08 UTC