Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

No same-origin-policy, since you can't access the data in the response, but you could do that already with hidden iframes.


You could stick hundreds of huge images forced to 1x1 px size.

Maybe the "annoy a minority of people with tight bandwidth-caps"-attack isn't all that big of a threat.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: