Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It doesn't because Same-origin protects data on example.com, not on the embedding page (in your example). It is not a security measure that aims to prevent the issue mentioned by the grand parent post


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: