Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I use RequestPolicy[1] to prevent cross-site requests. If only NoScript is used and a user has allowed javascript on a domain, then NoScript allows cross-site requests and javascript from that domain to run on any domain.

https://www.requestpolicy.com/



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: