Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The security risk is precisely why a lot of new services provide embeddable content via iframes now, rather than JS. On the other hand, this still isn't perfect - we wrote about it today, actually: https://www.tinfoilsecurity.com/blog/protect-your-website-fr...


As long as you host the JavaScript yourself this shouldn't be a problem. Why would it? Iframes suck.


Iframes do suck. However, success of a whole crop of companies like Disqus depends on it sucking less. I am sure this is a known issue for these companies.


It's only not a problem if you audit every single line of JS you host yourself. Most companies and people don't.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: