Feed Sign in with OpenID OpenID

Simon Willison’s Weblog

Frame-Busting Gadgets. I’ve always been slightly suspicious of the Google Gadgets / OpenSocial idea of sandboxing untrusted third party content in an iframe. Sure enough, it turns out iframe busting scripts work in Gadgets, meaning a seemingly harmless gadget could potentially launch a phishing attack.

Tagged , , , , ,

0 comments

No comments.

Comments are closed.
A django site