Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Facebook provides a link to disable this behavior in the message that appears when you try to use the console: https://www.facebook.com/selfxss Furthermore, a Facebook employee involved with the feature explained it on StackOverflow: http://stackoverflow.com/a/21693931/62628

It seems that users were being duped in to running malicious scripts that gave attackers control of their accounts. Sure, Facebook could be evil and not offer the option to re-enable the console and I'm sure other sites will do exactly that until browser makers prevent it, but at this time, Facebook is not being evil. I'm not sure about Netflix.

If people are being successfully duped in to running malicious scripts this way, perhaps browser developers should put a first-run warning on the dev tools saying that running code there supplied by a third-party is dangerous.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: