Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

”Interesting is, that this resource is only loaded when it is needed (for example when a link is clicked).”

The resource is retrieved using GET, so I wouldn’t think that is required by the http standard. If so, browsers can mitigate this kind of attack by pre-fetching these resources (even pre-fetching a fraction at random already might be enough)

It is a neat hack, though.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: