Hacker News new | past | comments | ask | show | jobs | submit login

That breaks the visitor counter, since it relied on updating the underlying document to update the counts!

I was going to go ahead and hide the lock button entirely to avoid this attack, but decided I would get some work done today instead.

EDIT: after a bit more hacking, I removed the password and hid the lock button. Nothing that would stop a determined adversary :) (Also, I kept the Khajit change in your honor)




Great. Thanks!

Fix for this incoming. I don't want to limit HTML insertion in general, but I'll make sure scripts are not possible.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: