Hacker News new | past | comments | ask | show | jobs | submit login

> NoScript detected a potential Cross-Site Scripting attack

> from https://edge.bigthink.com to https://js.stripe.com.

> Suspicious data:

> (URL) https://js.stripe.com/v3/elements-inner-card-212...b40.html#...

WTF is that about?

Setup for "Join Premium"?

But why talk to Stripe in advance?

Edit: Hey, I apologize for going off topic.

But I'm just a little surprised that a site would want to trigger XSS warnings. And why they'd risk it.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: