Hacker News new | past | comments | ask | show | jobs | submit login

So, letting arbitrary javascript from an untrusted source run on our production website?

No thanks.




You are a grump. The source is right there for all to see, audit, and fix.


The problem with this widget is the majority of the widget contents are stuck in an iframe. The js code mostly just does time detection and places the iframe on the site.

So even if you can audit and fix the js code you're running, you're still including content served straight from someone else's machine.

When we did this similar thing for sopa blackout (https://github.com/sirpengi/sopablackout), our widget was entirely self-contained (and under 200 LOC). And if you didn't trust our server you could host it entirely yourself.




Consider applying for YC's W25 batch! Applications are open till Nov 12.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: