Using Goatse to Stop App Theft
11–20 of 464 posts
There’s an HTTP header you can add that prevents a page being in an iframe, but go off, king.
Re: Using Goatse to Stop App Theft
#12Your website has the worst permalinks ever.
> This blog is now STATELESS. The entire post is contained in the URL that you are visiting now. All my "blog" is now is a hard-coded main page that contains links to posts I claim authorship of. Of course the entire post is contained in each of these links.
https://joshcsimmons.com/post/H4sIAAAAAAAA%2F3xV227cRgx911cQ...
Re: Using Goatse to Stop App Theft
#13Rest assured that the article linked here does not include any images, goatse or otherwise.
But there are instructions in the article:
>Yesterday one of my collaborators googled "sqword" and to his surprise, there were tons of first-page results that weren't the sqword.com domain.
Re: Using Goatse to Stop App Theft
#14Re: Using Goatse to Stop App Theft
#15There’s an HTTP header you can add that prevents a page being in an iframe, but go off, king.
[deleted]
Re: Using Goatse to Stop App Theft
#16There’s an HTTP header you can add that prevents a page being in an iframe, but go off, king.
Yup. The article mentions it was an “explicit” decision to use this approach instead. Seems much more effective than CSP headers.
Re: Using Goatse to Stop App Theft
#17maybe OP tried it's exploit in internet explorer 5.0, but I doubt it'll work in any recent (read: less than 5 years old) browser.
Re: Using Goatse to Stop App Theft
#18Re: Using Goatse to Stop App Theft
#19I would argue showing nonconsentual explicit imagery is worse than iframing someomes app. Just show a non nsfw troll meme or block it outright.
Re: Using Goatse to Stop App Theft
#20There’s an HTTP header you can add that prevents a page being in an iframe, but go off, king.
> The mature and responsible thing to do would have been to add a content security policy to the page
OP knows that