Live data from Hacker News

Ramarchy – a website anyone can edit

edit.ramarchy.com

11–12 of 12 posts

Re: Ramarchy – a website anyone can edit

#11
post #10
post #6

Seems like someone who uses LastPass got XSRF'd: view-source: http://ramarchy.com/

The source has changed since your post. If I use LastPass and visited the site, should I be worried? What did the script do?

The script grabbed document.documentElement.innerHTML and resubmitted it as the new page contents. See my post above regarding CSRF.

Re: Ramarchy – a website anyone can edit

#12
post #8

At least put some basic protection in place. There was a time when you could have launched this website without a problem, say 1995 or so. Today this is no longer possible. To the dumbass downvoting me: I just took a look with wget and the current homepage will set you in a loop that starts up endless mailer windows until your machine crashes. Good luck.

It looks like it intentionally didn't have any protections in place. The edit page has the comment

It also has What could possibly go wrong. go wrong in the default editor source.

Was it irresponsible? Yes zq should have put a warning for sure. Still a cool experiment. Twitch Plays Pokemon with bigger repercussions.

Post reply on HN