Live data from Hacker News

Firefox 6 for web developers

hacks.mozilla.org

31–32 of 32 posts

Re: Firefox 6 for web developers

#31
post #10
post #8

Earlier quoted context omitted.

Sounds smart. It's extremely easy to get an unsophisticated user (heck, any user who isn't a web developer) to paste a random string of junk in to their URL bar - and doing so is a very nasty XSS vector that works no matter what precautions a site's developers have taken. I'm sure I've heard of this attack being used successfully on Facebook, spread through messages that say "paste this in to your URL bar to get X".

So those messages will say "press [whatever key combo activates the console] and paste this text there for a funny video" instead?

Or possibly "drag this link to the toolbar and click when on any page on Facebook to see which of your friends is viewing that page" or whatever.

Re: Firefox 6 for web developers

#32

Earlier quoted context omitted.

Yeah, I caught this hanging out at the bottom of the list too... Immediately set to thinking how I'm gonna have to go rewrite the dozen or so bookmarklets I've written to support FF6

Bookmarklets are not affected when used as bookmarks. Only URIs typed directly into the location bar are affected.

Oh, sweet.
Post reply on HN