Re: [whatwg] Security restriction allows content thievery

2012-09-07 Thread Adam Barth
On Thu, Sep 6, 2012 at 9:53 PM, Ian Hickson i...@hixie.ch wrote: On Fri, 7 Sep 2012, Fred Andrews wrote: I think the aim is to have the URL of the page that includes these data: URLs sent to the tracking server? Ah, I see. So say you have a page A, which itself contains a data: URL, and you

Re: [whatwg] Security restriction allows content thievery

2012-09-06 Thread Ian Hickson
On Mon, 16 Jul 2012, Robert Eisele wrote: Browsers are very restrictive when one tries to access the contents of different domains (including the scheme), embedded via framesets. This is normally a good practice, but I'd suggest to weaken this restriction for the data: URI schema. It

Re: [whatwg] Security restriction allows content thievery

2012-09-06 Thread Fred Andrews
I'm currently building an analysis system like Google Analytics, which gets embedded into a website via a small JavaScript snippet. When I analyzed the data, I came across a very interesting trick because I got a lot of requests (with the data from location.href) where the entire

Re: [whatwg] Security restriction allows content thievery

2012-09-06 Thread Ian Hickson
On Fri, 7 Sep 2012, Fred Andrews wrote: I think the aim is to have the URL of the page that includes these data: URLs sent to the tracking server? Ah, I see. So say you have a page A, which itself contains a data: URL, and you load that data: URL as page B, and in B there is a link to

[whatwg] Security restriction allows content thievery

2012-07-15 Thread Robert Eisele
Browsers are very restrictive when one tries to access the contents of different domains (including the scheme), embedded via framesets. This is normally a good practice, but I'd suggest to weaken this restriction for the data: URI schema. I'm currently building an analysis system like Google

Re: [whatwg] Security restriction allows content thievery

2012-07-15 Thread Tab Atkins Jr.
On Sun, Jul 15, 2012 at 3:22 PM, Robert Eisele rob...@xarg.org wrote: Browsers are very restrictive when one tries to access the contents of different domains (including the scheme), embedded via framesets. This is normally a good practice, but I'd suggest to weaken this restriction for the

Re: [whatwg] Security restriction allows content thievery

2012-07-15 Thread Robert Eisele
2012/7/16 Tab Atkins Jr. jackalm...@gmail.com On Sun, Jul 15, 2012 at 3:22 PM, Robert Eisele rob...@xarg.org wrote: Browsers are very restrictive when one tries to access the contents of different domains (including the scheme), embedded via framesets. This is normally a good practice, but

Re: [whatwg] Security restriction allows content thievery

2012-07-15 Thread Ryosuke Niwa
On Sun, Jul 15, 2012 at 4:02 PM, Robert Eisele rob...@xarg.org wrote: 2012/7/16 Tab Atkins Jr. jackalm...@gmail.com On Sun, Jul 15, 2012 at 3:22 PM, Robert Eisele rob...@xarg.org wrote: Browsers are very restrictive when one tries to access the contents of different domains (including