Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

No same-origin-policy, since you can't access the data in the response, but you could do that already with hidden iframes.


You could stick hundreds of huge images forced to 1x1 px size.

Maybe the "annoy a minority of people with tight bandwidth-caps"-attack isn't all that big of a threat.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: