Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> > What stops a script on evil.com from going to bank.com...

> CORS

Incorrect. It's SOP that prevents an evil.com script from going to bank.com

It's CORS that allows evil.com. CORS is an insecurity feature that relaxes the SOP.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: