Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The unencrypted (or more importantly, unauthenticated) content loading into the iframe is subject to any number of malicious content injection techniques. E.g. http://www.thespanner.co.uk/2007/10/24/iframes-security-summ...

Professional malware distributors seem perfectly happy to obtain placement inside an iframe: http://www.usenix.org/event/hotbots07/tech/full_papers/provo...

Edit: Also, don't you trigger mixed content warnings in the browser?



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: