Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Assuming the codex editor is the editor for the area below the auction counter, isn't that a security vulnerability that can put the site audience at risk?




The Codex agent is only given tools to edit the single HTML file that displays on the homepage. The page is on a separate domain, so there's no cookie sharing, and the iFrame is in a sandbox. That said, the biggest risk is social engineering attacks.

What’s to stop someone rewriting the iframe wrapper to hide the real iframe and display a fake one?

They cannot edit the iFrame itself. The user is allowed to edit the contents within the iFrame.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: