Post #1828113
2023-07-01 11:44 UTC
Just think, now every single site that has an #embedded #tweet view in an article is no longer displaying that tweet.
* At best, #Elon can show whatever he wants on it's place, tweet-by-tweet from subtle change to full-on counter-factual or malvertising.
* At worst, it's a vector for Elon #musk to run whatever *code* he wants on your site.
Used an <iframe>? You're in the best case camp.
Used a #Twitter-hosted embed <script> ? Good luck.
Replies (3)
-
@Lazarou@mastodon.social 2023-07-01 14:12
@toychicken can so easily see #Twitter become a source of malware now, because people won't react in time, still wanting to give Elon a break for some reason.
-
@devnull@crag.social 2023-07-01 18:01
@toychicken sounds like a wonderful use-case to demonstrate exactly why a Content Security Policy is important! https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy
-
@Virginicus@universeodon.com 2023-07-01 18:31
@toychicken This isn’t true on my blog, or on the Washington Post. Where are you seeing it?