Author

Topic: Hacking protonmail - with a browser (Read 816 times)

legendary
Activity: 1806
Merit: 1024
July 07, 2014, 02:33:34 PM
#3
Hacking protonmail - with a browser

http://vimeo.com/99599725

/cc all those fancy HTML5-Javascript-wallets out there (blockchain.info, Ripple, etc)

I use a very simple heuristic that saved me from a lot of trouble: Scripted websites are unsuitable for security applications - don't use them for anything sensible.

These days every idiotic page requires scripting for useless effects - often you can't even view simple text without scripting enabled... i cannot express how much I hate this!

Scripting is a disease.

ya.ya.yo!
legendary
Activity: 2618
Merit: 1007
July 07, 2014, 02:11:30 PM
#2
So because they don't escape < > characters in their webmail client makes blockchain.info or Ripple-client vulnerable to something similar?! Huh
legendary
Activity: 1764
Merit: 1007
July 07, 2014, 12:24:17 PM
#1
Hacking protonmail - with a browser

http://vimeo.com/99599725

/cc all those fancy HTML5-Javascript-wallets out there (blockchain.info, Ripple, etc)
Jump to: