Settings

Theme

Persistent XSS for Medium accounts

medium.com

45 points by r2r 9 years ago · 2 comments

Reader

michaelt 9 years ago

As far as I can tell the TLDR here is: domains can have previous owners, who might have made users cache malicious pages forever.

I agree it's a concerning thing, but I must be missing something because I don't see why this is a medium-specific issue - doesn't it impact almost every website?

  • Rjevski 9 years ago

    I think the issue with Medium is that on a conventional self-hosted domain it only puts content and users of that domain at risk. With Medium it not only puts the content at risk but any user's Medium account.

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection