TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

I Got Hacked by Hacker News Readers

7 pointsby bbrennanover 9 years ago

3 comments

krappover 9 years ago
I think a lot of people probably get burned not realizing that the Markdown spec includes all valid HTML by default.<p>Still, I don&#x27;t think building a Markdown parser that doesn&#x27;t sanitize or whitelist allowed tags by default is really excusable, even if it would be slower.<p>And i&#x27;ve seen several mvp projects posted here that crash if you so much as post an empty form. It seems to be an easy thing to forget.
Nadyaover 9 years ago
At least they did something cute&#x2F;funny rather than fullscreen a liveleak gore video or worse. :)<p><i>&gt;This has also made me a more fervent believer in security-by-default.</i><p>I&#x27;ve yet to understand why anyone would be against security-by-default. How many users would rather have set of [x] features that for whatever reason require an insecure setup compared to those who would prefer a secure setup?
评论 #10314750 未加载
lightlyusedover 9 years ago
Ah, the good old days.