Hacker News new | past | comments | ask | show | jobs | submit login

> Or did my brief scan pick up the wrong idea?

I believe so. To quote: "The purpose of Instart Logic technology is to disguise 3rd-party requests as 1st-party requests"

The net result of this is also that third-party javascript will get loaded as if it is first-party. Third-party content will look like first-party content in it's entirety. This subverts any potential security features that rely on being able to distinguish a first party from a third party.

Edit: As an example you can read https://www.w3.org/Security/wiki/Same_Origin_Policy




Thanks for persisting in your explanation.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: