Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I suppose more awful thing could be an accidental XSS or other vulnerability.


Which would then compromise what? People's youtube accounts?


IE6 had plenty of nasty vulns by the time this banner had gone up (06/14/2009): https://www.cvedetails.com/vulnerability-list/vendor_id-26/p...

That said, the people with this access probably knew WTF they were doing.


Exactly. They were getting rid of IE6


As opposed to the denial of service style bugs like an empty src element in an img tag?


They're perfectly capable of introducing other DOS bugs that don't depend on bad markup.


This is a poor argument - just because we can shoot our own feet, doesn't mean we should not try to prevent it from happening by accident.

And it sounds like it wasn't just DOS - also just plain "it doesn't work in ie6" seems the most likely outcome; crashes and DOS that the article describes just sounds like the most egregious cases.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: