Hi HN, so that's my site, and well, I'm feeling pretty dumb right now. I really didn't think that post through--honestly I put more thought into carving pumpkins yesterday. So, here's my retraction that I added to the top of the post:
So, sometimes I am wrong. This attack does work, but it’s irrelevant, and here’s why: if someone has control of the DOM the game is already over, there’s nothing the browser can do for you in that case. It doesn’t really matter that the hover-status can be spoofed at that point. I’ll leave the post up so you can marvel in my stupid, but to summarize–nothing to see here. (At least I’m not throwing banner ads at you.)
If it's any consolation being dumb has a price :) I don't try to make any money off that site. No ads, no syndication, no attempts at revenue whatsoever. My bandwidth bill is gonna hurt this month, so if you don't mind down-voting the link, I'd be pretty appreciative.
Well, it says a lot for you that you admitted your mistake. Hope you will become a regular HNer :) I'm actually quite surprised your post got so many up votes considering this community is mostly dominated by web developers.