• KairuByte@lemmy.dbzer0.com
    link
    fedilink
    arrow-up
    0
    ·
    1 year ago

    Cross domain policies are enforced by the browser. If you’re using a third party app, guess what you’re using as a browser.

    Want an easy example of this? Userscrips on Firefox. Install GreaseMonkey, and you can run whatever the hell you want on any webpage. Keylogging, mouse movements, clicks and navigations. Not hard, and impossible to really stop from the site itself, because no matter what you tell the browser to do, you essentially have to just hope the browser follows through.

    • Echo Dot@feddit.uk
      link
      fedilink
      arrow-up
      0
      ·
      1 year ago

      Somebody else is already pointed out that it’s already been debunked so no it wasn’t happening

      • KairuByte@lemmy.dbzer0.com
        link
        fedilink
        arrow-up
        0
        ·
        1 year ago

        I was responding to your claim of “not happening, impossible” with proof of it being possible, and actually fairly easy to implement.