Hacker News new | past | comments | ask | show | jobs | submit login

"But, if you’re logged in the intranet of Awesome Corp., once you open my dangerous.com website I’ll know that you have access."

How? The subresource is a url to an internal server (https://intra.awesome-corp.com/avatars/john-doe.png)... sure it loads from my browser, but how does that tell that info to dangerous.com?




img = document.createElement('img'); img.src = 'https://intra.awesome-corp.com/avatars/john-doe.png'; img.onload = ?




Consider applying for YC's Summer 2025 batch! Applications are open till May 13

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: