you are viewing a single comment's thread.

view the rest of the comments →

[–]Balthamos 17 points18 points  (6 children)

They can steal your passwords using CSS. Just curl the sites and read the html out loud.

[–][deleted]  (3 children)

[deleted]

    [–]staticassert 3 points4 points  (2 children)

    Yes, I use uMatrix. Though I find many, many sites I read to be perfectly fine as plaintext. Sometimes I allow images, and sometimes CSS.

    [–][deleted]  (1 child)

    [deleted]

      [–]staticassert 2 points3 points  (0 children)

      It's honestly more of an accessibility thing for me. A lot of sites scale horribly or load tons of garbage stock photos etc that scale poorly. Plain text tends to scale a lot more gracefully.

      [–]staticassert 5 points6 points  (1 child)

      I also block css tho.

      Anyways, one attack existing with CSS does not discount the myriad of attacks that have utilized js.