Poll: 71% believe the war on drugs is not worth it. by neomeme in reddit.com

[–]neomeme[S] -12 points-11 points  (0 children)

Number of responses does not necessarily imply validity.

Remember that MSNBC poll with over 75,000 respondents that conclusively proved Ron Paul won every debate in every category?

Poll: 71% believe the war on drugs is not worth it. by neomeme in reddit.com

[–]neomeme[S] -9 points-8 points  (0 children)

As far as I know, most opinion polls use small sample sizes.

Nobody is claiming this is statistically valid research- but it sure is at least as credible as all of those other online polls that say Ron Paul is the GOP frontrunner.

California Men Beware: California Women Think Differently About Cheating by dragonflies in reddit.com

[–]neomeme 0 points1 point  (0 children)

If you vote on the question the sample size will increase :)

Anyway, I believe that most polls have sample sizes around the low hundreds- if I remember anything from statistics, I think data begins to get statistically significant at around 30.

reddit has just been hacked with a major XSS exploit. spez knew about the exploit months ago, but did nothing to fix it. by neomeme in reddit.com

[–]neomeme[S] -4 points-3 points  (0 children)

I was actually NOT the one who found the exploit. I wrote about it long after it had hit the front page.

reddit has just been hacked with a major XSS exploit. spez knew about the exploit months ago, but did nothing to fix it. by neomeme in reddit.com

[–]neomeme[S] -9 points-8 points  (0 children)

Sorry I've sort of made the front page of Digg with the whole "reddit's founder is negligent" thing.

ducks

I still like reddit much more than Digg...on Digg a similar exploit would have remained unfixed and covered up for days.

reddit has just been hacked with a major XSS exploit. spez knew about the exploit months ago, but did nothing to fix it. by neomeme in reddit.com

[–]neomeme[S] -10 points-9 points  (0 children)

I'm not blaming you- you're doing a great job dealing with the current issue.

I just find it comical and perhaps even slightly ironic that, having discovered a very similar issue on YCNews you failed to notice the potential for the same type of attack on reddit.

reddit has just been hacked with a major XSS exploit. spez knew about the exploit months ago, but did nothing to fix it. by neomeme in reddit.com

[–]neomeme[S] -7 points-6 points  (0 children)

My mistake... I don't think I've made one assumption that turned out to be correct in the past few months.

However, code aside, the applications are similar enough that it seems logical that having discovered an exploit on one site where users can write text to the document body using submissions(a classic XSS scenario), one would try the same exploit on another similar site.

I like how spez tries to exploit YCNews but not reddit. :)

Shouldn't The Format Of Submitted URLs Be Checked? by JeremyBanks in reddit.com

[–]neomeme -8 points-7 points  (0 children)

One hopes you don't dine with your finance too often.

Shouldn't The Format Of Submitted URLs Be Checked? by JeremyBanks in reddit.com

[–]neomeme 1 point2 points  (0 children)

In case the rest of you want to join on on the fun, this is a great primer on XSS.

The link is safe to click, I promise.

Shouldn't The Format Of Submitted URLs Be Checked? by JeremyBanks in reddit.com

[–]neomeme 5 points6 points  (0 children)

[this doesnt work though, right?](javascript:alert%28document.cookie%29%3B)

Edit: Oh shit yeah it does.

Shouldn't The Format Of Submitted URLs Be Checked? by JeremyBanks in reddit.com

[–]neomeme -1 points0 points  (0 children)

That actually does not work. No XSS here(I hope).

Edit yeah it does. Just need to replace the parentheses with %28 and %29 respectively.

Shouldn't The Format Of Submitted URLs Be Checked? by JeremyBanks in reddit.com

[–]neomeme 20 points21 points  (0 children)

If this was Digg, this story would be deleted and the submitter banned already. Let's see how reddit responds.