by spaniard_dev on 10/5/16, 8:01 PM with 5 comments
by pedalpete on 10/5/16, 9:37 PM
I see how this might be possible as the ads are loaded via javascript, but the javascript running the ads should be owned by Spotify, not the advertising company, that should just be an image file. Somebody please correct me if I'm wrong.
On another note, this statement "Some of them do not even require user action to be able to cause harm." makes me trust this even less. If the ad is opening a new browser window, that browser window is sandboxed. Sure it can ask the user to take an action, but it can't take an action on behalf of the user.
Anybody else have insights on this?
by wcummings on 10/5/16, 9:33 PM
>it's still puzzling something like this can actually happen.
I think the interesting thing is that its the default browser. If the ads were in an embedded trident or gecko frame, would something like window.open open the default browser?