Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I wonder whether any interesting HTML injection tricks could be done by exploiting autocorrect in the same way.


I think the point of BlastDoor, as covered in the post, is that Apple is indeed working to prevent injection at the cost of silently failing & poorly handling legitimate messages.

> By being pedantic about the formatting, BlastDoor is protecting the recipient from an exploit that would abuse that type of issue.

So, not impossible, but less likely than you think




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: