← Back to context

Comment by gcr

3 days ago

Does this mean an attacker can turn any impression into any GET request?

It'd be an interesting way to count how many impressions your tweets get: add a URL to every tweet, put a tracking "pixel" in the webpage (assuming the webview loads all assets; if not, then just add the "pixel' URL to the tweet..

Not sure how much of an attack that is. FWIW the preloading is nice as a user.

  • Is the request coming from the user's IP or via a Twitter proxy?

    As a plain webview would mean that you can grab everyone's details.