back
1 comments
I think the solution in this case is to not execute code in pictures rather than removing HTTP?

Also I'm starting to suspect the downvoting feature is used a sadistic tool, just keeping karma up so you can punish people.

They don't intentionally execute any code, they do sometimes have a vulnerability that allows memory corruption in a way that can be exploited to run attacker-provided code.

If you're not familiar with this omnipresent class of exploit, I wouldn't hope for many people on HN to take your advice on whether a security measure is needed or not seriously. Even if your comments were underlined and flashing on the page instead of grayed out.