I see people recommending that whenever one uses target="_blank"
in a link to open it in a different window, they should put rel="noopener noreferrer"
. I wonder how does this prevent me from using Developer Tools in Chrome, for example, and removing the rel attribute. Then clicking the link...
Is that an easy way to still keep the vulnerability?
See Question&Answers more detail:
os 与恶龙缠斗过久,自身亦成为恶龙;凝视深渊过久,深渊将回以凝视…