If you go to your text chat, and click on the icon that looks like a chain, you can embed a link like this

Picture 1

Picture 2

I think you might be referring to iframes. Things like embedding Google Forms so you don’t just click on a link, you can actually fill it out without leaving the IFC.

If that’s the case, it’s due to a security vulnerability called Cross-Site Scripting or XSS. Basically, your browser runs three main languages - HTML (makes the site structure), CSS (makes the site pretty) and JavaScript or JS (makes the site move without reloading the page). The last one, JavaScript, is extremely powerful. It can access a lot of things in your browser. In fact, there are fully-fledged exploits that use just JavaScript to impersonate a user after they visit a malicious site.

I think you can probably see where I’m going with this. If iframes were allowed, anybody could make an iframe with some malicious JavaScript code, have it run as soon as you innocently open their topic and then gain full access to your IFC account by stealing your cookies or even downloading a file that creates a backdoor into your device. No, I’m not exaggerating.

So that’s why iframes aren’t allowed. And before you ask, no I’m not some crazy hacker. I’m a developer and I’ve done some research on this stuff to help make my applications secure.


