Eradicating image authentication injection from the entire internet

from blog Blog | Sam Curry, | ↗ original
Thinking back to old forum days I can specifically remember an event where attackers modified their avatars to be invalid pages that responded with "HTTP 401 Unauthorized". This didn't really seem like an issue because there was interaction required by the users and the community was smart enough to simply close the prompt. After a long night of...