Paste this into the URL bar:
data:text/html,<h1>hello</h1>
or try this like the article suggests: data:text/html,<html contenteditable>Paste this into the URL bar:
data:text/html,<h1>hello</h1>
or try this like the article suggests: data:text/html,<html contenteditable> data:text/html,<script>alert('pasting code from the internet in to your address bar should not be encouraged');</script> javascript:alert(document.cookie)1. It strips the JavaScript: part away if I just paste it once
2. Even if I re-add it manually, it still does no alert
Ergo, a sane browser can be quite sandboxed to avoid the average user to do stupid to easily.
So that's one difference. Not that the type of person to use NoScript would likely paste obvious javascript into the address bar...
Edit: Doesn't look like you can create a valid URL with that format, but it can be launched via pasting in (obviously), a bookmark (which the contents of which could be obfuscated by telling a user to drag an image to the bookmark bar and click it), and can be launched via command line, e.g.
start firefox "data:text/html,<script>alert('');</script>" data:text/html,<div id="c" contenteditable></div><a id="p"></a><script>var el=document.getElementById('c');el.addEventListener('input',function(){document.getElementById('p').textContent='Copy me';document.getElementById('p').href="data:text/html,"+this.parentElement.innerHTML;},false);</script>
And to expand that awful payload, it's basically the very simple: <div id="c" contenteditable></div>
<a id="p"></a>
<script>
var el = document.getElementById('c');
el.addEventListener('input', function() {
document.getElementById('p').textContent = 'Copy me';
document.getElementById('p').href = "data:text/html," + this.parentElement.innerHTML;
}, false);
</script>
The idea being, you can _almost_ have a self-saving editable page. Because it was fun to make.bookmark to access archive.today instead of addon
And https://viewdns.info/ping/?domain=archive.today to get the fastest IP and include it in /etc/hosts