Ask HN: How did they do this?
I visited this website (http://chemistry.tutorvista.com/organic-chemistry/nitro-group.html) and was immediately greeted with a Google Chat-like message in the bottom right corner. Here's the transcript:
Tutor: Hi, I'm a Chemistry Tutor.
May I help you?
Do you want to take a free tutoring session with me?
me: o.O
Tutor: Let us start working on the whiteboard.
Please wait while the whiteboard loads
Redirecting to whiteboard
In less than 30 seconds after loading, someone had managed to engage a conversation with me and redirect my browser, without my consent, to their "Whiteboard" page. I am using Ghostery with NoScript in Firefox 20 on OS X. The only page with JS enabled was TutorVista's, so everything was apparently done on-page.How did they do this, and does this pose a security threat?
By the time I finished writing this, FF pushed an update. I'll try again under 21 to see if it still works.
Update: It still works in 21. It seemed very real at first, but I'm pretty sure it's a trigger-redirect. The messages are exactly the same. Still, I'm suspicious of how kosher the script is.