Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It is safe, and on my stock international S3 with Chrome as the browser it opens the dialer and displays my IMEI number, as advertised.

It seems to me that there's no reason at all to allow URI's beginning with tel: as the source of a frame. Surely that's a fair limitation?



The approach of prompting the user "Do you want to call this number?" is far simpler and safer. After all, you could probably use tel: links or tel: redirects or something if the frame didn't work.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: