Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I think parent comment was implying the alternative is NoScript


Certainly that's one approach, but perhaps there's a middle ground, where we can have trusted sources of JS.

Perhaps not, but I do stand by my initial comment, it's crazy we just download and execute stuff from wherever and somehow have expectations of security!


We need some kind of a code review system (peer based?) to review JS code that is allowed to be enabled.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: