Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's my fault for being imprecise, but I'm saying, developers can already designate regions of their output as "XSS-safe" or "script-free", without a browser extension.


Actually, I tend to agree with your point in the other comment you made in this thread, asking who will actually use it. As one of the few who care in my company, I am both the only one who might set this up, and one of the few who are careful with my encoding in the first place. It does seem an awfully narrow target of people who can't/won't encode correctly, but will do this thing which will also be hard.

Still, I might use it, contingent on broader support and some burn-in time to ensure that it doesn't somehow create some sort of huge hole itself.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: