4 ms·
It seems that HTML5 will force people to allow embedding Javascript. How will we be able to avoid cross-site scripting attacks this way?
by rivo 16y ago
It seems that HTML5 will force people to allow embedding Javascript. How will we be able to avoid cross-site scripting attacks this way?
- adamdecaf 16y agoI didn't have to enable javascript to play the video (chromium), all you have to do is create the video element and load the source. Then all extra commands can be loaded with javascript. <video controls> <source src="video.ogg" /> </video> <script> function load_video_extras() { ... } </script>
- mikeryan 16y agoHow, why? Why not just host the Javascript yourself to prevent XSS attacks. I'm missing something here - why would this be less secure then any other JS lib?