4 ms·
I can't think of a reliable way to filter out "malicious" code without also having many false positives. Without having seen their solution, I feel that the br
by phoboslab 16y ago
I can't think of a reliable way to filter out "malicious" code without also having many false positives.
Without having seen their solution, I feel that the browser is the wrong place to fix this kind of problem anyway. Much like PHP tried to prevent SQL Injection Attacks with "Magic Quotes" - we all know how that went.
- X-Istence 16y agoThis is not about the browser "fixing" the issue, but rather helping developers find the issues in the first place.