Linked by Thom Holwerda on Fri 20th Mar 2009 13:51 UTC, submitted by google_ninja
Thread beginning with comment 354162
To read all comments associated with this story, please click here.
To read all comments associated with this story, please click here.
RE: The problem isn't any particular browser
by google_ninja on Fri 20th Mar 2009 18:00
in reply to "The problem isn't any particular browser"
RE[2]: The problem isn't any particular browser
by rajj on Fri 20th Mar 2009 18:37
in reply to "RE: The problem isn't any particular browser"
I should have said arbitrary input, but I don't think you can say that javascript is strictly restricted to DOM manipulation either.
The point stands; the end result of all of this is endless turd polishing. We start with a turd; we end with a smoother turd, but it's still a turd nevertheless.




Member since:
2005-07-06
The problem is that browsers in concert with javascript basically allow arbitrary code execution on your machine by potentially anyone on the planet. Call me skeptical, but making such a thing secure _and_ convenient at the same time seems like an intractable problem, and no amount of indirection is going to change that.