On Wed, 02 Jan 2008 19:26:03 +0100, Close, Tyler J. <tyler.close@hp.com> wrote: > Sure, but the question is: "Who's responsibility is it?". In my opinion, > it is the server's responsibility to ensure a safe default for each > resource. You seem to have the perspective that it's the client's > responsibility. Most XSS problems have been due to lack of knowledge of the authors. SQL injection is a big one for instance. Also script injection due to lack of escaping on the server side. Trusting the authors to do the right thing does not seem responsible at all. -- Anne van Kesteren <http://annevankesteren.nl/> <http://www.opera.com/>Received on Wednesday, 2 January 2008 18:37:02 GMT
This archive was generated by hypermail 2.2.0+W3C-0.50 : Tuesday, 8 January 2008 14:10:24 GMT